Cypher00 | 03.06.2013 17:43 | hier der neue OTl log Code:
OTL logfile created on: 03.06.2013 18:34:06 - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Sabine\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,19 Gb Total Physical Memory | 2,16 Gb Available Physical Memory | 67,86% Memory free
6,60 Gb Paging File | 5,60 Gb Available in Paging File | 84,84% Paging File free
Paging file location(s): c:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 931,51 Gb Total Space | 584,02 Gb Free Space | 62,70% Space Free | Partition Type: NTFS
Drive D: | 436,59 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Computer Name: SABINE-PC | User Name: Sabine | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013.06.03 17:05:25 | 000,106,280 | ---- | M] (SurfRight B.V.) -- C:\Programme\HitmanPro\hmpsched.exe
PRC - [2013.05.16 01:02:51 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Sabine\Desktop\OTL.exe
PRC - [2013.05.15 12:08:44 | 001,435,984 | ---- | M] (LogMeIn Inc.) -- C:\Programme\LogMeIn Hamachi\hamachi-2.exe
PRC - [2013.05.13 13:56:02 | 002,245,232 | ---- | M] (Giraffic) -- C:\Programme\Giraffic\Veoh_GirafficWatchdog.exe
PRC - [2013.05.13 13:55:30 | 004,001,376 | ---- | M] (Giraffic) -- C:\Programme\Giraffic\Veoh_Giraffic.exe
PRC - [2013.05.10 09:57:22 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013.04.23 14:48:24 | 000,009,216 | ---- | M] (Hi-Rez Studios) -- C:\Programme\Hi-Rez Studios\HiPatchService.exe
PRC - [2013.04.04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware ger\mbamservice.exe
PRC - [2013.04.04 14:50:32 | 000,532,040 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware ger\mbamgui.exe
PRC - [2013.04.04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware ger\mbamscheduler.exe
PRC - [2013.01.18 16:21:02 | 000,873,248 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\Display\nvxdsync.exe
PRC - [2013.01.18 16:21:00 | 001,821,984 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\Display\nvtray.exe
PRC - [2013.01.18 08:14:20 | 000,383,264 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2012.07.18 18:04:42 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe
PRC - [2012.07.18 18:04:33 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\sched.exe
PRC - [2012.07.18 18:04:23 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe
PRC - [2012.07.18 18:04:22 | 000,348,664 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe
PRC - [2009.11.10 12:09:50 | 000,414,000 | ---- | M] (MKS Software Inc.) -- C:\Windows\System32\nutsrv4.exe
PRC - [2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009.04.11 08:27:28 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conime.exe
========== Modules (No Company Name) ==========
========== Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- C:\PROGRA~2\qeto08.dat -- (Winmgmt)
SRV - [2013.06.03 17:05:25 | 000,106,280 | ---- | M] (SurfRight B.V.) [Auto | Running] -- C:\Programme\HitmanPro\hmpsched.exe -- (HitmanProScheduler)
SRV - [2013.05.31 22:58:22 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013.05.15 12:08:44 | 001,435,984 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Programme\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
SRV - [2013.05.13 13:56:02 | 002,245,232 | ---- | M] (Giraffic) [Auto | Running] -- C:\Programme\Giraffic\Veoh_GirafficWatchdog.exe -- (Giraffic)
SRV - [2013.05.10 09:57:22 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013.05.04 01:35:30 | 000,543,656 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2013.04.23 14:48:24 | 000,009,216 | ---- | M] (Hi-Rez Studios) [Auto | Running] -- C:\Programme\Hi-Rez Studios\HiPatchService.exe -- (HiPatchService)
SRV - [2013.04.04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Programme\Malwarebytes' Anti-Malware ger\mbamservice.exe -- (MBAMService)
SRV - [2013.04.04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Programme\Malwarebytes' Anti-Malware ger\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2013.02.28 18:45:16 | 000,161,384 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Programme\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013.02.26 00:22:34 | 001,260,320 | ---- | M] (NVIDIA Corporation) [Auto | Stopped] -- C:\Programme\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2013.01.18 08:14:20 | 000,383,264 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Programme\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2012.07.18 18:04:33 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012.07.18 18:04:23 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2009.11.10 12:09:50 | 000,414,000 | ---- | M] (MKS Software Inc.) [Auto | Running] -- C:\Windows\System32\nutsrv4.exe -- (NuTCRACKERService)
SRV - [2008.01.21 04:25:33 | 000,896,512 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
SRV - [2008.01.21 04:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\vpnva.sys -- (vpnva)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\RTL8192su.sys -- (RTL8192su)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\RTKVHDA.sys -- (IntcAzAudAddService)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\ComboFix\catchme.sys -- (catchme)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\Drivers\AsrCDDrv.sys -- (AsrCDDrv)
