Police Virus

Started by DR M, September 01, 2013, 06:54:44 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

DR M

It's running! In safe mode.
Grecian Geek

"Count your blessings, remember your prayers..."

"In one of the stars I shall be living. In one of them I shall be laughing. And so it will be as if all the stars will be laughing when you look at the sky at night.. You, only you, will have stars that can laugh..."

DR M

I ran it 3 times due to different reasons, and now I have only one log. The first time two logs were created, but something went wrong, I re-ran the program and then no extras log...

I forgot to say that in c:users, two other accounts were created. I deleted them.


MARIAM'S ACCOUNT (NOT ADMIN'S, BUT RAN AS ADMIN)

OTL logfile created on: 9/5/2013 11:36:35 PM - Run 2
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\mariam\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16660)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.91 Gb Total Physical Memory | 3.07 Gb Available Physical Memory | 78.48% Memory free
7.82 Gb Paging File | 7.08 Gb Available in Paging File | 90.52% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 451.01 Gb Total Space | 404.48 Gb Free Space | 89.68% Space Free | Partition Type: NTFS
Drive E: | 3.74 Gb Total Space | 3.42 Gb Free Space | 91.59% Space Free | Partition Type: FAT32

Computer Name: 123456789 | User Name: ?a??aµ | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/09/05 22:59:57 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\mariam\Desktop\OTL.exe


========== Modules (No Company Name) ==========


========== Services (SafeList) ==========

SRV:64bit: - [2013/05/27 08:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2011/05/27 22:06:16 | 000,301,568 | ---- | M] (IDT, Inc.) [Auto | Stopped] -- C:\Program Files\IDT\WDM\stacsv64.exe -- (STacSV)
SRV:64bit: - [2011/01/14 00:56:40 | 000,956,192 | ---- | M] (Broadcom Corporation.) [Auto | Stopped] -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins)
SRV:64bit: - [2010/09/23 03:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2009/03/03 13:42:58 | 000,089,600 | ---- | M] (Andrea Electronics Corporation) [Auto | Stopped] -- C:\Program Files\IDT\WDM\AESTSr64.exe -- (AESTFilters)
SRV - [2013/08/01 08:48:40 | 000,246,112 | ---- | M] () [Auto | Stopped] -- C:\Program Files (x86)\MTN Mobile Broadband\UpdateDog\ouc.exe -- (MTN Mobile Broadband. RunOuc)
SRV - [2013/04/04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2013/04/04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012/12/18 07:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/07/13 16:27:00 | 000,769,432 | ---- | M] (Nero AG) [Auto | Stopped] -- C:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate)
SRV - [2011/02/01 22:20:48 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2011/02/01 22:20:46 | 000,326,168 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2011/01/13 03:00:42 | 000,013,336 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc)
SRV - [2010/10/12 20:59:12 | 000,206,072 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe -- (GamesAppService)
SRV - [2010/08/21 02:53:08 | 000,689,472 | ---- | M] (SoftThinks SAS) [Auto | Stopped] -- C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe -- (SftService)
SRV - [2010/03/18 22:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/12/02 22:23:38 | 000,209,768 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)
SRV - [2009/12/02 22:23:32 | 000,483,688 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)
SRV - [2009/06/11 00:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008/12/22 11:52:16 | 000,104,944 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2013/09/04 07:39:04 | 000,032,512 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hitmanpro37.sys -- (hitmanpro37)
DRV:64bit: - [2013/08/01 08:48:44 | 000,223,744 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ew_juwwanecm.sys -- (huawei_wwanecm)
DRV:64bit: - [2013/08/01 08:48:44 | 000,028,672 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ew_juextctrl.sys -- (huawei_ext_ctrl)
DRV:64bit: - [2013/08/01 08:48:44 | 000,013,952 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ew_usbenumfilter.sys -- (ew_usbenumfilter)
DRV:64bit: - [2013/08/01 08:48:43 | 000,117,248 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ew_hwusbdev.sys -- (ew_hwusbdev)
DRV:64bit: - [2013/08/01 08:48:43 | 000,098,304 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ew_jucdcacm.sys -- (huawei_cdcacm)
DRV:64bit: - [2013/08/01 08:48:43 | 000,087,040 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ew_jubusenum.sys -- (huawei_enumerator)
DRV:64bit: - [2013/04/04 14:50:32 | 000,025,928 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2012/03/01 09:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011/08/19 01:40:08 | 004,719,168 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:64bit: - [2011/08/19 01:39:52 | 000,039,464 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwl2cap.sys -- (btwl2cap)
DRV:64bit: - [2011/08/19 01:39:52 | 000,021,416 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwrchid.sys -- (btwrchid)
DRV:64bit: - [2011/08/19 01:39:50 | 000,349,736 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwampfl.sys -- (BTWAMPFL)
DRV:64bit: - [2011/08/19 01:39:50 | 000,138,280 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwavdt.sys -- (btwavdt)
DRV:64bit: - [2011/08/19 01:39:50 | 000,106,536 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwaudio.sys -- (btwaudio)
DRV:64bit: - [2011/05/27 22:06:16 | 000,528,384 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stwrt64.sys -- (STHDA)
DRV:64bit: - [2011/05/17 09:55:28 | 000,533,096 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011/04/01 06:35:12 | 000,355,960 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Apfiltr.sys -- (ApfiltrService)
DRV:64bit: - [2011/03/26 05:17:48 | 012,262,336 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2011/03/11 09:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 09:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/01/20 20:20:46 | 000,176,096 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CtClsFlt.sys -- (CtClsFlt)
DRV:64bit: - [2011/01/13 02:51:44 | 000,439,320 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2010/11/21 06:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/21 06:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/21 06:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2010/10/30 03:11:42 | 000,250,984 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV:64bit: - [2010/10/20 01:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:64bit: - [2010/10/15 12:28:16 | 000,317,440 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:64bit: - [2010/03/19 12:00:00 | 000,055,856 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2009/12/02 22:23:38 | 000,022,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Sftvollh.sys -- (Sftvol)
DRV:64bit: - [2009/12/02 22:23:34 | 000,025,960 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Sftredirlh.sys -- (Sftredir)
DRV:64bit: - [2009/12/02 22:23:32 | 000,269,672 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Sftplaylh.sys -- (Sftplay)
DRV:64bit: - [2009/12/02 22:23:26 | 000,721,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Sftfslh.sys -- (Sftfs)
DRV:64bit: - [2009/09/19 05:30:14 | 000,161,280 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ss_bmdm.sys -- (ss_bmdm)
DRV:64bit: - [2009/09/19 05:30:14 | 000,127,488 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ss_bbus.sys -- (ss_bbus)
DRV:64bit: - [2009/09/19 05:30:14 | 000,018,944 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ss_bmdfl.sys -- (ss_bmdfl)
DRV:64bit: - [2009/07/14 04:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/14 04:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/14 04:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 23:35:36 | 000,867,328 | ---- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netr28ux.sys -- (netr28ux)
DRV:64bit: - [2009/06/10 23:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 23:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 23:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 23:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2006/11/01 21:51:00 | 000,151,656 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WimFltr.sys -- (WimFltr)
DRV - [2009/07/14 04:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =  [binary data]
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{2F1E335A-858A-4BE9-8F6B-D0AF1D018B53}: "URL" = http://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =  [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{2F1E335A-858A-4BE9-8F6B-D0AF1D018B53}: "URL" = http://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
IE - HKU\.DEFAULT\..\URLSearchHook: {D8278076-BC68-4484-9233-6E7F1628B56C} - No CLSID value found
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
IE - HKU\S-1-5-18\..\URLSearchHook: {D8278076-BC68-4484-9233-6E7F1628B56C} - No CLSID value found
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)

IE - HKU\S-1-5-20\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)

IE - HKU\S-1-5-21-2441083668-204223877-1480447853-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
IE - HKU\S-1-5-21-2441083668-204223877-1480447853-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKU\S-1-5-21-2441083668-204223877-1480447853-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com.cy/
IE - HKU\S-1-5-21-2441083668-204223877-1480447853-1000\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
IE - HKU\S-1-5-21-2441083668-204223877-1480447853-1000\..\SearchScopes,DefaultScope = {43E5A87C-F225-441F-A611-63692E6C1B3E}
IE - HKU\S-1-5-21-2441083668-204223877-1480447853-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR
IE - HKU\S-1-5-21-2441083668-204223877-1480447853-1000\..\SearchScopes\{43E5A87C-F225-441F-A611-63692E6C1B3E}: "URL" = http://asksearch.ask.com/redirect?client=ie&src=kw&tb=SGTV7-SAT&itbv=12.1.0.298&o=APN11005&locale=en_EU&apn_uid=CC42A0B6-6FA4-47CE-A1E9-4CB866D04C76&apn_ptnrs=%5EB3R&apn_dtid=%5EYYYYYY%5EYY%5ECY&apn_dbr=iexplore.exe_6_10.0.9200.16635&doi=2013-07-17&q={searchTerms}&
IE - HKU\S-1-5-21-2441083668-204223877-1480447853-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\S-1-5-21-2441083668-204223877-1480447853-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-2441083668-204223877-1480447853-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
IE - HKU\S-1-5-21-2441083668-204223877-1480447853-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKU\S-1-5-21-2441083668-204223877-1480447853-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com.cy/?gws_rd=cr
IE - HKU\S-1-5-21-2441083668-204223877-1480447853-1002\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
IE - HKU\S-1-5-21-2441083668-204223877-1480447853-1002\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-2441083668-204223877-1480447853-1002\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR
IE - HKU\S-1-5-21-2441083668-204223877-1480447853-1002\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7RLTB_enCY518
IE - HKU\S-1-5-21-2441083668-204223877-1480447853-1002\..\SearchScopes\{F79FAD32-8DF3-4B79-BDB3-EFFCADA262BA}: "URL" = http://asksearch.ask.com/redirect?client=ie&src=kw&tb=SGTV7-SAT&itbv=12.1.0.298&o=APN11005&locale=en_EU&apn_uid=CC42A0B6-6FA4-47CE-A1E9-4CB866D04C76&apn_ptnrs=%5EB3R&apn_dtid=%5EYYYYYY%5EYY%5ECY&apn_dbr=iexplore.exe_6_10.0.9200.16635&doi=2013-07-17&q={searchTerms}&
IE - HKU\S-1-5-21-2441083668-204223877-1480447853-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpWinExt,version=5.0: C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\msntoolbar@msn.com: C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\Firefox [2012/01/29 12:10:19 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2012/01/29 12:10:21 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2012/01/29 12:10:24 | 000,000,000 | ---D | M]


========== Chrome  ==========

CHR - default_search_provider: Ask Search (Enabled)
CHR - default_search_provider: search_url = http://asksearch.ask.com/redirect?client=cr&src=kw&tb=SGT-V6&o=APN10026&itbv=11.8.2.659&doi=2013-05-07&locale=en_EU&apn_uid=108011FA-2EAB-428E-A7DE-11631F36B89B&apn_ptnrs=^AM3&apn_dtid=^YYYYYY^YY^CY&apn_dbr=iexplore.exe_6_10.0.9200.16537&&q={searchTerms}
CHR - default_search_provider: suggest_url = http://ss.websearch.ask.com/query?qsrc={qsrc}&li=ff&sstype=prefix&q={searchTerms}
CHR - homepage: http://www.search.ask.com/?l=dis&o=APN10026cr&gct=hp&apn_ptnrs=^AM3&apn_dtid=^YYYYYY^YY^CY&p2=^AM3^YYYYYY^YY^CY&tpid=SGT-V6&apn_dbr=iexplore.exe_6_10.0.9200.16537&apn_uid=108011FA-2EAB-428E-A7DE-11631F36B89B&itbv=11.8.2.659&doi=2013-05-07
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\gcswf32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 7.0.10.8 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 7 U1 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll
CHR - plugin: Bing Bar (Enabled) = C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\windows\SysWOW64\Adobe\Director\np32dsw_1167637.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\progra~2\mcafee\msc\npmcsn~1.dll
CHR - Extension: Ask Toolbar = C:\Users\Μαριαμ\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaklflnpehbaoodgpdnnfmnpobplpk\12.45346_0\
CHR - Extension: YouTube = C:\Users\Μαριαμ\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = C:\Users\Μαριαμ\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Gmail = C:\Users\Μαριαμ\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\

O1 HOSTS File: ([2013/09/04 22:03:18 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1       localhost
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll File not found
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Bing Bar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll File not found
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (@C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation)
O3:64bit: - HKU\S-1-5-21-2441083668-204223877-1480447853-1000\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKU\S-1-5-21-2441083668-204223877-1480447853-1000\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3:64bit: - HKU\S-1-5-21-2441083668-204223877-1480447853-1002\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKU\S-1-5-21-2441083668-204223877-1480447853-1002\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [AccuWeatherWidget] C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe ()
O4 - HKU\S-1-5-21-2441083668-204223877-1480447853-1002..\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent File not found
O4 - HKU\S-1-5-21-2441083668-204223877-1480447853-1002..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKLM..\RunOnce: [C5854111-94E3-4732-A438-3F2B13FBC101] C:\windows\SysWow64\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe (Softthinks)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2441083668-204223877-1480447853-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2441083668-204223877-1480447853-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-2441083668-204223877-1480447853-1002\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8:64bit: - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8:64bit: - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000001 [] - C:\Windows\SysNative\nlaapi.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000002 [] - C:\Windows\SysNative\NapiNSP.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000003 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000004 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Windows\SysNative\winrnr.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Windows\SysNative\wshbth.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000011 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\SysWOW64\nlaapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\SysWOW64\NapiNSP.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\SysWOW64\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Windows\SysWOW64\wshbth.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.10.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{000F090D-0BD2-41DB-9C77-F1C862EB7D0F}: DhcpNameServer = 192.168.10.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D289C21A-4F42-451F-8928-E8648F662A1D}: DhcpNameServer = 192.168.10.254
O18:64bit: - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysNative\inetcomm.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysWOW64\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\windows\SysNative\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\windows\SysWow64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\windows\SysWow64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\windows\SysWow64\mscoree.dll (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O29:64bit: - HKLM SecurityProviders - (credssp.dll) - C:\windows\SysWow64\credssp.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (credssp.dll) - C:\windows\SysWow64\credssp.dll (Microsoft Corporation)
O30:64bit: - LSA: Authentication Packages - (msv1_0) - C:\windows\SysNative\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\windows\SysWow64\msv1_0.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (kerberos) - C:\windows\SysNative\kerberos.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (msv1_0) - C:\windows\SysNative\msv1_0.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (schannel) - C:\windows\SysNative\schannel.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (wdigest) - C:\windows\SysNative\wdigest.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (tspkg) - C:\windows\SysNative\tspkg.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (pku2u) - C:\windows\SysNative\pku2u.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (livessp) - C:\windows\SysNative\livessp.dll (Microsoft Corp.)
O30 - LSA: Security Packages - (kerberos) - C:\windows\SysWow64\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\windows\SysWow64\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\windows\SysWow64\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\windows\SysWow64\wdigest.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (tspkg) - C:\windows\SysWow64\tspkg.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\windows\SysWow64\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (livessp) - C:\windows\SysWow64\livessp.dll (Microsoft Corp.)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2015/10/08 15:41:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Creative
[2013/09/05 19:41:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2013/09/05 14:38:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/09/05 14:38:43 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbam.sys
[2013/09/05 14:38:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/09/04 22:07:37 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2013/09/04 22:07:33 | 000,000,000 | ---D | C] -- C:\windows\temp
[2013/09/03 23:31:17 | 000,000,000 | ---D | C] -- C:\ProgramData\HitmanPro
[2013/09/03 18:19:34 | 000,518,144 | ---- | C] (SteelWerX) -- C:\windows\SWREG.exe
[2013/09/03 18:19:34 | 000,406,528 | ---- | C] (SteelWerX) -- C:\windows\SWSC.exe
[2013/09/03 18:19:34 | 000,060,416 | ---- | C] (NirSoft) -- C:\windows\NIRCMD.exe
[2013/09/03 18:19:04 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013/09/03 18:18:47 | 000,000,000 | ---D | C] -- C:\windows\erdnt
[2013/08/28 21:36:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Steam
[2013/08/28 21:36:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Steam
[2013/08/19 19:03:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Emsisoft Anti-Malware
[2013/08/19 16:47:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013/08/14 15:33:25 | 000,526,336 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ieui.dll
[2013/08/14 15:33:25 | 000,391,168 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ieui.dll
[2013/08/14 15:33:25 | 000,136,704 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\iesysprep.dll
[2013/08/14 15:33:25 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\iesysprep.dll
[2013/08/14 15:33:25 | 000,089,600 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\RegisterIEPKEYs.exe
[2013/08/14 15:33:25 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\RegisterIEPKEYs.exe
[2013/08/14 15:33:25 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\iesetup.dll
[2013/08/14 15:33:25 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\iesetup.dll
[2013/08/14 15:33:25 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ie4uinit.exe
[2013/08/14 15:33:25 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\iernonce.dll
[2013/08/14 15:33:25 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\iernonce.dll
[2013/08/14 15:33:24 | 000,603,136 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\msfeeds.dll
[2013/08/14 15:33:23 | 003,958,784 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\jscript9.dll
[2013/08/14 15:33:23 | 000,855,552 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\jscript.dll
[2013/08/14 15:33:23 | 000,690,688 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\jscript.dll
[2013/08/14 15:10:29 | 001,472,512 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\crypt32.dll
[2013/08/14 15:10:29 | 000,224,256 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wintrust.dll
[2013/08/14 15:10:27 | 000,139,776 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\cryptnet.dll
[2013/08/14 15:09:53 | 001,888,768 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\WMVDECOD.DLL
[2013/08/14 15:09:53 | 001,620,992 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\WMVDECOD.DLL
[2013/08/14 15:09:52 | 001,217,024 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\rpcrt4.dll
[2013/08/14 15:09:47 | 003,913,664 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ntoskrnl.exe
[2013/08/14 15:09:46 | 005,550,528 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ntoskrnl.exe
[2013/08/14 15:09:46 | 003,968,960 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ntkrnlpa.exe
[2013/08/14 15:09:45 | 001,732,032 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ntdll.dll
[2013/08/14 15:09:44 | 000,243,712 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wow64.dll
[2013/08/14 15:09:43 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ntvdm64.dll
[2013/08/14 15:09:35 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\wow32.dll
[2013/08/14 15:09:34 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\setup16.exe
[2013/08/14 15:09:33 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\instnm.exe
[2013/08/14 15:09:33 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\user.exe
[2013/08/13 09:00:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YTD Video Downloader

========== Files - Modified Within 30 Days ==========

[2015/11/02 09:33:00 | 000,000,422 | ---- | M] () -- C:\windows\tasks\SystemToolsDailyTest.job
[2015/11/01 10:18:38 | 000,000,000 | -H-- | M] () -- C:\windows\SysNative\drivers\Msft_Kernel_ew_juextctrl_01007.Wdf
[2015/11/01 10:18:33 | 000,000,000 | -H-- | M] () -- C:\windows\SysNative\drivers\Msft_Kernel_ew_jucdcacm_01007.Wdf
[2013/09/05 23:24:43 | 003,186,420 | ---- | M] () -- C:\windows\SysNative\perfh009.dat
[2013/09/05 23:24:43 | 001,001,554 | ---- | M] () -- C:\windows\SysNative\perfc009.dat
[2013/09/05 23:24:43 | 000,006,498 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI
[2013/09/05 23:05:14 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2013/09/05 23:05:02 | 3149,086,720 | -HS- | M] () -- C:\hiberfil.sys
[2013/09/05 23:00:51 | 000,327,680 | ---- | M] () -- C:\windows\SysNative\Ikeext.etl
[2013/09/05 22:10:33 | 000,000,894 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/09/05 22:08:31 | 000,020,720 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/09/05 22:08:31 | 000,020,720 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/09/05 22:01:02 | 000,000,898 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/09/05 19:36:11 | 000,003,288 | ---- | M] () -- C:\bootsqm.dat
[2013/09/05 14:38:44 | 000,001,071 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/09/04 22:03:18 | 000,000,027 | ---- | M] () -- C:\windows\SysNative\drivers\etc\hosts
[2013/09/04 21:40:30 | 000,277,184 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT
[2013/09/04 07:39:04 | 000,032,512 | ---- | M] () -- C:\windows\SysNative\drivers\hitmanpro37.sys
[2013/09/04 07:38:08 | 000,000,330 | ---- | M] () -- C:\windows\SysNative\.crusader
[2013/08/22 13:30:31 | 000,000,564 | ---- | M] () -- C:\windows\tasks\PCDoctorBackgroundMonitorTask.job
[2013/08/19 17:53:42 | 000,002,767 | ---- | M] () -- C:\Users\Public\Desktop\SyncUP.lnk
[2013/08/16 14:54:09 | 000,000,165 | ---- | M] () -- C:\ProgramData\oupkdkrjntyjjutsnpm.reg
[2013/08/16 14:54:09 | 000,000,070 | ---- | M] () -- C:\ProgramData\oupkdkrjntyjjutsnpm.bat

