Hi,
hier allle Erbebnisse der einzelnen Tools. Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 31.07.2014
Suchlauf-Zeit: 06:46:24
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.07.31.02
Rootkit Datenbank: v2014.07.17.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x86
Dateisystem: NTFS
Benutzer: Gnodti
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 315911
Verstrichene Zeit: 14 Min, 27 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 2
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginServices\PluginService.exe, 1840, Löschen bei Neustart, [de30e0c6a0db61d5a3f10956fa072dd3]
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, 1888, Löschen bei Neustart, [43cbbceabac10036eda9484a6c95f60a]
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 36
PUP.Optional.IePluginService.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IePluginServices, In Quarantäne, [de30e0c6a0db61d5a3f10956fa072dd3],
PUP.Optional.WPM.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WindowsMangerProtect, In Quarantäne, [43cbbceabac10036eda9484a6c95f60a],
PUP.Optional.WPM.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\WindowsMangerProtect, In Quarantäne, [43cbbceabac10036eda9484a6c95f60a],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [86887432e59676c03ece73f04fb3d42c],
PUP.Optional.HQVideo.A, HKLM\SOFTWARE\HQual-V1.8, In Quarantäne, [9b737b2b4f2c1c1aca619638f30fde22],
PUP.Optional.WPM.A, HKLM\SOFTWARE\supWindowsMangerProtect, In Quarantäne, [66a8e4c22d4e7abc7eb5af7ffa0ac739],
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\webssearchesSoftware, In Quarantäne, [8589ced8de9de74f39301dce7191e61a],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0059568.BHO, In Quarantäne, [96785c4a2d4ebb7bef99814d23df03fd],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0059568.BHO.1, In Quarantäne, [b55923835e1d053101872ba311f1867a],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0059568.Sandbox, In Quarantäne, [8e80e8be4f2cb87e2d5b606ef70b16ea],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0059568.Sandbox.1, In Quarantäne, [030becba4b304ee81177d8f6d42e26da],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\GLOBALUPDATE\UPDATE, In Quarantäne, [0b03e9bdf08bf83e52eec10f19e929d7],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\19979, In Quarantäne, [7f8fe2c4d7a4a0964444717aa55d7b85],
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [b25cb8eec6b513233979f42562a2e41c],
PUP.Optional.SystemSpeedup, HKLM\SOFTWARE\SYSTWEAK\ssd, In Quarantäne, [e727b0f6bfbc7fb78adcb81a29d9f10f],
PUP.Optional.HQVideo.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\HQual-V1.8, In Quarantäne, [fc12b8eebebd0c2a5dd0b5198b7741bf],
PUP.Optional.MediaPlayer.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\video MediaPlay-Air, In Quarantäne, [c747eabc205bfe3861da4fdfce366f91],
PUP.Optional.HQVideo.A, HKU\S-1-5-21-3047901106-525017762-2591671917-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\HQual-V1.8, In Quarantäne, [b15d9610c1ba50e6ea436767847ead53],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-3047901106-525017762-2591671917-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarantäne, [98762e780774989eb03542b5e22051af],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-3047901106-525017762-2591671917-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, In Quarantäne, [be50d1d5037849ed39ca28e694707f81],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3047901106-525017762-2591671917-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\19979, In Quarantäne, [ca4411952457ae88fd8cba31f30f05fb],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3047901106-525017762-2591671917-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\HQualVideo, In Quarantäne, [d33b6b3be79458de101e07c7ad550ff1],
PUP.Optional.Qone8, HKU\S-1-5-21-3047901106-525017762-2591671917-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [070734723e3d52e403ae0b0ea85c05fb],
PUP.Optional.SystemSpeedup, HKU\S-1-5-21-3047901106-525017762-2591671917-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SYSTWEAK\ssd, In Quarantäne, [35d98b1b8eedd363570e7c56a1612bd5],
PUP.Optional.GlobalUpdate.T, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\globalUpdatem, In Quarantäne, [729c4363522964d299d361642bd79967],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, In Quarantäne, [729c4363522964d299d361642bd79967],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, In Quarantäne, [729c4363522964d299d361642bd79967],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\globalUpdate.OneClickCtrl.10, In Quarantäne, [729c4363522964d299d361642bd79967],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, In Quarantäne, [729c4363522964d299d361642bd79967],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, In Quarantäne, [729c4363522964d299d361642bd79967],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, In Quarantäne, [729c4363522964d299d361642bd79967],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\globalUpdate.Update3WebControl.4, In Quarantäne, [729c4363522964d299d361642bd79967],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, In Quarantäne, [729c4363522964d299d361642bd79967],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, In Quarantäne, [729c4363522964d299d361642bd79967],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}, In Quarantäne, [729c4363522964d299d361642bd79967],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}, In Quarantäne, [729c4363522964d299d361642bd79967],
Registrierungswerte: 3
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\GLOBALUPDATE\UPDATE|path, C:\Program Files\globalUpdate\Update\GoogleUpdate.exe, In Quarantäne, [0b03e9bdf08bf83e52eec10f19e929d7]
PUP.Optional.InstallCore.A, HKU\S-1-5-21-3047901106-525017762-2591671917-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0X2O1C0R2R1R, In Quarantäne, [be50d1d5037849ed39ca28e694707f81]
PUP.Optional.FastStart.A, HKU\S-1-5-21-3047901106-525017762-2591671917-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\EXTENDS|appid, faststartff@gmail.com, In Quarantäne, [e5299016c3b894a24f106e65dd25f709]
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 31
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices, Löschen bei Neustart, [25e90d996516fa3c8c90fcc536ccb947],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update, In Quarantäne, [25e90d996516fa3c8c90fcc536ccb947],
PUP.Optional.SearchProtect.A, C:\Users\Gnodti\AppData\Local\SearchProtect, In Quarantäne, [bd512284344766d0d24b8f329b6713ed],
PUP.Optional.SearchProtect.A, C:\Users\Gnodti\AppData\Local\SearchProtect\Logs, In Quarantäne, [bd512284344766d0d24b8f329b6713ed],
PUP.Optional.CrossRider.A, C:\Users\Gnodti\AppData\Local\Google\Chrome\User Data\Default\Extensions\cdihkdldaicijakhchgojcokhpamkibi, In Quarantäne, [3cd25e487209c373fc20dce77c86cc34],
PUP.Optional.CrossRider.A, C:\Users\Gnodti\AppData\Local\Google\Chrome\User Data\Default\Extensions\cdihkdldaicijakhchgojcokhpamkibi\1.26.60_0, In Quarantäne, [3cd25e487209c373fc20dce77c86cc34],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect, Löschen bei Neustart, [26e8f0b6017a0e28b3dd51727b8708f8],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\log, In Quarantäne, [26e8f0b6017a0e28b3dd51727b8708f8],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update, In Quarantäne, [26e8f0b6017a0e28b3dd51727b8708f8],
PUP.Optional.SystemSpeedup, C:\Users\Gnodti\AppData\Roaming\Systweak\ssd, In Quarantäne, [927ce1c5681366d03bf820a4a65cf10f],
PUP.Optional.Fabulous.Discounts.T, C:\Users\Gnodti\AppData\Local\fabulous_07170539, In Quarantäne, [3ed0f9ad384388ae2249e2e3d9290cf4],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update, In Quarantäne, [729c4363522964d299d361642bd79967],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0, In Quarantäne, [729c4363522964d299d361642bd79967],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\Download, In Quarantäne, [729c4363522964d299d361642bd79967],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\Install, In Quarantäne, [729c4363522964d299d361642bd79967],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\Offline, In Quarantäne, [729c4363522964d299d361642bd79967],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\Offline\{182434C3-3954-4187-AD46-DDE83C868C43}, In Quarantäne, [729c4363522964d299d361642bd79967],
PUP.Optional.CrossRider.A, C:\Users\Gnodti\AppData\Local\Google\Chrome\User Data\Default\Extensions\dnaojefanpmakfgcaliphepgoiiafmpf, In Quarantäne, [df2f2d79e3988ea84738774e3dc5916f],
PUP.Optional.CrossRider.A, C:\Users\Gnodti\AppData\Local\Google\Chrome\User Data\Default\Extensions\dnaojefanpmakfgcaliphepgoiiafmpf\1.26.34_0, In Quarantäne, [df2f2d79e3988ea84738774e3dc5916f],
PUP.Optional.MultiPlug.A, C:\ProgramData\cosstminn, In Quarantäne, [4ac4c6e0fa81ae88d4d24b7a52b0a759],
PUP.Optional.MultiPlug.A, C:\Program Files\cosstminn, In Quarantäne, [d638693ddc9f88ae198efdc813ef936d],
PUP.Optional.SupTab.A, C:\Program Files\SupTab, In Quarantäne, [a16d376f2b506ec8a1163b8ede249c64],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System-Protector, In Quarantäne, [dc327b2be39853e3b0329336e41e4ab6],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System-Protector\2.1.1000.13665, In Quarantäne, [dc327b2be39853e3b0329336e41e4ab6],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System-Protector\signatures, In Quarantäne, [dc327b2be39853e3b0329336e41e4ab6],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System-Protector\updates, In Quarantäne, [dc327b2be39853e3b0329336e41e4ab6],
PUP.Optional.AdvancedSystemProtector.A, C:\Users\Gnodti\AppData\Roaming\Systweak\Advanced-System-Protector, In Quarantäne, [be50f1b58eedb086875b587126dc1de3],
PUP.Optional.AdvancedSystemProtector.A, C:\Users\Gnodti\AppData\Roaming\Systweak\Advanced-System-Protector\2.1.1000.13665, In Quarantäne, [be50f1b58eedb086875b587126dc1de3],
PUP.Optional.AdvancedSystemProtector.A, C:\Users\Gnodti\AppData\Roaming\Systweak\Advanced-System-Protector\Backup, In Quarantäne, [be50f1b58eedb086875b587126dc1de3],
PUP.Optional.AdvancedSystemProtector.A, C:\Users\Gnodti\AppData\Roaming\Systweak\Advanced-System-Protector\Logs, In Quarantäne, [be50f1b58eedb086875b587126dc1de3],
PUP.Optional.AdvancedSystemProtector.A, C:\Users\Gnodti\AppData\Roaming\Systweak\Advanced-System-Protector\Quarantine, In Quarantäne, [be50f1b58eedb086875b587126dc1de3],
Dateien: 48
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginServices\PluginService.exe, Löschen bei Neustart, [de30e0c6a0db61d5a3f10956fa072dd3],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, Löschen bei Neustart, [43cbbceabac10036eda9484a6c95f60a],
