Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Odepřený přístup k Antivirům

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
OWN3D
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 29 bře 2014 14:07

Odepřený přístup k Antivirům

#1 Příspěvek od OWN3D »

Dobrý den, nelze mi spustit žádný antivir :shock: , ať už Norton, Arovax (u obou je odepřen přístup) , když jsem si stáhl jiné antiviry to samé (u instalace je odepřen přístup, nebo windows nemá přístup k určenému zařízení). Díky za radu.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Odepřený přístup k Antivirům

#2 Příspěvek od vyosek »

Zdravim :)

:arrow: Stahnete SecurityCheck http://screen317.spywareinfoforum.org/SecurityCheck.exe
  • Ulozte nejlepe na Plochu
  • Spustte tradicne dvouklikem a postupujte dle pokynu utility
  • Po dokonceni skenu se vytvori a otevre log, ten mi sem vlozte
:arrow: Dejte log z RSIT http://forum.viry.cz/viewtopic.php?f=24&t=130784
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

OWN3D
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 29 bře 2014 14:07

Re: Odepřený přístup k Antivirům

#3 Příspěvek od OWN3D »

Při spouštění se to znovu ukázalo, ale nakonec dokončilo.
Logfile of random's system information tool 1.09 (written by random/random)
Run by Administrator at 2014-03-29 14:58:19
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 20 GB (19%) free of 102 GB
Total RAM: 2046 MB (70% free)


======Scheduled tasks folder======

C:\WINDOWS\tasks\1-Click Maintenance.job
C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-JIRKA-B0E4AC879-Administrator.job
C:\WINDOWS\tasks\Automatická údržba.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\Norton Security Scan for Administrator.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\akhpfps6.default-1382997821843

prefs.js - "browser.search.useDBForOrder" - "false"
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"

"{20a82645-c095-46ed-80e3-08825760534b}"=c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"{1E73965B-8B48-48be-9C8D-68B920ABC1C4}"=C:\Program Files\AVG\AVG2012\Firefox4\
"avg@toolbar"=C:\Documents and Settings\All Users\Data aplikací\AVG Secure Search\FireFoxExt\18.0.5.292
"jqs@sun.com"=C:\Program Files\Java\jre6\lib\deploy\jqs\ff


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 12.0.0.77 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\WINDOWS\system32\Adobe\Director\np32dsw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin]
"Description"=
"Path"=C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\18.0.5\\npsitesafety.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files\Google\Picasa3\npPicasa3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MI1933~1\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MI1933~1\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=1.1.11]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}

C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\akhpfps6.default-1382997821843\extensions\
battlefieldheroespatcher@ea.com
sitefinder@sitefinder.com
{ACAA314B-EEBA-48e4-AD47-84E31C44796C}

C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\akhpfps6.default-1382997821843\searchplugins\
buenosearch.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG2012\avgssie.dll [2012-10-15 1417336]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MI1933~1\Office14\GROOVEEX.DLL [2012-08-16 4171424]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2012-02-25 325408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3CF7606-E683-4375-A372-96B75DA0AEF7}]
GdfrDUEn Class - C:\Program Files\Get Styles\enlbrdr.dll [2010-02-11 185856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2014-03-26 194504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09 4502400]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll [2013-10-11 1001936]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MI1933~1\Office14\URLREDIR.DLL [2010-12-21 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
Bing Bar Helper - C:\Program Files\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-11 1431712]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{daf5b34c-1aa3-4c33-ae24-766a370635d2}]
KMP Media Toolbar - C:\Program Files\kmpmediatoolbar\searchresultsDx.dll [2012-03-22 87008]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2012-02-25 42272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2012-02-25 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{95B7759C-8C7F-4BF1-B163-73684A933233}
{daf5b34c-1aa3-4c33-ae24-766a370635d2} - KMP Media Toolbar - C:\Program Files\kmpmediatoolbar\searchresultsDx.dll [2012-03-22 87008]
{8dcb7100-df86-4384-8842-8fa844297b3f} - Bing Bar - C:\Program Files\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-11 1431712]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2014-03-26 194504]
{CCC7B159-1D8C-11E3-B2AD-F3EF3D58318D} - SiteFinder - C:\Program Files\SiteFinder\SiteFinder.dll [2014-03-06 367104]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"PES"=C:\Program Files\Pro Evolution Soccer 2010\pes.exe []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2011-11-04 39408]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2013-11-14 20584608]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"PES"=C:\Program Files\Pro Evolution Soccer 2010\pes.exe []
"Windows Updater"=C:\WINDOWS\system32\WinUpd\updsrv.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

C:\Documents and Settings\Administrator\Nabídka Start\Programy\Po spuštění
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
RocketDock.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
_uninst_77502439.lnk - C:\Documents and Settings\Administrator\Local Settings\temp\_uninst_77502439.bat

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2010-02-11 155648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
WgaLogon.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MI1933~1\Office14\GROOVEEX.DLL [2012-08-16 4171424]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLUA"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\Program Files\EA Games\Battlefield Heroes\BFHeroes.exe"="C:\Program Files\EA Games\Battlefield Heroes\BFHeroes.exe:*:Enabled:Battlefield Heroes"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Google\Chrome\Application\chrome.exe"="C:\Program Files\Google\Chrome\Application\chrome.exe:*:Enabled:Google Chrome"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\Documents and Settings\Administrator\Data aplikací\Seznam.cz\bin\MiniBrowser.exe"="C:\Documents and Settings\Administrator\Data aplikací\Seznam.cz\bin\MiniBrowser.exe:*:Enabled:Mini www prohlížec pro webové aplikace (pomocník poštáka)"
"C:\Program Files\Internet Explorer\iexplore.exe"="C:\Program Files\Internet Explorer\iexplore.exe:*:Disabled:Internet Explorer"
"C:\Program Files\Steam\Steam.exe"="C:\Program Files\Steam\Steam.exe:*:Enabled:Steam"
"C:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe"="C:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe:*:Enabled:Ubisoft Game Launcher"
"C:\Program Files\Steam\SteamApps\common\Half-Life\hl.exe"="C:\Program Files\Steam\SteamApps\common\Half-Life\hl.exe:*:Enabled:Counter-Strike"
"C:\Program Files\AVG\AVG2012\avgnsx.exe"="C:\Program Files\AVG\AVG2012\avgnsx.exe:*:Enabled:Webový štít"
"C:\Program Files\AVG\AVG2012\avgdiagex.exe"="C:\Program Files\AVG\AVG2012\avgdiagex.exe:*:Enabled:AVG Diagnostika 2012"
"C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe"="C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe:*:Enabled:Dota 2"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\PANDORA.TV\PanService\PandoraService.exe"="C:\Program Files\PANDORA.TV\PanService\PandoraService.exe:*:Enabled:PandoraService"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvastSvc.exe]
"Debugger="nqij.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvastUI.exe]
"Debugger="nqij.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avcenter.exe]
"Debugger="nqij.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avconfig.exe]
"Debugger="nqij.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgcsrvx.exe]
"Debugger="nqij.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgidsagent.exe]
"Debugger="nqij.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgnsx.exe]
"Debugger="nqij.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgnt.exe]
"Debugger="nqij.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgrsx.exe]
"Debugger="nqij.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avguard.exe]
"Debugger="nqij.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgui.exe]
"Debugger="nqij.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgwdsvc.exe]
"Debugger="nqij.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp.exe]
"Debugger="nqij.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avscan.exe]
"Debugger="nqij.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdagent.exe]
"Debugger="nqij.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\blindman.exe]
"Debugger="nqij.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccuac.exe]
"Debugger="nqij.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ComboFix.exe]
"Debugger="nqij.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egui.exe]
"Debugger="nqij.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hijackthis.exe]
"Debugger="nqij.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\instup.exe]
"Debugger="nqij.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\keyscrambler.exe]
"Debugger="nqij.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\loggingserver.exe]
"Debugger="nqij.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mbam.exe]
"Debugger="nqij.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mbamgui.exe]
"Debugger="nqij.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mbampt.exe]
"Debugger="nqij.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mbamscheduler.exe]
"Debugger="nqij.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mbamservice.exe]
"Debugger="nqij.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MpCmdRun.exe]
"Debugger="nqij.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSASCui.exe]
"Debugger="nqij.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MsMpEng.exe]
"Debugger="nqij.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe]
"Debugger="nqij.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rstrui.exe]
"Debugger="nqij.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SDFiles.exe]
"Debugger="nqij.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SDMain.exe]
"Debugger="nqij.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SDWinSec.exe]
"Debugger="nqij.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\spybotsd.exe]
"Debugger="nqij.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ToolbarUpdater.exe]
"Debugger="nqij.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wireshark.exe]
"Debugger="nqij.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zlclient.exe]
"Debugger="nqij.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.VP60"=vp6vfw.dll
"vidc.VP61"=vp6vfw.dll
"msacm.vorbis"=vorbis.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"VIDC.FPS1"=frapsvid.dll
"vidc.VP62"=vp6vfw.dll

