Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   SweetPacks IM , Yourfile Downloader (https://www.trojaner-board.de/125279-sweetpacks-yourfile-downloader.html)

holzdan 07.10.2012 00:38

SweetPacks IM , Yourfile Downloader
 
Hallo.
Da mir die Lizenz fuer meine Internet Security Suite verfallen ist war ich nun eine Zeit lang ohne Schutz im Netz unterwegs.Da hat es nicht lange gedauert und ich hatte schon verschiedene toolbars wie babylon , pc beschleunigen tool usw auf der Platte.Auch Sweet Packs IM und yourfile downloader obwohl ich mich nicht erinnern konnte sowas je installiert zu haben.Habe nun Sweet Packs und yourfile downloader , babylon deinstalliert doch ich werde einfach das Gefuehl nicht los dass noch irgendwas übrig ist da mein System wirklich ungalublich langsam läuft seitdem mir diese "Tools" aufgefallen sind.Habe auch mein System wieder ein wenig aufgeräumt mit tune up utilities und cc cleaner was normalerweise den Pc immer wieder etwas flotter macht , diesmal nicht.
Habe meinen Pc auch schon mit Malwarebytes , Eset und einigen anderen Scannern getestet jedoch wurde nix gefunden.
Daher wollte ich meinen OLT - Log hier posten und hoffe mir kann jemand damit weiterhelfen und vielleicht eine Infektion erkennen.

cosinus 07.10.2012 09:13

Trotzdem bitte alle Logs von malwarebytes und ESET posten
Die Logs enthalten ein paar mehr Infos als nur Fund oder kein Fund.

Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

holzdan 07.10.2012 10:28

Habe die Logs der Virenscans leider nicht gespeichert.
Werde sie daher nochmal laufen lassen.Hier inzwischen meine otl.txt

otl.txt part 1

Code:

OTL logfile created on: 07.10.2012 11:14:15 - Run 2
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\aaa\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,86 Gb Total Physical Memory | 2,63 Gb Available Physical Memory | 67,95% Memory free
7,73 Gb Paging File | 6,46 Gb Available in Paging File | 83,63% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 463,16 Gb Total Space | 379,91 Gb Free Space | 82,02% Space Free | Partition Type: NTFS
 
Computer Name: AAA-PC | User Name: aaa | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.10.07 01:21:44 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\aaa\Desktop\OTL.exe
PRC - [2012.09.20 05:38:56 | 000,175,496 | ---- | M] (GFI Software) -- C:\Program Files (x86)\GFI Software\VIPRE\SBPIMSvc.exe
PRC - [2012.08.06 13:44:16 | 000,642,216 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
PRC - [2012.07.27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012.01.27 09:47:20 | 000,828,944 | ---- | M] (GlavSoft LLC.) -- C:\Program Files (x86)\Common Files\Comodo\tvnserver.exe
PRC - [2009.10.01 06:01:32 | 002,320,920 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2009.10.01 06:01:30 | 000,268,824 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2009.08.28 11:38:58 | 001,150,496 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
PRC - [2009.07.10 03:54:44 | 000,253,952 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe
PRC - [2009.06.05 05:03:06 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
 
 
========== Modules (No Company Name) ==========
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - [2012.07.28 04:09:44 | 000,239,616 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2012.10.06 19:20:37 | 000,529,744 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2012.09.20 05:39:12 | 003,677,000 | ---- | M] (GFI Software) [Auto | Stopped] -- C:\Program Files (x86)\GFI Software\VIPRE\SBAMSvc.exe -- (SBAMSvc)
SRV - [2012.09.20 05:38:56 | 000,175,496 | ---- | M] (GFI Software) [Auto | Running] -- C:\Program Files (x86)\GFI Software\VIPRE\SBPIMSvc.exe -- (SBPIMSvc)
SRV - [2012.08.30 13:23:28 | 000,008,704 | ---- | M] (Hi-Rez Studios) [Auto | Stopped] -- C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe -- (HiPatchService)
SRV - [2012.08.28 17:52:44 | 000,250,568 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.08.23 10:17:28 | 000,070,352 | ---- | M] (Comodo Security Solutions Inc.) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\Comodo\launcher_service.exe -- (CLPSLauncher)
SRV - [2012.07.27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012.07.13 13:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.03.11 21:13:24 | 002,815,496 | ---- | M] (COMODO) [Auto | Running] -- C:\Programme\COMODO\COMODO Internet Security\cmdagent.exe -- (cmdAgent)
SRV - [2012.01.27 09:47:20 | 000,828,944 | ---- | M] (GlavSoft LLC.) [Auto | Running] -- C:\Program Files (x86)\Common Files\Comodo\tvnserver.exe -- (tvnserver)
SRV - [2010.07.08 14:18:29 | 000,333,264 | ---- | M] () [Auto | Stopped] -- C:\Program Files (x86)\3DataManager\WTGService.exe -- (WTGService)
SRV - [2010.03.18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.12.03 16:27:24 | 000,028,672 | ---- | M] (LSI Corporation) [Auto | Running] -- C:\Programme\LSI SoftModem\agr64svc.exe -- (AgereModemAudio)
SRV - [2009.11.02 13:48:18 | 000,126,352 | ---- | M] (Intel(R) Corporation) [On_Demand | Stopped] -- C:\Programme\Intel\TurboBoost\TurboBoost.exe -- (TurboBoost)
SRV - [2009.10.01 06:01:32 | 002,320,920 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2009.10.01 06:01:30 | 000,268,824 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2009.09.30 15:44:58 | 000,844,320 | ---- | M] (Acer Incorporated) [Auto | Stopped] -- C:\Programme\Acer\Acer ePower Management\ePowerSvc.exe -- (ePowerSvc)
SRV - [2009.09.25 01:42:28 | 000,062,720 | ---- | M] (NewTech Infosystems, Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe -- (NTI IScheduleSvc)
SRV - [2009.09.11 07:42:46 | 000,305,448 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe -- (MWLService)
SRV - [2009.08.28 11:38:58 | 001,150,496 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files (x86)\Acer\Registration\GregHSRW.exe -- (Greg_Service)
SRV - [2009.07.10 03:54:44 | 000,253,952 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe -- (RS_Service)
SRV - [2009.07.04 04:47:12 | 000,240,160 | ---- | M] (Acer) [Disabled | Stopped] -- C:\Programme\Acer\Acer Updater\UpdaterService.exe -- (Updater Service)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009.06.05 05:03:06 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe -- (IAANTMON)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2012.10.01 18:31:53 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2012.09.20 05:11:58 | 000,086,816 | ---- | M] (GFI Software) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sbwtis.sys -- (sbwtis)
DRV:64bit: - [2012.09.12 20:19:38 | 000,082,872 | ---- | M] (GFI Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\sbapifs.sys -- (sbapifs)
DRV:64bit: - [2012.08.30 22:03:48 | 000,128,456 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2012.08.03 10:23:28 | 000,035,064 | ---- | M] (Windows (R) Win 7 DDK provider) [File_System | System | Stopped] -- C:\Windows\SysNative\drivers\CFRMD.sys -- (CFRMD)
DRV:64bit: - [2012.07.28 06:07:44 | 010,278,912 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2012.07.28 06:07:44 | 010,278,912 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2012.07.28 03:14:46 | 000,368,640 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2012.05.14 08:12:30 | 000,096,896 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2012.04.13 20:12:13 | 000,121,344 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ZTEusbser6k.sys -- (ZTEusbser6k)
DRV:64bit: - [2012.04.13 20:12:13 | 000,121,344 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ZTEusbnmea.sys -- (ZTEusbnmea)
DRV:64bit: - [2012.04.13 20:12:13 | 000,121,344 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ZTEusbmdm6k.sys -- (ZTEusbmdm6k)
DRV:64bit: - [2012.04.13 20:12:13 | 000,012,800 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\massfilter.sys -- (massfilter)
DRV:64bit: - [2012.03.01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011.11.21 16:44:30 | 002,793,472 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:64bit: - [2011.10.17 16:55:32 | 000,559,384 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2011.07.01 05:46:40 | 000,031,232 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tap0901.sys -- (tap0901)
DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010.11.20 15:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.20 13:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.02.27 08:32:14 | 000,158,976 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd)
DRV:64bit: - [2009.12.03 17:07:04 | 001,224,192 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\agrsm64.sys -- (AgereSoftModem)
DRV:64bit: - [2009.09.18 06:12:06 | 000,292,912 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2009.09.17 22:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64)
DRV:64bit: - [2009.08.06 14:43:58 | 000,320,040 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\k57nd60a.sys -- (k57nd60a)
DRV:64bit: - [2009.07.23 00:06:26 | 000,040,448 | ---- | M] (Alcor Micro, Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AmUStor.sys -- (AmUStor)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.25 04:23:24 | 000,205,472 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtHDMIVX.sys -- (RTHDMIAzAudService)
DRV:64bit: - [2009.06.20 04:09:57 | 000,054,272 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\L1E62x64.sys -- (L1E)
DRV:64bit: - [2009.06.10 22:37:05 | 006,108,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2009.06.10 22:34:38 | 001,311,232 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.06.03 05:15:30 | 000,060,464 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDVDisk.sys -- (mwlPSDVDisk)
DRV:64bit: - [2009.06.03 05:15:30 | 000,022,576 | ---- | M] (Egis Technology Inc.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDFilter.sys -- (mwlPSDFilter)
DRV:64bit: - [2009.06.03 05:15:30 | 000,020,016 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDNserv.sys -- (mwlPSDNServ)
DRV:64bit: - [2009.05.06 02:46:08 | 000,018,432 | ---- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NTIDrvr.sys -- (NTIDrvr)
DRV:64bit: - [2009.05.06 02:46:08 | 000,016,896 | ---- | M] (NewTech Infosystems Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\UBHelper.sys -- (UBHelper)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_7740&r=27360312d206l04c8z135t64n1c413
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://home.sweetim.com/?crg=3.1010000.10002&barid={27A42084-C696-11E1-ACC2-0017C4F1B1FE}
IE - HKLM\..\SearchScopes,DefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_7740&r=27360312d206l04c8z135t64n1c413
IE - HKCU\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = hxxp://search.babylon.com/?q={searchTerms}&affID=112555&babsrc=SP_ss&mntrId=d65cf95f0000000000000017c4f1b1fe
IE - HKCU\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW_deAT474
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = https://isearch.avg.com/search?cid={224E4F9B-E9F3-4617-9BC5-9CE19CA4FA5F}&mid=59da8dcef8ac47d08f78d15e8215580d-2e33c930fa5d3169a9ea342d66355adcb0b86bd8&lang=de&ds=cv011&pr=sa&d=2012-07-05 13:39:36&v=12.2.5.32&sap=dsp&q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
========== FireFox ==========
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_265.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.4.53: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.4.53: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.4.53: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012.05.06 17:15:11 | 000,000,000 | ---D | M]
 
 
O1 HOSTS File: ([2012.10.06 16:26:02 | 000,444,411 | R--- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1        www.007guard.com
O1 - Hosts: 127.0.0.1        007guard.com
O1 - Hosts: 127.0.0.1        008i.com
O1 - Hosts: 127.0.0.1        www.008k.com
O1 - Hosts: 127.0.0.1        008k.com
O1 - Hosts: 127.0.0.1        www.00hq.com
O1 - Hosts: 127.0.0.1        00hq.com
O1 - Hosts: 127.0.0.1        010402.com
O1 - Hosts: 127.0.0.1        www.032439.com
O1 - Hosts: 127.0.0.1        032439.com
O1 - Hosts: 127.0.0.1        www.0scan.com
O1 - Hosts: 127.0.0.1        0scan.com
O1 - Hosts: 127.0.0.1        www.1000gratisproben.com
O1 - Hosts: 127.0.0.1        1000gratisproben.com
O1 - Hosts: 127.0.0.1        1001namen.com
O1 - Hosts: 127.0.0.1        www.1001namen.com
O1 - Hosts: 127.0.0.1        100888290cs.com
O1 - Hosts: 127.0.0.1        www.100888290cs.com
O1 - Hosts: 127.0.0.1        www.100sexlinks.com
O1 - Hosts: 127.0.0.1        100sexlinks.com
O1 - Hosts: 127.0.0.1        www.10sek.com
O1 - Hosts: 127.0.0.1        10sek.com
O1 - Hosts: 127.0.0.1        www.1-2005-search.com
O1 - Hosts: 127.0.0.1        1-2005-search.com
O1 - Hosts: 127.0.0.1        www.123fporn.info
O1 - Hosts: 15262 more lines...
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files (x86)\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files (x86)\Orbitdownloader\GrabPro.dll ()
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files (x86)\Orbitdownloader\GrabPro.dll ()
O4:64bit: - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4 - HKLM..\Run: [SBAMTray] C:\Program Files (x86)\GFI Software\VIPRE\SBAMTray.exe (GFI Software)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [tvncontrol] C:\Program Files (x86)\Common Files\Comodo\tvnserver.exe (GlavSoft LLC.)
O4 - HKCU..\Run: [FreeAC] C:\Program Files (x86)\FreeAlarmClock\FreeAlarmClock.exe (Comfort Software Group)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
O4 - HKLM..\RunOnceEx: [Flags] Reg Error: Invalid data type. File not found
O4 - Startup: C:\Users\aaa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Proxomitron.exe - Verknüpfung.lnk = C:\Users\aaa\Desktop\PROXOMITRON\Proxomitron.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8:64bit: - Extra context menu item: &Download by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8:64bit: - Extra context menu item: &Grab video by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8:64bit: - Extra context menu item: Do&wnload selected by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8:64bit: - Extra context menu item: Down&load all by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Download by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab video by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload selected by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load all by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL (Microsoft Corporation)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{04DDC8C3-4207-4A03-847A-5F0D098AC1F3}: NameServer = 8.26.56.26,156.154.70.22
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{908D8B77-90CF-4CB0-84F4-67EF8DA6CDD4}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{908D8B77-90CF-4CB0-84F4-67EF8DA6CDD4}: NameServer = 8.26.56.26,156.154.70.22
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18:64bit: - Protocol\Filter\text/html - No CLSID value found
O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/html - No CLSID value found
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - AppInit_DLLs: (C:\Windows\system32\guard64.dll) - C:\Windows\SysNative\guard64.dll (COMODO)
O20 - AppInit_DLLs: (C:\Windows\SysWOW64\guard32.dll) - C:\Windows\SysWOW64\guard32.dll (COMODO)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{70624967-858a-11e1-a36c-0017c4f1b1fe}\Shell - "" = AutoRun
O33 - MountPoints2\{70624967-858a-11e1-a36c-0017c4f1b1fe}\Shell\AutoRun\command - "" = E:\.\Autorun.exe AUTORUN=1
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (MACHINE BootExecut)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.10.07 11:12:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\COMODO
[2012.10.07 11:12:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Comodo
[2012.10.07 11:12:07 | 000,000,000 | -HSD | C] -- C:\Windows\SysWow64\%APPDATA%
[2012.10.07 11:10:41 | 000,000,000 | ---D | C] -- C:\ProgramData\CPA_VA
[2012.10.07 11:09:35 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\COMODO
[2012.10.07 01:21:44 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\aaa\Desktop\OTL.exe
[2012.10.07 01:10:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2012.10.07 00:49:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TweakNow PowerPack 2012
[2012.10.07 00:49:00 | 000,000,000 | ---D | C] -- C:\Users\aaa\AppData\Roaming\TweakNow PowerPack 2012
[2012.10.07 00:49:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TweakNow PowerPack 2012
[2012.10.07 00:37:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Comodo
[2012.10.07 00:37:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\COMODO
[2012.10.07 00:37:01 | 000,000,000 | ---D | C] -- C:\Program Files\COMODO
[2012.10.07 00:04:47 | 000,000,000 | ---D | C] -- C:\ProgramData\GFI Software
[2012.10.07 00:04:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GFI Software
[2012.10.07 00:04:24 | 000,047,496 | ---- | C] (GFI Software) -- C:\Windows\SysNative\sbbd.exe
[2012.10.07 00:03:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Downloaded Installations
[2012.10.06 23:52:02 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\directx
[2012.10.06 23:08:38 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2012.10.06 23:03:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD APP
[2012.10.06 23:03:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
[2012.10.06 22:53:52 | 000,000,000 | ---D | C] -- C:\AMD
[2012.10.06 22:48:11 | 000,000,000 | ---D | C] -- C:\Users\aaa\AppData\Local\Chromium
[2012.10.06 22:43:36 | 000,000,000 | ---D | C] -- C:\Users\aaa\Documents\My Games
[2012.10.06 21:28:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xvid
[2012.10.06 21:28:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Xvid
[2012.10.06 21:26:49 | 000,000,000 | ---D | C] -- C:\Users\aaa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zak McKracken - Between Time & Space
[2012.10.06 21:26:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zak McKracken - Between Time & Space
[2012.10.06 21:26:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Zak2
[2012.10.06 21:22:09 | 000,000,000 | ---D | C] -- C:\Users\aaa\Desktop\zak
[2012.10.06 21:14:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hi-Rez Studios
[2012.10.06 21:14:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Hi-Rez Studios
[2012.10.06 21:14:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Hi-Rez Studios
[2012.10.06 20:00:52 | 000,000,000 | -HSD | C] -- C:\Windows\SysNative\%APPDATA%
[2012.10.06 19:28:34 | 000,000,000 | ---D | C] -- C:\Users\aaa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
[2012.10.06 19:07:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Opera
[2012.10.06 16:15:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2012.10.06 16:15:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy
[2012.10.06 15:28:17 | 000,000,000 | -H-D | C] -- C:\Users\aaa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Disabled Startup Items
[2012.10.06 15:28:17 | 000,000,000 | -H-D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Disabled Startup Items
[2012.10.06 15:28:02 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\regruninfo
[2012.10.06 15:27:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Greatis
[2012.10.06 15:16:09 | 000,039,184 | ---- | C] (Greatis Software) -- C:\Windows\SysNative\Partizan.exe
[2012.10.06 15:12:24 | 000,000,000 | ---D | C] -- C:\ProgramData\RegRun
[2012.10.06 15:11:49 | 000,000,000 | ---D | C] -- C:\Users\aaa\Documents\RegRun2
[2012.10.06 12:20:58 | 000,000,000 | ---D | C] -- C:\Users\aaa\Desktop\Bücher-links
[2012.10.06 02:34:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Coranti
[2012.10.06 02:32:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Coranti
[2012.10.06 02:16:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GFI Software
[2012.10.06 02:16:35 | 000,000,000 | ---D | C] -- C:\Users\aaa\AppData\Roaming\GFI Software
[2012.10.06 01:44:52 | 000,000,000 | ---D | C] -- C:\Users\aaa\AppData\Local\Sophos
[2012.10.06 01:25:13 | 000,000,000 | ---D | C] -- C:\Users\aaa\Local Settings
[2012.10.06 01:16:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Sophos
[2012.10.06 01:00:50 | 000,000,000 | ---D | C] -- C:\escw_100_sa
[2012.10.06 00:57:47 | 000,000,000 | ---D | C] -- C:\Users\aaa\AppData\Local\Symantec
[2012.10.06 00:55:23 | 000,287,152 | ---- | C] (Symantec Corporation) -- C:\Windows\SysNative\SymVPN.dll
[2012.10.06 00:55:23 | 000,058,288 | ---- | C] (Symantec Corporation) -- C:\Windows\SysNative\snacnp.dll
[2012.10.05 23:52:02 | 000,251,560 | ---- | C] (PC Tools) -- C:\Windows\SysNative\drivers\PCTSD64.sys
[2012.10.05 23:52:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PC Tools
[2012.10.05 23:51:30 | 000,000,000 | ---D | C] -- C:\ProgramData\PC Tools
[2012.10.05 23:51:28 | 000,000,000 | ---D | C] -- C:\Users\aaa\AppData\Roaming\TestApp
[2012.10.05 23:27:42 | 000,000,000 | -HSD | C] -- C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
[2012.10.05 22:06:34 | 000,000,000 | ---D | C] -- C:\Program Files\InstallShield Installation Information
[2012.10.05 21:41:00 | 000,000,000 | ---D | C] -- C:\Users\aaa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameSpy Arcade
[2012.10.05 21:41:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GameSpy Arcade
[2012.10.05 21:40:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GameSpy Arcade
[2012.10.05 21:40:14 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Monolith Productions
[2012.10.05 21:35:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sierra
[2012.10.05 20:30:20 | 000,000,000 | ---D | C] -- C:\Users\aaa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Netdevil
[2012.10.05 20:06:36 | 000,000,000 | ---D | C] -- C:\Users\aaa\AppData\Local\GameSpy
[2012.10.05 20:06:27 | 000,000,000 | ---D | C] -- C:\Users\aaa\AppData\Local\ApplicationHistory
[2012.10.05 20:06:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GameSpy
[2012.10.05 20:06:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GameSpy
[2012.10.05 20:05:09 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\URTTEMP
[2012.10.05 20:04:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AGEIA
[2012.10.05 20:03:46 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\AGEIA
[2012.10.05 20:03:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AGEIA Technologies
[2012.10.05 20:03:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wise Installation Wizard
[2012.10.05 20:03:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Netdevil
[2012.10.05 15:34:02 | 000,000,000 | ---D | C] -- C:\Users\aaa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tennis Elbow 2011
[2012.10.05 15:34:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tennis Elbow 2011
[2012.10.05 15:34:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Tennis Elbow 2011
[2012.10.01 18:35:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LucasArts
[2012.10.01 18:34:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LucasArts
[2012.10.01 18:32:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Pro
[2012.10.01 18:31:53 | 000,283,200 | ---- | C] (DT Soft Ltd) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys
[2012.10.01 18:31:49 | 000,000,000 | ---D | C] -- C:\Users\aaa\AppData\Roaming\DAEMON Tools Pro
[2012.10.01 18:31:43 | 000,000,000 | ---D | C] -- C:\Users\aaa\AppData\Roaming\OpenCandy
[2012.10.01 18:31:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DAEMON Tools Pro
[2012.10.01 18:30:41 | 000,000,000 | ---D | C] -- C:\ProgramData\DAEMON Tools Pro
[2012.09.20 05:40:04 | 000,047,496 | ---- | C] (GFI Software) -- C:\Windows\SysWow64\sbbd.exe
[2012.09.20 05:11:58 | 000,086,816 | ---- | C] (GFI Software) -- C:\Windows\SysNative\drivers\sbwtis.sys
[2012.09.12 20:19:42 | 000,634,560 | ---- | C] (Xceed Software Inc        (450) 442-2626        support@xceedsoft.com        www.xceedsoft.com) -- C:\Windows\SysWow64\XceedZip.dll
[2012.09.12 20:19:38 | 000,082,872 | ---- | C] (GFI Software) -- C:\Windows\SysNative\drivers\sbapifs.sys
[2009.11.05 05:33:04 | 000,036,136 | ---- | C] (Oberon Media) -- C:\ProgramData\FullRemove.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.10.07 11:18:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.10.07 11:17:10 | 000,017,600 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.10.07 11:17:10 | 000,017,600 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.10.07 11:12:19 | 000,002,051 | ---- | M] () -- C:\Users\Public\Desktop\AntiError.lnk
[2012.10.07 11:12:19 | 000,002,047 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk
[2012.10.07 11:12:19 | 000,002,047 | ---- | M] () -- C:\Users\Public\Desktop\GeekBuddy.lnk
[2012.10.07 11:09:30 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.10.07 11:08:55 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.10.07 10:40:01 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.10.07 01:39:54 | 000,000,000 | ---- | M] () -- C:\Users\aaa\defogger_reenable
[2012.10.07 01:22:06 | 000,050,477 | ---- | M] () -- C:\Users\aaa\Desktop\Defogger.exe
[2012.10.07 01:21:44 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\aaa\Desktop\OTL.exe
[2012.10.07 00:49:08 | 000,002,035 | ---- | M] () -- C:\Users\Public\Desktop\TweakNow PowerPack 2012.lnk
[2012.10.07 00:37:17 | 000,001,846 | ---- | M] () -- C:\Users\Public\Desktop\COMODO Firewall.lnk
[2012.10.07 00:04:28 | 000,002,019 | ---- | M] () -- C:\Users\Public\Desktop\VIPRE.lnk
[2012.10.06 23:45:46 | 000,007,669 | ---- | M] () -- C:\Users\aaa\AppData\Local\Resmon.ResmonCfg
[2012.10.06 23:22:32 | 000,001,110 | ---- | M] () -- C:\Users\aaa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Proxomitron.exe - Verknüpfung.lnk
[2012.10.06 23:17:42 | 000,000,372 | ---- | M] () -- C:\Windows\ODBC.INI
[2012.10.06 22:36:54 | 003,629,231 | ---- | M] () -- C:\Program Files (x86)\YourFileDownloader.rar
[2012.10.06 21:26:50 | 000,000,959 | ---- | M] () -- C:\Users\aaa\Desktop\Zak McKracken - BTAS.lnk
[2012.10.06 21:14:57 | 000,002,041 | ---- | M] () -- C:\Users\Public\Desktop\Hi-Rez Diagnostics and Support.lnk
[2012.10.06 21:14:57 | 000,002,032 | ---- | M] () -- C:\Users\Public\Desktop\Tribes Ascend.lnk
[2012.10.06 19:28:34 | 000,000,219 | ---- | M] () -- C:\Users\aaa\Desktop\Counter-Strike Source.url
[2012.10.06 19:08:02 | 000,001,837 | ---- | M] () -- C:\Users\Public\Desktop\Opera.lnk
[2012.10.06 16:46:41 | 000,005,104 | ---- | M] () -- C:\Windows\wininit.ini
[2012.10.06 16:26:02 | 000,444,411 | R--- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012.10.06 15:28:21 | 000,000,002 | RHS- | M] () -- C:\Windows\winstart.bat
[2012.10.06 15:28:21 | 000,000,002 | RHS- | M] () -- C:\Windows\SysWow64\CONFIG.NT
[2012.10.06 15:28:21 | 000,000,002 | RHS- | M] () -- C:\Windows\SysWow64\AUTOEXEC.NT
[2012.10.06 15:16:09 | 000,039,184 | ---- | M] (Greatis Software) -- C:\Windows\SysNative\Partizan.exe
[2012.10.06 00:55:23 | 000,287,152 | ---- | M] (Symantec Corporation) -- C:\Windows\SysNative\SymVPN.dll
[2012.10.06 00:55:23 | 000,058,288 | ---- | M] (Symantec Corporation) -- C:\Windows\SysNative\snacnp.dll
[2012.10.05 23:52:24 | 001,997,385 | ---- | M] () -- C:\Windows\SysNative\drivers\Cat.DB
[2012.10.05 20:41:19 | 000,362,016 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.10.05 20:06:27 | 000,000,091 | ---- | M] () -- C:\Users\aaa\AppData\Local\fusioncache.dat
[2012.10.05 20:05:29 | 001,554,122 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012.10.05 20:05:29 | 000,664,634 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.10.05 20:05:29 | 000,624,776 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.10.05 20:05:29 | 000,134,770 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.10.05 20:05:29 | 000,110,414 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.10.02 03:00:36 | 000,001,912 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012.10.01 18:33:54 | 001,505,034 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.10.01 18:31:53 | 000,283,200 | ---- | M] (DT Soft Ltd) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys
[2012.09.26 16:55:44 | 000,000,162 | ---- | M] () -- C:\Users\aaa\SecurityKISSTunnel.config
[2012.09.20 05:40:04 | 000,047,496 | ---- | M] (GFI Software) -- C:\Windows\SysWow64\sbbd.exe
[2012.09.20 05:40:04 | 000,047,496 | ---- | M] (GFI Software) -- C:\Windows\SysNative\sbbd.exe
[2012.09.20 05:11:58 | 000,086,816 | ---- | M] (GFI Software) -- C:\Windows\SysNative\drivers\sbwtis.sys
[2012.09.12 20:19:42 | 000,634,560 | ---- | M] (Xceed Software Inc        (450) 442-2626        support@xceedsoft.com        www.xceedsoft.com) -- C:\Windows\SysWow64\XceedZip.dll
[2012.09.12 20:19:38 | 000,082,872 | ---- | M] (GFI Software) -- C:\Windows\SysNative\drivers\sbapifs.sys
[2012.09.07 17:04:46 | 000,025,928 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.10.07 11:12:19 | 000,002,051 | ---- | C] () -- C:\Users\Public\Desktop\AntiError.lnk
[2012.10.07 11:12:19 | 000,002,047 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk
[2012.10.07 11:12:19 | 000,002,047 | ---- | C] () -- C:\Users\Public\Desktop\GeekBuddy.lnk
[2012.10.07 01:39:54 | 000,000,000 | ---- | C] () -- C:\Users\aaa\defogger_reenable
[2012.10.07 01:22:06 | 000,050,477 | ---- | C] () -- C:\Users\aaa\Desktop\Defogger.exe
[2012.10.07 00:49:08 | 000,002,035 | ---- | C] () -- C:\Users\Public\Desktop\TweakNow PowerPack 2012.lnk
[2012.10.07 00:37:17 | 000,001,846 | ---- | C] () -- C:\Users\Public\Desktop\COMODO Firewall.lnk
[2012.10.07 00:04:28 | 000,002,019 | ---- | C] () -- C:\Users\Public\Desktop\VIPRE.lnk
[2012.10.06 23:45:46 | 000,007,669 | ---- | C] () -- C:\Users\aaa\AppData\Local\Resmon.ResmonCfg
[2012.10.06 23:22:32 | 000,001,110 | ---- | C] () -- C:\Users\aaa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Proxomitron.exe - Verknüpfung.lnk
[2012.10.06 22:36:53 | 003,629,231 | ---- | C] () -- C:\Program Files (x86)\YourFileDownloader.rar
[2012.10.06 21:28:52 | 000,765,952 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2012.10.06 21:28:52 | 000,077,824 | ---- | C] () -- C:\Windows\SysWow64\xvid.ax
[2012.10.06 21:28:50 | 000,180,224 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2012.10.06 21:26:50 | 000,000,959 | ---- | C] () -- C:\Users\aaa\Desktop\Zak McKracken - BTAS.lnk
[2012.10.06 21:14:57 | 000,002,041 | ---- | C] () -- C:\Users\Public\Desktop\Hi-Rez Diagnostics and Support.lnk
[2012.10.06 21:14:57 | 000,002,032 | ---- | C] () -- C:\Users\Public\Desktop\Tribes Ascend.lnk
[2012.10.06 19:28:34 | 000,000,219 | ---- | C] () -- C:\Users\aaa\Desktop\Counter-Strike Source.url
[2012.10.06 19:08:02 | 000,001,849 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
[2012.10.06 19:08:02 | 000,001,837 | ---- | C] () -- C:\Users\Public\Desktop\Opera.lnk
[2012.10.06 16:46:33 | 000,005,104 | ---- | C] () -- C:\Windows\wininit.ini
[2012.10.06 15:28:02 | 000,057,556 | ---- | C] () -- C:\Windows\guard.bmp
[2012.10.06 15:11:51 | 000,000,002 | RHS- | C] () -- C:\Windows\winstart.bat
[2012.10.06 15:11:51 | 000,000,002 | RHS- | C] () -- C:\Windows\SysWow64\CONFIG.NT
[2012.10.06 15:11:51 | 000,000,002 | RHS- | C] () -- C:\Windows\SysWow64\AUTOEXEC.NT
[2012.10.05 23:52:08 | 001,997,385 | ---- | C] () -- C:\Windows\SysNative\drivers\Cat.DB
[2012.10.05 20:06:27 | 000,000,091 | ---- | C] () -- C:\Users\aaa\AppData\Local\fusioncache.dat
[2012.10.05 15:34:10 | 000,921,600 | ---- | C] () -- C:\Windows\SysNative\vorbisenc.dll
[2012.10.05 15:34:10 | 000,237,568 | ---- | C] () -- C:\Windows\SysNative\OggDS.dll
[2012.10.05 15:34:10 | 000,188,416 | ---- | C] () -- C:\Windows\SysNative\vorbis.dll
[2012.10.05 15:34:10 | 000,045,056 | ---- | C] () -- C:\Windows\SysNative\ogg.dll
[2012.05.28 12:29:23 | 000,000,162 | ---- | C] () -- C:\Users\aaa\SecurityKISSTunnel.config
[2012.03.11 17:44:19 | 001,554,122 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012.03.11 05:13:30 | 000,001,744 | ---- | C] () -- C:\Windows\WPatchProgress.ini
[2012.03.11 02:40:53 | 000,026,569 | ---- | C] () -- C:\ProgramData\1331426446.4376.bin
[2012.03.11 02:40:48 | 000,008,383 | ---- | C] () -- C:\ProgramData\1331426446.3708.bin
[2012.03.11 02:40:47 | 000,006,945 | ---- | C] () -- C:\ProgramData\1331426446.3724.bin
[2012.03.11 02:40:46 | 000,054,366 | ---- | C] () -- C:\ProgramData\1331426446.2708.bin
[2012.03.11 01:48:28 | 000,000,372 | ---- | C] () -- C:\Windows\ODBC.INI
[2012.03.11 01:15:44 | 000,302,835 | ---- | C] () -- C:\ProgramData\1331420176.bdinstall.bin
[2012.03.10 21:05:49 | 000,626,688 | ---- | C] () -- C:\Windows\Image.dll
[2012.03.10 21:05:49 | 000,200,704 | ---- | C] () -- C:\Windows\PLFSetI.exe
[2012.03.10 21:05:49 | 000,020,480 | ---- | C] () -- C:\Windows\USB_VIDEO_REG.exe
[2012.03.10 21:05:49 | 000,000,323 | ---- | C] () -- C:\Windows\PidList.ini
[2012.03.10 20:46:34 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2012.02.15 04:36:36 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012.02.15 04:36:36 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2012.02.07 20:35:48 | 000,119,296 | ---- | C] () -- C:\Windows\SysWow64\zlibwapi.dll
[2012.02.07 20:35:48 | 000,119,296 | ---- | C] () -- C:\Windows\SysWow64\zlib.dll
[2012.01.31 07:00:24 | 000,016,896 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2011.09.13 00:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
 