DRV - [2013.06.03 18:09:24 | 000,030,464 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\hitmanpro37.sys -- (hitmanpro37)
DRV - [2013.04.04 14:50:32 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2013.02.26 00:22:06 | 008,939,296 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2012.07.18 18:04:42 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2012.07.18 18:04:42 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2012.07.18 18:04:42 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2010.06.17 15:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009.09.14 14:22:10 | 000,120,840 | ---- | M] (Saitek) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\SaiKA50A.sys -- (SaiKA50A)
DRV - [2009.09.14 14:22:10 | 000,035,336 | ---- | M] (Saitek) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\SaiUA50A.sys -- (SaiUA50A)
DRV - [2009.09.14 08:28:04 | 000,043,656 | ---- | M] (Saitek) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\SaiBus.sys -- (SaiNtBus)
DRV - [2009.09.14 08:28:04 | 000,020,744 | ---- | M] (Saitek) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\SaiMini.sys -- (SaiMini)
DRV - [2009.03.18 16:35:40 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\hamachi.sys -- (hamachi)
DRV - [2008.08.06 10:26:08 | 000,124,928 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2007.09.21 10:38:22 | 000,554,496 | ---- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\netr28u.sys -- (netr28u)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.mysearchdial.com/?f=1&a=tugumsd&cd=2XzuyEtN2Y1L1Qzu0B0CyD0F0FyEtD0D0A0FyD0E0AtDzzyDtN0D0Tzu0CyEzytCtN1L2XzutBtFtBtFtCtFyCtCzztN1L1Czu2Z2Y1N2Y1H1B1Q&cr=1207875316&ir=
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{072E35EC-1E3A-F4EA-65B0-0D7D63EAC49F}: "URL" = hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10011&barid={2AA40F9D-2317-4856-B88D-A0CD65219231}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.mysearchdial.com/?f=1&a=tugumsd&cd=2XzuyEtN2Y1L1Qzu0B0CyD0F0FyEtD0D0A0FyD0E0AtDzzyDtN0D0Tzu0CyEzytCtN1L2XzutBtFtBtFtCtFyCtCzztN1L1Czu2Z2Y1N2Y1H1B1Q&cr=1207875316&ir=
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com
IE - HKCU\..\URLSearchHook: {cd90bf73-20f6-44ef-993d-bb920303bd2e} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{072E35EC-1E3A-F4EA-65B0-0D7D63EAC49F}: "URL" = hxxp://mixidj.claro-search.com/?q={searchTerms}&affID=121139&tt=3612_3&babsrc=SP_ss&mntrId=70aba0850000000000000022436bc8dd
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{D7A5C187-ED99-4C30-8795-5CAD44133D98}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2653012
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.21.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin: C:\Users\Sabine\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
[2013.05.05 18:55:24 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Sabine\AppData\Roaming\mozilla\firefox\Profiles\extensions
[2013.05.31 21:49:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Sabine\AppData\Roaming\mozilla\firefox\Profiles\extensions\extensions
[2012.09.06 18:36:08 | 000,000,000 | ---D | M] (OneClickDownloader) -- C:\Users\Sabine\AppData\Roaming\mozilla\firefox\Profiles\extensions\OneClickDownload@OneClickDownload.com
[2013.05.05 18:55:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Sabine\AppData\Roaming\mozilla\firefox\Profiles\extensions\searchplugins
[2013.05.05 18:55:30 | 000,000,000 | ---D | M] (MySearchDial) -- C:\Users\Sabine\AppData\Roaming\mozilla\firefox\Profiles\extensions\extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}
[2013.05.31 21:49:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Sabine\AppData\Roaming\mozilla\firefox\Profiles\toolbar@ask.com\extensions
[2013.05.05 18:55:32 | 000,000,000 | ---D | M] (MySearchDial) -- C:\Users\Sabine\AppData\Roaming\mozilla\firefox\Profiles\toolbar@ask.com\extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}
[2013.02.10 14:33:15 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
========== Chrome ==========
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\27.0.1453.94\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\27.0.1453.94\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\27.0.1453.94\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll
CHR - plugin: Java(TM) Platform SE 7 U21 (Enabled) = C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files\VideoLAN\VLC\npvlc.dll
CHR - plugin: AmazonMP3DownloaderPlugin (Enabled) = C:\Users\Sabine\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll
CHR - plugin: Java Deployment Toolkit 7.0.210.11 (Enabled) = C:\Windows\system32\npDeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
O1 HOSTS File: ([2013.05.17 14:39:16 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (WebCGMHlprObj Class) - {56B38F40-4E70-11d4-A076-0080AD86BA2F} - C:\Windows\System32\cgmopenbho.dll (CGM Open Consortium, Inc.)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CD90BF73-20F6-44EF-993D-BB920303BD2E} - No CLSID value found.