========== Files Created - No Company Name ==========

[2015/11/01 10:18:38 | 000,000,000 | -H-- | C] () -- C:\windows\SysNative\drivers\Msft_Kernel_ew_juextctrl_01007.Wdf
[2015/11/01 10:18:33 | 000,000,000 | -H-- | C] () -- C:\windows\SysNative\drivers\Msft_Kernel_ew_jucdcacm_01007.Wdf
[2013/09/05 19:36:11 | 000,003,288 | ---- | C] () -- C:\bootsqm.dat
[2013/09/05 14:38:44 | 000,001,071 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/09/04 07:39:04 | 000,032,512 | ---- | C] () -- C:\windows\SysNative\drivers\hitmanpro37.sys
[2013/09/04 07:38:08 | 000,000,330 | ---- | C] () -- C:\windows\SysNative\.crusader
[2013/09/03 18:19:34 | 000,256,000 | ---- | C] () -- C:\windows\PEV.exe
[2013/09/03 18:19:34 | 000,208,896 | ---- | C] () -- C:\windows\MBR.exe
[2013/09/03 18:19:34 | 000,098,816 | ---- | C] () -- C:\windows\sed.exe
[2013/09/03 18:19:34 | 000,080,412 | ---- | C] () -- C:\windows\grep.exe
[2013/09/03 18:19:34 | 000,068,096 | ---- | C] () -- C:\windows\zip.exe
[2013/08/16 14:54:09 | 000,000,165 | ---- | C] () -- C:\ProgramData\oupkdkrjntyjjutsnpm.reg
[2013/08/16 14:54:09 | 000,000,070 | ---- | C] () -- C:\ProgramData\oupkdkrjntyjjutsnpm.bat
[2012/01/29 13:09:45 | 000,963,116 | ---- | C] () -- C:\windows\SysWow64\igkrng600.bin
[2012/01/29 13:09:44 | 000,216,876 | ---- | C] () -- C:\windows\SysWow64\igfcg600m.bin
[2012/01/29 13:09:44 | 000,145,804 | ---- | C] () -- C:\windows\SysWow64\igcompkrng600.bin
[2012/01/29 11:43:36 | 000,017,776 | ---- | C] () -- C:\windows\EvtMessage.dll
[2011/11/16 23:49:04 | 000,000,096 | ---- | C] () -- C:\windows\LaunApp.ini
[2011/11/16 23:49:01 | 000,000,325 | ---- | C] () -- C:\windows\Prelaunch.ini
[2011/11/16 23:49:01 | 000,000,271 | ---- | C] () -- C:\windows\WisPriority.ini
[2011/11/16 23:49:01 | 000,000,035 | ---- | C] () -- C:\windows\DELL_LANGCODE.ini
[2011/11/16 23:49:01 | 000,000,033 | ---- | C] () -- C:\windows\DELL_OSTYPE.ini
[2011/11/16 23:49:01 | 000,000,032 | ---- | C] () -- C:\windows\WisHWDest.ini
[2011/11/16 23:49:01 | 000,000,028 | ---- | C] () -- C:\windows\WisLangCode.ini
[2011/11/16 23:49:01 | 000,000,023 | ---- | C] () -- C:\windows\WisSysInfo.ini
[2011/11/16 22:25:01 | 000,774,004 | ---- | C] () -- C:\windows\SysWow64\PerfStringBackup.INI

========== ZeroAccess Check ==========

[2009/07/14 07:55:00 | 000,000,227 | RHS- | M] () -- C:\windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURREN
Grecian Geek

"Count your blessings, remember your prayers..."

"In one of the stars I shall be living. In one of them I shall be laughing. And so it will be as if all the stars will be laughing when you look at the sky at night.. You, only you, will have stars that can laugh..."

DR M

And the rest log (from zero access)