======File associations======

.reg - open - "regedit.exe" "%1"
.scr - config - "%1" %*

======List of files/folders created in the last 1 month======

2014-03-29 14:54:46 ----D---- C:\rsit
2014-03-29 14:54:46 ----D---- C:\Program Files\trend micro
2014-03-29 13:41:26 ----A---- C:\WINDOWS\ntbtlog.txt
2014-03-29 13:26:45 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2014-03-29 13:16:31 ----D---- C:\Program Files\SiteFinder
2014-03-29 13:16:17 ----D---- C:\Documents and Settings\Administrator\Data aplikací\SimilarSites
2014-03-29 12:50:39 ----A---- C:\Documents and Settings\Administrator\Data aplikací\msconfig.ini
2014-03-29 12:50:38 ----SHD---- C:\WINDOWS\system32\NT Kernel
2014-03-29 12:50:37 ----A---- C:\Documents and Settings\Administrator\Data aplikací\Dota2.bat
2014-03-29 12:10:44 ----D---- C:\Program Files\Mozilla Firefox
2014-03-23 13:27:25 ----SHD---- C:\Config.Msi
2014-03-12 00:27:36 ----D---- C:\Program Files\NHL 09

======List of files/folders modified in the last 1 month======

2014-03-29 14:54:46 ----D---- C:\Program Files
2014-03-29 14:50:02 ----D---- C:\Documents and Settings\Administrator\Data aplikací\AIMP3
2014-03-29 14:33:09 ----A---- C:\WINDOWS\wincmd.ini
2014-03-29 14:32:39 ----D---- C:\Staženo
2014-03-29 14:05:46 ----D---- C:\WINDOWS\system32
2014-03-29 14:05:46 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2014-03-29 14:01:48 ----D---- C:\WINDOWS\Temp
2014-03-29 14:01:24 ----D---- C:\WINDOWS
2014-03-29 14:00:28 ----D---- C:\WINDOWS\system32\CatRoot2
2014-03-29 13:43:07 ----D---- C:\WINDOWS\system32\drivers
2014-03-29 13:22:50 ----A---- C:\WINDOWS\system.ini
2014-03-29 13:04:08 ----D---- C:\Documents and Settings\Administrator\Data aplikací\DAEMON Tools Lite
2014-03-29 13:04:07 ----D---- C:\Program Files\Steam
2014-03-29 13:04:06 ----D---- C:\Documents and Settings\Administrator\Data aplikací\uTorrent
2014-03-29 13:02:28 ----D---- C:\WINDOWS\Minidump
2014-03-29 13:02:28 ----D---- C:\WINDOWS\Logs
2014-03-29 12:53:58 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Skype
2014-03-29 12:53:30 ----D---- C:\Program Files\Mozilla Maintenance Service
2014-03-29 12:51:54 ----A---- C:\WINDOWS\NeroDigital.ini
2014-03-29 12:51:51 ----D---- C:\WINDOWS\Prefetch
2014-03-26 17:20:30 ----SHD---- C:\WINDOWS\Installer
2014-03-23 15:45:20 ----A---- C:\WINDOWS\system32\PnkBstrB.exe
2014-03-23 13:34:30 ----D---- C:\WINDOWS\WinSxS
2014-03-23 10:03:11 ----D---- C:\Program Files\Arovax AntiSpyware
2014-03-21 08:20:29 ----D---- C:\WINDOWS\system32\cache
2014-03-21 08:20:27 ----D---- C:\Program Files\AVG Secure Search
2014-03-13 08:02:36 ----D---- C:\Documents and Settings\Administrator\Data aplikací\ICQ
2014-03-12 19:06:09 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2014-03-12 09:48:06 ----D---- C:\WINDOWS\system32\DirectX
2014-03-12 09:48:05 ----HD---- C:\WINDOWS\inf
2014-03-12 09:47:48 ----RSD---- C:\WINDOWS\assembly
2014-03-11 07:28:09 ----HD---- C:\Program Files\InstallShield Installation Information
2014-03-09 07:29:18 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Sony Online Entertainment
2014-03-02 17:29:27 ----D---- C:\Documents and Settings\All Users\Data aplikací\AVG Secure Search

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AVGIDSHX;AVGIDSHX; C:\WINDOWS\system32\DRIVERS\avgidshx.sys [2012-04-19 24896]
R0 imagedrv;imagedrv; C:\WINDOWS\System32\Drivers\imagedrv.sys [2005-08-15 5888]
R0 imagesrv;imagesrv; C:\WINDOWS\system32\DRIVERS\imagesrv.sys [2005-08-15 127488]
R0 prohlp02;StarForce Protection Helper Driver v2; C:\WINDOWS\System32\drivers\prohlp02.sys [2004-09-03 115680]
R0 prosync1;StarForce Protection Synchronization Driver v1; C:\WINDOWS\System32\drivers\prosync1.sys [2004-07-19 7040]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2009-04-28 44944]
R0 sfdrv01;StarForce Protection Environment Driver (version 1.x); C:\WINDOWS\System32\drivers\sfdrv01.sys [2005-08-10 50688]
R0 sfhlp01;StarForce Protection Helper Driver; C:\WINDOWS\System32\drivers\sfhlp01.sys [2003-12-01 4832]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:\WINDOWS\System32\drivers\sfhlp02.sys [2005-05-16 6656]
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x); C:\WINDOWS\System32\drivers\sfsync03.sys [2005-12-06 35328]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2012-06-08 477240]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 Avgtdix;AVG TDI Driver; C:\WINDOWS\system32\DRIVERS\avgtdix.sys [2013-04-11 302368]
R1 avgtp;avgtp; \??\C:\WINDOWS\system32\drivers\avgtpx86.sys []
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys [2012-12-20 242240]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys []
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 oreans32;oreans32; \??\C:\WINDOWS\system32\drivers\oreans32.sys []
R1 prodrv06;StarForce Protection Environment Driver v6; C:\WINDOWS\System32\drivers\prodrv06.sys [2004-09-03 54368]
R1 Tcpip6;Ovladač protokolu Microsoft IPv6; C:\WINDOWS\system32\DRIVERS\tcpip6.sys [2010-02-11 226880]
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2009-12-10 281760]
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2009-12-10 25888]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2010-02-11 3565056]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2009-11-03 5940736]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2009-07-28 143360]
R3 tunmp;Microsoft Tun Miniport Adapter Driver; C:\WINDOWS\system32\DRIVERS\tunmp.sys [2008-04-14 12288]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S0 vmci;VMware VMCI Bus Driver; C:\WINDOWS\system32\DRIVERS\vmci.sys []
S1 InCDPass;InCDPass; C:\WINDOWS\system32\drivers\InCDPass.sys []
S1 InCDRm;InCD Reader; C:\WINDOWS\system32\drivers\InCDRm.sys []
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S3 Ambfilt;Ambfilt; C:\WINDOWS\system32\drivers\Ambfilt.sys [2008-08-05 1684736]
S3 ao7xfjlg;ao7xfjlg; C:\WINDOWS\system32\drivers\ao7xfjlg.sys []
S3 catchme;catchme; \??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\catchme.sys []
S3 Cbimlau;Cbimlau; C:\WINDOWS\system32\drivers\nwlnkspx.sys [2001-10-25 55936]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-07-09 16384]
S3 cdiskdun;cdiskdun; \??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cdiskdun.sys []
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2009-03-18 26176]
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
S3 Monfilt;Monfilt; C:\WINDOWS\system32\drivers\Monfilt.sys [2006-01-04 1389056]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2002-12-11 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-07-09 83968]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-07-09 10112]
S3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2010-02-03 47360]
S3 SCREAMINGBDRIVER;Screaming Bee Audio; C:\WINDOWS\system32\drivers\ScreamingBAudio.sys [2010-07-01 34896]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-07-09 10880]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-07-09 14976]
S3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 usbvideo;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-14 121984]
S3 VMnetAdapter;VMware Virtual Ethernet Adapter Driver; C:\WINDOWS\system32\DRIVERS\vmnetadapter.sys []
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-03-27 503008]
S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-07-09 18688]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S3 xusb21;Xbox 360 Wireless Receiver Driver Service 21; C:\WINDOWS\system32\DRIVERS\xusb21.sys [2009-09-09 62424]
S4 InCDFs;InCD File System; C:\WINDOWS\system32\drivers\InCDFs.sys []
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 6to4;Pomocná služba protokolu IPv6; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2010-02-11 602112]
R2 Fabs;FABS - Helping agent for MAGIX media database; C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe [2009-08-27 1253376]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2012-02-25 153376]
R2 LicCtrlService;LicCtrl Service; C:\WINDOWS\runservice.exe [2011-08-05 2560]
R2 PanService;PandoraService; C:\Program Files\PANDORA.TV\PanService\PandoraService.exe [2012-06-22 625816]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2013-05-02 76888]
R2 Skype C2C Service;Skype C2C Service; C:\Documents [2014-02-07 49511]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service; C:\WINDOWS\System32\TUProgSt.exe [2010-01-31 604488]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 BBUpdate;BBUpdate; C:\Program Files\Microsoft\BingBar\7.3.132.0\SeaPort.exe [2014-03-11 247968]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2010-02-10 593920]
S2 avgwd;AVG WatchDog; C:\Program Files\AVG\AVG2012\avgwdsvc.exe [2012-02-14 193288]
S2 BBSvc;BingBar Service; C:\Program Files\Microsoft\BingBar\7.3.132.0\BBSvc.exe [2014-03-11 193696]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-11-04 136176]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2013-09-05 171680]
S2 vToolbarUpdater18.0.5;vToolbarUpdater18.0.5; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.0.5\ToolbarUpdater.exe [2014-03-21 1771032]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2011-04-07 72704]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-12 257928]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance; C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe [2008-08-07 3276800]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-11-04 136176]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2012-08-14 194032]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2012-09-20 30785672]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2014-03-29 119408]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S3 SwitchBoard;SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; C:\WINDOWS\System32\TuneUpDefragService.exe [2010-01-31 361288]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Odepřený přístup k Antivirům