PUP.Optional.WebsSearches.A, C:\Program Files\Mozilla Firefox\browser\searchplugins\webssearches.xml, In Quarantäne, [0e004561adcebb7b452616d555add927],
PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job, In Quarantäne, [25e93472dba0a0960bdd35f9857f817f],
PUP.Optional.GlobalUpdate.A, C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore, In Quarantäne, [55b90f97ed8e77bf688166c87f85c040],
PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job, In Quarantäne, [7c92bee81d5eee4883673fefb84c1be5],
PUP.Optional.GlobalUpdate.A, C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA, In Quarantäne, [19f5efb757240a2cea0170be6c985aa6],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update\conf, In Quarantäne, [25e90d996516fa3c8c90fcc536ccb947],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update\conf, In Quarantäne, [26e8f0b6017a0e28b3dd51727b8708f8],
PUP.Optional.SystemSpeedup, C:\Users\Gnodti\AppData\Roaming\Systweak\ssd\SSDPTstub.exe, In Quarantäne, [927ce1c5681366d03bf820a4a65cf10f],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\GoogleUpdate.exe, In Quarantäne, [729c4363522964d299d361642bd79967],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleCrashHandler.exe, In Quarantäne, [729c4363522964d299d361642bd79967],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdate.exe, In Quarantäne, [729c4363522964d299d361642bd79967],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe, In Quarantäne, [729c4363522964d299d361642bd79967],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdateHelper.msi, In Quarantäne, [729c4363522964d299d361642bd79967],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe, In Quarantäne, [729c4363522964d299d361642bd79967],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\goopdate.dll, In Quarantäne, [729c4363522964d299d361642bd79967],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\goopdateres_en.dll, In Quarantäne, [729c4363522964d299d361642bd79967],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll, In Quarantäne, [729c4363522964d299d361642bd79967],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\psmachine.dll, In Quarantäne, [729c4363522964d299d361642bd79967],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\psuser.dll, In Quarantäne, [729c4363522964d299d361642bd79967],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\DpInterface32.dll, In Quarantäne, [a16d376f2b506ec8a1163b8ede249c64],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\SupTab.dll, In Quarantäne, [a16d376f2b506ec8a1163b8ede249c64],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System-Protector\AddonSafelist, In Quarantäne, [dc327b2be39853e3b0329336e41e4ab6],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System-Protector\signatures\completedatabase.db, In Quarantäne, [dc327b2be39853e3b0329336e41e4ab6],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System-Protector\signatures\Cookies.bin, In Quarantäne, [dc327b2be39853e3b0329336e41e4ab6],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System-Protector\signatures\DigSign.bin, In Quarantäne, [dc327b2be39853e3b0329336e41e4ab6],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System-Protector\signatures\FilePathFIX.bin, In Quarantäne, [dc327b2be39853e3b0329336e41e4ab6],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System-Protector\signatures\FilePaths.bin, In Quarantäne, [dc327b2be39853e3b0329336e41e4ab6],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System-Protector\signatures\FileSignature.bin, In Quarantäne, [dc327b2be39853e3b0329336e41e4ab6],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System-Protector\signatures\Folders.bin, In Quarantäne, [dc327b2be39853e3b0329336e41e4ab6],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System-Protector\signatures\Md5.bin, In Quarantäne, [dc327b2be39853e3b0329336e41e4ab6],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System-Protector\signatures\Registry.bin, In Quarantäne, [dc327b2be39853e3b0329336e41e4ab6],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System-Protector\signatures\SetupSign.bin, In Quarantäne, [dc327b2be39853e3b0329336e41e4ab6],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System-Protector\signatures\StrSetupSign.bin, In Quarantäne, [dc327b2be39853e3b0329336e41e4ab6],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System-Protector\updates\100oupdate.zip, In Quarantäne, [dc327b2be39853e3b0329336e41e4ab6],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System-Protector\updates\1835completedatabase.zip, In Quarantäne, [dc327b2be39853e3b0329336e41e4ab6],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System-Protector\updates\1884mupdate.zip, In Quarantäne, [dc327b2be39853e3b0329336e41e4ab6],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System-Protector\updates\1885update.zip, In Quarantäne, [dc327b2be39853e3b0329336e41e4ab6],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System-Protector\updates\1886update.zip, In Quarantäne, [dc327b2be39853e3b0329336e41e4ab6],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System-Protector\updates\1887update.zip, In Quarantäne, [dc327b2be39853e3b0329336e41e4ab6],
PUP.Optional.AdvancedSystemProtector.A, C:\Users\Gnodti\AppData\Roaming\Systweak\Advanced-System-Protector\QDetail.db, In Quarantäne, [be50f1b58eedb086875b587126dc1de3],
PUP.Optional.AdvancedSystemProtector.A, C:\Users\Gnodti\AppData\Roaming\Systweak\Advanced-System-Protector\Settings.db, In Quarantäne, [be50f1b58eedb086875b587126dc1de3],
PUP.Optional.AdvancedSystemProtector.A, C:\Users\Gnodti\AppData\Roaming\Systweak\Advanced-System-Protector\Update.ini, In Quarantäne, [be50f1b58eedb086875b587126dc1de3],
PUP.Optional.AdvancedSystemProtector.A, C:\Users\Gnodti\AppData\Roaming\Systweak\Advanced-System-Protector\2.1.1000.13665\ASPLog.txt, In Quarantäne, [be50f1b58eedb086875b587126dc1de3],
PUP.Optional.AdvancedSystemProtector.A, C:\Users\Gnodti\AppData\Roaming\Systweak\Advanced-System-Protector\Logs\log_22-07-14_10-41-01.xml, In Quarantäne, [be50f1b58eedb086875b587126dc1de3],
PUP.Optional.AdvancedSystemProtector.A, C:\Users\Gnodti\AppData\Roaming\Systweak\Advanced-System-Protector\Logs\SMLog.xml, In Quarantäne, [be50f1b58eedb086875b587126dc1de3],
PUP.Optional.CrossRider.A, C:\Users\Gnodti\AppData\Roaming\Mozilla\Firefox\Profiles\0937xwmn.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.crossrider.bic", "147445e5a0bb00f086fa16a6868bfa65");), Ersetzt,[39d5d5d16c0fcb6b0a3545a5dc2809f7]
Physische Sektoren: 0
(No malicious items detected)
(end) Code:
# AdwCleaner v3.302 - Bericht erstellt am 31/07/2014 um 07:16:02
# Aktualisiert 30/07/2014 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (32 bits)
# Benutzername : Gnodti - INTER-ZSE-HS-38
# Gestartet von : C:\Users\Gnodti\Downloads\adwcleaner_3.302.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\ParetoLogic
Ordner Gelöscht : C:\ProgramData\Systweak
Ordner Gelöscht : C:\Program Files\globalUpdate
Ordner Gelöscht : C:\Program Files\predm
Ordner Gelöscht : C:\Users\Gnodti\AppData\Local\globalUpdate
Ordner Gelöscht : C:\Users\Gnodti\AppData\Roaming\DriverCure
Ordner Gelöscht : C:\Users\Gnodti\AppData\Roaming\ParetoLogic
Ordner Gelöscht : C:\Users\Gnodti\AppData\Roaming\Systweak
Datei Gelöscht : C:\END
Datei Gelöscht : C:\Windows\system32\roboot.exe
***** [ Tasks ] *****
Task Gelöscht : ASP
Task Gelöscht : Dealply
Task Gelöscht : driverupdate startup
Task Gelöscht : LaunchApp
Task Gelöscht : YourFile DownloaderUpdate
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\WajamInternetEnhancer_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\WajamInternetEnhancer_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginServices
Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550555955568}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660566956668}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Schlüssel Gelöscht : HKCU\Software\GlobalUpdate
Schlüssel Gelöscht : HKCU\Software\InstalledBrowserExtensions
Schlüssel Gelöscht : HKCU\Software\ParetoLogic
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKCU\Software\TutoTag
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\adawarebp
Schlüssel Gelöscht : HKLM\Software\GlobalUpdate
Schlüssel Gelöscht : HKLM\Software\InstalledBrowserExtensions
Schlüssel Gelöscht : HKLM\Software\ParetoLogic
Schlüssel Gelöscht : HKLM\Software\SupDp
Schlüssel Gelöscht : HKLM\Software\SupTab
Schlüssel Gelöscht : HKLM\Software\supWPM
Schlüssel Gelöscht : HKLM\Software\systweak
Schlüssel Gelöscht : HKLM\Software\Tutorials
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17207
-\\ Mozilla Firefox v30.0 (de)
[ Datei : C:\Users\Gnodti\AppData\Roaming\Mozilla\Firefox\Profiles\0937xwmn.default\prefs.js ]
Zeile gelöscht : user_pref("extensions.af80af4ec42b9429d99b04078ec7cf86444882d2088654b13b79eae8470d9a955com59568.59568.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssf[...]
Zeile gelöscht : user_pref("extensions.crossrider.bic", "147445e5a0bb00f086fa16a6868bfa65");
[ Datei : C:\Users\Gnodti\AppData\Roaming\Mozilla\Firefox\Profiles\jvcxtz0c.default\prefs.js ]
-\\ Google Chrome v
[ Datei : C:\Users\Gnodti\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [22911 octets] - [16/07/2014 11:21:44]
AdwCleaner[R1].txt - [875 octets] - [16/07/2014 11:33:50]
AdwCleaner[R2].txt - [8154 octets] - [17/07/2014 13:21:02]
AdwCleaner[R3].txt - [7733 octets] - [31/07/2014 07:14:55]
AdwCleaner[S0].txt - [21658 octets] - [16/07/2014 11:23:33]
AdwCleaner[S1].txt - [7582 octets] - [17/07/2014 13:22:27]
AdwCleaner[S2].txt - [7654 octets] - [31/07/2014 07:16:02]
########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [7714 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Professional x86
Ran by Gnodti on 31.07.2014 at 7:21:40,47
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\privdogservice
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{44444444-4444-4444-4444-440544954468}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{44444444-4444-4444-4444-440544954468}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\adtrustmedia"
Successfully deleted: [Folder] "C:\Program Files\adtrustmedia"
Successfully deleted: [Folder] "C:\Program Files\software informer"
~~~ FireFox
Successfully deleted: [Folder] C:\Users\Gnodti\AppData\Roaming\mozilla\firefox\profiles\0937xwmn.default\extensions\toolbar@web.de
Emptied folder: C:\Users\Gnodti\AppData\Roaming\mozilla\firefox\profiles\0937xwmn.default\minidumps [6 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 31.07.2014 at 7:25:26,28
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Momentan weiß ich zwar nicht was ich mir trotz Comodo eingefangen habe/hatte. Aber eines ist mal sicher so langsam und allmählich fängt meine Maschine wieder an vernünftig zu laufen.