========== ZeroAccess Check ==========

[2009/07/14 07:55:00 | 000,000,227 | RHS- | M] () -- C:\windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013/02/27 08:52:56 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013/02/27 07:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 04:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/21 06:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 04:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== Files - Unicode (All) ==========
[2015/10/31 17:15:11 | 000,000,000 | R--D | C](C:\Users\?a??aµ\Pictures) -- C:\Users\Μαριαμ\Pictures
[2015/10/16 14:56:33 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\Dell Edoc Viewer) -- C:\Users\Μαριαμ\AppData\Local\Dell Edoc Viewer
[2015/10/16 14:56:33 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\Dell Edoc Viewer) -- C:\Users\Μαριαμ\AppData\Local\Dell Edoc Viewer
[2013/09/05 23:36:03 | 002,359,296 | -HS- | M] ()(C:\Users\?a??aµ\ntuser.dat) -- C:\Users\Μαριαμ\ntuser.dat
[2013/09/05 23:36:03 | 000,262,144 | -HS- | M] ()(C:\Users\?a??aµ\ntuser.dat.LOG1) -- C:\Users\Μαριαμ\ntuser.dat.LOG1
[2013/09/05 23:15:13 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\temp) -- C:\Users\Μαριαμ\AppData\Local\temp
[2013/09/05 23:15:13 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\temp) -- C:\Users\Μαριαμ\AppData\Local\temp
[2013/09/05 22:23:03 | 002,748,256 | ---- | M] (Kaspersky Lab ZAO)(C:\Users\?a??aµ\Desktop\troika.com) -- C:\Users\Μαριαμ\Desktop\troika.com
[2013/09/05 22:23:03 | 002,748,256 | ---- | C] (Kaspersky Lab ZAO)(C:\Users\?a??aµ\Desktop\troika.com) -- C:\Users\Μαριαμ\Desktop\troika.com
[2013/09/05 22:23:03 | 000,000,000 | R--D | M](C:\Users\?a??aµ\Desktop) -- C:\Users\Μαριαμ\Desktop
[2013/09/05 22:23:03 | 000,000,000 | R--D | M](C:\Users\?a??aµ\Desktop) -- C:\Users\Μαριαμ\Desktop
[2013/09/05 22:07:14 | 002,748,256 | ---- | M] (Kaspersky Lab ZAO)(C:\Users\?a??aµ\Desktop\CORRINE.com) -- C:\Users\Μαριαμ\Desktop\CORRINE.com
[2013/09/05 22:07:14 | 002,748,256 | ---- | C] (Kaspersky Lab ZAO)(C:\Users\?a??aµ\Desktop\CORRINE.com) -- C:\Users\Μαριαμ\Desktop\CORRINE.com
[2013/09/05 22:06:15 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\SoftThinks) -- C:\Users\Μαριαμ\AppData\Local\SoftThinks
[2013/09/05 22:06:15 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\SoftThinks) -- C:\Users\Μαριαμ\AppData\Local\SoftThinks
[2013/09/05 14:33:09 | 010,285,040 | ---- | M] (Malwarebytes Corporation                                    )(C:\Users\?a??aµ\Desktop\mbam-setup-1.75.0.1300.exe) -- C:\Users\Μαριαμ\Desktop\mbam-setup-1.75.0.1300.exe
[2013/09/05 14:32:56 | 010,285,040 | ---- | C] (Malwarebytes Corporation                                    )(C:\Users\?a??aµ\Desktop\mbam-setup-1.75.0.1300.exe) -- C:\Users\Μαριαμ\Desktop\mbam-setup-1.75.0.1300.exe
[2013/09/04 22:08:28 | 000,020,390 | ---- | M] ()(C:\Users\?a??aµ\Desktop\combo.txt) -- C:\Users\Μαριαμ\Desktop\combo.txt
[2013/09/04 22:08:28 | 000,020,390 | ---- | C] ()(C:\Users\?a??aµ\Desktop\combo.txt) -- C:\Users\Μαριαμ\Desktop\combo.txt
[2013/09/04 22:07:33 | 000,000,000 | ---D | C](C:\Users\?a??aµ\AppData\Local\temp) -- C:\Users\Μαριαμ\AppData\Local\temp
[2013/09/04 21:44:10 | 005,121,173 | ---- | M] (Swearware)(C:\Users\?a??aµ\Desktop\ComboFix.exe) -- C:\Users\Μαριαμ\Desktop\ComboFix.exe
[2013/09/04 21:43:40 | 005,121,173 | ---- | C] (Swearware)(C:\Users\?a??aµ\Desktop\ComboFix.exe) -- C:\Users\Μαριαμ\Desktop\ComboFix.exe
[2013/09/04 21:31:24 | 000,000,146 | ---- | M] ()(C:\Users\?a??aµ\Desktop\CFScript.txt) -- C:\Users\Μαριαμ\Desktop\CFScript.txt
[2013/09/04 21:31:24 | 000,000,146 | ---- | C] ()(C:\Users\?a??aµ\Desktop\CFScript.txt) -- C:\Users\Μαριαμ\Desktop\CFScript.txt
[2013/09/04 21:15:17 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\Roxio) -- C:\Users\Μαριαμ\AppData\Roaming\Roxio
[2013/09/04 21:15:17 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\Roxio) -- C:\Users\Μαριαμ\AppData\Roaming\Roxio
[2013/09/04 21:14:39 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\Roxio Log Files) -- C:\Users\Μαριαμ\AppData\Roaming\Roxio Log Files
[2013/09/04 21:14:39 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\Roxio Log Files) -- C:\Users\Μαριαμ\AppData\Roaming\Roxio Log Files
[2013/09/04 21:14:39 | 000,000,000 | ---D | C](C:\Users\?a??aµ\AppData\Roaming\Roxio Log Files) -- C:\Users\Μαριαμ\AppData\Roaming\Roxio Log Files
[2013/09/04 13:50:47 | 000,688,992 | ---- | M] (Swearware)(C:\Users\?a??aµ\Desktop\dds.scr) -- C:\Users\Μαριαμ\Desktop\dds.scr
[2013/09/04 13:50:47 | 000,688,992 | ---- | C] (Swearware)(C:\Users\?a??aµ\Desktop\dds.scr) -- C:\Users\Μαριαμ\Desktop\dds.scr
[2013/09/03 18:42:44 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\SoftGrid Client) -- C:\Users\Μαριαμ\AppData\Roaming\SoftGrid Client
[2013/09/03 18:42:44 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\SoftGrid Client) -- C:\Users\Μαριαμ\AppData\Roaming\SoftGrid Client
[2013/09/02 17:23:50 | 000,891,144 | ---- | C] ()(C:\Users\?a??aµ\Desktop\SecurityCheck.exe) -- C:\Users\Μαριαμ\Desktop\SecurityCheck.exe
[2013/09/02 17:23:33 | 001,898,112 | ---- | C] (Bleeping Computer, LLC)(C:\Users\?a??aµ\Desktop\rkill.exe) -- C:\Users\Μαριαμ\Desktop\rkill.exe
[2013/09/02 17:19:20 | 000,891,144 | ---- | M] ()(C:\Users\?a??aµ\Desktop\SecurityCheck.exe) -- C:\Users\Μαριαμ\Desktop\SecurityCheck.exe
[2013/09/02 17:16:18 | 001,898,112 | ---- | M] (Bleeping Computer, LLC)(C:\Users\?a??aµ\Desktop\rkill.exe) -- C:\Users\Μαριαμ\Desktop\rkill.exe
[2013/09/01 22:35:35 | 000,001,482 | -HS- | M] ()(C:\Users\?a??aµ\Desktop\desktop.ini) -- C:\Users\Μαριαμ\Desktop\desktop.ini
[2013/09/01 22:35:35 | 000,001,415 | ---- | M] ()(C:\Users\?a??aµ\Desktop\Internet Explorer (2).lnk) -- C:\Users\Μαριαμ\Desktop\Internet Explorer (2).lnk
[2013/09/01 22:35:35 | 000,001,415 | ---- | C] ()(C:\Users\?a??aµ\Desktop\Internet Explorer (2).lnk) -- C:\Users\Μαριαμ\Desktop\Internet Explorer (2).lnk
[2013/08/29 10:39:00 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\Google) -- C:\Users\Μαριαμ\AppData\Local\Google
[2013/08/29 10:39:00 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\Google) -- C:\Users\Μαριαμ\AppData\Local\Google
[2013/08/28 21:40:49 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\Nero) -- C:\Users\Μαριαμ\AppData\Local\Nero
[2013/08/28 21:40:49 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\Nero) -- C:\Users\Μαριαμ\AppData\Local\Nero
[2013/08/20 15:36:19 | 000,000,000 | ---D | M](C:\Users\?a??aµ\Documents\Anti-Malware) -- C:\Users\Μαριαμ\Documents\Anti-Malware
[2013/08/19 19:03:19 | 000,000,000 | R--D | M](C:\Users\?a??aµ\Documents) -- C:\Users\Μαριαμ\Documents
[2013/08/19 19:03:19 | 000,000,000 | R--D | M](C:\Users\?a??aµ\Documents) -- C:\Users\Μαριαμ\Documents
[2013/08/19 19:03:19 | 000,000,000 | ---D | C](C:\Users\?a??aµ\Documents\Anti-Malware) -- C:\Users\Μαριαμ\Documents\Anti-Malware
[2013/08/19 16:46:04 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\Programs) -- C:\Users\Μαριαμ\AppData\Local\Programs
[2013/08/19 16:46:04 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\Programs) -- C:\Users\Μαριαμ\AppData\Local\Programs
[2013/08/19 16:46:04 | 000,000,000 | ---D | C](C:\Users\?a??aµ\AppData\Local\Programs) -- C:\Users\Μαριαμ\AppData\Local\Programs
[2013/08/19 16:36:24 | 000,524,288 | -HS- | M] ()(C:\Users\?a??aµ\ntuser.dat{4dec9a77-08a0-11e3-9493-9114f2237b38}.TMContainer00000000000000000002.regtrans-ms) -- C:\Users\Μαριαμ\ntuser.dat{4dec9a77-08a0-11e3-9493-9114f2237b38}.TMContainer00000000000000000002.regtrans-ms
[2013/08/19 16:36:24 | 000,524,288 | -HS- | M] ()(C:\Users\?a??aµ\ntuser.dat{4dec9a77-08a0-11e3-9493-9114f2237b38}.TMContainer00000000000000000001.regtrans-ms) -- C:\Users\Μαριαμ\ntuser.dat{4dec9a77-08a0-11e3-9493-9114f2237b38}.TMContainer00000000000000000001.regtrans-ms
[2013/08/19 16:36:24 | 000,065,536 | -HS- | M] ()(C:\Users\?a??aµ\ntuser.dat{4dec9a77-08a0-11e3-9493-9114f2237b38}.TM.blf) -- C:\Users\Μαριαμ\ntuser.dat{4dec9a77-08a0-11e3-9493-9114f2237b38}.TM.blf
[2013/08/19 16:36:18 | 000,524,288 | -HS- | C] ()(C:\Users\?a??aµ\ntuser.dat{4dec9a77-08a0-11e3-9493-9114f2237b38}.TMContainer00000000000000000002.regtrans-ms) -- C:\Users\Μαριαμ\ntuser.dat{4dec9a77-08a0-11e3-9493-9114f2237b38}.TMContainer00000000000000000002.regtrans-ms
[2013/08/19 16:36:18 | 000,524,288 | -HS- | C] ()(C:\Users\?a??aµ\ntuser.dat{4dec9a77-08a0-11e3-9493-9114f2237b38}.TMContainer00000000000000000001.regtrans-ms) -- C:\Users\Μαριαμ\ntuser.dat{4dec9a77-08a0-11e3-9493-9114f2237b38}.TMContainer00000000000000000001.regtrans-ms
[2013/08/19 16:36:18 | 000,065,536 | -HS- | C] ()(C:\Users\?a??aµ\ntuser.dat{4dec9a77-08a0-11e3-9493-9114f2237b38}.TM.blf) -- C:\Users\Μαριαμ\ntuser.dat{4dec9a77-08a0-11e3-9493-9114f2237b38}.TM.blf
[2013/08/19 10:25:45 | 000,524,288 | -HS- | M] ()(C:\Users\?a??aµ\ntuser.dat{4dec9a4c-08a0-11e3-9493-9114f2237b38}.TMContainer00000000000000000002.regtrans-ms) -- C:\Users\Μαριαμ\ntuser.dat{4dec9a4c-08a0-11e3-9493-9114f2237b38}.TMContainer00000000000000000002.regtrans-ms
[2013/08/19 10:25:45 | 000,524,288 | -HS- | M] ()(C:\Users\?a??aµ\ntuser.dat{4dec9a4c-08a0-11e3-9493-9114f2237b38}.TMContainer00000000000000000001.regtrans-ms) -- C:\Users\Μαριαμ\ntuser.dat{4dec9a4c-08a0-11e3-9493-9114f2237b38}.TMContainer00000000000000000001.regtrans-ms
[2013/08/19 10:25:45 | 000,524,288 | -HS- | C] ()(C:\Users\?a??aµ\ntuser.dat{4dec9a4c-08a0-11e3-9493-9114f2237b38}.TMContainer00000000000000000002.regtrans-ms) -- C:\Users\Μαριαμ\ntuser.dat{4dec9a4c-08a0-11e3-9493-9114f2237b38}.TMContainer00000000000000000002.regtrans-ms
[2013/08/19 10:25:45 | 000,524,288 | -HS- | C] ()(C:\Users\?a??aµ\ntuser.dat{4dec9a4c-08a0-11e3-9493-9114f2237b38}.TMContainer00000000000000000001.regtrans-ms) -- C:\Users\Μαριαμ\ntuser.dat{4dec9a4c-08a0-11e3-9493-9114f2237b38}.TMContainer00000000000000000001.regtrans-ms
[2013/08/19 10:25:45 | 000,065,536 | -HS- | M] ()(C:\Users\?a??aµ\ntuser.dat{4dec9a4c-08a0-11e3-9493-9114f2237b38}.TM.blf) -- C:\Users\Μαριαμ\ntuser.dat{4dec9a4c-08a0-11e3-9493-9114f2237b38}.TM.blf
[2013/08/19 10:25:45 | 000,065,536 | -HS- | C] ()(C:\Users\?a??aµ\ntuser.dat{4dec9a4c-08a0-11e3-9493-9114f2237b38}.TM.blf) -- C:\Users\Μαριαμ\ntuser.dat{4dec9a4c-08a0-11e3-9493-9114f2237b38}.TM.blf
[2013/08/19 10:16:04 | 000,524,288 | -HS- | M] ()(C:\Users\?a??aµ\ntuser.dat{27736dc4-089b-11e3-a0e1-e4d53df12725}.TMContainer00000000000000000002.regtrans-ms) -- C:\Users\Μαριαμ\ntuser.dat{27736dc4-089b-11e3-a0e1-e4d53df12725}.TMContainer00000000000000000002.regtrans-ms
[2013/08/19 10:16:04 | 000,524,288 | -HS- | M] ()(C:\Users\?a??aµ\ntuser.dat{27736dc4-089b-11e3-a0e1-e4d53df12725}.TMContainer00000000000000000001.regtrans-ms) -- C:\Users\Μαριαμ\ntuser.dat{27736dc4-089b-11e3-a0e1-e4d53df12725}.TMContainer00000000000000000001.regtrans-ms
[2013/08/19 10:16:04 | 000,524,288 | -HS- | C] ()(C:\Users\?a??aµ\ntuser.dat{27736dc4-089b-11e3-a0e1-e4d53df12725}.TMContainer00000000000000000002.regtrans-ms) -- C:\Users\Μαριαμ\ntuser.dat{27736dc4-089b-11e3-a0e1-e4d53df12725}.TMContainer00000000000000000002.regtrans-ms
[2013/08/19 10:16:04 | 000,524,288 | -HS- | C] ()(C:\Users\?a??aµ\ntuser.dat{27736dc4-089b-11e3-a0e1-e4d53df12725}.TMContainer00000000000000000001.regtrans-ms) -- C:\Users\Μαριαμ\ntuser.dat{27736dc4-089b-11e3-a0e1-e4d53df12725}.TMContainer00000000000000000001.regtrans-ms
[2013/08/19 10:16:04 | 000,065,536 | -HS- | M] ()(C:\Users\?a??aµ\ntuser.dat{27736dc4-089b-11e3-a0e1-e4d53df12725}.TM.blf) -- C:\Users\Μαριαμ\ntuser.dat{27736dc4-089b-11e3-a0e1-e4d53df12725}.TM.blf
[2013/08/19 10:16:04 | 000,065,536 | -HS- | C] ()(C:\Users\?a??aµ\ntuser.dat{27736dc4-089b-11e3-a0e1-e4d53df12725}.TM.blf) -- C:\Users\Μαριαμ\ntuser.dat{27736dc4-089b-11e3-a0e1-e4d53df12725}.TM.blf
[2013/08/19 08:20:05 | 000,524,288 | -HS- | M] ()(C:\Users\?a??aµ\NTUSER.DAT{00737b80-088a-11e3-99b4-e4d53df12726}.TMContainer00000000000000000002.regtrans-ms) -- C:\Users\Μαριαμ\NTUSER.DAT{00737b80-088a-11e3-99b4-e4d53df12726}.TMContainer00000000000000000002.regtrans-ms
[2013/08/19 08:20:05 | 000,524,288 | -HS- | M] ()(C:\Users\?a??aµ\NTUSER.DAT{00737b80-088a-11e3-99b4-e4d53df12726}.TMContainer00000000000000000001.regtrans-ms) -- C:\Users\Μαριαμ\NTUSER.DAT{00737b80-088a-11e3-99b4-e4d53df12726}.TMContainer00000000000000000001.regtrans-ms
[2013/08/19 08:20:05 | 000,524,288 | -HS- | C] ()(C:\Users\?a??aµ\NTUSER.DAT{00737b80-088a-11e3-99b4-e4d53df12726}.TMContainer00000000000000000002.regtrans-ms) -- C:\Users\Μαριαμ\NTUSER.DAT{00737b80-088a-11e3-99b4-e4d53df12726}.TMContainer00000000000000000002.regtrans-ms
[2013/08/19 08:20:05 | 000,524,288 | -HS- | C] ()(C:\Users\?a??aµ\NTUSER.DAT{00737b80-088a-11e3-99b4-e4d53df12726}.TMContainer00000000000000000001.regtrans-ms) -- C:\Users\Μαριαμ\NTUSER.DAT{00737b80-088a-11e3-99b4-e4d53df12726}.TMContainer00000000000000000001.regtrans-ms
[2013/08/19 08:20:05 | 000,065,536 | -HS- | M] ()(C:\Users\?a??aµ\NTUSER.DAT{00737b80-088a-11e3-99b4-e4d53df12726}.TM.blf) -- C:\Users\Μαριαμ\NTUSER.DAT{00737b80-088a-11e3-99b4-e4d53df12726}.TM.blf
[2013/08/19 08:20:05 | 000,065,536 | -HS- | C] ()(C:\Users\?a??aµ\NTUSER.DAT{00737b80-088a-11e3-99b4-e4d53df12726}.TM.blf) -- C:\Users\Μαριαμ\NTUSER.DAT{00737b80-088a-11e3-99b4-e4d53df12726}.TM.blf
[2013/08/09 13:51:52 | 000,524,288 | -HS- | M] ()(C:\Users\?a??aµ\NTUSER.DAT{8737f5fa-00e1-11e3-ae65-e4d53df12726}.TMContainer00000000000000000002.regtrans-ms) -- C:\Users\Μαριαμ\NTUSER.DAT{8737f5fa-00e1-11e3-ae65-e4d53df12726}.TMContainer00000000000000000002.regtrans-ms
[2013/08/09 13:51:52 | 000,524,288 | -HS- | M] ()(C:\Users\?a??aµ\NTUSER.DAT{8737f5fa-00e1-11e3-ae65-e4d53df12726}.TMContainer00000000000000000001.regtrans-ms) -- C:\Users\Μαριαμ\NTUSER.DAT{8737f5fa-00e1-11e3-ae65-e4d53df12726}.TMContainer00000000000000000001.regtrans-ms
[2013/08/09 13:51:52 | 000,524,288 | -HS- | C] ()(C:\Users\?a??aµ\NTUSER.DAT{8737f5fa-00e1-11e3-ae65-e4d53df12726}.TMContainer00000000000000000002.regtrans-ms) -- C:\Users\Μαριαμ\NTUSER.DAT{8737f5fa-00e1-11e3-ae65-e4d53df12726}.TMContainer00000000000000000002.regtrans-ms
[2013/08/09 13:51:52 | 000,524,288 | -HS- | C] ()(C:\Users\?a??aµ\NTUSER.DAT{8737f5fa-00e1-11e3-ae65-e4d53df12726}.TMContainer00000000000000000001.regtrans-ms) -- C:\Users\Μαριαμ\NTUSER.DAT{8737f5fa-00e1-11e3-ae65-e4d53df12726}.TMContainer00000000000000000001.regtrans-ms
[2013/08/09 13:51:52 | 000,065,536 | -HS- | M] ()(C:\Users\?a??aµ\NTUSER.DAT{8737f5fa-00e1-11e3-ae65-e4d53df12726}.TM.blf) -- C:\Users\Μαριαμ\NTUSER.DAT{8737f5fa-00e1-11e3-ae65-e4d53df12726}.TM.blf
[2013/08/09 13:51:52 | 000,065,536 | -HS- | C] ()(C:\Users\?a??aµ\NTUSER.DAT{8737f5fa-00e1-11e3-ae65-e4d53df12726}.TM.blf) -- C:\Users\Μαριαμ\NTUSER.DAT{8737f5fa-00e1-11e3-ae65-e4d53df12726}.TM.blf
[2013/08/02 15:05:40 | 000,524,288 | -HS- | M] ()(C:\Users\?a??aµ\NTUSER.DAT{e25ccf1a-fb62-11e2-94b7-e4d53df12726}.TMContainer00000000000000000002.regtrans-ms) -- C:\Users\Μαριαμ\NTUSER.DAT{e25ccf1a-fb62-11e2-94b7-e4d53df12726}.TMContainer00000000000000000002.regtrans-ms
[2013/08/02 15:05:40 | 000,524,288 | -HS- | M] ()(C:\Users\?a??aµ\NTUSER.DAT{e25ccf1a-fb62-11e2-94b7-e4d53df12726}.TMContainer00000000000000000001.regtrans-ms) -- C:\Users\Μαριαμ\NTUSER.DAT{e25ccf1a-fb62-11e2-94b7-e4d53df12726}.TMContainer00000000000000000001.regtrans-ms
[2013/08/02 15:05:40 | 000,065,536 | -HS- | M] ()(C:\Users\?a??aµ\NTUSER.DAT{e25ccf1a-fb62-11e2-94b7-e4d53df12726}.TM.blf) -- C:\Users\Μαριαμ\NTUSER.DAT{e25ccf1a-fb62-11e2-94b7-e4d53df12726}.TM.blf