========== ZeroAccess Check ==========
 
[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 07:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 14:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2012.04.13 20:47:28 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\3DataManager
[2012.03.11 01:03:45 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\Bitdefender
[2012.03.14 23:51:04 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\BitTorrent
[2012.03.24 20:40:48 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\Cerberus LLC
[2012.10.06 19:09:42 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\DAEMON Tools Pro
[2012.03.26 19:10:35 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\foobar2000
[2012.05.01 20:29:42 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\GameHouse
[2012.10.06 02:16:35 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\GFI Software
[2012.03.24 20:07:29 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\GrabPro
[2012.07.05 13:17:39 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\ImgBurn
[2012.03.11 16:53:28 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\KC Softwares
[2012.10.01 18:31:46 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\OpenCandy
[2012.05.11 11:03:43 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\OpenOffice.org
[2012.10.06 19:08:11 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\Opera
[2012.10.05 23:28:13 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\Orbit
[2012.03.24 20:08:18 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\ProgSense
[2012.03.11 01:00:45 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\QuickScan
[2012.03.14 22:34:31 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\Securepoint Operation Center
[2012.10.05 23:51:28 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\TestApp
[2012.10.05 23:28:33 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\TuneUp Software
[2012.10.07 00:49:03 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\TweakNow PowerPack 2012
[2012.10.06 19:09:42 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\uTorrent
[2012.05.02 17:42:17 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\YourFileDownloader

otl.txt part 2

Code:

========== Purity Check ==========
 
 
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 52 bytes -> C:\Windows\write.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\WPatchProgress.ini:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\WMSysPr9.prx:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\WLXPGSS.SCR:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\WisPriority.ini:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\WisMvImg.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\WisLangCode.ini:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\WisGAPasx64.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\WisGAPas.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winhlp32.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\WindowsUpdate.log:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\WindowsShell.Manifest:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\WIN7BASE_XX.TAG:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\win.ini:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\USER.XML:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\USB_VIDEO_REG.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\UNINST32.EXE:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\twunk_32.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\twunk_16.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\twain_32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\twain.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\tasks\SCHEDLGU.TXT:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\zlibwapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\zlib.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\zipfldr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\xwtpw32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\xwtpdui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\xwreg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\xwizards.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\xwizard.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\xwizard.dtd:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\xpssvcs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\XPSSHHDR.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\xpsservices.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\xpsrchvw.xml:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\xpsrchvw.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\XpsRasterService.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\XpsPrint.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\XpsGdiConverter.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\XpsFilt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\xolehlp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\xmlprovi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\xmllite.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\xmlfilter.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\XInput9_1_0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\xcopy.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\XceedSco.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\XceedCry.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wzcdlg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wwapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WWanAPI.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wvc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wuwebv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wusa.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wups.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wudriver.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wuapp.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wuapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wtsapi32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WSTPager.ax:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wsock32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wsnmp32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WsmWmiPl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WsmTxt.xsl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WsmSvc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WsmRes.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WsmPty.xsl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wsmprovhost.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wsmplpxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WsmAuto.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WSManMigrationPlugin.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WSManHTTPConfig.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wsmanconfig_schema.xml:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WSHTCPIP.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wshrm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wshqos.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wshom.ocx:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wshirda.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wship6.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wshext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wshelper.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wshcon.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wshbth.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wsecedit.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wsdchngr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WSDApi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wscui.cpl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wscript.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wscproxystub.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wscmisetup.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wscisvif.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wscinterop.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wscapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ws2help.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ws2_32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\write.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wpdwcn.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WPDSp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WPDShServiceObj.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WPDShextAutoplay.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wpdshext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wpcsvc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wpcao.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Wpc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wowreg32.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wow32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WMVXENCD.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WMVSENCD.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WMVSDECD.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WMVENCOD.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wmvdspa.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WMVDECOD.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WMVCORE.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WMSPDMOE.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WMSPDMOD.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wmsgapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WMPhoto.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WMNetMgr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wmiprop.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wmidx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wmi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wmdrmsdk.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wmdrmnet.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wmdrmdev.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wmdmps.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wmdmlog.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wmcodecdspps.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WMASF.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WMADMOE.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WMADMOD.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WlS0WndH.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wlgpclnt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Wldap32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wlanutil.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wlanui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wlansec.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wlanpref.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wlanmsm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WlanMM.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wlaninst.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wlanhlp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wlangpui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wlanext.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wlandlg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WLanConn.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wlancfg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wlanapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wksprtPS.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wkscli.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WISPTIS.EXE:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\winver.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\winusb.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wintrust.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WinSyncProviders.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WinSyncMetastore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WinSync.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\winsta.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WINSRPC.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\winspool.drv:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\winsockhc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\winshfhc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WinSCard.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WinSATAPI.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\winrssrv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\winrsmgr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\winrshost.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\winrscmd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\winrs.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\winrnr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\winrm.vbs:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\winrm.cmd:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\winnsi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\winmm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\winipsec.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wininit.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wininet.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\winhttp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WinFax.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WindowsCodecsExt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WindowsCodecs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wincredprovider.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\winbrand.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\winbio.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\win32spl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wimserv.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wimgapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wiavideo.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wiatrace.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wiashext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wiascanprofiles.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WiaExtensionHost64.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wiadss.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wiadefui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wiaaut.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wiaacmgr.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\whoami.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\whhelper.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\where.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\whealogr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WfHC.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wfapigp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WF.msc:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wextract.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wevtutil.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wevtfwd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wevtapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\werui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wermgr.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WerFaultSecure.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WerFault.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\werdiagcontroller.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wer.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wecutil.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wecapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\webservices.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\webio.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WebClnt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\webcheck.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WEB.rs:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wdscore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wdmaud.drv:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wdigest.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wdi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wdc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WcsPlugInService.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wcnwiz.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WcnEapPeerProxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WcnEapAuthProxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wcncsvc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WcnApi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wbemcomn.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wavemsp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\waitfor.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WABSyncProvider.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\w32topl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\w32tm.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\vsstrace.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\vssapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\vssadmin.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\vss_ps.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\vpnikeapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\virtdisk.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\VIDRESZR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\vidcap.ax:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\vfwwdm32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\vfpodbc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\version.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\verifier.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\verifier.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\verclsid.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\VEN2232.OLB:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\vdsvd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\vdsdyn.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\vdsbas.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\vds_ps.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\vdmdbg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\vcomp100.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\vbscript.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\vbisurf.ax:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\VBICodec.ax:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\VBAME.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\vbajet32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\VBAEND32.OLB:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\VBAEN32.OLB:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\VBADE32.OLB:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\vaultcli.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Vault.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\VAN.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\uxtheme.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\uxlibres.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\uxlib.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\UXInit.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\uudf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Utilman.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\utildll.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\usp10.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\usk.rs:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\userinit.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\userenv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\usercpl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\UserAccountControlSettings.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\UserAccountControlSettings.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\user32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\user.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\usbui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\usbperf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\usbceip.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\urlmon.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\url.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ureg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\upnphost.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\upnpcont.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\upnp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\untfs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\unlodctr.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\uniplat.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\unimdmat.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\unimdm.tsp:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\umdmxfrm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ulib.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\UIRibbonRes.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\UIRibbon.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\uicom.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\UIAutomationCore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\UIAnimation.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ufat.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\uexfat.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\udhisapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ucmhc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ubpm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tzutil.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tzres.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\typeperf.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\typelib.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\txfw32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\txflog.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\twext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tvratings.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\TsWpfWrp.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\TSWorkspace.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\TSTheme.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tspkg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tsmf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tsgqec.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\TSChannel.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tsbyuv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tree.com:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\TRAPI.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\traffic.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\TRACERT.EXE:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tracerpt.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tquery.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\TpmInit.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tpmcompc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tpm.msc:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tlscsp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tintlgnt.ime:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\timeout.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\TimeDateMUICallback.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\timedate.cpl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ticrf.rat:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\thumbcache.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\themeui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\themecpl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\thawbrkr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\termmgr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\telephon.cpl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tdh.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tdc.ocx:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\TCPSVCS.EXE:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tcpmonui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tcpipcfg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tcpbidi.xml:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tcmsetup.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tbs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\TaskSchdPS.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\taskschd.msc:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\taskschd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\taskmgr.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tasklist.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\taskkill.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\taskeng.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\taskcomp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\TapiUnattend.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tapiui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\TapiSysprep.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tapisrv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tapiperf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\TapiMigPlugin.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tapi32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tapi3.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\takeown.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\t2embed.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\systray.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SystemPropertiesRemote.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SystemPropertiesProtection.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SystemPropertiesPerformance.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SystemPropertiesHardware.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SystemPropertiesDataExecutionPrevention.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SystemPropertiesComputerName.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SystemPropertiesAdvanced.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\systeminfo.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\systemcpl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\syssetup.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sysprtj.sep:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sysprint.sep:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sysmon.ocx:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\syskey.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sysdm.cpl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SynTPCOM.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\syncui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SynCtrl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Syncreg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SynCOM.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SyncInfrastructureps.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SyncInfrastructure.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SyncHostps.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SyncHost.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\synceng.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SyncCenter.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sxstrace.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sxsstore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sxshared.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sxs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sxproxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\svchost.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sud.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\subst.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SubRange.uce:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\StructuredQuery.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Storprop.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\StorageContextHandler.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\storage.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\stobject.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sti.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\stdole32.tlb:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\stdole2.tlb:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\stclient.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ssText3d.scr:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SSShim.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sspicli.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ssdpapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sscore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\srvcli.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\srhelper.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\srdelayed.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\srclient.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\srchadmin.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sqmapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sqlwoa.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sqlwid.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sqlunirl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sqlsrv32.rll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sqlsrv32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sqlcese30.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sqlceqp30.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sqlceoledb30.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\spwizres.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\spwizimg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\spwizeng.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\spwinsat.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sppwmi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sppinst.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sppcommdlg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sppcomapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sppcext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sppcc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sppc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\spp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\spopk.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\spnet.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SPInf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\spfileq.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\spbcd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SortWindows6Compat.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SortServer2003Compat.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sort.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\softpub.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\softkbd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\snmpapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SndVolSSO.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SndVol.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SMBHelperClass.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SmartcardCredentialProvider.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\slwga.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\slmgr.vbs:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\slcext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\slc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sisbkup.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\simpdata.tlb:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\signdrv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\shwebsvc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\shutdown.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\shunimpl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\shsvcs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\shsetup.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\shrpubw.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\shpafact.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\shlwapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\shimgvw.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\shimeng.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ShiftJIS.uce:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\shgina.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\shfolder.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\shellstyle.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\shell32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\shdocvw.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\shacct.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SFCOM.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sfc_os.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sfc.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sfc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\setx.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\setupugc.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\setupSNK.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\setupcln.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\setupapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\setup16.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SetIEInstalledDate.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sethc.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SessEnv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\serwvdrv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\services.msc:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\serialui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SensorsCpl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SensorsApi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SensApi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Sens.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sendmail.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\security.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\secur32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\secproc_ssp_isv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\secproc_ssp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\secproc_isv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\secproc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\secinit.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sechost.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SecEdit.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SearchProtocolHost.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SearchIndexer.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SearchFolder.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SearchFilterHost.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sdohlp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sdiagprv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sdiagnhost.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sdiageng.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sdchange.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sdbinst.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\scrrun.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\scrobj.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\scrnsave.scr:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\scripto.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SCP32.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\scksp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\schtasks.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\schedcli.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\schannel.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\scesrv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\scecli.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SCardDlg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\scansetting.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sc.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sberes.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sbeio.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sbe.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sas.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SampleRes.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\samlib.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\samcli.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\runonce.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\RunLegacyCPLElevated.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rundll32.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\runas.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rtutils.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rtm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rtffilt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\RstrtMgr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rshx32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rsaenh.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rrinstaller.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\RpcRtRemote.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rpcrt4.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\RpcPing.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rpcnsh.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\RpcNs4.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\RPCNDFP.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rpchttp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\RpcDiag.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ROUTE.EXE:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Robocopy.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rnr20.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rmoc3260.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\RmClient.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\RMActivate_ssp_isv.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\RMActivate_ssp.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\RMActivate_isv.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\RMActivate.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\riched32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\riched20.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Ribbons.scr:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rgb9rast.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\resutils.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\RestartManagerUninstall.mof:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\RestartManager.mof:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\resmon.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\RESAMPLEDMO.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\replace.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rendezvousSession.tlb:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\remotesp.tsp:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\remotepg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\relog.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rekeywiz.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\regsvr32.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\regini.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\regedt32.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\regedit.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\RegCtrl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\regapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\reg.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\recover.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ReAgentc.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ReAgent.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rdrleakdiag.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rdprefdrvapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rdpencom.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rdpd3d.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rdpcore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rastls.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rastapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rasser.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rasppp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rasplap.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rasphone.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rasmxs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rasmontr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\RASMM.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rasman.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rasgcw.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\raserver.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rasdlg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rasdial.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rasdiag.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rasctrs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rasctrnm.h:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\raschap.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rascfg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rasautou.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rasapi32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rasadhlp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\radarrs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\radardt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\RacRules.xml:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\racpldlg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\RacEngn.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\qwave.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\QUTIL.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\quick.ime:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Query.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\quartz.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\QSVRMGMT.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\QSHVHOST.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\qmgrprxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\qintlgnt.ime:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\qedwipes.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\qedit.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\qdvd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\qdv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\QCLIPROV.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\qcap.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\qasf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\QAGENT.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pwrshplugin.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\puiobj.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\puiapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pstorsvc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pstorec.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\psr.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\psisrndr.ax:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\psisdecd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PSHED.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pscript.sep:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\psbase.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\psapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\provthrd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\provsvc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\proquota.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\propsys.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\profapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\prntvpt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\prnntfy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\prnfldr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\prncache.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\printui.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\printui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\print.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\prflbmsg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\prevhost.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PresentationNative_v0300.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PresentationHostProxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PresentationHost.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\powrprof.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\powercpl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\powercfg.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\powercfg.cpl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pots.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PortableDeviceWMDRM.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PortableDeviceWiaCompat.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PortableDeviceTypes.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PortableDeviceSyncProvider.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PortableDeviceStatus.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PortableDeviceConnectApi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PortableDeviceClassExtension.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PortableDeviceApi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\poqexec.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\polstore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pnrpnsp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pnpsetup.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pnidui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pngfilt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pndx5032.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pndx5016.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pncrt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PlaySndSrv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pla.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pku2u.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PkgMgr.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pintlgnt.ime:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PING.EXE:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pifmgr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pidgenx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pid.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PhysXLoader.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PhysX.cpl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\photowiz.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PhotoScreensaver.scr:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PhotoMetadataHandler.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\phon.ime:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\perfts.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PerfStringBackup.INI:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\perfproc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\perfos.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\perfnet.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\perfmon.msc:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\perfmon.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\perfhost.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\perfdisk.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\perfctrs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PerfCenterCpl.ico:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PerfCenterCPL.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pegi-pt.rs:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pegi-fi.rs:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pegibbfc.rs:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pegi.rs:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pdhui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pdh.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pcwum.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pcl.sep:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pcaui.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pcaui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pautoenr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PATHPING.EXE:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\panmap.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\packager.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\p2pnetsh.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\P2PGraph.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\p2pcollab.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\P2P.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\osuninst.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\osk.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\osbaseln.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\OptionalFeatures.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\opengl32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\openfiles.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\OpenCL.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\OpcServices.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\OobeFldr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\OnLineIDCpl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\onexui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\onex.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\olethk32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\olesvr32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\oleres.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\olepro32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\oleprn.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\oledlg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\olecli32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\oleaut32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\oleaccrc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\oleacchooks.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\oleacc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ole32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ole2nls.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ole2disp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ole2.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ogldrv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\oflc.rs:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\offfilt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\odtext32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\odpdx32.dll:coranti


holzdan 07.10.2012 10:52

otl.txt part 3

Code:

@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\odfox32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\odexl32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\oddbse32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\odbctrac.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\odbcjt32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\odbcji32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\odbcint.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\odbccu32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\odbccr32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\odbccp32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\odbcconf.rsp:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\odbcconf.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\odbcconf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\odbcbcp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\odbcad32.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\odbc32gt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\odbc32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ocsetup.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ocsetapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\occache.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\objsel.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ntvdm64.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ntshrui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ntprint.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ntprint.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ntoskrnl.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ntmarta.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ntlanui2.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ntlanman.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ntkrnlpa.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ntdsapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ntdll.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\nslookup.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\nsi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\nshwfp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\nshipsec.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\nshhttp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\npmproxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\notepad.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\normaliz.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NOISE.THA:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\noise.kor:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\noise.jpn:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NOISE.DAT:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NOISE.CHT:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NOISE.CHS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsModels0011.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0c1a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons081a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0816.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0416.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0414.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons004e.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons004c.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons004b.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons004a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0049.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0047.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0046.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0045.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons003e.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0039.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons002a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0027.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0026.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0024.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0022.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0021.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0020.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons001d.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons001b.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons001a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0019.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0018.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0013.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0011.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0010.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons000f.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons000d.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons000c.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons000a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0009.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0007.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0003.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0002.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0001.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Nlsdl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0c1a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData081a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0816.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0416.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0414.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData004e.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData004c.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData004b.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData004a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0049.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0047.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0046.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0045.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData003e.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0039.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData002a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0027.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0026.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0024.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0022.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0021.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0020.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData001d.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData001b.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData001a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0019.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0018.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0013.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0011.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0010.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData000f.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData000d.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData000c.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData000a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0009.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0007.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0003.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0002.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0001.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0000.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\nlsbres.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\nlmsprep.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\nlmgp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\nlhtml.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\nlaapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\newdev.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\newdev.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\networkmap.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\networkitemfactory.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\networkexplorer.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netutils.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NETSTAT.EXE:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netshell.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netsh.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netprofm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netprof.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Netplwiz.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netplwiz.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netmsg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netlogon.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netjoin.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netiougc.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netiohlp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netid.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\neth.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netfxperf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netevent.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netdiagfx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netcorehc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netcfgx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netcenter.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netbtugc.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netbios.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netapi32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\net1.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\net.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\negoexts.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ndptsp.tsp:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ndproxystub.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ndishc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ndiscapCfg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ndfhcdiscovery.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NdfEventView.xml:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ndfetw.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ndfapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\nddeapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ndadmin.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ncsi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ncryptui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ncrypt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ncpa.cpl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ncobjapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\nci.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NcdProp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NaturalLanguage6.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NativeHooks.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NAPSTAT.EXE:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NAPMONTR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\napipsec.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NapiNSP.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NAPHLPR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\napdsnap.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NAPCRYPT.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NAPCLCFG.MSC:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Mystify.scr:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mydocs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mycomput.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MuiUnattend.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\muifontsetup.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mtxoci.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mtxlegih.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mtxex.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mtxdm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mtxclu.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mtstocom.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msyuv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msxml6r.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msxml6.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msxml4r.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msxml4a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msxml3r.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msxml3.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msxbde40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mswstr10.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mswsock.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mswmdm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mswdat10.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MSVidCtl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msvidc32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msvfw32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msvcrt40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msvcrt20.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msvcrt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msvcr70.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msvcr100_clr0400.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msvcr100.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msvcp60.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msvcp100.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msvcirt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msvbvm60.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msv1_0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msutb.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mstscax.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mstsc.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mstext40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mstask.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msswch.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mssvp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MSSTDFMT.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mssrch.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mssprxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mssphtb.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mssph.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mssitlb.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mssip32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mssign32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msshooks.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msshavmsg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mssha.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msscript.ocx:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msscp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msscntrs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msrle32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msrepl40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MsRdpWebAccess.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msrdc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msrd3x40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msrd2x40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msrating.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MsraLegacy.tlb:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msra.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msports.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mspbde40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mspatcha.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mspaint.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msorcl32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msorc32r.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msoert2.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msoeacct.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msobjs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MSNP.ax:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msnetobj.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msmpeg2vdec.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MSMPEG2ENC.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msmpeg2adec.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msltus40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msls31.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msjtes40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msjter40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msjint40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msjetoledb40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msjet40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msisip.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msinfo32.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msimtf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msimsg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msimg32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msiltcfg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msihnd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msiexec.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msieftp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msidntld.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msidle.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msident.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msidcrl30.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mshtmler.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mshtmled.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mshtml.tlb:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mshtml.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mshta.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msgsm32.acm:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msg711.acm:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msftedit.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msfeedssync.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msfeedsbs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msfeeds.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msexcl40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msexch40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MSDvbNP.ax:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msdtcVSp1res.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msdtcuiu.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msdtcprx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msdt.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msdrm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msdmo.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msdelta.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msdatsrc.tlb:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msdart.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msdadiag.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msctfui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msctfp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MsCtfMonitor.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msctfime.ime:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msctf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mscpxl32.dLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mscpx32r.dLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mscories.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mscorier.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mscoree.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MSCOMCTL.OCX:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mscms.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msclmd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mscat32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mscandui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msaudite.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msasn1.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msafd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msadp32.acm:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msacm32.drv:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msacm32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MSAC3ENC.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msaatext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MRINFO.EXE:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mprmsg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mprdim.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mprddm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mprapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mpr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MPG4DECD.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mpg2splt.ax:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Mpeg2Data.ax:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MP4SDECD.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MP43DECD.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MP3DMOD.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mountvol.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\moricons.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\more.com:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\modemui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mode.com:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mobsync.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mmsys.cpl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mmres.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MMDevAPI.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mmcshext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mmcndmgr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mmcico.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mmci.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mmcbase.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mmc.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mlang.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mlang.dat:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mimefilt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\miguiresource.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\migisol.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MigAutoPlay.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\midimap.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mgmtapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MFWMAAEC.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfvdsp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfreadwrite.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfps.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfpmp.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MFPlay.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfplat.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfmjpegdec.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfh264enc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mferror.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfdvdec.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfds.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfcsubs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfcm100u.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfcm100.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfc42u.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfc42.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfc40u.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfc40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfc100u.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfc100rus.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfc100kor.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfc100jpn.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfc100ita.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfc100fra.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfc100esn.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfc100enu.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfc100deu.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfc100cht.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfc100chs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfc100.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfAACEnc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mf3216.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mdminst.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mctres.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mciwave.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mciseq.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mciqtz32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mcicda.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mciavi32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MCEWMDRMNDBootstrap.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mcbuilder.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mapisvc.inf:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mapistub.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mapi32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\makecab.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\main.cpl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Magnify.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Magnification.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\lz32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\lusrmgr.msc:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\luainstall.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\lsmproxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\lpk.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\logoncli.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\logman.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\loghours.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\logagent.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\lodctr.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\locationnotificationsview.xml:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\LocationNotifications.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\LocationApi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\localsec.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\locale.nls:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\loadperf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\linkinfo.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\licmgr10.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\license.rtf:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\lcptr.tbl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\lcphrase.tbl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\LAPRXY.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\label.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\l3codecp.acm:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\l3codeca.acm:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\L2SecHC.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\l2nacp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\l2gpstore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\l_intl.nls:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ktmw32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ktmutil.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ksxbar.ax:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Kswdmcap.ax:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ksuser.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kstvtune.ax:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ksproxy.ax:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\korwbrkr.lex:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\korwbrkr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\korean.uce:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kmddsp.tsp:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\keymgr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\keyiso.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KernelBase.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kernel32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kerberos.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kdbsdk32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDYCL.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDYCC.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDYBA.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDYAK.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDWOL.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDVNTC.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDUZB.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDUSX.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDUSR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDUSL.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDUSA.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDUS.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDURDU.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDUR1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDUR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDUKX.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDUK.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDUGHR1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDUGHR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDTURME.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDTUQ.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDTUF.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDTIPRC.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDTH3.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDTH2.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDTH1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDTH0.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDTAT.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDTAJIK.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDSYR2.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDSYR1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDSW09.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDSW.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDSP.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDSORST.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDSORS1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDSOREX.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDSN1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDSMSNO.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDSMSFI.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDSL1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDSL.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDSG.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDSF.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDRU1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDRU.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDROST.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDROPR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDRO.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDPO.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDPL1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDPL.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDPASH.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDNSO.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDNO1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDNO.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDNEPR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kbdnecnt.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kbdnecat.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kbdnec95.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kbdnec.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDNE.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDMONMO.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDMON.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDMLT48.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDMLT47.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDMAORI.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDMACST.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDMAC.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDLV1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDLV.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDLT2.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDLT1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDLT.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kbdlk41a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDLAO.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDLA.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDKYR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDKOR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDKHMR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDKAZ.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDJPN.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDIULAT.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDIT142.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDIT.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDIR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDINUK2.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDINTEL.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDINTAM.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDINPUN.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDINORI.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDINMAR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDINMAL.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDINKAN.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDINHIN.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDINGUJ.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDINDEV.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDINBEN.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDINBE2.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDINBE1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDINASA.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDIC.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDIBO.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kbdibm02.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDHU1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDHU.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDHEPT.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDHELA3.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDHELA2.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDHEB.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDHE319.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDHE220.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDHE.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDHAU.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDGRLND.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDGR1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDGR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDGKL.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kbdgeoqw.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kbdgeoer.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDGEO.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDGAE.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDFR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDFO.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDFI1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDFI.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDFC.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDFA.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDEST.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDES.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDDV.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDDIV2.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDDIV1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDDA.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDCZ2.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDCZ1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDCZ.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDCR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDCAN.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDCA.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDBULG.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDBU.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDBR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDBLR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDBHC.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDBGPH1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDBGPH.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDBENE.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDBE.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDBASH.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDAZEL.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDAZE.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kbdax2.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDARMW.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDARME.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDAL.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDA3.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDA2.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDA1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kbd106n.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kbd106.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kbd103.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kbd101c.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kbd101b.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kbd101a.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kbd101.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kanji_2.uce:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kanji_1.uce:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\jsproxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\jscript9.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\jscript.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\joy.cpl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iyuv_32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ivfsrc.ax:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\itss.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\itircl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\isoburn.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iscsiwmi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iscsium.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iscsied.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iscsidsc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iscsicpl.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iscsicpl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iscsicli.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\irprops.cpl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\irclass.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ir50_qcx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ir50_qc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ir50_32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ir41_qcx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ir41_qc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ir41_32.ax:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ir32_32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ipsmsnap.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ipsecsnp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iprtrmgr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iprtprio.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iprop.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\IPHLPAPI.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ipconfig.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\IPBusEnumProxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iologmsg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\intl.cpl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\instnm.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\inseng.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\input.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\InkEd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\infocardcpl.cpl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\infocardapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\InfDefaultInstall.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\INETRES.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\inetmib1.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\inetcpl.cpl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\inetcomm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\imm32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\imkr80.ime:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\IMJP10K.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\IMJP10.IME:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\imgutil.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\imapi2fs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\imapi2.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\imapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\imagesp1.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\imageres.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\imagehlp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\imaadp32.acm:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\igkrng500.bin:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\igfcg500m.bin:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\igfcg500.bin:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\igdumd32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\igd10umd32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\igcompkrng500.bin:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ifsutilx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ifsutil.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ifmon.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iexpress.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ieUnatt.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ieuinit.inf:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ieui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iesysprep.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iesetup.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iertutil.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iernonce.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iepeers.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ieframe.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iedkcs32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ieapfltr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ieapfltr.dat:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ieakui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ieaksie.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ieakeng.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\IEAdvpack.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ie4uinit.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\IDStore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\idndl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ideograf.uce:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\icsunattend.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\icsigd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\icrav03.rat:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\IconCodecService.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\icmui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\icmp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\icm32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iccvid.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\icardres.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\icardie.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\icardagt.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\icacls.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iassvcs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iassdo.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iassam.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iasrecst.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iasrad.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iaspolcy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iasnap.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\IasMigPlugin.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iashlpr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iasdatastore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iasads.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iasacct.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ias.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iac25_32.ax:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\htui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\httpapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\html.iec:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\HOSTNAME.EXE:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\hnetmon.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\hnetcfg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\hlp95en.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\hlink.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\hidserv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\hidphone.tsp:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\hid.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\hhsetup.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\hhctrl.ocx:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\hh.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\hgcpl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\HelpPaneProxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\help.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\hdwwiz.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\hdwwiz.cpl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\hcproviders.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\hbaapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\grpconv.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\grb.rs:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\gpupdate.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\gptext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\gpresult.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\gpprnext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\gpedit.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\gpapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\glu32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\glmf32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\getuname.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\getmac.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\gdi32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\gcdef.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\gb2312.uce:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\GameUXLegacyGDFs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\gameux.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\g711codc.ax:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\FXSXP32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\FXSRESM.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\FXSEXT32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\FXSCOMEX.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\FXSCOM.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\FXSAPI.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\FwRemoteSvr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\FWPUCLNT.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fwcfg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fundisc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ftp.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fthsvc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fsutil.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fsmgmt.msc:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\framedynos.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\framedyn.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fphc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\format.com:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\forfiles.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fontview.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fontsub.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fontext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fms.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fmifs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\FM20ENU.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\FM20DEU.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\FM20.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fltMC.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fltLib.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\FlashPlayerCPLApp.cpl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\FlashPlayerApp.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fixmapi.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\FirewallControlPanel.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\FirewallAPI.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Firewall.cpl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\finger.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\findstr.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\findnetprinters.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\find.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\filemgmt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\feclient.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fdWSD.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fdWNet.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fdWCN.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fdSSDP.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fdProxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fdPnp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fdeploy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fde.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fdBthProxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fdBth.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fc.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Faultrep.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\f3ahvoas.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\extrac32.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\expsrv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ExplorerFrame.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\explorer.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\expand.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\evr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\eventvwr.msc:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\eventvwr.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\EventViewer_EventDetails.xsl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\eventcreate.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\eventcls.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\eudcedit.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\esrb.rs:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\esentutl.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\esentprf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\esent.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\es.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\eqossnap.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\EncDec.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\encapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\elsTrans.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\elslad.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ELSCore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\els.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\EhStorShell.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\EhStorPwdMgr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\EhStorAuthn.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\EhStorAPI.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\efsutil.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\efsui.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\efscore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\efsadu.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\EAPQEC.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\eappprxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\eapphost.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\eappgnui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\eappcfg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\eapp3hst.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dxva2.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dxtrans.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dxtmsft.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DxpTaskSync.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DXPTaskRingtone.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dxgi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dxdiagn.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dxdiag.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DWWIN.EXE:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DWrite.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dwmcore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dwmapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dvdupgrd.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dvdplay.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\duser.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dui70.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dtsh.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dswave.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dsuiext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dssenh.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dssec.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dssec.dat:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dsrole.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dsquery.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dsprop.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dsound.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dskquoui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dskquota.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DShowRdpFilter.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dsdmo.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dsauth.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ds32gt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\drvstore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\drvinst.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\drttransport.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\drtprov.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\drt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\drprov.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\drmv2clt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\drmmgrtn.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\drivers\wimmount.sys:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\drivers\gmreadme.txt:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\drivers\gm.dls:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\drivers\DKbFltr.sys:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\driverquery.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dpx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dpwsockx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dpnsvr.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dpnlobby.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dpnhupnp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dpnhpast.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dpnet.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dpnathlp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dpnaddr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dpmodemx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dplayx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dplaysvr.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DpiScaling.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dpapiprovider.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dpapimig.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dot3ui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dot3msm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dot3hc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dot3gpui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dot3gpclnt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dot3dlg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dot3cfg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dot3api.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\doskey.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\docprop.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dnscmmc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dnscacheugc.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dnsapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dmview.ocx:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dmvdsitf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dmutil.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dmusic.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dmsynth.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dmstyle.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dmscript.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dmrc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dmocx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dmloader.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dmintf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dmime.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dmdskres2.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dmdskres.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dmdskmgr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dmdlgs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dmcompos.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dmband.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dllhst3g.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dllhost.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DisplaySwitch.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Display.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dispex.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Dism.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\diskraid.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\diskperf.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\diskpart.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\diskmgmt.msc:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\diskcopy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\diskcopy.com:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\diskcomp.com:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dinput8.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dinput.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dimsroam.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dimsjob.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\difxapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\diantz.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dialer.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dhcpsapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DHCPQEC.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dhcpcsvc6.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dhcpcsvc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dhcpcore6.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dhcpcore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dhcpcmonitor.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DfsShlEx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dfshim.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dfscli.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dfrgui.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\devrtl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\devobj.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\devmgr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\devmgmt.msc:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DeviceUxRes.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DeviceProperties.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DevicePairingWizard.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DevicePairingProxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DevicePairingHandler.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DevicePairingFolder.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DevicePairing.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DeviceMetadataParsers.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DeviceDisplayStatusManager.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DeviceCenter.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\devenum.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\deskperf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\deskmon.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\deskadp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\desk.cpl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\defaultlocationcpl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ddrawex.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ddraw.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DDORes.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DDOIProxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ddodiag.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DDACLSys.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dcomcnfg.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dciman32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dccw.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dbnmpntw.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dbnetlib.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dbghelp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dbgeng.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\davhlpr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\davclnt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dataclen.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\d3dxof.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\d3dx9_32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\d3dx9_27.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\d3dramp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\d3dim700.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\d3dim.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\d3d9.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\d3d8thk.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\d3d8.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\d3d11.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\d3d10warp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\d3d10level9.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\d3d10core.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\d3d10_1core.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\d3d10_1.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\d3d10.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\d2d1.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cttunesvr.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cttune.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ctl3d32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ctfmon.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\CSVer.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\csrr.rs:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cscript.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cscdll.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cscapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cryptxml.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cryptui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cryptsvc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cryptsp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cryptnet.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cryptext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cryptdll.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cryptdlg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cryptbase.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\crypt32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\crtdll.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\credwiz.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\credui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\credssp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\CPFilters.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\convert.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\control.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\console.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\connect.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\comuid.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\comsvcs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\comsnap.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\comres.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\comrepl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ComputerDefaults.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\compstui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\compobj.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\compmgmt.msc:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\compact.exe:coranti


holzdan 07.10.2012 10:53

otl.txt part 4

Code:

@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\comp.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\comexp.msc:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\comdlg32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\comctl32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\comcat.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\colorui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\colorcpl.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\COLORCNV.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\colbact.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cnvfat.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cngprovider.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cngaudit.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cmutil.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cmstplua.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cmstp.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cmpbk32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cmmon32.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cmlua.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cmipnpinstall.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cmifw.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cmicryptinstall.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cmdl32.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cmdkey.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cmdial32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cmd.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cmcfg32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\clusapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\clip.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cliconfg.rll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cliconfg.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cliconfg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\clfsw32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cleanmgr.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\clbcatq.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\clb.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cipher.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cintlgnt.ime:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cic.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\CHxReadingStringIME.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\chtbrkr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\chsbrkr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\choice.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\chkntfs.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\chkdsk.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\chcp.com:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\charmap.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\chajei.ime:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cfgmgr32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cfgbkend.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cewmdm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\certutil.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\certreq.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\CertPolEng.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\certmgr.msc:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\certmgr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\CertEnrollUI.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\CertEnrollCtrl.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\CertEnroll.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\certenc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\certCredProvider.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\certcli.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cero.rs:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cdosys.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\CCCInstall_201203111630271511.log:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cca.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\catsrvut.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\catsrvps.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\catsrv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\capisp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\capiprovider.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\capicom.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\calc.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cacls.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cabview.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cabinet.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_ISCII.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_IS2022.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_G18030.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_950.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_949.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_936.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_932.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_875.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_874.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_870.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_869.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_866.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_865.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_864.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_863.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_862.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_861.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_860.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_858.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_857.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_855.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_852.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_850.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_775.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_737.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_720.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_708.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_500.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_437.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_28605.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\c_28603.nls:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_28599.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_28598.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_28597.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_28596.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_28595.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_28594.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_28593.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_28592.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_28591.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_21866.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_21027.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_21025.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20949.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20936.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20932.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20924.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20905.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20880.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20871.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20866.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20838.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20833.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20424.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20423.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20420.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20297.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20290.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20285.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20284.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20280.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20278.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20277.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20273.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20269.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20261.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20127.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20108.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20107.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20106.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20105.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20005.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20004.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20003.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20002.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20001.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20000.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1361.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1258.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1257.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1256.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1255.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1254.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1253.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1252.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1251.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1250.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1149.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1148.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1147.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1146.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1145.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1144.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1143.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1142.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1141.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1140.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1047.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1026.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_10082.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_10081.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_10079.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_10029.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_10021.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_10017.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_10010.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_10008.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_10007.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_10006.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_10005.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_10004.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_10003.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_10002.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_10001.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_10000.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_037.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\BWUnpairElevated.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\BWContextHandler.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Bubbles.scr:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\btpanui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\bthudtask.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\bthprops.cpl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\browseui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\browcli.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\bopomofo.uce:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\BOOTVID.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\bootcfg.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\boot.sdi:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\blackbox.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\bitsprx6.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\bitsprx5.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\bitsprx4.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\bitsprx3.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\bitsprx2.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\bitsperf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\bitsadmin.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\BioCredProv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\bidispl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\bdaplgin.ax:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\bcryptprimitives.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\bcrypt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\batmeter.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\basecsp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AzSqlExt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\azroleui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\azroles.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\azman.msc:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\avrt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\avifil32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\avicap32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AuxiliaryDisplayCpl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AuxiliaryDisplayApi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\autoplay.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\autofmt.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\autoconv.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\autochk.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\authz.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\authui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AuthFWWizFwk.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AuthFWSnapin.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AuthFWGP.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\authfwcfg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\auditpol.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AudioSes.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AUDIOKSE.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AudioEng.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\audiodev.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\attrib.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\atmlib.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\atmfd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\atl100.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\atl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ativvsvl.dat:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ativvsva.dat:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\atiumdmv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\atipdlxx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\atipblag.dat:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AtBroker.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\at.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\asycfilt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\asferror.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ARP.EXE:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\apss.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\appwiz.cpl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\appidapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Apphlpdm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\apphelp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\apisetschema.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\apircl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-service-winsvc-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-service-management-l2-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-service-management-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-service-core-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-security-sddl-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-security-lsalookup-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\apilogen.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\apds.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\amxread.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\amstream.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AltTab.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AgCPanelTraditionalChinese.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AgCPanelSwedish.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AgCPanelSpanish.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AgCPanelSimplifiedChinese.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AgCPanelPortugese.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AgCPanelKorean.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AgCPanelJapanese.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AgCPanelGerman.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AgCPanelFrench.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\aeevts.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\aecache.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\advpack.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\advapi32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\adtschema.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\adsnt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\adsmsext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\adsldpc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\adsldp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\adprovider.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\admparse.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AdapterTroubleshooter.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\actxprxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\activeds.tlb:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\activeds.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ActionCenterCPL.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ActionCenter.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\acppage.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\aclui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\acledit.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ACCTRES.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\accessibilitycpl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\aaclient.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\12520850.cpx:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\12520437.cpx:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system.ini:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysNative\drivers\etc\services:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysNative\drivers\etc\protocol:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysNative\drivers\etc\networks:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysNative\drivers\etc\lmhosts.sam:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysNative\drivers\etc\hosts.20121006-162602.backup:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\Suyin.reg:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\Starter.xml:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\splwow64.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\RtlExUpd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\regedit.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\Prelaunch.ini:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\PLFSetI.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\PLaunch.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\PidList.ini:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\PatchFul.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\ParseModule_X86.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\ParseModule_X64.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\ODBC.INI:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\notepad.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\NewDeployWinRE.cmd:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\msdfmap.ini:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\MOD01SET75000N0006.enc:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\MOD01SET74DE0N0003.XML:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\MOD01SET74DE0N0003.enc:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\mib.bin:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\LManager.UNI:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\LaunApp.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\Image.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\HomePremium.xml:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\HomeBasic.xml:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\hh.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\HelpPane.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\GVUni.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\GridV.UNI:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\fveupdate.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\Fonts\GlobalUserInterface.CompositeFont:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\Fonts\GlobalSerif.CompositeFont:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\Fonts\GlobalSansSerif.CompositeFont:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\Fonts\GlobalMonospace.CompositeFont:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\Factory.xml:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\explorer.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\epplauncher.mif:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\EB6BE8A5-11AE-4e2b-8B6E-974168C301C8.DSI:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\CSUP.txt:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\ChangeLang_Done.tag:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\Capsule.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\bootstat.dat:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\bfsvc.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\agrsmdel.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\agrdel64.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\Acer Crystal Eye webcam.ico:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\Acer Crystal Eye webcam.EXE:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\0:coranti
@Alternate Data Stream - 52 bytes -> C:\vcredist.bmp:coranti
@Alternate Data Stream - 52 bytes -> C:\VC_RED.MSI:coranti
@Alternate Data Stream - 52 bytes -> C:\VC_RED.cab:coranti
@Alternate Data Stream - 52 bytes -> C:\Users\Public\Documents\NTILiveUpdate.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Users\Public\Documents\NTIBUN5.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Users\Public\Documents\desktop.ini:coranti
@Alternate Data Stream - 52 bytes -> C:\Users\aaa\SecurityKISSTunnel.config:coranti
@Alternate Data Stream - 52 bytes -> C:\Users\aaa\ntuser.ini:coranti
@Alternate Data Stream - 52 bytes -> C:\Users\aaa\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms:coranti
@Alternate Data Stream - 52 bytes -> C:\Users\aaa\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms:coranti
@Alternate Data Stream - 52 bytes -> C:\Users\aaa\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf:coranti
@Alternate Data Stream - 52 bytes -> C:\Users\aaa\Documents\desktop.ini:coranti
@Alternate Data Stream - 52 bytes -> C:\Users\aaa\Desktop\END Strom.PDF:coranti
@Alternate Data Stream - 52 bytes -> C:\Users\aaa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini:coranti
@Alternate Data Stream - 52 bytes -> C:\Users\aaa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini:coranti
@Alternate Data Stream - 52 bytes -> C:\Users\aaa\AppData\Local\GDIPFONTCACHEV1.DAT:coranti
@Alternate Data Stream - 52 bytes -> C:\Users\aaa\AppData\Local\fusioncache.dat:coranti
@Alternate Data Stream - 52 bytes -> C:\user.js:coranti
@Alternate Data Stream - 52 bytes -> C:\RHDSetup.log:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\PS.log:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Works-Start.lnk:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Word Viewer 2003.lnk:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office PowerPoint Viewer 2007.lnk:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader.lnk:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Update.lnk:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Deinstallationsprogramm.lnk:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn.lnk:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\foobar2000.lnk:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat.com.lnk:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\FullRemove.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\ArcadeDeluxe3.log:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\1331426446.4376.bin:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\1331426446.3724.bin:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\1331426446.3708.bin:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\1331426446.2708.bin:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\1331420176.bdinstall.bin:coranti
@Alternate Data Stream - 52 bytes -> C:\Program Files\desktop.ini:coranti
@Alternate Data Stream - 52 bytes -> C:\Program Files (x86)\Steam\Steam.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Program Files (x86)\FreeAlarmClock\FreeAlarmClock.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Program Files (x86)\desktop.ini:coranti
@Alternate Data Stream - 52 bytes -> C:\Program Files (x86)\Common Files\Acer GameZone online.ico:coranti
@Alternate Data Stream - 52 bytes -> C:\Preload.rev:coranti
@Alternate Data Stream - 52 bytes -> C:\Patch.rev:coranti
@Alternate Data Stream - 52 bytes -> C:\mcdbp.log:coranti
@Alternate Data Stream - 52 bytes -> C:\install.res.3082.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\install.res.2052.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\install.res.1049.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\install.res.1042.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\install.res.1041.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\install.res.1040.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\install.res.1036.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\install.res.1033.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\install.res.1031.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\install.res.1028.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\install.ini:coranti
@Alternate Data Stream - 52 bytes -> C:\install.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\globdata.ini:coranti
@Alternate Data Stream - 52 bytes -> C:\eula.3082.txt:coranti
@Alternate Data Stream - 52 bytes -> C:\eula.2052.txt:coranti
@Alternate Data Stream - 52 bytes -> C:\eula.1049.txt:coranti
@Alternate Data Stream - 52 bytes -> C:\eula.1042.txt:coranti
@Alternate Data Stream - 52 bytes -> C:\eula.1041.txt:coranti
@Alternate Data Stream - 52 bytes -> C:\eula.1040.txt:coranti
@Alternate Data Stream - 52 bytes -> C:\eula.1036.txt:coranti
@Alternate Data Stream - 52 bytes -> C:\eula.1033.txt:coranti
@Alternate Data Stream - 52 bytes -> C:\eula.1031.txt:coranti
@Alternate Data Stream - 52 bytes -> C:\eula.1028.txt:coranti
@Alternate Data Stream - 52 bytes -> C:\BOOTSECT.BAK:coranti
@Alternate Data Stream - 52 bytes -> C:\bootmgr:coranti
@Alternate Data Stream - 52 bytes -> C:\bdlog.txt:coranti
@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:430C6D84
@Alternate Data Stream - 115 bytes -> C:\ProgramData\Temp:F297470E
@Alternate Data Stream - 105 bytes -> C:\ProgramData\Temp:DFC5A2B2

< End of report >

koennte vielleicht jemand bitte einen Blick drueber werfen wenn es sich ausgeht

cosinus 07.10.2012 18:57

Zitat:

Habe die Logs der Virenscans leider nicht gespeichert.
Malwarebytes speichert alle Logs im Reiter Logdateien

holzdan 07.10.2012 21:02

Code:

Malwarebytes Anti-Malware 1.65.0.1400
www.malwarebytes.org

Datenbank Version: v2012.10.04.09

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
aaa :: AAA-PC [Administrator]

07.10.2012 11:37:07
mbam-log-2012-10-07 (11-37-07).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 345652
Laufzeit: 35 Minute(n), 48 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)


cosinus 07.10.2012 21:11

Sind das alle Logs von Malwarebytes?

holzdan 07.10.2012 21:19

Es sind mehrere aber alle mit dem selben inhalt

cosinus 07.10.2012 21:26

Verschiedene Logs mit demselben Inhalt? :pfeiff: :lach:
Wie auch immer: es wurde nichts und niemals was gefunden?

holzdan 07.10.2012 21:29

mit malwarebytes nicht.
klar hatte ich mal irgendwann was drauf aber das ist schon lange her und kann mich nicht mehr an di malware erinnern , auch nicht welches av ich damals benutzte... ich wechsele staendig av programme und probier wieder andere aus. Habe Malwarebytes uebrigens erst vor einigen Tagen installiert

cosinus 07.10.2012 21:42

Zitat:

klar hatte ich mal irgendwann was drauf
Bitte nicht zu genau posten, wir könnte sonst wissen was gefunden wurde

holzdan 08.10.2012 11:34

habe windows nun bereits um die 2 Jahre installiert und noch nie formatiert...
daher kann ich mich nicht mehr genau erinnern was damals gefunden wurde , ich erinnere mich nur noch daran dass mal etwas gefunden wurde aber das ist ja eher die Regel als die Ausnahme...

cosinus 08.10.2012 13:13

Weiß du denn welcher Scanner was gefunden hat? Wenn ja ist vllt noch das Log da?

holzdan 08.10.2012 17:54

nein kann mich wirklich nicht mehr daran erinnern.
Habe auch die Verzeichnisse nach eventuellen Logs untersucht.
Leider nix zu finden , sorry

cosinus 08.10.2012 19:30

adwCleaner - Toolbars und ungewollte Start-/Suchseiten aufspüren

Downloade Dir bitte AdwCleaner auf deinen Desktop.

Falls der adwCleaner schon mal in der runtergeladen wurde, bitte die alte adwcleaner.exe löschen und neu runterladen!!
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Suche.
  • Nach Ende des Suchlaufs öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[Rx].txt. (x=fortlaufende Nummer)

holzdan 08.10.2012 21:51

Code:

# AdwCleaner v2.004 - Datei am 08/10/2012 um 22:48:27 erstellt
# Aktualisiert am 06/10/2012 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzer : aaa - AAA-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\aaa\AppData\Local\Opera\Opera\temporary_downloads\adwcleaner.exe
# Option [Suche]


**** [Dienste] ****


***** [Dateien / Ordner] *****

Datei Gefunden : C:\user.js
Ordner Gefunden : C:\ProgramData\Partner
Ordner Gefunden : C:\Users\aaa\AppData\LocalLow\BabylonToolbar
Ordner Gefunden : C:\Users\aaa\AppData\Roaming\OpenCandy

***** [Registrierungsdatenbank] *****

Schlüssel Gefunden : HKCU\Software\IGearSettings
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{98889811-442D-49DD-99D7-DC866BE87DBC}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredibar.com
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredibar.com
Schlüssel Gefunden : HKCU\Software\Softonic
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{35C1605E-438B-4D64-AAB1-8885F097A9B1}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredibar.com
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredibar.com
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEE6C367-6118-11DC-9C72-001320C79847}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Schlüssel Gefunden : HKU\S-1-5-21-1121988522-4199441151-2918872926-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Schlüssel Gefunden : HKU\S-1-5-21-1121988522-4199441151-2918872926-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gefunden : HKU\S-1-5-21-1121988522-4199441151-2918872926-1000\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}

***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16421

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main - Start Page] = hxxp://home.sweetim.com/?crg=3.1010000.10002&barid={27A42084-C696-11E1-ACC2-0017C4F1B1FE}

-\\ Google Chrome v [Version kann nicht ermittelt werden]

Datei : C:\Users\aaa\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Die Datei ist sauber.

-\\ Opera v12.2.1578.0

Datei : C:\Users\aaa\AppData\Roaming\Opera\Opera\operaprefs.ini

[OK] Die Datei ist sauber.

*************************

AdwCleaner[R1].txt - [4677 octets] - [08/10/2012 22:48:27]

########## EOF - C:\AdwCleaner[R1].txt - [4737 octets] ##########


cosinus 09.10.2012 12:05

adwCleaner - Toolbars und ungewollte Start-/Suchseiten entfernen
  • Schließe alle offenen Programme und Browser.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Löschen.
  • Bestätige jeweils mit Ok.
  • Dein Rechner wird neu gestartet. Nach dem Neustart öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[Sx].txt. (x=fortlaufende Nummer)

holzdan 09.10.2012 12:56

Code:

# AdwCleaner v2.004 - Datei am 09/10/2012 um 13:52:34 erstellt
# Aktualisiert am 06/10/2012 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzer : aaa - AAA-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\aaa\AppData\Local\Opera\Opera\temporary_downloads\adwcleaner.exe
# Option [Löschen]


**** [Dienste] ****


***** [Dateien / Ordner] *****

Datei Gelöscht : C:\user.js
Ordner Gelöscht : C:\ProgramData\Partner
Ordner Gelöscht : C:\Users\aaa\AppData\LocalLow\BabylonToolbar
Ordner Gelöscht : C:\Users\aaa\AppData\Roaming\OpenCandy

***** [Registrierungsdatenbank] *****

Schlüssel Gelöscht : HKCU\Software\IGearSettings
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{98889811-442D-49DD-99D7-DC866BE87DBC}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredibar.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredibar.com
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{35C1605E-438B-4D64-AAB1-8885F097A9B1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredibar.com
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredibar.com
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEE6C367-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}

***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16421

Ersetzt : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main - Start Page] = hxxp://home.sweetim.com/?crg=3.1010000.10002&barid={27A42084-C696-11E1-ACC2-0017C4F1B1FE} --> hxxp://www.google.com

-\\ Google Chrome v [Version kann nicht ermittelt werden]

Datei : C:\Users\aaa\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Die Datei ist sauber.

-\\ Opera v12.2.1578.0

Datei : C:\Users\aaa\AppData\Roaming\Opera\Opera\operaprefs.ini

[OK] Die Datei ist sauber.

*************************

AdwCleaner[R1].txt - [4790 octets] - [08/10/2012 22:48:27]
AdwCleaner[S1].txt - [4289 octets] - [09/10/2012 13:52:34]

########## EOF - C:\AdwCleaner[S1].txt - [4349 octets] ##########


cosinus 09.10.2012 15:20

Hätte da mal drei Fragen bevor es weiter geht (wir sind noch nicht fertig!)

1.) Geht der normale Modus von Windows (wieder) uneingeschränkt?
2.) Vermisst du irgendwas im Startmenü? Sind da leere Ordner unter alle Programme oder ist alles vorhanden?
3.) Die Werbeeinblendungen bzw Weiterleitungen wie zB Incredibar oder Mystart sind nun weg?

holzdan 09.10.2012 19:56

scheint alles gut zu laufen.
mir waere nichts zewcks werbeeinblendungen aufgefallen und auch keine fehlenden Ordner ecc.

cosinus 09.10.2012 20:17

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop. Falls schon vorhanden, bitte die ältere vorhandene Datei durch die neu heruntergeladene Datei ersetzen, damit du auch wirklich mit einer aktuellen Version von OTL arbeitest.
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


holzdan 09.10.2012 21:37

Code:

OTL logfile created on: 09.10.2012 22:22:18 - Run 3
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\aaa\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,86 Gb Total Physical Memory | 2,73 Gb Available Physical Memory | 70,60% Memory free
7,73 Gb Paging File | 6,55 Gb Available in Paging File | 84,81% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 463,16 Gb Total Space | 380,61 Gb Free Space | 82,18% Space Free | Partition Type: NTFS
 
Computer Name: AAA-PC | User Name: aaa | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.10.07 01:21:44 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\aaa\Desktop\OTL.exe
PRC - [2012.09.07 17:04:46 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2010.07.08 14:18:29 | 000,333,264 | ---- | M] () -- C:\Program Files (x86)\3DataManager\WTGService.exe
PRC - [2009.10.01 06:01:32 | 002,320,920 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2009.10.01 06:01:30 | 000,268,824 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2009.07.10 03:54:44 | 000,253,952 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe
PRC - [2009.06.05 05:03:06 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
 
 
========== Modules (No Company Name) ==========
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - [2012.07.28 04:09:44 | 000,239,616 | ---- | M] (AMD) [Disabled | Stopped] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2012.10.06 19:20:37 | 000,529,744 | ---- | M] (Valve Corporation) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2012.09.07 17:04:46 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.09.07 17:04:46 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012.08.30 13:23:28 | 000,008,704 | ---- | M] (Hi-Rez Studios) [Auto | Running] -- C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe -- (HiPatchService)
SRV - [2012.08.28 17:52:44 | 000,250,568 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.07.27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012.07.13 13:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.03.11 21:13:24 | 002,815,496 | ---- | M] (COMODO) [Auto | Running] -- C:\Programme\COMODO\COMODO Internet Security\cmdagent.exe -- (cmdAgent)
SRV - [2010.07.08 14:18:29 | 000,333,264 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\3DataManager\WTGService.exe -- (WTGService)
SRV - [2010.03.18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.12.03 16:27:24 | 000,028,672 | ---- | M] (LSI Corporation) [Auto | Running] -- C:\Programme\LSI SoftModem\agr64svc.exe -- (AgereModemAudio)
SRV - [2009.11.02 13:48:18 | 000,126,352 | ---- | M] (Intel(R) Corporation) [On_Demand | Stopped] -- C:\Programme\Intel\TurboBoost\TurboBoost.exe -- (TurboBoost)
SRV - [2009.10.01 06:01:32 | 002,320,920 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2009.10.01 06:01:30 | 000,268,824 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2009.09.30 15:44:58 | 000,844,320 | ---- | M] (Acer Incorporated) [Disabled | Stopped] -- C:\Programme\Acer\Acer ePower Management\ePowerSvc.exe -- (ePowerSvc)
SRV - [2009.09.25 01:42:28 | 000,062,720 | ---- | M] (NewTech Infosystems, Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe -- (NTI IScheduleSvc)
SRV - [2009.09.11 07:42:46 | 000,305,448 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe -- (MWLService)
SRV - [2009.08.28 11:38:58 | 001,150,496 | ---- | M] (Acer Incorporated) [Disabled | Stopped] -- C:\Program Files (x86)\Acer\Registration\GregHSRW.exe -- (Greg_Service)
SRV - [2009.07.10 03:54:44 | 000,253,952 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe -- (RS_Service)
SRV - [2009.07.04 04:47:12 | 000,240,160 | ---- | M] (Acer) [Disabled | Stopped] -- C:\Programme\Acer\Acer Updater\UpdaterService.exe -- (Updater Service)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009.06.05 05:03:06 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe -- (IAANTMON)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2012.10.01 18:31:53 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2012.09.07 17:04:46 | 000,025,928 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2012.08.30 22:03:48 | 000,128,456 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2012.07.28 06:07:44 | 010,278,912 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2012.07.28 06:07:44 | 010,278,912 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2012.07.28 03:14:46 | 000,368,640 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2012.05.14 08:12:30 | 000,096,896 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2012.04.13 20:12:13 | 000,121,344 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ZTEusbser6k.sys -- (ZTEusbser6k)
DRV:64bit: - [2012.04.13 20:12:13 | 000,121,344 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ZTEusbnmea.sys -- (ZTEusbnmea)
DRV:64bit: - [2012.04.13 20:12:13 | 000,121,344 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ZTEusbmdm6k.sys -- (ZTEusbmdm6k)
DRV:64bit: - [2012.04.13 20:12:13 | 000,012,800 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\massfilter.sys -- (massfilter)
DRV:64bit: - [2012.03.01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011.11.21 16:44:30 | 002,793,472 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:64bit: - [2011.10.17 16:55:32 | 000,559,384 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2011.07.01 05:46:40 | 000,031,232 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tap0901.sys -- (tap0901)
DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010.11.20 15:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.20 13:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.02.27 08:32:14 | 000,158,976 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd)
DRV:64bit: - [2009.12.03 17:07:04 | 001,224,192 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\agrsm64.sys -- (AgereSoftModem)
DRV:64bit: - [2009.09.18 06:12:06 | 000,292,912 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2009.09.17 22:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64)
DRV:64bit: - [2009.08.06 14:43:58 | 000,320,040 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\k57nd60a.sys -- (k57nd60a)
DRV:64bit: - [2009.07.23 00:06:26 | 000,040,448 | ---- | M] (Alcor Micro, Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AmUStor.sys -- (AmUStor)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.25 04:23:24 | 000,205,472 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtHDMIVX.sys -- (RTHDMIAzAudService)
DRV:64bit: - [2009.06.20 04:09:57 | 000,054,272 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\L1E62x64.sys -- (L1E)
DRV:64bit: - [2009.06.10 22:37:05 | 006,108,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2009.06.10 22:34:38 | 001,311,232 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.06.03 05:15:30 | 000,060,464 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDVDisk.sys -- (mwlPSDVDisk)
DRV:64bit: - [2009.06.03 05:15:30 | 000,022,576 | ---- | M] (Egis Technology Inc.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDFilter.sys -- (mwlPSDFilter)
DRV:64bit: - [2009.06.03 05:15:30 | 000,020,016 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDNserv.sys -- (mwlPSDNServ)
DRV:64bit: - [2009.05.06 02:46:08 | 000,018,432 | ---- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NTIDrvr.sys -- (NTIDrvr)
DRV:64bit: - [2009.05.06 02:46:08 | 000,016,896 | ---- | M] (NewTech Infosystems Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\UBHelper.sys -- (UBHelper)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_7740&r=27360312d206l04c8z135t64n1c413
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
 
 
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
 
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
 
IE - HKU\S-1-5-21-1121988522-4199441151-2918872926-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_7740&r=27360312d206l04c8z135t64n1c413
IE - HKU\S-1-5-21-1121988522-4199441151-2918872926-1000\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-1121988522-4199441151-2918872926-1000\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW_deAT474
IE - HKU\S-1-5-21-1121988522-4199441151-2918872926-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\S-1-5-21-1121988522-4199441151-2918872926-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
========== FireFox ==========
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_265.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.4.53: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.4.53: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.4.53: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012.05.06 17:15:11 | 000,000,000 | ---D | M]
 
 
========== Chrome  ==========
 
CHR - homepage:
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage:
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.79\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.92\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.92\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll
CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit)  (Enabled) = C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Download Plugin (Enabled) = C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll
CHR - plugin: RealPlayer(tm) HTML5VideoShim Plug-In (32-bit)  (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: RealNetworks(tm) Chrome Background Extension Plug-In (32-bit)  (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\aaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google-Suche = C:\Users\aaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\aaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: Google Mail = C:\Users\aaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
 
O1 HOSTS File: ([2012.10.06 16:26:02 | 000,444,411 | R--- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1        www.007guard.com
O1 - Hosts: 127.0.0.1        007guard.com
O1 - Hosts: 127.0.0.1        008i.com
O1 - Hosts: 127.0.0.1        www.008k.com
O1 - Hosts: 127.0.0.1        008k.com
O1 - Hosts: 127.0.0.1        www.00hq.com
O1 - Hosts: 127.0.0.1        00hq.com
O1 - Hosts: 127.0.0.1        010402.com
O1 - Hosts: 127.0.0.1        www.032439.com
O1 - Hosts: 127.0.0.1        032439.com
O1 - Hosts: 127.0.0.1        www.0scan.com
O1 - Hosts: 127.0.0.1        0scan.com
O1 - Hosts: 127.0.0.1        www.1000gratisproben.com
O1 - Hosts: 127.0.0.1        1000gratisproben.com
O1 - Hosts: 127.0.0.1        1001namen.com
O1 - Hosts: 127.0.0.1        www.1001namen.com
O1 - Hosts: 127.0.0.1        100888290cs.com
O1 - Hosts: 127.0.0.1        www.100888290cs.com
O1 - Hosts: 127.0.0.1        www.100sexlinks.com
O1 - Hosts: 127.0.0.1        100sexlinks.com
O1 - Hosts: 127.0.0.1        www.10sek.com
O1 - Hosts: 127.0.0.1        10sek.com
O1 - Hosts: 127.0.0.1        www.1-2005-search.com
O1 - Hosts: 127.0.0.1        1-2005-search.com
O1 - Hosts: 127.0.0.1        www.123fporn.info
O1 - Hosts: 15262 more lines...
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files (x86)\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files (x86)\Orbitdownloader\GrabPro.dll ()
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-1121988522-4199441151-2918872926-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-1121988522-4199441151-2918872926-1000\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files (x86)\Orbitdownloader\GrabPro.dll ()
O4:64bit: - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4 - HKU\S-1-5-19..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun File not found
O4 - HKU\S-1-5-20..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun File not found
O4 - HKU\S-1-5-21-1121988522-4199441151-2918872926-1000..\Run: [FreeAC] C:\Program Files (x86)\FreeAlarmClock\FreeAlarmClock.exe (Comfort Software Group)
O4 - HKU\.DEFAULT..\RunOnce: [osk.exe] C:\Windows\SysWow64\osk.exe (Microsoft Corporation)
O4 - HKU\S-1-5-18..\RunOnce: [osk.exe] C:\Windows\SysWow64\osk.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKLM..\RunOnceEx: [Flags] Reg Error: Invalid data type. File not found
O4 - Startup: C:\Users\aaa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Proxomitron.exe - Verknüpfung.lnk = C:\Users\aaa\Desktop\PROXOMITRON\Proxomitron.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-21-1121988522-4199441151-2918872926-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1121988522-4199441151-2918872926-1000\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8:64bit: - Extra context menu item: &Download by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8:64bit: - Extra context menu item: &Grab video by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8:64bit: - Extra context menu item: Do&wnload selected by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8:64bit: - Extra context menu item: Down&load all by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Download by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab video by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload selected by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load all by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL (Microsoft Corporation)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{04DDC8C3-4207-4A03-847A-5F0D098AC1F3}: NameServer = 8.26.56.26,156.154.70.22
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{908D8B77-90CF-4CB0-84F4-67EF8DA6CDD4}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18:64bit: - Protocol\Filter\text/html - No CLSID value found
O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/html - No CLSID value found
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - AppInit_DLLs: (C:\Windows\system32\guard64.dll) - C:\Windows\SysNative\guard64.dll (COMODO)
O20 - AppInit_DLLs: (C:\Windows\SysWOW64\guard32.dll) - C:\Windows\SysWOW64\guard32.dll (COMODO)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{70624967-858a-11e1-a36c-0017c4f1b1fe}\Shell - "" = AutoRun
O33 - MountPoints2\{70624967-858a-11e1-a36c-0017c4f1b1fe}\Shell\AutoRun\command - "" = E:\.\Autorun.exe AUTORUN=1
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (MACHINE BootExecut)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
 
MsConfig:64bit - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Start GeekBuddy.lnk -  - File not found
MsConfig:64bit - StartUpReg: Adobe ARM - hkey= - key= - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
MsConfig:64bit - StartUpReg: IAAnotif - hkey= - key= - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
MsConfig:64bit - StartUpReg: RtHDVCpl - hkey= - key= - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
MsConfig:64bit - StartUpReg: SpybotSD TeaTimer - hkey= - key= -  File not found
MsConfig:64bit - StartUpReg: StartCCC - hkey= - key= - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
MsConfig:64bit - StartUpReg: tvncontrol - hkey= - key= -  File not found
MsConfig:64bit - State: "startup" - Reg Error: Key error.
MsConfig:64bit - State: "services" - Reg Error: Key error.
 