Bis hier her an alle ein großes DANKE SCHÖN :-) :-) :-)
LG Michael
Oh, sorry die frische FRST.log in der Euphorie vergessen.
Teil I Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:31-07-2014 01
Ran by Gnodti (administrator) on INTER-ZSE-HS-38 on 31-07-2014 07:43:23
Running from C:\Users\Gnodti\Downloads
Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
() C:\Program Files\Dokan\DokanLibrary\mounter.exe
(PDF Complete Inc) C:\Program Files\PDF Complete\pdfsvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(AMD) C:\Program Files\ATI Technologies\HydraVision\HydraDM.exe
() C:\Program Files\USB Sharing\usbshare.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\RunOnce: [NCPluginUpdater] => C:\Program Files\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe [21720 2014-07-08] (Hewlett-Packard)
HKU\S-1-5-21-3047901106-525017762-2591671917-1000\...\Run: [HydraVisionDesktopManager] => C:\Program Files\ATI Technologies\HydraVision\HydraDM.exe [393216 2012-03-22] (AMD)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\USB Sharing.lnk
ShortcutTarget: USB Sharing.lnk -> C:\Program Files\USB Sharing\usbshare.exe ()
ShellIconOverlayIdentifiers: SkyDrivePro1 (ErrorConflict) -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers: SkyDrivePro2 (SyncInProgress) -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers: SkyDrivePro3 (InSync) -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software)
ShellIconOverlayIdentifiers: ShareOverlay -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://de.yahoo.com?fr=fp-comodo
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=AV01
HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.msn.com/?pc=AV01
SearchScopes: HKLM - {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKCU - {297F98C7-9E48-435C-B75C-5BDC33923972} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKCU - {8EEAC88A-079B-4b2c-80C1-7836F79EB40A} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-comodo
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll (IvoSoft)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Gnodti\AppData\Roaming\Mozilla\Firefox\Profiles\0937xwmn.default
FF NewTab: chrome://unitedtb/content/newtab/newtab-page.xhtml
FF SelectedSearchEngine: Yahoo
FF Homepage: about:home
FF Keyword.URL: hxxp://de.search.yahoo.com/search?fr=ytff-comodo&p=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=10.65.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.65.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/Lync,version=15.0 - C:\Program Files\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll No File
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll No File
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Adblock Plus - C:\Users\Gnodti\AppData\Roaming\Mozilla\Firefox\Profiles\0937xwmn.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-07-18]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-07-25]
FF HKCU\...\Firefox\Extensions: [PrivDog@AdTrustMedia.com] - C:\Users\Gnodti\AppData\Roaming\Mozilla\Firefox\Profiles\jvcxtz0c.default\extensions
FF Extension: No Name - C:\Users\Gnodti\AppData\Roaming\Mozilla\Firefox\Profiles\jvcxtz0c.default\extensions [2013-06-17]
Chrome:
=======
CHR HomePage: hxxp://de.yahoo.com?fr=fpc-comodo
CHR RestoreOnStartup: "hxxp://de.yahoo.com?fr=fpc-comodo"
CHR Extension: (No Name) - C:\Users\Gnodti\AppData\Local\Google\Chrome\User Data\Default\Extensions\elioeckkoogikoehmiigdhokijamnmaj [2014-07-17]
CHR Extension: (No Name) - C:\Users\Gnodti\AppData\Local\Google\Chrome\User Data\Default\Extensions\olplonfdcekbkpjnoeecfihlkfdkehbj [2014-07-10]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-07-25]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [291840 2012-03-22] (Advanced Micro Devices, Inc.) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-07-25] (AVAST Software)
R2 DokanMounter; C:\Program Files\Dokan\DokanLibrary\mounter.exe [14848 2011-01-10] () [File not signed]
R2 HP Support Assistant Service; C:\Program Files\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2013-11-04] (Hewlett-Packard Company) [File not signed]
R2 pdfcDispatcher; C:\Program Files\PDF Complete\pdfsvc.exe [1128952 2011-05-06] (PDF Complete Inc)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService.exe [250072 2014-07-11] (Realtek Semiconductor)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R0 amd_sata; C:\Windows\System32\drivers\amd_sata.sys [64128 2010-11-05] (Advanced Micro Devices)
R0 amd_xata; C:\Windows\System32\drivers\amd_xata.sys [32384 2010-11-05] (Advanced Micro Devices)
R2 AODDriver4.1; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [39936 2011-11-13] (Advanced Micro Devices) [File not signed]
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24184 2014-07-25] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [67824 2014-07-25] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [81768 2014-07-25] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2014-07-25] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [779536 2014-07-25] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [414520 2014-07-25] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [71944 2014-07-25] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [192352 2014-07-25] ()
R3 cxbu0wdm; C:\Windows\System32\DRIVERS\cxbu0wdm.sys [131064 2014-04-05] (HID Global Corporation)
R2 Dokan; C:\Windows\system32\drivers\dokan.sys [95744 2011-01-10] (Windows (R) Win 7 DDK provider) [File not signed]
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [110296 2014-07-31] (Malwarebytes Corporation)
S3 netr28u; C:\Windows\System32\DRIVERS\netr28u.sys [657408 2009-07-14] (Ralink Technology Corp.)
S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [13464 2014-07-16] ()
S3 BEHRINGER_2902; System32\Drivers\BUSB2902.sys [X]
S3 BUSB_AUDIO_WDM; system32\drivers\busbwdm.sys [X]
S3 catchme; \??\C:\Users\Gnodti\AppData\Local\Temp\catchme.sys [X]
S3 cpuz134; \??\C:\Users\Gnodti\AppData\Local\Temp\cpuz134\cpuz134_x32.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-07-31 07:43 - 2014-07-31 07:43 - 01084928 _____ (Farbar) C:\Users\Gnodti\Downloads\FRST.exe
2014-07-31 07:25 - 2014-07-31 07:25 - 00001436 _____ () C:\Users\Gnodti\Desktop\JRT.txt
2014-07-31 07:21 - 2014-07-31 07:21 - 01016261 _____ (Thisisu) C:\Users\Gnodti\Downloads\JRT.exe
2014-07-31 07:21 - 2014-07-31 07:21 - 00000000 ____D () C:\Windows\ERUNT
2014-07-31 07:14 - 2014-07-31 07:14 - 01361309 _____ () C:\Users\Gnodti\Downloads\adwcleaner_3.302.exe
2014-07-31 07:12 - 2014-07-31 07:12 - 00019763 _____ () C:\Users\Gnodti\Desktop\mbam.txt
2014-07-31 06:58 - 2014-07-31 06:59 - 00000000 ____D () C:\d3temp
2014-07-31 06:45 - 2014-07-31 07:09 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-31 06:45 - 2014-07-31 06:45 - 00001022 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-31 06:45 - 2014-07-31 06:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-31 06:45 - 2014-07-31 06:45 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-07-31 06:45 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-07-31 06:45 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-07-31 06:45 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-07-31 06:44 - 2014-07-31 06:44 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Gnodti\Downloads\mbam-setup-2.0.2.1012.exe
2014-07-30 12:55 - 2014-07-30 12:55 - 00026326 _____ () C:\ComboFix.txt
2014-07-30 12:38 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-07-30 12:38 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-07-30 12:38 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-07-30 12:38 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-07-30 12:38 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-07-30 12:38 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-07-30 12:38 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-07-30 12:38 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-07-30 08:03 - 2014-07-30 08:03 - 00000000 ____D () C:\Users\Gnodti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WOT Statistics
2014-07-28 09:00 - 2014-07-28 09:01 - 00000052 _____ () C:\Windows\system32\DOErrors.log
2014-07-25 11:44 - 2014-07-25 11:44 - 00002081 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-07-25 11:44 - 2014-07-25 11:44 - 00000000 ____D () C:\Users\Gnodti\AppData\Roaming\AVAST Software
2014-07-25 11:44 - 2014-07-25 11:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
2014-07-25 11:44 - 2014-07-25 11:43 - 00779536 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-07-25 11:44 - 2014-07-25 11:43 - 00192352 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-07-25 11:44 - 2014-07-25 11:43 - 00071944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2014-07-25 11:43 - 2014-07-25 11:44 - 00414520 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2014-07-25 11:43 - 2014-07-25 11:43 - 00276432 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-07-25 11:43 - 2014-07-25 11:43 - 00081768 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-07-25 11:43 - 2014-07-25 11:43 - 00067824 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-07-25 11:43 - 2014-07-25 11:43 - 00049944 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-07-25 11:43 - 2014-07-25 11:43 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-07-25 11:43 - 2014-07-25 11:43 - 00024184 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-07-25 11:43 - 2014-07-25 11:43 - 00000000 ____D () C:\Program Files\AVAST Software
2014-07-25 11:29 - 2014-07-25 11:30 - 91906368 _____ (AVAST Software) C:\Users\Gnodti\Downloads\avast_free_antivirus_setup_9_0_2021.exe
2014-07-25 11:16 - 2014-07-31 07:17 - 00028044 _____ () C:\Windows\PFRO.log
2014-07-25 10:22 - 2014-04-16 22:12 - 03942104 _____ (COMODO) C:\ProgramData\cis2E8F.exe
2014-07-25 08:54 - 2014-07-30 12:55 - 00000000 ____D () C:\Qoobox
2014-07-25 08:53 - 2014-07-30 12:54 - 00000000 ____D () C:\Windows\erdnt
2014-07-25 08:51 - 2014-07-30 12:33 - 05563986 ____R (Swearware) C:\Users\Gnodti\Downloads\ComboFix.exe
2014-07-25 08:30 - 2014-07-25 08:30 - 00001184 _____ () C:\Users\Gnodti\Desktop\Revo Uninstaller.lnk
2014-07-25 08:30 - 2014-07-25 08:30 - 00000000 ____D () C:\Program Files\VS Revo Group
2014-07-25 08:29 - 2014-07-25 08:29 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Gnodti\Downloads\revosetup95.exe
2014-07-23 11:58 - 2014-07-31 07:17 - 00004098 _____ () C:\Windows\setupact.log
2014-07-23 11:58 - 2014-07-25 10:33 - 00000000 ____D () C:\Windows\Minidump
2014-07-23 11:58 - 2014-07-23 12:00 - 00488112 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-23 11:58 - 2014-07-23 11:58 - 00000000 _____ () C:\Windows\setuperr.log
2014-07-23 09:53 - 2014-07-23 09:53 - 00030235 _____ () C:\Users\Gnodti\Downloads\Gmer.txt
2014-07-23 09:28 - 2014-07-31 07:43 - 00013691 _____ () C:\Users\Gnodti\Downloads\FRST.txt
2014-07-23 09:19 - 2014-07-23 09:19 - 00000474 _____ () C:\Users\Gnodti\Downloads\defogger_disable.log
2014-07-23 08:47 - 2014-07-23 08:47 - 00000000 _____ () C:\Users\Gnodti\defogger_reenable
2014-07-23 07:23 - 2014-07-23 07:23 - 00122515 _____ () C:\Users\Gnodti\Downloads\Addition.txt
2014-07-23 07:22 - 2014-07-31 07:43 - 00000000 ____D () C:\FRST
2014-07-22 11:47 - 2014-07-22 11:47 - 00141704 _____ () C:\Users\Gnodti\AppData\Local\GDIPFONTCACHEV1.DAT
2014-07-22 07:20 - 2014-07-25 11:15 - 00050193 _____ () C:\Windows\system32\Drivers\sfi.dat
2014-07-22 07:18 - 2014-07-22 07:18 - 00000000 ____D () C:\ProgramData\Comodo Downloader
2014-07-22 06:47 - 2014-07-22 06:48 - 230403216 _____ (COMODO) C:\Users\Gnodti\Downloads\cispremium_installer_6100_08.exe