#4 Příspěvek od vyosek »

:arrow: Stahnete RKill http://download.bleepingcomputer.com/grinler/rkill.com PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

OWN3D
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 29 bře 2014 14:07

Re: Odepřený přístup k Antivirům

#5 Příspěvek od OWN3D »

Když zapnu Rkill, PC se po chvilce restartuje.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Odepřený přístup k Antivirům

#6 Příspěvek od vyosek »

Zkuste jej aplikovat v nouzovem rezimu
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

OWN3D
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 29 bře 2014 14:07

Re: Odepřený přístup k Antivirům

#7 Příspěvek od OWN3D »

V Nouzovém řežimu to dělá to samé. :cry:

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Odepřený přístup k Antivirům

#8 Příspěvek od vyosek »

Zkuste tedy spustit ComboFix
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

OWN3D
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 29 bře 2014 14:07

Re: Odepřený přístup k Antivirům

#9 Příspěvek od OWN3D »

Spustím ComboFix jako Administrátor a vyskočí Error (Systém Windows nemůže nalézt)

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Odepřený přístup k Antivirům

#10 Příspěvek od vyosek »

V nouzovem rezimu znovu stahnete CF a zkuste spustit
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

OWN3D
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 29 bře 2014 14:07

Re: Odepřený přístup k Antivirům

#11 Příspěvek od OWN3D »

Znovu Error (Zařízení připojené k systému nefunguje), je to začarovaný kruh :40:

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Odepřený přístup k Antivirům

#12 Příspěvek od vyosek »

:arrow: Stahnete Malwarebytes Anti-Rootkit http://www.bleepingcomputer.com/downloa ... i-rootkit/
  • Ulozte nejlepe na Plochu a rozbalte
  • Spustte kliknutim na mbar
  • Nyni postupne kliknete na Next a Update
  • Po dokonceni update (aktualizace) databaze kliknete opet na Next
  • Nechte zaskrtnute vsechny tri moznosti a klinete na Scan cimz spustite prohledavani PC
  • Po dokonceni skenu (cca 5 minutek) zkontrolujte, zda-li je u vsech nalezu (samozrejme pokud budou) zatrzitko
  • Tez zkontrolujte, jetsli je zatrzitko u Create Restore point
  • Nyni kliknete na CleanUp cimz nalezenou infekci odstranime
  • PC bude restartovan
  • Slozka mbar by mela obsahovat log (a zrejme se i sam otevre) mbar-log-rok-mesic-den (hodina-minuta-sekunda).txt, ten mi sem dejte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

OWN3D
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 29 bře 2014 14:07

Re: Odepřený přístup k Antivirům

#13 Příspěvek od OWN3D »

Konečně něco zabralo :D

Malwarebytes Anti-Rootkit BETA 1.07.0.1009
www.malwarebytes.org

Database version: v2014.03.30.02

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
:: JIRKA-B0E4AC879 [administrator]

30.3.2014 10:38:47
mbar-log-2014-03-30 (10-38-47).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Kernel memory modifications detected. Deep Anti-Rootkit Scan engaged.
Objects scanned: 280043
Time elapsed: 21 minute(s), 29 second(s)

Memory Processes Detected: 2
C:\WINDOWS\system32\NT Kernel\NTKernel.exe (Backdoor.Agent.E) -> 948 -> Delete on reboot.
C:\WINDOWS\system32\NT Kernel\NTKernel.exe (Backdoor.Agent.E) -> 2020 -> Delete on reboot.

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 30
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\NTKERNEL.EXE (Backdoor.Agent.E) -> Delete on reboot.
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\avcenter.exe (Security.Hijack) -> Delete on reboot.
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\avconfig.exe (Security.Hijack) -> Delete on reboot.
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\avgcsrvx.exe (Security.Hijack) -> Delete on reboot.
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\avgnsx.exe (Security.Hijack) -> Delete on reboot.
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\avgnt.exe (Security.Hijack) -> Delete on reboot.
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\avgrsx.exe (Security.Hijack) -> Delete on reboot.
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\avguard.exe (Security.Hijack) -> Delete on reboot.
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\avgui.exe (Security.Hijack) -> Delete on reboot.
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\avgwdsvc.exe (Security.Hijack) -> Delete on reboot.
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\avscan.exe (Security.Hijack) -> Delete on reboot.
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\ccuac.exe (Security.Hijack) -> Delete on reboot.
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\ComboFix.exe (Security.Hijack) -> Delete on reboot.
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\hijackthis.exe (Security.Hijack) -> Delete on reboot.
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\keyscrambler.exe (Security.Hijack) -> Delete on reboot.
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\mbam.exe (Security.Hijack) -> Delete on reboot.
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\mbamgui.exe (Security.Hijack) -> Delete on reboot.
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\mbampt.exe (Security.Hijack) -> Delete on reboot.
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\mbamscheduler.exe (Security.Hijack) -> Delete on reboot.
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\mbamservice.exe (Security.Hijack) -> Delete on reboot.
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\MpCmdRun.exe (Security.Hijack) -> Delete on reboot.
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\MSASCui.exe (Security.Hijack) -> Delete on reboot.
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\MsMpEng.exe (Security.Hijack) -> Delete on reboot.
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\msseces.exe (Security.Hijack) -> Delete on reboot.
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\rstrui.exe (Security.Hijack) -> Delete on reboot.
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\spybotsd.exe (Security.Hijack) -> Delete on reboot.
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\wireshark.exe (Security.Hijack) -> Delete on reboot.
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\zlclient.exe (Security.Hijack) -> Delete on reboot.
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\AVASTSVC.EXE (Security.Hijack) -> Delete on reboot.
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\AVP.EXE (Security.Hijack) -> Delete on reboot.

Registry Values Detected: 9
HKCU\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON|shell (Backdoor.Agent.E) -> Data: explorer.exe,"C:\WINDOWS\system32\NT Kernel\NTKernel.exe" -> Delete on reboot.
HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN|Windows Updater (Backdoor.PWin.Gen) -> Data: C:\WINDOWS\system32\WinUpd\updsrv.exe -> Delete on reboot.
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\AVASTSVC.EXE|Debugger (Security.Hijack) -> Data: nqij.exe -> Delete on reboot.
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\AVASTUI.EXE|Debugger (Security.Hijack) -> Data: nqij.exe -> Delete on reboot.
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\AVGIDSAGENT.EXE|Debugger (Hijack.Security) -> Data: nqij.exe -> Delete on reboot.
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\AVP.EXE|Debugger (Security.Hijack) -> Data: nqij.exe -> Delete on reboot.
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\BDAGENT.EXE|Debugger (Security.Hijack) -> Data: nqij.exe -> Delete on reboot.
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\EGUI.EXE|Debugger (Security.Hijack) -> Data: nqij.exe -> Delete on reboot.
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\INSTUP.EXE|Debugger (Hijack.Security) -> Data: nqij.exe -> Delete on reboot.

Registry Data Items Detected: 5
HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page (Hijack.StartPage) -> Bad: (http://www.buenosearch.com/?babsrc=HP_s ... 2&tsp=5201) Good: (http://www.google.com) -> Replace on reboot.
HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL (Hijack.StartPage) -> Bad: (http://search13.net/) Good: (http://www.Google.com) -> Replace on reboot.
HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|CustomizeSearch (Hijack.SearchPage) -> Bad: (http://search13.net/) Good: (http://www.Google.com/) -> Replace on reboot.
HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page (Hijack.StartPage) -> Bad: (http://searchab.com/?aff=7&uid=a6ffa236 ... 1d7da8044a) Good: (http://www.google.com) -> Replace on reboot.
HKCR\regfile\shell\open\command| (Broken.OpenCommand) -> Bad: ("regedit.exe" "%1") Good: (regedit.exe "%1") -> Replace on reboot.

Folders Detected: 7
C:\WINDOWS\system32\28463 (Keylogger.Ardamax) -> Delete on reboot.
C:\RECYCLER\S-1-5-18\$b8e3fed19c34d60c2fa9421e6dffd6b2\U (Trojan.Siredef.C) -> Delete on reboot.
C:\RECYCLER\S-1-5-21-57989841-616249376-839522115-500\$b8e3fed19c34d60c2fa9421e6dffd6b2\U (Trojan.Siredef.C) -> Delete on reboot.
C:\RECYCLER\S-1-5-18\$b8e3fed19c34d60c2fa9421e6dffd6b2\L (Trojan.Siredef.C) -> Delete on reboot.
C:\RECYCLER\S-1-5-21-57989841-616249376-839522115-500\$b8e3fed19c34d60c2fa9421e6dffd6b2\L (Trojan.Siredef.C) -> Delete on reboot.
C:\RECYCLER\S-1-5-18\$b8e3fed19c34d60c2fa9421e6dffd6b2 (Trojan.Siredef.C) -> Delete on reboot.
C:\RECYCLER\S-1-5-21-57989841-616249376-839522115-500\$b8e3fed19c34d60c2fa9421e6dffd6b2 (Trojan.Siredef.C) -> Delete on reboot.