[2013/08/02 15:05:39 | 000,524,288 | -HS- | C] ()(C:\Users\?a??aµ\NTUSER.DAT{e25ccf1a-fb62-11e2-94b7-e4d53df12726}.TMContainer00000000000000000002.regtrans-ms) -- C:\Users\Μαριαμ\NTUSER.DAT{e25ccf1a-fb62-11e2-94b7-e4d53df12726}.TMContainer00000000000000000002.regtrans-ms
[2013/08/02 15:05:39 | 000,524,288 | -HS- | C] ()(C:\Users\?a??aµ\NTUSER.DAT{e25ccf1a-fb62-11e2-94b7-e4d53df12726}.TMContainer00000000000000000001.regtrans-ms) -- C:\Users\Μαριαμ\NTUSER.DAT{e25ccf1a-fb62-11e2-94b7-e4d53df12726}.TMContainer00000000000000000001.regtrans-ms
[2013/08/02 15:05:39 | 000,065,536 | -HS- | C] ()(C:\Users\?a??aµ\NTUSER.DAT{e25ccf1a-fb62-11e2-94b7-e4d53df12726}.TM.blf) -- C:\Users\Μαριαμ\NTUSER.DAT{e25ccf1a-fb62-11e2-94b7-e4d53df12726}.TM.blf
[2013/07/31 11:55:54 | 000,028,160 | ---- | M] ()(C:\Users\?a??aµ\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini) -- C:\Users\Μαριαμ\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/07/23 19:14:38 | 000,000,000 | ---D | M](C:\Users\?a??aµ\Desktop\t?a???d?a) -- C:\Users\Μαριαμ\Desktop\τραγουδια
[2013/06/05 15:11:13 | 006,395,264 | ---- | M] ()(C:\Users\?a??aµ\Desktop\Rock Me - One Direction (BEST LYRIC VIDEO).mp3) -- C:\Users\Μαριαμ\Desktop\Rock Me - One Direction (BEST LYRIC VIDEO).mp3
[2013/06/05 15:11:07 | 006,395,264 | ---- | C] ()(C:\Users\?a??aµ\Desktop\Rock Me - One Direction (BEST LYRIC VIDEO).mp3) -- C:\Users\Μαριαμ\Desktop\Rock Me - One Direction (BEST LYRIC VIDEO).mp3
[2013/06/05 15:10:55 | 005,034,368 | ---- | M] ()(C:\Users\?a??aµ\Desktop\One Direction - One Way Or Another (Lyric Video) - Copy.mp3) -- C:\Users\Μαριαμ\Desktop\One Direction - One Way Or Another (Lyric Video) - Copy.mp3
[2013/06/05 15:10:50 | 005,034,368 | ---- | C] ()(C:\Users\?a??aµ\Desktop\One Direction - One Way Or Another (Lyric Video) - Copy.mp3) -- C:\Users\Μαριαμ\Desktop\One Direction - One Way Or Another (Lyric Video) - Copy.mp3
[2013/06/05 15:10:48 | 006,081,920 | ---- | M] ()(C:\Users\?a??aµ\Desktop\One Direction - Kiss You (Official).mp3) -- C:\Users\Μαριαμ\Desktop\One Direction - Kiss You (Official).mp3
[2013/06/05 15:10:43 | 006,081,920 | ---- | C] ()(C:\Users\?a??aµ\Desktop\One Direction - Kiss You (Official).mp3) -- C:\Users\Μαριαμ\Desktop\One Direction - Kiss You (Official).mp3
[2013/06/05 12:31:48 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\Diagnostics) -- C:\Users\Μαριαμ\AppData\Local\Diagnostics
[2013/06/05 12:31:48 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\Diagnostics) -- C:\Users\Μαριαμ\AppData\Local\Diagnostics
[2013/06/03 17:37:56 | 000,000,402 | -HS- | M] ()(C:\Users\?a??aµ\Documents\desktop.ini) -- C:\Users\Μαριαμ\Documents\desktop.ini
[2013/06/03 17:37:56 | 000,000,174 | -HS- | M] ()(C:\Users\?a??aµ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini) -- C:\Users\Μαριαμ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
[2013/06/03 17:37:56 | 000,000,000 | R--D | M](C:\Users\?a??aµ\Videos) -- C:\Users\Μαριαμ\Videos
[2013/06/03 17:37:56 | 000,000,000 | R--D | M](C:\Users\?a??aµ\Searches) -- C:\Users\Μαριαμ\Searches
[2013/06/03 17:37:56 | 000,000,000 | R--D | M](C:\Users\?a??aµ\Saved Games) -- C:\Users\Μαριαμ\Saved Games
[2013/06/03 17:37:56 | 000,000,000 | R--D | M](C:\Users\?a??aµ\Pictures) -- C:\Users\Μαριαμ\Pictures
[2013/06/03 17:37:56 | 000,000,000 | R--D | M](C:\Users\?a??aµ\Music) -- C:\Users\Μαριαμ\Music
[2013/06/03 17:37:56 | 000,000,000 | R--D | M](C:\Users\?a??aµ\Links) -- C:\Users\Μαριαμ\Links
[2013/06/03 17:37:56 | 000,000,000 | R--D | M](C:\Users\?a??aµ\Favorites) -- C:\Users\Μαριαμ\Favorites
[2013/06/03 17:37:56 | 000,000,000 | R--D | M](C:\Users\?a??aµ\Downloads) -- C:\Users\Μαριαμ\Downloads
[2013/06/03 17:37:56 | 000,000,000 | R--D | M](C:\Users\?a??aµ\Contacts) -- C:\Users\Μαριαμ\Contacts
[2013/06/03 17:37:56 | 000,000,000 | R--D | M](C:\Users\?a??aµ\Videos) -- C:\Users\Μαριαμ\Videos
[2013/06/03 17:37:56 | 000,000,000 | R--D | M](C:\Users\?a??aµ\Searches) -- C:\Users\Μαριαμ\Searches
[2013/06/03 17:37:56 | 000,000,000 | R--D | M](C:\Users\?a??aµ\Saved Games) -- C:\Users\Μαριαμ\Saved Games
[2013/06/03 17:37:56 | 000,000,000 | R--D | M](C:\Users\?a??aµ\Pictures) -- C:\Users\Μαριαμ\Pictures
[2013/06/03 17:37:56 | 000,000,000 | R--D | M](C:\Users\?a??aµ\Music) -- C:\Users\Μαριαμ\Music
[2013/06/03 17:37:56 | 000,000,000 | R--D | M](C:\Users\?a??aµ\Links) -- C:\Users\Μαριαμ\Links
[2013/06/03 17:37:56 | 000,000,000 | R--D | M](C:\Users\?a??aµ\Favorites) -- C:\Users\Μαριαμ\Favorites
[2013/06/03 17:37:56 | 000,000,000 | R--D | M](C:\Users\?a??aµ\Downloads) -- C:\Users\Μαριαμ\Downloads
[2013/06/03 17:37:56 | 000,000,000 | R--D | M](C:\Users\?a??aµ\Contacts) -- C:\Users\Μαριαμ\Contacts
[2013/06/01 16:19:41 | 000,524,288 | -HS- | M] ()(C:\Users\?a??aµ\NTUSER.DAT{81ab0aed-cabd-11e2-8048-e4d53df12726}.TMContainer00000000000000000002.regtrans-ms) -- C:\Users\Μαριαμ\NTUSER.DAT{81ab0aed-cabd-11e2-8048-e4d53df12726}.TMContainer00000000000000000002.regtrans-ms
[2013/06/01 16:19:41 | 000,524,288 | -HS- | M] ()(C:\Users\?a??aµ\NTUSER.DAT{81ab0aed-cabd-11e2-8048-e4d53df12726}.TMContainer00000000000000000001.regtrans-ms) -- C:\Users\Μαριαμ\NTUSER.DAT{81ab0aed-cabd-11e2-8048-e4d53df12726}.TMContainer00000000000000000001.regtrans-ms
[2013/06/01 16:19:41 | 000,524,288 | -HS- | C] ()(C:\Users\?a??aµ\NTUSER.DAT{81ab0aed-cabd-11e2-8048-e4d53df12726}.TMContainer00000000000000000002.regtrans-ms) -- C:\Users\Μαριαμ\NTUSER.DAT{81ab0aed-cabd-11e2-8048-e4d53df12726}.TMContainer00000000000000000002.regtrans-ms
[2013/06/01 16:19:41 | 000,524,288 | -HS- | C] ()(C:\Users\?a??aµ\NTUSER.DAT{81ab0aed-cabd-11e2-8048-e4d53df12726}.TMContainer00000000000000000001.regtrans-ms) -- C:\Users\Μαριαμ\NTUSER.DAT{81ab0aed-cabd-11e2-8048-e4d53df12726}.TMContainer00000000000000000001.regtrans-ms
[2013/06/01 16:19:41 | 000,065,536 | -HS- | M] ()(C:\Users\?a??aµ\NTUSER.DAT{81ab0aed-cabd-11e2-8048-e4d53df12726}.TM.blf) -- C:\Users\Μαριαμ\NTUSER.DAT{81ab0aed-cabd-11e2-8048-e4d53df12726}.TM.blf
[2013/06/01 16:19:41 | 000,065,536 | -HS- | C] ()(C:\Users\?a??aµ\NTUSER.DAT{81ab0aed-cabd-11e2-8048-e4d53df12726}.TM.blf) -- C:\Users\Μαριαμ\NTUSER.DAT{81ab0aed-cabd-11e2-8048-e4d53df12726}.TM.blf
[2013/06/01 11:03:17 | 000,000,000 | R--D | M](C:\Users\?a??aµ\Desktop\MARIAM   TOMA   E  TA?? ??? F???S) -- C:\Users\Μαριαμ\Desktop\MARIAM   TOMA   E  TAΞΗ ΚΑΙ ΦΙΛΕΣ
[2013/06/01 10:54:56 | 000,000,000 | ---D | C](C:\Users\?a??aµ\Desktop\t?a???d?a) -- C:\Users\Μαριαμ\Desktop\τραγουδια
[2013/06/01 09:51:36 | 001,048,576 | -HS- | M] ()(C:\Users\?a??aµ\NTUSER.DAT{016888bc-6c6f-11de-8d1d-001e0bcde3ec}.TxR.2.regtrans-ms) -- C:\Users\Μαριαμ\NTUSER.DAT{016888bc-6c6f-11de-8d1d-001e0bcde3ec}.TxR.2.regtrans-ms
[2013/06/01 09:51:36 | 001,048,576 | -HS- | M] ()(C:\Users\?a??aµ\NTUSER.DAT{016888bc-6c6f-11de-8d1d-001e0bcde3ec}.TxR.1.regtrans-ms) -- C:\Users\Μαριαμ\NTUSER.DAT{016888bc-6c6f-11de-8d1d-001e0bcde3ec}.TxR.1.regtrans-ms
[2013/06/01 09:51:36 | 001,048,576 | -HS- | M] ()(C:\Users\?a??aµ\NTUSER.DAT{016888bc-6c6f-11de-8d1d-001e0bcde3ec}.TxR.0.regtrans-ms) -- C:\Users\Μαριαμ\NTUSER.DAT{016888bc-6c6f-11de-8d1d-001e0bcde3ec}.TxR.0.regtrans-ms
[2013/06/01 09:51:36 | 001,048,576 | -HS- | C] ()(C:\Users\?a??aµ\NTUSER.DAT{016888bc-6c6f-11de-8d1d-001e0bcde3ec}.TxR.2.regtrans-ms) -- C:\Users\Μαριαμ\NTUSER.DAT{016888bc-6c6f-11de-8d1d-001e0bcde3ec}.TxR.2.regtrans-ms
[2013/06/01 09:51:36 | 001,048,576 | -HS- | C] ()(C:\Users\?a??aµ\NTUSER.DAT{016888bc-6c6f-11de-8d1d-001e0bcde3ec}.TxR.1.regtrans-ms) -- C:\Users\Μαριαμ\NTUSER.DAT{016888bc-6c6f-11de-8d1d-001e0bcde3ec}.TxR.1.regtrans-ms
[2013/06/01 09:51:36 | 001,048,576 | -HS- | C] ()(C:\Users\?a??aµ\NTUSER.DAT{016888bc-6c6f-11de-8d1d-001e0bcde3ec}.TxR.0.regtrans-ms) -- C:\Users\Μαριαμ\NTUSER.DAT{016888bc-6c6f-11de-8d1d-001e0bcde3ec}.TxR.0.regtrans-ms
[2013/06/01 09:51:36 | 000,262,144 | -HS- | M] ()(C:\Users\?a??aµ\ntuser.dat.LOG2) -- C:\Users\Μαριαμ\ntuser.dat.LOG2
[2013/06/01 09:51:36 | 000,065,536 | -HS- | M] ()(C:\Users\?a??aµ\NTUSER.DAT{016888bc-6c6f-11de-8d1d-001e0bcde3ec}.TxR.blf) -- C:\Users\Μαριαμ\NTUSER.DAT{016888bc-6c6f-11de-8d1d-001e0bcde3ec}.TxR.blf
[2013/06/01 09:51:36 | 000,065,536 | -HS- | C] ()(C:\Users\?a??aµ\NTUSER.DAT{016888bc-6c6f-11de-8d1d-001e0bcde3ec}.TxR.blf) -- C:\Users\Μαριαμ\NTUSER.DAT{016888bc-6c6f-11de-8d1d-001e0bcde3ec}.TxR.blf
[2013/05/17 18:40:55 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\{57E7C397-FA3E-4479-8A07-9BB9B9DF56D3}) -- C:\Users\Μαριαμ\AppData\Local\{57E7C397-FA3E-4479-8A07-9BB9B9DF56D3}
[2013/05/17 18:40:55 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\{57E7C397-FA3E-4479-8A07-9BB9B9DF56D3}) -- C:\Users\Μαριαμ\AppData\Local\{57E7C397-FA3E-4479-8A07-9BB9B9DF56D3}
[2013/05/17 17:39:01 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\{4DDC82B0-C6E4-40E1-8ED8-677F7A41B25A}) -- C:\Users\Μαριαμ\AppData\Local\{4DDC82B0-C6E4-40E1-8ED8-677F7A41B25A}
[2013/05/17 17:39:01 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\{4DDC82B0-C6E4-40E1-8ED8-677F7A41B25A}) -- C:\Users\Μαριαμ\AppData\Local\{4DDC82B0-C6E4-40E1-8ED8-677F7A41B25A}
[2013/05/13 16:31:53 | 000,038,927 | ---- | M] ()(C:\Users\?a??aµ\Documents\?? ?????? µp????? ?a a???????.docx) -- C:\Users\Μαριαμ\Documents\Οι Μοχλοί μπορούν να αλλάξουν.docx
[2013/05/13 16:31:52 | 000,038,927 | ---- | C] ()(C:\Users\?a??aµ\Documents\?? ?????? µp????? ?a a???????.docx) -- C:\Users\Μαριαμ\Documents\Οι Μοχλοί μπορούν να αλλάξουν.docx
[2013/05/08 18:32:29 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\ElevatedDiagnostics) -- C:\Users\Μαριαμ\AppData\Local\ElevatedDiagnostics
[2013/05/08 18:32:29 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\ElevatedDiagnostics) -- C:\Users\Μαριαμ\AppData\Local\ElevatedDiagnostics
[2013/05/07 22:19:09 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\Microsoft) -- C:\Users\Μαριαμ\AppData\Local\Microsoft
[2013/05/07 22:19:09 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\Microsoft) -- C:\Users\Μαριαμ\AppData\Local\Microsoft
[2013/05/07 21:21:44 | 000,001,251 | ---- | M] ()(C:\Users\?a??aµ\Desktop\YTD Video Downloader.lnk) -- C:\Users\Μαριαμ\Desktop\YTD Video Downloader.lnk
[2013/05/07 21:21:44 | 000,001,251 | ---- | C] ()(C:\Users\?a??aµ\Desktop\YTD Video Downloader.lnk) -- C:\Users\Μαριαμ\Desktop\YTD Video Downloader.lnk
[2013/05/06 10:59:15 | 000,012,529 | ---- | M] ()(C:\Users\?a??aµ\Documents\Stellashell2.docx) -- C:\Users\Μαριαμ\Documents\Stellashell2.docx
[2013/05/06 10:59:14 | 000,012,529 | ---- | C] ()(C:\Users\?a??aµ\Documents\Stellashell2.docx) -- C:\Users\Μαριαμ\Documents\Stellashell2.docx
[2013/05/04 18:21:20 | 000,012,537 | ---- | M] ()(C:\Users\?a??aµ\Documents\rozishell.docx) -- C:\Users\Μαριαμ\Documents\rozishell.docx
[2013/05/04 18:21:19 | 000,012,537 | ---- | C] ()(C:\Users\?a??aµ\Documents\rozishell.docx) -- C:\Users\Μαριαμ\Documents\rozishell.docx
[2013/04/26 18:08:01 | 000,000,162 | -H-- | M] ()(C:\Users\?a??aµ\Documents\~$a?a??a.docx) -- C:\Users\Μαριαμ\Documents\~$αναγία.docx
[2013/04/26 18:08:01 | 000,000,162 | -H-- | C] ()(C:\Users\?a??aµ\Documents\~$a?a??a.docx) -- C:\Users\Μαριαμ\Documents\~$αναγία.docx
[2013/04/26 18:06:11 | 000,011,874 | ---- | M] ()(C:\Users\?a??aµ\Documents\My Movie.wlmp) -- C:\Users\Μαριαμ\Documents\My Movie.wlmp
[2013/04/26 18:05:03 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\{198F7432-6FBF-418A-91C9-59B5B2CC0D20}) -- C:\Users\Μαριαμ\AppData\Local\{198F7432-6FBF-418A-91C9-59B5B2CC0D20}
[2013/04/26 18:05:03 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\{198F7432-6FBF-418A-91C9-59B5B2CC0D20}) -- C:\Users\Μαριαμ\AppData\Local\{198F7432-6FBF-418A-91C9-59B5B2CC0D20}
[2013/04/21 20:35:42 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\{E70A5469-8500-4998-B521-5E025FD6AD3A}) -- C:\Users\Μαριαμ\AppData\Local\{E70A5469-8500-4998-B521-5E025FD6AD3A}
[2013/04/21 20:35:42 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\{E70A5469-8500-4998-B521-5E025FD6AD3A}) -- C:\Users\Μαριαμ\AppData\Local\{E70A5469-8500-4998-B521-5E025FD6AD3A}
[2013/04/21 20:23:38 | 000,000,000 | ---D | M](C:\Users\?a??aµ\Desktop\SMURFS) -- C:\Users\Μαριαμ\Desktop\SMURFS
[2013/04/21 20:23:38 | 000,000,000 | ---D | C](C:\Users\?a??aµ\Desktop\SMURFS) -- C:\Users\Μαριαμ\Desktop\SMURFS
[2013/04/19 21:01:37 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\WildTangentv1000) -- C:\Users\Μαριαμ\AppData\Roaming\WildTangentv1000
[2013/04/19 21:01:37 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\WildTangentv1000) -- C:\Users\Μαριαμ\AppData\Roaming\WildTangentv1000
[2013/04/16 17:51:18 | 000,447,891 | ---- | M] ()(C:\Users\?a??aµ\Documents\Doc9.docx) -- C:\Users\Μαριαμ\Documents\Doc9.docx
[2013/04/16 17:47:36 | 000,128,470 | ---- | M] ()(C:\Users\?a??aµ\Documents\Doc7.docx) -- C:\Users\Μαριαμ\Documents\Doc7.docx
[2013/04/14 19:52:24 | 000,128,449 | ---- | M] ()(C:\Users\?a??aµ\Documents\Doc8.docx) -- C:\Users\Μαριαμ\Documents\Doc8.docx
[2013/04/14 19:47:12 | 000,447,891 | ---- | C] ()(C:\Users\?a??aµ\Documents\Doc9.docx) -- C:\Users\Μαριαμ\Documents\Doc9.docx
[2013/04/14 19:44:21 | 000,164,235 | ---- | M] ()(C:\Users\?a??aµ\Documents\Doc6.docx) -- C:\Users\Μαριαμ\Documents\Doc6.docx
[2013/04/14 19:43:49 | 000,128,449 | ---- | C] ()(C:\Users\?a??aµ\Documents\Doc8.docx) -- C:\Users\Μαριαμ\Documents\Doc8.docx
[2013/04/14 19:30:36 | 000,128,470 | ---- | C] ()(C:\Users\?a??aµ\Documents\Doc7.docx) -- C:\Users\Μαριαμ\Documents\Doc7.docx
[2013/04/14 19:22:27 | 000,164,235 | ---- | C] ()(C:\Users\?a??aµ\Documents\Doc6.docx) -- C:\Users\Μαριαμ\Documents\Doc6.docx
[2013/04/14 18:59:59 | 000,075,656 | ---- | M] ()(C:\Users\?a??aµ\AppData\Local\GDIPFONTCACHEV1.DAT) -- C:\Users\Μαριαμ\AppData\Local\GDIPFONTCACHEV1.DAT
[2013/04/14 11:14:08 | 000,140,800 | ---- | M] ()(C:\Users\?a??aµ\Documents\55lysi_provlimatos.doc) -- C:\Users\Μαριαμ\Documents\55lysi_provlimatos.doc
[2013/04/14 11:14:07 | 000,140,800 | ---- | C] ()(C:\Users\?a??aµ\Documents\55lysi_provlimatos.doc) -- C:\Users\Μαριαμ\Documents\55lysi_provlimatos.doc
[2013/04/14 11:07:11 | 000,086,528 | ---- | M] ()(C:\Users\?a??aµ\Documents\55epanalipsi_axiologisi.doc) -- C:\Users\Μαριαμ\Documents\55epanalipsi_axiologisi.doc
[2013/04/14 11:07:10 | 000,086,528 | ---- | C] ()(C:\Users\?a??aµ\Documents\55epanalipsi_axiologisi.doc) -- C:\Users\Μαριαμ\Documents\55epanalipsi_axiologisi.doc
[2013/04/12 21:27:13 | 000,024,244 | ---- | M] ()(C:\Users\?a??aµ\Documents\G?a ?.docx) -- C:\Users\Μαριαμ\Documents\Για ό.docx
[2013/04/12 15:52:42 | 000,012,544 | ---- | M] ()(C:\Users\?a??aµ\Documents\OFACOA2654.docx) -- C:\Users\Μαριαμ\Documents\OFACOA2654.docx
[2013/04/12 15:52:41 | 000,012,544 | ---- | C] ()(C:\Users\?a??aµ\Documents\OFACOA2654.docx) -- C:\Users\Μαριαμ\Documents\OFACOA2654.docx
[2013/04/11 18:14:39 | 000,024,244 | ---- | C] ()(C:\Users\?a??aµ\Documents\G?a ?.docx) -- C:\Users\Μαριαμ\Documents\Για ό.docx
[2013/04/09 15:50:46 | 000,000,000 | R--D | M](C:\Users\?a??aµ\Desktop\MARIAM  TOMA) -- C:\Users\Μαριαμ\Desktop\MARIAM  TOMA
[2013/04/09 15:50:35 | 000,000,000 | R--D | C](C:\Users\?a??aµ\Desktop\MARIAM  TOMA) -- C:\Users\Μαριαμ\Desktop\MARIAM  TOMA
[2013/04/08 21:44:41 | 000,106,380 | ---- | M] ()(C:\Users\?a??aµ\Documents\?a?a??a.docx) -- C:\Users\Μαριαμ\Documents\Παναγία.docx
[2013/04/08 21:44:41 | 000,106,380 | ---- | C] ()(C:\Users\?a??aµ\Documents\?a?a??a.docx) -- C:\Users\Μαριαμ\Documents\Παναγία.docx
[2013/04/08 19:41:41 | 000,580,051 | ---- | M] ()(C:\Users\?a??aµ\Documents\? ??h.docx) -- C:\Users\Μαριαμ\Documents\Η ζωh.docx