2014-07-17 14:28 - 2014-07-25 11:43 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-07-17 13:40 - 2014-07-17 13:40 - 00000000 ____D () C:\Users\Gnodti\AppData\Roaming\GlarySoft
2014-07-17 07:42 - 2014-07-17 08:04 - 00000000 ____D () C:\ProgramData\2d7fd1c98058af9e
2014-07-17 07:41 - 2014-07-22 07:20 - 00000000 ____D () C:\Users\Gast
2014-07-17 07:41 - 2014-07-22 07:20 - 00000000 ____D () C:\Users\Administrator
2014-07-17 07:41 - 2014-07-17 07:41 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google
2014-07-17 07:41 - 2014-07-17 07:41 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo
2014-07-17 07:41 - 2014-07-17 07:41 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-07-17 07:41 - 2014-07-17 07:41 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo
2014-07-16 14:55 - 2014-07-16 14:55 - 56260608 _____ () C:\Users\Gnodti\Downloads\calibre-1.44.0.msi
2014-07-16 14:31 - 2014-07-16 14:53 - 00000000 ____D () C:\Users\Gnodti\Downloads\Ebooks
2014-07-16 13:17 - 2014-07-17 15:01 - 00001095 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-07-16 13:17 - 2014-07-17 15:01 - 00001095 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-07-16 13:17 - 2014-07-16 13:17 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-07-16 13:13 - 2014-07-16 13:13 - 00000288 _____ () C:\Users\Gnodti\Documents\cc_20140716_131308.reg
2014-07-16 13:13 - 2014-07-16 13:13 - 00000180 _____ () C:\Users\Gnodti\Documents\cc_20140716_131327.reg
2014-07-16 13:12 - 2014-07-16 13:12 - 00027212 _____ () C:\Users\Gnodti\Documents\cc_20140716_131251.reg
2014-07-16 12:14 - 2014-07-17 08:01 - 00000000 ____D () C:\Users\Gnodti\AppData\Roaming\Probit Software
2014-07-16 12:14 - 2014-07-17 07:50 - 00000000 ____D () C:\ProgramData\TEMP
2014-07-16 12:12 - 2014-07-16 12:13 - 00017966 _____ () C:\Windows\system32\bddel.dat
2014-07-16 11:51 - 2014-07-17 08:01 - 00000000 ____D () C:\Program Files\Probit Software
2014-07-16 11:50 - 2014-07-16 11:50 - 00000000 ____D () C:\Users\Gnodti\AppData\Roaming\LavasoftStatistics
2014-07-16 11:48 - 2014-07-17 13:25 - 00000000 ____D () C:\ProgramData\Ad-Aware Browsing Protection
2014-07-16 11:48 - 2014-07-16 11:48 - 00000000 ____D () C:\Users\Gnodti\AppData\Local\adawarebp
2014-07-16 11:46 - 2014-07-18 12:25 - 00000000 ____D () C:\Users\Gnodti\AppData\Roaming\Lavasoft
2014-07-16 11:44 - 2014-07-16 11:44 - 00000000 ____D () C:\ProgramData\Lavasoft
2014-07-16 11:39 - 2014-07-16 11:39 - 00013464 _____ () C:\Windows\system32\Drivers\SWDUMon.sys
2014-07-16 11:39 - 2014-07-16 11:39 - 00000000 ____D () C:\Users\Gnodti\AppData\Local\SlimWare Utilities Inc
2014-07-16 11:38 - 2014-07-16 12:19 - 00000000 ____D () C:\Program Files\DriverUpdate
2014-07-16 11:36 - 2014-07-16 11:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-07-16 11:36 - 2014-07-16 11:36 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-07-16 11:36 - 2014-07-11 03:02 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2014-07-16 11:36 - 2014-07-11 02:56 - 00272808 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-07-16 11:36 - 2014-07-11 02:56 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-07-16 11:36 - 2014-07-11 02:55 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-07-16 11:35 - 2014-07-16 11:35 - 00000000 ____D () C:\Users\Public\Documents\Downloaded Installers
2014-07-16 11:22 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll
2014-07-16 11:21 - 2014-07-31 07:16 - 00000000 ____D () C:\AdwCleaner
2014-07-15 14:28 - 2014-07-15 14:28 - 00001755 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-07-15 14:28 - 2014-07-15 14:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-07-15 14:24 - 2014-07-15 14:24 - 00000000 ____D () C:\Program Files\iPod
2014-07-15 14:23 - 2014-07-15 14:28 - 00000000 ____D () C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
2014-07-15 14:23 - 2014-07-15 14:28 - 00000000 ____D () C:\Program Files\iTunes
2014-07-15 13:36 - 2014-07-15 13:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
2014-07-11 11:17 - 2014-07-16 12:12 - 01042433 _____ () C:\Users\Gnodti\AppData\Local\ghqrrsae.gss
2014-07-11 11:17 - 2014-07-16 11:58 - 00018432 _____ () C:\Users\Gnodti\AppData\Local\ghqrrsae.gdb
2014-07-11 10:04 - 2014-07-11 10:04 - 01837296 _____ (Microsoft Corporation) C:\Windows\system32\WUDFUpdate_01009.dll
2014-07-11 09:57 - 2014-07-11 09:57 - 37850112 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoRes.dat
2014-07-11 09:57 - 2014-07-11 09:57 - 02395680 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO.dll
2014-07-11 09:57 - 2014-07-11 09:57 - 02328792 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkAPO.dll
2014-07-11 09:57 - 2014-07-11 09:57 - 00782040 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApoApi.dll
2014-07-11 09:57 - 2014-07-11 09:57 - 00673037 _____ () C:\Windows\system32\Drivers\RTAIODAT.DAT
2014-07-11 09:57 - 2014-07-11 09:57 - 00214368 _____ (Synopsys, Inc.) C:\Windows\system32\SFNHK.dll
2014-07-11 09:57 - 2014-07-11 09:57 - 00182472 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTACap.dll
2014-07-11 09:57 - 2014-07-11 09:57 - 00123608 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoInstII.dll
2014-07-11 09:57 - 2014-07-11 09:57 - 00095840 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTARen.dll
2014-07-11 09:57 - 2014-07-11 09:57 - 00092584 _____ (Real Sound Lab SIA) C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2014-07-11 09:57 - 2014-07-11 09:57 - 00074080 _____ (Synopsys, Inc.) C:\Windows\system32\SFCOM.dll
2014-07-11 09:57 - 2014-07-11 09:57 - 00068960 _____ (Synopsys, Inc.) C:\Windows\system32\SFAPO.dll
2014-07-11 09:57 - 2014-07-11 09:57 - 00013416 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR.dll
2014-07-11 09:31 - 2014-07-11 09:31 - 00000000 ____D () C:\Users\Gnodti\AppData\Local\Thinstall
2014-07-09 22:37 - 2014-06-20 21:39 - 00240824 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-07-09 22:37 - 2014-06-19 01:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-09 22:37 - 2014-06-19 01:36 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-07-09 22:37 - 2014-06-19 01:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-09 22:37 - 2014-06-19 01:28 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-07-09 22:37 - 2014-06-19 01:23 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-09 22:37 - 2014-06-19 01:23 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-07-09 22:37 - 2014-06-19 01:16 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-09 22:37 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-09 22:37 - 2014-06-19 01:06 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-09 22:37 - 2014-06-19 01:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-07-09 22:37 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-09 22:37 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-09 22:37 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-09 22:37 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-07-09 22:36 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-09 22:36 - 2014-06-19 01:56 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-07-09 22:36 - 2014-06-19 01:38 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-09 22:36 - 2014-06-19 01:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-07-09 22:36 - 2014-06-19 01:35 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-07-09 22:36 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-09 22:36 - 2014-06-19 01:25 - 00442368 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-09 22:36 - 2014-06-19 01:22 - 00592896 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-07-09 22:36 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-09 22:36 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-09 22:36 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-09 22:36 - 2014-06-19 00:52 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-07-09 22:36 - 2014-06-19 00:46 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-07-09 22:36 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-09 22:36 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-09 22:36 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-07-09 22:36 - 2014-06-18 02:52 - 02350080 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-07-09 22:36 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-07-09 22:36 - 2014-05-30 09:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-07-09 22:36 - 2014-05-30 09:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-07-09 22:36 - 2014-05-30 09:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-07-09 22:36 - 2014-05-30 09:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-07-09 22:36 - 2014-05-30 09:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-07-09 22:36 - 2014-05-30 09:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-07-09 22:36 - 2014-05-30 09:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-07-09 22:36 - 2014-05-30 08:36 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-07-09 22:35 - 2014-06-05 16:26 - 01059840 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-07-09 10:33 - 2014-07-09 10:33 - 05659136 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerInstaller.exe
2014-07-03 11:51 - 2014-07-03 12:18 - 00000187 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
2014-07-03 11:51 - 2014-07-03 12:18 - 00000000 ____D () C:\Users\Gnodti\AppData\Roaming\Infigo
2014-07-03 11:51 - 2014-07-03 11:51 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\vcrfod.bat
2014-07-03 11:49 - 2014-07-03 11:49 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\mucip.bat
2014-07-03 11:47 - 2014-07-03 11:47 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\nfmflef.bat
2014-07-03 11:43 - 2014-07-03 11:43 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ysmgr.bat
2014-07-03 11:41 - 2014-07-03 11:41 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\fdcbrp.bat
2014-07-03 11:39 - 2014-07-03 11:39 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\fmmts.bat
2014-07-03 11:37 - 2014-07-03 11:37 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\dumdtk.bat
2014-07-03 11:35 - 2014-07-03 11:35 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\hjsuvxaa.bat
2014-07-03 11:33 - 2014-07-03 11:33 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\sqvsxuc.bat
2014-07-03 11:31 - 2014-07-03 11:31 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\amekepk.bat
2014-07-03 11:29 - 2014-07-03 11:29 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\sxcig.bat
2014-07-03 11:26 - 2014-07-03 11:26 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\jdavq.bat
2014-07-03 11:24 - 2014-07-03 11:24 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\rozwthb.bat
2014-07-03 11:22 - 2014-07-03 11:22 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\qbcojbw.bat
2014-07-03 11:20 - 2014-07-03 11:20 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\pyzkevg.bat
2014-07-03 11:18 - 2014-07-03 11:18 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\wazcl.bat
2014-07-03 11:16 - 2014-07-03 11:16 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\swcocg.bat
2014-07-03 11:14 - 2014-07-03 11:14 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\nvfmudk.bat
2014-07-03 11:12 - 2014-07-03 11:12 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ghpbj.bat
2014-07-03 11:10 - 2014-07-03 11:10 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\khebeb.bat
2014-07-03 11:08 - 2014-07-03 11:08 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\icdghcdf.bat
2014-07-03 11:06 - 2014-07-03 11:06 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\yeqbo.bat