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [NuTCSetupEnviron] C:\Programme\PTC\MKS Toolkit\bin\ncoeenv.exe (MKS Software Inc.)
O4 - HKCU..\Run: [Ahytovl] C:\Users\Sabine\AppData\Roaming\Poyrra\zedo.exe File not found
O4 - HKCU..\Run: [ctfmon32.exe] C:\PROGRA~2\rundll32.exe C:\PROGRA~2\qeto08.dat,XFG00 File not found
O4 - HKCU..\Run: [IExplorer Util] C:\Users\Sabine\AppData\Roaming\ie_util.exe File not found
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - Startup: C:\Users\Sabine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk = C:\Programme\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\System32\nutafun4.dll (MKS Software Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Windows\System32\nutafun4.dll (MKS Software Inc.)
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: fritz.box ([]* in Lokales Intranet)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Ranges: Range1 ([*] in Lokales Intranet)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.6.2.cab (DLM Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B7CC0766-2E6A-42BF-8B72-7A20ED70B36A}: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E0797513-0FF2-4E11-AB21-5E74FF1D48A3}: DhcpNameServer = 192.168.178.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Sabine\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\Sabine\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2006.03.24 13:06:41 | 000,000,053 | R--- | M] () - D:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2013.06.02 22:05:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro
[2013.06.02 22:05:38 | 000,000,000 | ---D | C] -- C:\Program Files\HitmanPro
[2013.06.02 22:05:17 | 000,000,000 | ---D | C] -- C:\ProgramData\HitmanPro
[2013.06.02 22:04:45 | 000,000,000 | ---D | C] -- C:\Users\Sabine\Desktop\HitmanPro_3.7.5.199
[2013.05.31 23:08:34 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2013.05.31 23:03:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013.05.31 22:58:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Google
[2013.05.31 21:14:32 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2013.05.31 21:13:31 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2013.05.31 20:14:06 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2013.05.31 00:25:03 | 000,000,000 | ---D | C] -- C:\Users\Sabine\AppData\Roaming\pim
[2013.05.30 19:26:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2013.05.30 19:26:53 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2013.05.30 19:19:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware ger
[2013.05.30 19:19:22 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware ger
[2013.05.30 18:49:34 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2013.05.30 18:49:34 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2013.05.28 15:32:47 | 000,000,000 | ---D | C] -- C:\Users\Sabine\AppData\Roaming\Malwarebytes
[2013.05.28 15:32:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013.05.28 15:32:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013.05.24 03:00:16 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\ProgramData\rundll32.exe
[2013.05.23 23:17:19 | 000,000,000 | ---D | C] -- C:\Users\Sabine\AppData\Roaming\Poyrra
[2013.05.23 23:17:19 | 000,000,000 | ---D | C] -- C:\Users\Sabine\AppData\Roaming\Cuig
[2013.05.23 23:17:19 | 000,000,000 | ---D | C] -- C:\Users\Sabine\AppData\Roaming\Aztuup
[2013.05.23 23:02:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
[2013.05.23 23:02:52 | 000,000,000 | ---D | C] -- C:\Program Files\LogMeIn Hamachi
[2013.05.17 14:52:53 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2013.05.17 14:41:46 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
[2013.05.17 14:38:55 | 000,000,000 | ---D | C] -- C:\Users\Sabine\AppData\Local\temp
[2013.05.17 14:23:15 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2013.05.17 14:23:15 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2013.05.17 14:23:15 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2013.05.17 14:23:11 | 000,000,000 | ---D | C] -- C:\ComboFix
[2013.05.17 14:23:06 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013.05.17 13:26:08 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2013.05.17 13:24:48 | 005,066,411 | R--- | C] (Swearware) -- C:\Users\Sabine\Desktop\ComboFix.exe
[2013.05.16 21:09:21 | 000,000,000 | ---D | C] -- C:\TDSSKiller Log
[2013.05.16 02:07:45 | 000,000,000 | ---D | C] -- C:\Users\Sabine\AppData\Roaming\Wuqao
[2013.05.16 02:07:45 | 000,000,000 | ---D | C] -- C:\Users\Sabine\AppData\Roaming\Tayv
[2013.05.16 01:40:06 | 002,237,968 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Sabine\Desktop\tdsskiller.exe
[2013.05.16 01:04:57 | 000,000,000 | ---D | C] -- C:\_OTL
[2013.05.15 16:05:37 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Sabine\Desktop\OTL.exe
[2013.05.12 14:11:36 | 000,000,000 | ---D | C] -- C:\Users\Sabine\Documents\Amazon MP3