[2013/04/08 19:41:37 | 000,580,051 | ---- | C] ()(C:\Users\?a??aµ\Documents\? ??h.docx) -- C:\Users\Μαριαμ\Documents\Η ζωh.docx
[2013/04/07 12:33:06 | 000,000,000 | R--D | M](C:\Users\?a??aµ\Desktop\MySyncUPFiles) -- C:\Users\Μαριαμ\Desktop\MySyncUPFiles
[2013/04/07 12:33:06 | 000,000,000 | R--D | C](C:\Users\?a??aµ\Desktop\MySyncUPFiles) -- C:\Users\Μαριαμ\Desktop\MySyncUPFiles
[2013/04/06 21:43:10 | 000,000,000 | R--D | C](C:\Users\?a??aµ\Desktop\MARIAM   TOMA   E  TA?? ??? F???S) -- C:\Users\Μαριαμ\Desktop\MARIAM   TOMA   E  TAΞΗ ΚΑΙ ΦΙΛΕΣ
[2013/04/06 21:35:19 | 000,000,000 | --SD | M](C:\Users\?a??aµ\Documents\My Data Sources) -- C:\Users\Μαριαμ\Documents\My Data Sources
[2013/04/06 21:28:57 | 000,450,951 | ---- | M] ()(C:\Users\?a??aµ\Documents\20.docx) -- C:\Users\Μαριαμ\Documents\20.docx
[2013/04/06 21:22:39 | 000,020,014 | ---- | M] ()(C:\Users\?a??aµ\Documents\Doc5.docx) -- C:\Users\Μαριαμ\Documents\Doc5.docx
[2013/04/05 20:51:03 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\IDT) -- C:\Users\Μαριαμ\AppData\Roaming\IDT
[2013/04/05 20:51:03 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\IDT) -- C:\Users\Μαριαμ\AppData\Roaming\IDT
[2013/04/05 16:18:39 | 000,020,014 | ---- | C] ()(C:\Users\?a??aµ\Documents\Doc5.docx) -- C:\Users\Μαριαμ\Documents\Doc5.docx
[2013/04/03 18:10:24 | 000,000,000 | --SD | M](C:\Users\?a??aµ\AppData\Roaming\Microsoft) -- C:\Users\Μαριαμ\AppData\Roaming\Microsoft
[2013/04/03 18:10:24 | 000,000,000 | --SD | M](C:\Users\?a??aµ\AppData\Roaming\Microsoft) -- C:\Users\Μαριαμ\AppData\Roaming\Microsoft
[2013/04/02 16:35:39 | 000,040,960 | ---- | M] ()(C:\Users\?a??aµ\Documents\Axiologisi-Vretania(2).doc) -- C:\Users\Μαριαμ\Documents\Axiologisi-Vretania(2).doc
[2013/04/02 15:31:20 | 000,030,208 | ---- | M] ()(C:\Users\?a??aµ\Documents\Axiologisi-Vretania(1).doc) -- C:\Users\Μαριαμ\Documents\Axiologisi-Vretania(1).doc
[2013/04/02 15:18:53 | 000,030,208 | ---- | C] ()(C:\Users\?a??aµ\Documents\Axiologisi-Vretania(1).doc) -- C:\Users\Μαριαμ\Documents\Axiologisi-Vretania(1).doc
[2013/04/02 15:18:23 | 000,040,960 | ---- | C] ()(C:\Users\?a??aµ\Documents\Axiologisi-Vretania(2).doc) -- C:\Users\Μαριαμ\Documents\Axiologisi-Vretania(2).doc
[2013/03/26 18:11:50 | 000,000,000 | ---D | M](C:\Users\?a??aµ\SyncUP) -- C:\Users\Μαριαμ\SyncUP
[2013/03/26 18:11:50 | 000,000,000 | ---D | M](C:\Users\?a??aµ\SyncUP) -- C:\Users\Μαριαμ\SyncUP
[2013/03/26 17:03:12 | 000,633,287 | ---- | C] ()(C:\Users\?a??aµ\Documents\S1000004 - Copy (3) - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000004 - Copy (3) - Copy - Copy.JPG
[2013/03/26 17:03:12 | 000,633,287 | ---- | C] ()(C:\Users\?a??aµ\Documents\S1000004 - Copy (2) - Copy - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000004 - Copy (2) - Copy - Copy - Copy.JPG
[2013/03/26 17:03:12 | 000,633,287 | ---- | C] ()(C:\Users\?a??aµ\Documents\S1000004 - Copy - Copy - Copy (2) - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000004 - Copy - Copy - Copy (2) - Copy.JPG
[2013/03/26 17:03:12 | 000,633,287 | ---- | C] ()(C:\Users\?a??aµ\Documents\S1000004 - Copy - Copy - Copy - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000004 - Copy - Copy - Copy - Copy - Copy.JPG
[2013/03/26 17:03:12 | 000,624,763 | ---- | C] ()(C:\Users\?a??aµ\Documents\S1000010 - Copy - Copy - Copy - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000010 - Copy - Copy - Copy - Copy - Copy.JPG
[2013/03/26 17:03:12 | 000,599,763 | ---- | C] ()(C:\Users\?a??aµ\Documents\S1000003 - Copy (3) - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000003 - Copy (3) - Copy.JPG
[2013/03/26 17:03:12 | 000,599,763 | ---- | C] ()(C:\Users\?a??aµ\Documents\S1000003 - Copy (2) - Copy - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000003 - Copy (2) - Copy - Copy - Copy.JPG
[2013/03/26 17:03:12 | 000,599,763 | ---- | C] ()(C:\Users\?a??aµ\Documents\S1000003 - Copy - Copy - Copy - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000003 - Copy - Copy - Copy - Copy - Copy.JPG
[2013/03/26 17:03:12 | 000,591,306 | ---- | C] ()(C:\Users\?a??aµ\Documents\S1000001 - Copy (3) - Copy - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000001 - Copy (3) - Copy - Copy - Copy.JPG
[2013/03/26 17:03:12 | 000,591,306 | ---- | C] ()(C:\Users\?a??aµ\Documents\S1000001 - Copy (2) - Copy - Copy - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000001 - Copy (2) - Copy - Copy - Copy - Copy.JPG
[2013/03/26 17:03:12 | 000,591,306 | ---- | C] ()(C:\Users\?a??aµ\Documents\S1000001 - Copy - Copy - Copy - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000001 - Copy - Copy - Copy - Copy - Copy.JPG
[2013/03/26 17:03:12 | 000,591,271 | ---- | C] ()(C:\Users\?a??aµ\Documents\S1000002 - Copy (2) - Copy - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000002 - Copy (2) - Copy - Copy - Copy.JPG
[2013/03/26 17:03:12 | 000,591,271 | ---- | C] ()(C:\Users\?a??aµ\Documents\S1000002 - Copy - Copy (2) - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000002 - Copy - Copy (2) - Copy.JPG
[2013/03/26 17:03:12 | 000,591,271 | ---- | C] ()(C:\Users\?a??aµ\Documents\S1000002 - Copy - Copy - Copy - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000002 - Copy - Copy - Copy - Copy - Copy.JPG
[2013/03/26 17:03:12 | 000,583,853 | ---- | C] ()(C:\Users\?a??aµ\Documents\S1000007 - Copy (2) - Copy - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000007 - Copy (2) - Copy - Copy - Copy.JPG
[2013/03/26 17:03:12 | 000,583,853 | ---- | C] ()(C:\Users\?a??aµ\Documents\S1000007 - Copy - Copy (2) - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000007 - Copy - Copy (2) - Copy - Copy.JPG
[2013/03/26 17:03:12 | 000,583,853 | ---- | C] ()(C:\Users\?a??aµ\Documents\S1000007 - Copy - Copy - Copy - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000007 - Copy - Copy - Copy - Copy - Copy.JPG
[2013/03/26 17:03:12 | 000,581,903 | ---- | C] ()(C:\Users\?a??aµ\Documents\S1000008 - Copy (3) - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000008 - Copy (3) - Copy - Copy.JPG
[2013/03/26 17:03:12 | 000,581,903 | ---- | C] ()(C:\Users\?a??aµ\Documents\S1000008 - Copy (2) - Copy - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000008 - Copy (2) - Copy - Copy - Copy.JPG
[2013/03/26 17:03:12 | 000,581,903 | ---- | C] ()(C:\Users\?a??aµ\Documents\S1000008 - Copy - Copy (2) - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000008 - Copy - Copy (2) - Copy - Copy.JPG
[2013/03/26 17:03:12 | 000,581,903 | ---- | C] ()(C:\Users\?a??aµ\Documents\S1000008 - Copy - Copy - Copy - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000008 - Copy - Copy - Copy - Copy - Copy.JPG
[2013/03/26 17:03:12 | 000,578,239 | ---- | C] ()(C:\Users\?a??aµ\Documents\S1000009 - Copy - Copy - Copy - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000009 - Copy - Copy - Copy - Copy - Copy.JPG
[2013/03/26 17:03:12 | 000,562,137 | ---- | C] ()(C:\Users\?a??aµ\Documents\S1000005 - Copy (2) - Copy - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000005 - Copy (2) - Copy - Copy - Copy.JPG
[2013/03/26 17:03:12 | 000,562,137 | ---- | C] ()(C:\Users\?a??aµ\Documents\S1000005 - Copy - Copy - Copy - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000005 - Copy - Copy - Copy - Copy - Copy.JPG
[2013/03/26 17:03:12 | 000,556,547 | ---- | C] ()(C:\Users\?a??aµ\Documents\S1000017 - Copy - Copy - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000017 - Copy - Copy - Copy - Copy.JPG
[2013/03/26 17:03:12 | 000,547,345 | ---- | C] ()(C:\Users\?a??aµ\Documents\S1000014 - Copy - Copy - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000014 - Copy - Copy - Copy - Copy.JPG
[2013/03/26 17:03:08 | 000,591,271 | ---- | C] ()(C:\Users\?a??aµ\Documents\S1000002 - Copy - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000002 - Copy - Copy - Copy.JPG
[2013/03/24 13:24:56 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\{7BB71E01-FC17-4CE7-B52E-6B54B9E2DD18}) -- C:\Users\Μαριαμ\AppData\Local\{7BB71E01-FC17-4CE7-B52E-6B54B9E2DD18}
[2013/03/24 13:24:56 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\{7BB71E01-FC17-4CE7-B52E-6B54B9E2DD18}) -- C:\Users\Μαριαμ\AppData\Local\{7BB71E01-FC17-4CE7-B52E-6B54B9E2DD18}
[2013/03/23 19:02:37 | 000,184,579 | ---- | M] ()(C:\Users\?a??aµ\Documents\Untitled (2).wma) -- C:\Users\Μαριαμ\Documents\Untitled (2).wma
[2013/03/23 19:02:37 | 000,184,579 | ---- | C] ()(C:\Users\?a??aµ\Documents\Untitled (2).wma) -- C:\Users\Μαριαμ\Documents\Untitled (2).wma
[2013/03/17 17:19:21 | 000,718,889 | ---- | M] ()(C:\Users\?a??aµ\Documents\Untitled.wma) -- C:\Users\Μαριαμ\Documents\Untitled.wma
[2013/03/17 17:19:21 | 000,718,889 | ---- | C] ()(C:\Users\?a??aµ\Documents\Untitled.wma) -- C:\Users\Μαριαμ\Documents\Untitled.wma
[2013/03/17 17:17:43 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\{F56B3EA2-5A4F-45B7-92C1-D9AC07709BE0}) -- C:\Users\Μαριαμ\AppData\Local\{F56B3EA2-5A4F-45B7-92C1-D9AC07709BE0}
[2013/03/17 17:17:43 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\{F56B3EA2-5A4F-45B7-92C1-D9AC07709BE0}) -- C:\Users\Μαριαμ\AppData\Local\{F56B3EA2-5A4F-45B7-92C1-D9AC07709BE0}
[2013/03/17 17:17:31 | 000,000,000 | ---D | M](C:\Users\?a??aµ\Documents\My Weblog Posts) -- C:\Users\Μαριαμ\Documents\My Weblog Posts
[2013/03/17 17:17:31 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\Windows Live Writer) -- C:\Users\Μαριαμ\AppData\Local\Windows Live Writer
[2013/03/17 17:17:31 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\Windows Live Writer) -- C:\Users\Μαριαμ\AppData\Local\Windows Live Writer
[2013/03/17 17:17:31 | 000,000,000 | ---D | C](C:\Users\?a??aµ\Documents\My Weblog Posts) -- C:\Users\Μαριαμ\Documents\My Weblog Posts
[2013/03/15 12:03:14 | 000,556,547 | ---- | M] ()(C:\Users\?a??aµ\Documents\S1000017 - Copy - Copy - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000017 - Copy - Copy - Copy - Copy.JPG
[2013/03/15 11:52:18 | 000,547,345 | ---- | M] ()(C:\Users\?a??aµ\Documents\S1000014 - Copy - Copy - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000014 - Copy - Copy - Copy - Copy.JPG
[2013/03/15 11:41:22 | 000,624,763 | ---- | M] ()(C:\Users\?a??aµ\Documents\S1000010 - Copy - Copy - Copy - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000010 - Copy - Copy - Copy - Copy - Copy.JPG
[2013/03/15 11:40:50 | 000,578,239 | ---- | M] ()(C:\Users\?a??aµ\Documents\S1000009 - Copy - Copy - Copy - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000009 - Copy - Copy - Copy - Copy - Copy.JPG
[2013/03/15 11:40:36 | 000,581,903 | ---- | M] ()(C:\Users\?a??aµ\Documents\S1000008 - Copy (3) - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000008 - Copy (3) - Copy - Copy.JPG
[2013/03/15 11:40:36 | 000,581,903 | ---- | M] ()(C:\Users\?a??aµ\Documents\S1000008 - Copy (2) - Copy - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000008 - Copy (2) - Copy - Copy - Copy.JPG
[2013/03/15 11:40:36 | 000,581,903 | ---- | M] ()(C:\Users\?a??aµ\Documents\S1000008 - Copy - Copy (2) - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000008 - Copy - Copy (2) - Copy - Copy.JPG
[2013/03/15 11:40:36 | 000,581,903 | ---- | M] ()(C:\Users\?a??aµ\Documents\S1000008 - Copy - Copy - Copy - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000008 - Copy - Copy - Copy - Copy - Copy.JPG
[2013/03/15 11:40:06 | 000,583,853 | ---- | M] ()(C:\Users\?a??aµ\Documents\S1000007 - Copy (2) - Copy - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000007 - Copy (2) - Copy - Copy - Copy.JPG
[2013/03/15 11:40:06 | 000,583,853 | ---- | M] ()(C:\Users\?a??aµ\Documents\S1000007 - Copy - Copy (2) - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000007 - Copy - Copy (2) - Copy - Copy.JPG
[2013/03/15 11:40:06 | 000,583,853 | ---- | M] ()(C:\Users\?a??aµ\Documents\S1000007 - Copy - Copy - Copy - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000007 - Copy - Copy - Copy - Copy - Copy.JPG
[2013/03/15 11:37:04 | 000,562,137 | ---- | M] ()(C:\Users\?a??aµ\Documents\S1000005 - Copy (2) - Copy - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000005 - Copy (2) - Copy - Copy - Copy.JPG
[2013/03/15 11:37:04 | 000,562,137 | ---- | M] ()(C:\Users\?a??aµ\Documents\S1000005 - Copy - Copy - Copy - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000005 - Copy - Copy - Copy - Copy - Copy.JPG
[2013/03/15 11:35:38 | 000,633,287 | ---- | M] ()(C:\Users\?a??aµ\Documents\S1000004 - Copy (3) - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000004 - Copy (3) - Copy - Copy.JPG
[2013/03/15 11:35:38 | 000,633,287 | ---- | M] ()(C:\Users\?a??aµ\Documents\S1000004 - Copy (2) - Copy - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000004 - Copy (2) - Copy - Copy - Copy.JPG
[2013/03/15 11:35:38 | 000,633,287 | ---- | M] ()(C:\Users\?a??aµ\Documents\S1000004 - Copy - Copy - Copy (2) - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000004 - Copy - Copy - Copy (2) - Copy.JPG
[2013/03/15 11:35:38 | 000,633,287 | ---- | M] ()(C:\Users\?a??aµ\Documents\S1000004 - Copy - Copy - Copy - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000004 - Copy - Copy - Copy - Copy - Copy.JPG
[2013/03/15 11:34:48 | 000,599,763 | ---- | M] ()(C:\Users\?a??aµ\Documents\S1000003 - Copy (3) - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000003 - Copy (3) - Copy.JPG
[2013/03/15 11:34:48 | 000,599,763 | ---- | M] ()(C:\Users\?a??aµ\Documents\S1000003 - Copy (2) - Copy - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000003 - Copy (2) - Copy - Copy - Copy.JPG
[2013/03/15 11:34:48 | 000,599,763 | ---- | M] ()(C:\Users\?a??aµ\Documents\S1000003 - Copy - Copy - Copy - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000003 - Copy - Copy - Copy - Copy - Copy.JPG
[2013/03/15 11:34:20 | 000,591,271 | ---- | M] ()(C:\Users\?a??aµ\Documents\S1000002 - Copy (2) - Copy - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000002 - Copy (2) - Copy - Copy - Copy.JPG
[2013/03/15 11:34:20 | 000,591,271 | ---- | M] ()(C:\Users\?a??aµ\Documents\S1000002 - Copy - Copy (2) - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000002 - Copy - Copy (2) - Copy.JPG
[2013/03/15 11:34:20 | 000,591,271 | ---- | M] ()(C:\Users\?a??aµ\Documents\S1000002 - Copy - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000002 - Copy - Copy - Copy.JPG
[2013/03/15 11:34:20 | 000,591,271 | ---- | M] ()(C:\Users\?a??aµ\Documents\S1000002 - Copy - Copy - Copy - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000002 - Copy - Copy - Copy - Copy - Copy.JPG
[2013/03/15 11:33:56 | 000,591,306 | ---- | M] ()(C:\Users\?a??aµ\Documents\S1000001 - Copy (3) - Copy - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000001 - Copy (3) - Copy - Copy - Copy.JPG
[2013/03/15 11:33:56 | 000,591,306 | ---- | M] ()(C:\Users\?a??aµ\Documents\S1000001 - Copy (2) - Copy - Copy - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000001 - Copy (2) - Copy - Copy - Copy - Copy.JPG
[2013/03/15 11:33:56 | 000,591,306 | ---- | M] ()(C:\Users\?a??aµ\Documents\S1000001 - Copy - Copy - Copy - Copy - Copy.JPG) -- C:\Users\Μαριαμ\Documents\S1000001 - Copy - Copy - Copy - Copy - Copy.JPG
[2013/03/08 21:48:12 | 000,011,874 | ---- | C] ()(C:\Users\?a??aµ\Documents\My Movie.wlmp) -- C:\Users\Μαριαμ\Documents\My Movie.wlmp
[2013/03/08 21:47:40 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\{69369693-B309-4230-AAB3-41E38EFBD614}) -- C:\Users\Μαριαμ\AppData\Local\{69369693-B309-4230-AAB3-41E38EFBD614}