2014-07-03 11:04 - 2014-07-03 11:04 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\hirttv.bat
2014-07-03 11:02 - 2014-07-03 11:02 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\auwjdas.bat
2014-07-03 11:00 - 2014-07-03 11:00 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\kodheh.bat
2014-07-03 10:58 - 2014-07-03 10:58 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\pxiiqz.bat
2014-07-03 10:56 - 2014-07-03 10:56 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\xcnxcfp.bat
2014-07-03 10:53 - 2014-07-03 10:53 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\anzma.bat
2014-07-03 10:51 - 2014-07-03 10:51 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\bxecocyf.bat
2014-07-03 10:49 - 2014-07-03 10:49 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\dqndr.bat
2014-07-03 10:47 - 2014-07-03 10:47 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\wwnnwf.bat
2014-07-03 10:45 - 2014-07-03 10:45 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\dmfmc.bat
2014-07-03 10:43 - 2014-07-03 10:43 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ukbhdlt.bat
2014-07-03 10:41 - 2014-07-03 10:41 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\waijcben.bat
2014-07-03 10:39 - 2014-07-03 10:39 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\qbmvbcug.bat
2014-07-03 10:37 - 2014-07-03 10:37 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\qtwycfi.bat
2014-07-03 10:35 - 2014-07-03 10:35 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\yeordhze.bat
2014-07-03 10:33 - 2014-07-03 10:33 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\hpirra.bat
2014-07-03 10:31 - 2014-07-03 10:31 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\vvmmbdd.bat
2014-07-03 10:29 - 2014-07-03 10:29 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\cakaqgv.bat
2014-07-03 10:27 - 2014-07-03 10:27 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\fdubtl.bat
2014-07-03 10:25 - 2014-07-03 10:25 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\wwnodgw.bat
2014-07-03 10:23 - 2014-07-03 10:23 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\pakte.bat
2014-07-03 10:21 - 2014-07-03 10:21 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\mmkrqh.bat
2014-07-03 10:18 - 2014-07-03 10:18 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\bnivp.bat
2014-07-03 10:16 - 2014-07-03 10:16 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\khezxt.bat
2014-07-03 10:14 - 2014-07-03 10:14 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\pkupj.bat
2014-07-03 10:12 - 2014-07-03 10:12 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ukbgckap.bat
2014-07-03 10:10 - 2014-07-03 10:10 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\jfimae.bat
2014-07-03 10:08 - 2014-07-03 10:08 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\xaclcei.bat
2014-07-03 10:06 - 2014-07-03 10:06 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\edjzydn.bat
2014-07-03 10:04 - 2014-07-03 10:04 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\hqkuu.bat
2014-07-03 10:02 - 2014-07-03 10:02 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\accey.bat
2014-07-03 10:00 - 2014-07-03 10:00 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\fewew.bat
2014-07-03 09:58 - 2014-07-03 09:58 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\lpuaea.bat
2014-07-03 09:56 - 2014-07-03 09:56 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\jdbdruqe.bat
2014-07-03 09:54 - 2014-07-03 09:54 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\wmemds.bat
2014-07-03 09:52 - 2014-07-03 09:52 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ofmudlm.bat
2014-07-03 09:50 - 2014-07-03 09:50 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\vwwxfip.bat
2014-07-03 09:48 - 2014-07-03 09:48 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\dtcapev.bat
2014-07-03 09:45 - 2014-07-03 09:45 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ajbngykd.bat
2014-07-03 09:43 - 2014-07-03 09:43 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\bnagan.bat
2014-07-03 09:41 - 2014-07-03 09:41 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ebsjaa.bat
2014-07-03 09:39 - 2014-07-03 09:39 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\zgcwchl.bat
2014-07-03 09:37 - 2014-07-03 09:37 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\jeabxsoy.bat
2014-07-03 09:35 - 2014-07-03 09:35 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ilvatwy.bat
2014-07-03 09:33 - 2014-07-03 09:33 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\capndbxn.bat
2014-07-03 09:31 - 2014-07-03 09:31 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\xalvfqa.bat
2014-07-03 09:29 - 2014-07-03 09:29 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\vgmul.bat
2014-07-03 09:27 - 2014-07-03 09:27 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\uckyyg.bat
2014-07-03 09:25 - 2014-07-03 09:25 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\buqlecui.bat
2014-07-03 09:23 - 2014-07-03 09:23 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\icreym.bat
2014-07-03 09:21 - 2014-07-03 09:21 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\mkihutr.bat
2014-07-03 09:19 - 2014-07-03 09:19 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\dravkzhe.bat
2014-07-03 09:17 - 2014-07-03 09:17 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\xoxqbra.bat
2014-07-03 09:14 - 2014-07-03 09:14 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\bcwrgbt.bat
2014-07-03 09:12 - 2014-07-03 09:12 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\tagmsffk.bat
2014-07-03 09:10 - 2014-07-03 09:10 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\feuskj.bat
2014-07-03 09:08 - 2014-07-03 09:08 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\pqsuc.bat
2014-07-03 09:06 - 2014-07-03 09:06 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\rfrcpehl.bat
2014-07-03 09:04 - 2014-07-03 09:04 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ngmfgf.bat
2014-07-03 09:02 - 2014-07-03 09:02 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\axeco.bat
2014-07-03 09:00 - 2014-07-03 09:00 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\gwhhpirq.bat
2014-07-03 08:58 - 2014-07-03 08:58 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\lbfvtjh.bat
2014-07-03 08:56 - 2014-07-03 08:56 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\zhsxdp.bat
2014-07-03 08:54 - 2014-07-03 08:54 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\cbrpf.bat
2014-07-03 08:52 - 2014-07-03 08:52 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\dyhdr.bat
2014-07-03 08:50 - 2014-07-03 08:50 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\dtesaqa.bat
2014-07-03 08:47 - 2014-07-03 08:47 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\xacmo.bat
2014-07-03 08:45 - 2014-07-03 08:45 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\zuytgsm.bat
2014-07-03 08:43 - 2014-07-03 08:43 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\lkpot.bat
2014-07-03 08:41 - 2014-07-03 08:41 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\rehswbma.bat
2014-07-03 08:39 - 2014-07-03 08:39 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ijlmnp.bat
2014-07-03 08:37 - 2014-07-03 08:37 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\gegexwph.bat
2014-07-03 08:35 - 2014-07-03 08:35 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\dfczvspl.bat
2014-07-03 08:33 - 2014-07-03 08:33 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\cecedw.bat
2014-07-03 08:31 - 2014-07-03 08:31 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\vffmnu.bat
2014-07-03 08:29 - 2014-07-03 08:29 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\hqissbn.bat
2014-07-03 08:27 - 2014-07-03 08:27 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ahtyerd.bat
2014-07-03 08:25 - 2014-07-03 08:25 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ucjxde.bat
2014-07-03 08:23 - 2014-07-03 08:23 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\izmfy.bat
2014-07-03 08:21 - 2014-07-03 08:21 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\oibleeg.bat
2014-07-03 08:19 - 2014-07-03 08:19 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\cocxlhth.bat
2014-07-03 08:16 - 2014-07-03 08:16 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\uthgnbz.bat
2014-07-03 08:14 - 2014-07-03 08:14 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\sejdi.bat
2014-07-03 08:12 - 2014-07-03 08:12 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\uielaw.bat
2014-07-03 08:10 - 2014-07-03 08:10 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\jeabqswj.bat
2014-07-03 08:08 - 2014-07-03 08:08 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\fmedk.bat
2014-07-03 08:06 - 2014-07-03 08:06 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\prbdtv.bat
2014-07-03 08:04 - 2014-07-03 08:04 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\kwuyvag.bat
2014-07-03 08:02 - 2014-07-03 08:02 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\kolqbrda.bat
2014-07-03 08:00 - 2014-07-03 08:00 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\gzlfoatm.bat
2014-07-03 07:58 - 2014-07-03 07:58 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\reyjfq.bat
2014-07-03 07:56 - 2014-07-03 07:56 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\hxrrkcb.bat
2014-07-03 07:54 - 2014-07-03 07:54 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\saddb.bat
2014-07-03 07:52 - 2014-07-03 07:52 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\auavpdp.bat
2014-07-03 07:50 - 2014-07-03 07:50 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\xqaugw.bat
2014-07-03 07:47 - 2014-07-03 07:47 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\rwaxb.bat
2014-07-03 07:45 - 2014-07-03 07:45 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\fepwhi.bat
2014-07-03 07:43 - 2014-07-03 07:43 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\tsefkhvt.bat
2014-07-03 07:41 - 2014-07-03 07:41 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\jnimi.bat
2014-07-03 07:39 - 2014-07-03 07:39 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\atgiuh.bat
2014-07-03 07:37 - 2014-07-03 07:37 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\bqfth.bat
2014-07-03 07:35 - 2014-07-03 07:35 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\fecba.bat
2014-07-03 07:33 - 2014-07-03 07:33 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ejffuj.bat
2014-07-03 07:31 - 2014-07-03 07:31 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\auhdp.bat
2014-07-03 07:29 - 2014-07-03 07:29 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\azdgxc.bat
2014-07-03 07:27 - 2014-07-03 07:27 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\wxiijad.bat
2014-07-03 07:25 - 2014-07-03 07:25 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\eqgdyoc.bat
2014-07-03 07:23 - 2014-07-03 07:23 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\izmffslf.bat
2014-07-03 07:21 - 2014-07-03 07:21 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\bifmiwl.bat
2014-07-03 07:19 - 2014-07-03 07:19 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\xqbtmd.bat
2014-07-03 07:17 - 2014-07-03 07:17 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\bxebnb.bat
2014-07-03 07:15 - 2014-07-03 07:15 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\fedccb.bat
2014-07-03 07:13 - 2014-07-03 07:13 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\bygeje.bat
2014-07-03 07:11 - 2014-07-03 07:11 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\eonxwhe.bat
2014-07-03 07:09 - 2014-07-03 07:09 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\nmmmsl.bat