[2013.05.12 14:11:36 | 000,000,000 | ---D | C] -- C:\Users\Sabine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Amazon
[2013.05.12 14:11:03 | 000,000,000 | ---D | C] -- C:\Users\Sabine\AppData\Local\Program Files
[2013.05.05 23:32:04 | 000,000,000 | ---D | C] -- C:\Users\Sabine\AppData\Local\Game Dev Tycoon
========== Files - Modified Within 30 Days ==========
[2013.06.03 18:09:52 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.06.03 18:09:26 | 000,004,112 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013.06.03 18:09:26 | 000,004,112 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013.06.03 18:09:24 | 000,030,464 | ---- | M] () -- C:\Windows\System32\drivers\hitmanpro37.sys
[2013.06.03 18:09:21 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.06.03 18:09:11 | 3421,822,976 | -HS- | M] () -- C:\hiberfil.sys
[2013.06.03 18:08:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.06.03 17:40:23 | 000,000,840 | ---- | M] () -- C:\Windows\System32\.crusader
[2013.06.03 17:09:01 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.06.02 22:18:44 | 000,002,011 | ---- | M] () -- C:\Users\Sabine\Documents\HitmanPro_20130602_2217.zip
[2013.06.02 22:05:39 | 000,001,744 | ---- | M] () -- C:\Users\Public\Desktop\HitmanPro.lnk
[2013.05.31 23:10:40 | 000,001,971 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2013.05.31 23:09:14 | 000,001,892 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2013.05.31 23:01:05 | 000,632,031 | ---- | M] () -- C:\Users\Sabine\Desktop\adwcleaner.exe
[2013.05.31 09:00:37 | 000,000,004 | ---- | M] () -- C:\Users\Sabine\AppData\Roaming\skype.ini
[2013.05.31 08:58:32 | 000,258,056 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2013.05.30 19:26:54 | 000,000,804 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2013.05.29 22:58:59 | 095,023,320 | ---- | M] () -- C:\ProgramData\80oteq.pad
[2013.05.29 22:29:48 | 000,002,669 | ---- | M] () -- C:\ProgramData\80oteq.js
[2013.05.29 17:32:57 | 000,671,212 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2013.05.29 17:32:57 | 000,631,942 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013.05.29 17:32:57 | 000,144,380 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2013.05.29 17:32:57 | 000,118,568 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013.05.24 03:00:16 | 000,155,648 | ---- | M] () -- C:\ProgramData\4lo9qe.dat
[2013.05.17 14:39:16 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2013.05.17 14:05:13 | 000,001,356 | ---- | M] () -- C:\Users\Sabine\AppData\Local\d3d9caps.dat
[2013.05.17 13:25:01 | 005,066,411 | R--- | M] (Swearware) -- C:\Users\Sabine\Desktop\ComboFix.exe
[2013.05.16 21:10:02 | 000,023,832 | ---- | M] () -- C:\TDSSKiller Log.zip
[2013.05.16 01:40:06 | 002,237,968 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Sabine\Desktop\tdsskiller.exe
[2013.05.16 01:02:51 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Sabine\Desktop\OTL.exe
[2013.05.15 16:21:00 | 000,377,856 | ---- | M] () -- C:\Users\Sabine\Desktop\gmer_2.1.19163.exe
[2013.05.15 16:03:30 | 000,000,000 | ---- | M] () -- C:\Users\Sabine\defogger_reenable
[2013.05.15 16:02:35 | 000,050,477 | ---- | M] () -- C:\Users\Sabine\Desktop\Defogger.exe
========== Files Created - No Company Name ==========
[2013.06.03 18:09:24 | 000,030,464 | ---- | C] () -- C:\Windows\System32\drivers\hitmanpro37.sys
[2013.06.03 17:40:23 | 000,000,840 | ---- | C] () -- C:\Windows\System32\.crusader
[2013.06.02 22:18:44 | 000,002,011 | ---- | C] () -- C:\Users\Sabine\Documents\HitmanPro_20130602_2217.zip
[2013.06.02 22:05:39 | 000,001,744 | ---- | C] () -- C:\Users\Public\Desktop\HitmanPro.lnk
[2013.05.31 23:09:14 | 000,002,425 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2013.05.31 23:09:14 | 000,001,892 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2013.05.31 23:03:35 | 000,001,971 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2013.05.31 23:01:05 | 000,632,031 | ---- | C] () -- C:\Users\Sabine\Desktop\adwcleaner.exe
[2013.05.31 22:58:42 | 000,001,098 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.05.31 22:58:41 | 000,001,094 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.05.31 22:58:26 | 000,000,884 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.05.31 01:14:49 | 000,000,004 | ---- | C] () -- C:\Users\Sabine\AppData\Roaming\skype.ini
[2013.05.30 19:26:54 | 000,000,804 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2013.05.30 18:31:09 | 3421,822,976 | -HS- | C] () -- C:\hiberfil.sys
[2013.05.29 22:29:48 | 000,002,669 | ---- | C] () -- C:\ProgramData\80oteq.js
[2013.05.29 22:29:46 | 095,023,320 | ---- | C] () -- C:\ProgramData\80oteq.pad
[2013.05.24 03:00:16 | 000,155,648 | ---- | C] () -- C:\ProgramData\4lo9qe.dat
[2013.05.17 14:23:15 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2013.05.17 14:23:15 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2013.05.17 14:23:15 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2013.05.17 14:23:15 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2013.05.17 14:23:15 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2013.05.16 21:10:02 | 000,023,832 | ---- | C] () -- C:\TDSSKiller Log.zip