[2013/03/08 21:47:40 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\{69369693-B309-4230-AAB3-41E38EFBD614}) -- C:\Users\Μαριαμ\AppData\Local\{69369693-B309-4230-AAB3-41E38EFBD614}
[2013/03/08 21:44:59 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\{54BA7F56-3060-48A1-8208-A3453C61A7BE}) -- C:\Users\Μαριαμ\AppData\Local\{54BA7F56-3060-48A1-8208-A3453C61A7BE}
[2013/03/08 21:44:59 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\{54BA7F56-3060-48A1-8208-A3453C61A7BE}) -- C:\Users\Μαριαμ\AppData\Local\{54BA7F56-3060-48A1-8208-A3453C61A7BE}
[2013/03/05 20:17:51 | 000,050,872 | ---- | M] ()(C:\Users\?a??aµ\Documents\MARIAM     AND     MARISSA.docx) -- C:\Users\Μαριαμ\Documents\MARIAM     AND     MARISSA.docx
[2013/03/04 22:56:14 | 000,050,872 | ---- | C] ()(C:\Users\?a??aµ\Documents\MARIAM     AND     MARISSA.docx) -- C:\Users\Μαριαμ\Documents\MARIAM     AND     MARISSA.docx
[2013/03/03 18:02:58 | 000,124,725 | ---- | M] ()(C:\Users\?a??aµ\Documents\G?ß?a?t??.docx) -- C:\Users\Μαριαμ\Documents\Γιβραλτάρ.docx
[2013/03/03 17:59:27 | 001,050,136 | ---- | M] ()(C:\Users\?a??aµ\Documents\Wiki Home.docx) -- C:\Users\Μαριαμ\Documents\Wiki Home.docx
[2013/03/03 17:56:16 | 000,384,321 | ---- | M] ()(C:\Users\?a??aµ\Documents\???p???? ??????a?.docx) -- C:\Users\Μαριαμ\Documents\Τροπικός κυκλώνας.docx
[2013/03/03 17:53:34 | 000,042,735 | ---- | M] ()(C:\Users\?a??aµ\Documents\????? ß???? ???µ??eta? t? fa???µe?? t?? as?????sta ?????? µete?????????? ?ata???µ??sµ?t??.docx) -- C:\Users\Μαριαμ\Documents\Όξινη βροχή ονομάζεται το φαινόμενο των ασυνήθιστα όξινων μετεωρολογικών κατακρημνισμάτων.docx
[2013/03/03 17:52:26 | 000,039,782 | ---- | M] ()(C:\Users\?a??aµ\Documents\? ???e???? ???t?? st?? a??a??t?ta ?a? ? s?et??? ep?st?µ????? ??e??a.docx) -- C:\Users\Μαριαμ\Documents\Ο Εύξεινος Πόντος στην αρχαίοτητα και η σχετική επιστημονική έρευνα.docx
[2013/03/01 20:09:25 | 000,012,579 | ---- | M] ()(C:\Users\?a??aµ\Documents\Mima2345.docx) -- C:\Users\Μαριαμ\Documents\Mima2345.docx
[2013/03/01 20:08:43 | 000,012,579 | ---- | C] ()(C:\Users\?a??aµ\Documents\Mima2345.docx) -- C:\Users\Μαριαμ\Documents\Mima2345.docx
[2013/02/08 17:16:04 | 000,000,000 | ---D | M](C:\Users\?a??aµ\Documents\Blio) -- C:\Users\Μαριαμ\Documents\Blio
[2013/02/01 16:28:01 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\VirtualStore) -- C:\Users\Μαριαμ\AppData\Local\VirtualStore
[2013/02/01 16:28:01 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\VirtualStore) -- C:\Users\Μαριαμ\AppData\Local\VirtualStore
[2013/01/27 18:55:07 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\{A2AD4592-2474-4F8E-BBBC-1B3ECA2E02A5}) -- C:\Users\Μαριαμ\AppData\Local\{A2AD4592-2474-4F8E-BBBC-1B3ECA2E02A5}
[2013/01/27 18:55:07 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\{A2AD4592-2474-4F8E-BBBC-1B3ECA2E02A5}) -- C:\Users\Μαριαμ\AppData\Local\{A2AD4592-2474-4F8E-BBBC-1B3ECA2E02A5}
[2013/01/25 18:24:17 | 000,355,055 | ---- | M] ()(C:\Users\?a??aµ\Documents\mariam.docx) -- C:\Users\Μαριαμ\Documents\mariam.docx
[2013/01/25 18:24:16 | 000,355,055 | ---- | C] ()(C:\Users\?a??aµ\Documents\mariam.docx) -- C:\Users\Μαριαμ\Documents\mariam.docx
[2013/01/24 18:14:04 | 000,015,089 | ---- | C] ()(C:\Users\?a??aµ\Documents\S?? ?a???? t? fe????? ??a s?µpa? ?a ?e?? - Copy.docx) -- C:\Users\Μαριαμ\Documents\Σου χαρίζω το φεγγάρι ένα σύμπαν θα χεις - Copy.docx
[2013/01/21 20:28:24 | 000,074,398 | ---- | M] ()(C:\Users\?a??aµ\Documents\Doc4.docx) -- C:\Users\Μαριαμ\Documents\Doc4.docx
[2013/01/21 20:28:24 | 000,074,398 | ---- | C] ()(C:\Users\?a??aµ\Documents\Doc4.docx) -- C:\Users\Μαριαμ\Documents\Doc4.docx
[2013/01/21 20:20:41 | 000,450,951 | ---- | C] ()(C:\Users\?a??aµ\Documents\20.docx) -- C:\Users\Μαριαμ\Documents\20.docx
[2013/01/21 17:48:39 | 000,012,514 | ---- | M] ()(C:\Users\?a??aµ\Documents\Doc3.docx) -- C:\Users\Μαριαμ\Documents\Doc3.docx
[2013/01/21 17:48:38 | 000,012,514 | ---- | C] ()(C:\Users\?a??aµ\Documents\Doc3.docx) -- C:\Users\Μαριαμ\Documents\Doc3.docx
[2013/01/17 18:09:08 | 000,050,341 | ---- | M] ()(C:\Users\?a??aµ\Documents\???????.docx) -- C:\Users\Μαριαμ\Documents\γιωργος.docx
[2013/01/17 18:09:08 | 000,050,341 | ---- | C] ()(C:\Users\?a??aµ\Documents\???????.docx) -- C:\Users\Μαριαμ\Documents\γιωργος.docx
[2013/01/17 16:08:14 | 000,016,446 | ---- | M] ()(C:\Users\?a??aµ\Documents\george.docx) -- C:\Users\Μαριαμ\Documents\george.docx
[2013/01/17 16:08:13 | 000,016,446 | ---- | C] ()(C:\Users\?a??aµ\Documents\george.docx) -- C:\Users\Μαριαμ\Documents\george.docx
[2013/01/16 18:07:44 | 000,039,782 | ---- | C] ()(C:\Users\?a??aµ\Documents\? ???e???? ???t?? st?? a??a??t?ta ?a? ? s?et??? ep?st?µ????? ??e??a.docx) -- C:\Users\Μαριαμ\Documents\Ο Εύξεινος Πόντος στην αρχαίοτητα και η σχετική επιστημονική έρευνα.docx
[2013/01/15 17:48:18 | 000,557,056 | ---- | M] ()(C:\Users\?a??aµ\Desktop\e??as?a G?????? ??µa.doc) -- C:\Users\Μαριαμ\Desktop\εργασια Γιώργου Τόμα.doc
[2013/01/15 07:42:36 | 000,557,056 | ---- | C] ()(C:\Users\?a??aµ\Desktop\e??as?a G?????? ??µa.doc) -- C:\Users\Μαριαμ\Desktop\εργασια Γιώργου Τόμα.doc
[2013/01/13 20:08:00 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\Google) -- C:\Users\Μαριαμ\AppData\Roaming\Google
[2013/01/13 20:08:00 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\Google) -- C:\Users\Μαριαμ\AppData\Roaming\Google
[2013/01/13 19:33:48 | 000,124,725 | ---- | C] ()(C:\Users\?a??aµ\Documents\G?ß?a?t??.docx) -- C:\Users\Μαριαμ\Documents\Γιβραλτάρ.docx
[2013/01/11 15:57:20 | 000,031,284 | ---- | M] ()(C:\Users\?a??aµ\Documents\????????s?.docx) -- C:\Users\Μαριαμ\Documents\Αξιολόγηση.docx
[2013/01/11 15:57:19 | 000,031,284 | ---- | C] ()(C:\Users\?a??aµ\Documents\????????s?.docx) -- C:\Users\Μαριαμ\Documents\Αξιολόγηση.docx
[2013/01/11 15:55:25 | 000,198,304 | ---- | M] ()(C:\Users\?a??aµ\Documents\???S????.docx) -- C:\Users\Μαριαμ\Documents\ΕΠΙΣΤΗΜΗ.docx
[2013/01/11 15:55:24 | 000,198,304 | ---- | C] ()(C:\Users\?a??aµ\Documents\???S????.docx) -- C:\Users\Μαριαμ\Documents\ΕΠΙΣΤΗΜΗ.docx
[2013/01/11 15:44:11 | 000,172,847 | ---- | M] ()(C:\Users\?a??aµ\Documents\e?a pe??stat??? st? ?????.docx) -- C:\Users\Μαριαμ\Documents\ενα περιστατικό στο χωριό.docx
[2013/01/10 19:11:47 | 000,161,692 | ---- | M] ()(C:\Users\?a??aµ\Documents\??????? ?e??.docx) -- C:\Users\Μαριαμ\Documents\Ιούλιος Βερν.docx
[2013/01/10 18:22:33 | 000,195,365 | ---- | M] ()(C:\Users\?a??aµ\Documents\S?µ?? ?p???ßa?.docx) -- C:\Users\Μαριαμ\Documents\Σιμόν Μπολίβαρ.docx
[2013/01/09 16:28:23 | 000,036,801 | ---- | M] ()(C:\Users\?a??aµ\Documents\St??? 25 a???e?  megas    alejantros.docx) -- C:\Users\Μαριαμ\Documents\Στους 25 αιώνες  megas    alejantros.docx
[2013/01/09 16:28:22 | 000,036,801 | ---- | C] ()(C:\Users\?a??aµ\Documents\St??? 25 a???e?  megas    alejantros.docx) -- C:\Users\Μαριαμ\Documents\Στους 25 αιώνες  megas    alejantros.docx
[2013/01/09 16:26:37 | 000,195,365 | ---- | C] ()(C:\Users\?a??aµ\Documents\S?µ?? ?p???ßa?.docx) -- C:\Users\Μαριαμ\Documents\Σιμόν Μπολίβαρ.docx
[2013/01/09 16:25:35 | 000,161,692 | ---- | C] ()(C:\Users\?a??aµ\Documents\??????? ?e??.docx) -- C:\Users\Μαριαμ\Documents\Ιούλιος Βερν.docx
[2013/01/09 16:21:11 | 000,037,741 | ---- | M] ()(C:\Users\?a??aµ\Documents\sugrafeas.docx) -- C:\Users\Μαριαμ\Documents\sugrafeas.docx
[2013/01/09 16:21:11 | 000,037,741 | ---- | C] ()(C:\Users\?a??aµ\Documents\sugrafeas.docx) -- C:\Users\Μαριαμ\Documents\sugrafeas.docx
[2013/01/09 16:19:59 | 000,305,101 | ---- | M] ()(C:\Users\?a??aµ\Documents\sygrafeas.docx) -- C:\Users\Μαριαμ\Documents\sygrafeas.docx
[2013/01/09 16:19:59 | 000,305,101 | ---- | C] ()(C:\Users\?a??aµ\Documents\sygrafeas.docx) -- C:\Users\Μαριαμ\Documents\sygrafeas.docx
[2013/01/09 16:07:59 | 000,000,213 | ---- | M] ()(C:\Users\?a??aµ\Desktop\??p??? - ????pa?de?a.url) -- C:\Users\Μαριαμ\Desktop\Κύπρος - Βικιπαίδεια.url
[2013/01/09 16:07:59 | 000,000,213 | ---- | C] ()(C:\Users\?a??aµ\Desktop\??p??? - ????pa?de?a.url) -- C:\Users\Μαριαμ\Desktop\Κύπρος - Βικιπαίδεια.url
[2013/01/08 21:57:51 | 000,097,871 | ---- | M] ()(C:\Users\?a??aµ\Documents\H ????G??? ??? ?? ??S???.docx) -- C:\Users\Μαριαμ\Documents\H ΜΠΟΥΓΑΔΑ ΤΟΥ ΑΙ ΒΑΣΙΛΗ.docx
[2013/01/08 18:46:27 | 000,014,591 | ---- | M] ()(C:\Users\?a??aµ\Documents\Pop star Rihanna releases the son1.docx) -- C:\Users\Μαριαμ\Documents\Pop star Rihanna releases the son1.docx
[2013/01/08 18:46:26 | 000,014,591 | ---- | C] ()(C:\Users\?a??aµ\Documents\Pop star Rihanna releases the son1.docx) -- C:\Users\Μαριαμ\Documents\Pop star Rihanna releases the son1.docx
[2013/01/08 17:54:25 | 000,017,121 | ---- | M] ()(C:\Users\?a??aµ\Documents\Pop star Rihanna releases the song.docx) -- C:\Users\Μαριαμ\Documents\Pop star Rihanna releases the song.docx
[2013/01/08 17:54:25 | 000,017,121 | ---- | C] ()(C:\Users\?a??aµ\Documents\Pop star Rihanna releases the song.docx) -- C:\Users\Μαριαμ\Documents\Pop star Rihanna releases the song.docx
[2013/01/07 18:59:42 | 000,106,819 | ---- | M] ()(C:\Users\?a??aµ\Documents\?????? t?? ??fe?.docx) -- C:\Users\Μαριαμ\Documents\Πύργος του Άιφελ.docx
[2013/01/07 18:37:48 | 000,106,819 | ---- | C] ()(C:\Users\?a??aµ\Documents\?????? t?? ??fe?.docx) -- C:\Users\Μαριαμ\Documents\Πύργος του Άιφελ.docx
[2012/12/21 19:03:37 | 000,097,871 | ---- | C] ()(C:\Users\?a??aµ\Documents\H ????G??? ??? ?? ??S???.docx) -- C:\Users\Μαριαμ\Documents\H ΜΠΟΥΓΑΔΑ ΤΟΥ ΑΙ ΒΑΣΙΛΗ.docx
[2012/12/15 12:44:31 | 000,339,559 | ---- | M] ()(C:\Users\?a??aµ\Documents\?a sp??d???t? ??a st? p???? t?? ??a??ssa?.docx) -- C:\Users\Μαριαμ\Documents\Τα σπονδυλωτά ζώα στο πάρκο της Αθαλάσσας.docx
[2012/12/15 12:42:52 | 000,339,559 | ---- | C] ()(C:\Users\?a??aµ\Documents\?a sp??d???t? ??a st? p???? t?? ??a??ssa?.docx) -- C:\Users\Μαριαμ\Documents\Τα σπονδυλωτά ζώα στο πάρκο της Αθαλάσσας.docx
[2012/12/14 16:07:17 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\Microsoft_Corporation) -- C:\Users\Μαριαμ\AppData\Local\Microsoft_Corporation
[2012/12/14 16:07:17 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\Microsoft_Corporation) -- C:\Users\Μαριαμ\AppData\Local\Microsoft_Corporation
[2012/12/11 21:19:34 | 001,050,136 | ---- | C] ()(C:\Users\?a??aµ\Documents\Wiki Home.docx) -- C:\Users\Μαριαμ\Documents\Wiki Home.docx
[2012/12/10 15:25:21 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\{F8C9425F-0274-482F-ABA0-B4BE76CED672}) -- C:\Users\Μαριαμ\AppData\Local\{F8C9425F-0274-482F-ABA0-B4BE76CED672}
[2012/12/10 15:25:21 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\{F8C9425F-0274-482F-ABA0-B4BE76CED672}) -- C:\Users\Μαριαμ\AppData\Local\{F8C9425F-0274-482F-ABA0-B4BE76CED672}
[2012/12/10 15:25:14 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\{9510853A-7718-45CA-AB77-8D13D479F21E}) -- C:\Users\Μαριαμ\AppData\Local\{9510853A-7718-45CA-AB77-8D13D479F21E}
[2012/12/10 15:25:14 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\{9510853A-7718-45CA-AB77-8D13D479F21E}) -- C:\Users\Μαριαμ\AppData\Local\{9510853A-7718-45CA-AB77-8D13D479F21E}
[2012/12/06 20:21:16 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\Apps) -- C:\Users\Μαριαμ\AppData\Local\Apps
[2012/12/06 20:21:16 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\Apps) -- C:\Users\Μαριαμ\AppData\Local\Apps
[2012/12/02 20:59:29 | 000,100,177 | ---- | M] ()(C:\Users\?a??aµ\Documents\?O? ?S??????? ??? S??????O??.docx) -- C:\Users\Μαριαμ\Documents\ΖΩΑ ΑΣΠΟΝΔΥΛΑ ΚΑΙ ΣΠΟΝΔΥΛΩΤΑ.docx
[2012/12/02 20:59:28 | 000,100,177 | ---- | C] ()(C:\Users\?a??aµ\Documents\?O? ?S??????? ??? S??????O??.docx) -- C:\Users\Μαριαμ\Documents\ΖΩΑ ΑΣΠΟΝΔΥΛΑ ΚΑΙ ΣΠΟΝΔΥΛΩΤΑ.docx
[2012/11/28 17:36:56 | 000,087,840 | ---- | M] ()(C:\Users\?a??aµ\Documents\Doc2.docx) -- C:\Users\Μαριαμ\Documents\Doc2.docx
[2012/11/28 17:36:56 | 000,087,840 | ---- | C] ()(C:\Users\?a??aµ\Documents\Doc2.docx) -- C:\Users\Μαριαμ\Documents\Doc2.docx
[2012/11/28 17:27:54 | 000,025,177 | ---- | M] ()(C:\Users\?a??aµ\Documents\Doc1.docx) -- C:\Users\Μαριαμ\Documents\Doc1.docx
[2012/11/28 17:27:53 | 000,025,177 | ---- | C] ()(C:\Users\?a??aµ\Documents\Doc1.docx) -- C:\Users\Μαριαμ\Documents\Doc1.docx
[2012/11/25 21:02:33 | 000,061,645 | ---- | M] ()(C:\Users\?a??aµ\Documents\?e???ß???.docx) -- C:\Users\Μαριαμ\Documents\Βεζούβιος.docx
[2012/11/25 21:02:33 | 000,061,645 | ---- | C] ()(C:\Users\?a??aµ\Documents\?e???ß???.docx) -- C:\Users\Μαριαμ\Documents\Βεζούβιος.docx
[2012/11/25 20:20:53 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\{6CD4B9DE-3C67-4F06-97E4-65431F7DC29F}) -- C:\Users\Μαριαμ\AppData\Local\{6CD4B9DE-3C67-4F06-97E4-65431F7DC29F}
[2012/11/25 20:20:53 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\{6CD4B9DE-3C67-4F06-97E4-65431F7DC29F}) -- C:\Users\Μαριαμ\AppData\Local\{6CD4B9DE-3C67-4F06-97E4-65431F7DC29F}
[2012/11/25 18:47:33 | 000,172,847 | ---- | C] ()(C:\Users\?a??aµ\Documents\e?a pe??stat??? st? ?????.docx) -- C:\Users\Μαριαμ\Documents\ενα περιστατικό στο χωριό.docx
[2012/11/25 18:32:29 | 000,015,997 | ---- | M] ()(C:\Users\?a??aµ\Documents\??a ap?? s.docx) -- C:\Users\Μαριαμ\Documents\Ένα απλό σ.docx
[2012/11/24 22:23:00 | 000,015,089 | ---- | M] ()(C:\Users\?a??aµ\Documents\S?? ?a???? t? fe????? ??a s?µpa? ?a ?e??.docx) -- C:\Users\Μαριαμ\Documents\Σου χαρίζω το φεγγάρι ένα σύμπαν θα χεις.docx
[2012/11/24 22:23:00 | 000,015,089 | ---- | M] ()(C:\Users\?a??aµ\Documents\S?? ?a???? t? fe????? ??a s?µpa? ?a ?e?? - Copy.docx) -- C:\Users\Μαριαμ\Documents\Σου χαρίζω το φεγγάρι ένα σύμπαν θα χεις - Copy.docx
[2012/11/24 20:29:07 | 000,015,997 | ---- | C] ()(C:\Users\?a??aµ\Documents\??a ap?? s.docx) -- C:\Users\Μαριαμ\Documents\Ένα απλό σ.docx
[2012/11/24 20:18:59 | 000,015,089 | ---- | C] ()(C:\Users\?a??aµ\Documents\S?? ?a???? t? fe????? ??a s?µpa? ?a ?e??.docx) -- C:\Users\Μαριαμ\Documents\Σου χαρίζω το φεγγάρι ένα σύμπαν θα χεις.docx
[2012/11/24 19:06:39 | 000,303,057 | ---- | M] ()(C:\Users\?a??aµ\Documents\xartes.docx) -- C:\Users\Μαριαμ\Documents\xartes.docx
[2012/11/23 18:16:10 | 000,384,321 | ---- | C] ()(C:\Users\?a??aµ\Documents\???p???? ??????a?.docx) -- C:\Users\Μαριαμ\Documents\Τροπικός κυκλώνας.docx
[2012/11/23 18:10:20 | 000,042,735 | ---- | C] ()(C:\Users\?a??aµ\Documents\????? ß???? ???µ??eta? t? fa???µe?? t?? as?????sta ?????? µete?????????? ?ata???µ??sµ?t??.docx) -- C:\Users\Μαριαμ\Documents\Όξινη βροχή ονομάζεται το φαινόμενο των ασυνήθιστα όξινων μετεωρολογικών κατακρημνισμάτων.docx
[2012/11/23 17:42:53 | 000,303,057 | ---- | C] ()(C:\Users\?a??aµ\Documents\xartes.docx) -- C:\Users\Μαριαμ\Documents\xartes.docx
[2012/11/10 22:29:28 | 000,020,054 | ---- | M] ()(C:\Users\?a??aµ\Documents\NOEMBRHS.docx) -- C:\Users\Μαριαμ\Documents\NOEMBRHS.docx
[2012/11/03 18:08:09 | 000,020,054 | ---- | C] ()(C:\Users\?a??aµ\Documents\NOEMBRHS.docx) -- C:\Users\Μαριαμ\Documents\NOEMBRHS.docx
[2012/10/12 15:16:13 | 000,018,320 | ---- | M] ()(C:\Users\?a??aµ\Documents\? ?????S    µ??.docx) -- C:\Users\Μαριαμ\Documents\Ο ΕΑΥΤΟΣ    μου.docx
[2012/10/08 20:15:13 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\Microsoft Games) -- C:\Users\Μαριαμ\AppData\Local\Microsoft Games
[2012/10/08 20:15:13 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\Microsoft Games) -- C:\Users\Μαριαμ\AppData\Local\Microsoft Games
[2012/10/07 12:12:28 | 000,018,320 | ---- | C] ()(C:\Users\?a??aµ\Documents\? ?????S    µ??.docx) -- C:\Users\Μαριαμ\Documents\Ο ΕΑΥΤΟΣ    μου.docx
[2012/10/07 11:58:19 | 000,000,000 | ---D | M](C:\Use
Grecian Geek