2014-07-03 07:07 - 2014-07-03 07:07 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\fnmtllsr.bat
2014-07-03 07:04 - 2014-07-03 07:04 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\fecsrphg.bat
2014-07-03 07:02 - 2014-07-03 07:02 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\aifzgmaf.bat
2014-07-03 07:00 - 2014-07-03 07:00 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\oqrsu.bat
2014-07-03 06:58 - 2014-07-03 06:58 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\wngnenf.bat
2014-07-03 06:56 - 2014-07-03 06:56 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\eqbtfwoa.bat
2014-07-03 06:54 - 2014-07-03 06:54 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\nmtcsbag.bat
2014-07-03 06:52 - 2014-07-03 06:52 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\khdada.bat
2014-07-03 06:50 - 2014-07-03 06:50 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\sotquie.bat
2014-07-03 06:48 - 2014-07-03 06:48 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\edsrigxv.bat
2014-07-03 06:46 - 2014-07-03 06:46 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\gnvnfn.bat
2014-07-03 06:44 - 2014-07-03 06:44 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\tqwuhfki.bat
2014-07-03 06:42 - 2014-07-03 06:42 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\daczw.bat
2014-07-03 06:40 - 2014-07-03 06:40 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\spbaeanj.bat
2014-07-03 06:38 - 2014-07-03 06:38 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\habvxj.bat
2014-07-03 06:36 - 2014-07-03 06:36 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ydpafxc.bat
2014-07-03 06:34 - 2014-07-03 06:34 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\etrigwud.bat
2014-07-03 06:32 - 2014-07-03 11:45 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\jcylh.bat
2014-07-03 06:30 - 2014-07-03 06:30 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\tyfkqcc.bat
2014-07-03 06:28 - 2014-07-03 06:28 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\dulbrbyp.bat
2014-07-03 06:26 - 2014-07-03 06:26 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\cscqgn.bat
2014-07-03 06:24 - 2014-07-03 06:24 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ztgbua.bat
2014-07-03 06:21 - 2014-07-03 06:21 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\nooopg.bat
2014-07-03 06:19 - 2014-07-03 06:19 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\msapvcci.bat
2014-07-03 06:17 - 2014-07-03 06:17 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ulcbq.bat
2014-07-03 06:15 - 2014-07-03 06:15 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\jeavrnje.bat
2014-07-03 06:13 - 2014-07-03 06:13 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\pbcnia.bat
2014-07-03 06:11 - 2014-07-03 06:11 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\yjbfgi.bat
2014-07-03 06:09 - 2014-07-03 06:09 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\rososp.bat
2014-07-03 06:07 - 2014-07-03 06:07 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\chbpup.bat
2014-07-03 06:05 - 2014-07-03 06:05 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\iavwide.bat
2014-07-03 06:03 - 2014-07-03 06:03 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\hxjaslv.bat
2014-07-03 06:01 - 2014-07-03 06:01 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\vfnve.bat
2014-07-03 05:59 - 2014-07-03 05:59 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\tchmtagn.bat
2014-07-03 05:57 - 2014-07-03 05:57 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ujxfahw.bat
2014-07-03 05:55 - 2014-07-03 05:55 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\kbxnsh.bat
2014-07-03 05:53 - 2014-07-03 05:53 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ohicdlef.bat
2014-07-03 05:51 - 2014-07-03 05:51 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\zgbnsvbg.bat
2014-07-03 05:47 - 2014-07-03 05:47 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ykvasep.bat
2014-07-03 05:45 - 2014-07-03 05:45 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\mbgmafnt.bat
2014-07-03 05:43 - 2014-07-03 05:43 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\bnagtnag.bat
2014-07-03 05:40 - 2014-07-03 05:40 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\hbudpj.bat
2014-07-03 05:38 - 2014-07-03 05:38 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\nggef.bat
2014-07-03 05:36 - 2014-07-03 05:36 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\gggghhhh.bat
2014-07-03 05:34 - 2014-07-03 05:34 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\bcidql.bat
2014-07-03 05:32 - 2014-07-03 05:32 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\lrpvtaw.bat
2014-07-03 05:30 - 2014-07-03 05:30 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\vukjrafh.bat
2014-07-03 05:28 - 2014-07-03 05:28 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\qlnil.bat
2014-07-03 05:26 - 2014-07-03 05:26 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\rnyuq.bat
2014-07-03 05:24 - 2014-07-03 05:24 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\lqglrpub.bat
2014-07-03 05:22 - 2014-07-03 05:22 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\cdlbqa.bat
2014-07-03 05:20 - 2014-07-03 05:20 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\bcjxgfai.bat
2014-07-03 05:18 - 2014-07-03 05:18 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\mdjaaevb.bat
2014-07-03 05:16 - 2014-07-03 05:16 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\abunabno.bat
2014-07-03 05:14 - 2014-07-03 05:14 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\udcjipw.bat
2014-07-03 05:12 - 2014-07-03 05:12 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\zuidxdw.bat
2014-07-03 05:10 - 2014-07-03 05:10 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\vhowop.bat
2014-07-03 05:08 - 2014-07-03 05:08 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ajbfxitf.bat
2014-07-03 05:05 - 2014-07-03 05:05 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\cgbwa.bat
2014-07-03 05:03 - 2014-07-03 05:03 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\kxcgsxd.bat
2014-07-03 05:01 - 2014-07-03 05:01 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\rxcgsw.bat
2014-07-03 04:59 - 2014-07-03 04:59 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\kfvkod.bat
2014-07-03 04:57 - 2014-07-03 04:57 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\xccnq.bat
2014-07-03 04:55 - 2014-07-03 04:55 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\fzdgxbbn.bat
2014-07-03 04:53 - 2014-07-03 04:53 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\dafvtjo.bat
2014-07-03 04:51 - 2014-07-03 04:51 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\cgbxmq.bat
2014-07-03 04:49 - 2014-07-03 04:49 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\swcnlwc.bat
2014-07-03 04:47 - 2014-07-03 04:47 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\rosoagbg.bat
2014-07-03 04:45 - 2014-07-03 04:45 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\cyvkhv.bat
2014-07-03 04:43 - 2014-07-03 04:43 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\atgiu.bat
2014-07-03 04:41 - 2014-07-03 04:41 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\haztmvo.bat
2014-07-03 04:39 - 2014-07-03 04:39 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\goxirc.bat
2014-07-03 04:37 - 2014-07-03 04:37 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\sgjvb.bat
2014-07-03 04:35 - 2014-07-03 04:35 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\jcxan.bat
2014-07-03 04:33 - 2014-07-03 04:33 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\farkl.bat
2014-07-03 04:31 - 2014-07-03 04:31 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\cxapladr.bat
2014-07-03 04:29 - 2014-07-03 04:29 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\thkxd.bat
2014-07-03 04:27 - 2014-07-03 04:27 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\gfxfyr.bat
2014-07-03 04:24 - 2014-07-03 04:24 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\fstfh.bat
2014-07-03 04:22 - 2014-07-03 04:22 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\yrlwp.bat
2014-07-03 04:20 - 2014-07-03 04:20 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\iztuoh.bat
2014-07-03 04:18 - 2014-07-03 04:18 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\velajah.bat
2014-07-03 04:16 - 2014-07-03 04:16 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\hcvxklfa.bat
2014-07-03 04:14 - 2014-07-03 04:14 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\kgsos.bat
2014-07-03 04:12 - 2014-07-03 04:12 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\fdvcumed.bat
2014-07-03 04:10 - 2014-07-03 04:10 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\fdvng.bat
2014-07-03 04:08 - 2014-07-03 04:08 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ehikbtfg.bat
2014-07-03 04:06 - 2014-07-03 04:06 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\jesvkgsw.bat
2014-07-03 04:04 - 2014-07-03 04:04 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\haaunhb.bat
2014-07-03 04:02 - 2014-07-03 04:02 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\linsxvs.bat
2014-07-03 04:00 - 2014-07-03 04:00 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\quxblps.bat
2014-07-03 03:58 - 2014-07-03 03:58 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\kimcglbg.bat
2014-07-03 03:56 - 2014-07-03 03:56 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\bldqkd.bat
2014-07-03 03:54 - 2014-07-03 03:54 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\aisegyqt.bat
2014-07-03 03:52 - 2014-07-03 03:52 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\pbcnizd.bat
2014-07-03 03:50 - 2014-07-03 03:50 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\drhetbe.bat
2014-07-03 03:48 - 2014-07-03 03:48 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\aiamew.bat
2014-07-03 03:46 - 2014-07-03 03:46 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\xbbehx.bat
2014-07-03 03:44 - 2014-07-03 03:44 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\prsuwx.bat
2014-07-03 03:41 - 2014-07-03 03:41 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\drhwsb.bat
2014-07-03 03:39 - 2014-07-03 03:39 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\frdxj.bat
2014-07-03 03:37 - 2014-07-03 03:37 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\evnxog.bat
2014-07-03 03:35 - 2014-07-03 03:35 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ejqeet.bat
2014-07-03 03:33 - 2014-07-03 03:33 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\cpesfubg.bat
2014-07-03 03:31 - 2014-07-03 03:31 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\uutta.bat
2014-07-03 03:29 - 2014-07-03 03:29 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\fmedkc.bat
2014-07-03 03:27 - 2014-07-03 03:27 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\yqbvh.bat
2014-07-03 03:25 - 2014-07-03 03:25 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\vetbscb.bat
2014-07-03 03:23 - 2014-07-03 03:23 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\xbtdha.bat
2014-07-03 03:21 - 2014-07-03 03:21 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\oxqyh.bat
2014-07-03 03:19 - 2014-07-03 03:19 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ggyyrrc.bat
2014-07-03 03:17 - 2014-07-03 03:17 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\khlqtjn.bat
2014-07-03 03:15 - 2014-07-03 03:15 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ykoad.bat
2014-07-03 03:13 - 2014-07-03 03:13 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\qcmwi.bat