Files Detected: 1678
C:\RECYCLER\S-1-5-18\$b8e3fed19c34d60c2fa9421e6dffd6b2\@ (Trojan.Siredef.C) -> Delete on reboot.
C:\RECYCLER\S-1-5-21-57989841-616249376-839522115-500\$b8e3fed19c34d60c2fa9421e6dffd6b2\@ (Trojan.Siredef.C) -> Delete on reboot.
C:\Documents and Settings\Administrator\7658354235994425565\winsvc.exe (Trojan.IRCBot) -> Delete on reboot.
C:\RECYCLER\S-1-5-18\$b8e3fed19c34d60c2fa9421e6dffd6b2\L\00000004.@ (Trojan.Siredef.C) -> Delete on reboot.
C:\RECYCLER\S-1-5-18\$b8e3fed19c34d60c2fa9421e6dffd6b2\L\201d3dde (Trojan.Siredef.C) -> Delete on reboot.
C:\RECYCLER\S-1-5-18\$b8e3fed19c34d60c2fa9421e6dffd6b2\L\76603ac3 (Trojan.Siredef.C) -> Delete on reboot.
C:\RECYCLER\S-1-5-18\$b8e3fed19c34d60c2fa9421e6dffd6b2\U\00000004.@ (Trojan.0Access) -> Delete on reboot.
C:\RECYCLER\S-1-5-18\$b8e3fed19c34d60c2fa9421e6dffd6b2\U\00000008.@ (Trojan.0Access) -> Delete on reboot.
C:\RECYCLER\S-1-5-18\$b8e3fed19c34d60c2fa9421e6dffd6b2\U\000000cb.@ (Trojan.0Access) -> Delete on reboot.
C:\RECYCLER\S-1-5-18\$b8e3fed19c34d60c2fa9421e6dffd6b2\U\80000000.@ (Trojan.0Access) -> Delete on reboot.
C:\WINDOWS\system32\NT Kernel\NTKernel.exe (Backdoor.Agent.E) -> Delete on reboot.
C:\Documents and Settings\Administrator\Data aplikací\addon.dat (Malware.Trace) -> Delete on reboot.
C:\Documents and Settings\Administrator\Data aplikací\logs.dat (Bifrose.Trace) -> Delete on reboot.
C:\Documents and Settings\Administrator\Data aplikací\Skype\Phone\Skype.exe (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\Administrator\Data aplikací\msconfig.ini (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\Administrator\Data aplikací\winsvcns.sys (Malware.Trace) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_13_2010__22_12_38.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_13_2010__22_22_38.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_13_2010__22_32_38.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_13_2010__22_42_38.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_14_2010__15_36_59.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_14_2010__15_46_59.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_14_2010__15_56_59.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_14_2010__16_07_08.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_14_2010__16_17_08.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_14_2010__16_27_08.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_14_2010__16_37_08.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_14_2010__16_57_08.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_14_2010__17_07_08.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_14_2010__17_17_08.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_14_2010__17_27_08.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_14_2010__17_37_08.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_14_2010__18_28_38.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_14_2010__18_38_38.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_14_2010__19_01_03.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_14_2010__19_39_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_14_2010__19_49_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_14_2010__19_59_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_14_2010__20_09_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_14_2010__20_19_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_14_2010__20_39_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_14_2010__20_59_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_15_2010__11_11_45.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_15_2010__11_41_45.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_15_2010__11_51_45.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_15_2010__12_01_45.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_15_2010__12_11_45.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_15_2010__12_21_45.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_15_2010__12_41_45.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_15_2010__13_01_45.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_15_2010__13_21_45.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_15_2010__13_31_45.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_15_2010__13_41_46.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_15_2010__13_51_46.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_15_2010__21_15_14.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_15_2010__21_25_14.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_15_2010__21_45_14.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_15_2010__21_55_14.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_15_2010__22_05_14.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_15_2010__22_15_14.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_15_2010__22_25_14.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_15_2010__22_35_14.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_15_2010__22_45_14.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_16_2010__06_37_50.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_16_2010__06_47_51.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_16_2010__07_07_51.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_16_2010__07_17_51.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_16_2010__07_27_51.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_16_2010__08_49_57.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_16_2010__13_42_43.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_16_2010__13_52_43.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_16_2010__17_12_44.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_16_2010__19_52_44.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_16_2010__20_12_44.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_16_2010__20_22_44.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_16_2010__20_32_44.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_16_2010__20_42_44.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_16_2010__20_52_44.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_16_2010__21_02_44.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_16_2010__21_22_44.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_16_2010__21_32_44.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_16_2010__22_02_44.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_16_2010__22_12_45.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_16_2010__22_22_45.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_16_2010__22_52_45.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_16_2010__23_02_45.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_16_2010__23_12_45.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_17_2010__07_48_44.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_17_2010__07_58_44.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_17_2010__08_12_30.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_17_2010__08_22_30.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_17_2010__08_32_30.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_17_2010__08_42_30.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_17_2010__09_02_30.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_17_2010__09_12_30.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_17_2010__09_22_30.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_17_2010__09_32_30.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_17_2010__09_42_30.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_17_2010__09_52_30.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_17_2010__10_02_30.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_17_2010__10_12_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_17_2010__11_22_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_17_2010__12_32_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_17_2010__12_42_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_17_2010__12_52_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_17_2010__13_02_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_17_2010__13_12_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_17_2010__20_35_20.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_18_2010__15_14_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_18_2010__17_34_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_18_2010__17_44_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_18_2010__18_04_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_18_2010__18_24_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_18_2010__18_34_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_18_2010__18_44_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_18_2010__18_54_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_18_2010__19_04_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_18_2010__19_14_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_18_2010__19_24_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_18_2010__19_34_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_18_2010__19_54_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_18_2010__20_14_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_18_2010__20_24_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_18_2010__20_56_59.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_18_2010__21_07_00.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_18_2010__21_27_00.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_18_2010__21_37_00.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_18_2010__21_47_00.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_18_2010__22_07_00.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_18_2010__22_27_00.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_18_2010__22_37_00.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_18_2010__22_47_00.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_18_2010__22_57_00.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__07_26_48.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__07_46_48.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__08_46_48.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__10_16_48.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__10_26_48.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__10_36_48.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__11_06_48.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__11_16_48.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__11_26_48.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__11_36_48.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__11_46_48.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__11_56_48.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__12_06_48.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__13_06_49.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__13_46_49.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__14_06_49.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__14_26_49.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__14_46_49.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__15_36_49.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__16_16_49.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__16_36_49.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__16_56_49.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__17_06_49.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__17_16_49.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__17_46_49.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__17_56_49.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__18_16_50.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__19_56_50.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__20_26_50.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__20_36_50.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__21_26_50.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__21_46_50.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__22_06_50.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__22_16_50.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__22_46_50.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__22_56_50.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__23_06_50.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_16_2010__11_32_43.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_16_2010__14_02_43.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_16_2010__16_02_44.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_16_2010__17_42_44.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_16_2010__21_42_44.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_17_2010__07_38_44.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_17_2010__10_22_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_18_2010__17_24_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_18_2010__20_44_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__06_26_48.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__08_56_48.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__13_26_49.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__17_26_49.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__08_10_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__08_20_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__08_30_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__08_40_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__08_50_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__09_00_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__09_10_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__09_20_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__09_30_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__09_40_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__10_30_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__10_50_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__11_10_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__11_30_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__11_40_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__11_50_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__12_10_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__12_20_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__12_40_23.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__13_40_23.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__13_50_23.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__14_10_23.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__14_30_23.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__15_10_23.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__15_20_23.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__15_30_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__15_40_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__15_50_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__16_00_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__16_30_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__16_40_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__16_50_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__17_10_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__17_20_25.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__17_50_26.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__19_00_26.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__19_10_26.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__19_20_26.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__19_40_26.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__20_00_26.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__20_20_26.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__20_40_26.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__20_50_27.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__21_20_28.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__21_30_28.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__21_40_28.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__21_50_28.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__22_00_28.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__22_30_28.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__23_00_28.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__23_10_28.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_21_2010__08_20_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_21_2010__12_40_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_21_2010__13_00_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_21_2010__13_20_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_21_2010__13_40_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_21_2010__14_00_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_21_2010__14_10_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_21_2010__14_20_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_21_2010__14_30_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_21_2010__14_50_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_21_2010__15_10_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_21_2010__15_30_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_21_2010__15_50_55.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_21_2010__16_40_55.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_21_2010__17_00_55.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_21_2010__17_40_55.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_21_2010__18_20_55.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_21_2010__18_50_55.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_21_2010__19_10_55.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_21_2010__19_50_55.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_21_2010__20_10_55.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_21_2010__20_30_55.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_21_2010__20_40_55.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_21_2010__21_00_55.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_21_2010__21_30_56.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_21_2010__21_40_56.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_21_2010__22_00_56.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_21_2010__22_30_56.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_22_2010__07_16_38.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_22_2010__07_36_38.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_22_2010__07_46_38.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_22_2010__11_11_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_22_2010__11_31_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_22_2010__12_21_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_22_2010__13_21_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_22_2010__13_41_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_22_2010__13_51_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_22_2010__14_11_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_22_2010__14_31_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_22_2010__14_51_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_22_2010__15_01_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_22_2010__16_01_23.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_22_2010__17_01_23.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_22_2010__17_21_23.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_22_2010__17_31_23.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_22_2010__17_41_23.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_22_2010__18_11_23.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_22_2010__18_21_23.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_22_2010__18_31_23.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_22_2010__19_21_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_22_2010__19_31_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_22_2010__20_01_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_22_2010__20_51_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_22_2010__21_01_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_22_2010__21_11_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_22_2010__21_21_25.