"Count your blessings, remember your prayers..."

"In one of the stars I shall be living. In one of them I shall be laughing. And so it will be as if all the stars will be laughing when you look at the sky at night.. You, only you, will have stars that can laugh..."

DR M

And the rest!!!

[2012/10/07 12:12:28 | 000,018,320 | ---- | C] ()(C:\Users\?a??aµ\Documents\? ?????S    µ??.docx) -- C:\Users\Μαριαμ\Documents\Ο ΕΑΥΤΟΣ    μου.docx
[2012/10/07 11:58:19 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\Microsoft Help) -- C:\Users\Μαριαμ\AppData\Local\Microsoft Help
[2012/10/07 11:58:19 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\Microsoft Help) -- C:\Users\Μαριαμ\AppData\Local\Microsoft Help
[2012/10/04 19:07:27 | 000,010,579 | ---- | M] ()(C:\Users\?a??aµ\Documents\µa??aµ.xlsx) -- C:\Users\Μαριαμ\Documents\μαριαμ.xlsx
[2012/10/04 19:07:24 | 000,010,579 | ---- | C] ()(C:\Users\?a??aµ\Documents\µa??aµ.xlsx) -- C:\Users\Μαριαμ\Documents\μαριαμ.xlsx
[2012/10/04 17:08:22 | 000,000,000 | --SD | C](C:\Users\?a??aµ\Documents\My Data Sources) -- C:\Users\Μαριαμ\Documents\My Data Sources
[2012/10/03 15:23:14 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\TP) -- C:\Users\Μαριαμ\AppData\Roaming\TP
[2012/10/03 15:23:14 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\TP) -- C:\Users\Μαριαμ\AppData\Roaming\TP
[2012/10/03 15:22:54 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\SoftGrid Client) -- C:\Users\Μαριαμ\AppData\Local\SoftGrid Client
[2012/10/03 15:22:54 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\SoftGrid Client) -- C:\Users\Μαριαμ\AppData\Local\SoftGrid Client
[2012/10/03 15:17:31 | 000,013,312 | -HS- | M] ()(C:\Users\?a??aµ\Thumbs.db) -- C:\Users\Μαριαμ\Thumbs.db
[2012/10/03 15:17:31 | 000,013,312 | -HS- | C] ()(C:\Users\?a??aµ\Thumbs.db) -- C:\Users\Μαριαμ\Thumbs.db
[2012/09/08 21:28:25 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\Adobe) -- C:\Users\Μαριαμ\AppData\Roaming\Adobe
[2012/09/08 21:28:25 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\Adobe) -- C:\Users\Μαριαμ\AppData\Local\Adobe
[2012/09/08 21:28:25 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\Adobe) -- C:\Users\Μαριαμ\AppData\Roaming\Adobe
[2012/09/08 21:28:25 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\Adobe) -- C:\Users\Μαριαμ\AppData\Local\Adobe
[2012/09/03 16:34:07 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\Reallusion) -- C:\Users\Μαριαμ\AppData\Roaming\Reallusion
[2012/09/03 16:34:07 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\Reallusion) -- C:\Users\Μαριαμ\AppData\Roaming\Reallusion
[2012/08/12 16:20:50 | 000,028,160 | ---- | C] ()(C:\Users\?a??aµ\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini) -- C:\Users\Μαριαμ\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/08/07 18:46:55 | 000,350,941 | ---- | M] ()(C:\Users\?a??aµ\Documents\mariam.xps) -- C:\Users\Μαριαμ\Documents\mariam.xps
[2012/08/07 18:46:54 | 000,350,941 | ---- | C] ()(C:\Users\?a??aµ\Documents\mariam.xps) -- C:\Users\Μαριαμ\Documents\mariam.xps
[2012/06/08 19:48:12 | 000,001,345 | ---- | M] ()(C:\Users\?a??aµ\Desktop\Media Center.lnk) -- C:\Users\Μαριαμ\Desktop\Media Center.lnk
[2012/06/08 19:48:12 | 000,001,345 | ---- | C] ()(C:\Users\?a??aµ\Desktop\Media Center.lnk) -- C:\Users\Μαριαμ\Desktop\Media Center.lnk
[2012/06/07 14:42:30 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\WildTangent) -- C:\Users\Μαριαμ\AppData\Roaming\WildTangent
[2012/06/07 14:42:30 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\WildTangent) -- C:\Users\Μαριαμ\AppData\Roaming\WildTangent
[2012/06/04 17:00:15 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\PlayFirst) -- C:\Users\Μαριαμ\AppData\Roaming\PlayFirst
[2012/06/04 17:00:15 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\PlayFirst) -- C:\Users\Μαριαμ\AppData\Roaming\PlayFirst
[2012/06/04 15:40:40 | 000,000,000 | -H-D | M](C:\Users\?a??aµ\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned) -- C:\Users\Μαριαμ\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2012/06/03 09:29:23 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\Namco) -- C:\Users\Μαριαμ\AppData\Roaming\Namco
[2012/06/03 09:29:23 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\Namco) -- C:\Users\Μαριαμ\AppData\Roaming\Namco
[2012/06/03 09:23:18 | 000,000,000 | ---D | M](C:\Users\?a??aµ\Documents\Fax) -- C:\Users\Μαριαμ\Documents\Fax
[2012/06/03 09:23:17 | 000,000,000 | R--D | M](C:\Users\?a??aµ\Documents\Scanned Documents) -- C:\Users\Μαριαμ\Documents\Scanned Documents
[2012/06/03 09:23:17 | 000,000,000 | R--D | C](C:\Users\?a??aµ\Documents\Scanned Documents) -- C:\Users\Μαριαμ\Documents\Scanned Documents
[2012/06/03 09:23:17 | 000,000,000 | ---D | C](C:\Users\?a??aµ\Documents\Fax) -- C:\Users\Μαριαμ\Documents\Fax
[2012/06/02 15:04:35 | 000,524,288 | -HS- | M] ()(C:\Users\?a??aµ\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms) -- C:\Users\Μαριαμ\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
[2012/06/02 15:04:35 | 000,524,288 | -HS- | M] ()(C:\Users\?a??aµ\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms) -- C:\Users\Μαριαμ\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
[2012/06/02 15:04:35 | 000,065,536 | -HS- | M] ()(C:\Users\?a??aµ\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf) -- C:\Users\Μαριαμ\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
[2012/06/02 15:00:46 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\Powercinema) -- C:\Users\Μαριαμ\AppData\Local\Powercinema
[2012/06/02 15:00:46 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\Powercinema) -- C:\Users\Μαριαμ\AppData\Local\Powercinema
[2012/06/02 15:00:45 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\CyberLink) -- C:\Users\Μαριαμ\AppData\Roaming\CyberLink
[2012/06/02 15:00:45 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\CyberLink) -- C:\Users\Μαριαμ\AppData\Roaming\CyberLink
[2012/06/02 15:00:33 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\Dell) -- C:\Users\Μαριαμ\AppData\Local\Dell
[2012/06/02 15:00:33 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\Dell) -- C:\Users\Μαριαμ\AppData\Local\Dell
[2012/06/02 15:00:29 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\PCDr) -- C:\Users\Μαριαμ\AppData\Roaming\PCDr
[2012/06/02 15:00:29 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\PCDr) -- C:\Users\Μαριαμ\AppData\Roaming\PCDr
[2012/06/02 14:58:05 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\Dell) -- C:\Users\Μαριαμ\AppData\Roaming\Dell
[2012/06/02 14:58:05 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\Dell) -- C:\Users\Μαριαμ\AppData\Roaming\Dell
[2012/06/02 14:42:22 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\Blio) -- C:\Users\Μαριαμ\AppData\Roaming\Blio
[2012/06/02 14:42:22 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\Blio) -- C:\Users\Μαριαμ\AppData\Roaming\Blio
[2012/06/02 14:41:59 | 000,000,000 | ---D | C](C:\Users\?a??aµ\Documents\Blio) -- C:\Users\Μαριαμ\Documents\Blio
[2012/06/02 14:41:00 | 000,000,000 | ---D | M](C:\Users\?a??aµ\My Backup Files) -- C:\Users\Μαριαμ\My Backup Files
[2012/06/02 14:41:00 | 000,000,000 | ---D | M](C:\Users\?a??aµ\My Backup Files) -- C:\Users\Μαριαμ\My Backup Files
[2012/06/02 14:40:48 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\Nero_AG) -- C:\Users\Μαριαμ\AppData\Local\Nero_AG
[2012/06/02 14:40:48 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\Nero_AG) -- C:\Users\Μαριαμ\AppData\Local\Nero_AG
[2012/06/02 14:40:28 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\Nero) -- C:\Users\Μαριαμ\AppData\Roaming\Nero
[2012/06/02 14:40:28 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\Nero) -- C:\Users\Μαριαμ\AppData\Roaming\Nero
[2012/06/02 14:34:40 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\Windows Live Writer) -- C:\Users\Μαριαμ\AppData\Roaming\Windows Live Writer
[2012/06/02 14:34:40 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\Windows Live Writer) -- C:\Users\Μαριαμ\AppData\Roaming\Windows Live Writer
[2012/06/02 14:25:30 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\ArcSoft) -- C:\Users\Μαριαμ\AppData\Local\ArcSoft
[2012/06/02 14:25:30 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\ArcSoft) -- C:\Users\Μαριαμ\AppData\Local\ArcSoft
[2012/06/02 14:23:06 | 000,001,439 | ---- | M] ()(C:\Users\?a??aµ\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk) -- C:\Users\Μαριαμ\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/06/02 14:23:06 | 000,001,439 | ---- | C] ()(C:\Users\?a??aµ\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk) -- C:\Users\Μαριαμ\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/06/02 14:23:06 | 000,000,221 | -HS- | M] ()(C:\Users\?a??aµ\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini) -- C:\Users\Μαριαμ\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2012/06/02 14:22:27 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\Fingertapps) -- C:\Users\Μαριαμ\AppData\Roaming\Fingertapps
[2012/06/02 14:22:27 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\Fingertapps) -- C:\Users\Μαριαμ\AppData\Roaming\Fingertapps
[2012/06/02 14:22:25 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\Intel Corporation) -- C:\Users\Μαριαμ\AppData\Roaming\Intel Corporation
[2012/06/02 14:22:25 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\Intel Corporation) -- C:\Users\Μαριαμ\AppData\Roaming\Intel Corporation
[2012/06/02 14:22:21 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\Dell Touch Zone) -- C:\Users\Μαριαμ\AppData\Roaming\Dell Touch Zone
[2012/06/02 14:22:21 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\Dell Touch Zone) -- C:\Users\Μαριαμ\AppData\Roaming\Dell Touch Zone
[2012/06/02 14:22:15 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\Creative) -- C:\Users\Μαριαμ\AppData\Roaming\Creative
[2012/06/02 14:22:15 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\Creative) -- C:\Users\Μαριαμ\AppData\Roaming\Creative
[2012/06/02 14:22:01 | 000,000,174 | -HS- | C] ()(C:\Users\?a??aµ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini) -- C:\Users\Μαριαμ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
[2012/06/02 14:22:00 | 000,001,482 | -HS- | C] ()(C:\Users\?a??aµ\Desktop\desktop.ini) -- C:\Users\Μαριαμ\Desktop\desktop.ini
[2012/06/02 14:22:00 | 000,000,402 | -HS- | C] ()(C:\Users\?a??aµ\Documents\desktop.ini) -- C:\Users\Μαριαμ\Documents\desktop.ini
[2012/06/02 14:22:00 | 000,000,000 | -H-D | C](C:\Users\?a??aµ\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned) -- C:\Users\Μαριαμ\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2012/06/02 14:19:19 | 000,075,656 | ---- | C] ()(C:\Users\?a??aµ\AppData\Local\GDIPFONTCACHEV1.DAT) -- C:\Users\Μαριαμ\AppData\Local\GDIPFONTCACHEV1.DAT
[2012/06/02 14:19:08 | 000,000,020 | -HS- | M] ()(C:\Users\?a??aµ\ntuser.ini) -- C:\Users\Μαριαμ\ntuser.ini
[2012/06/02 14:19:08 | 000,000,020 | -HS- | C] ()(C:\Users\?a??aµ\ntuser.ini) -- C:\Users\Μαριαμ\ntuser.ini
[2012/06/02 14:19:08 | 000,000,000 | -HSD | M](C:\Users\?a??aµ\Templates) -- C:\Users\Μαριαμ\Templates
[2012/06/02 14:19:08 | 000,000,000 | -HSD | M](C:\Users\?a??aµ\Start Menu) -- C:\Users\Μαριαμ\Start Menu
[2012/06/02 14:19:08 | 000,000,000 | -HSD | M](C:\Users\?a??aµ\SendTo) -- C:\Users\Μαριαμ\SendTo
[2012/06/02 14:19:08 | 000,000,000 | -HSD | M](C:\Users\?a??aµ\Recent) -- C:\Users\Μαριαμ\Recent
[2012/06/02 14:19:08 | 000,000,000 | -HSD | M](C:\Users\?a??aµ\PrintHood) -- C:\Users\Μαριαμ\PrintHood
[2012/06/02 14:19:08 | 000,000,000 | -HSD | M](C:\Users\?a??aµ\NetHood) -- C:\Users\Μαριαμ\NetHood
[2012/06/02 14:19:08 | 000,000,000 | -HSD | M](C:\Users\?a??aµ\My Documents) -- C:\Users\Μαριαμ\My Documents
[2012/06/02 14:19:08 | 000,000,000 | -HSD | M](C:\Users\?a??aµ\Local Settings) -- C:\Users\Μαριαμ\Local Settings
[2012/06/02 14:19:08 | 000,000,000 | -HSD | M](C:\Users\?a??aµ\Documents\My Videos) -- C:\Users\Μαριαμ\Documents\My Videos
[2012/06/02 14:19:08 | 000,000,000 | -HSD | M](C:\Users\?a??aµ\Documents\My Pictures) -- C:\Users\Μαριαμ\Documents\My Pictures
[2012/06/02 14:19:08 | 000,000,000 | -HSD | M](C:\Users\?a??aµ\Documents\My Music) -- C:\Users\Μαριαμ\Documents\My Music
[2012/06/02 14:19:08 | 000,000,000 | -HSD | M](C:\Users\?a??aµ\Cookies) -- C:\Users\Μαριαμ\Cookies
[2012/06/02 14:19:08 | 000,000,000 | -HSD | M](C:\Users\?a??aµ\Application Data) -- C:\Users\Μαριαμ\Application Data
[2012/06/02 14:19:08 | 000,000,000 | -HSD | M](C:\Users\?a??aµ\AppData\Local\Temporary Internet Files) -- C:\Users\Μαριαμ\AppData\Local\Temporary Internet Files
[2012/06/02 14:19:08 | 000,000,000 | -HSD | M](C:\Users\?a??aµ\AppData\Local\History) -- C:\Users\Μαριαμ\AppData\Local\History
[2012/06/02 14:19:08 | 000,000,000 | -HSD | M](C:\Users\?a??aµ\AppData\Local\Application Data) -- C:\Users\Μαριαμ\AppData\Local\Application Data
[2012/06/02 14:19:08 | 000,000,000 | -HSD | M](C:\Users\?a??aµ\Templates) -- C:\Users\Μαριαμ\Templates
[2012/06/02 14:19:08 | 000,000,000 | -HSD | M](C:\Users\?a??aµ\Start Menu) -- C:\Users\Μαριαμ\Start Menu
[2012/06/02 14:19:08 | 000,000,000 | -HSD | M](C:\Users\?a??aµ\SendTo) -- C:\Users\Μαριαμ\SendTo
[2012/06/02 14:19:08 | 000,000,000 | -HSD | M](C:\Users\?a??aµ\Recent) -- C:\Users\Μαριαμ\Recent
[2012/06/02 14:19:08 | 000,000,000 | -HSD | M](C:\Users\?a??aµ\PrintHood) -- C:\Users\Μαριαμ\PrintHood
[2012/06/02 14:19:08 | 000,000,000 | -HSD | M](C:\Users\?a??aµ\NetHood) -- C:\Users\Μαριαμ\NetHood
[2012/06/02 14:19:08 | 000,000,000 | -HSD | M](C:\Users\?a??aµ\My Documents) -- C:\Users\Μαριαμ\My Documents
[2012/06/02 14:19:08 | 000,000,000 | -HSD | M](C:\Users\?a??aµ\Local Settings) -- C:\Users\Μαριαμ\Local Settings
[2012/06/02 14:19:08 | 000,000,000 | -HSD | M](C:\Users\?a??aµ\Cookies) -- C:\Users\Μαριαμ\Cookies
[2012/06/02 14:19:08 | 000,000,000 | -HSD | M](C:\Users\?a??aµ\Application Data) -- C:\Users\Μαριαμ\Application Data
[2012/06/02 14:19:08 | 000,000,000 | -HSD | M](C:\Users\?a??aµ\AppData\Local\Temporary Internet Files) -- C:\Users\Μαριαμ\AppData\Local\Temporary Internet Files
[2012/06/02 14:19:08 | 000,000,000 | -HSD | M](C:\Users\?a??aµ\AppData\Local\History) -- C:\Users\Μαριαμ\AppData\Local\History
[2012/06/02 14:19:08 | 000,000,000 | -HSD | M](C:\Users\?a??aµ\AppData\Local\Application Data) -- C:\Users\Μαριαμ\AppData\Local\Application Data
[2012/06/02 14:19:08 | 000,000,000 | -HSD | C](C:\Users\?a??aµ\Documents\My Videos) -- C:\Users\Μαριαμ\Documents\My Videos
[2012/06/02 14:19:08 | 000,000,000 | -HSD | C](C:\Users\?a??aµ\Documents\My Pictures) -- C:\Users\Μαριαμ\Documents\My Pictures
[2012/06/02 14:19:08 | 000,000,000 | -HSD | C](C:\Users\?a??aµ\Documents\My Music) -- C:\Users\Μαριαμ\Documents\My Music
[2012/06/02 14:19:08 | 000,000,000 | -H-D | M](C:\Users\?a??aµ\AppData) -- C:\Users\Μαριαμ\AppData
[2012/06/02 14:19:08 | 000,000,000 | -H-D | M](C:\Users\?a??aµ\AppData) -- C:\Users\Μαριαμ\AppData
[2012/06/02 14:19:07 | 000,524,288 | -HS- | C] ()(C:\Users\?a??aµ\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms) -- C:\Users\Μαριαμ\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
[2012/06/02 14:19:07 | 000,524,288 | -HS- | C] ()(C:\Users\?a??aµ\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms) -- C:\Users\Μαριαμ\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
[2012/06/02 14:19:07 | 000,262,144 | -HS- | C] ()(C:\Users\?a??aµ\ntuser.dat.LOG2) -- C:\Users\Μαριαμ\ntuser.dat.LOG2
[2012/06/02 14:19:07 | 000,262,144 | -HS- | C] ()(C:\Users\?a??aµ\ntuser.dat.LOG1) -- C:\Users\Μαριαμ\ntuser.dat.LOG1
[2012/06/02 14:19:07 | 000,065,536 | -HS- | C] ()(C:\Users\?a??aµ\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf) -- C:\Users\Μαριαμ\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
[2012/06/02 14:19:07 | 000,000,290 | ---- | C] ()(C:\Users\?a??aµ\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk) -- C:\Users\Μαριαμ\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2012/06/02 14:19:07 | 000,000,272 | ---- | C] ()(C:\Users\?a??aµ\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk) -- C:\Users\Μαριαμ\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2012/06/02 14:19:07 | 000,000,221 | -HS- | C] ()(C:\Users\?a??aµ\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini) -- C:\Users\Μαριαμ\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2012/06/02 14:19:06 | 002,359,296 | -HS- | C] ()(C:\Users\?a??aµ\ntuser.dat) -- C:\Users\Μαριαμ\ntuser.dat
[2012/01/29 13:26:44 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\Media Center Programs) -- C:\Users\Μαριαμ\AppData\Roaming\Media Center Programs
[2012/01/29 13:26:44 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\Media Center Programs) -- C:\Users\Μαριαμ\AppData\Roaming\Media Center Programs
[2012/01/29 11:47:17 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\Macromedia) -- C:\Users\Μαριαμ\AppData\Roaming\Macromedia
[2012/01/29 11:47:17 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Roaming\Macromedia) -- C:\Users\Μαριαμ\AppData\Roaming\Macromedia
[2009/07/14 07:49:38 | 000,000,290 | ---- | M] ()(C:\Users\?a??aµ\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk) -- C:\Users\Μαριαμ\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2009/07/14 07:49:38 | 000,000,272 | ---- | M] ()(C:\Users\?a??aµ\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk) -- C:\Users\Μαριαμ\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
(C:\Users\?a??aµ\Videos) -- C:\Users\Μαριαμ\Videos
(C:\Users\?a??aµ\Templates) -- C:\Users\Μαριαμ\Templates
(C:\Users\?a??aµ\SyncUP) -- C:\Users\Μαριαμ\SyncUP
(C:\Users\?a??aµ\Start Menu) -- C:\Users\Μαριαμ\Start Menu
(C:\Users\?a??aµ\SendTo) -- C:\Users\Μαριαμ\SendTo
(C:\Users\?a??aµ\Searches) -- C:\Users\Μαριαμ\Searches
(C:\Users\?a??aµ\Saved Games) -- C:\Users\Μαριαμ\Saved Games
(C:\Users\?a??aµ\Recent) -- C:\Users\Μαριαμ\Recent
(C:\Users\?a??aµ\PrintHood) -- C:\Users\Μαριαμ\PrintHood
(C:\Users\?a??aµ\NetHood) -- C:\Users\Μαριαμ\NetHood
(C:\Users\?a??aµ\My Documents) -- C:\Users\Μαριαμ\My Documents
(C:\Users\?a??aµ\My Backup Files) -- C:\Users\Μαριαμ\My Backup Files
(C:\Users\?a??aµ\Music) -- C:\Users\Μαριαμ\Music
(C:\Users\?a??aµ\Local Settings) -- C:\Users\Μαριαμ\Local Settings
(C:\Users\?a??aµ\Links) -- C:\Users\Μαριαμ\Links
(C:\Users\?a??aµ\Favorites) -- C:\Users\Μαριαμ\Favorites
(C:\Users\?a??aµ\Downloads) -- C:\Users\Μαριαμ\Downloads
(C:\Users\?a??aµ\Documents) -- C:\Users\Μαριαμ\Documents
(C:\Users\?a??aµ\Desktop) -- C:\Users\Μαριαμ\Desktop
(C:\Users\?a??aµ\Cookies) -- C:\Users\Μαριαμ\Cookies
(C:\Users\?a??aµ\Contacts) -- C:\Users\Μαριαμ\Contacts
(C:\Users\?a??aµ\Application Data) -- C:\Users\Μαριαμ\Application Data
(C:\Users\?a??aµ\AppData\Roaming\Windows Live Writer) -- C:\Users\Μαριαμ\AppData\Roaming\Windows Live Writer
(C:\Users\?a??aµ\AppData\Roaming\WildTangentv1000) -- C:\Users\Μαριαμ\AppData\Roaming\WildTangentv1000
(C:\Users\?a??aµ\AppData\Roaming\WildTangent) -- C:\Users\Μαριαμ\AppData\Roaming\WildTangent
(C:\Users\?a??aµ\AppData\Roaming\TP) -- C:\Users\Μαριαμ\AppData\Roaming\TP
(C:\Users\?a??aµ\AppData\Roaming\SoftGrid Client) -- C:\Users\Μαριαμ\AppData\Roaming\SoftGrid Client
(C:\Users\?a??aµ\AppData\Roaming\Roxio) -- C:\Users\Μαριαμ\AppData\Roaming\Roxio
(C:\Users\?a??aµ\AppData\Roaming\Reallusion) -- C:\Users\Μαριαμ\AppData\Roaming\Reallusion
(C:\Users\?a??aµ\AppData\Roaming\PlayFirst) -- C:\Users\Μαριαμ\AppData\Roaming\PlayFirst
(C:\Users\?a??aµ\AppData\Roaming\PCDr) -- C:\Users\Μαριαμ\AppData\Roaming\PCDr
(C:\Users\?a??aµ\AppData\Roaming\Nero) -- C:\Users\Μαριαμ\AppData\Roaming\Nero
(C:\Users\?a??aµ\AppData\Roaming\Namco) -- C:\Users\Μαριαμ\AppData\Roaming\Namco
(C:\Users\?a??aµ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup) -- C:\Users\Μαριαμ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
(C:\Users\?a??aµ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance) -- C:\Users\Μαριαμ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
(C:\Users\?a??aµ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games) -- C:\Users\Μαριαμ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
(C:\Users\?a??aµ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bluetooth Devices) -- C:\Users\Μαριαμ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bluetooth Devices
(C:\Users\?a??aµ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools) -- C:\Users\Μαριαμ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
(C:\Users\?a??aµ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories) -- C:\Users\Μαριαμ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
(C:\Users\?a??aµ\AppData\Roaming\Microsoft) -- C:\Users\Μαριαμ\AppData\Roaming\Microsoft
(C:\Users\?a??aµ\AppData\Roaming\Media Center Programs) -- C:\Users\Μαριαμ\AppData\Roaming\Media Center Programs
(C:\Users\?a??aµ\AppData\Roaming\Macromedia) -- C:\Users\Μαριαμ\AppData\Roaming\Macromedia
(C:\Users\?a??aµ\AppData\Roaming\Intel Corporation) -- C:\Users\Μαριαμ\AppData\Roaming\Intel Corporation
(C:\Users\?a??aµ\AppData\Roaming\IDT) -- C:\Users\Μαριαμ\AppData\Roaming\IDT
(C:\Users\?a??aµ\AppData\Roaming\Google) -- C:\Users\Μαριαμ\AppData\Roaming\Google
(C:\Users\?a??aµ\AppData\Roaming\Fingertapps) -- C:\Users\Μαριαμ\AppData\Roaming\Fingertapps
(C:\Users\?a??aµ\AppData\Roaming\Dell Touch Zone) -- C:\Users\Μαριαμ\AppData\Roaming\Dell Touch Zone
(C:\Users\?a??aµ\AppData\Roaming\Dell) -- C:\Users\Μαριαμ\AppData\Roaming\Dell
(C:\Users\?a??aµ\AppData\Roaming\CyberLink) -- C:\Users\Μαριαμ\AppData\Roaming\CyberLink
(C:\Users\?a??aµ\AppData\Roaming\Creative) -- C:\Users\Μαριαμ\AppData\Roaming\Creative
(C:\Users\?a??aµ\AppData\Roaming\Blio) -- C:\Users\Μαριαμ\AppData\Roaming\Blio
(C:\Users\?a??aµ\AppData\Roaming\Adobe) -- C:\Users\Μαριαμ\AppData\Roaming\Adobe
(C:\Users\?a??aµ\AppData\Local\Windows Live Writer) -- C:\Users\Μαριαμ\AppData\Local\Windows Live Writer
(C:\Users\?a??aµ\AppData\Local\VirtualStore) -- C:\Users\Μαριαμ\AppData\Local\VirtualStore
(C:\Users\?a??aµ\AppData\Local\Temporary Internet Files) -- C:\Users\Μαριαμ\AppData\Local\Temporary Internet Files
(C:\Users\?a??aµ\AppData\Local\SoftThinks) -- C:\Users\Μαριαμ\AppData\Local\SoftThinks
(C:\Users\?a??aµ\AppData\Local\SoftGrid Client) -- C:\Users\Μαριαμ\AppData\Local\SoftGrid Client
(C:\Users\?a??aµ\AppData\Local\Powercinema) -- C:\Users\Μαριαμ\AppData\Local\Powercinema
(C:\Users\?a??aµ\AppData\Local\Nero_AG) -- C:\Users\Μαριαμ\AppData\Local\Nero_AG
(C:\Users\?a??aµ\AppData\Local\Nero) -- C:\Users\Μαριαμ\AppData\Local\Nero
(C:\Users\?a??aµ\AppData\Local\Microsoft_Corporation) -- C:\Users\Μαριαμ\AppData\Local\Microsoft_Corporation
(C:\Users\?a??aµ\AppData\Local\Microsoft Help) -- C:\Users\Μαριαμ\AppData\Local\Microsoft Help
(C:\Users\?a??aµ\AppData\Local\Microsoft Games) -- C:\Users\Μαριαμ\AppData\Local\Microsoft Games
(C:\Users\?a??aµ\AppData\Local\Microsoft) -- C:\Users\Μαριαμ\AppData\Local\Microsoft
(C:\Users\?a??aµ\AppData\Local\History) -- C:\Users\Μαριαμ\AppData\Local\History
(C:\Users\?a??aµ\AppData\Local\Google) -- C:\Users\Μαριαμ\AppData\Local\Google
(C:\Users\?a??aµ\AppData\Local\ElevatedDiagnostics) -- C:\Users\Μαριαμ\AppData\Local\ElevatedDiagnostics
(C:\Users\?a??aµ\AppData\Local\Diagnostics) -- C:\Users\Μαριαμ\AppData\Local\Diagnostics
(C:\Users\?a??aµ\AppData\Local\Dell Edoc Viewer) -- C:\Users\Μαριαμ\AppData\Local\Dell Edoc Viewer
(C:\Users\?a??aµ\AppData\Local\Dell) -- C:\Users\Μαριαμ\AppData\Local\Dell
(C:\Users\?a??aµ\AppData\Local\ArcSoft) -- C:\Users\Μαριαμ\AppData\Local\ArcSoft
(C:\Users\?a??aµ\AppData\Local\Apps) -- C:\Users\Μαριαμ\AppData\Local\Apps
(C:\Users\?a??aµ\AppData\Local\Application Data) -- C:\Users\Μαριαμ\AppData\Local\Application Data
(C:\Users\?a??aµ\AppData\Local\Adobe) -- C:\Users\Μαριαμ\AppData\Local\Adobe
(C:\Users\?a??aµ\AppData\Local\{F8C9425F-0274-482F-ABA0-B4BE76CED672}) -- C:\Users\Μαριαμ\AppData\Local\{F8C9425F-0274-482F-ABA0-B4BE76CED672}
(C:\Users\?a??aµ\AppData\Local\{F56B3EA2-5A4F-45B7-92C1-D9AC07709BE0}) -- C:\Users\Μαριαμ\AppData\Local\{F56B3EA2-5A4F-45B7-92C1-D9AC07709BE0}
(C:\Users\?a??aµ\AppData\Local\{E70A5469-8500-4998-B521-5E025FD6AD3A}) -- C:\Users\Μαριαμ\AppData\Local\{E70A5469-8500-4998-B521-5E025FD6AD3A}
(C:\Users\?a??aµ\AppData\Local\{A2AD4592-2474-4F8E-BBBC-1B3ECA2E02A5}) -- C:\Users\Μαριαμ\AppData\Local\{A2AD4592-2474-4F8E-BBBC-1B3ECA2E02A5}
(C:\Users\?a??aµ\AppData\Local\{9510853A-7718-45CA-AB77-8D13D479F21E}) -- C:\Users\Μαριαμ\AppData\Local\{9510853A-7718-45CA-AB77-8D13D479F21E}
(C:\Users\?a??aµ\AppData\Local\{7BB71E01-FC17-4CE7-B52E-6B54B9E2DD18}) -- C:\Users\Μαριαμ\AppData\Local\{7BB71E01-FC17-4CE7-B52E-6B54B9E2DD18}
(C:\Users\?a??aµ\AppData\Local\{6CD4B9DE-3C67-4F06-97E4-65431F7DC29F}) -- C:\Users\Μαριαμ\AppData\Local\{6CD4B9DE-3C67-4F06-97E4-65431F7DC29F}
(C:\Users\?a??aµ\AppData\Local\{69369693-B309-4230-AAB3-41E38EFBD614}) -- C:\Users\Μαριαμ\AppData\Local\{69369693-B309-4230-AAB3-41E38EFBD614}
(C:\Users\?a??aµ\AppData\Local\{57E7C397-FA3E-4479-8A07-9BB9B9DF56D3}) -- C:\Users\Μαριαμ\AppData\Local\{57E7C397-FA3E-4479-8A07-9BB9B9DF56D3}
(C:\Users\?a??aµ\AppData\Local\{54BA7F56-3060-48A1-8208-A3453C61A7BE}) -- C:\Users\Μαριαμ\AppData\Local\{54BA7F56-3060-48A1-8208-A3453C61A7BE}
(C:\Users\?a??aµ\AppData\Local\{4DDC82B0-C6E4-40E1-8ED8-677F7A41B25A}) -- C:\Users\Μαριαμ\AppData\Local\{4DDC82B0-C6E4-40E1-8ED8-677F7A41B25A}
(C:\Users\?a??aµ\AppData\Local\{198F7432-6FBF-418A-91C9-59B5B2CC0D20}) -- C:\Users\Μαριαμ\AppData\Local\{198F7432-6FBF-418A-91C9-59B5B2CC0D20}
(C:\Users\?a??aµ\AppData) -- C:\Users\Μαριαμ\AppData

========== Alternate Data Streams ==========

@Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:D1B5B4F1

< End of report >
Grecian Geek

"Count your blessings, remember your prayers..."