[2013.05.15 16:21:00 | 000,377,856 | ---- | C] () -- C:\Users\Sabine\Desktop\gmer_2.1.19163.exe
[2013.05.15 16:03:30 | 000,000,000 | ---- | C] () -- C:\Users\Sabine\defogger_reenable
[2013.05.15 16:03:01 | 000,050,477 | ---- | C] () -- C:\Users\Sabine\Desktop\Defogger.exe
[2013.02.10 14:29:46 | 000,000,058 | ---- | C] () -- C:\Users\Sabine\AppData\Local\DonationCoder_ScreenshotCaptor_InstallInfo.dat
[2012.09.12 20:39:54 | 000,003,584 | ---- | C] () -- C:\Users\Sabine\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.09.09 18:13:15 | 000,000,410 | ---- | C] () -- C:\Windows\{27018D57-D152-44EF-BCE0-5E3B3445EABE}_WiseFW.ini
[2012.08.13 16:51:33 | 000,111,932 | ---- | C] () -- C:\Windows\System32\EPPICPrinterDB.dat
[2012.08.13 16:51:33 | 000,031,053 | ---- | C] () -- C:\Windows\System32\EPPICPattern131.dat
[2012.08.13 16:51:33 | 000,027,417 | ---- | C] () -- C:\Windows\System32\EPPICPattern121.dat
[2012.08.13 16:51:33 | 000,026,154 | ---- | C] () -- C:\Windows\System32\EPPICPattern1.dat
[2012.08.13 16:51:33 | 000,024,903 | ---- | C] () -- C:\Windows\System32\EPPICPattern3.dat
[2012.08.13 16:51:33 | 000,021,390 | ---- | C] () -- C:\Windows\System32\EPPICPattern5.dat
[2012.08.13 16:51:33 | 000,020,148 | ---- | C] () -- C:\Windows\System32\EPPICPattern2.dat
[2012.08.13 16:51:33 | 000,011,811 | ---- | C] () -- C:\Windows\System32\EPPICPattern4.dat
[2012.08.13 16:51:33 | 000,004,943 | ---- | C] () -- C:\Windows\System32\EPPICPattern6.dat
[2012.08.13 16:51:33 | 000,001,146 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_DU.dat
[2012.08.13 16:51:33 | 000,001,139 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_PT.dat
[2012.08.13 16:51:33 | 000,001,139 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_BP.dat
[2012.08.13 16:51:33 | 000,001,136 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_ES.dat
[2012.08.13 16:51:33 | 000,001,129 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_FR.dat
[2012.08.13 16:51:33 | 000,001,129 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_CF.dat
[2012.08.13 16:51:33 | 000,001,120 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_IT.dat
[2012.08.13 16:51:33 | 000,001,107 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_GE.dat
[2012.08.13 16:51:33 | 000,001,104 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_EN.dat
[2012.08.13 16:51:33 | 000,000,097 | ---- | C] () -- C:\Windows\System32\PICSDK.ini
[2012.08.10 18:13:48 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2012.08.10 18:13:48 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2012.08.10 16:58:44 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2012.08.10 15:52:37 | 000,001,356 | ---- | C] () -- C:\Users\Sabine\AppData\Local\d3d9caps.dat
[2011.09.28 17:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
========== ZeroAccess Check ==========
[2006.11.02 14:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 19:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 08:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.04.11 08:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2013.03.21 22:48:39 | 000,000,000 | ---D | M] -- C:\Users\Sabine\AppData\Roaming\Awesomium
[2013.05.28 15:37:03 | 000,000,000 | ---D | M] -- C:\Users\Sabine\AppData\Roaming\Aztuup
[2013.03.01 01:24:14 | 000,000,000 | ---D | M] -- C:\Users\Sabine\AppData\Roaming\com.stoicstudio.TheBannerSagaFactions
[2013.05.23 23:17:19 | 000,000,000 | ---D | M] -- C:\Users\Sabine\AppData\Roaming\Cuig
[2013.06.01 02:34:38 | 000,000,000 | ---D | M] -- C:\Users\Sabine\AppData\Roaming\DAEMON Tools Lite
[2013.02.10 14:29:46 | 000,000,000 | ---D | M] -- C:\Users\Sabine\AppData\Roaming\DonationCoder
[2012.08.14 22:51:36 | 000,000,000 | ---D | M] -- C:\Users\Sabine\AppData\Roaming\Downloaded Installations
[2012.10.09 20:33:56 | 000,000,000 | ---D | M] -- C:\Users\Sabine\AppData\Roaming\e-academy Inc
[2013.05.31 00:54:45 | 000,000,000 | ---D | M] -- C:\Users\Sabine\AppData\Roaming\Epson
[2012.08.11 19:37:22 | 000,000,000 | ---D | M] -- C:\Users\Sabine\AppData\Roaming\LolClient
[2012.08.18 18:52:37 | 000,000,000 | ---D | M] -- C:\Users\Sabine\AppData\Roaming\Mumble
[2012.09.05 01:16:10 | 000,000,000 | ---D | M] -- C:\Users\Sabine\AppData\Roaming\OpenOffice.org
[2013.05.31 20:45:14 | 000,000,000 | ---D | M] -- C:\Users\Sabine\AppData\Roaming\pim
[2013.05.31 21:00:37 | 000,000,000 | ---D | M] -- C:\Users\Sabine\AppData\Roaming\player
[2013.05.28 15:41:47 | 000,000,000 | ---D | M] -- C:\Users\Sabine\AppData\Roaming\Poyrra
[2012.09.01 19:41:40 | 000,000,000 | ---D | M] -- C:\Users\Sabine\AppData\Roaming\RenPy
[2012.08.11 17:58:33 | 000,000,000 | ---D | M] -- C:\Users\Sabine\AppData\Roaming\Smart PC Cleaner
[2013.01.30 19:10:36 | 000,000,000 | ---D | M] -- C:\Users\Sabine\AppData\Roaming\SplitMediaLabs
[2013.05.16 23:34:26 | 000,000,000 | ---D | M] -- C:\Users\Sabine\AppData\Roaming\Tayv
[2013.06.03 00:19:01 | 000,000,000 | ---D | M] -- C:\Users\Sabine\AppData\Roaming\TS3Client