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_22_2010__22_01_25.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_22_2010__22_11_25.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_22_2010__22_21_25.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_22_2010__22_31_25.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_23_2010__08_40_44.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_23_2010__08_50_44.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_23_2010__09_10_44.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_23_2010__09_40_44.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_23_2010__09_50_44.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_23_2010__10_50_45.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_23_2010__11_00_45.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_23_2010__11_10_45.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_23_2010__11_20_45.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_23_2010__11_40_45.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_23_2010__12_00_45.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_23_2010__12_10_45.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_23_2010__14_10_46.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_23_2010__15_00_46.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_23_2010__15_20_46.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_23_2010__15_40_46.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_23_2010__15_50_46.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_23_2010__16_00_46.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_23_2010__16_30_46.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_23_2010__16_40_47.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_23_2010__16_50_47.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_23_2010__17_20_47.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_23_2010__18_00_47.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__08_00_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__11_00_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__14_50_23.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__18_10_26.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_20_2010__22_40_28.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_21_2010__09_00_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_21_2010__13_50_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_21_2010__17_20_55.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_21_2010__22_10_56.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_22_2010__08_06_38.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_22_2010__10_51_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_22_2010__15_11_23.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_22_2010__19_41_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_23_2010__09_00_44.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_23_2010__20_30_47.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_23_2010__21_00_47.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_23_2010__21_10_47.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_23_2010__21_40_47.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_23_2010__21_50_47.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_23_2010__22_00_47.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_23_2010__22_20_47.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_24_2010__09_54_47.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_24_2010__10_44_47.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_24_2010__10_54_47.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_24_2010__11_14_47.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_24_2010__11_44_47.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_24_2010__12_54_48.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_24_2010__13_14_48.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_24_2010__13_34_48.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_24_2010__13_54_48.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_24_2010__14_44_48.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_24_2010__15_04_48.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_24_2010__15_24_48.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_24_2010__16_04_48.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_24_2010__16_24_48.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_24_2010__21_17_44.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_24_2010__21_27_44.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_24_2010__21_37_44.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_25_2010__17_16_34.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_25_2010__17_46_34.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_25_2010__18_06_34.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_25_2010__19_06_34.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_25_2010__19_26_34.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_25_2010__19_36_34.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_25_2010__20_26_34.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_25_2010__20_36_34.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_26_2010__08_43_25.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_26_2010__09_03_25.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_26_2010__11_36_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_26_2010__14_36_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_26_2010__14_46_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_26_2010__15_16_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_26_2010__15_46_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_26_2010__15_56_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_26_2010__17_26_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_26_2010__18_06_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_26_2010__18_26_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_26_2010__18_36_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_26_2010__18_46_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_26_2010__18_56_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_26_2010__19_06_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_26_2010__19_16_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_26_2010__19_36_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_26_2010__19_56_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_26_2010__20_06_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_26_2010__20_46_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_26_2010__20_56_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_26_2010__21_06_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_26_2010__21_46_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_26_2010__22_16_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_27_2010__13_22_42.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_27_2010__13_32_42.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_27_2010__13_42_42.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_27_2010__13_52_42.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_27_2010__14_02_42.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_27_2010__14_32_43.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_27_2010__15_02_43.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_27_2010__15_12_43.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_27_2010__15_42_43.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_27_2010__16_22_43.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_27_2010__16_52_43.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_27_2010__17_22_43.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_27_2010__17_52_43.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_27_2010__18_02_43.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_27_2010__19_42_43.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_27_2010__20_42_43.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_27_2010__21_02_43.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_27_2010__21_12_43.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_27_2010__21_32_43.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_27_2010__21_52_43.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_27_2010__22_12_43.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_28_2010__07_05_16.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_28_2010__07_15_16.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_28_2010__07_25_16.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_28_2010__09_07_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_28_2010__09_47_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_28_2010__10_57_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_28_2010__11_57_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_28_2010__12_17_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_28_2010__12_37_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_28_2010__12_47_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_28_2010__13_17_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_28_2010__13_27_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_28_2010__13_47_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_28_2010__13_57_55.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_28_2010__15_57_57.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_28_2010__16_07_57.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_28_2010__16_57_57.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_28_2010__17_47_57.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_28_2010__18_27_57.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_28_2010__20_37_57.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_28_2010__21_07_57.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_28_2010__21_37_57.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_28_2010__21_57_57.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_28_2010__22_17_57.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_28_2010__22_47_57.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_28_2010__22_57_57.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_28_2010__23_27_57.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_28_2010__23_57_58.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_29_2010__00_17_58.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_29_2010__00_27_58.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_29_2010__01_07_58.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_29_2010__01_27_58.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_29_2010__11_34_23.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_29_2010__11_44_23.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_29_2010__11_54_23.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_29_2010__13_54_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_29_2010__14_24_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_29_2010__15_14_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_29_2010__16_04_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_29_2010__16_14_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_29_2010__17_24_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_29_2010__17_34_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_29_2010__17_54_25.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_29_2010__18_04_25.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_29_2010__18_24_25.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_29_2010__19_44_25.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_29_2010__20_54_25.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_29_2010__21_04_25.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_29_2010__21_14_25.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_29_2010__21_34_25.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_29_2010__22_14_25.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_29_2010__22_24_25.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_30_2010__12_08_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_30_2010__12_18_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_30_2010__12_28_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_30_2010__13_08_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_30_2010__13_18_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_23_2010__18_10_47.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_24_2010__10_24_47.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_24_2010__15_44_48.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_25_2010__18_56_34.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_26_2010__12_26_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_26_2010__17_36_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_26_2010__21_16_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_27_2010__14_42_43.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_27_2010__18_32_43.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_28_2010__08_47_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_28_2010__13_37_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_28_2010__18_47_57.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_29_2010__15_44_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_30_2010__13_48_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_30_2010__14_38_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_30_2010__16_48_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_30_2010__16_58_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_30_2010__17_28_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_30_2010__19_08_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_30_2010__19_18_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_30_2010__20_08_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_30_2010__20_18_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_30_2010__21_08_33.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_30_2010__21_18_33.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_30_2010__21_28_33.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_30_2010__21_58_33.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_30_2010__22_18_33.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_30_2010__22_48_33.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_30_2010__22_58_33.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_31_2010__09_35_50.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_31_2010__09_45_50.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_31_2010__09_55_50.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_31_2010__10_15_50.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_31_2010__10_25_50.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_31_2010__10_35_50.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_31_2010__10_45_50.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_31_2010__10_55_50.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_31_2010__12_35_02.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_31_2010__12_45_02.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_31_2010__12_55_02.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_31_2010__13_05_02.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_31_2010__16_00_45.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_31_2010__16_30_45.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_31_2010__16_50_45.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_31_2010__17_00_46.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_31_2010__18_00_46.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_31_2010__19_10_46.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_31_2010__19_30_46.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_31_2010__19_50_46.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_31_2010__20_10_46.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_31_2010__20_40_46.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_31_2010__21_20_47.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_31_2010__21_50_47.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_13_2010__22_02_38.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_14_2010__16_47_08.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_14_2010__20_49_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_15_2010__12_51_45.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_15_2010__20_55_14.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_01_2010__11_51_55.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_01_2010__12_11_55.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_01_2010__13_11_55.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_01_2010__13_31_55.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_01_2010__14_01_55.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_01_2010__14_41_55.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_01_2010__15_11_56.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_01_2010__15_51_56.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_01_2010__16_21_56.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_01_2010__16_41_56.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_01_2010__17_01_56.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_01_2010__17_21_56.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_01_2010__18_41_34.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_01_2010__20_16_01.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_01_2010__20_46_01.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_01_2010__20_56_02.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_01_2010__21_36_03.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_01_2010__21_56_03.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_01_2010__22_26_03.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_02_2010__07_54_59.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_02_2010__11_52_06.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_02_2010__13_42_06.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_02_2010__14_52_06.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_02_2010__15_22_06.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_02_2010__15_32_06.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_02_2010__16_32_07.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_02_2010__17_12_07.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_02_2010__17_52_07.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_02_2010__19_02_07.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_02_2010__19_22_07.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_02_2010__20_22_08.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_02_2010__20_32_08.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_02_2010__20_52_08.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_02_2010__21_22_08.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_02_2010__21_32_08.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_03_2010__09_19_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_03_2010__09_29_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_03_2010__09_49_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_03_2010__10_09_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_03_2010__10_39_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_03_2010__10_59_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_03_2010__11_19_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_03_2010__11_29_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_03_2010__11_49_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_03_2010__13_09_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_03_2010__13_39_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_03_2010__16_31_43.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_03_2010__17_21_43.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_03_2010__17_41_53.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_03_2010__18_01_53.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_03_2010__21_23_51.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_03_2010__21_33_52.