"In one of the stars I shall be living. In one of them I shall be laughing. And so it will be as if all the stars will be laughing when you look at the sky at night.. You, only you, will have stars that can laugh..."

DR M

One more post before go to bed:

Your tools have no problem with greek. Those ??μα?? (for example) are the accounts that are being created from no one!

Good night!  :rose:
Grecian Geek

"Count your blessings, remember your prayers..."

"In one of the stars I shall be living. In one of them I shall be laughing. And so it will be as if all the stars will be laughing when you look at the sky at night.. You, only you, will have stars that can laugh..."

Corrine

Actually, Panos, I think it is having a problem with the Greek.  It is seeing ?a??aµ but is able to copy Μαριαμ (the admin account).

With the volume of files, I am not surprised now that ESET and other tools hung up.  Unless Georgia's family has access to a time machine, it appears there has been a problem for a while with the clock.  Note the year 2015:

[2015/10/08 15:41:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Creative
[2015/11/02 09:33:00 | 000,000,422 | ---- | M] () -- C:\windows\tasks\SystemToolsDailyTest.job
[2015/11/01 10:18:38 | 000,000,000 | -H-- | M] () -- C:\windows\SysNative\drivers\Msft_Kernel_ew_juextctrl_01007.Wdf
[2015/11/01 10:18:33 | 000,000,000 | -H-- | M] () -- C:\windows\SysNative\drivers\Msft_Kernel_ew_jucdcacm_01007.Wdf
[2015/10/31 17:15:11 | 000,000,000 | R--D | C](C:\Users\?a??aµ\Pictures) -- C:\Users\Μαριαμ\Pictures
[2015/10/16 14:56:33 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\Dell Edoc Viewer) -- C:\Users\Μαριαμ\AppData\Local\Dell Edoc Viewer
[2015/10/16 14:56:33 | 000,000,000 | ---D | M](C:\Users\?a??aµ\AppData\Local\Dell Edoc Viewer) -- C:\Users\Μαριαμ\AppData\Local\Dell Edoc Viewer




This will take some time to review.


Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

DonnaB

Hi DR M,

Corrine had an emergency and she asked for me to help her out in her time of need.  Hope you don't mind. :)

Could I ask you to attach the OTL log. I'm hoping that will fix the issues with the unicode characters to properly display on the forum.

I do have to take off to work here shortly and my replies might be a bit delayed.

Thank you,
Donna :)
"To achieve the impossible, it is precisely the unthinkable that must be thought."
Tom Robbins

DR M

Hi, Donna,

Thank you for your willingness to help.

This "word" ?a??aµ was found in c:users' folder, as well as another one with letters meaning nothing, the Μαριαμ account (admin), the mariam account (standard user), the public accound and the guest account. I deleted them twice (the first time the letters were shown in a different way) from there (not from control panel, because there only the three accounts are shown), but they appear in the OTL log. No one created them, this is for sure.

Anyway, I will attach the log later (in a couple of hours).

Grecian Geek

"Count your blessings, remember your prayers..."

"In one of the stars I shall be living. In one of them I shall be laughing. And so it will be as if all the stars will be laughing when you look at the sky at night.. You, only you, will have stars that can laugh..."

DR M

Hi, Donna.

I attach the log.
Grecian Geek

"Count your blessings, remember your prayers..."

"In one of the stars I shall be living. In one of them I shall be laughing. And so it will be as if all the stars will be laughing when you look at the sky at night.. You, only you, will have stars that can laugh..."

DonnaB

Hi DR M,

QuoteThank you for your willingness to help.

You are very welcome. Corrine knows that I am at her beck and call on the drop of a hat anytime she is in need of assistance.

I do need to point out that I am presently in training for the removal of malware and my highly experienced instructor will have to review all of my responses to you before I post them (hence, the delay in responding), though this will be to your advantage.

Thank you for uploading the OTL log for my viewing pleasure. At quick glance, I see that didn't make much of a difference. While I review the OTL log more thoroughly and discuss what is found with my instructor, please see if you can boot to safe mode again and in Start Search type Extras.txt to see if that log can be found anywhere. If it is found, please upload that log as well. We may get lucky and find it in the following path:

C:\Users\mariam\Desktop\OTL

If not, no need to worry. We can work without it.

Due to long work days I endure and differences in time zones, I'll do my best to post back as soon as possible.

Thank you kindly for your understanding.
Donna :)
"To achieve the impossible, it is precisely the unthinkable that must be thought."
Tom Robbins

DR M

Hi, Donna.

No Extras.txt, unfortunately...

But we have a new episode.  :D

MARIAM'S ACCOUNT (NOT ADMIN'S) IN SAFE MODE:

1. Ran MBAM. It found 1 object and then freezed.

2. Ran MBAM again. When it found the infected object, I clicked immediately abort scan and then show results. The infected object was: PUP.Optional.Bundled Toolbar.A.  I removed it.

3. Downloaded Super Antispyware and ran it. It ound 156 threats. The log follows at the end of the post.

4. Ran MBAM many times. I noticed that it freezes on c:\windows\system32\NlsData0046.dll (the number after the word data may be different every time).

5. Ran Combofix to check if the new accounts in users have something to do with this. Yes. After Combofix running, two new accounts were created in c:\users (ααμ and AA4FBF 1). Shall I delete them?

6. I ran the infected computer in safe mode with networking (my network) and I forgot to disconnect my ipod from the network. Corrine advised me to disconnect my devices from the network when connecting the infected computer. So I wonder what to do after this mistake...

Here is the log of Super Antispyware:


SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 09/07/2013 at 11:42 AM

Application Version : 5.6.1032

Core Rules Database Version : 10752
Trace Rules Database Version: 8564

Scan type       : Quick Scan
Total Scan Time : 00:05:45

Operating System Information
Windows 7 Home Premium 64-bit, Service Pack 1 (Build 6.01.7601)
UAC Off - Limited User

Memory items scanned      : 338
Memory threats detected   : 0
Registry items scanned    : 64360
Registry threats detected : 0
File items scanned        : 10747
File threats detected     : 156

Adware.Tracking Cookie
   www.googleadservices.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .doubleclick.net [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .lucidmedia.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .atdmt.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .atdmt.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .invitemedia.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .invitemedia.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .imrworldwide.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .imrworldwide.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\FJ0CFG1O.txt [ /invitemedia.com ]
   .service.24media.gr [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .service.24media.gr [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .service.24media.gr [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\I335ZO6D.txt [ /revsci.net ]
   www.googleadservices.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\3E39SNMS.txt [ /ad.360yield.com ]
   .burstnet.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .adtech.de [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .fastclick.net [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   ad.yieldmanager.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   ad.yieldmanager.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\OP5WMM22.txt [ /e-2dj6wjkyuhajgko.stats.esomniture.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\6V3UG4TH.txt [ /tribalfusion.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\WF7GJGTH.txt [ /e-2dj6aekignczafo.stats.esomniture.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\QPX2NF7C.txt [ /lucidmedia.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\WPEFR7VG.txt [ /adtechus.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\8SQI4AX0.txt [ /www.googleadservices.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\KTY60IKM.txt [ /www.googleadservices.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\A0U2NDKP.txt [ /pro-market.net ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\QXXC17BX.txt [ /ad.yieldmanager.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\TLH5MC19.txt [ /at.atwola.com ]
   www.googleadservices.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   accounts.google.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .accounts.google.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .accounts.google.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .server.cpmstar.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .statcounter.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\ERANYRGQ.txt [ /advertising.com ]
   .server.cpmstar.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\RBBY27WQ.txt [ /track.adform.net ]
   .adtech.de [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .advertising.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .advertising.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\TICOR5TM.txt [ /e-2dj6whmisndzaep.stats.esomniture.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\5IRSPH9O.txt [ /e-2dj6wcmiqkcjgdo.stats.esomniture.com ]
   .ptvgoalv15.122.2o7.net [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\KI2B2H50.txt [ /casalemedia.com ]
   .apmebf.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .mediaplex.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .mediaplex.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .amazon-adsystem.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\PRSTSVY1.txt [ /atdmt.com ]
   .amazon-adsystem.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\R1J0TLFT.txt [ /e-2dj6aekiqkdpcap.stats.esomniture.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\CGGPXJV2.txt [ /e-2dj6wfkigpdjkgp.stats.esomniture.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\TYO5EHH5.txt [ /doubleclick.net ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\VMAU4M4X.txt [ /e-2dj6afkyunc5wkp.stats.esomniture.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\1NGVL0LI.txt [ /imrworldwide.com ]
   .histats.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .histats.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\MBL6L2B0.txt [ /e-2dj6aeloqhcjokp.stats.esomniture.com ]
   adserving.unibet.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\704CI776.txt [ /adform.net ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\I1L4M46S.txt [ /e-2dj6wjk4chd5ibo.stats.esomniture.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\9KOT20MG.txt [ /fastclick.net ]
   .subaruofamerica.112.2o7.net [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   ad.yieldmanager.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .trinitymirror.112.2o7.net [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   network.clickbanner.gr [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   ad.yieldmanager.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   ad.yieldmanager.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   ads.gamesbannernet.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   ads.gamesbannernet.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   ads.gamesbannernet.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   advertising.copacet.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   advertising.copacet.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   track.adform.net [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .adform.net [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .at.atwola.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .ru4.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .invitemedia.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   ad.yieldmanager.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .collective-media.net [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .revsci.net [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   a.intentmedia.net [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .server.cpmstar.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .revsci.net [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .revsci.net [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .revsci.net [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .invitemedia.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .collective-media.net [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .counter.inkfrog.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .casalemedia.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .casalemedia.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .casalemedia.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .casalemedia.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .casalemedia.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   ad.yieldmanager.com [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .doubleclick.net [ C:\USERS\MARIAM\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\Y9GVCH11.txt [ /wmedia.rotator.hadj7.adjuggler.net ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\2X4WYXL6.txt [ /invitemedia.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\6U0Y9XHD.txt [ /ads.ad4game.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\4LXN2HTJ.txt [ /hardsextube.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\WIYN2YRC.txt [ /yieldmanager.net ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\7YDT1801.txt [ /ad.360yield.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\53NG0J63.txt [ /statcounter.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\E1ZUO5C2.txt [ /tribalfusion.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\113J08SL.txt [ /www.atticamediagroup.gr ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\DCALAMWS.txt [ /www.hardsextube.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\FZZSB8WT.txt [ /lucidmedia.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\VC3SNEES.txt [ /ads.betfair.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\3E07BA6F.txt [ /e-2dj6wfkisjazccq.stats.esomniture.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\Q1EA9IRQ.txt [ /serving-sys.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\QEHKMAB3.txt [ /media.mybet.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\W3ABHBGL.txt [ /adtechus.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\QYUWDYUZ.txt [ /www.googleadservices.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\3XDY66Y0.txt [ /www.googleadservices.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\H7ZMGKIB.txt [ /www.googleadservices.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\PNSM5KCG.txt [ /www.googleadservices.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\HJ5VL72B.txt [ /www.googleadservices.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\W4VW6AWI.txt [ /www.googleadservices.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\EC89XX53.txt [ /ad.yieldmanager.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\I5Z2OA2Q.txt [ /adserver.hardsextube.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\9MPYI1TC.txt [ /ads.pornerbros.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\NWDS7110.txt [ /adxpansion.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\6PK295KX.txt [ /smartadserver.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\U2LOC1CQ.txt [ /advertising.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\UZ1BWLDE.txt [ /ru4.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\KA15YU62.txt [ /track.adform.net ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\M6YJXMWM.txt [ /mediaplex.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\MPJCI3B0.txt [ /ads.tunein.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\2O6L8KUJ.txt [ /e-2dj6ael4ahcpsdq.stats.esomniture.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\AXYSF05T.txt [ /server.cpmstar.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\V4N5M43D.txt [ /banners.victor.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\ARU2A3HY.txt [ /apmebf.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\QVSAOLZ5.txt [ /e-2dj6ael4okdjwbq.stats.esomniture.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\SZNIVXYH.txt [ /ero-advertising.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\WJJ71A72.txt [ /lfstmedia.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\9W13JJUI.txt [ /questionmarket.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\FP7PDOQL.txt [ /media.paddypower.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\LH687ZY0.txt [ /e-2dj6wcmiqkcjgdo.stats.esomniture.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\24Q61PPS.txt [ /adserving.unibet.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\Z6C9MHI5.txt [ /casalemedia.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\S2SD3VB5.txt [ /h.atdmt.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\HXPUWJ2P.txt [ /e-2dj6afkyaodzmgo.stats.esomniture.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\228ZGDO4.txt [ /atdmt.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\YEU1YSSO.txt [ /ads.adk2.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\38GZFF1J.txt [ /doubleclick.net ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\G3N7W7LH.txt [ /hardsextube.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\Y90B0V8L.txt [ /imrworldwide.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\VXLNGNLC.txt [ /ads2.zeusclicks.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZCVGOAD6.txt [ /c.atdmt.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\R0I0CQNJ.txt [ /adform.net ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\4FBO0V3I.txt [ /advertise365.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\01M40SZN.txt [ /e-2dj6wmloeid5egq.stats.esomniture.com ]
   C:\Users\mariam\AppData\Roaming\Microsoft\Windows\Cookies\Low\7Q2JJQOP.txt [ /www.media970.com ]
Grecian Geek

"Count your blessings, remember your prayers..."

"In one of the stars I shall be living. In one of them I shall be laughing. And so it will be as if all the stars will be laughing when you look at the sky at night.. You, only you, will have stars that can laugh..."

DonnaB

Hello Panos,

I'm not ignoring your above questions, just preparing for what to do that is best for all concerned.

Were you ever able to contact Georgia to discuss a possible clean install? Even though you do not have any recovery media to accomplish this task, it can be done by other means.

We do have two options here:

Continue to fight the beast and do our best to cleanse the system, which could still result in a clean install, or just go for a clean install which will wipe the drive and everything will be lost. If it is possible to cleanse the system, it can never be trusted again.

I personally would suggest a clean install though I am more than willing to try our best to cleanse the system.

I'll leave the choice up to you and the owner of the computer.

Let me know what you decide.

I do have to head of to work here very shortly. I'll check back later today after work to see what you have decided to do and we'll go from there.

Have a nice day!

Donna :)
"To achieve the impossible, it is precisely the unthinkable that must be thought."
Tom Robbins

DR M

Hi, Donna.

When Georgia realised that this thing is difficult to deal with, said that format would be the best solution. So, if you think that there is nothing else to be done, I will return the laptop so they can save whatever they want. I don't know if they want me to proceed with the clean install, which is fact will be a Revert to Factory Installation Settings. What do you think about this? Is it safe? Isn't format safer?

Now something about my computer, please...

MBAM scan found a similar PUP with the one found in Georgia's computer (please see number 1, in my previous post). Here is the log:

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Database version: v2013.09.07.01

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16660
DR WHO :: DR-WHO [administrator]

7/9/2013 2:40:33 μμ
mbam-log-2013-09-07 (14-40-33).txt

Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P
Scan options disabled:
Objects scanned: 427829
Time elapsed: 1 hour(s), 7 minute(s), 15 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 1
HKCR\AppID\{72D89EBF-0C5D-4190-91FD-398E45F1D007} (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)


I hope that it is a coincidence. Please, also see my question number 6 in my previous post.

Thank you.

Panos
Grecian Geek

"Count your blessings, remember your prayers..."

"In one of the stars I shall be living. In one of them I shall be laughing. And so it will be as if all the stars will be laughing when you look at the sky at night.. You, only you, will have stars that can laugh..."

DonnaB

QuoteI hope that it is a coincidence.
Yes, I would say that is a coincidence. Do you recall installing any software since you last ran an MBAM scan on your computer? It is not malicious in any way. PUP stands for Potentially Unwanted Program. I see that the managing director for Search Results that distributes the Default Tab toolbar had contacted Malwarebytes to discuss the possibility of their software to removed from their definition database. You can read more about that "friendly" little discussionhere. :)

My response will cover question #'s 1 & 2 in your list of questions above.

As for #3, those are just cookies/tracking cookies and you can read more about 1st and 3rd party cookies here and here.

Ok. Question #4. I have no idea why the MBAM scan freezes at those files. I have those same files on my Windows7 Home Premium 64-bit.  Those files are ok. Why the system is freezing at those files, I do not know unless it is the infection causing this behavior.

Allow me to jump to question #6 and we'll come back to question #5.

Concerning your iPod. Let me check into that further. I've never had an infected iPod, though I do recall that Apple had accidentally shipped iPods with a virus so I know they can become infected. Might just be abe to scan with your on board AV software. For the time being, just set it aside till I find out for sure.

Now for question #5:

You could delete those accounts but I'm sure they will just keep coming back. I'm pretty sure the infection is causing those fictitious accounts to be created.

Yes. Format and clean install would be the best way to go to ensure the system is clean, though you mentioned earlier that you have no Recovery Media for the computer.

Did I see somewhere that this computer is a Dell? Is this the original OS that came installed on this laptop when purchased?

I don't see a D:\ drive in the header of the OTL log and I assume there is no recovery partition for the laptop to be restored to factory condition. Under normal circumstances if no D:\Recovery partition is included there is usually a hidden partition that is accessible through the Dell Recovery Manager that will be found in the Start Menu > All Programs > Dell folder so you can create Recovery discs. Go ahead and have a look to see if there is such a folder.

Other option is to do the best we can to cleanse the infection. Let me know if Georgia wants us to at least try to cleanse the infection.
"To achieve the impossible, it is precisely the unthinkable that must be thought."
Tom Robbins

DR M

Good morning, Donna.

I realised that the infection of the computer was severe. Although I would be impressed (   :dance: ) seing the virus go away, there was no other reason to fight it. The computer had no important files in it, except for some school projects and many downloaded games, so...

... I reverted it to its factory installation settings last night. I don't know about the partition D. I just followed the instrunctions.

I hope that now everything is ok. Is there anything you want me to do, so you can check the result?

P.S. The ipod seems to be ok, although I have no antivirus to check it...
Grecian Geek

"Count your blessings, remember your prayers..."

"In one of the stars I shall be living. In one of them I shall be laughing. And so it will be as if all the stars will be laughing when you look at the sky at night.. You, only you, will have stars that can laugh..."