[2013.02.10 14:36:22 | 000,000,000 | ---D | M] -- C:\Users\Sabine\AppData\Roaming\TuneUp Software
[2013.05.16 02:07:45 | 000,000,000 | ---D | M] -- C:\Users\Sabine\AppData\Roaming\Wuqao
========== Purity Check ==========
========== Files - Unicode (All) ==========
[2013.05.03 09:15:28 | 000,000,000 | ---D | M](C:\ProgramData\?!?!0) -- C:\ProgramData\䋠ǃ㾐ǃ0
[2013.05.03 09:15:28 | 000,000,000 | ---D | M](C:\ProgramData\?!?!0) -- C:\ProgramData\䋠ǃ㾐ǃ0
[2013.05.02 14:25:00 | 000,000,000 | ---D | M](C:\ProgramData\?U?U0) -- C:\ProgramData\䋠Ű㾐Ű0
[2013.05.02 14:25:00 | 000,000,000 | ---D | M](C:\ProgramData\?U?U0) -- C:\ProgramData\䋠Ű㾐Ű0
[2013.04.30 08:40:44 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䋠ƹ㾐ƹ0
[2013.04.30 08:40:44 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䋠ƹ㾐ƹ0
[2013.04.28 11:33:04 | 000,000,000 | ---D | M](C:\ProgramData\?w?w0) -- C:\ProgramData\䋠w㾐w0
[2013.04.28 11:33:04 | 000,000,000 | ---D | M](C:\ProgramData\?w?w0) -- C:\ProgramData\䋠w㾐w0
[2013.04.27 11:49:21 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䋠ƅ㾐ƅ0
[2013.04.27 11:49:21 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䋠ƅ㾐ƅ0
[2013.04.25 12:04:43 | 000,000,000 | ---D | M](C:\ProgramData\?T?T0) -- C:\ProgramData\䋠Ʈ㾐Ʈ0
[2013.04.25 12:04:43 | 000,000,000 | ---D | M](C:\ProgramData\?T?T0) -- C:\ProgramData\䋠Ʈ㾐Ʈ0
[2013.04.24 16:30:48 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䋠Nj㾐Nj0
[2013.04.24 16:30:48 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䋠Nj㾐Nj0
[2013.04.22 17:24:23 | 000,000,000 | ---D | M](C:\ProgramData\?Œ?Œ0) -- C:\ProgramData\䋠Œ㾐Œ0
[2013.04.22 17:24:23 | 000,000,000 | ---D | M](C:\ProgramData\?Œ?Œ0) -- C:\ProgramData\䋠Œ㾐Œ0
[2013.04.22 08:05:32 | 000,000,000 | ---D | M](C:\ProgramData\?Y?Y0) -- C:\ProgramData\䋠Ŷ㾐Ŷ0
[2013.04.22 08:05:32 | 000,000,000 | ---D | M](C:\ProgramData\?Y?Y0) -- C:\ProgramData\䋠Ŷ㾐Ŷ0
[2013.04.21 09:57:11 | 000,000,000 | ---D | M](C:\ProgramData\?S?S0) -- C:\ProgramData\䋠Ş㾐Ş0
[2013.04.21 09:57:11 | 000,000,000 | ---D | M](C:\ProgramData\?S?S0) -- C:\ProgramData\䋠Ş㾐Ş0
[2013.04.20 18:38:32 | 000,000,000 | ---D | M](C:\ProgramData\?Ú?Ú0) -- C:\ProgramData\䋠Ú㾐Ú0
[2013.04.20 18:38:32 | 000,000,000 | ---D | M](C:\ProgramData\?Ú?Ú0) -- C:\ProgramData\䋠Ú㾐Ú0
[2013.04.18 17:04:39 | 000,000,000 | ---D | M](C:\ProgramData\?.?.0) -- C:\ProgramData\䋠.㾐.0
[2013.04.18 17:04:39 | 000,000,000 | ---D | M](C:\ProgramData\?.?.0) -- C:\ProgramData\䋠.㾐.0
[2013.04.16 09:49:15 | 000,000,000 | ---D | M](C:\ProgramData\??0) -- C:\ProgramData\䋠㾐0
[2013.04.16 09:49:15 | 000,000,000 | ---D | M](C:\ProgramData\??0) -- C:\ProgramData\䋠㾐0
[2013.04.14 18:18:18 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䋠ƨ㾐ƨ0
[2013.04.14 18:18:18 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䋠ƨ㾐ƨ0
[2013.04.13 22:31:51 | 000,000,000 | ---D | M](C:\ProgramData\??0) -- C:\ProgramData\䋠㾐0
[2013.04.13 22:31:51 | 000,000,000 | ---D | M](C:\ProgramData\??0) -- C:\ProgramData\䋠㾐0
[2013.04.13 10:02:23 | 000,000,000 | ---D | M](C:\ProgramData\?ç?ç0) -- C:\ProgramData\䋠ç㾐ç0
[2013.04.13 10:02:23 | 000,000,000 | ---D | M](C:\ProgramData\?ç?ç0) -- C:\ProgramData\䋠ç㾐ç0
[2013.04.12 16:10:01 | 000,000,000 | ---D | M](C:\ProgramData\?5?50) -- C:\ProgramData\䋠5㾐50
[2013.04.12 16:10:01 | 000,000,000 | ---D | M](C:\ProgramData\?5?50) -- C:\ProgramData\䋠5㾐50
[2013.04.10 11:48:11 | 000,000,000 | ---D | M](C:\ProgramData\?U?U0) -- C:\ProgramData\䋠Ư㾐Ư0
[2013.04.10 11:48:11 | 000,000,000 | ---D | M](C:\ProgramData\?U?U0) -- C:\ProgramData\䋠Ư㾐Ư0
[2013.04.09 18:19:19 | 000,000,000 | ---D | M](C:\ProgramData\?É?É0) -- C:\ProgramData\䋠É㾐É0
[2013.04.09 18:19:19 | 000,000,000 | ---D | M](C:\ProgramData\?É?É0) -- C:\ProgramData\䋠É㾐É0
[2013.04.07 05:25:55 | 000,000,000 | ---D | M](C:\ProgramData\?ø?ø0) -- C:\ProgramData\䋠ø㾐ø0
[2013.04.07 05:25:55 | 000,000,000 | ---D | M](C:\ProgramData\?ø?ø0) -- C:\ProgramData\䋠ø㾐ø0
[2013.04.05 15:12:20 | 000,000,000 | ---D | M](C:\ProgramData\?-?-0) -- C:\ProgramData\䋠-㾐-0
[2013.04.05 15:12:20 | 000,000,000 | ---D | M](C:\ProgramData\?-?-0) -- C:\ProgramData\䋠-㾐-0
[2013.04.03 10:45:42 | 000,000,000 | ---D | M](C:\ProgramData\?C?C0) -- C:\ProgramData\䋠C㾐C0
[2013.04.03 10:45:42 | 000,000,000 | ---D | M](C:\ProgramData\?C?C0) -- C:\ProgramData\䋠C㾐C0
[2013.04.01 12:17:02 | 000,000,000 | ---D | M](C:\ProgramData\?t?t0) -- C:\ProgramData\䋠ƫ㾐ƫ0
[2013.04.01 12:17:02 | 000,000,000 | ---D | M](C:\ProgramData\?t?t0) -- C:\ProgramData\䋠ƫ㾐ƫ0
[2013.03.30 12:40:00 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䋠㾐0
[2013.03.30 12:40:00 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䋠㾐0
[2013.03.25 15:07:36 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䋠ǂ㾐ǂ0
[2013.03.25 15:07:36 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䋠ǂ㾐ǂ0
[2013.03.24 12:01:06 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䋠LJ㾐LJ0
[2013.03.24 12:01:06 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䋠LJ㾐LJ0
[2013.03.24 06:31:25 | 000,000,000 | ---D | M](C:\ProgramData\?ü?ü0) -- C:\ProgramData\䋠ü㾐ü0
[2013.03.24 06:31:25 | 000,000,000 | ---D | M](C:\ProgramData\?ü?ü0) -- C:\ProgramData\䋠ü㾐ü0