SafeBootMin:64bit: AppMgmt - Service
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: mcmscsvc - Service
SafeBootMin:64bit: MCODS - Service
SafeBootMin:64bit: MsMpSvc - Service
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: vmms - Service
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: mcmscsvc - Service
SafeBootMin: MCODS - Service
SafeBootMin: MsMpSvc - Service
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet:64bit: AppMgmt - Service
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: mcmscsvc - Service
SafeBootNet:64bit: MCODS - Service
SafeBootNet:64bit: MpfService - Service
SafeBootNet:64bit: MsMpSvc - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: vmms - Service
SafeBootNet:64bit: WRkrn - Driver
SafeBootNet:64bit: WRSVC - Service
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: mcmscsvc - Service
SafeBootNet: MCODS - Service
SafeBootNet: MpfService - Service
SafeBootNet: MsMpSvc - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WRkrn - Driver
SafeBootNet: WRSVC - Service
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.XVID - C:\Windows\SysWow64\xvidvfw.dll ()
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.10.07 18:24:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2012.10.07 17:17:35 | 000,000,000 | R--D | C] -- C:\Program Files (x86)\Skype
[2012.10.07 17:17:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2012.10.07 17:17:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2012.10.07 17:15:09 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2012.10.07 11:12:07 | 000,000,000 | -HSD | C] -- C:\Windows\SysWow64\%APPDATA%
[2012.10.07 11:10:41 | 000,000,000 | ---D | C] -- C:\ProgramData\CPA_VA
[2012.10.07 11:09:35 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\COMODO
[2012.10.07 01:21:44 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\aaa\Desktop\OTL.exe
[2012.10.07 01:10:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2012.10.07 00:49:00 | 000,000,000 | ---D | C] -- C:\Users\aaa\AppData\Roaming\TweakNow PowerPack 2012
[2012.10.07 00:37:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Comodo
[2012.10.07 00:37:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\COMODO
[2012.10.07 00:37:01 | 000,000,000 | ---D | C] -- C:\Program Files\COMODO
[2012.10.07 00:03:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Downloaded Installations
[2012.10.06 23:52:02 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\directx
[2012.10.06 23:08:38 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2012.10.06 23:03:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD APP
[2012.10.06 23:03:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
[2012.10.06 22:53:52 | 000,000,000 | ---D | C] -- C:\AMD
[2012.10.06 22:48:11 | 000,000,000 | ---D | C] -- C:\Users\aaa\AppData\Local\Chromium
[2012.10.06 22:43:36 | 000,000,000 | ---D | C] -- C:\Users\aaa\Documents\My Games
[2012.10.06 21:28:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xvid
[2012.10.06 21:28:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Xvid
[2012.10.06 21:26:49 | 000,000,000 | ---D | C] -- C:\Users\aaa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zak McKracken - Between Time & Space
[2012.10.06 21:26:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zak McKracken - Between Time & Space
[2012.10.06 21:26:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Zak2
[2012.10.06 21:22:09 | 000,000,000 | ---D | C] -- C:\Users\aaa\Desktop\zak
[2012.10.06 21:14:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hi-Rez Studios
[2012.10.06 21:14:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Hi-Rez Studios
[2012.10.06 21:14:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Hi-Rez Studios
[2012.10.06 20:00:52 | 000,000,000 | -HSD | C] -- C:\Windows\SysNative\%APPDATA%
[2012.10.06 19:28:34 | 000,000,000 | ---D | C] -- C:\Users\aaa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
[2012.10.06 19:07:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Opera
[2012.10.06 16:15:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2012.10.06 16:15:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy
[2012.10.06 15:28:17 | 000,000,000 | -H-D | C] -- C:\Users\aaa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Disabled Startup Items
[2012.10.06 15:28:17 | 000,000,000 | -H-D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Disabled Startup Items
[2012.10.06 15:28:02 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\regruninfo
[2012.10.06 15:27:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Greatis
[2012.10.06 15:16:09 | 000,039,184 | ---- | C] (Greatis Software) -- C:\Windows\SysNative\Partizan.exe
[2012.10.06 15:12:24 | 000,000,000 | ---D | C] -- C:\ProgramData\RegRun
[2012.10.06 15:11:49 | 000,000,000 | ---D | C] -- C:\Users\aaa\Documents\RegRun2
[2012.10.06 12:20:58 | 000,000,000 | ---D | C] -- C:\Users\aaa\Desktop\Bücher-links
[2012.10.06 02:34:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Coranti
[2012.10.06 02:32:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Coranti
[2012.10.06 02:16:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GFI Software
[2012.10.06 01:44:52 | 000,000,000 | ---D | C] -- C:\Users\aaa\AppData\Local\Sophos
[2012.10.06 01:25:13 | 000,000,000 | ---D | C] -- C:\Users\aaa\Local Settings
[2012.10.06 01:16:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Sophos
[2012.10.06 01:00:50 | 000,000,000 | ---D | C] -- C:\escw_100_sa
[2012.10.06 00:57:47 | 000,000,000 | ---D | C] -- C:\Users\aaa\AppData\Local\Symantec
[2012.10.06 00:55:23 | 000,287,152 | ---- | C] (Symantec Corporation) -- C:\Windows\SysNative\SymVPN.dll
[2012.10.06 00:55:23 | 000,058,288 | ---- | C] (Symantec Corporation) -- C:\Windows\SysNative\snacnp.dll
[2012.10.05 23:52:02 | 000,251,560 | ---- | C] (PC Tools) -- C:\Windows\SysNative\drivers\PCTSD64.sys
[2012.10.05 23:52:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PC Tools
[2012.10.05 23:51:30 | 000,000,000 | ---D | C] -- C:\ProgramData\PC Tools
[2012.10.05 23:51:28 | 000,000,000 | ---D | C] -- C:\Users\aaa\AppData\Roaming\TestApp
[2012.10.05 23:27:42 | 000,000,000 | -HSD | C] -- C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
[2012.10.05 22:06:34 | 000,000,000 | ---D | C] -- C:\Program Files\InstallShield Installation Information
[2012.10.05 21:41:00 | 000,000,000 | ---D | C] -- C:\Users\aaa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameSpy Arcade
[2012.10.05 21:41:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GameSpy Arcade
[2012.10.05 21:40:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GameSpy Arcade
[2012.10.05 21:40:14 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Monolith Productions
[2012.10.05 21:35:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sierra
[2012.10.05 20:30:20 | 000,000,000 | ---D | C] -- C:\Users\aaa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Netdevil
[2012.10.05 20:06:36 | 000,000,000 | ---D | C] -- C:\Users\aaa\AppData\Local\GameSpy
[2012.10.05 20:06:27 | 000,000,000 | ---D | C] -- C:\Users\aaa\AppData\Local\ApplicationHistory
[2012.10.05 20:06:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GameSpy
[2012.10.05 20:06:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GameSpy
[2012.10.05 20:05:09 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\URTTEMP
[2012.10.05 20:04:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AGEIA
[2012.10.05 20:03:46 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\AGEIA
[2012.10.05 20:03:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AGEIA Technologies
[2012.10.05 20:03:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wise Installation Wizard
[2012.10.05 20:03:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Netdevil
[2012.10.05 15:34:02 | 000,000,000 | ---D | C] -- C:\Users\aaa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tennis Elbow 2011
[2012.10.05 15:34:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tennis Elbow 2011
[2012.10.05 15:34:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Tennis Elbow 2011
[2012.10.01 18:32:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Pro
[2012.10.01 18:31:53 | 000,283,200 | ---- | C] (DT Soft Ltd) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys
[2012.10.01 18:31:49 | 000,000,000 | ---D | C] -- C:\Users\aaa\AppData\Roaming\DAEMON Tools Pro
[2012.10.01 18:31:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DAEMON Tools Pro
[2012.10.01 18:30:41 | 000,000,000 | ---D | C] -- C:\ProgramData\DAEMON Tools Pro
[2009.11.05 05:33:04 | 000,036,136 | ---- | C] (Oberon Media) -- C:\ProgramData\FullRemove.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.10.09 22:18:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.10.09 21:50:45 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.10.09 21:40:00 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.10.09 15:22:32 | 000,478,024 | ---- | M] () -- C:\Users\aaa\Desktop\Label_Holzer.PDF
[2012.10.09 14:01:30 | 000,017,600 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.10.09 14:01:30 | 000,017,600 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.10.09 13:54:00 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.10.07 21:15:00 | 001,527,314 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.10.07 21:15:00 | 000,664,634 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.10.07 21:15:00 | 000,624,776 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.10.07 21:15:00 | 000,134,770 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.10.07 21:15:00 | 000,110,414 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.10.07 18:24:10 | 000,002,255 | ---- | M] () -- C:\Users\aaa\Desktop\Google Chrome.lnk
[2012.10.07 17:17:35 | 000,002,515 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2012.10.07 15:16:44 | 000,001,451 | ---- | M] () -- C:\Users\aaa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Proxomitron.exe - Verknüpfung.lnk
[2012.10.07 01:39:54 | 000,000,000 | ---- | M] () -- C:\Users\aaa\defogger_reenable
[2012.10.07 01:22:06 | 000,050,477 | ---- | M] () -- C:\Users\aaa\Desktop\Defogger.exe
[2012.10.07 01:21:44 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\aaa\Desktop\OTL.exe
[2012.10.07 00:37:17 | 000,001,846 | ---- | M] () -- C:\Users\Public\Desktop\COMODO Firewall.lnk
[2012.10.06 23:45:46 | 000,007,669 | ---- | M] () -- C:\Users\aaa\AppData\Local\Resmon.ResmonCfg
[2012.10.06 23:17:42 | 000,000,372 | ---- | M] () -- C:\Windows\ODBC.INI
[2012.10.06 22:36:54 | 003,629,231 | ---- | M] () -- C:\Program Files (x86)\YourFileDownloader.rar
[2012.10.06 21:26:50 | 000,000,959 | ---- | M] () -- C:\Users\aaa\Desktop\Zak McKracken - BTAS.lnk
[2012.10.06 21:14:57 | 000,002,041 | ---- | M] () -- C:\Users\Public\Desktop\Hi-Rez Diagnostics and Support.lnk
[2012.10.06 21:14:57 | 000,002,032 | ---- | M] () -- C:\Users\Public\Desktop\Tribes Ascend.lnk
[2012.10.06 19:28:34 | 000,000,219 | ---- | M] () -- C:\Users\aaa\Desktop\Counter-Strike Source.url
[2012.10.06 19:08:02 | 000,001,837 | ---- | M] () -- C:\Users\Public\Desktop\Opera.lnk
[2012.10.06 16:46:41 | 000,005,104 | ---- | M] () -- C:\Windows\wininit.ini
[2012.10.06 16:26:02 | 000,444,411 | R--- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012.10.06 15:28:21 | 000,000,002 | RHS- | M] () -- C:\Windows\winstart.bat
[2012.10.06 15:28:21 | 000,000,002 | RHS- | M] () -- C:\Windows\SysWow64\CONFIG.NT
[2012.10.06 15:28:21 | 000,000,002 | RHS- | M] () -- C:\Windows\SysWow64\AUTOEXEC.NT
[2012.10.06 15:16:09 | 000,039,184 | ---- | M] (Greatis Software) -- C:\Windows\SysNative\Partizan.exe
[2012.10.06 00:55:23 | 000,287,152 | ---- | M] (Symantec Corporation) -- C:\Windows\SysNative\SymVPN.dll
[2012.10.06 00:55:23 | 000,058,288 | ---- | M] (Symantec Corporation) -- C:\Windows\SysNative\snacnp.dll
[2012.10.05 23:52:24 | 001,997,385 | ---- | M] () -- C:\Windows\SysNative\drivers\Cat.DB
[2012.10.05 20:41:19 | 000,362,016 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.10.05 20:06:27 | 000,000,091 | ---- | M] () -- C:\Users\aaa\AppData\Local\fusioncache.dat
[2012.10.05 20:05:29 | 001,554,122 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012.10.02 03:00:36 | 000,001,912 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012.10.01 18:31:53 | 000,283,200 | ---- | M] (DT Soft Ltd) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys
[2012.09.26 16:55:44 | 000,000,162 | ---- | M] () -- C:\Users\aaa\SecurityKISSTunnel.config
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.10.09 15:22:32 | 000,478,024 | ---- | C] () -- C:\Users\aaa\Desktop\Label_Holzer.PDF
[2012.10.07 18:24:10 | 000,002,255 | ---- | C] () -- C:\Users\aaa\Desktop\Google Chrome.lnk
[2012.10.07 17:17:35 | 000,002,515 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk
[2012.10.07 01:39:54 | 000,000,000 | ---- | C] () -- C:\Users\aaa\defogger_reenable
[2012.10.07 01:22:06 | 000,050,477 | ---- | C] () -- C:\Users\aaa\Desktop\Defogger.exe
[2012.10.07 00:37:17 | 000,001,846 | ---- | C] () -- C:\Users\Public\Desktop\COMODO Firewall.lnk
[2012.10.06 23:45:46 | 000,007,669 | ---- | C] () -- C:\Users\aaa\AppData\Local\Resmon.ResmonCfg
[2012.10.06 23:22:32 | 000,001,451 | ---- | C] () -- C:\Users\aaa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Proxomitron.exe - Verknüpfung.lnk
[2012.10.06 22:36:53 | 003,629,231 | ---- | C] () -- C:\Program Files (x86)\YourFileDownloader.rar
[2012.10.06 21:28:52 | 000,765,952 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2012.10.06 21:28:52 | 000,077,824 | ---- | C] () -- C:\Windows\SysWow64\xvid.ax
[2012.10.06 21:28:50 | 000,180,224 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2012.10.06 21:26:50 | 000,000,959 | ---- | C] () -- C:\Users\aaa\Desktop\Zak McKracken - BTAS.lnk
[2012.10.06 21:14:57 | 000,002,041 | ---- | C] () -- C:\Users\Public\Desktop\Hi-Rez Diagnostics and Support.lnk
[2012.10.06 21:14:57 | 000,002,032 | ---- | C] () -- C:\Users\Public\Desktop\Tribes Ascend.lnk
[2012.10.06 19:28:34 | 000,000,219 | ---- | C] () -- C:\Users\aaa\Desktop\Counter-Strike Source.url
[2012.10.06 19:08:02 | 000,001,849 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
[2012.10.06 19:08:02 | 000,001,837 | ---- | C] () -- C:\Users\Public\Desktop\Opera.lnk
[2012.10.06 16:46:33 | 000,005,104 | ---- | C] () -- C:\Windows\wininit.ini
[2012.10.06 15:28:02 | 000,057,556 | ---- | C] () -- C:\Windows\guard.bmp
[2012.10.06 15:11:51 | 000,000,002 | RHS- | C] () -- C:\Windows\winstart.bat
[2012.10.06 15:11:51 | 000,000,002 | RHS- | C] () -- C:\Windows\SysWow64\CONFIG.NT
[2012.10.06 15:11:51 | 000,000,002 | RHS- | C] () -- C:\Windows\SysWow64\AUTOEXEC.NT
[2012.10.05 23:52:08 | 001,997,385 | ---- | C] () -- C:\Windows\SysNative\drivers\Cat.DB
[2012.10.05 20:06:27 | 000,000,091 | ---- | C] () -- C:\Users\aaa\AppData\Local\fusioncache.dat
[2012.10.05 15:34:10 | 000,921,600 | ---- | C] () -- C:\Windows\SysNative\vorbisenc.dll
[2012.10.05 15:34:10 | 000,237,568 | ---- | C] () -- C:\Windows\SysNative\OggDS.dll
[2012.10.05 15:34:10 | 000,188,416 | ---- | C] () -- C:\Windows\SysNative\vorbis.dll
[2012.10.05 15:34:10 | 000,045,056 | ---- | C] () -- C:\Windows\SysNative\ogg.dll
[2012.05.28 12:29:23 | 000,000,162 | ---- | C] () -- C:\Users\aaa\SecurityKISSTunnel.config
[2012.03.11 17:44:19 | 001,554,122 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012.03.11 05:13:30 | 000,001,744 | ---- | C] () -- C:\Windows\WPatchProgress.ini
[2012.03.11 02:40:53 | 000,026,569 | ---- | C] () -- C:\ProgramData\1331426446.4376.bin
[2012.03.11 02:40:48 | 000,008,383 | ---- | C] () -- C:\ProgramData\1331426446.3708.bin
[2012.03.11 02:40:47 | 000,006,945 | ---- | C] () -- C:\ProgramData\1331426446.3724.bin
[2012.03.11 02:40:46 | 000,054,366 | ---- | C] () -- C:\ProgramData\1331426446.2708.bin
[2012.03.11 01:48:28 | 000,000,372 | ---- | C] () -- C:\Windows\ODBC.INI
[2012.03.11 01:15:44 | 000,302,835 | ---- | C] () -- C:\ProgramData\1331420176.bdinstall.bin
[2012.03.10 21:05:49 | 000,626,688 | ---- | C] () -- C:\Windows\Image.dll
[2012.03.10 21:05:49 | 000,200,704 | ---- | C] () -- C:\Windows\PLFSetI.exe
[2012.03.10 21:05:49 | 000,020,480 | ---- | C] () -- C:\Windows\USB_VIDEO_REG.exe
[2012.03.10 21:05:49 | 000,000,323 | ---- | C] () -- C:\Windows\PidList.ini
[2012.03.10 20:46:34 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2012.02.15 04:36:36 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012.02.15 04:36:36 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2012.02.07 20:35:48 | 000,119,296 | ---- | C] () -- C:\Windows\SysWow64\zlibwapi.dll
[2012.02.07 20:35:48 | 000,119,296 | ---- | C] () -- C:\Windows\SysWow64\zlib.dll
[2012.01.31 07:00:24 | 000,016,896 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2011.09.13 00:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
 
========== ZeroAccess Check ==========
 
[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 07:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 14:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2012.04.13 20:47:28 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\3DataManager
[2012.03.11 01:03:45 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\Bitdefender
[2012.03.14 23:51:04 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\BitTorrent
[2012.03.24 20:40:48 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\Cerberus LLC
[2012.10.06 19:09:42 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\DAEMON Tools Pro
[2012.03.26 19:10:35 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\foobar2000
[2012.05.01 20:29:42 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\GameHouse
[2012.03.24 20:07:29 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\GrabPro
[2012.07.05 13:17:39 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\ImgBurn
[2012.03.11 16:53:28 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\KC Softwares
[2012.05.11 11:03:43 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\OpenOffice.org
[2012.10.06 19:08:11 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\Opera
[2012.10.05 23:28:13 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\Orbit
[2012.03.24 20:08:18 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\ProgSense
[2012.03.11 01:00:45 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\QuickScan
[2012.03.14 22:34:31 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\Securepoint Operation Center
[2012.10.05 23:51:28 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\TestApp
[2012.10.05 23:28:33 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\TuneUp Software
[2012.10.07 17:19:36 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\TweakNow PowerPack 2012
[2012.10.06 19:09:42 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\uTorrent
[2012.05.02 17:42:17 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\YourFileDownloader
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2012.04.13 20:47:28 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\3DataManager
[2012.03.13 11:58:03 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\Adobe
[2012.03.10 21:02:43 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\ATI
[2012.03.11 01:03:45 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\Bitdefender
[2012.03.14 23:51:04 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\BitTorrent
[2012.03.24 20:40:48 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\Cerberus LLC
[2012.10.06 19:09:42 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\DAEMON Tools Pro
[2012.03.26 19:10:35 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\foobar2000
[2012.05.01 20:29:42 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\GameHouse
[2012.03.10 21:04:46 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\Google
[2012.03.24 20:07:29 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\GrabPro
[2012.03.10 21:01:06 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\Identities
[2012.07.05 13:17:39 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\ImgBurn
[2012.03.10 21:02:46 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\InstallShield
[2012.03.11 16:53:28 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\KC Softwares
[2012.03.10 21:06:57 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\Macromedia
[2012.03.17 22:36:07 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\Malwarebytes
[2009.11.05 02:26:35 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\Media Center Programs
[2012.10.08 22:59:31 | 000,000,000 | --SD | M] -- C:\Users\aaa\AppData\Roaming\Microsoft
[2012.05.11 11:03:43 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\OpenOffice.org
[2012.10.06 19:08:11 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\Opera
[2012.10.05 23:28:13 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\Orbit
[2012.03.24 20:08:18 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\ProgSense
[2012.03.11 01:00:45 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\QuickScan
[2012.10.01 10:36:28 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\Real
[2012.03.14 22:34:31 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\Securepoint Operation Center
[2012.10.09 22:21:18 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\Skype
[2012.10.05 23:51:28 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\TestApp
[2012.10.05 23:28:33 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\TuneUp Software
[2012.10.07 17:19:36 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\TweakNow PowerPack 2012
[2012.10.06 19:09:42 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\uTorrent
[2012.08.05 14:40:15 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\vlc
[2012.03.11 16:44:30 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\WinRAR
[2012.05.02 17:42:17 | 000,000,000 | ---D | M] -- C:\Users\aaa\AppData\Roaming\YourFileDownloader
 
< %APPDATA%\*.exe /s >
[2012.10.01 10:36:31 | 000,450,712 | ---- | M] (RealNetworks, Inc.) -- C:\Users\aaa\AppData\Roaming\Real\Update\temp\~Upg0\rnupgagent.exe
[2012.10.01 10:36:31 | 000,450,712 | ---- | M] (RealNetworks, Inc.) -- C:\Users\aaa\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.20\agent\rnupgagent.exe
[2010.11.10 15:44:22 | 000,242,024 | ---- | M] (Igor Pavlov) -- C:\Users\aaa\AppData\Roaming\Securepoint Operation Center\_base\7za.exe
[2010.11.10 15:44:22 | 000,023,920 | ---- | M] () -- C:\Users\aaa\AppData\Roaming\Securepoint Operation Center\_base\base64.exe
 
< %SYSTEMDRIVE%\*.exe >
[2008.04.11 08:03:48 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe
 
< MD5 for: AGP440.SYS  >
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
 
< MD5 for: IASTOR.SYS  >
[2009.06.05 04:54:36 | 000,408,600 | ---- | M] (Intel Corporation) MD5=1D004CB1DA6323B1F55CAEF7F94B61D9 -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\driver64\IaStor.sys
[2009.06.05 04:54:36 | 000,408,600 | ---- | M] (Intel Corporation) MD5=1D004CB1DA6323B1F55CAEF7F94B61D9 -- C:\Windows\SysNative\DriverStore\FileRepository\iaahci.inf_amd64_neutral_7fb62b08f6b7117a\iaStor.sys
[2011.10.17 16:55:32 | 000,559,384 | ---- | M] (Intel Corporation) MD5=8180A2392E732E8871589B54FAB6991F -- C:\Windows\SysNative\drivers\iaStor.sys
[2011.10.17 16:55:32 | 000,559,384 | ---- | M] (Intel Corporation) MD5=8180A2392E732E8871589B54FAB6991F -- C:\Windows\SysNative\DriverStore\FileRepository\iaahci.inf_amd64_neutral_74f348dee3038044\iaStor.sys
[2009.06.05 04:43:16 | 000,330,264 | ---- | M] (Intel Corporation) MD5=D483687EACE0C065EE772481A96E05F5 -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\driver\IaStor.sys
 
< MD5 for: IASTORV.SYS  >
[2010.11.20 15:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys
[2010.11.20 15:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
[2011.03.11 08:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
[2011.03.11 08:23:00 | 000,410,496 | ---- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_0b141c81a16e25e6\iaStorV.sys
[2011.03.11 08:25:49 | 000,410,496 | ---- | M] (Intel Corporation) MD5=BFDC9D75698800CFE4D1698BF2750EA2 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_0bccc8c8ba6985c1\iaStorV.sys
[2009.07.14 03:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2009.07.14 03:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2010.11.20 15:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll
[2010.11.20 15:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll
[2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2009.07.14 03:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
[2011.03.11 08:23:06 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_95dd8d30d8a4cfbe\nvstor.sys
[2011.03.11 08:25:53 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=AE274836BA56518E279087363A781214 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_96963977f1a02f99\nvstor.sys
[2011.03.11 08:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\drivers\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
[2010.11.20 15:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys
[2010.11.20 15:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009.07.14 03:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
[2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010.11.20 15:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010.11.20 15:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
 
< MD5 for: USER32.DLL  >
[2010.11.20 14:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\SysWOW64\user32.dll
[2010.11.20 14:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[2009.07.14 03:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
[2010.11.20 15:27:27 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\SysNative\user32.dll
[2010.11.20 15:27:27 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009.07.14 03:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010.11.20 15:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010.11.20 15:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\SysNative\wininit.exe
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2010.11.20 15:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010.11.20 15:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009.07.14 03:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2012.09.07 17:04:42 | 000,218,696 | ---- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009.10.28 09:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009.10.28 08:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\SysNative\drivers\ws2ifsl.sys
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 52 bytes -> C:\Windows\write.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\WPatchProgress.ini:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\WMSysPr9.prx:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\WLXPGSS.SCR:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\WisPriority.ini:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\WisMvImg.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\WisLangCode.ini:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\WisGAPasx64.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\WisGAPas.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_96963977f1a02f99\nvstor.sys:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_95dd8d30d8a4cfbe\nvstor.sys:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_0bccc8c8ba6985c1\iaStorV.sys:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_0b141c81a16e25e6\iaStorV.sys:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\winhlp32.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\WindowsUpdate.log:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\WindowsShell.Manifest:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\WIN7BASE_XX.TAG:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\win.ini:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\USER.XML:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\USB_VIDEO_REG.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\UNINST32.EXE:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\twunk_32.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\twunk_16.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\twain_32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\twain.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\tasks\SCHEDLGU.TXT:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\zlibwapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\zlib.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\zipfldr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\xwtpw32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\xwtpdui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\xwreg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\xwizards.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\xwizard.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\xwizard.dtd:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\xpssvcs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\XPSSHHDR.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\xpsservices.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\xpsrchvw.xml:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\xpsrchvw.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\XpsRasterService.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\XpsPrint.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\XpsGdiConverter.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\XpsFilt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\xolehlp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\xmlprovi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\xmllite.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\xmlfilter.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\XInput9_1_0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\xcopy.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\XceedSco.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\XceedCry.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wzcdlg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wwapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WWanAPI.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wvc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wuwebv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wusa.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wups.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wudriver.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wuapp.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wuapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wtsapi32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WSTPager.ax:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wsock32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wsnmp32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WsmWmiPl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WsmTxt.xsl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WsmSvc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WsmRes.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WsmPty.xsl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wsmprovhost.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wsmplpxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WsmAuto.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WSManMigrationPlugin.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WSManHTTPConfig.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wsmanconfig_schema.xml:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WSHTCPIP.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wshrm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wshqos.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wshom.ocx:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wshirda.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wship6.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wshext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wshelper.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wshcon.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wshbth.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wsecedit.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wsdchngr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WSDApi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wscui.cpl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wscript.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wscproxystub.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wscmisetup.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wscisvif.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wscinterop.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wscapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ws2help.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ws2_32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\write.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wpdwcn.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WPDSp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WPDShServiceObj.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WPDShextAutoplay.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wpdshext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wpcsvc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wpcao.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Wpc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wowreg32.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wow32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WMVXENCD.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WMVSENCD.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WMVSDECD.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WMVENCOD.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wmvdspa.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WMVDECOD.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WMVCORE.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WMSPDMOE.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WMSPDMOD.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wmsgapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WMPhoto.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WMNetMgr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wmiprop.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wmidx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wmi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wmdrmsdk.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wmdrmnet.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wmdrmdev.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wmdmps.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wmdmlog.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wmcodecdspps.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WMASF.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WMADMOE.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WMADMOD.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WlS0WndH.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wlgpclnt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Wldap32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wlanutil.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wlanui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wlansec.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wlanpref.dl


holzdan 09.10.2012 21:38

Code:

@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wlanmsm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WlanMM.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wlaninst.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wlanhlp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wlangpui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wlanext.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wlandlg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WLanConn.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wlancfg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wlanapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wksprtPS.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wkscli.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WISPTIS.EXE:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\winver.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\winusb.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wintrust.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WinSyncProviders.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WinSyncMetastore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WinSync.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\winsta.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WINSRPC.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\winspool.drv:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\winsockhc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\winshfhc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WinSCard.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WinSATAPI.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\winrssrv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\winrsmgr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\winrshost.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\winrscmd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\winrs.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\winrnr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\winrm.vbs:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\winrm.cmd:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\winnsi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\winmm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\winipsec.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wininit.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wininet.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\winhttp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WinFax.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WindowsCodecsExt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WindowsCodecs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wincredprovider.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\winbrand.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\winbio.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\win32spl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wimserv.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wimgapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wiavideo.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wiatrace.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wiashext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wiascanprofiles.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WiaExtensionHost64.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wiadss.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wiadefui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wiaaut.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wiaacmgr.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\whoami.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\whhelper.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\where.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\whealogr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WfHC.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wfapigp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WF.msc:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wextract.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wevtutil.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wevtfwd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wevtapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\werui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wermgr.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WerFaultSecure.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WerFault.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\werdiagcontroller.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wer.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wecutil.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wecapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\webservices.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\webio.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WebClnt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\webcheck.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WEB.rs:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wdscore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wdmaud.drv:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wdigest.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wdi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wdc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WcsPlugInService.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wcnwiz.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WcnEapPeerProxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WcnEapAuthProxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wcncsvc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WcnApi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wbemcomn.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\wavemsp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\waitfor.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\WABSyncProvider.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\w32topl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\w32tm.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\vsstrace.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\vssapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\vssadmin.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\vss_ps.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\vpnikeapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\virtdisk.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\VIDRESZR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\vidcap.ax:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\vfwwdm32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\vfpodbc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\version.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\verifier.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\verifier.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\verclsid.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\VEN2232.OLB:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\vdsvd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\vdsdyn.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\vdsbas.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\vds_ps.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\vdmdbg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\vcomp100.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\vbscript.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\vbisurf.ax:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\VBICodec.ax:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\VBAME.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\vbajet32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\VBAEND32.OLB:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\VBAEN32.OLB:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\VBADE32.OLB:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\vaultcli.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Vault.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\VAN.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\uxtheme.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\uxlibres.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\uxlib.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\UXInit.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\uudf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Utilman.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\utildll.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\usp10.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\usk.rs:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\userinit.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\userenv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\usercpl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\UserAccountControlSettings.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\UserAccountControlSettings.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\user32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\user.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\usbui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\usbperf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\usbceip.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\urlmon.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\url.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ureg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\upnphost.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\upnpcont.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\upnp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\untfs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\unlodctr.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\uniplat.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\unimdmat.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\unimdm.tsp:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\umdmxfrm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ulib.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\UIRibbonRes.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\UIRibbon.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\uicom.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\UIAutomationCore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\UIAnimation.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ufat.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\uexfat.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\udhisapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ucmhc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ubpm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tzutil.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tzres.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\typeperf.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\typelib.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\txfw32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\txflog.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\twext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tvratings.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\TsWpfWrp.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\TSWorkspace.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\TSTheme.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tspkg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tsmf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tsgqec.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\TSChannel.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tsbyuv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tree.com:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\TRAPI.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\traffic.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\TRACERT.EXE:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tracerpt.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tquery.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\TpmInit.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tpmcompc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tpm.msc:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tlscsp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tintlgnt.ime:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\timeout.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\TimeDateMUICallback.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\timedate.cpl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ticrf.rat:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\thumbcache.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\themeui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\themecpl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\thawbrkr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\termmgr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\telephon.cpl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tdh.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tdc.ocx:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\TCPSVCS.EXE:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tcpmonui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tcpipcfg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tcpbidi.xml:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tcmsetup.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tbs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\TaskSchdPS.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\taskschd.msc:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\taskschd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\taskmgr.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tasklist.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\taskkill.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\taskeng.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\taskcomp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\TapiUnattend.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tapiui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\TapiSysprep.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tapisrv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tapiperf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\TapiMigPlugin.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tapi32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\tapi3.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\takeown.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\t2embed.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\systray.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SystemPropertiesRemote.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SystemPropertiesProtection.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SystemPropertiesPerformance.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SystemPropertiesHardware.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SystemPropertiesDataExecutionPrevention.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SystemPropertiesComputerName.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SystemPropertiesAdvanced.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\systeminfo.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\systemcpl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\syssetup.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sysprtj.sep:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sysprint.sep:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sysmon.ocx:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\syskey.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sysdm.cpl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SynTPCOM.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\syncui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SynCtrl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Syncreg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SynCOM.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SyncInfrastructureps.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SyncInfrastructure.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SyncHostps.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SyncHost.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\synceng.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SyncCenter.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sxstrace.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sxsstore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sxshared.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sxs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sxproxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\svchost.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sud.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\subst.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SubRange.uce:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\StructuredQuery.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Storprop.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\StorageContextHandler.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\storage.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\stobject.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sti.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\stdole32.tlb:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\stdole2.tlb:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\stclient.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ssText3d.scr:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SSShim.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sspicli.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ssdpapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sscore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\srvcli.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\srhelper.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\srdelayed.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\srclient.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\srchadmin.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sqmapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sqlwoa.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sqlwid.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sqlunirl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sqlsrv32.rll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sqlsrv32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sqlcese30.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sqlceqp30.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sqlceoledb30.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\spwizres.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\spwizimg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\spwizeng.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\spwinsat.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sppwmi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sppinst.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sppcommdlg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sppcomapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sppcext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sppcc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sppc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\spp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\spopk.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\spnet.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SPInf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\spfileq.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\spbcd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SortWindows6Compat.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SortServer2003Compat.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sort.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\softpub.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\softkbd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\snmpapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SndVolSSO.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SndVol.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SMBHelperClass.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SmartcardCredentialProvider.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\slwga.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\slmgr.vbs:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\slcext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\slc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sisbkup.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\simpdata.tlb:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\signdrv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\shwebsvc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\shutdown.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\shunimpl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\shsvcs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\shsetup.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\shrpubw.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\shpafact.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\shlwapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\shimgvw.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\shimeng.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ShiftJIS.uce:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\shgina.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\shfolder.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\shellstyle.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\shell32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\shdocvw.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\shacct.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SFCOM.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sfc_os.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sfc.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sfc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\setx.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\setupugc.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\setupSNK.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\setupcln.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\setupapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\setup16.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SetIEInstalledDate.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sethc.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SessEnv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\serwvdrv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\services.msc:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\serialui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SensorsCpl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SensorsApi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SensApi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Sens.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sendmail.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\security.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\secur32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\secproc_ssp_isv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\secproc_ssp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\secproc_isv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\secproc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\secinit.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sechost.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SecEdit.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SearchProtocolHost.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SearchIndexer.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SearchFolder.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SearchFilterHost.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sdohlp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sdiagprv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sdiagnhost.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sdiageng.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sdchange.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sdbinst.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\scrrun.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\scrobj.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\scrnsave.scr:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\scripto.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SCP32.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\scksp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\schtasks.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\schedcli.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\schannel.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\scesrv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\scecli.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SCardDlg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\scansetting.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sc.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sberes.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sbeio.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sbe.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\sas.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\SampleRes.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\samlib.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\samcli.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\runonce.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\RunLegacyCPLElevated.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rundll32.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\runas.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rtutils.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rtm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rtffilt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\RstrtMgr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rshx32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rsaenh.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rrinstaller.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\RpcRtRemote.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rpcrt4.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\RpcPing.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rpcnsh.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\RpcNs4.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\RPCNDFP.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rpchttp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\RpcDiag.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ROUTE.EXE:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Robocopy.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rnr20.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rmoc3260.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\RmClient.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\RMActivate_ssp_isv.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\RMActivate_ssp.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\RMActivate_isv.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\RMActivate.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\riched32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\riched20.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Ribbons.scr:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rgb9rast.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\resutils.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\RestartManagerUninstall.mof:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\RestartManager.mof:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\resmon.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\RESAMPLEDMO.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\replace.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rendezvousSession.tlb:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\remotesp.tsp:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\remotepg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\relog.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rekeywiz.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\regsvr32.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\regini.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\regedt32.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\regedit.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\RegCtrl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\regapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\reg.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\recover.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ReAgentc.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ReAgent.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rdrleakdiag.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rdprefdrvapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rdpencom.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rdpd3d.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rdpcore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rastls.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rastapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rasser.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rasppp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rasplap.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rasphone.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rasmxs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rasmontr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\RASMM.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rasman.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rasgcw.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\raserver.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rasdlg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rasdial.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rasdiag.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rasctrs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rasctrnm.h:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\raschap.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rascfg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rasautou.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rasapi32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\rasadhlp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\radarrs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\radardt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\RacRules.xml:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\racpldlg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\RacEngn.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\qwave.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\QUTIL.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\quick.ime:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Query.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\quartz.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\QSVRMGMT.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\QSHVHOST.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\qmgrprxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\qintlgnt.ime:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\qedwipes.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\qedit.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\qdvd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\qdv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\QCLIPROV.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\qcap.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\qasf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\QAGENT.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pwrshplugin.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\puiobj.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\puiapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pstorsvc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pstorec.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\psr.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\psisrndr.ax:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\psisdecd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PSHED.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pscript.sep:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\psbase.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\psapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\provthrd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\provsvc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\proquota.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\propsys.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\profapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\prntvpt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\prnntfy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\prnfldr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\prncache.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\printui.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\printui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\print.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\prflbmsg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\prevhost.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PresentationNative_v0300.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PresentationHostProxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PresentationHost.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\powrprof.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\powercpl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\powercfg.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\powercfg.cpl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pots.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PortableDeviceWMDRM.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PortableDeviceWiaCompat.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PortableDeviceTypes.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PortableDeviceSyncProvider.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PortableDeviceStatus.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PortableDeviceConnectApi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PortableDeviceClassExtension.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PortableDeviceApi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\poqexec.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\polstore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pnrpnsp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pnpsetup.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pnidui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pngfilt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pndx5032.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pndx5016.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pncrt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PlaySndSrv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pla.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pku2u.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PkgMgr.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pintlgnt.ime:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PING.EXE:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pifmgr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pidgenx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pid.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PhysXLoader.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PhysX.cpl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\photowiz.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PhotoScreensaver.scr:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PhotoMetadataHandler.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\phon.ime:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\perfts.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PerfStringBackup.INI:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\perfproc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\perfos.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\perfnet.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\perfmon.msc:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\perfmon.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\perfhost.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\perfdisk.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\perfctrs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PerfCenterCpl.ico:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PerfCenterCPL.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pegi-pt.rs:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pegi-fi.rs:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pegibbfc.rs:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pegi.rs:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pdhui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pdh.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pcwum.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pcl.sep:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pcaui.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pcaui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\pautoenr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\PATHPING.EXE:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\panmap.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\packager.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\p2pnetsh.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\P2PGraph.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\p2pcollab.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\P2P.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\osuninst.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\osk.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\osbaseln.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\OptionalFeatures.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\opengl32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\openfiles.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\OpenCL.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\OpcServices.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\OobeFldr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\OnLineIDCpl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\onexui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\onex.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\olethk32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\olesvr32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\oleres.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\olepro32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\oleprn.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\oledlg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\olecli32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\oleaut32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\oleaccrc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\oleacchooks.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\oleacc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ole32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ole2nls.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ole2disp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ole2.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ogldrv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\oflc.rs:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\offfilt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\odtext32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\odpdx32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\odfox32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\odexl32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\oddbse32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\odbctrac.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\odbcjt32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\odbcji32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\odbcint.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\odbccu32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\odbccr32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\odbccp32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\odbcconf.rsp:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\odbcconf.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\odbcconf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\odbcbcp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\odbcad32.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\odbc32gt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\odbc32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ocsetup.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ocsetapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\occache.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\objsel.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ntvdm64.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ntshrui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ntprint.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ntprint.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ntoskrnl.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ntmarta.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ntlanui2.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ntlanman.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ntkrnlpa.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ntdsapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ntdll.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\nslookup.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\nsi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\nshwfp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\nshipsec.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\nshhttp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\npmproxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\notepad.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\normaliz.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NOISE.THA:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\noise.kor:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\noise.jpn:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NOISE.DAT:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NOISE.CHT:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NOISE.CHS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsModels0011.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0c1a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons081a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0816.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0416.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0414.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons004e.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons004c.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons004b.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons004a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0049.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0047.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0046.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0045.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons003e.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0039.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons002a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0027.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0026.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0024.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0022.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0021.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0020.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons001d.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons001b.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons001a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0019.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0018.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0013.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0011.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0010.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons000f.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons000d.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons000c.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons000a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0009.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0007.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0003.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0002.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsLexicons0001.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Nlsdl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0c1a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData081a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0816.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0416.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0414.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData004e.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData004c.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData004b.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData004a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0049.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0047.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0046.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0045.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData003e.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0039.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData002a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0027.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0026.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0024.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0022.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0021.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0020.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData001d.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData001b.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData001a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0019.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0018.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0013.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0011.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0010.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData000f.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData000d.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData000c.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData000a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0009.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0007.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0003.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0002.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0001.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NlsData0000.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\nlsbres.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\nlmsprep.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\nlmgp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\nlhtml.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\nlaapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\newdev.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\newdev.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\networkmap.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\networkitemfactory.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\networkexplorer.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netutils.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NETSTAT.EXE:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netshell.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netsh.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netprofm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netprof.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Netplwiz.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netplwiz.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netmsg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netlogon.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netjoin.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netiougc.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netiohlp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netid.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\neth.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netfxperf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netevent.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netdiagfx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netcorehc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netcfgx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netcenter.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netbtugc.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netbios.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\netapi32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\net1.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\net.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\negoexts.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ndptsp.tsp:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ndproxystub.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ndishc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ndiscapCfg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ndfhcdiscovery.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NdfEventView.xml:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ndfetw.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ndfapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\nddeapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ndadmin.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ncsi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ncryptui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ncrypt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ncpa.cpl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ncobjapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\nci.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NcdProp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NaturalLanguage6.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NativeHooks.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NAPSTAT.EXE:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NAPMONTR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\napipsec.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NapiNSP.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NAPHLPR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\napdsnap.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NAPCRYPT.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\NAPCLCFG.MSC:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Mystify.scr:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mydocs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mycomput.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MuiUnattend.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\muifontsetup.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mtxoci.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mtxlegih.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mtxex.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mtxdm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mtxclu.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mtstocom.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msyuv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msxml6r.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msxml6.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msxml4r.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msxml4a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msxml3r.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msxml3.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msxbde40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mswstr10.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mswsock.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mswmdm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mswdat10.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MSVidCtl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msvidc32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msvfw32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msvcrt40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msvcrt20.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msvcrt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msvcr70.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msvcr100_clr0400.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msvcr100.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msvcp60.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msvcp100.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msvcirt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msvbvm60.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msv1_0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msutb.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mstscax.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mstsc.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mstext40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mstask.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msswch.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mssvp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MSSTDFMT.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mssrch.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mssprxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mssphtb.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mssph.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mssitlb.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mssip32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mssign32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msshooks.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msshavmsg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mssha.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msscript.ocx:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msscp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msscntrs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msrle32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msrepl40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MsRdpWebAccess.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msrdc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msrd3x40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msrd2x40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msrating.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MsraLegacy.tlb:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msra.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msports.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mspbde40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mspatcha.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mspaint.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msorcl32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msorc32r.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msoert2.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msoeacct.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msobjs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MSNP.ax:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msnetobj.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msmpeg2vdec.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MSMPEG2ENC.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msmpeg2adec.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msltus40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msls31.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msjtes40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msjter40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msjint40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msjetoledb40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msjet40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msisip.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msinfo32.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msimtf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msimsg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msimg32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msiltcfg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msihnd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msiexec.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msieftp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msidntld.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msidle.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msident.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msidcrl30.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mshtmler.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mshtmled.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mshtml.tlb:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mshtml.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mshta.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msgsm32.acm:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msg711.acm:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msftedit.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msfeedssync.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msfeedsbs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msfeeds.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msexcl40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msexch40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MSDvbNP.ax:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msdtcVSp1res.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msdtcuiu.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msdtcprx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msdt.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msdrm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msdmo.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msdelta.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msdatsrc.tlb:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msdart.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msdadiag.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msctfui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msctfp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MsCtfMonitor.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msctfime.ime:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msctf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mscpxl32.dLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mscpx32r.dLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mscories.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mscorier.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mscoree.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MSCOMCTL.OCX:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mscms.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msclmd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mscat32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mscandui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msaudite.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msasn1.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msafd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msadp32.acm:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msacm32.drv:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msacm32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MSAC3ENC.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\msaatext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MRINFO.EXE:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mprmsg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mprdim.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mprddm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mprapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mpr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MPG4DECD.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mpg2splt.ax:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Mpeg2Data.ax:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MP4SDECD.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MP43DECD.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MP3DMOD.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mountvol.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\moricons.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\more.com:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\modemui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mode.com:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mobsync.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mmsys.cpl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mmres.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MMDevAPI.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mmcshext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mmcndmgr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mmcico.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mmci.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mmcbase.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mmc.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mlang.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mlang.dat:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mimefilt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\miguiresource.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\migisol.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MigAutoPlay.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\midimap.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mgmtapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MFWMAAEC.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfvdsp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfreadwrite.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfps.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfpmp.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MFPlay.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfplat.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfmjpegdec.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfh264enc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mferror.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfdvdec.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfds.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfcsubs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfcm100u.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfcm100.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfc42u.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfc42.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfc40u.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfc40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfc100u.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfc100rus.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfc100kor.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfc100jpn.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfc100ita.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfc100fra.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfc100esn.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfc100enu.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfc100deu.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfc100cht.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfc100chs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfc100.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mfAACEnc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mf3216.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mdminst.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mctres.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mciwave.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mciseq.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mciqtz32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mcicda.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mciavi32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\MCEWMDRMNDBootstrap.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mcbuilder.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mapisvc.inf:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mapistub.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\mapi32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\makecab.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\main.cpl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Magnify.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Magnification.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\lz32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\lusrmgr.msc:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\luainstall.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\lsmproxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\lpk.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\logoncli.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\logman.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\loghours.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\logagent.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\lodctr.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\locationnotificationsview.xml:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\LocationNotifications.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\LocationApi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\localsec.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\locale.nls:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\loadperf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\linkinfo.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\licmgr10.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\license.rtf:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\lcptr.tbl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\lcphrase.tbl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\LAPRXY.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\label.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\l3codecp.acm:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\l3codeca.acm:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\L2SecHC.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\l2nacp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\l2gpstore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\l_intl.nls:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ktmw32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ktmutil.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ksxbar.ax:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Kswdmcap.ax:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ksuser.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kstvtune.ax:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ksproxy.ax:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\korwbrkr.lex:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\korwbrkr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\korean.uce:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kmddsp.tsp:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\keymgr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\keyiso.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KernelBase.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kernel32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kerberos.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kdbsdk32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDYCL.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDYCC.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDYBA.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDYAK.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDWOL.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDVNTC.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDUZB.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDUSX.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDUSR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDUSL.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDUSA.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDUS.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDURDU.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDUR1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDUR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDUKX.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDUK.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDUGHR1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDUGHR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDTURME.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDTUQ.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDTUF.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDTIPRC.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDTH3.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDTH2.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDTH1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDTH0.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDTAT.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDTAJIK.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDSYR2.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDSYR1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDSW09.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDSW.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDSP.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDSORST.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDSORS1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDSOREX.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDSN1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDSMSNO.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDSMSFI.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDSL1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDSL.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDSG.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDSF.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDRU1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDRU.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDROST.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDROPR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDRO.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDPO.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDPL1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDPL.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDPASH.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDNSO.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDNO1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDNO.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDNEPR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kbdnecnt.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kbdnecat.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kbdnec95.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kbdnec.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDNE.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDMONMO.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDMON.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDMLT48.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDMLT47.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDMAORI.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDMACST.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDMAC.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDLV1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDLV.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDLT2.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDLT1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDLT.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kbdlk41a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDLAO.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDLA.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDKYR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDKOR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDKHMR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDKAZ.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDJPN.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDIULAT.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDIT142.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDIT.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDIR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDINUK2.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDINTEL.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDINTAM.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDINPUN.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDINORI.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDINMAR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDINMAL.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDINKAN.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDINHIN.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDINGUJ.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDINDEV.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDINBEN.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDINBE2.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDINBE1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDINASA.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDIC.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDIBO.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kbdibm02.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDHU1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDHU.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDHEPT.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDHELA3.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDHELA2.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDHEB.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDHE319.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDHE220.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDHE.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDHAU.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDGRLND.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDGR1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDGR.DLL:coranti


holzdan 09.10.2012 21:43

Code:

> C:\Windows\SysWow64\KBDGKL.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kbdgeoqw.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kbdgeoer.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDGEO.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDGAE.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDFR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDFO.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDFI1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDFI.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDFC.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDFA.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDEST.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDES.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDDV.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDDIV2.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDDIV1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDDA.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDCZ2.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDCZ1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDCZ.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDCR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDCAN.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDCA.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDBULG.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDBU.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDBR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDBLR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDBHC.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDBGPH1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDBGPH.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDBENE.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDBE.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDBASH.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDAZEL.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDAZE.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kbdax2.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDARMW.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDARME.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDAL.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDA3.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDA2.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\KBDA1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kbd106n.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kbd106.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kbd103.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kbd101c.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kbd101b.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kbd101a.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kbd101.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kanji_2.uce:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\kanji_1.uce:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\jsproxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\jscript9.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\jscript.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\joy.cpl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iyuv_32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ivfsrc.ax:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\itss.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\itircl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\isoburn.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iscsiwmi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iscsium.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iscsied.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iscsidsc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iscsicpl.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iscsicpl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iscsicli.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\irprops.cpl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\irclass.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ir50_qcx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ir50_qc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ir50_32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ir41_qcx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ir41_qc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ir41_32.ax:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ir32_32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ipsmsnap.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ipsecsnp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iprtrmgr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iprtprio.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iprop.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\IPHLPAPI.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ipconfig.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\IPBusEnumProxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iologmsg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\intl.cpl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\instnm.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\inseng.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\input.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\InkEd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\infocardcpl.cpl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\infocardapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\InfDefaultInstall.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\INETRES.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\inetmib1.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\inetcpl.cpl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\inetcomm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\imm32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\imkr80.ime:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\IMJP10K.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\IMJP10.IME:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\imgutil.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\imapi2fs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\imapi2.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\imapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\imagesp1.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\imageres.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\imagehlp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\imaadp32.acm:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\igkrng500.bin:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\igfcg500m.bin:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\igfcg500.bin:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\igdumd32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\igd10umd32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\igcompkrng500.bin:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ifsutilx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ifsutil.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ifmon.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iexpress.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ieUnatt.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ieuinit.inf:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ieui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iesysprep.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iesetup.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iertutil.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iernonce.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iepeers.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ieframe.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iedkcs32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ieapfltr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ieapfltr.dat:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ieakui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ieaksie.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ieakeng.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\IEAdvpack.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ie4uinit.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\IDStore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\idndl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ideograf.uce:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\icsunattend.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\icsigd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\icrav03.rat:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\IconCodecService.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\icmui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\icmp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\icm32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iccvid.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\icardres.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\icardie.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\icardagt.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\icacls.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iassvcs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iassdo.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iassam.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iasrecst.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iasrad.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iaspolcy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iasnap.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\IasMigPlugin.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iashlpr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iasdatastore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iasads.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iasacct.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ias.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\iac25_32.ax:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\htui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\httpapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\html.iec:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\HOSTNAME.EXE:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\hnetmon.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\hnetcfg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\hlp95en.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\hlink.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\hidserv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\hidphone.tsp:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\hid.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\hhsetup.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\hhctrl.ocx:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\hh.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\hgcpl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\HelpPaneProxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\help.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\hdwwiz.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\hdwwiz.cpl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\hcproviders.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\hbaapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\grpconv.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\grb.rs:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\gpupdate.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\gptext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\gpresult.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\gpprnext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\gpedit.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\gpapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\glu32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\glmf32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\getuname.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\getmac.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\gdi32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\gcdef.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\gb2312.uce:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\GameUXLegacyGDFs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\gameux.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\g711codc.ax:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\FXSXP32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\FXSRESM.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\FXSEXT32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\FXSCOMEX.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\FXSCOM.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\FXSAPI.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\FwRemoteSvr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\FWPUCLNT.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fwcfg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fundisc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ftp.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fthsvc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fsutil.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fsmgmt.msc:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\framedynos.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\framedyn.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fphc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\format.com:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\forfiles.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fontview.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fontsub.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fontext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fms.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fmifs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\FM20ENU.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\FM20DEU.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\FM20.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fltMC.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fltLib.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\FlashPlayerCPLApp.cpl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\FlashPlayerApp.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fixmapi.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\FirewallControlPanel.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\FirewallAPI.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Firewall.cpl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\finger.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\findstr.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\findnetprinters.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\find.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\filemgmt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\feclient.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fdWSD.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fdWNet.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fdWCN.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fdSSDP.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fdProxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fdPnp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fdeploy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fde.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fdBthProxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fdBth.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\fc.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Faultrep.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\f3ahvoas.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\extrac32.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\expsrv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ExplorerFrame.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\explorer.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\expand.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\evr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\eventvwr.msc:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\eventvwr.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\EventViewer_EventDetails.xsl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\eventcreate.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\eventcls.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\eudcedit.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\esrb.rs:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\esentutl.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\esentprf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\esent.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\es.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\eqossnap.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\EncDec.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\encapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\elsTrans.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\elslad.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ELSCore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\els.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\EhStorShell.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\EhStorPwdMgr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\EhStorAuthn.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\EhStorAPI.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\efsutil.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\efsui.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\efscore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\efsadu.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\EAPQEC.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\eappprxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\eapphost.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\eappgnui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\eappcfg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\eapp3hst.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dxva2.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dxtrans.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dxtmsft.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DxpTaskSync.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DXPTaskRingtone.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dxgi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dxdiagn.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dxdiag.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DWWIN.EXE:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DWrite.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dwmcore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dwmapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dvdupgrd.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dvdplay.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\duser.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dui70.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dtsh.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dswave.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dsuiext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dssenh.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dssec.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dssec.dat:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dsrole.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dsquery.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dsprop.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dsound.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dskquoui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dskquota.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DShowRdpFilter.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dsdmo.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dsauth.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ds32gt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\drvstore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\drvinst.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\drttransport.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\drtprov.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\drt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\drprov.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\drmv2clt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\drmmgrtn.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\drivers\wimmount.sys:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\drivers\gmreadme.txt:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\drivers\gm.dls:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\drivers\DKbFltr.sys:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\driverquery.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dpx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dpwsockx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dpnsvr.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dpnlobby.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dpnhupnp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dpnhpast.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dpnet.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dpnathlp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dpnaddr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dpmodemx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dplayx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dplaysvr.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DpiScaling.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dpapiprovider.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dpapimig.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dot3ui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dot3msm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dot3hc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dot3gpui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dot3gpclnt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dot3dlg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dot3cfg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dot3api.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\doskey.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\docprop.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dnscmmc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dnscacheugc.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dnsapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dmview.ocx:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dmvdsitf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dmutil.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dmusic.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dmsynth.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dmstyle.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dmscript.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dmrc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dmocx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dmloader.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dmintf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dmime.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dmdskres2.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dmdskres.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dmdskmgr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dmdlgs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dmcompos.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dmband.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dllhst3g.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dllhost.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DisplaySwitch.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Display.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dispex.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Dism.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\diskraid.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\diskperf.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\diskpart.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\diskmgmt.msc:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\diskcopy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\diskcopy.com:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\diskcomp.com:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dinput8.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dinput.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dimsroam.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dimsjob.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\difxapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\diantz.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dialer.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dhcpsapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DHCPQEC.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dhcpcsvc6.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dhcpcsvc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dhcpcore6.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dhcpcore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dhcpcmonitor.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DfsShlEx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dfshim.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dfscli.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dfrgui.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\devrtl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\devobj.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\devmgr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\devmgmt.msc:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DeviceUxRes.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DeviceProperties.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DevicePairingWizard.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DevicePairingProxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DevicePairingHandler.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DevicePairingFolder.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DevicePairing.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DeviceMetadataParsers.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DeviceDisplayStatusManager.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DeviceCenter.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\devenum.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\deskperf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\deskmon.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\deskadp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\desk.cpl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\defaultlocationcpl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ddrawex.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ddraw.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DDORes.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DDOIProxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ddodiag.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\DDACLSys.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dcomcnfg.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dciman32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dccw.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dbnmpntw.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dbnetlib.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dbghelp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dbgeng.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\davhlpr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\davclnt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\dataclen.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\d3dxof.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\d3dx9_32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\d3dx9_27.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\d3dramp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\d3dim700.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\d3dim.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\d3d9.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\d3d8thk.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\d3d8.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\d3d11.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\d3d10warp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\d3d10level9.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\d3d10core.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\d3d10_1core.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\d3d10_1.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\d3d10.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\d2d1.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cttunesvr.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cttune.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ctl3d32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ctfmon.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\CSVer.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\csrr.rs:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cscript.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cscdll.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cscapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cryptxml.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cryptui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cryptsvc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cryptsp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cryptnet.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cryptext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cryptdll.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cryptdlg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cryptbase.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\crypt32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\crtdll.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\credwiz.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\credui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\credssp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\CPFilters.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\convert.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\control.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\console.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\connect.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\comuid.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\comsvcs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\comsnap.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\comres.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\comrepl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ComputerDefaults.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\compstui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\compobj.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\compmgmt.msc:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\compact.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\comp.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\comexp.msc:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\comdlg32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\comctl32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\comcat.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\colorui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\colorcpl.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\COLORCNV.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\colbact.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cnvfat.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cngprovider.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cngaudit.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cmutil.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cmstplua.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cmstp.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cmpbk32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cmmon32.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cmlua.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cmipnpinstall.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cmifw.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cmicryptinstall.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cmdl32.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cmdkey.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cmdial32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cmd.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cmcfg32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\clusapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\clip.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cliconfg.rll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cliconfg.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cliconfg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\clfsw32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cleanmgr.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\clbcatq.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\clb.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cipher.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cintlgnt.ime:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cic.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\CHxReadingStringIME.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\chtbrkr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\chsbrkr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\choice.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\chkntfs.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\chkdsk.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\chcp.com:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\charmap.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\chajei.ime:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cfgmgr32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cfgbkend.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cewmdm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\certutil.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\certreq.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\CertPolEng.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\certmgr.msc:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\certmgr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\CertEnrollUI.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\CertEnrollCtrl.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\CertEnroll.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\certenc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\certCredProvider.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\certcli.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cero.rs:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cdosys.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\CCCInstall_201203111630271511.log:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cca.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\catsrvut.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\catsrvps.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\catsrv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\capisp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\capiprovider.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\capicom.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\calc.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cacls.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cabview.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\cabinet.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_ISCII.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_IS2022.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_G18030.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_950.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_949.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_936.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_932.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_875.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_874.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_870.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_869.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_866.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_865.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_864.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_863.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_862.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_861.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_860.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_858.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_857.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_855.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_852.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_850.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_775.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_737.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_720.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_708.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_500.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_437.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_28605.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\c_28603.nls:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_28599.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_28598.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_28597.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_28596.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_28595.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_28594.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_28593.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_28592.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_28591.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_21866.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_21027.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_21025.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20949.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20936.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20932.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20924.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20905.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20880.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20871.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20866.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20838.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20833.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20424.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20423.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20420.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20297.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20290.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20285.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20284.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20280.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20278.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20277.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20273.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20269.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20261.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20127.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20108.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20107.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20106.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20105.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20005.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20004.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20003.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20002.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20001.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_20000.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1361.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1258.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1257.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1256.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1255.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1254.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1253.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1252.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1251.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1250.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1149.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1148.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1147.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1146.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1145.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1144.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1143.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1142.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1141.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1140.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1047.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_1026.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_10082.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_10081.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_10079.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_10029.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_10021.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_10017.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_10010.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_10008.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_10007.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_10006.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_10005.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_10004.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_10003.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_10002.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_10001.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_10000.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\C_037.NLS:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\BWUnpairElevated.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\BWContextHandler.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Bubbles.scr:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\btpanui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\bthudtask.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\bthprops.cpl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\browseui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\browcli.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\bopomofo.uce:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\BOOTVID.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\bootcfg.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\boot.sdi:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\blackbox.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\bitsprx6.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\bitsprx5.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\bitsprx4.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\bitsprx3.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\bitsprx2.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\bitsperf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\bitsadmin.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\BioCredProv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\bidispl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\bdaplgin.ax:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\bcryptprimitives.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\bcrypt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\batmeter.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\basecsp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AzSqlExt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\azroleui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\azroles.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\azman.msc:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\avrt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\avifil32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\avicap32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AuxiliaryDisplayCpl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AuxiliaryDisplayApi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\autoplay.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\autofmt.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\autoconv.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\autochk.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\authz.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\authui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AuthFWWizFwk.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AuthFWSnapin.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AuthFWGP.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\authfwcfg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\auditpol.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AudioSes.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AUDIOKSE.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AudioEng.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\audiodev.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\attrib.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\atmlib.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\atmfd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\atl100.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\atl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ativvsvl.dat:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ativvsva.dat:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\atiumdmv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\atipdlxx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\atipblag.dat:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AtBroker.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\at.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\asycfilt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\asferror.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ARP.EXE:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\apss.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\appwiz.cpl:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\appidapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\Apphlpdm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\apphelp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\apisetschema.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\apircl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-service-winsvc-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-service-management-l2-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-service-management-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-service-core-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-security-sddl-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-security-lsalookup-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\apilogen.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\apds.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\amxread.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\amstream.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AltTab.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AgCPanelTraditionalChinese.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AgCPanelSwedish.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AgCPanelSpanish.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AgCPanelSimplifiedChinese.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AgCPanelPortugese.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AgCPanelKorean.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AgCPanelJapanese.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AgCPanelGerman.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AgCPanelFrench.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\aeevts.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\aecache.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\advpack.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\advapi32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\adtschema.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\adsnt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\adsmsext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\adsldpc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\adsldp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\adprovider.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\admparse.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\AdapterTroubleshooter.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\actxprxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\activeds.tlb:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\activeds.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ActionCenterCPL.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ActionCenter.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\acppage.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\aclui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\acledit.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\ACCTRES.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\accessibilitycpl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\aaclient.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\12520850.cpx:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysWow64\12520437.cpx:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\zlibwapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\zlib.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\zipfldr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\xwtpw32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\xwtpdui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\xwreg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\xwizards.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\xpssvcs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\XPSSHHDR.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\xpsservices.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\XpsRasterService.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\XpsPrint.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\XpsGdiConverter.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\XpsFilt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\xolehlp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\xmlprovi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\xmllite.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\xmlfilter.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\XInput9_1_0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\XceedSco.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\XceedCry.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wzcdlg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wwapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WWanAPI.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wvc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wuwebv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wups.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wudriver.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wuapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wtsapi32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wsock32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wsnmp32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WsmWmiPl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WsmSvc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WsmRes.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wsmplpxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WsmAuto.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WSManMigrationPlugin.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WSHTCPIP.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wshrm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wshqos.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wshirda.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wship6.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wshext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wshelper.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wshcon.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wshbth.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wsecedit.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wsdchngr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WSDApi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wscproxystub.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wscmisetup.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wscisvif.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wscinterop.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wscapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ws2help.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ws2_32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wpdwcn.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WPDSp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WPDShServiceObj.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wpdshext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wpcsvc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wpcao.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\Wpc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wow32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WMVXENCD.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WMVSENCD.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WMVSDECD.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WMVENCOD.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wmvdspa.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WMVDECOD.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WMVCORE.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WMSPDMOE.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WMSPDMOD.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wmsgapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WMPhoto.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WMNetMgr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wmiprop.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wmidx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wmi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wmdrmsdk.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wmdrmnet.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wmdrmdev.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wmdmps.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wmdmlog.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wmcodecdspps.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WMASF.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WMADMOE.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WMADMOD.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WlS0WndH.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wlgpclnt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\Wldap32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wlanutil.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wlanui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wlansec.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wlanpref.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wlanmsm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WlanMM.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wlaninst.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wlanhlp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wlangpui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wlandlg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WLanConn.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wlancfg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wlanapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wksprtPS.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wkscli.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\winusb.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wintrust.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WinSyncProviders.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WinSyncMetastore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WinSync.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\winsta.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WINSRPC.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\winsockhc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\winshfhc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WinSCard.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WinSATAPI.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\winrssrv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\winrsmgr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\winrscmd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\winrnr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\winnsi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\winmm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\winipsec.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wininet.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\winhttp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WinFax.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WindowsCodecsExt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WindowsCodecs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wincredprovider.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\winbrand.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\winbio.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\win32spl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wimgapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wiavideo.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wiatrace.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wiashext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wiascanprofiles.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WiaExtensionHost64.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wiadss.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wiadefui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wiaaut.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\whhelper.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\whealogr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WfHC.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wfapigp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wevtfwd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wevtapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\werui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\werdiagcontroller.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wer.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wecapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\webservices.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\webio.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WebClnt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\webcheck.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wdscore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wdigest.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wdi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wdc.dll:coranti


holzdan 09.10.2012 21:44

Code:

> C:\Windows\system32\WcsPlugInService.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wcnwiz.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WcnEapPeerProxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WcnEapAuthProxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wcncsvc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WcnApi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wbemcomn.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\wavemsp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\WABSyncProvider.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\w32topl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\vsstrace.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\vssapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\vss_ps.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\vpnikeapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\virtdisk.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\VIDRESZR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\vfwwdm32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\vfpodbc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\version.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\verifier.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\vdsvd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\vdsdyn.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\vdsbas.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\vds_ps.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\vdmdbg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\vcomp100.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\vbscript.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\VBAME.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\vbajet32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\vaultcli.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\Vault.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\VAN.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\uxtheme.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\uxlibres.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\uxlib.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\UXInit.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\uudf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\utildll.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\usp10.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\userenv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\usercpl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\UserAccountControlSettings.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\user32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\usbui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\usbperf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\usbceip.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\urlmon.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\url.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ureg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\upnphost.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\upnp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\untfs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\uniplat.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\unimdmat.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\umdmxfrm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ulib.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\UIRibbonRes.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\UIRibbon.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\uicom.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\UIAutomationCore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\UIAnimation.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ufat.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\uexfat.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\udhisapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ucmhc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ubpm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\tzres.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\typelib.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\txfw32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\txflog.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\twext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\tvratings.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\TSWorkspace.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\TSpkg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\tsmf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\tsgqec.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\TSChannel.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\tsbyuv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\TRAPI.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\traffic.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\tquery.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\tpmcompc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\tlscsp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\TimeDateMUICallback.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\thumbcache.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\themeui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\themecpl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\thawbrkr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\termmgr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\tdh.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\tcpmonui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\tcpipcfg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\tbs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\TaskSchdPS.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\taskschd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\taskcomp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\tapiui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\TapiSysprep.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\tapisrv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\tapiperf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\TapiMigPlugin.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\tapi32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\tapi3.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\t2embed.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\systemcpl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\syssetup.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\SynTPCOM.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\syncui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\SynCtrl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\Syncreg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\SynCOM.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\SyncInfrastructureps.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\SyncInfrastructure.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\SyncHostps.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\synceng.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\SyncCenter.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\sxsstore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\sxshared.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\sxs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\sxproxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\sud.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\StructuredQuery.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\Storprop.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\StorageContextHandler.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\storage.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\stobject.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\sti.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\stclient.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\SSShim.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\sspicli.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ssdpapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\sscore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\srvcli.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\srhelper.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\srclient.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\srchadmin.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\sqmapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\sqlwoa.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\sqlwid.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\sqlunirl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\sqlsrv32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\sqlcese30.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\sqlceqp30.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\sqlceoledb30.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\spwizres.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\spwizimg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\spwizeng.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\spwinsat.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\sppwmi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\sppinst.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\sppcommdlg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\sppcomapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\sppcext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\sppcc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\sppc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\spp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\spopk.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\spnet.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\SPInf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\spfileq.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\spbcd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\SortWindows6Compat.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\SortServer2003Compat.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\softpub.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\softkbd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\snmpapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\SndVolSSO.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\SMBHelperClass.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\SmartcardCredentialProvider.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\slwga.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\slcext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\slc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\sisbkup.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\signdrv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\shwebsvc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\shunimpl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\shsvcs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\shsetup.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\shpafact.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\shlwapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\shimgvw.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\shimeng.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\shgina.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\shfolder.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\shellstyle.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\shell32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\shdocvw.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\shacct.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\SFCOM.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\sfc_os.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\sfc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\setupcln.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\setupapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\SessEnv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\serwvdrv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\serialui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\SensorsCpl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\SensorsApi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\SensApi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\Sens.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\sendmail.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\security.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\secur32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\secproc_ssp_isv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\secproc_ssp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\secproc_isv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\secproc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\sechost.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\SearchFolder.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\sdohlp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\sdiagprv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\sdiageng.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\scrrun.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\scrobj.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\scripto.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\SCP32.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\scksp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\schedcli.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\schannel.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\scesrv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\scecli.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\SCardDlg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\scansetting.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\sberes.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\sbeio.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\sbe.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\sas.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\SampleRes.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\samlib.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\samcli.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\rtutils.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\rtm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\rtffilt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\RstrtMgr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\rshx32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\rsaenh.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\RpcRtRemote.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\rpcrt4.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\rpcnsh.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\RpcNs4.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\RPCNDFP.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\rpchttp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\RpcDiag.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\rnr20.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\rmoc3260.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\riched32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\riched20.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\rgb9rast.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\resutils.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\RESAMPLEDMO.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\remotepg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\RegCtrl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\regapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ReAgent.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\rdprefdrvapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\rdpencom.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\rdpd3d.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\rdpcore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\rastls.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\rastapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\rasser.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\rasppp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\rasplap.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\rasmxs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\rasmontr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\RASMM.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\rasman.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\rasgcw.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\rasdlg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\rasdiag.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\rasctrs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\raschap.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\rascfg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\rasapi32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\rasadhlp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\radarrs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\radardt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\racpldlg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\RacEngn.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\qwave.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\QUTIL.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\Query.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\quartz.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\QSVRMGMT.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\QSHVHOST.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\qmgrprxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\qedwipes.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\qedit.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\qdvd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\qdv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\QCLIPROV.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\qcap.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\qasf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\QAGENT.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\pwrshplugin.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\puiobj.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\puiapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\pstorsvc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\pstorec.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\psisdecd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\PSHED.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\psbase.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\psapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\provthrd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\provsvc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\propsys.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\profapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\prntvpt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\prnntfy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\prnfldr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\prncache.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\printui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\prflbmsg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\PresentationNative_v0300.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\PresentationHostProxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\powrprof.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\powercpl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\pots.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\PortableDeviceWMDRM.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\PortableDeviceWiaCompat.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\PortableDeviceTypes.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\PortableDeviceSyncProvider.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\PortableDeviceStatus.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\PortableDeviceConnectApi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\PortableDeviceClassExtension.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\PortableDeviceApi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\polstore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\pnrpnsp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\pnpsetup.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\pnidui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\pngfilt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\pndx5032.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\pndx5016.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\pncrt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\PlaySndSrv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\pla.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\pku2u.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\pifmgr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\pidgenx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\pid.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\PhysXLoader.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\photowiz.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\PhotoMetadataHandler.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\perfts.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\perfproc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\perfos.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\perfnet.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\perfdisk.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\perfctrs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\PerfCenterCPL.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\pdhui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\pdh.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\pcwum.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\pcaui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\pautoenr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\panmap.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\packager.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\p2pnetsh.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\P2PGraph.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\p2pcollab.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\P2P.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\osuninst.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\osbaseln.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\opengl32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\OpenCL.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\OpcServices.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\OobeFldr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\OnLineIDCpl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\onexui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\onex.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\olethk32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\olesvr32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\oleres.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\olepro32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\oleprn.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\oledlg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\olecli32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\oleaut32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\oleaccrc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\oleacchooks.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\oleacc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ole32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ole2nls.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ole2disp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ole2.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ogldrv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\offfilt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\odtext32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\odpdx32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\odfox32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\odexl32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\oddbse32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\odbctrac.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\odbcjt32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\odbcji32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\odbcint.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\odbccu32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\odbccr32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\odbccp32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\odbcconf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\odbcbcp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\odbc32gt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\odbc32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ocsetapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\occache.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\objsel.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ntvdm64.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ntshrui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ntprint.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ntmarta.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ntlanui2.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ntlanman.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ntdsapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ntdll.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\nsi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\nshwfp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\nshipsec.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\nshhttp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\npmproxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\normaliz.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsModels0011.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsLexicons0c1a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsLexicons081a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsLexicons0816.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsLexicons0416.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsLexicons0414.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsLexicons004e.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsLexicons004c.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsLexicons004b.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsLexicons004a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsLexicons0049.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsLexicons0047.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsLexicons0046.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsLexicons0045.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsLexicons003e.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsLexicons0039.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsLexicons002a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsLexicons0027.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsLexicons0026.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsLexicons0024.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsLexicons0022.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsLexicons0021.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsLexicons0020.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsLexicons001d.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsLexicons001b.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsLexicons001a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsLexicons0019.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsLexicons0018.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsLexicons0013.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsLexicons0011.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsLexicons0010.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsLexicons000f.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsLexicons000d.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsLexicons000c.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsLexicons000a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsLexicons0009.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsLexicons0007.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsLexicons0003.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsLexicons0002.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsLexicons0001.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\Nlsdl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsData0c1a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsData081a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsData0816.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsData0416.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsData0414.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsData004e.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsData004c.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsData004b.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsData004a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsData0049.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsData0047.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsData0046.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsData0045.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsData003e.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsData0039.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsData002a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsData0027.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsData0026.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsData0024.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsData0022.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsData0021.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsData0020.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsData001d.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsData001b.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsData001a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsData0019.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsData0018.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsData0013.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsData0011.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsData0010.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsData000f.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsData000d.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsData000c.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsData000a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsData0009.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsData0007.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsData0003.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsData0002.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsData0001.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NlsData0000.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\nlsbres.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\nlmsprep.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\nlmgp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\nlhtml.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\nlaapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\newdev.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\networkmap.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\networkitemfactory.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\networkexplorer.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\netutils.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\netshell.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\netprofm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\netprof.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\netplwiz.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\netmsg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\netlogon.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\netjoin.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\netiohlp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\netid.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\neth.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\netfxperf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\netevent.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\netdiagfx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\netcorehc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\netcfgx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\netcenter.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\netbios.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\netapi32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\negoexts.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ndproxystub.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ndishc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ndiscapCfg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ndfhcdiscovery.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ndfetw.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ndfapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\nddeapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ncsi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ncryptui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ncrypt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ncobjapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\nci.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NcdProp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NaturalLanguage6.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NativeHooks.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NAPMONTR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\napipsec.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NapiNSP.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NAPHLPR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\napdsnap.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\NAPCRYPT.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mydocs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mycomput.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\muifontsetup.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mtxoci.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mtxlegih.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mtxex.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mtxdm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mtxclu.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msyuv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msxml6r.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msxml6.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msxml4r.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msxml4a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msxml3r.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msxml3.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msxbde40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mswstr10.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mswsock.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mswmdm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mswdat10.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\MSVidCtl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msvidc32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msvfw32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msvcrt40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msvcrt20.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msvcrt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msvcr70.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msvcr100_clr0400.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msvcr100.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msvcp60.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msvcp100.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msvcirt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msvbvm60.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msv1_0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msutb.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mstscax.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mstext40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mstask.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msswch.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mssvp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\MSSTDFMT.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mssrch.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mssprxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mssphtb.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mssph.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mssitlb.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mssip32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mssign32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msshooks.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msshavmsg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mssha.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msscp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msscntrs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msrle32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msrepl40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\MsRdpWebAccess.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msrdc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msrd3x40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msrd2x40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msrating.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msports.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mspbde40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mspatcha.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msorcl32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msorc32r.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msoert2.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msoeacct.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msobjs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msnetobj.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msmpeg2vdec.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\MSMPEG2ENC.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msmpeg2adec.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msltus40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msls31.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msjtes40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msjter40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msjint40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msjetoledb40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msjet40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msisip.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msimtf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msimsg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msimg32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msiltcfg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msihnd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msieftp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msidntld.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msidle.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msident.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msidcrl30.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mshtmler.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mshtmled.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mshtml.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msftedit.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msfeedsbs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msfeeds.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msexcl40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msexch40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msdtcVSp1res.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msdtcuiu.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msdtcprx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msdrm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msdmo.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msdelta.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msdart.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msdadiag.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msctfui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msctfp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\MsCtfMonitor.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msctf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mscpxl32.dLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mscpx32r.dLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mscories.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mscorier.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mscoree.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mscms.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msclmd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mscat32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mscandui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msaudite.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msasn1.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msafd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msacm32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\MSAC3ENC.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\msaatext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mprmsg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mprdim.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mprddm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mprapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mpr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\MPG4DECD.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\MP4SDECD.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\MP43DECD.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\MP3DMOD.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\moricons.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\modemui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mmres.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\MMDevAPI.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mmcshext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mmcndmgr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mmcico.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mmci.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mmcbase.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mlang.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mimefilt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\miguiresource.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\migisol.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\midimap.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mgmtapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\MFWMAAEC.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mfvdsp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mfreadwrite.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mfps.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\MFPlay.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mfplat.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mfmjpegdec.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mfh264enc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mferror.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mfdvdec.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mfds.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mfcsubs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mfcm100u.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mfcm100.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mfc42u.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mfc42.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mfc40u.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mfc40.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mfc100u.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mfc100rus.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mfc100kor.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mfc100jpn.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mfc100ita.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mfc100fra.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mfc100esn.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mfc100enu.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mfc100deu.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mfc100cht.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mfc100chs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mfc100.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mfAACEnc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mf3216.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mdminst.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mctres.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mciwave.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mciseq.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mciqtz32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mcicda.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mciavi32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\MCEWMDRMNDBootstrap.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mapistub.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\mapi32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\Magnification.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\lz32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\luainstall.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\lsmproxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\lpk.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\logoncli.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\loghours.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\LocationApi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\localsec.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\loadperf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\linkinfo.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\licmgr10.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\LAPRXY.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\L2SecHC.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\l2nacp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\l2gpstore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ktmw32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ksuser.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\korwbrkr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\keymgr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\keyiso.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KernelBase.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\kernel32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\kerberos.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\kdbsdk32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDYCL.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDYCC.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDYBA.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDYAK.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDWOL.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDVNTC.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDUZB.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDUSX.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDUSR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDUSL.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDUSA.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDUS.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDURDU.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDUR1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDUR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDUKX.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDUK.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDUGHR1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDUGHR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDTURME.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDTUQ.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDTUF.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDTIPRC.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDTH3.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDTH2.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDTH1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDTH0.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDTAT.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDTAJIK.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDSYR2.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDSYR1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDSW09.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDSW.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDSP.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDSORST.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDSORS1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDSOREX.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDSN1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDSMSNO.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDSMSFI.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDSL1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDSL.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDSG.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDSF.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDRU1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDRU.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDROST.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDROPR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDRO.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDPO.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDPL1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDPL.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDPASH.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDNSO.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDNO1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDNO.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDNEPR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\kbdnecnt.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\kbdnecat.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\kbdnec95.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\kbdnec.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDNE.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDMONMO.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDMON.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDMLT48.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDMLT47.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDMAORI.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDMACST.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDMAC.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDLV1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDLV.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDLT2.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDLT1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDLT.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\kbdlk41a.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDLAO.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDLA.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDKYR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDKOR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDKHMR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDKAZ.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDJPN.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDIULAT.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDIT142.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDIT.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDIR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDINUK2.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDINTEL.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDINTAM.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDINPUN.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDINORI.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDINMAR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDINMAL.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDINKAN.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDINHIN.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDINGUJ.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDINDEV.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDINBEN.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDINBE2.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDINBE1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDINASA.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDIC.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDIBO.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\kbdibm02.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDHU1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDHU.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDHEPT.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDHELA3.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDHELA2.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDHEB.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDHE319.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDHE220.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDHE.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDHAU.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDGRLND.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDGR1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDGR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDGKL.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\kbdgeoqw.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\kbdgeoer.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDGEO.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDGAE.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDFR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDFO.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDFI1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDFI.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDFC.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDFA.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDEST.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDES.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDDV.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDDIV2.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDDIV1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDDA.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDCZ2.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDCZ1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDCZ.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDCR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDCAN.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDCA.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDBULG.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDBU.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDBR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDBLR.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDBHC.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDBGPH1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDBGPH.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDBENE.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDBE.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDBASH.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDAZEL.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDAZE.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\kbdax2.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDARMW.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDARME.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDAL.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDA3.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDA2.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\KBDA1.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\kbd106n.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\kbd106.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\kbd103.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\kbd101c.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\kbd101b.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\kbd101a.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\kbd101.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\jsproxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\jscript9.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\jscript.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\iyuv_32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\itss.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\itircl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\iscsiwmi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\iscsium.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\iscsied.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\iscsidsc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\iscsicpl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\irclass.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ir50_qcx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ir50_qc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ir50_32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ir41_qcx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ir41_qc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ir32_32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ipsmsnap.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ipsecsnp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\iprtrmgr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\iprtprio.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\iprop.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\IPHLPAPI.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\IPBusEnumProxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\iologmsg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\inseng.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\input.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\InkEd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\infocardapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\INETRES.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\inetmib1.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\inetcomm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\imm32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\IMJP10K.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\imgutil.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\imapi2fs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\imapi2.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\imapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\imagesp1.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\imageres.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\imagehlp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\igdumd32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\igd10umd32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ifsutilx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ifsutil.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ifmon.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ieui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\iesysprep.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\iesetup.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\iertutil.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\iernonce.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\iepeers.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ieframe.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\iedkcs32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ieapfltr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ieakui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ieaksie.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ieakeng.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\IEAdvpack.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\IDStore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\idndl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\icsigd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\IconCodecService.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\icmui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\icmp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\icm32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\iccvid.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\icardres.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\icardie.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\iassvcs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\iassdo.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\iassam.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\iasrecst.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\iasrad.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\iaspolcy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\iasnap.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\IasMigPlugin.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\iashlpr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\iasdatastore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\iasads.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\iasacct.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ias.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\htui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\httpapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\hnetmon.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\hnetcfg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\hlp95en.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\hlink.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\hidserv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\hid.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\hhsetup.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\hgcpl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\HelpPaneProxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\hcproviders.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\hbaapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\gptext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\gpprnext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\gpedit.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\gpapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\glu32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\glmf32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\getuname.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\gdi32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\gcdef.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\GameUXLegacyGDFs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\gameux.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\FXSXP32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\FXSRESM.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\FXSEXT32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\FXSCOMEX.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\FXSCOM.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\FXSAPI.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\FwRemoteSvr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\FWPUCLNT.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\fwcfg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\fundisc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\fthsvc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\framedynos.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\framedyn.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\fphc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\fontsub.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\fontext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\fms.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\fmifs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\FM20ENU.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\FM20DEU.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\FM20.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\fltLib.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\FirewallControlPanel.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\FirewallAPI.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\findnetprinters.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\filemgmt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\feclient.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\fdWSD.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\fdWNet.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\fdWCN.dll:coranti


holzdan 09.10.2012 21:46

Code:

@Alternate Data Stream - 52 bytes -> C:\Windows\system32\fdSSDP.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\fdProxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\fdPnp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\fdeploy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\fde.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\fdBthProxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\fdBth.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\Faultrep.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\f3ahvoas.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\expsrv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ExplorerFrame.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\evr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\eventcls.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\esentprf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\esent.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\es.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\eqossnap.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\EncDec.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\encapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\elsTrans.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\elslad.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ELSCore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\els.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\EhStorShell.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\EhStorPwdMgr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\EhStorAPI.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\efsutil.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\efscore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\efsadu.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\EAPQEC.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\eappprxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\eapphost.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\eappgnui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\eappcfg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\eapp3hst.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dxva2.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dxtrans.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dxtmsft.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\DxpTaskSync.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\DXPTaskRingtone.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dxgi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dxdiagn.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\DWrite.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dwmcore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dwmapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\duser.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dui70.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dtsh.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dswave.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dsuiext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dssenh.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dssec.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dsrole.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dsquery.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dsprop.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dsound.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dskquoui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dskquota.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\DShowRdpFilter.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dsdmo.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dsauth.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ds32gt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\drvstore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\drttransport.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\drtprov.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\drt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\drprov.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\drmv2clt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\drmmgrtn.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\drivers\wimmount.sys:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\drivers\DKbFltr.sys:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dpx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dpwsockx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dpnlobby.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dpnhupnp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dpnhpast.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dpnet.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dpnathlp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dpnaddr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dpmodemx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dplayx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dpapiprovider.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dot3ui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dot3msm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dot3hc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dot3gpui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dot3gpclnt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dot3dlg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dot3cfg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dot3api.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\docprop.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dnscmmc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dnsapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dmvdsitf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dmutil.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dmusic.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dmsynth.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dmstyle.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dmscript.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dmrc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dmocx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dmloader.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dmintf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dmime.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dmdskres2.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dmdskres.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dmdskmgr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dmdlgs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dmcompos.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dmband.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\Display.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dispex.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\diskcopy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dinput8.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dinput.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dimsroam.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dimsjob.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\difxapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dhcpsapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\DHCPQEC.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dhcpcsvc6.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dhcpcsvc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dhcpcore6.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dhcpcore.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dhcpcmonitor.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\DfsShlEx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dfshim.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dfscli.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\devrtl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\devobj.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\devmgr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\DeviceUxRes.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\DevicePairingProxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\DevicePairingHandler.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\DevicePairingFolder.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\DevicePairing.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\DeviceMetadataParsers.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\DeviceDisplayStatusManager.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\DeviceCenter.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\devenum.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\deskperf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\deskmon.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\deskadp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\defaultlocationcpl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ddrawex.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ddraw.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\DDORes.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\DDOIProxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\DDACLSys.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dciman32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dbnmpntw.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dbnetlib.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dbghelp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dbgeng.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\davhlpr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\davclnt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\dataclen.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\d3dxof.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\d3dx9_32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\d3dx9_27.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\d3dramp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\d3dim700.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\d3dim.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\d3d9.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\d3d8thk.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\d3d8.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\d3d11.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\d3d10warp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\d3d10level9.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\d3d10core.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\d3d10_1core.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\d3d10_1.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\d3d10.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\d2d1.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ctl3d32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\CSVer.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\cscdll.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\cscapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\cryptxml.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\cryptui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\cryptsvc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\cryptsp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\cryptnet.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\cryptext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\cryptdll.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\cryptdlg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\cryptbase.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\crypt32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\crtdll.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\credui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\credssp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\CPFilters.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\console.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\connect.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\comuid.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\comsvcs.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\comsnap.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\comres.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\comrepl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\compstui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\compobj.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\comdlg32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\comctl32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\comcat.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\colorui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\COLORCNV.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\colbact.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\cnvfat.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\cngprovider.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\cngaudit.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\cmutil.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\cmstplua.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\cmpbk32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\cmlua.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\cmipnpinstall.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\cmifw.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\cmicryptinstall.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\cmdial32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\cmcfg32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\clusapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\cliconfg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\clfsw32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\clbcatq.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\clb.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\cic.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\CHxReadingStringIME.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\chtbrkr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\chsbrkr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\cfgmgr32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\cfgbkend.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\cewmdm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\CertPolEng.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\certmgr.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\CertEnrollUI.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\CertEnroll.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\certenc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\certCredProvider.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\certcli.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\cdosys.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\cca.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\catsrvut.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\catsrvps.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\catsrv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\capisp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\capiprovider.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\capicom.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\cabview.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\cabinet.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\C_ISCII.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\C_IS2022.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\C_G18030.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\BWUnpairElevated.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\BWContextHandler.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\btpanui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\browseui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\browcli.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\BOOTVID.DLL:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\blackbox.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\bitsprx6.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\bitsprx5.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\bitsprx4.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\bitsprx3.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\bitsprx2.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\bitsperf.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\BioCredProv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\bidispl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\bcryptprimitives.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\bcrypt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\batmeter.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\basecsp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\AzSqlExt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\azroleui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\azroles.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\avrt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\avifil32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\avicap32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\AuxiliaryDisplayCpl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\AuxiliaryDisplayApi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\autoplay.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\authz.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\authui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\AuthFWWizFwk.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\AuthFWSnapin.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\AuthFWGP.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\authfwcfg.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\AudioSes.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\AUDIOKSE.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\AudioEng.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\audiodev.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\atmlib.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\atmfd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\atl100.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\atl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\atiumdmv.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\atipdlxx.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\asycfilt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\asferror.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\apss.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\appidapi.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\Apphlpdm.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\apphelp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\apisetschema.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\apircl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\api-ms-win-service-winsvc-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\api-ms-win-service-management-l2-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\api-ms-win-service-management-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\api-ms-win-service-core-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\api-ms-win-security-sddl-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\api-ms-win-security-lsalookup-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\apilogen.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\apds.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\amxread.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\amstream.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\AltTab.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\AgCPanelTraditionalChinese.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\AgCPanelSwedish.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\AgCPanelSpanish.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\AgCPanelSimplifiedChinese.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\AgCPanelPortugese.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\AgCPanelKorean.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\AgCPanelJapanese.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\AgCPanelGerman.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\AgCPanelFrench.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\aeevts.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\aecache.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\advpack.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\advapi32.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\adtschema.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\adsnt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\adsmsext.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\adsldpc.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\adsldp.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\adprovider.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\admparse.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\actxprxy.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\activeds.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ActionCenterCPL.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ActionCenter.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\acppage.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\aclui.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\acledit.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\ACCTRES.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\accessibilitycpl.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system32\aaclient.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\system.ini:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysNative\DriverStore\FileRepository\iaahci.inf_amd64_neutral_7fb62b08f6b7117a\iaStor.sys:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysNative\DriverStore\FileRepository\iaahci.inf_amd64_neutral_74f348dee3038044\iaStor.sys:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysNative\drivers\etc\services:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysNative\drivers\etc\protocol:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysNative\drivers\etc\networks:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysNative\drivers\etc\lmhosts.sam:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\SysNative\drivers\etc\hosts.20121006-162602.backup:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\Suyin.reg:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\Starter.xml:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\splwow64.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\RtlExUpd.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\regedit.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\Prelaunch.ini:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\PLFSetI.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\PLaunch.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\PidList.ini:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\PatchFul.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\ParseModule_X86.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\ParseModule_X64.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\ODBC.INI:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\notepad.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\NewDeployWinRE.cmd:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\msdfmap.ini:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\MOD01SET75000N0006.enc:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\MOD01SET74DE0N0003.XML:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\MOD01SET74DE0N0003.enc:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\mib.bin:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\LManager.UNI:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\LaunApp.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\Image.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\HomePremium.xml:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\HomeBasic.xml:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\hh.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\HelpPane.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\GVUni.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\GridV.UNI:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\fveupdate.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\Fonts\GlobalUserInterface.CompositeFont:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\Fonts\GlobalSerif.CompositeFont:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\Fonts\GlobalSansSerif.CompositeFont:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\Fonts\GlobalMonospace.CompositeFont:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\Factory.xml:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\explorer.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\epplauncher.mif:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\EB6BE8A5-11AE-4e2b-8B6E-974168C301C8.DSI:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\CSUP.txt:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\ChangeLang_Done.tag:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\Capsule.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\bootstat.dat:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\bfsvc.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\agrsmdel.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\agrdel64.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\Acer Crystal Eye webcam.ico:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\Acer Crystal Eye webcam.EXE:coranti
@Alternate Data Stream - 52 bytes -> C:\Windows\0:coranti
@Alternate Data Stream - 52 bytes -> C:\vcredist.bmp:coranti
@Alternate Data Stream - 52 bytes -> C:\VC_RED.MSI:coranti
@Alternate Data Stream - 52 bytes -> C:\VC_RED.cab:coranti
@Alternate Data Stream - 52 bytes -> C:\Users\Public\Documents\NTILiveUpdate.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Users\Public\Documents\NTIBUN5.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Users\Public\Documents\desktop.ini:coranti
@Alternate Data Stream - 52 bytes -> C:\Users\aaa\SecurityKISSTunnel.config:coranti
@Alternate Data Stream - 52 bytes -> C:\Users\aaa\ntuser.ini:coranti
@Alternate Data Stream - 52 bytes -> C:\Users\aaa\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms:coranti
@Alternate Data Stream - 52 bytes -> C:\Users\aaa\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms:coranti
@Alternate Data Stream - 52 bytes -> C:\Users\aaa\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf:coranti
@Alternate Data Stream - 52 bytes -> C:\Users\aaa\Documents\desktop.ini:coranti
@Alternate Data Stream - 52 bytes -> C:\Users\aaa\Desktop\END Strom.PDF:coranti
@Alternate Data Stream - 52 bytes -> C:\Users\aaa\AppData\Roaming\Securepoint Operation Center\_base\base64.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Users\aaa\AppData\Roaming\Securepoint Operation Center\_base\7za.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Users\aaa\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.20\agent\rnupgagent.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Users\aaa\AppData\Roaming\Real\Update\temp\~Upg0\rnupgagent.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Users\aaa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini:coranti
@Alternate Data Stream - 52 bytes -> C:\Users\aaa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini:coranti
@Alternate Data Stream - 52 bytes -> C:\Users\aaa\AppData\Local\GDIPFONTCACHEV1.DAT:coranti
@Alternate Data Stream - 52 bytes -> C:\Users\aaa\AppData\Local\fusioncache.dat:coranti
@Alternate Data Stream - 52 bytes -> C:\RHDSetup.log:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\PS.log:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Works-Start.lnk:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Word Viewer 2003.lnk:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office PowerPoint Viewer 2007.lnk:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader.lnk:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Update.lnk:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Deinstallationsprogramm.lnk:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn.lnk:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\foobar2000.lnk:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat.com.lnk:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\FullRemove.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\ArcadeDeluxe3.log:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\1331426446.4376.bin:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\1331426446.3724.bin:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\1331426446.3708.bin:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\1331426446.2708.bin:coranti
@Alternate Data Stream - 52 bytes -> C:\ProgramData\1331420176.bdinstall.bin:coranti
@Alternate Data Stream - 52 bytes -> C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Program Files\desktop.ini:coranti
@Alternate Data Stream - 52 bytes -> C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\driver64\IaStor.sys:coranti
@Alternate Data Stream - 52 bytes -> C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\driver\IaStor.sys:coranti
@Alternate Data Stream - 52 bytes -> C:\Program Files (x86)\FreeAlarmClock\FreeAlarmClock.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Program Files (x86)\desktop.ini:coranti
@Alternate Data Stream - 52 bytes -> C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\Program Files (x86)\Common Files\Acer GameZone online.ico:coranti
@Alternate Data Stream - 52 bytes -> C:\Preload.rev:coranti
@Alternate Data Stream - 52 bytes -> C:\Patch.rev:coranti
@Alternate Data Stream - 52 bytes -> C:\mcdbp.log:coranti
@Alternate Data Stream - 52 bytes -> C:\install.res.3082.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\install.res.2052.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\install.res.1049.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\install.res.1042.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\install.res.1041.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\install.res.1040.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\install.res.1036.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\install.res.1033.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\install.res.1031.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\install.res.1028.dll:coranti
@Alternate Data Stream - 52 bytes -> C:\install.ini:coranti
@Alternate Data Stream - 52 bytes -> C:\install.exe:coranti
@Alternate Data Stream - 52 bytes -> C:\globdata.ini:coranti
@Alternate Data Stream - 52 bytes -> C:\eula.3082.txt:coranti
@Alternate Data Stream - 52 bytes -> C:\eula.2052.txt:coranti
@Alternate Data Stream - 52 bytes -> C:\eula.1049.txt:coranti
@Alternate Data Stream - 52 bytes -> C:\eula.1042.txt:coranti
@Alternate Data Stream - 52 bytes -> C:\eula.1041.txt:coranti
@Alternate Data Stream - 52 bytes -> C:\eula.1040.txt:coranti
@Alternate Data Stream - 52 bytes -> C:\eula.1036.txt:coranti
@Alternate Data Stream - 52 bytes -> C:\eula.1033.txt:coranti
@Alternate Data Stream - 52 bytes -> C:\eula.1031.txt:coranti
@Alternate Data Stream - 52 bytes -> C:\eula.1028.txt:coranti
@Alternate Data Stream - 52 bytes -> C:\BOOTSECT.BAK:coranti
@Alternate Data Stream - 52 bytes -> C:\bootmgr:coranti
@Alternate Data Stream - 52 bytes -> C:\bdlog.txt:coranti
@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:430C6D84
@Alternate Data Stream - 115 bytes -> C:\ProgramData\Temp:F297470E
@Alternate Data Stream - 105 bytes -> C:\ProgramData\Temp:DFC5A2B2

< End of report >


cosinus 10.10.2012 12:20

Laufen bei dir zwei Scanner parallel? Coranti und Comodo?

holzdan 10.10.2012 14:07

Hallo
Ja die Einträge von coranti sind mir auch bereits ins Auge gestochen.
Ich habe coranti jedoch nur fuer einen Tag installiert und dann wieder deinstalliert da es auch nix gefunden hat.Deshalb wundert es mich wieso da immer noch : CORANTI steht.Ansonsten habe ich nur die Comodo firewall laufen

cosinus 10.10.2012 15:08

Code:

Ansonsten habe ich nur die Comodo firewall laufen
Würde ich von abraten, nimm max. als Softwarelösung die Windows-Firewall


Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.

Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition ( meistens Laufwerk C: ) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtg4nzy0ywy5/settings_2012-09-04.png

holzdan 10.10.2012 15:37

Code:

16:32:37.0193 2256  TDSS rootkit removing tool 2.8.10.0 Sep 17 2012 19:23:24
16:32:37.0287 2256  ============================================================
16:32:37.0287 2256  Current date / time: 2012/10/10 16:32:37.0287
16:32:37.0287 2256  SystemInfo:
16:32:37.0287 2256 
16:32:37.0287 2256  OS Version: 6.1.7601 ServicePack: 1.0
16:32:37.0287 2256  Product type: Workstation
16:32:37.0287 2256  ComputerName: AAA-PC
16:32:37.0287 2256  UserName: aaa
16:32:37.0287 2256  Windows directory: C:\Windows
16:32:37.0287 2256  System windows directory: C:\Windows
16:32:37.0287 2256  Running under WOW64
16:32:37.0287 2256  Processor architecture: Intel x64
16:32:37.0287 2256  Number of processors: 4
16:32:37.0287 2256  Page size: 0x1000
16:32:37.0287 2256  Boot type: Normal boot
16:32:37.0287 2256  ============================================================
16:32:37.0661 2256  Drive \Device\Harddisk0\DR0 - Size: 0x950B056000 (596.17 Gb), SectorSize: 0x200, Cylinders: 0x13001, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
16:32:37.0661 2256  ============================================================
16:32:37.0661 2256  \Device\Harddisk0\DR0:
16:32:37.0661 2256  MBR partitions:
16:32:37.0661 2256  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1770800, BlocksNum 0x32000
16:32:37.0661 2256  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x17A2800, BlocksNum 0x39E541BB
16:32:37.0692 2256  ============================================================
16:32:37.0739 2256  C: <-> \Device\Harddisk0\DR0\Partition2
16:32:37.0739 2256  ============================================================
16:32:37.0739 2256  Initialize success
16:32:37.0739 2256  ============================================================
16:32:58.0799 3440  ============================================================
16:32:58.0799 3440  Scan started
16:32:58.0799 3440  Mode: Manual; SigCheck; TDLFS;
16:32:58.0799 3440  ============================================================
16:32:59.0095 3440  ================ Scan system memory ========================
16:32:59.0095 3440  System memory - ok
16:32:59.0095 3440  ================ Scan services =============================
16:32:59.0283 3440  [ A87D604AEA360176311474C87A63BB88 ] 1394ohci        C:\Windows\system32\drivers\1394ohci.sys
16:32:59.0329 3440  1394ohci - ok
16:32:59.0392 3440  [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI            C:\Windows\system32\drivers\ACPI.sys
16:32:59.0407 3440  ACPI - ok
16:32:59.0439 3440  [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi        C:\Windows\system32\drivers\acpipmi.sys
16:32:59.0454 3440  AcpiPmi - ok
16:32:59.0563 3440  [ D19C4EE2AC7C47B8F5F84FFF1A789D8A ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
16:32:59.0579 3440  AdobeARMservice - ok
16:32:59.0704 3440  [ B2B64AF436FACCFA854DD397027C5360 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
16:32:59.0719 3440  AdobeFlashPlayerUpdateSvc - ok
16:32:59.0766 3440  [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx        C:\Windows\system32\DRIVERS\adp94xx.sys
16:32:59.0782 3440  adp94xx - ok
16:32:59.0829 3440  [ 597F78224EE9224EA1A13D6350CED962 ] adpahci        C:\Windows\system32\DRIVERS\adpahci.sys
16:32:59.0844 3440  adpahci - ok
16:32:59.0844 3440  [ E109549C90F62FB570B9540C4B148E54 ] adpu320        C:\Windows\system32\DRIVERS\adpu320.sys
16:32:59.0860 3440  adpu320 - ok
16:32:59.0907 3440  [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc    C:\Windows\System32\aelupsvc.dll
16:32:59.0938 3440  AeLookupSvc - ok
16:33:00.0016 3440  [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD            C:\Windows\system32\drivers\afd.sys
16:33:00.0031 3440  AFD - ok
16:33:00.0094 3440  [ 48008D4EA73C1058F36D323A644410D4 ] AgereModemAudio C:\Program Files\LSI SoftModem\agr64svc.exe
16:33:00.0109 3440  AgereModemAudio - ok
16:33:00.0156 3440  [ 068F096925062D112E0F6ADDAF55B764 ] AgereSoftModem  C:\Windows\system32\DRIVERS\agrsm64.sys
16:33:00.0187 3440  AgereSoftModem - ok
16:33:00.0219 3440  [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440          C:\Windows\system32\drivers\agp440.sys
16:33:00.0234 3440  agp440 - ok
16:33:00.0281 3440  [ 3290D6946B5E30E70414990574883DDB ] ALG            C:\Windows\System32\alg.exe
16:33:00.0297 3440  ALG - ok
16:33:00.0328 3440  [ 5812713A477A3AD7363C7438CA2EE038 ] aliide          C:\Windows\system32\drivers\aliide.sys
16:33:00.0343 3440  aliide - ok
16:33:00.0390 3440  [ B3B263B419FC9E7B1D41E61FDAE45BD9 ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
16:33:00.0406 3440  AMD External Events Utility - ok
16:33:00.0437 3440  [ 1FF8B4431C353CE385C875F194924C0C ] amdide          C:\Windows\system32\drivers\amdide.sys
16:33:00.0437 3440  amdide - ok
16:33:00.0484 3440  [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8          C:\Windows\system32\DRIVERS\amdk8.sys
16:33:00.0499 3440  AmdK8 - ok
16:33:00.0702 3440  [ 9A6E9363F7A5E5A06629D9DDC76EE6B5 ] amdkmdag        C:\Windows\system32\DRIVERS\atikmdag.sys
16:33:00.0827 3440  amdkmdag - ok
16:33:00.0936 3440  [ 957A4C13E1981B1701E600EF1E823C68 ] amdkmdap        C:\Windows\system32\DRIVERS\atikmpag.sys
16:33:00.0967 3440  amdkmdap - ok
16:33:01.0014 3440  [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM          C:\Windows\system32\DRIVERS\amdppm.sys
16:33:01.0030 3440  AmdPPM - ok
16:33:01.0077 3440  [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata        C:\Windows\system32\drivers\amdsata.sys
16:33:01.0092 3440  amdsata - ok
16:33:01.0123 3440  [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs          C:\Windows\system32\DRIVERS\amdsbs.sys
16:33:01.0139 3440  amdsbs - ok
16:33:01.0155 3440  [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata        C:\Windows\system32\drivers\amdxata.sys
16:33:01.0170 3440  amdxata - ok
16:33:01.0201 3440  [ 391887990CDAA83DE5C56C3FDE966DA1 ] AmUStor        C:\Windows\system32\drivers\AmUStor.SYS
16:33:01.0217 3440  AmUStor - ok
16:33:01.0248 3440  [ 89A69C3F2F319B43379399547526D952 ] AppID          C:\Windows\system32\drivers\appid.sys
16:33:01.0295 3440  AppID - ok
16:33:01.0326 3440  [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc        C:\Windows\System32\appidsvc.dll
16:33:01.0357 3440  AppIDSvc - ok
16:33:01.0389 3440  [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo        C:\Windows\System32\appinfo.dll
16:33:01.0435 3440  Appinfo - ok
16:33:01.0467 3440  [ C484F8CEB1717C540242531DB7845C4E ] arc            C:\Windows\system32\DRIVERS\arc.sys
16:33:01.0482 3440  arc - ok
16:33:01.0482 3440  [ 019AF6924AEFE7839F61C830227FE79C ] arcsas          C:\Windows\system32\DRIVERS\arcsas.sys
16:33:01.0498 3440  arcsas - ok
16:33:01.0560 3440  [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
16:33:01.0591 3440  AsyncMac - ok
16:33:01.0638 3440  [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi          C:\Windows\system32\drivers\atapi.sys
16:33:01.0654 3440  atapi - ok
16:33:01.0716 3440  [ 78117AEA65177490C87BBD9518A7CCA4 ] athr            C:\Windows\system32\DRIVERS\athrx.sys
16:33:01.0763 3440  athr - ok
16:33:01.0825 3440  [ B0790FF0E25B7A2674296052F2162C1A ] AtiHDAudioService C:\Windows\system32\drivers\AtihdW76.sys
16:33:01.0841 3440  AtiHDAudioService - ok
16:33:02.0044 3440  [ 9A6E9363F7A5E5A06629D9DDC76EE6B5 ] atikmdag        C:\Windows\system32\DRIVERS\atikmdag.sys
16:33:02.0169 3440  atikmdag - ok
16:33:02.0215 3440  [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
16:33:02.0262 3440  AudioEndpointBuilder - ok
16:33:02.0278 3440  [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv        C:\Windows\System32\Audiosrv.dll
16:33:02.0325 3440  AudioSrv - ok
16:33:02.0356 3440  [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV        C:\Windows\System32\AxInstSV.dll
16:33:02.0387 3440  AxInstSV - ok
16:33:02.0449 3440  [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv        C:\Windows\system32\DRIVERS\bxvbda.sys
16:33:02.0465 3440  b06bdrv - ok
16:33:02.0527 3440  [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a        C:\Windows\system32\DRIVERS\b57nd60a.sys
16:33:02.0543 3440  b57nd60a - ok
16:33:02.0590 3440  [ 9E84A931DBEE0292E38ED672F6293A99 ] BCM43XX        C:\Windows\system32\DRIVERS\bcmwl664.sys
16:33:02.0621 3440  BCM43XX - ok
16:33:02.0668 3440  [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC          C:\Windows\System32\bdesvc.dll
16:33:02.0683 3440  BDESVC - ok
16:33:02.0746 3440  [ 16A47CE2DECC9B099349A5F840654746 ] Beep            C:\Windows\system32\drivers\Beep.sys
16:33:02.0777 3440  Beep - ok
16:33:02.0824 3440  [ 82974D6A2FD19445CC5171FC378668A4 ] BFE            C:\Windows\System32\bfe.dll
16:33:02.0871 3440  BFE - ok
16:33:02.0902 3440  [ 1EA7969E3271CBC59E1730697DC74682 ] BITS            C:\Windows\System32\qmgr.dll
16:33:02.0949 3440  BITS - ok
16:33:02.0980 3440  [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive        C:\Windows\system32\DRIVERS\blbdrive.sys
16:33:02.0995 3440  blbdrive - ok
16:33:03.0027 3440  [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
16:33:03.0042 3440  bowser - ok
16:33:03.0089 3440  [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo        C:\Windows\system32\DRIVERS\BrFiltLo.sys
16:33:03.0105 3440  BrFiltLo - ok
16:33:03.0120 3440  [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp        C:\Windows\system32\DRIVERS\BrFiltUp.sys
16:33:03.0136 3440  BrFiltUp - ok
16:33:03.0183 3440  [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser        C:\Windows\System32\browser.dll
16:33:03.0198 3440  Browser - ok
16:33:03.0214 3440  [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid        C:\Windows\System32\Drivers\Brserid.sys
16:33:03.0229 3440  Brserid - ok
16:33:03.0245 3440  [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm        C:\Windows\System32\Drivers\BrSerWdm.sys
16:33:03.0261 3440  BrSerWdm - ok
16:33:03.0292 3440  [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm        C:\Windows\System32\Drivers\BrUsbMdm.sys
16:33:03.0323 3440  BrUsbMdm - ok
16:33:03.0339 3440  [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer        C:\Windows\System32\Drivers\BrUsbSer.sys
16:33:03.0354 3440  BrUsbSer - ok
16:33:03.0385 3440  [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM        C:\Windows\system32\DRIVERS\bthmodem.sys
16:33:03.0401 3440  BTHMODEM - ok
16:33:03.0432 3440  [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv        C:\Windows\system32\bthserv.dll
16:33:03.0479 3440  bthserv - ok
16:33:03.0495 3440  [ B8BD2BB284668C84865658C77574381A ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
16:33:03.0541 3440  cdfs - ok
16:33:03.0588 3440  [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom          C:\Windows\system32\DRIVERS\cdrom.sys
16:33:03.0604 3440  cdrom - ok
16:33:03.0619 3440  [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc    C:\Windows\System32\certprop.dll
16:33:03.0666 3440  CertPropSvc - ok
16:33:03.0697 3440  [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass        C:\Windows\system32\DRIVERS\circlass.sys
16:33:03.0713 3440  circlass - ok
16:33:03.0760 3440  [ FE1EC06F2253F691FE36217C592A0206 ] CLFS            C:\Windows\system32\CLFS.sys
16:33:03.0791 3440  CLFS - ok
16:33:03.0838 3440  [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
16:33:03.0838 3440  clr_optimization_v2.0.50727_32 - ok
16:33:03.0885 3440  [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
16:33:03.0900 3440  clr_optimization_v2.0.50727_64 - ok
16:33:03.0963 3440  [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
16:33:03.0978 3440  clr_optimization_v4.0.30319_32 - ok
16:33:03.0994 3440  [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
16:33:04.0009 3440  clr_optimization_v4.0.30319_64 - ok
16:33:04.0025 3440  [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt          C:\Windows\system32\DRIVERS\CmBatt.sys
16:33:04.0041 3440  CmBatt - ok
16:33:04.0165 3440  [ CEE48CCC4D561DDB19C72F9FB55D28D5 ] cmdAgent        C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
16:33:04.0228 3440  cmdAgent - ok
16:33:04.0259 3440  [ 0599D5A458D4E0E37AB84E9D1C5C73E5 ] cmdGuard        C:\Windows\system32\DRIVERS\cmdguard.sys
16:33:04.0275 3440  cmdGuard - ok
16:33:04.0306 3440  [ 2D3E08C7106F748F9EFF3DEC14142D3E ] cmdHlp          C:\Windows\system32\DRIVERS\cmdhlp.sys
16:33:04.0321 3440  cmdHlp - ok
16:33:04.0353 3440  [ E19D3F095812725D88F9001985B94EDD ] cmdide          C:\Windows\system32\drivers\cmdide.sys
16:33:04.0368 3440  cmdide - ok
16:33:04.0415 3440  [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG            C:\Windows\system32\Drivers\cng.sys
16:33:04.0446 3440  CNG - ok
16:33:04.0477 3440  [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt        C:\Windows\system32\DRIVERS\compbatt.sys
16:33:04.0477 3440  Compbatt - ok
16:33:04.0509 3440  [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus    C:\Windows\system32\drivers\CompositeBus.sys
16:33:04.0540 3440  CompositeBus - ok
16:33:04.0540 3440  COMSysApp - ok
16:33:04.0571 3440  [ 1C827878A998C18847245FE1F34EE597 ] crcdisk        C:\Windows\system32\DRIVERS\crcdisk.sys
16:33:04.0571 3440  crcdisk - ok
16:33:04.0618 3440  [ 4F5414602E2544A4554D95517948B705 ] CryptSvc        C:\Windows\system32\cryptsvc.dll
16:33:04.0633 3440  CryptSvc - ok
16:33:04.0665 3440  [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch      C:\Windows\system32\rpcss.dll
16:33:04.0696 3440  DcomLaunch - ok
16:33:04.0743 3440  [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc      C:\Windows\System32\defragsvc.dll
16:33:04.0789 3440  defragsvc - ok
16:33:04.0821 3440  [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
16:33:04.0852 3440  DfsC - ok
16:33:04.0883 3440  [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp            C:\Windows\system32\dhcpcore.dll
16:33:04.0930 3440  Dhcp - ok
16:33:04.0961 3440  [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache        C:\Windows\system32\drivers\discache.sys
16:33:05.0008 3440  discache - ok
16:33:05.0039 3440  [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk            C:\Windows\system32\DRIVERS\disk.sys
16:33:05.0055 3440  Disk - ok
16:33:05.0101 3440  [ D5BCB77BE83CF99F508943945D46343D ] DKbFltr        C:\Windows\syswow64\Drivers\DKbFltr.sys
16:33:05.0117 3440  DKbFltr - ok
16:33:05.0148 3440  [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache        C:\Windows\System32\dnsrslvr.dll
16:33:05.0164 3440  Dnscache - ok
16:33:05.0195 3440  [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc        C:\Windows\System32\dot3svc.dll
16:33:05.0242 3440  dot3svc - ok
16:33:05.0242 3440  [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS            C:\Windows\system32\dps.dll
16:33:05.0289 3440  DPS - ok
16:33:05.0335 3440  [ 9B19F34400D24DF84C858A421C205754 ] drmkaud        C:\Windows\system32\drivers\drmkaud.sys
16:33:05.0351 3440  drmkaud - ok
16:33:05.0398 3440  [ 46571ED73AE84469DCA53081D33CF3C8 ] dtsoftbus01    C:\Windows\system32\DRIVERS\dtsoftbus01.sys
16:33:05.0413 3440  dtsoftbus01 - ok
16:33:05.0445 3440  [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl        C:\Windows\System32\drivers\dxgkrnl.sys
16:33:05.0476 3440  DXGKrnl - ok
16:33:05.0507 3440  [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost        C:\Windows\System32\eapsvc.dll
16:33:05.0538 3440  EapHost - ok
16:33:05.0632 3440  [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv          C:\Windows\system32\DRIVERS\evbda.sys
16:33:05.0694 3440  ebdrv - ok
16:33:05.0710 3440  [ C118A82CD78818C29AB228366EBF81C3 ] EFS            C:\Windows\System32\lsass.exe
16:33:05.0725 3440  EFS - ok
16:33:05.0772 3440  [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor        C:\Windows\system32\DRIVERS\elxstor.sys
16:33:05.0788 3440  elxstor - ok
16:33:05.0881 3440  [ FB67AA8AC61B9365ADD546139A21BED6 ] ePowerSvc      C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
16:33:05.0897 3440  ePowerSvc - ok
16:33:05.0913 3440  [ 34A3C54752046E79A126E15C51DB409B ] ErrDev          C:\Windows\system32\drivers\errdev.sys
16:33:05.0928 3440  ErrDev - ok
16:33:05.0991 3440  [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem    C:\Windows\system32\es.dll
16:33:06.0037 3440  EventSystem - ok
16:33:06.0069 3440  [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat          C:\Windows\system32\drivers\exfat.sys
16:33:06.0100 3440  exfat - ok
16:33:06.0131 3440  [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat        C:\Windows\system32\drivers\fastfat.sys
16:33:06.0178 3440  fastfat - ok
16:33:06.0225 3440  [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax            C:\Windows\system32\fxssvc.exe
16:33:06.0240 3440  Fax - ok
16:33:06.0271 3440  [ D765D19CD8EF61F650C384F62FAC00AB ] fdc            C:\Windows\system32\DRIVERS\fdc.sys
16:33:06.0287 3440  fdc - ok
16:33:06.0349 3440  [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost        C:\Windows\system32\fdPHost.dll
16:33:06.0381 3440  fdPHost - ok
16:33:06.0396 3440  [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub        C:\Windows\system32\fdrespub.dll
16:33:06.0443 3440  FDResPub - ok
16:33:06.0459 3440  [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
16:33:06.0459 3440  FileInfo - ok
16:33:06.0490 3440  [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace      C:\Windows\system32\drivers\filetrace.sys
16:33:06.0521 3440  Filetrace - ok
16:33:06.0568 3440  [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk        C:\Windows\system32\DRIVERS\flpydisk.sys
16:33:06.0583 3440  flpydisk - ok
16:33:06.0630 3440  [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
16:33:06.0646 3440  FltMgr - ok
16:33:06.0708 3440  [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache      C:\Windows\system32\FntCache.dll
16:33:06.0724 3440  FontCache - ok
16:33:06.0771 3440  [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
16:33:06.0786 3440  FontCache3.0.0.0 - ok
16:33:06.0802 3440  [ D43703496149971890703B4B1B723EAC ] FsDepends      C:\Windows\system32\drivers\FsDepends.sys
16:33:06.0817 3440  FsDepends - ok
16:33:06.0833 3440  [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
16:33:06.0849 3440  Fs_Rec - ok
16:33:06.0880 3440  [ 1F7B25B858FA27015169FE95E54108ED ] fvevol          C:\Windows\system32\DRIVERS\fvevol.sys
16:33:06.0895 3440  fvevol - ok
16:33:06.0927 3440  [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx        C:\Windows\system32\DRIVERS\gagp30kx.sys
16:33:06.0942 3440  gagp30kx - ok
16:33:06.0973 3440  [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc          C:\Windows\System32\gpsvc.dll
16:33:07.0020 3440  gpsvc - ok
16:33:07.0114 3440  [ 816FD5A6F3C2F3D600900096632FC60E ] Greg_Service    C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
16:33:07.0145 3440  Greg_Service - ok
16:33:07.0207 3440  [ 8F0DE4FEF8201E306F9938B0905AC96A ] gupdate        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
16:33:07.0223 3440  gupdate - ok
16:33:07.0239 3440  [ 8F0DE4FEF8201E306F9938B0905AC96A ] gupdatem        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
16:33:07.0254 3440  gupdatem - ok
16:33:07.0285 3440  [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir        C:\Windows\system32\drivers\hcw85cir.sys
16:33:07.0301 3440  hcw85cir - ok
16:33:07.0348 3440  [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
16:33:07.0363 3440  HdAudAddService - ok
16:33:07.0395 3440  [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus        C:\Windows\system32\drivers\HDAudBus.sys
16:33:07.0410 3440  HDAudBus - ok
16:33:07.0457 3440  [ B6AC71AAA2B10848F57FC49D55A651AF ] HECIx64        C:\Windows\system32\DRIVERS\HECIx64.sys
16:33:07.0473 3440  HECIx64 - ok
16:33:07.0504 3440  [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt        C:\Windows\system32\DRIVERS\HidBatt.sys
16:33:07.0504 3440  HidBatt - ok
16:33:07.0519 3440  [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth          C:\Windows\system32\DRIVERS\hidbth.sys
16:33:07.0551 3440  HidBth - ok
16:33:07.0551 3440  [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr          C:\Windows\system32\DRIVERS\hidir.sys
16:33:07.0582 3440  HidIr - ok
16:33:07.0613 3440  [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv        C:\Windows\system32\hidserv.dll
16:33:07.0644 3440  hidserv - ok
16:33:07.0675 3440  [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
16:33:07.0691 3440  HidUsb - ok
16:33:07.0753 3440  [ FD1837DEE0A1D7F180D7B301C0656511 ] HiPatchService  C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
16:33:07.0753 3440  HiPatchService ( UnsignedFile.Multi.Generic ) - warning
16:33:07.0753 3440  HiPatchService - detected UnsignedFile.Multi.Generic (1)
16:33:07.0785 3440  [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc          C:\Windows\system32\kmsvc.dll
16:33:07.0816 3440  hkmsvc - ok
16:33:07.0863 3440  [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
16:33:07.0878 3440  HomeGroupListener - ok
16:33:07.0894 3440  [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
16:33:07.0909 3440  HomeGroupProvider - ok
16:33:07.0956 3440  [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD          C:\Windows\system32\drivers\HpSAMD.sys
16:33:07.0972 3440  HpSAMD - ok
16:33:08.0003 3440  [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
16:33:08.0050 3440  HTTP - ok
16:33:08.0097 3440  [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy        C:\Windows\system32\drivers\hwpolicy.sys
16:33:08.0097 3440  hwpolicy - ok
16:33:08.0143 3440  [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt        C:\Windows\system32\drivers\i8042prt.sys
16:33:08.0143 3440  i8042prt - ok
16:33:08.0221 3440  [ 7548066DF68A8A1A56B043359F915F37 ] IAANTMON        C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
16:33:08.0237 3440  IAANTMON - ok
16:33:08.0268 3440  [ 8180A2392E732E8871589B54FAB6991F ] iaStor          C:\Windows\system32\DRIVERS\iaStor.sys
16:33:08.0284 3440  iaStor - ok
16:33:08.0320 3440  [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV        C:\Windows\system32\drivers\iaStorV.sys
16:33:08.0351 3440  iaStorV - ok
16:33:08.0386 3440  [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc          C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
16:33:08.0419 3440  idsvc - ok
16:33:08.0565 3440  [ A87261EF1546325B559374F5689CF5BC ] igfx            C:\Windows\system32\DRIVERS\igdkmd64.sys
16:33:08.0643 3440  igfx - ok
16:33:08.0674 3440  [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp          C:\Windows\system32\DRIVERS\iirsp.sys
16:33:08.0692 3440  iirsp - ok
16:33:08.0743 3440  [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT          C:\Windows\System32\ikeext.dll
16:33:08.0790 3440  IKEEXT - ok
16:33:08.0824 3440  [ DD587A55390ED2295BCE6D36AD567DA9 ] Impcd          C:\Windows\system32\DRIVERS\Impcd.sys
16:33:08.0839 3440  Impcd - ok
16:33:08.0873 3440  [ EFFF0AFD27CC97BF0E5E0BAB78419DE7 ] inspect        C:\Windows\system32\DRIVERS\inspect.sys
16:33:08.0889 3440  inspect - ok
16:33:09.0016 3440  [ 150AC23F21DBDBF8488408BA944B0D65 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
16:33:09.0094 3440  IntcAzAudAddService - ok
16:33:09.0125 3440  [ F00F20E70C6EC3AA366910083A0518AA ] intelide        C:\Windows\system32\drivers\intelide.sys
16:33:09.0125 3440  intelide - ok
16:33:09.0156 3440  [ ADA036632C664CAA754079041CF1F8C1 ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
16:33:09.0172 3440  intelppm - ok
16:33:09.0219 3440  [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum      C:\Windows\system32\ipbusenum.dll
16:33:09.0250 3440  IPBusEnum - ok
16:33:09.0286 3440  [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
16:33:09.0337 3440  IpFilterDriver - ok
16:33:09.0367 3440  [ A34A587FFFD45FA649FBA6D03784D257 ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
16:33:09.0415 3440  iphlpsvc - ok
16:33:09.0434 3440  [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV        C:\Windows\system32\drivers\IPMIDrv.sys
16:33:09.0449 3440  IPMIDRV - ok
16:33:09.0485 3440  [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT          C:\Windows\system32\drivers\ipnat.sys
16:33:09.0534 3440  IPNAT - ok
16:33:09.0565 3440  [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM          C:\Windows\system32\drivers\irenum.sys
16:33:09.0581 3440  IRENUM - ok
16:33:09.0596 3440  [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp          C:\Windows\system32\drivers\isapnp.sys
16:33:09.0612 3440  isapnp - ok
16:33:09.0659 3440  [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt        C:\Windows\system32\drivers\msiscsi.sys
16:33:09.0674 3440  iScsiPrt - ok
16:33:09.0706 3440  [ D85F3F18E44F7447B5F1BA5C85BAEB7C ] k57nd60a        C:\Windows\system32\DRIVERS\k57nd60a.sys
16:33:09.0721 3440  k57nd60a - ok
16:33:09.0752 3440  [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass        C:\Windows\system32\drivers\kbdclass.sys
16:33:09.0768 3440  kbdclass - ok
16:33:09.0799 3440  [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid          C:\Windows\system32\drivers\kbdhid.sys
16:33:09.0799 3440  kbdhid - ok
16:33:09.0830 3440  [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso          C:\Windows\system32\lsass.exe
16:33:09.0846 3440  KeyIso - ok
16:33:09.0877 3440  [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
16:33:09.0893 3440  KSecDD - ok
16:33:09.0908 3440  [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg        C:\Windows\system32\Drivers\ksecpkg.sys
16:33:09.0924 3440  KSecPkg - ok
16:33:09.0955 3440  [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk        C:\Windows\system32\drivers\ksthunk.sys
16:33:10.0002 3440  ksthunk - ok
16:33:10.0033 3440  [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm          C:\Windows\system32\msdtckrm.dll
16:33:10.0080 3440  KtmRm - ok
16:33:10.0111 3440  [ 2AC603C3188C704CFCE353659AA7AD71 ] L1E            C:\Windows\system32\DRIVERS\L1E62x64.sys
16:33:10.0127 3440  L1E - ok
16:33:10.0158 3440  [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer    C:\Windows\system32\srvsvc.dll
16:33:10.0205 3440  LanmanServer - ok
16:33:10.0236 3440  [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
16:33:10.0267 3440  LanmanWorkstation - ok
16:33:10.0298 3440  [ 1538831CF8AD2979A04C423779465827 ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
16:33:10.0330 3440  lltdio - ok
16:33:10.0376 3440  [ C1185803384AB3FEED115F79F109427F ] lltdsvc        C:\Windows\System32\lltdsvc.dll
16:33:10.0423 3440  lltdsvc - ok
16:33:10.0423 3440  [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts        C:\Windows\System32\lmhsvc.dll
16:33:10.0470 3440  lmhosts - ok
16:33:10.0532 3440  [ 7485FBCEF9136F530953575E2977859D ] LMS            C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
16:33:10.0548 3440  LMS - ok
16:33:10.0579 3440  [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC          C:\Windows\system32\DRIVERS\lsi_fc.sys
16:33:10.0595 3440  LSI_FC - ok
16:33:10.0610 3440  [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS        C:\Windows\system32\DRIVERS\lsi_sas.sys
16:33:10.0626 3440  LSI_SAS - ok
16:33:10.0642 3440  [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2        C:\Windows\system32\DRIVERS\lsi_sas2.sys
16:33:10.0642 3440  LSI_SAS2 - ok
16:33:10.0657 3440  [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI        C:\Windows\system32\DRIVERS\lsi_scsi.sys
16:33:10.0673 3440  LSI_SCSI - ok
16:33:10.0688 3440  [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv          C:\Windows\system32\drivers\luafv.sys
16:33:10.0720 3440  luafv - ok
16:33:10.0782 3440  [ 1B4DBCAA0321BBB76255983148051F09 ] massfilter      C:\Windows\system32\drivers\massfilter.sys
16:33:10.0798 3440  massfilter - ok
16:33:10.0844 3440  [ B9FC4CCE5758B816F27DD4D1EED11841 ] MBAMProtector  C:\Windows\system32\drivers\mbam.sys
16:33:10.0860 3440  MBAMProtector - ok
16:33:10.0938 3440  [ 0DCF16B1449811EFA47AB52CAC84093C ] MBAMScheduler  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
16:33:10.0954 3440  MBAMScheduler - ok
16:33:11.0000 3440  [ 9EAABA4D601004BEA4DAA6E146E19A96 ] MBAMService    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
16:33:11.0016 3440  MBAMService - ok
16:33:11.0047 3440  [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas        C:\Windows\system32\DRIVERS\megasas.sys
16:33:11.0063 3440  megasas - ok
16:33:11.0078 3440  [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR          C:\Windows\system32\DRIVERS\MegaSR.sys
16:33:11.0094 3440  MegaSR - ok
16:33:11.0141 3440  [ E40E80D0304A73E8D269F7141D77250B ] MMCSS          C:\Windows\system32\mmcss.dll
16:33:11.0172 3440  MMCSS - ok
16:33:11.0203 3440  [ 800BA92F7010378B09F9ED9270F07137 ] Modem          C:\Windows\system32\drivers\modem.sys
16:33:11.0234 3440  Modem - ok
16:33:11.0234 3440  [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor        C:\Windows\system32\DRIVERS\monitor.sys
16:33:11.0250 3440  monitor - ok
16:33:11.0297 3440  [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
16:33:11.0312 3440  mouclass - ok
16:33:11.0312 3440  [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
16:33:11.0328 3440  mouhid - ok
16:33:11.0359 3440  [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr        C:\Windows\system32\drivers\mountmgr.sys
16:33:11.0375 3440  mountmgr - ok
16:33:11.0437 3440  [ 05BF204EC0E82CC4A054DB189C8A3D84 ] MpFilter        C:\Windows\system32\DRIVERS\MpFilter.sys
16:33:11.0453 3440  MpFilter - ok
16:33:11.0484 3440  [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio            C:\Windows\system32\drivers\mpio.sys
16:33:11.0500 3440  mpio - ok
16:33:11.0531 3440  [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
16:33:11.0562 3440  mpsdrv - ok
16:33:11.0609 3440  [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc          C:\Windows\system32\mpssvc.dll
16:33:11.0656 3440  MpsSvc - ok
16:33:11.0702 3440  [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
16:33:11.0734 3440  MRxDAV - ok
16:33:11.0796 3440  [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
16:33:11.0812 3440  mrxsmb - ok
16:33:11.0827 3440  [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
16:33:11.0843 3440  mrxsmb10 - ok
16:33:11.0874 3440  [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
16:33:11.0874 3440  mrxsmb20 - ok
16:33:11.0912 3440  [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci          C:\Windows\system32\drivers\msahci.sys
16:33:11.0928 3440  msahci - ok
16:33:11.0961 3440  [ DB801A638D011B9633829EB6F663C900 ] msdsm          C:\Windows\system32\drivers\msdsm.sys
16:33:11.0977 3440  msdsm - ok
16:33:11.0993 3440  [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC          C:\Windows\System32\msdtc.exe
16:33:12.0008 3440  MSDTC - ok
16:33:12.0024 3440  [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs            C:\Windows\system32\drivers\Msfs.sys
16:33:12.0071 3440  Msfs - ok
16:33:12.0086 3440  [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf      C:\Windows\System32\drivers\mshidkmdf.sys
16:33:12.0117 3440  mshidkmdf - ok
16:33:12.0149 3440  [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
16:33:12.0164 3440  msisadrv - ok
16:33:12.0180 3440  [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI        C:\Windows\system32\iscsiexe.dll
16:33:12.0227 3440  MSiSCSI - ok
16:33:12.0227 3440  msiserver - ok
16:33:12.0258 3440  [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV        C:\Windows\system32\drivers\MSKSSRV.sys
16:33:12.0305 3440  MSKSSRV - ok
16:33:12.0320 3440  [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
16:33:12.0351 3440  MSPCLOCK - ok
16:33:12.0367 3440  [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM          C:\Windows\system32\drivers\MSPQM.sys
16:33:12.0414 3440  MSPQM - ok
16:33:12.0445 3440  [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC          C:\Windows\system32\drivers\MsRPC.sys
16:33:12.0461 3440  MsRPC - ok
16:33:12.0492 3440  [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios        C:\Windows\system32\drivers\mssmbios.sys
16:33:12.0507 3440  mssmbios - ok
16:33:12.0539 3440  [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE          C:\Windows\system32\drivers\MSTEE.sys
16:33:12.0585 3440  MSTEE - ok
16:33:12.0601 3440  [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig        C:\Windows\system32\DRIVERS\MTConfig.sys
16:33:12.0617 3440  MTConfig - ok
16:33:12.0653 3440  [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup            C:\Windows\system32\Drivers\mup.sys
16:33:12.0671 3440  Mup - ok
16:33:12.0707 3440  [ 6FFECC25B39DC7652A0CEC0ADA9DB589 ] mwlPSDFilter    C:\Windows\system32\DRIVERS\mwlPSDFilter.sys
16:33:12.0707 3440  mwlPSDFilter - ok
16:33:12.0770 3440  [ 0BEFE32CA56D6EE89D58175725596A85 ] mwlPSDNServ    C:\Windows\system32\DRIVERS\mwlPSDNServ.sys
16:33:12.0770 3440  mwlPSDNServ - ok
16:33:12.0801 3440  [ D43BC633B8660463E446E28E14A51262 ] mwlPSDVDisk    C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys
16:33:12.0816 3440  mwlPSDVDisk - ok
16:33:12.0897 3440  [ 2F139207F618EC2933830227EEFFDDB4 ] MWLService      C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe
16:33:12.0912 3440  MWLService - ok
16:33:12.0959 3440  [ 582AC6D9873E31DFA28A4547270862DD ] napagent        C:\Windows\system32\qagentRT.dll
16:33:12.0993 3440  napagent - ok
16:33:13.0055 3440  [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP    C:\Windows\system32\DRIVERS\nwifi.sys
16:33:13.0087 3440  NativeWifiP - ok
16:33:13.0165 3440  [ 760E38053BF56E501D562B70AD796B88 ] NDIS            C:\Windows\system32\drivers\ndis.sys
16:33:13.0180 3440  NDIS - ok
16:33:13.0211 3440  [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap        C:\Windows\system32\DRIVERS\ndiscap.sys
16:33:13.0243 3440  NdisCap - ok
16:33:13.0274 3440  [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
16:33:13.0321 3440  NdisTapi - ok
16:33:13.0367 3440  [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio        C:\Windows\system32\DRIVERS\ndisuio.sys
16:33:13.0399 3440  Ndisuio - ok
16:33:13.0430 3440  [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan        C:\Windows\system32\DRIVERS\ndiswan.sys
16:33:13.0477 3440  NdisWan - ok
16:33:13.0492 3440  [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy        C:\Windows\system32\drivers\NDProxy.sys
16:33:13.0539 3440  NDProxy - ok
16:33:13.0570 3440  [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS        C:\Windows\system32\DRIVERS\netbios.sys
16:33:13.0617 3440  NetBIOS - ok
16:33:13.0633 3440  [ 09594D1089C523423B32A4229263F068 ] NetBT          C:\Windows\system32\DRIVERS\netbt.sys
16:33:13.0679 3440  NetBT - ok
16:33:13.0711 3440  [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon        C:\Windows\system32\lsass.exe
16:33:13.0711 3440  Netlogon - ok
16:33:13.0757 3440  [ 847D3AE376C0817161A14A82C8922A9E ] Netman          C:\Windows\System32\netman.dll
16:33:13.0789 3440  Netman - ok
16:33:13.0804 3440  [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm        C:\Windows\System32\netprofm.dll
16:33:13.0851 3440  netprofm - ok
16:33:13.0867 3440  [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
16:33:13.0882 3440  NetTcpPortSharing - ok
16:33:13.0913 3440  [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960        C:\Windows\system32\DRIVERS\nfrd960.sys
16:33:13.0929 3440  nfrd960 - ok
16:33:13.0945 3440  [ 5FF89F20317309D28AC1EDEB0CD1BA72 ] NisDrv          C:\Windows\system32\DRIVERS\NisDrvWFP.sys
16:33:13.0960 3440  NisDrv - ok
16:33:14.0007 3440  [ 1EE99A89CC788ADA662441D1E9830529 ] NlaSvc          C:\Windows\System32\nlasvc.dll
16:33:14.0054 3440  NlaSvc - ok
16:33:14.0069 3440  [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs            C:\Windows\system32\drivers\Npfs.sys
16:33:14.0101 3440  Npfs - ok
16:33:14.0132 3440  [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi            C:\Windows\system32\nsisvc.dll
16:33:14.0179 3440  nsi - ok
16:33:14.0179 3440  [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
16:33:14.0210 3440  nsiproxy - ok
16:33:14.0272 3440  [ A2F74975097F52A00745F9637451FDD8 ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
16:33:14.0303 3440  Ntfs - ok
16:33:14.0381 3440  [ 14E66F603FB187713AEB02AD3B0390CF ] NTI IScheduleSvc C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
16:33:14.0381 3440  NTI IScheduleSvc - ok
16:33:14.0428 3440  [ FD324CCE1D4D5BB5AF65F8E55B462C7E ] NTIBackupSvc    C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
16:33:14.0428 3440  NTIBackupSvc - ok
16:33:14.0459 3440  [ 64DDD0DEE976302F4BD93E5EFCC2F013 ] NTIDrvr        C:\Windows\system32\drivers\NTIDrvr.sys
16:33:14.0475 3440  NTIDrvr - ok
16:33:14.0491 3440  [ 3F6268A2EC33CD38CF75C880AF8DED42 ] NTISchedulerSvc C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
16:33:14.0506 3440  NTISchedulerSvc - ok
16:33:14.0522 3440  [ 9899284589F75FA8724FF3D16AED75C1 ] Null            C:\Windows\system32\drivers\Null.sys
16:33:14.0569 3440  Null - ok
16:33:14.0584 3440  [ 0A92CB65770442ED0DC44834632F66AD ] nvraid          C:\Windows\system32\drivers\nvraid.sys
16:33:14.0600 3440  nvraid - ok
16:33:14.0615 3440  [ DAB0E87525C10052BF65F06152F37E4A ] nvstor          C:\Windows\system32\drivers\nvstor.sys
16:33:14.0631 3440  nvstor - ok
16:33:14.0662 3440  [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
16:33:14.0678 3440  nv_agp - ok
16:33:14.0771 3440  [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv          C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
16:33:14.0787 3440  odserv - ok
16:33:14.0818 3440  [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394        C:\Windows\system32\drivers\ohci1394.sys
16:33:14.0834 3440  ohci1394 - ok
16:33:14.0883 3440  [ 5A432A042DAE460ABE7199B758E8606C ] ose            C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
16:33:14.0899 3440  ose - ok
16:33:14.0930 3440  [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc        C:\Windows\system32\pnrpsvc.dll
16:33:14.0945 3440  p2pimsvc - ok
16:33:14.0961 3440  [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc          C:\Windows\system32\p2psvc.dll
16:33:14.0992 3440  p2psvc - ok
16:33:15.0023 3440  [ 0086431C29C35BE1DBC43F52CC273887 ] Parport        C:\Windows\system32\DRIVERS\parport.sys
16:33:15.0039 3440  Parport - ok
16:33:15.0055 3440  Partizan - ok
16:33:15.0086 3440  [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr        C:\Windows\system32\drivers\partmgr.sys
16:33:15.0101 3440  partmgr - ok
16:33:15.0117 3440  [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc          C:\Windows\System32\pcasvc.dll
16:33:15.0148 3440  PcaSvc - ok
16:33:15.0164 3440  [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci            C:\Windows\system32\drivers\pci.sys
16:33:15.0179 3440  pci - ok
16:33:15.0195 3440  [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide          C:\Windows\system32\drivers\pciide.sys
16:33:15.0211 3440  pciide - ok
16:33:15.0242 3440  [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia          C:\Windows\system32\DRIVERS\pcmcia.sys
16:33:15.0257 3440  pcmcia - ok
16:33:15.0289 3440  [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw            C:\Windows\system32\drivers\pcw.sys
16:33:15.0289 3440  pcw - ok
16:33:15.0320 3440  [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
16:33:15.0367 3440  PEAUTH - ok
16:33:15.0445 3440  [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost        C:\Windows\SysWow64\perfhost.exe
16:33:15.0460 3440  PerfHost - ok
16:33:15.0507 3440  [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla            C:\Windows\system32\pla.dll
16:33:15.0569 3440  pla - ok
16:33:15.0601 3440  [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
16:33:15.0616 3440  PlugPlay - ok
16:33:15.0616 3440  [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg    C:\Windows\system32\pnrpauto.dll
16:33:15.0632 3440  PNRPAutoReg - ok
16:33:15.0663 3440  [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc        C:\Windows\system32\pnrpsvc.dll
16:33:15.0679 3440  PNRPsvc - ok
16:33:15.0694 3440  [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent    C:\Windows\System32\ipsecsvc.dll
16:33:15.0741 3440  PolicyAgent - ok
16:33:15.0772 3440  [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power          C:\Windows\system32\umpo.dll
16:33:15.0819 3440  Power - ok
16:33:15.0850 3440  [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
16:33:15.0881 3440  PptpMiniport - ok
16:33:15.0928 3440  [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor      C:\Windows\system32\DRIVERS\processr.sys
16:33:15.0944 3440  Processor - ok
16:33:15.0959 3440  [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc        C:\Windows\system32\profsvc.dll
16:33:15.0975 3440  ProfSvc - ok
16:33:15.0991 3440  [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
16:33:16.0006 3440  ProtectedStorage - ok
16:33:16.0053 3440  [ 0557CF5A2556BD58E26384169D72438D ] Psched          C:\Windows\system32\DRIVERS\pacer.sys
16:33:16.0084 3440  Psched - ok
16:33:16.0131 3440  [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300          C:\Windows\system32\DRIVERS\ql2300.sys
16:33:16.0162 3440  ql2300 - ok
16:33:16.0209 3440  [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx          C:\Windows\system32\DRIVERS\ql40xx.sys
16:33:16.0209 3440  ql40xx - ok
16:33:16.0240 3440  [ 906191634E99AEA92C4816150BDA3732 ] QWAVE          C:\Windows\system32\qwave.dll
16:33:16.0271 3440  QWAVE - ok
16:33:16.0287 3440  [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
16:33:16.0303 3440  QWAVEdrv - ok
16:33:16.0318 3440  [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
16:33:16.0365 3440  RasAcd - ok
16:33:16.0396 3440  [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn    C:\Windows\system32\DRIVERS\AgileVpn.sys
16:33:16.0443 3440  RasAgileVpn - ok
16:33:16.0459 3440  [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto        C:\Windows\System32\rasauto.dll
16:33:16.0490 3440  RasAuto - ok
16:33:16.0521 3440  [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp        C:\Windows\system32\DRIVERS\rasl2tp.sys
16:33:16.0568 3440  Rasl2tp - ok
16:33:16.0615 3440  [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan          C:\Windows\System32\rasmans.dll
16:33:16.0646 3440  RasMan - ok
16:33:16.0677 3440  [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
16:33:16.0708 3440  RasPppoe - ok
16:33:16.0739 3440  [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp        C:\Windows\system32\DRIVERS\rassstp.sys
16:33:16.0786 3440  RasSstp - ok
16:33:16.0802 3440  [ 77F665941019A1594D887A74F301FA2F ] rdbss          C:\Windows\system32\DRIVERS\rdbss.sys
16:33:16.0849 3440  rdbss - ok
16:33:16.0880 3440  [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus          C:\Windows\system32\DRIVERS\rdpbus.sys
16:33:16.0895 3440  rdpbus - ok
16:33:16.0911 3440  [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
16:33:16.0942 3440  RDPCDD - ok
16:33:16.0958 3440  [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
16:33:17.0005 3440  RDPENCDD - ok
16:33:17.0005 3440  [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP        C:\Windows\system32\drivers\rdprefmp.sys
16:33:17.0036 3440  RDPREFMP - ok
16:33:17.0067 3440  [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD          C:\Windows\system32\drivers\RDPWD.sys
16:33:17.0083 3440  RDPWD - ok
16:33:17.0129 3440  [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost        C:\Windows\system32\drivers\rdyboost.sys
16:33:17.0145 3440  rdyboost - ok
16:33:17.0192 3440  [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess    C:\Windows\System32\mprdim.dll
16:33:17.0223 3440  RemoteAccess - ok
16:33:17.0270 3440  [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry  C:\Windows\system32\regsvc.dll
16:33:17.0317 3440  RemoteRegistry - ok
16:33:17.0332 3440  [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper    C:\Windows\System32\RpcEpMap.dll
16:33:17.0379 3440  RpcEptMapper - ok
16:33:17.0410 3440  [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator      C:\Windows\system32\locator.exe
16:33:17.0426 3440  RpcLocator - ok
16:33:17.0473 3440  [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs          C:\Windows\system32\rpcss.dll
16:33:17.0519 3440  RpcSs - ok
16:33:17.0551 3440  [ DDC86E4F8E7456261E637E3552E804FF ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
16:33:17.0597 3440  rspndr - ok
16:33:17.0675 3440  [ B5A4B7D779CF4070DF408DE18BD33B02 ] RS_Service      C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe
16:33:17.0675 3440  RS_Service ( UnsignedFile.Multi.Generic ) - warning
16:33:17.0675 3440  RS_Service - detected UnsignedFile.Multi.Generic (1)
16:33:17.0738 3440  [ 7421A35C45484B95E83B5E9E107CEFC2 ] RTHDMIAzAudService C:\Windows\system32\drivers\RtHDMIVX.sys
16:33:17.0753 3440  RTHDMIAzAudService - ok
16:33:17.0753 3440  [ C118A82CD78818C29AB228366EBF81C3 ] SamSs          C:\Windows\system32\lsass.exe
16:33:17.0769 3440  SamSs - ok
16:33:17.0800 3440  [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
16:33:17.0800 3440  sbp2port - ok
16:33:17.0847 3440  [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr        C:\Windows\System32\SCardSvr.dll
16:33:17.0878 3440  SCardSvr - ok
16:33:17.0909 3440  [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter        C:\Windows\system32\DRIVERS\scfilter.sys
16:33:17.0941 3440  scfilter - ok
16:33:17.0987 3440  [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule        C:\Windows\system32\schedsvc.dll
16:33:18.0034 3440  Schedule - ok
16:33:18.0050 3440  [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc    C:\Windows\System32\certprop.dll
16:33:18.0097 3440  SCPolicySvc - ok
16:33:18.0128 3440  [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
16:33:18.0143 3440  SDRSVC - ok
16:33:18.0175 3440  [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv          C:\Windows\system32\drivers\secdrv.sys
16:33:18.0206 3440  secdrv - ok
16:33:18.0237 3440  [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon        C:\Windows\system32\seclogon.dll
16:33:18.0268 3440  seclogon - ok
16:33:18.0299 3440  [ C32AB8FA018EF34C0F113BD501436D21 ] SENS            C:\Windows\System32\sens.dll
16:33:18.0346 3440  SENS - ok
16:33:18.0377 3440  [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc        C:\Windows\system32\sensrsvc.dll
16:33:18.0393 3440  SensrSvc - ok
16:33:18.0424 3440  [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum        C:\Windows\system32\DRIVERS\serenum.sys
16:33:18.0440 3440  Serenum - ok
16:33:18.0455 3440  [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial          C:\Windows\system32\DRIVERS\serial.sys
16:33:18.0471 3440  Serial - ok
16:33:18.0518 3440  [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse        C:\Windows\system32\DRIVERS\sermouse.sys
16:33:18.0533 3440  sermouse - ok
16:33:18.0580 3440  [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv      C:\Windows\system32\sessenv.dll
16:33:18.0627 3440  SessionEnv - ok
16:33:18.0643 3440  [ A554811BCD09279536440C964AE35BBF ] sffdisk        C:\Windows\system32\drivers\sffdisk.sys
16:33:18.0658 3440  sffdisk - ok
16:33:18.0658 3440  [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
16:33:18.0674 3440  sffp_mmc - ok
16:33:18.0674 3440  [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd        C:\Windows\system32\drivers\sffp_sd.sys
16:33:18.0689 3440  sffp_sd - ok
16:33:18.0721 3440  [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy        C:\Windows\system32\DRIVERS\sfloppy.sys
16:33:18.0736 3440  sfloppy - ok
16:33:18.0767 3440  [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess    C:\Windows\System32\ipnathlp.dll
16:33:18.0799 3440  SharedAccess - ok
16:33:18.0830 3440  [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
16:33:18.0877 3440  ShellHWDetection - ok
16:33:18.0892 3440  [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2        C:\Windows\system32\DRIVERS\SiSRaid2.sys
16:33:18.0908 3440  SiSRaid2 - ok
16:33:18.0923 3440  [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4        C:\Windows\system32\DRIVERS\sisraid4.sys
16:33:18.0955 3440  SiSRaid4 - ok
16:33:18.0973 3440  [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate    C:\Program Files (x86)\Skype\Updater\Updater.exe
16:33:18.0988 3440  SkypeUpdate - ok
16:33:19.0020 3440  [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb            C:\Windows\system32\DRIVERS\smb.sys
16:33:19.0066 3440  Smb - ok
16:33:19.0082 3440  [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
16:33:19.0098 3440  SNMPTRAP - ok
16:33:19.0129 3440  [ B9E31E5CACDFE584F34F730A677803F9 ] spldr          C:\Windows\system32\drivers\spldr.sys
16:33:19.0144 3440  spldr - ok
16:33:19.0176 3440  [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler        C:\Windows\System32\spoolsv.exe
16:33:19.0191 3440  Spooler - ok
16:33:19.0272 3440  [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc          C:\Windows\system32\sppsvc.exe
16:33:19.0350 3440  sppsvc - ok
16:33:19.0381 3440  [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify    C:\Windows\system32\sppuinotify.dll
16:33:19.0417 3440  sppuinotify - ok
16:33:19.0464 3440  [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv            C:\Windows\system32\DRIVERS\srv.sys
16:33:19.0479 3440  srv - ok
16:33:19.0495 3440  [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
16:33:19.0511 3440  srv2 - ok
16:33:19.0526 3440  [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
16:33:19.0542 3440  srvnet - ok
16:33:19.0589 3440  [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV        C:\Windows\System32\ssdpsrv.dll
16:33:19.0635 3440  SSDPSRV - ok
16:33:19.0651 3440  [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc        C:\Windows\system32\sstpsvc.dll
16:33:19.0682 3440  SstpSvc - ok
16:33:19.0713 3440  Steam Client Service - ok
16:33:19.0745 3440  [ F3817967ED533D08327DC73BC4D5542A ] stexstor        C:\Windows\system32\DRIVERS\stexstor.sys
16:33:19.0760 3440  stexstor - ok
16:33:19.0791 3440  [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc          C:\Windows\System32\wiaservc.dll
16:33:19.0807 3440  stisvc - ok
16:33:19.0838 3440  [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum          C:\Windows\system32\drivers\swenum.sys
16:33:19.0854 3440  swenum - ok
16:33:19.0869 3440  [ E08E46FDD841B7184194011CA1955A0B ] swprv          C:\Windows\System32\swprv.dll
16:33:19.0916 3440  swprv - ok
16:33:19.0963 3440  [ ED6D1424E5B0C21A57B28DD8508D6843 ] SynTP          C:\Windows\system32\DRIVERS\SynTP.sys
16:33:19.0979 3440  SynTP - ok
16:33:20.0041 3440  [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain        C:\Windows\system32\sysmain.dll
16:33:20.0072 3440  SysMain - ok
16:33:20.0088 3440  [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
16:33:20.0119 3440  TabletInputService - ok
16:33:20.0166 3440  [ F0B9D3ED88E56D3CD713DFF21E42AAF0 ] tap0901        C:\Windows\system32\DRIVERS\tap0901.sys
16:33:20.0166 3440  tap0901 - ok
16:33:20.0197 3440  [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv        C:\Windows\System32\tapisrv.dll
16:33:20.0228 3440  TapiSrv - ok
16:33:20.0259 3440  [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS            C:\Windows\System32\tbssvc.dll
16:33:20.0291 3440  TBS - ok
16:33:20.0353 3440  [ F782CAD3CEDBB3F9FFE3BF2775D92DDC ] Tcpip          C:\Windows\system32\drivers\tcpip.sys
16:33:20.0400 3440  Tcpip - ok
16:33:20.0447 3440  [ F782CAD3CEDBB3F9FFE3BF2775D92DDC ] TCPIP6          C:\Windows\system32\DRIVERS\tcpip.sys
16:33:20.0493 3440  TCPIP6 - ok
16:33:20.0525 3440  [ DF687E3D8836BFB04FCC0615BF15A519 ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
16:33:20.0556 3440  tcpipreg - ok
16:33:20.0587 3440  [ 3371D21011695B16333A3934340C4E7C ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
16:33:20.0587 3440  TDPIPE - ok
16:33:20.0618 3440  [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP          C:\Windows\system32\drivers\tdtcp.sys
16:33:20.0634 3440  TDTCP - ok
16:33:20.0649 3440  [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx            C:\Windows\system32\DRIVERS\tdx.sys
16:33:20.0696 3440  tdx - ok
16:33:20.0712 3440  [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD          C:\Windows\system32\drivers\termdd.sys
16:33:20.0727 3440  TermDD - ok
16:33:20.0743 3440  [ 2E648163254233755035B46DD7B89123 ] TermService    C:\Windows\System32\termsrv.dll
16:33:20.0790 3440  TermService - ok
16:33:20.0805 3440  [ F0344071948D1A1FA732231785A0664C ] Themes          C:\Windows\system32\themeservice.dll
16:33:20.0837 3440  Themes - ok
16:33:20.0868 3440  [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER    C:\Windows\system32\mmcss.dll
16:33:20.0915 3440  THREADORDER - ok
16:33:20.0930 3440  [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks          C:\Windows\System32\trkwks.dll
16:33:20.0961 3440  TrkWks - ok
16:33:21.0024 3440  [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
16:33:21.0071 3440  TrustedInstaller - ok
16:33:21.0086 3440  [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
16:33:21.0117 3440  tssecsrv - ok
16:33:21.0164 3440  [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt        C:\Windows\system32\drivers\tsusbflt.sys
16:33:21.0164 3440  TsUsbFlt - ok
16:33:21.0211 3440  [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
16:33:21.0258 3440  tunnel - ok
16:33:21.0336 3440  [ B206BE1174D5964D49A56BB6C4E0524A ] TurboBoost      C:\Program Files\Intel\TurboBoost\TurboBoost.exe
16:33:21.0351 3440  TurboBoost - ok
16:33:21.0383 3440  [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35          C:\Windows\system32\DRIVERS\uagp35.sys
16:33:21.0383 3440  uagp35 - ok
16:33:21.0429 3440  [ 2E22C1FD397A5A9FFEF55E9D1FC96C00 ] UBHelper        C:\Windows\system32\drivers\UBHelper.sys
16:33:21.0429 3440  UBHelper - ok
16:33:21.0461 3440  [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
16:33:21.0507 3440  udfs - ok
16:33:21.0539 3440  [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect      C:\Windows\system32\UI0Detect.exe
16:33:21.0554 3440  UI0Detect - ok
16:33:21.0585 3440  [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
16:33:21.0601 3440  uliagpkx - ok
16:33:21.0648 3440  [ DC54A574663A895C8763AF0FA1FF7561 ] umbus          C:\Windows\system32\DRIVERS\umbus.sys
16:33:21.0648 3440  umbus - ok
16:33:21.0695 3440  [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass          C:\Windows\system32\DRIVERS\umpass.sys
16:33:21.0695 3440  UmPass - ok
16:33:21.0788 3440  [ 765F2DD351BA064F657751D8D75E58C0 ] UNS            C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
16:33:21.0835 3440  UNS - ok
16:33:21.0897 3440  [ 70DDE3A86DBEB1D6C3C30AD687B1877A ] Updater Service C:\Program Files\Acer\Acer Updater\UpdaterService.exe
16:33:21.0897 3440  Updater Service - ok
16:33:21.0929 3440  [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost        C:\Windows\System32\upnphost.dll
16:33:21.0975 3440  upnphost - ok
16:33:21.0991 3440  [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp        C:\Windows\system32\DRIVERS\usbccgp.sys
16:33:22.0007 3440  usbccgp - ok
16:33:22.0038 3440  [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir          C:\Windows\system32\drivers\usbcir.sys
16:33:22.0053 3440  usbcir - ok
16:33:22.0069 3440  [ C025055FE7B87701EB042095DF1A2D7B ] usbehci        C:\Windows\system32\drivers\usbehci.sys
16:33:22.0085 3440  usbehci - ok
16:33:22.0116 3440  [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
16:33:22.0131 3440  usbhub - ok
16:33:22.0147 3440  [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci        C:\Windows\system32\drivers\usbohci.sys
16:33:22.0147 3440  usbohci - ok
16:33:22.0194 3440  [ 73188F58FB384E75C4063D29413CEE3D ] usbprint        C:\Windows\system32\DRIVERS\usbprint.sys
16:33:22.0209 3440  usbprint - ok
16:33:22.0225 3440  [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR        C:\Windows\system32\DRIVERS\USBSTOR.SYS
16:33:22.0241 3440  USBSTOR - ok
16:33:22.0241 3440  [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci        C:\Windows\system32\drivers\usbuhci.sys
16:33:22.0256 3440  usbuhci - ok
16:33:22.0303 3440  [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo        C:\Windows\System32\Drivers\usbvideo.sys
16:33:22.0319 3440  usbvideo - ok
16:33:22.0350 3440  [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms          C:\Windows\System32\uxsms.dll
16:33:22.0381 3440  UxSms - ok
16:33:22.0397 3440  [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc        C:\Windows\system32\lsass.exe
16:33:22.0412 3440  VaultSvc - ok
16:33:22.0428 3440  [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot        C:\Windows\system32\drivers\vdrvroot.sys
16:33:22.0443 3440  vdrvroot - ok
16:33:22.0475 3440  [ 8D6B481601D01A456E75C3210F1830BE ] vds            C:\Windows\System32\vds.exe
16:33:22.0506 3440  vds - ok
16:33:22.0537 3440  [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga            C:\Windows\system32\DRIVERS\vgapnp.sys
16:33:22.0553 3440  vga - ok
16:33:22.0568 3440  [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave        C:\Windows\System32\drivers\vga.sys
16:33:22.0600 3440  VgaSave - ok
16:33:22.0631 3440  [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp          C:\Windows\system32\drivers\vhdmp.sys
16:33:22.0646 3440  vhdmp - ok
16:33:22.0678 3440  [ E5689D93FFE4E5D66C0178761240DD54 ] viaide          C:\Windows\system32\drivers\viaide.sys
16:33:22.0693 3440  viaide - ok
16:33:22.0693 3440  [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
16:33:22.0709 3440  volmgr - ok
16:33:22.0740 3440  [ A255814907C89BE58B79EF2F189B843B ] volmgrx        C:\Windows\system32\drivers\volmgrx.sys
16:33:22.0756 3440  volmgrx - ok
16:33:22.0787 3440  [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap        C:\Windows\system32\drivers\volsnap.sys
16:33:22.0802 3440  volsnap - ok
16:33:22.0834 3440  [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid        C:\Windows\system32\DRIVERS\vsmraid.sys
16:33:22.0849 3440  vsmraid - ok
16:33:22.0912 3440  [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS            C:\Windows\system32\vssvc.exe
16:33:22.0958 3440  VSS - ok
16:33:22.0974 3440  [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus        C:\Windows\system32\DRIVERS\vwifibus.sys
16:33:22.0990 3440  vwifibus - ok
16:33:23.0005 3440  [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt        C:\Windows\system32\DRIVERS\vwififlt.sys
16:33:23.0021 3440  vwififlt - ok
16:33:23.0083 3440  [ 1C9D80CC3849B3788048078C26486E1A ] W32Time        C:\Windows\system32\w32time.dll
16:33:23.0130 3440  W32Time - ok
16:33:23.0146 3440  [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen        C:\Windows\system32\DRIVERS\wacompen.sys
16:33:23.0161 3440  WacomPen - ok
16:33:23.0208 3440  [ 356AFD78A6ED4457169241AC3965230C ] WANARP          C:\Windows\system32\DRIVERS\wanarp.sys
16:33:23.0239 3440  WANARP - ok
16:33:23.0255 3440  [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
16:33:23.0286 3440  Wanarpv6 - ok
16:33:23.0348 3440  [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc    C:\Windows\system32\Wat\WatAdminSvc.exe
16:33:23.0380 3440  WatAdminSvc - ok
16:33:23.0426 3440  [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine        C:\Windows\system32\wbengine.exe
16:33:23.0458 3440  wbengine - ok
16:33:23.0473 3440  [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc        C:\Windows\System32\wbiosrvc.dll
16:33:23.0504 3440  WbioSrvc - ok
16:33:23.0536 3440  [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc        C:\Windows\System32\wcncsvc.dll
16:33:23.0567 3440  wcncsvc - ok
16:33:23.0582 3440  [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
16:33:23.0598 3440  WcsPlugInService - ok
16:33:23.0629 3440  [ 72889E16FF12BA0F235467D6091B17DC ] Wd              C:\Windows\system32\DRIVERS\wd.sys
16:33:23.0629 3440  Wd - ok
16:33:23.0660 3440  [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
16:33:23.0676 3440  Wdf01000 - ok
16:33:23.0692 3440  [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost  C:\Windows\system32\wdi.dll
16:33:23.0707 3440  WdiServiceHost - ok
16:33:23.0723 3440  [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost  C:\Windows\system32\wdi.dll
16:33:23.0738 3440  WdiSystemHost - ok
16:33:23.0770 3440  [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient      C:\Windows\System32\webclnt.dll
16:33:23.0785 3440  WebClient - ok
16:33:23.0816 3440  [ C749025A679C5103E575E3B48E092C43 ] Wecsvc          C:\Windows\system32\wecsvc.dll
16:33:23.0863 3440  Wecsvc - ok
16:33:23.0863 3440  [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport  C:\Windows\System32\wercplsupport.dll
16:33:23.0910 3440  wercplsupport - ok
16:33:23.0926 3440  [ 6D137963730144698CBD10F202E9F251 ] WerSvc          C:\Windows\System32\WerSvc.dll
16:33:23.0972 3440  WerSvc - ok
16:33:24.0019 3440  [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf          C:\Windows\system32\DRIVERS\wfplwf.sys
16:33:24.0050 3440  WfpLwf - ok
16:33:24.0066 3440  [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount        C:\Windows\system32\drivers\wimmount.sys
16:33:24.0082 3440  WIMMount - ok
16:33:24.0097 3440  WinDefend - ok
16:33:24.0097 3440  WinHttpAutoProxySvc - ok
16:33:24.0175 3440  [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt        C:\Windows\system32\wbem\WMIsvc.dll
16:33:24.0206 3440  Winmgmt - ok
16:33:24.0253 3440  [ BCB1310604AA415C4508708975B3931E ] WinRM          C:\Windows\system32\WsmSvc.dll
16:33:24.0316 3440  WinRM - ok
16:33:24.0362 3440  [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc        C:\Windows\System32\wlansvc.dll
16:33:24.0394 3440  Wlansvc - ok
16:33:24.0409 3440  [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi        C:\Windows\system32\drivers\wmiacpi.sys
16:33:24.0425 3440  WmiAcpi - ok
16:33:24.0440 3440  [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
16:33:24.0456 3440  wmiApSrv - ok
16:33:24.0487 3440  [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc          C:\Windows\System32\wpcsvc.dll
16:33:24.0503 3440  WPCSvc - ok
16:33:24.0534 3440  [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
16:33:24.0550 3440  WPDBusEnum - ok
16:33:24.0596 3440  [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl        C:\Windows\system32\drivers\ws2ifsl.sys
16:33:24.0628 3440  ws2ifsl - ok
16:33:24.0643 3440  [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc          C:\Windows\System32\wscsvc.dll
16:33:24.0674 3440  wscsvc - ok
16:33:24.0674 3440  WSearch - ok
16:33:24.0737 3440  [ 86293B6785260309606B0B0B46E42252 ] WTGService      C:\Program Files (x86)\3DataManager\WTGService.exe
16:33:24.0752 3440  WTGService - ok
16:33:24.0815 3440  [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv        C:\Windows\system32\wuaueng.dll
16:33:24.0877 3440  wuauserv - ok
16:33:24.0877 3440  [ D3381DC54C34D79B22CEE0D65BA91B7C ] WudfPf          C:\Windows\system32\drivers\WudfPf.sys
16:33:24.0924 3440  WudfPf - ok
16:33:24.0971 3440  [ CF8D590BE3373029D57AF80914190682 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
16:33:25.0002 3440  WUDFRd - ok
16:33:25.0033 3440  [ 7A95C95B6C4CF292D689106BCAE49543 ] wudfsvc        C:\Windows\System32\WUDFSvc.dll
16:33:25.0064 3440  wudfsvc - ok
16:33:25.0111 3440  [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc        C:\Windows\System32\wwansvc.dll
16:33:25.0127 3440  WwanSvc - ok
16:33:25.0174 3440  [ 9313FE79FF3240FA0A73FBE6015B6887 ] ZTEusbmdm6k    C:\Windows\system32\DRIVERS\ZTEusbmdm6k.sys
16:33:25.0174 3440  ZTEusbmdm6k - ok
16:33:25.0220 3440  [ 9313FE79FF3240FA0A73FBE6015B6887 ] ZTEusbnmea      C:\Windows\system32\DRIVERS\ZTEusbnmea.sys
16:33:25.0236 3440  ZTEusbnmea - ok
16:33:25.0267 3440  [ 9313FE79FF3240FA0A73FBE6015B6887 ] ZTEusbser6k    C:\Windows\system32\DRIVERS\ZTEusbser6k.sys
16:33:25.0283 3440  ZTEusbser6k - ok
16:33:25.0298 3440  ================ Scan global ===============================
16:33:25.0330 3440  [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
16:33:25.0361 3440  [ EB6A48CC998E1090E44E8E7F1009A640 ] C:\Windows\system32\winsrv.dll
16:33:25.0376 3440  [ EB6A48CC998E1090E44E8E7F1009A640 ] C:\Windows\system32\winsrv.dll
16:33:25.0392 3440  [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
16:33:25.0423 3440  [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
16:33:25.0423 3440  [Global] - ok
16:33:25.0423 3440  ================ Scan MBR ==================================
16:33:25.0439 3440  [ 973E9BA32FDBB305C552ED3E1EBF0686 ] \Device\Harddisk0\DR0
16:33:25.0867 3440  \Device\Harddisk0\DR0 - ok
16:33:25.0867 3440  ================ Scan VBR ==================================
16:33:25.0899 3440  [ B1092CFFCB644F3F06B43EF3F8AC9E43 ] \Device\Harddisk0\DR0\Partition1
16:33:25.0899 3440  \Device\Harddisk0\DR0\Partition1 - ok
16:33:25.0914 3440  [ A2EE0752C66849AD087DCE2588219CBC ] \Device\Harddisk0\DR0\Partition2
16:33:25.0914 3440  \Device\Harddisk0\DR0\Partition2 - ok
16:33:25.0914 3440  ============================================================
16:33:25.0914 3440  Scan finished
16:33:25.0914 3440  ============================================================
16:33:25.0914 5072  Detected object count: 2
16:33:25.0914 5072  Actual detected object count: 2
16:34:43.0230 5072  HiPatchService ( UnsignedFile.Multi.Generic ) - skipped by user
16:34:43.0230 5072  HiPatchService ( UnsignedFile.Multi.Generic ) - User select action: Skip
16:34:43.0230 5072  RS_Service ( UnsignedFile.Multi.Generic ) - skipped by user
16:34:43.0230 5072  RS_Service ( UnsignedFile.Multi.Generic ) - User select action: Skip