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_03_2010__21_43_52.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_03_2010__22_03_52.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_03_2010__22_13_52.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_03_2010__22_23_52.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_04_2010__06_35_06.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_04_2010__06_55_06.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_04_2010__07_05_06.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_04_2010__08_48_57.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_04_2010__09_08_57.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_04_2010__09_18_57.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_04_2010__09_28_57.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_04_2010__09_58_57.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_04_2010__10_08_57.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_04_2010__10_18_57.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_04_2010__12_14_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_04_2010__12_34_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_04_2010__13_04_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_04_2010__13_14_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_04_2010__13_24_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_04_2010__08_28_57.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_18_2010__21_49_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_25_2010__10_41_19.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_16_2010__06_57_51.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_19_2010__21_16_50.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_23_2010__14_40_46.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_29_2010__21_24_25.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_16_2010__15_58_19.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_04_2010__13_44_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_04_2010__13_54_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_04_2010__14_24_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_04_2010__14_54_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_04_2010__15_24_14.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_04_2010__16_44_19.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_04_2010__18_04_19.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_04_2010__18_54_19.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_04_2010__19_24_19.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_04_2010__20_14_19.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_04_2010__20_24_19.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_04_2010__20_34_19.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_04_2010__21_44_20.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_04_2010__21_54_20.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_04_2010__22_04_20.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_04_2010__22_14_20.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_05_2010__11_11_02.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_05_2010__12_31_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_05_2010__13_01_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_05_2010__13_41_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_05_2010__13_51_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_05_2010__14_01_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_05_2010__14_21_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_05_2010__15_01_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_05_2010__15_51_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_05_2010__16_01_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_05_2010__16_11_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_05_2010__16_41_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_05_2010__17_11_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_05_2010__17_31_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_05_2010__18_01_14.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_05_2010__18_21_14.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_05_2010__19_31_14.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_05_2010__20_51_14.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_05_2010__21_11_14.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_05_2010__21_41_14.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_05_2010__21_51_14.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_05_2010__22_11_14.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_05_2010__22_31_14.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_05_2010__22_41_14.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_06_2010__08_35_10.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_06_2010__09_05_10.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_06_2010__09_55_10.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_06_2010__10_15_10.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_06_2010__10_35_11.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_06_2010__16_45_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_06_2010__16_55_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_06_2010__17_05_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_06_2010__17_55_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_06_2010__18_35_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_06_2010__19_15_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_06_2010__19_35_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_06_2010__19_45_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_06_2010__20_05_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_06_2010__21_15_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_06_2010__21_35_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_06_2010__21_45_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_06_2010__22_05_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_07_2010__12_08_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_07_2010__13_18_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_07_2010__13_38_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_07_2010__14_28_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_07_2010__14_48_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_07_2010__14_58_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_07_2010__15_28_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_07_2010__15_48_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_07_2010__18_25_55.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_07_2010__18_45_55.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_07_2010__20_25_20.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_07_2010__20_45_20.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_07_2010__21_15_20.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_07_2010__21_45_20.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_07_2010__22_15_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_07_2010__22_25_26.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_08_2010__12_07_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_08_2010__12_57_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_08_2010__14_17_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_08_2010__14_47_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_08_2010__15_27_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_08_2010__15_47_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_08_2010__15_57_14.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_08_2010__16_07_14.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_08_2010__16_37_14.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_08_2010__17_07_14.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_08_2010__17_17_14.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_08_2010__17_27_14.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_08_2010__18_17_15.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_08_2010__18_27_15.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_08_2010__18_57_15.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_08_2010__19_07_15.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_08_2010__19_17_15.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_08_2010__19_27_15.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_08_2010__19_47_15.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_08_2010__19_57_15.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_08_2010__20_07_15.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_08_2010__20_17_16.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_08_2010__20_27_16.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_08_2010__21_57_16.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_08_2010__22_07_16.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_09_2010__09_12_39.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_09_2010__09_42_39.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_09_2010__09_52_39.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_09_2010__10_02_40.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_09_2010__10_22_40.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_09_2010__12_32_40.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_09_2010__12_42_40.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_09_2010__12_52_40.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_09_2010__16_02_41.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_09_2010__17_42_42.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_09_2010__17_52_42.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_09_2010__19_32_42.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_09_2010__20_02_42.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_09_2010__20_12_42.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_09_2010__20_22_42.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_09_2010__20_42_42.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_09_2010__20_52_42.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_09_2010__21_02_42.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_09_2010__21_12_42.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_10_2010__10_10_53.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_10_2010__10_30_53.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_10_2010__10_40_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_10_2010__16_01_03.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_10_2010__16_41_03.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_10_2010__16_51_03.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_10_2010__17_31_03.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_10_2010__17_51_04.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_10_2010__18_41_04.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_10_2010__18_51_04.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_10_2010__19_21_04.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_10_2010__19_31_04.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_10_2010__20_31_04.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_10_2010__21_51_04.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_10_2010__22_01_04.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_04_2010__13_34_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_04_2010__21_34_19.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_05_2010__14_11_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_05_2010__19_01_14.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_06_2010__10_55_11.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_06_2010__16_25_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_06_2010__22_45_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_07_2010__19_05_55.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_08_2010__15_07_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_08_2010__19_37_15.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_09_2010__10_12_40.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_09_2010__13_02_40.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_09_2010__15_52_41.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_10_2010__11_51_02.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_10_2010__15_51_03.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_11_2010__07_49_37.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_11_2010__07_59_37.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_11_2010__08_09_37.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_11_2010__14_32_59.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_11_2010__14_52_59.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_11_2010__15_02_59.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_11_2010__15_32_59.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_11_2010__15_42_59.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_11_2010__15_52_59.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_11_2010__21_02_17.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_11_2010__22_22_17.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_11_2010__22_32_17.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_11_2010__22_42_17.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_12_2010__10_50_29.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_12_2010__12_20_39.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_12_2010__13_20_39.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_12_2010__13_50_39.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_12_2010__14_00_39.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_12_2010__15_28_34.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_12_2010__16_08_34.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_12_2010__16_18_34.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_12_2010__17_08_34.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_12_2010__17_18_34.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_12_2010__17_58_35.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_12_2010__18_28_35.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_12_2010__19_38_35.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_12_2010__20_38_35.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_12_2010__21_18_35.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_12_2010__21_48_35.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_12_2010__21_58_35.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_12_2010__22_08_35.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_13_2010__07_13_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_13_2010__07_23_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_13_2010__07_33_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_13_2010__08_41_59.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_13_2010__09_31_59.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_13_2010__09_41_59.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_13_2010__11_46_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_13_2010__12_26_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_13_2010__12_46_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_13_2010__13_16_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_13_2010__13_36_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_13_2010__14_26_33.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_13_2010__14_56_34.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_13_2010__15_06_34.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_13_2010__15_26_34.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_13_2010__16_16_34.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_13_2010__17_16_34.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_13_2010__17_36_34.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_13_2010__18_46_34.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_13_2010__20_36_34.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_13_2010__21_06_35.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_13_2010__21_26_35.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_13_2010__21_56_35.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_14_2010__12_31_50.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_14_2010__13_11_50.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_14_2010__13_31_50.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_14_2010__14_51_50.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_14_2010__15_01_51.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_14_2010__15_31_51.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_14_2010__15_41_51.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_14_2010__16_11_51.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_14_2010__16_51_52.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_14_2010__17_41_52.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_14_2010__18_11_52.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_14_2010__19_31_52.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_14_2010__19_51_52.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_14_2010__20_21_52.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_14_2010__20_41_52.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_15_2010__10_58_19.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_15_2010__11_28_19.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_15_2010__12_03_06.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_15_2010__12_23_06.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_15_2010__17_33_07.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_15_2010__18_03_07.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_15_2010__18_23_07.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_15_2010__18_43_07.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_15_2010__19_03_07.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_15_2010__19_43_07.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_15_2010__19_53_07.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_15_2010__22_23_08.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_15_2010__22_33_08.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_15_2010__23_13_08.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_16_2010__11_03_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_16_2010__12_03_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_16_2010__12_23_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_16_2010__12_33_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_16_2010__17_53_25.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_16_2010__18_03_25.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_16_2010__18_43_25.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_16_2010__20_13_25.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_16_2010__20_23_25.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_16_2010__20_33_25.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_16_2010__20_53_25.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_16_2010__21_13_25.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_16_2010__21_43_25.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_16_2010__22_13_26.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_16_2010__22_43_26.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_17_2010__07_55_52.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_17_2010__08_46_47.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_17_2010__09_36_47.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_17_2010__10_06_48.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_17_2010__17_46_50.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_17_2010__18_06_50.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_17_2010__18_56_50.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_17_2010__19_26_50.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_17_2010__19_56_50.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_17_2010__20_26_50.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_17_2010__20_36_50.jpg (Keylogger.Ardamax) -> Delete on