[2013.03.23 11:54:35 | 000,000,000 | ---D | M](C:\ProgramData\?ë?ë0) -- C:\ProgramData\䋠ë㾐ë0
[2013.03.23 11:54:35 | 000,000,000 | ---D | M](C:\ProgramData\?ë?ë0) -- C:\ProgramData\䋠ë㾐ë0
[2013.03.22 08:03:13 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䋠㾐0
[2013.03.22 08:03:13 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䋠㾐0
[2013.03.21 16:33:01 | 000,000,000 | ---D | M](C:\ProgramData\?L?L0) -- C:\ProgramData\䋠L㾐L0
[2013.03.21 16:33:01 | 000,000,000 | ---D | M](C:\ProgramData\?L?L0) -- C:\ProgramData\䋠L㾐L0
[2013.03.21 15:35:42 | 000,000,000 | ---D | M](C:\ProgramData\?E?E0) -- C:\ProgramData\䋠Ē㾐Ē0
[2013.03.21 15:35:42 | 000,000,000 | ---D | M](C:\ProgramData\?E?E0) -- C:\ProgramData\䋠Ē㾐Ē0
[2013.03.19 16:23:21 | 000,000,000 | ---D | M](C:\ProgramData\?D?D0) -- C:\ProgramData\䋠Ď㾐Ď0
[2013.03.19 16:23:21 | 000,000,000 | ---D | M](C:\ProgramData\?D?D0) -- C:\ProgramData\䋠Ď㾐Ď0
[2013.03.17 12:37:57 | 000,000,000 | ---D | M](C:\ProgramData\?A?A0) -- C:\ProgramData\䋠Ǟ㾐Ǟ0
[2013.03.17 12:37:57 | 000,000,000 | ---D | M](C:\ProgramData\?A?A0) -- C:\ProgramData\䋠Ǟ㾐Ǟ0
[2013.03.16 10:44:12 | 000,000,000 | ---D | M](C:\ProgramData\?3?30) -- C:\ProgramData\䋠3㾐30
[2013.03.16 10:44:12 | 000,000,000 | ---D | M](C:\ProgramData\?3?30) -- C:\ProgramData\䋠3㾐30
[2013.03.14 17:36:03 | 000,000,000 | ---D | M](C:\ProgramData\?ª?ª0) -- C:\ProgramData\䋠ª㾐ª0
[2013.03.14 17:36:03 | 000,000,000 | ---D | M](C:\ProgramData\?ª?ª0) -- C:\ProgramData\䋠ª㾐ª0
[2013.03.14 10:52:24 | 000,000,000 | ---D | M](C:\ProgramData\?M?M0) -- C:\ProgramData\䋠M㾐M0
[2013.03.14 10:52:24 | 000,000,000 | ---D | M](C:\ProgramData\?M?M0) -- C:\ProgramData\䋠M㾐M0
[2013.03.13 18:27:51 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䋠Ȍ㾐Ȍ0
[2013.03.13 18:27:51 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䋠Ȍ㾐Ȍ0
[2013.03.13 11:16:21 | 000,000,000 | ---D | M](C:\ProgramData\??0) -- C:\ProgramData\䋠㾐0
[2013.03.13 11:16:21 | 000,000,000 | ---D | M](C:\ProgramData\??0) -- C:\ProgramData\䋠㾐0
[2013.03.11 11:02:00 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䋠Ƿ㾐Ƿ0
[2013.03.11 11:02:00 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䋠Ƿ㾐Ƿ0
[2013.03.10 13:57:27 | 000,000,000 | ---D | M](C:\ProgramData\?c?c0) -- C:\ProgramData\䋠ć㾐ć0
[2013.03.10 13:57:27 | 000,000,000 | ---D | M](C:\ProgramData\?c?c0) -- C:\ProgramData\䋠ć㾐ć0
[2013.03.09 13:21:12 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䋠ǵ㾐ǵ0
[2013.03.09 13:21:12 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䋠ǵ㾐ǵ0
[2013.03.08 18:27:36 | 000,000,000 | ---D | M](C:\ProgramData\?U?U0) -- C:\ProgramData\䋠Ǖ㾐Ǖ0
[2013.03.08 18:27:36 | 000,000,000 | ---D | M](C:\ProgramData\?U?U0) -- C:\ProgramData\䋠Ǖ㾐Ǖ0
[2013.03.08 11:18:28 | 000,000,000 | ---D | M](C:\ProgramData\?D?D0) -- C:\ProgramData\䋠D㾐D0
[2013.03.08 11:18:28 | 000,000,000 | ---D | M](C:\ProgramData\?D?D0) -- C:\ProgramData\䋠D㾐D0
[2013.03.07 11:06:46 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䋠㾐0
[2013.03.07 11:06:46 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䋠㾐0
[2013.03.05 11:31:02 | 000,000,000 | ---D | M](C:\ProgramData\?u?u0) -- C:\ProgramData\䋠ǜ㾐ǜ0
[2013.03.05 11:31:02 | 000,000,000 | ---D | M](C:\ProgramData\?u?u0) -- C:\ProgramData\䋠ǜ㾐ǜ0
[2013.03.04 16:57:05 | 000,000,000 | ---D | M](C:\ProgramData\?6?60) -- C:\ProgramData\䋠6㾐60
[2013.03.04 16:57:05 | 000,000,000 | ---D | M](C:\ProgramData\?6?60) -- C:\ProgramData\䋠6㾐60
[2013.03.04 11:24:25 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䋠ǹ㾐ǹ0
[2013.03.04 11:24:25 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䋠ǹ㾐ǹ0
[2013.03.01 18:34:20 | 000,000,000 | ---D | M](C:\ProgramData\?E?E0) -- C:\ProgramData\䋠E㾐E0
[2013.03.01 18:34:20 | 000,000,000 | ---D | M](C:\ProgramData\?E?E0) -- C:\ProgramData\䋠E㾐E0
[2013.02.28 11:19:41 | 000,000,000 | ---D | M](C:\ProgramData\?U?U0) -- C:\ProgramData\䋠Ǘ㾐Ǘ0
[2013.02.28 11:19:41 | 000,000,000 | ---D | M](C:\ProgramData\?U?U0) -- C:\ProgramData\䋠Ǘ㾐Ǘ0
[2013.02.27 16:53:30 | 000,000,000 | ---D | M](C:\ProgramData\?'?'0) -- C:\ProgramData\䋠'㾐'0
[2013.02.27 16:53:30 | 000,000,000 | ---D | M](C:\ProgramData\?'?'0) -- C:\ProgramData\䋠'㾐'0
[2013.02.25 13:04:59 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䋠ǯ㾐ǯ0
[2013.02.25 13:04:59 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䋠ǯ㾐ǯ0
[2013.02.25 00:18:45 | 000,000,000 | ---D | M](C:\ProgramData\?Á?Á0) -- C:\ProgramData\䋠Á㾐Á0
[2013.02.25 00:18:45 | 000,000,000 | ---D | M](C:\ProgramData\?Á?Á0) -- C:\ProgramData\䋠Á㾐Á0
[2013.02.23 12:49:22 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䋠dž㾐dž0
[2013.02.23 12:49:22 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䋠dž㾐dž0
[2013.02.22 22:49:04 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䋠ǡ㾐ǡ0
[2013.02.22 22:49:04 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䋠ǡ㾐ǡ0
[2013.02.21 12:37:18 | 000,000,000 | ---D | M](C:\ProgramData\?i?i0) -- C:\ProgramData\䋠ǐ㾐ǐ0
[2013.02.21 12:37:18 | 000,000,000 | ---D | M](C:\ProgramData\?i?i0) -- C:\ProgramData\䋠ǐ㾐ǐ0
[2013.02.19 13:58:51 | 000,000,000 | ---D | M](C:\ProgramData\?O?O0) -- C:\ProgramData\䋠Ǭ㾐Ǭ0