2014-07-03 03:11 - 2014-07-03 03:11 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\vggwh.bat
2014-07-03 03:09 - 2014-07-03 03:09 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\jcxanj.bat
2014-07-03 03:07 - 2014-07-03 03:07 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\erhea.bat
2014-07-03 03:05 - 2014-07-03 03:05 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\frtfhr.bat
2014-07-03 03:03 - 2014-07-03 03:03 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\refjuf.bat
2014-07-03 03:01 - 2014-07-03 03:01 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\cglxcjo.bat
2014-07-03 02:58 - 2014-07-03 02:58 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\cfydq.bat
2014-07-03 02:56 - 2014-07-03 02:56 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\acxzvpkm.bat
2014-07-03 02:54 - 2014-07-03 02:54 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ykchsk.bat
2014-07-03 02:52 - 2014-07-03 02:52 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\acvyd.bat
2014-07-03 02:50 - 2014-07-03 02:50 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\bocpkx.bat
2014-07-03 02:48 - 2014-07-03 02:48 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\prtvxhj.bat
2014-07-03 02:46 - 2014-07-03 02:46 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\woxpaqz.bat
2014-07-03 02:44 - 2014-07-03 02:44 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\kgdadzw.bat
2014-07-03 02:42 - 2014-07-03 02:42 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\gykenfr.bat
2014-07-03 02:40 - 2014-07-03 02:40 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\rdepzeoy.bat
2014-07-03 02:38 - 2014-07-03 02:38 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\gpyjtdud.bat
2014-07-03 02:36 - 2014-07-03 02:36 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\cfmiwti.bat
2014-07-03 02:34 - 2014-07-03 02:34 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\clcjyhp.bat
2014-07-03 02:32 - 2014-07-03 02:32 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\docrws.bat
2014-07-03 02:30 - 2014-07-03 02:30 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\dafdid.bat
2014-07-03 02:28 - 2014-07-03 02:28 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\xjaefhak.bat
2014-07-03 02:26 - 2014-07-03 02:26 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\rwbmrvzn.bat
2014-07-03 02:24 - 2014-07-03 02:24 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\nopixqq.bat
2014-07-03 02:22 - 2014-07-03 02:22 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\kwbfrvb.bat
2014-07-03 02:20 - 2014-07-03 02:20 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\zugbvh.bat
2014-07-03 02:17 - 2014-07-03 02:17 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\thcbocid.bat
2014-07-03 02:15 - 2014-07-03 02:15 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\amzfrfi.bat
2014-07-03 02:13 - 2014-07-03 02:13 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\yjtfp.bat
2014-07-03 02:11 - 2014-07-03 02:11 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ecrpgec.bat
2014-07-03 02:09 - 2014-07-03 02:09 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\oiqleng.bat
2014-07-03 02:07 - 2014-07-03 02:07 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\iccxr.bat
2014-07-03 02:05 - 2014-07-03 02:05 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\acfqte.bat
2014-07-03 02:03 - 2014-07-03 02:03 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\eewwhi.bat
2014-07-03 02:01 - 2014-07-03 02:01 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\bcyah.bat
2014-07-03 01:59 - 2014-07-03 01:59 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\hpqbabk.bat
2014-07-03 01:57 - 2014-07-03 01:57 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\fycevfxj.bat
2014-07-03 01:55 - 2014-07-03 01:55 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\vffnn.bat
2014-07-03 01:53 - 2014-07-03 01:53 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\edets.bat
2014-07-03 01:51 - 2014-07-03 01:51 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ofgmnu.bat
2014-07-03 01:49 - 2014-07-03 01:49 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\esqheusa.bat
2014-07-03 01:47 - 2014-07-03 01:47 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\usbxg.bat
2014-07-03 01:44 - 2014-07-03 01:44 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\alejvoa.bat
2014-07-03 01:42 - 2014-07-03 01:42 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\numtb.bat
2014-07-03 01:40 - 2014-07-03 01:40 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\eewgghxi.bat
2014-07-03 01:38 - 2014-07-03 01:38 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\seydxkvj.bat
2014-07-03 01:36 - 2014-07-03 01:36 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\oqrcbvwg.bat
2014-07-03 01:34 - 2014-07-03 01:34 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\qktwhb.bat
2014-07-03 01:32 - 2014-07-03 01:32 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\dnmvuet.bat
2014-07-03 01:30 - 2014-07-03 01:30 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\uutbb.bat
2014-07-03 01:28 - 2014-07-03 01:28 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\kptxeidi.bat
2014-07-03 01:26 - 2014-07-03 01:26 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\hatnabtg.bat
2014-07-03 01:24 - 2014-07-03 01:24 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\clcjygod.bat
2014-07-03 01:22 - 2014-07-03 01:22 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\idehjdf.bat
2014-07-03 01:20 - 2014-07-03 01:20 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\flcjboeu.bat
2014-07-03 01:18 - 2014-07-03 01:18 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\qcvgbkn.bat
2014-07-03 01:16 - 2014-07-03 01:16 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\qcdnqz.bat
2014-07-03 01:14 - 2014-07-03 01:14 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\bwkiuidr.bat
2014-07-03 01:12 - 2014-07-03 01:12 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\mlrqpvul.bat
2014-07-03 01:10 - 2014-07-03 01:10 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\yefjnqu.bat
2014-07-03 01:07 - 2014-07-03 01:07 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\shkwc.bat
2014-07-03 01:05 - 2014-07-03 01:05 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\cqmbpm.bat
2014-07-03 01:03 - 2014-07-03 01:03 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\xalvxb.bat
2014-07-03 01:01 - 2014-07-03 01:01 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\icxzmi.bat
2014-07-03 00:59 - 2014-07-03 00:59 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\yjuejug.bat
2014-07-03 00:57 - 2014-07-03 00:57 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\cplaokw.bat
2014-07-03 00:55 - 2014-07-03 00:55 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\qscfqz.bat
2014-07-03 00:53 - 2014-07-03 00:53 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\xirbfp.bat
2014-07-03 00:51 - 2014-07-03 00:51 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\zuaua.bat
2014-07-03 00:49 - 2014-07-03 00:49 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\havpjddq.bat
2014-07-03 00:47 - 2014-07-03 00:47 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\qaduxbsv.bat
2014-07-03 00:45 - 2014-07-03 00:45 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\hcuojcvq.bat
2014-07-03 00:43 - 2014-07-03 00:43 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\haauc.bat
2014-07-03 00:41 - 2014-07-03 00:41 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\dohpfpha.bat
2014-07-03 00:39 - 2014-07-03 00:39 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\kolpm.bat
2014-07-03 00:37 - 2014-07-03 00:37 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\utbyn.bat
2014-07-03 00:35 - 2014-07-03 00:35 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\udbiho.bat
2014-07-03 00:32 - 2014-07-03 00:32 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\uudba.bat
2014-07-03 00:30 - 2014-07-03 00:30 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\sgjoagdp.bat
2014-07-03 00:28 - 2014-07-03 00:28 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\aiwer.bat
2014-07-03 00:26 - 2014-07-03 00:26 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\wfgwx.bat
2014-07-03 00:24 - 2014-07-03 00:24 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\mtagn.bat
2014-07-03 00:22 - 2014-07-03 00:22 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\kbxmcyct.bat
2014-07-03 00:20 - 2014-07-03 00:20 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\jfhli.bat
2014-07-03 00:18 - 2014-07-03 00:18 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\spureb.bat
2014-07-03 00:16 - 2014-07-03 00:16 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\lbfkxckp.bat
2014-07-03 00:14 - 2014-07-03 00:14 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\tagtbfm.bat
2014-07-03 00:12 - 2014-07-03 00:12 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\hcdfg.bat
2014-07-03 00:10 - 2014-07-03 00:10 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\nnooff.bat
2014-07-03 00:08 - 2014-07-03 00:08 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ukbhdl.bat
2014-07-03 00:06 - 2014-07-03 00:06 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\jtprnatw.bat
2014-07-03 00:04 - 2014-07-03 00:04 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\yswqcnhc.bat
2014-07-03 00:02 - 2014-07-03 00:02 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\cywliwl.bat
2014-07-03 00:00 - 2014-07-03 00:00 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\udjqa.bat
2014-07-02 23:58 - 2014-07-02 23:58 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\zlqdg.bat
2014-07-02 23:56 - 2014-07-02 23:56 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ubbpv.bat
2014-07-02 23:53 - 2014-07-02 23:53 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\khtqurf.bat
2014-07-02 23:51 - 2014-07-02 23:51 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\evhxfxia.bat
2014-07-02 23:49 - 2014-07-02 23:49 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\fumem.bat
2014-07-02 23:47 - 2014-07-02 23:47 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ovoveg.bat
2014-07-02 23:45 - 2014-07-02 23:45 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\fnvnfmvm.bat
2014-07-02 23:43 - 2014-07-02 23:43 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\pracmvx.bat
2014-07-02 23:41 - 2014-07-02 23:41 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ghhiii.bat
2014-07-02 23:39 - 2014-07-02 23:39 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\dbpmdapm.bat
2014-07-02 23:37 - 2014-07-02 23:37 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\cmatobvb.bat
2014-07-02 23:35 - 2014-07-02 23:35 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\drhwsbhm.bat
2014-07-02 23:33 - 2014-07-02 23:33 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\lredjwe.bat
2014-07-02 23:31 - 2014-07-02 23:31 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\cwsocg.bat
2014-07-02 23:29 - 2014-07-02 23:29 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\eblqa.bat
2014-07-02 23:27 - 2014-07-02 23:27 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\zgrvh.bat
2014-07-02 23:25 - 2014-07-02 23:25 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\tydkp.bat
2014-07-02 23:23 - 2014-07-02 23:23 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ffmdee.bat
2014-07-02 23:21 - 2014-07-02 23:21 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\dbrqgx.bat
2014-07-02 23:19 - 2014-07-02 23:19 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\rexcwi.bat
2014-07-02 23:17 - 2014-07-02 23:17 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\fdcbf.bat