OWN3D
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 29 bře 2014 14:07

Re: Odepřený přístup k Antivirům

#14 Příspěvek od OWN3D »

reboot.
C:\WINDOWS\system32\28463\Aug_18_2010__09_48_29.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_18_2010__09_58_29.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_18_2010__11_48_30.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_18_2010__15_58_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_18_2010__16_08_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_18_2010__16_48_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_18_2010__16_58_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_18_2010__18_49_30.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_18_2010__18_59_30.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_18_2010__19_09_30.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_18_2010__19_19_30.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_18_2010__19_29_30.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_18_2010__19_39_30.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_18_2010__20_19_30.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_18_2010__20_39_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_18_2010__21_09_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_18_2010__21_19_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_11_2010__10_52_58.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_11_2010__14_12_59.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_12_2010__11_10_29.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_12_2010__18_58_35.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_13_2010__07_43_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_13_2010__15_46_34.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_14_2010__14_01_50.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_15_2010__12_43_06.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_15_2010__17_13_07.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_16_2010__07_06_58.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_16_2010__13_13_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_16_2010__17_03_25.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_17_2010__10_36_48.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_17_2010__14_36_50.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_18_2010__11_58_30.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_18_2010__15_38_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_18_2010__21_59_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_19_2010__08_21_39.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_19_2010__08_31_39.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_19_2010__09_11_39.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_19_2010__09_21_39.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_19_2010__09_31_39.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_19_2010__09_41_39.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_19_2010__09_51_39.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_19_2010__10_11_40.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_19_2010__10_21_40.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_19_2010__12_31_40.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_19_2010__12_41_40.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_19_2010__14_01_40.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_19_2010__15_11_40.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_19_2010__17_11_41.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_19_2010__17_21_41.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_19_2010__17_31_41.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_19_2010__17_41_41.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_19_2010__17_51_41.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_19_2010__18_01_41.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_19_2010__18_11_41.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_19_2010__21_01_41.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_19_2010__21_21_41.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_19_2010__21_31_41.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_19_2010__21_41_41.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_19_2010__22_01_41.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_19_2010__22_11_41.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_20_2010__09_21_01.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_20_2010__10_01_01.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_20_2010__10_11_01.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_20_2010__10_21_01.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_20_2010__10_31_01.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_20_2010__11_41_01.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_20_2010__11_51_01.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_20_2010__12_51_01.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_20_2010__13_21_01.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_20_2010__18_41_03.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_20_2010__18_51_03.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_20_2010__19_11_03.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_20_2010__19_21_03.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_20_2010__19_31_03.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_20_2010__19_41_03.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_20_2010__20_21_03.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_20_2010__20_31_03.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_20_2010__21_01_03.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_20_2010__21_11_04.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_21_2010__11_35_26.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_21_2010__12_05_26.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_21_2010__12_45_26.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_21_2010__12_55_26.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_21_2010__13_05_26.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_21_2010__13_45_26.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_21_2010__15_35_27.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_21_2010__15_45_27.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_21_2010__17_05_27.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_21_2010__17_55_27.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_21_2010__18_25_27.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_21_2010__19_15_27.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_21_2010__19_25_27.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_21_2010__19_45_27.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_21_2010__20_05_27.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_21_2010__20_45_27.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_21_2010__20_55_28.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_21_2010__21_15_28.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_21_2010__21_25_28.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_22_2010__12_17_16.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_22_2010__12_57_16.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_22_2010__13_27_16.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_22_2010__20_48_03.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_22_2010__20_58_03.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_22_2010__21_08_03.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_22_2010__21_18_03.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_22_2010__21_38_03.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_23_2010__08_50_46.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_23_2010__09_50_51.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_23_2010__10_30_51.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_23_2010__11_10_52.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_23_2010__11_50_52.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_23_2010__12_51_23.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_23_2010__13_41_23.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_23_2010__13_51_23.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_23_2010__14_21_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_23_2010__14_41_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_23_2010__15_01_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_23_2010__15_58_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_23_2010__16_28_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_23_2010__18_08_29.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_23_2010__18_18_29.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_23_2010__18_58_29.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_23_2010__19_18_29.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_23_2010__20_38_29.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_23_2010__20_48_29.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_23_2010__21_23_07.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_23_2010__22_23_07.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_23_2010__22_33_07.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_23_2010__22_43_07.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_23_2010__23_13_08.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_24_2010__07_26_38.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_24_2010__08_06_38.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_24_2010__08_46_38.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_24_2010__09_16_38.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_24_2010__09_56_38.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_24_2010__10_16_38.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_24_2010__11_36_44.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_24_2010__11_46_46.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_24_2010__11_57_02.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_24_2010__12_17_02.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_24_2010__12_57_03.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_24_2010__14_17_03.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_24_2010__15_17_03.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_24_2010__15_57_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_24_2010__16_17_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_24_2010__16_37_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_24_2010__16_47_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_24_2010__17_37_29.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_24_2010__18_07_29.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_24_2010__19_27_29.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_24_2010__21_07_29.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_24_2010__21_17_29.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_24_2010__22_07_29.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_24_2010__22_27_29.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_24_2010__22_37_29.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_24_2010__23_11_44.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_24_2010__23_41_44.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_25_2010__08_11_18.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_25_2010__09_01_18.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_25_2010__09_31_18.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_25_2010__11_51_19.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_25_2010__12_31_19.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_25_2010__13_01_27.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_25_2010__14_02_38.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_25_2010__14_22_38.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_25_2010__15_32_39.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_25_2010__15_42_39.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_25_2010__16_22_39.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_25_2010__16_32_39.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_25_2010__16_42_40.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_19_2010__11_51_40.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_19_2010__21_11_41.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_20_2010__10_41_01.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_20_2010__14_11_02.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_20_2010__18_01_03.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_21_2010__09_25_26.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_21_2010__16_05_27.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_22_2010__13_47_16.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_22_2010__19_27_43.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_23_2010__13_31_23.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_23_2010__22_13_07.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_24_2010__10_36_38.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_24_2010__20_17_29.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_25_2010__19_42_40.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_25_2010__20_02_40.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_25_2010__20_42_40.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_25_2010__20_52_40.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_25_2010__22_22_40.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_26_2010__07_24_28.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_26_2010__08_33_15.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_26_2010__08_53_15.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_26_2010__09_13_15.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_26_2010__09_33_15.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_26_2010__12_03_20.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_26_2010__12_43_20.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_26_2010__14_13_20.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_26_2010__14_23_20.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_26_2010__14_33_20.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_26_2010__15_23_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_26_2010__15_33_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_26_2010__15_53_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_26_2010__16_26_50.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_26_2010__16_36_50.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_26_2010__17_26_53.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_27_2010__07_35_01.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_27_2010__07_55_01.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_27_2010__08_30_50.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_27_2010__09_21_01.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_27_2010__09_41_01.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_27_2010__09_51_01.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_27_2010__10_11_01.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_27_2010__10_21_01.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_27_2010__10_51_01.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_27_2010__11_21_02.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_27_2010__12_41_02.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_27_2010__13_51_02.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_27_2010__14_21_02.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_27_2010__15_21_02.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_27_2010__15_41_02.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_27_2010__16_01_02.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_27_2010__16_41_02.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_27_2010__17_01_03.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_27_2010__17_11_03.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_27_2010__17_31_03.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_27_2010__18_41_05.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_27_2010__19_11_05.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_27_2010__20_41_06.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_27_2010__21_01_06.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_27_2010__21_41_06.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_28_2010__08_06_17.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_28_2010__08_16_17.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_28_2010__08_26_17.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_28_2010__08_36_17.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_28_2010__09_36_18.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_28_2010__09_46_19.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_28_2010__09_56_19.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_28_2010__10_06_19.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_28_2010__11_16_20.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_28_2010__11_46_20.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_28_2010__12_26_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_28_2010__14_51_53.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_28_2010__15_21_53.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_28_2010__15_51_53.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_28_2010__17_11_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_28_2010__17_21_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_28_2010__17_31_55.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_28_2010__17_41_55.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_28_2010__17_51_55.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_28_2010__19_21_55.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_28_2010__20_11_56.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_28_2010__21_01_56.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_28_2010__21_51_56.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_28_2010__22_21_56.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_29_2010__11_14_28.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_29_2010__12_14_29.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_29_2010__12_34_29.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_29_2010__13_14_29.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_29_2010__14_04_29.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_29_2010__14_44_29.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_29_2010__14_54_29.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_29_2010__15_04_29.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_29_2010__17_24_29.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_29_2010__17_44_29.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_29_2010__18_14_30.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_29_2010__18_24_30.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_29_2010__18_34_30.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_29_2010__19_14_30.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_29_2010__19_44_30.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_29_2010__20_04_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_29_2010__20_24_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_29_2010__21_04_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_29_2010__21_54_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_29_2010__22_04_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_29_2010__22_24_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_29_2010__22_34_33.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_29_2010__23_14_33.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_30_2010__07_00_23.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_30_2010__08_32_50.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_30_2010__11_12_50.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_30_2010__11_22_50.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_30_2010__12_52_51.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_30_2010__13_02_51.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_30_2010__13_22_53.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_30_2010__14_22_55.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_30_2010__15_32_56.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_30_2010__15_42_56.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_30_2010__16_33_51.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_30_2010__16_53_51.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_30_2010__21_51_59.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_30_2010__22_12_19.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_30_2010__22_52_19.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_30_2010__23_02_19.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_30_2010__23_12_19.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_31_2010__00_02_19.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_31_2010__13_05_27.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_31_2010__13_15_27.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_31_2010__16_35_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_31_2010__17_35_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_31_2010__17_45_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_31_2010__17_55_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_31_2010__18_35_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_31_2010__18_45_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_31_2010__18_55_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_31_2010__19_05_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_31_2010__20_50_11.