[2013.02.19 13:58:51 | 000,000,000 | ---D | M](C:\ProgramData\?O?O0) -- C:\ProgramData\䋠Ǭ㾐Ǭ0
[2013.02.18 15:07:39 | 000,000,000 | ---D | M](C:\ProgramData\?{?{0) -- C:\ProgramData\䋠{㾐{0
[2013.02.18 15:07:39 | 000,000,000 | ---D | M](C:\ProgramData\?{?{0) -- C:\ProgramData\䋠{㾐{0
[2013.02.17 17:18:31 | 000,000,000 | ---D | M](C:\ProgramData\?g?g0) -- C:\ProgramData\䋠ĝ㾐ĝ0
[2013.02.17 17:18:31 | 000,000,000 | ---D | M](C:\ProgramData\?g?g0) -- C:\ProgramData\䋠ĝ㾐ĝ0
[2013.02.16 06:24:05 | 000,000,000 | ---D | M](C:\ProgramData\?K?K0) -- C:\ProgramData\䋠Ǩ㾐Ǩ0
[2013.02.16 06:24:05 | 000,000,000 | ---D | M](C:\ProgramData\?K?K0) -- C:\ProgramData\䋠Ǩ㾐Ǩ0
[2013.02.15 14:15:29 | 000,000,000 | ---D | M](C:\ProgramData\?g?g0) -- C:\ProgramData\䋠ǧ㾐ǧ0
[2013.02.15 14:15:29 | 000,000,000 | ---D | M](C:\ProgramData\?g?g0) -- C:\ProgramData\䋠ǧ㾐ǧ0
[2013.02.14 13:41:36 | 000,000,000 | ---D | M](C:\ProgramData\?c?c0) -- C:\ProgramData\䋠ċ㾐ċ0
[2013.02.14 13:41:36 | 000,000,000 | ---D | M](C:\ProgramData\?c?c0) -- C:\ProgramData\䋠ċ㾐ċ0
[2013.02.13 19:52:31 | 000,000,000 | ---D | M](C:\ProgramData\?R?R0) -- C:\ProgramData\䋠Ř㾐Ř0
[2013.02.13 19:52:31 | 000,000,000 | ---D | M](C:\ProgramData\?R?R0) -- C:\ProgramData\䋠Ř㾐Ř0
[2013.02.13 12:44:11 | 000,000,000 | ---D | M](C:\ProgramData\?A?A0) -- C:\ProgramData\䋠Ă㾐Ă0
[2013.02.13 12:44:11 | 000,000,000 | ---D | M](C:\ProgramData\?A?A0) -- C:\ProgramData\䋠Ă㾐Ă0
[2013.02.12 20:45:33 | 000,000,000 | ---D | M](C:\ProgramData\?å?å0) -- C:\ProgramData\䋠å㾐å0
[2013.02.12 20:45:33 | 000,000,000 | ---D | M](C:\ProgramData\?å?å0) -- C:\ProgramData\䋠å㾐å0
[2013.02.12 12:56:50 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䋠ǝ㾐ǝ0
[2013.02.12 12:56:50 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䋠ǝ㾐ǝ0
[2013.02.11 14:01:44 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䋠DZ㾐DZ0
[2013.02.11 14:01:44 | 000,000,000 | ---D | M](C:\ProgramData\????0) -- C:\ProgramData\䋠DZ㾐DZ0
(C:\ProgramData\?Y?Y0) -- C:\ProgramData\䋠Ŷ㾐Ŷ0
(C:\ProgramData\?w?w0) -- C:\ProgramData\䋠w㾐w0
(C:\ProgramData\?ü?ü0) -- C:\ProgramData\䋠ü㾐ü0
(C:\ProgramData\?Ú?Ú0) -- C:\ProgramData\䋠Ú㾐Ú0
(C:\ProgramData\?U?U0) -- C:\ProgramData\䋠Ư㾐Ư0
(C:\ProgramData\?U?U0) -- C:\ProgramData\䋠Ǖ㾐Ǖ0
(C:\ProgramData\?u?u0) -- C:\ProgramData\䋠ǜ㾐ǜ0
(C:\ProgramData\?U?U0) -- C:\ProgramData\䋠Ǘ㾐Ǘ0
(C:\ProgramData\?U?U0) -- C:\ProgramData\䋠Ű㾐Ű0
(C:\ProgramData\?T?T0) -- C:\ProgramData\䋠Ʈ㾐Ʈ0
(C:\ProgramData\?t?t0) -- C:\ProgramData\䋠ƫ㾐ƫ0
(C:\ProgramData\?S?S0) -- C:\ProgramData\䋠Ş㾐Ş0
(C:\ProgramData\?R?R0) -- C:\ProgramData\䋠Ř㾐Ř0
(C:\ProgramData\?Œ?Œ0) -- C:\ProgramData\䋠Œ㾐Œ0
(C:\ProgramData\?ø?ø0) -- C:\ProgramData\䋠ø㾐ø0
(C:\ProgramData\?O?O0) -- C:\ProgramData\䋠Ǭ㾐Ǭ0
(C:\ProgramData\?M?M0) -- C:\ProgramData\䋠M㾐M0
(C:\ProgramData\?L?L0) -- C:\ProgramData\䋠L㾐L0
(C:\ProgramData\?K?K0) -- C:\ProgramData\䋠Ǩ㾐Ǩ0
(C:\ProgramData\?i?i0) -- C:\ProgramData\䋠ǐ㾐ǐ0
(C:\ProgramData\?g?g0) -- C:\ProgramData\䋠ǧ㾐ǧ0
(C:\ProgramData\?g?g0) -- C:\ProgramData\䋠ĝ㾐ĝ0
(C:\ProgramData\?ë?ë0) -- C:\ProgramData\䋠ë㾐ë0
(C:\ProgramData\?É?É0) -- C:\ProgramData\䋠É㾐É0
(C:\ProgramData\?E?E0) -- C:\ProgramData\䋠Ē㾐Ē0
(C:\ProgramData\?E?E0) -- C:\ProgramData\䋠E㾐E0
(C:\ProgramData\?D?D0) -- C:\ProgramData\䋠Ď㾐Ď0
(C:\ProgramData\?D?D0) -- C:\ProgramData\䋠D㾐D0
(C:\ProgramData\?ç?ç0) -- C:\ProgramData\䋠ç㾐ç0
(C:\ProgramData\?c?c0) -- C:\ProgramData\䋠ċ㾐ċ0
(C:\ProgramData\?c?c0) -- C:\ProgramData\䋠ć㾐ć0
(C:\ProgramData\?C?C0) -- C:\ProgramData\䋠C㾐C0
(C:\ProgramData\?å?å0) -- C:\ProgramData\䋠å㾐å0
(C:\ProgramData\?Á?Á0) -- C:\ProgramData\䋠Á㾐Á0
(C:\ProgramData\?ª?ª0) -- C:\ProgramData\䋠ª㾐ª0
(C:\ProgramData\?A?A0) -- C:\ProgramData\䋠Ǟ㾐Ǟ0
(C:\ProgramData\?A?A0) -- C:\ProgramData\䋠Ă㾐Ă0
(C:\ProgramData\?6?60) -- C:\ProgramData\䋠6㾐60
(C:\ProgramData\?5?50) -- C:\ProgramData\䋠5㾐50
(C:\ProgramData\?3?30) -- C:\ProgramData\䋠3㾐30
(C:\ProgramData\??0) -- C:\ProgramData\䋠㾐0
(C:\ProgramData\??0) -- C:\ProgramData\䋠㾐0
(C:\ProgramData\??0) -- C:\ProgramData\䋠㾐0
(C:\ProgramData\?{?{0) -- C:\ProgramData\䋠{㾐{0
(C:\ProgramData\?-?-0) -- C:\ProgramData\䋠-㾐-0
(C:\ProgramData\?'?'0) -- C:\ProgramData\䋠'㾐'0
(C:\ProgramData\????0) -- C:\ProgramData\䋠ƹ㾐ƹ0
(C:\ProgramData\????0) -- C:\ProgramData\䋠ǯ㾐ǯ0
(C:\ProgramData\????0) -- C:\ProgramData\䋠ƨ㾐ƨ0
(C:\ProgramData\????0) -- C:\ProgramData\䋠Ƿ㾐Ƿ0
(C:\ProgramData\????0) -- C:\ProgramData\䋠Ȍ㾐Ȍ0
(C:\ProgramData\????0) -- C:\ProgramData\䋠ǹ㾐ǹ0
(C:\ProgramData\????0) -- C:\ProgramData\䋠Nj㾐Nj0
(C:\ProgramData\????0) -- C:\ProgramData\䋠LJ㾐LJ0
(C:\ProgramData\????0) -- C:\ProgramData\䋠ǵ㾐ǵ0
(C:\ProgramData\????0) -- C:\ProgramData\䋠ǝ㾐ǝ0
(C:\ProgramData\????0) -- C:\ProgramData\䋠dž㾐dž0
(C:\ProgramData\????0) -- C:\ProgramData\䋠DZ㾐DZ0
(C:\ProgramData\????0) -- C:\ProgramData\䋠ƅ㾐ƅ0
(C:\ProgramData\????0) -- C:\ProgramData\䋠ǡ㾐ǡ0
(C:\ProgramData\????0) -- C:\ProgramData\䋠㾐0
(C:\ProgramData\????0) -- C:\ProgramData\䋠㾐0
(C:\ProgramData\????0) -- C:\ProgramData\䋠㾐0
(C:\ProgramData\????0) -- C:\ProgramData\䋠ǂ㾐ǂ0
(C:\ProgramData\?.?.0) -- C:\ProgramData\䋠.㾐.0
(C:\ProgramData\?!?!0) -- C:\ProgramData\䋠ǃ㾐ǃ0
< End of report > |