cosinus 10.10.2012 15:43

Ok ist soweit unauffällig

Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

holzdan 10.10.2012 16:30

Hi. Danke
Malwarebytes hat nix gefunden und SuperAntispyaware nur tracking cookies.
Was hat das mit dem :coranti eigentlich auf sich ?

cosinus 10.10.2012 19:48

Das Tool hat wohl damals nur zusätzliche Infos in die Datei Dateien "abgelegt" per NTFS Alternate Data Stream, das macht mW Kaspersky auch bzw. so ähnlich


Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )


Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat.

Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller http://filepony.de/download-cookie_culler/
Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird.

Ich halte es so, dass ich zum "wilden Surfen" den Opera-Browser oder Chromium unter meinem Linux verwende. Mein Hauptbrowser (Firefox) speichert nur die Cookies von den Sites die ich auch will, alles andere lehne ich manuell ab (der FF fragt mich immer) - die anderen Browser nehmen alles an Cookies zwar an, aber spätestens beim nächsten Start von Opera oder Chromium sind keine Cookies mehr da.

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?

holzdan 11.10.2012 10:35

hi
scheint alles gut zu laufen , hab mir wieder den proxomitron installiert , habe die Erfahrung gemacht dass damit mein System eigentlich meistens sauber war und Werbung hab ich damit auch so gut wie keine. Mit den cookies kann ich leben...

Danke fuer deine Hilfe

cosinus 11.10.2012 14:21

Dann wären wir durch! :abklatsch:

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. Mit Hilfe von OTL kannst du auch viele Tools entfernen:

Starte bitte OTL und klicke auf Bereinigung.
Dies wird die meisten Tools entfernen, die wir zur Bereinigung benötigt haben. Sollte etwas bestehen bleiben, bitte mit Rechtsklick --> Löschen entfernen.


Malwarebytes zu behalten ist zu empfehlen. Kannst ja 1x im Monat damit einen Vollscan machen, aber immer vorher ans Update denken.


Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:
Prüfen => Adobe - Flash Player
Downloadlinks => Adobe Flash Player Distribution | Adobe

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.


Alle Zeitangaben in WEZ +1. Es ist jetzt 07:45 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55