ok gmer ging, asw musste ich mit none machen.
gmer log: Code:
GMER 2.0.18454 - hxxp://www.gmer.net
Rootkit scan 2013-02-01 17:15:40
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST950032 rev.0005 465,76GB
Running: gmer_2.0.18454.exe; Driver: C:\Users\THOMAS~1\AppData\Local\Temp\fxldipoc.sys
---- User code sections - GMER 2.0 ----
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1892] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 00000000777d1401 2 bytes [7D, 77]
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1892] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 00000000777d1419 2 bytes [7D, 77]
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1892] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 00000000777d1431 2 bytes [7D, 77]
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1892] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 00000000777d144a 2 bytes [7D, 77]
.text ... * 9
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1892] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000777d14dd 2 bytes [7D, 77]
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1892] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000777d14f5 2 bytes [7D, 77]
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1892] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 00000000777d150d 2 bytes [7D, 77]
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1892] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 00000000777d1525 2 bytes [7D, 77]
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1892] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 00000000777d153d 2 bytes [7D, 77]
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1892] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 00000000777d1555 2 bytes [7D, 77]
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1892] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 00000000777d156d 2 bytes [7D, 77]
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1892] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 00000000777d1585 2 bytes [7D, 77]
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1892] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 00000000777d159d 2 bytes [7D, 77]
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1892] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000777d15b5 2 bytes [7D, 77]
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1892] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000777d15cd 2 bytes [7D, 77]
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1892] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000777d16b2 2 bytes [7D, 77]
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1892] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000777d16bd 2 bytes [7D, 77]
.text C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe[3080] C:\Windows\SysWOW64\ntdll.dll!DbgBreakPoint 0000000077cd000c 1 byte [C3]
.text C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe[3080] C:\Windows\SysWOW64\ntdll.dll!DbgUiRemoteBreakin 0000000077d5f85a 5 bytes JMP 0000000177d0d571
.text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3104] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 00000000777d1401 2 bytes [7D, 77]
.text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3104] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 00000000777d1419 2 bytes [7D, 77]
.text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3104] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 00000000777d1431 2 bytes [7D, 77]
.text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3104] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 00000000777d144a 2 bytes [7D, 77]
.text ... * 9
.text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3104] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000777d14dd 2 bytes [7D, 77]
.text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3104] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000777d14f5 2 bytes [7D, 77]
.text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3104] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 00000000777d150d 2 bytes [7D, 77]
.text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3104] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 00000000777d1525 2 bytes [7D, 77]
.text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3104] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 00000000777d153d 2 bytes [7D, 77]
.text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3104] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 00000000777d1555 2 bytes [7D, 77]
.text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3104] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 00000000777d156d 2 bytes [7D, 77]
.text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3104] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 00000000777d1585 2 bytes [7D, 77]
.text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3104] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 00000000777d159d 2 bytes [7D, 77]
.text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3104] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000777d15b5 2 bytes [7D, 77]
.text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3104] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000777d15cd 2 bytes [7D, 77]
.text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3104] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000777d16b2 2 bytes [7D, 77]
.text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3104] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000777d16bd 2 bytes [7D, 77]
.text C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe[3316] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 00000000777d1401 2 bytes [7D, 77]
.text C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe[3316] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 00000000777d1419 2 bytes [7D, 77]
.text C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe[3316] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 00000000777d1431 2 bytes [7D, 77]
.text C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe[3316] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 00000000777d144a 2 bytes [7D, 77]
.text ... * 9
.text C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe[3316] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000777d14dd 2 bytes [7D, 77]
.text C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe[3316] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000777d14f5 2 bytes [7D, 77]
.text C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe[3316] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 00000000777d150d 2 bytes [7D, 77]
.text C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe[3316] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 00000000777d1525 2 bytes [7D, 77]
.text C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe[3316] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 00000000777d153d 2 bytes [7D, 77]
.text C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe[3316] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 00000000777d1555 2 bytes [7D, 77]