2014-07-02 23:15 - 2014-07-02 23:15 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\vlbqgc.bat
2014-07-02 23:13 - 2014-07-02 23:13 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\rmxce.bat
2014-07-02 23:10 - 2014-07-02 23:10 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\xbdnpa.bat
2014-07-02 23:08 - 2014-07-02 23:08 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\lkipne.bat
2014-07-02 23:06 - 2014-07-02 23:06 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\drhwtb.bat
2014-07-02 23:04 - 2014-07-02 23:04 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\bbiwlsyg.bat
2014-07-02 23:02 - 2014-07-02 23:02 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\msage.bat
2014-07-02 23:00 - 2014-07-02 23:00 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\exabcale.bat
2014-07-02 22:58 - 2014-07-02 22:58 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\shuzf.bat
2014-07-02 22:56 - 2014-07-02 22:56 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\gfqjc.bat
2014-07-02 22:54 - 2014-07-02 22:54 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\mkjhgts.bat
2014-07-02 22:52 - 2014-07-02 22:52 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\rvzeb.bat
2014-07-02 22:50 - 2014-07-02 22:50 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ekioms.bat
2014-07-02 22:48 - 2014-07-02 22:48 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\wgoehq.bat
2014-07-02 22:46 - 2014-07-02 22:46 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\fwhaiack.bat
2014-07-02 22:44 - 2014-07-02 22:44 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ztyseq.bat
2014-07-02 22:42 - 2014-07-02 22:42 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\jtwaknxa.bat
2014-07-02 22:40 - 2014-07-02 22:40 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\sxdoty.bat
2014-07-02 22:38 - 2014-07-02 22:38 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\aiuzgtaf.bat
2014-07-02 22:36 - 2014-07-02 22:36 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\kawkawtj.bat
2014-07-02 22:34 - 2014-07-02 22:34 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\aizev.bat
2014-07-02 22:31 - 2014-07-02 22:31 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ukafnd.bat
2014-07-02 22:29 - 2014-07-02 22:29 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\eewxpp.bat
2014-07-02 22:27 - 2014-07-02 22:27 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\rozvrfz.bat
2014-07-02 22:25 - 2014-07-02 22:25 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\sxchtxcb.bat
2014-07-02 22:23 - 2014-07-02 22:23 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\sqmkwuyw.bat
2014-07-02 22:21 - 2014-07-02 22:21 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\dzigush.bat
2014-07-02 22:19 - 2014-07-02 22:19 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\vdsap.bat
2014-07-02 22:17 - 2014-07-02 22:17 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\kfuje.bat
2014-07-02 22:15 - 2014-07-02 22:15 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\fceal.bat
2014-07-02 22:13 - 2014-07-02 22:13 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ewoarj.bat
2014-07-02 22:11 - 2014-07-02 22:11 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\sgagli.bat
2014-07-02 22:09 - 2014-07-02 22:09 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\vvfddllt.bat
2014-07-02 22:07 - 2014-07-02 22:07 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ubiwddbi.bat
2014-07-02 22:05 - 2014-07-02 22:05 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ljwtrw.bat
2014-07-02 22:03 - 2014-07-02 22:03 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\tyfkpvaa.bat
2014-07-02 22:01 - 2014-07-02 22:01 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\trpntrpn.bat
2014-07-02 21:59 - 2014-07-02 21:59 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ngmfme.bat
2014-07-02 21:57 - 2014-07-02 21:57 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\rexch.bat
2014-07-02 21:55 - 2014-07-02 21:55 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\oghoowg.bat
2014-07-02 21:53 - 2014-07-02 21:53 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\qcnxkvfr.bat
2014-07-02 21:51 - 2014-07-02 21:51 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\hqrbbcf.bat
2014-07-02 21:48 - 2014-07-02 21:48 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\lkiffbsq.bat
2014-07-02 21:46 - 2014-07-02 21:46 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ykvhzlgq.bat
2014-07-02 21:44 - 2014-07-02 21:44 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\nnudcjjp.bat
2014-07-02 21:42 - 2014-07-02 21:42 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\wfndeo.bat
2014-07-02 21:40 - 2014-07-02 21:40 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\trxvcy.bat
2014-07-02 21:38 - 2014-07-02 21:38 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\kwbxco.bat
2014-07-02 21:36 - 2014-07-02 21:36 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\sfzealx.bat
2014-07-02 21:34 - 2014-07-02 21:34 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\oibkdc.bat
2014-07-02 21:32 - 2014-07-02 21:32 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\xqbtnex.bat
2014-07-02 21:30 - 2014-07-02 21:30 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\addfsm.bat
2014-07-02 21:28 - 2014-07-02 21:28 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\fxpizrkc.bat
2014-07-02 21:26 - 2014-07-02 21:26 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\trawk.bat
2014-07-02 21:22 - 2014-07-02 21:22 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\dqeuiwm.bat
2014-07-02 21:20 - 2014-07-02 21:20 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\kfcrod.bat
2014-07-02 21:18 - 2014-07-02 21:18 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\khdzwtie.bat
2014-07-02 21:16 - 2014-07-02 21:16 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\qsvybeh.bat
2014-07-02 21:14 - 2014-07-02 21:14 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\bqflav.bat
2014-07-02 21:12 - 2014-07-02 21:12 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\opqrstuv.bat
2014-07-02 21:09 - 2014-07-02 21:09 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\kawlb.bat
2014-07-02 21:07 - 2014-07-02 21:07 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\avqdf.bat
2014-07-02 21:05 - 2014-07-02 21:05 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\erhezp.bat
2014-07-02 21:03 - 2014-07-02 21:03 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\gvnmf.bat
2014-07-02 21:01 - 2014-07-02 21:01 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ycofkvar.bat
2014-07-02 20:59 - 2014-07-02 20:59 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\sxcaedin.bat
2014-07-02 20:57 - 2014-07-02 20:57 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ecaenmki.bat
2014-07-02 20:55 - 2014-07-02 20:55 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\rwimfdi.bat
2014-07-02 20:53 - 2014-07-02 20:53 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\msagmaa.bat
2014-07-02 20:51 - 2014-07-02 20:51 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\eekjh.bat
2014-07-02 20:49 - 2014-07-02 20:49 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\hbuvxkmn.bat
2014-07-02 20:47 - 2014-07-02 20:47 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\fnmelk.bat
2014-07-02 20:45 - 2014-07-02 20:45 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ljgejfeb.bat
2014-07-02 20:43 - 2014-07-02 20:43 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\cpesnb.bat
2014-07-02 20:41 - 2014-07-02 20:41 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ubipwc.bat
2014-07-02 20:39 - 2014-07-02 20:39 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\cocpcxla.bat
2014-07-02 20:37 - 2014-07-02 20:37 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\hqrddeno.bat
2014-07-02 20:35 - 2014-07-02 20:35 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\rwzwagcg.bat
2014-07-02 20:33 - 2014-07-02 20:33 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\caqoecb.bat
2014-07-02 20:31 - 2014-07-02 20:31 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\syekp.bat
2014-07-02 20:28 - 2014-07-02 20:28 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\bcaetbp.bat
2014-07-02 20:26 - 2014-07-02 20:26 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\hwpiyqq.bat
2014-07-02 20:24 - 2014-07-02 20:24 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\izmgztff.bat
2014-07-02 20:22 - 2014-07-02 20:22 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\byola.bat
2014-07-02 20:20 - 2014-07-02 20:20 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\brgujf.bat
2014-07-02 20:18 - 2014-07-02 20:18 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\rercpmfk.bat
2014-07-02 20:16 - 2014-07-02 20:16 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\frdwpb.bat
2014-07-02 20:14 - 2014-07-02 20:14 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\oiccwx.bat
2014-07-02 20:12 - 2014-07-02 20:12 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\daavm.bat
2014-07-02 20:10 - 2014-07-02 20:10 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\mdihee.bat
2014-07-02 20:08 - 2014-07-02 20:08 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\bwsnbfkg.bat
2014-07-02 20:06 - 2014-07-02 21:24 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ifaurma.bat
2014-07-02 20:04 - 2014-07-02 20:04 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\icmhi.bat
2014-07-02 20:02 - 2014-07-02 20:02 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\iceyccqr.bat
2014-07-02 19:58 - 2014-07-02 19:58 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\cfkwbi.bat
2014-07-02 19:56 - 2014-07-02 19:56 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\mchnazfn.bat
2014-07-02 19:54 - 2014-07-02 19:54 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\lkinlcp.bat
2014-07-02 19:52 - 2014-07-02 19:52 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\pqstvwya.bat
2014-07-02 19:50 - 2014-07-02 19:50 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ognpxhp.bat
2014-07-02 19:47 - 2014-07-02 19:47 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\kodgkh.bat
2014-07-02 19:45 - 2014-07-02 19:45 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\warasv.bat
2014-07-02 19:43 - 2014-07-02 19:43 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\zviealh.bat
2014-07-02 19:41 - 2014-07-02 19:41 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\kpbhd.bat
2014-07-02 19:39 - 2014-07-02 19:39 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\bkdpjnfs.bat
2014-07-02 19:37 - 2014-07-03 05:49 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\cxmbxm.bat
2014-07-02 19:35 - 2014-07-02 19:35 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\bddrto.bat
2014-07-02 19:33 - 2014-07-02 19:33 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\nmdcc.bat
2014-07-02 19:31 - 2014-07-02 19:31 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\iscpblej.bat
2014-07-02 19:29 - 2014-07-02 19:29 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\droeb.bat
2014-07-02 19:27 - 2014-07-02 19:27 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\thfayns.bat
2014-07-02 19:25 - 2014-07-02 19:25 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\ecdzrpfh.bat
2014-07-02 19:23 - 2014-07-02 19:23 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\gnvgf.bat
2014-07-02 19:21 - 2014-07-02 19:21 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\branujqg.bat
2014-07-02 19:19 - 2014-07-02 19:19 - 00000266 _____ () C:\Users\Gnodti\AppData\Local\bwsnb.bat LG |