.text C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe[3316] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 00000000777d156d 2 bytes [7D, 77]
.text C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe[3316] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 00000000777d1585 2 bytes [7D, 77]
.text C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe[3316] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 00000000777d159d 2 bytes [7D, 77]
.text C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe[3316] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000777d15b5 2 bytes [7D, 77]
.text C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe[3316] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000777d15cd 2 bytes [7D, 77]
.text C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe[3316] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000777d16b2 2 bytes [7D, 77]
.text C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe[3316] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000777d16bd 2 bytes [7D, 77]
.text C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe[3812] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 00000000777d1401 2 bytes [7D, 77]
.text C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe[3812] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 00000000777d1419 2 bytes [7D, 77]
.text C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe[3812] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 00000000777d1431 2 bytes [7D, 77]
.text C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe[3812] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 00000000777d144a 2 bytes [7D, 77]
.text ... * 9
.text C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe[3812] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000777d14dd 2 bytes [7D, 77]
.text C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe[3812] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000777d14f5 2 bytes [7D, 77]
.text C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe[3812] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 00000000777d150d 2 bytes [7D, 77]
.text C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe[3812] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 00000000777d1525 2 bytes [7D, 77]
.text C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe[3812] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 00000000777d153d 2 bytes [7D, 77]
.text C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe[3812] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 00000000777d1555 2 bytes [7D, 77]
.text C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe[3812] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 00000000777d156d 2 bytes [7D, 77]
.text C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe[3812] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 00000000777d1585 2 bytes [7D, 77]
.text C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe[3812] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 00000000777d159d 2 bytes [7D, 77]
.text C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe[3812] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000777d15b5 2 bytes [7D, 77]
.text C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe[3812] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000777d15cd 2 bytes [7D, 77]
.text C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe[3812] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000777d16b2 2 bytes [7D, 77]
.text C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe[3812] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000777d16bd 2 bytes [7D, 77]
---- User IAT/EAT - GMER 2.0 ----
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1324] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSetAppId] [7fef8dd2750] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1324] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSetMachineId] [7fef8dd2b98] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1324] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmWriteSharedMachineId] [7fef8dd7de0] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1324] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmCreateNewId] [7fef8dd8130] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1324] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmReadSharedMachineId] [7fef8dd1908] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1324] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmGetSession] [7fef8dd1c00] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1324] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmStartUpload] [7fef8dd81d8] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1324] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSet] [7fef8dd2878] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1324] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmAddToStreamString] [7fef8dd7a5c] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1324] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmIncrement] [7fef8dd6c48] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1324] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmAddToStreamDWord] [7fef8dd77bc] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1324] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSetAppVersion] [7fef8dd7064] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1324] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmStartSession] [7fef8dd6544] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1324] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmEndSession] [7fef8dd5e30] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
---- EOF - GMER 2.0 ---- asw log: Code:
aswMBR version 0.9.9.1707 Copyright(c) 2011 AVAST Software
Run date: 2013-02-01 17:42:29
-----------------------------
17:42:29.067 OS Version: Windows x64 6.1.7601 Service Pack 1
17:42:29.067 Number of processors: 4 586 0x2A07
17:42:29.067 ComputerName: TOMSTOP UserName:
17:42:30.167 Initialize success
17:42:37.923 AVAST engine defs: 13020100
17:42:47.892 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
17:42:47.892 Disk 0 Vendor: ST950032 0005 Size: 476940MB BusType: 3
17:42:48.032 Disk 0 MBR read successfully
17:42:48.048 Disk 0 MBR scan
17:42:48.048 Disk 0 Windows 7 default MBR code
17:42:48.079 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 199 MB offset 2048
17:42:48.095 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 461734 MB offset 409600
17:42:48.126 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 14902 MB offset 946040832
17:42:48.151 Disk 0 Partition 4 00 0C FAT32 LBA MSDOS5.0 103 MB offset 976560128
17:42:48.231 Disk 0 scanning C:\Windows\system32\drivers
17:43:05.614 Service scanning
17:43:34.733 Modules scanning
17:43:34.743 Disk 0 trace - called modules:
17:43:35.143 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
17:43:35.153 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004dc5060]
17:43:35.163 3 CLASSPNP.SYS[fffff88001bc643f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004a33050]
17:43:35.173 Scan finished successfully
17:44:08.180 Disk 0 MBR has been saved successfully to "C:\Users\Thomas Marquardt\Desktop\MBR.dat"
17:44:08.180 The log file has been saved successfully to "C:\Users\Thomas Marquardt\Desktop\aswMBR.txt" |