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_01_2010__08_25_05.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_01_2010__11_41_55.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_01_2010__17_31_56.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_02_2010__14_02_06.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_03_2010__16_01_43.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_03_2010__18_21_53.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_03_2010__21_13_51.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_01_2010__12_38_20.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_01_2010__13_18_20.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_01_2010__14_18_20.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_01_2010__16_58_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_01_2010__17_48_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_01_2010__17_58_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_01_2010__18_08_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_01_2010__18_18_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_01_2010__19_08_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_01_2010__19_18_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_01_2010__20_08_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_01_2010__22_05_36.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_02_2010__14_58_02.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_02_2010__17_08_03.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_02_2010__17_28_03.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_02_2010__17_38_03.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_02_2010__17_48_03.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_02_2010__19_18_03.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_02_2010__20_08_03.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_02_2010__20_18_03.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_03_2010__08_27_00.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_03_2010__08_37_00.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_03_2010__13_39_37.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_03_2010__13_49_37.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_03_2010__13_59_37.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_03_2010__14_09_37.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_03_2010__15_19_37.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_03_2010__16_29_37.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_03_2010__16_39_37.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_03_2010__17_59_37.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_03_2010__18_19_37.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_03_2010__18_49_37.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_04_2010__07_00_33.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_04_2010__07_50_33.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_04_2010__08_00_33.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_04_2010__08_20_33.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_04_2010__08_30_33.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_04_2010__14_50_34.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_04_2010__15_00_34.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_04_2010__15_10_34.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_04_2010__16_35_56.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_04_2010__16_45_56.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_04_2010__17_15_56.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_04_2010__17_25_56.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_04_2010__18_25_56.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_04_2010__18_55_56.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_04_2010__19_05_56.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_04_2010__19_35_56.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_04_2010__21_55_57.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_04_2010__22_05_57.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_05_2010__14_20_53.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_05_2010__14_40_53.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_05_2010__15_50_53.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_05_2010__16_00_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_05_2010__16_20_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_05_2010__16_40_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_05_2010__18_10_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_05_2010__19_00_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_05_2010__19_20_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_05_2010__21_00_56.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_06_2010__12_20_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_06_2010__12_30_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_06_2010__12_40_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_06_2010__14_41_52.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_06_2010__14_51_52.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_06_2010__15_21_52.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_06_2010__15_31_52.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_06_2010__15_41_52.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_06_2010__17_01_53.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_06_2010__18_11_53.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_06_2010__18_21_53.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_06_2010__18_31_53.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_06_2010__19_21_53.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_06_2010__19_31_53.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_06_2010__21_01_53.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_30_2010__13_38_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_30_2010__20_38_33.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_31_2010__10_05_50.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_31_2010__17_20_46.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_07_2010__17_14_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_07_2010__17_54_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_07_2010__18_04_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_07_2010__18_14_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_07_2010__18_54_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_07_2010__19_24_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_07_2010__19_34_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_07_2010__19_44_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_07_2010__20_24_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_07_2010__20_44_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_08_2010__16_23_05.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_08_2010__16_33_05.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_08_2010__16_43_05.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_08_2010__17_13_05.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_08_2010__18_13_06.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_08_2010__18_23_06.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_08_2010__18_43_06.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_08_2010__19_03_06.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_08_2010__19_13_06.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_08_2010__20_03_06.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_08_2010__20_33_06.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_08_2010__20_53_06.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_09_2010__12_40_18.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_09_2010__12_50_18.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_09_2010__13_00_18.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_09_2010__13_10_18.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_09_2010__13_20_18.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_09_2010__20_30_07.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_09_2010__21_20_07.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_10_2010__08_34_30.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_10_2010__12_07_08.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_10_2010__14_08_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_10_2010__14_18_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_10_2010__14_48_55.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_10_2010__15_38_55.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_10_2010__15_48_55.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_10_2010__16_08_55.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_10_2010__17_39_01.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_10_2010__18_09_01.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_10_2010__19_49_01.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_10_2010__20_19_01.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_10_2010__20_29_01.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_10_2010__20_59_01.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_10_2010__21_09_01.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_11_2010__09_44_20.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_11_2010__11_54_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_11_2010__12_34_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_11_2010__21_24_34.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_12_2010__14_28_01.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_12_2010__15_08_01.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_12_2010__16_38_01.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_12_2010__16_48_01.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_12_2010__17_28_01.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_12_2010__17_38_01.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_12_2010__18_49_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_12_2010__20_09_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_12_2010__21_39_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_13_2010__12_02_11.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_13_2010__15_51_26.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_13_2010__16_01_26.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_13_2010__16_51_26.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_13_2010__17_11_26.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_13_2010__17_41_27.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_13_2010__18_51_27.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_13_2010__19_51_27.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_13_2010__20_21_27.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_13_2010__20_41_28.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_13_2010__20_51_28.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_13_2010__21_21_28.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_14_2010__14_22_27.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_14_2010__14_52_28.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_14_2010__15_02_28.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_14_2010__16_22_28.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_14_2010__18_32_28.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_14_2010__18_42_28.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_14_2010__19_52_28.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_14_2010__20_12_28.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_14_2010__21_02_28.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_14_2010__21_12_28.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_15_2010__15_58_56.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_15_2010__16_48_56.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_15_2010__18_08_56.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_15_2010__18_38_57.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_15_2010__19_38_57.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_15_2010__19_58_57.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_15_2010__20_28_57.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_15_2010__21_28_57.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_16_2010__06_47_00.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_16_2010__06_57_00.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_16_2010__12_06_53.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_16_2010__13_46_53.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_16_2010__14_16_53.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_16_2010__16_18_19.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_16_2010__16_38_19.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_16_2010__18_08_19.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_16_2010__19_08_19.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_16_2010__20_18_19.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_16_2010__20_48_20.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_16_2010__20_58_20.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_17_2010__11_09_36.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_17_2010__11_29_36.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_17_2010__12_09_36.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_17_2010__12_29_36.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_04_2010__08_40_33.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_04_2010__14_40_34.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_04_2010__20_05_56.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_05_2010__19_10_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_06_2010__16_51_53.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_07_2010__17_04_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_09_2010__13_30_18.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_09_2010__19_40_07.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_10_2010__16_39_01.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_11_2010__10_34_20.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_12_2010__18_29_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_13_2010__19_21_27.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_14_2010__17_22_28.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_15_2010__17_18_56.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_17_2010__14_55_26.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_17_2010__15_15_27.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_17_2010__16_05_27.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_17_2010__16_35_27.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_17_2010__17_25_27.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_17_2010__17_45_27.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_17_2010__19_15_27.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_17_2010__19_55_27.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_17_2010__20_25_27.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_17_2010__20_35_27.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_17_2010__20_45_27.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_17_2010__21_05_28.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_17_2010__23_37_48.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_17_2010__23_47_48.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_18_2010__00_07_48.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_18_2010__00_27_48.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_18_2010__09_25_25.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_18_2010__09_55_25.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_18_2010__10_15_25.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_18_2010__10_35_25.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_18_2010__11_05_25.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_18_2010__19_02_57.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_18_2010__20_22_57.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_18_2010__21_22_58.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_18_2010__22_02_58.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_18_2010__22_22_58.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_18_2010__22_32_58.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_18_2010__23_42_58.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_19_2010__09_07_52.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_19_2010__09_37_52.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_19_2010__10_57_52.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_19_2010__12_07_52.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_19_2010__12_47_53.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_19_2010__13_17_53.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_19_2010__17_43_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_19_2010__18_43_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_19_2010__20_13_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_19_2010__21_03_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_19_2010__21_33_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_20_2010__11_10_42.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_20_2010__11_50_42.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_20_2010__12_10_42.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_20_2010__12_50_42.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_20_2010__13_49_05.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_20_2010__14_19_05.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_20_2010__14_49_05.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_20_2010__15_19_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_20_2010__15_59_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_20_2010__16_39_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_20_2010__16_59_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_20_2010__17_39_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_20_2010__18_09_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_20_2010__18_19_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_20_2010__18_29_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_20_2010__19_59_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_20_2010__20_49_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_21_2010__08_04_28.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_21_2010__12_13_01.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_21_2010__15_53_57.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_21_2010__16_13_57.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_21_2010__16_33_57.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_21_2010__17_56_18.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_21_2010__18_26_18.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_21_2010__19_06_18.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_21_2010__19_36_18.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_21_2010__20_16_18.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_21_2010__20_46_18.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_22_2010__13_26_00.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_22_2010__13_36_00.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_22_2010__14_56_00.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_22_2010__15_16_00.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_22_2010__17_06_00.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_22_2010__18_16_00.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_22_2010__18_36_00.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_22_2010__18_56_00.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_22_2010__19_36_00.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_22_2010__19_56_00.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_23_2010__09_36_14.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_23_2010__10_16_14.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_23_2010__10_36_14.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_23_2010__11_06_14.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_23_2010__11_16_14.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_23_2010__11_46_14.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_23_2010__13_06_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_23_2010__13_26_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_23_2010__14_16_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_23_2010__14_56_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_23_2010__15_16_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_23_2010__15_36_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_23_2010__16_06_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_23_2010__17_26_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_23_2010__17_46_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_23_2010__18_26_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_23_2010__18_52_20.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_23_2010__19_32_20.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_23_2010__20_22_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_23_2010__20_32_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_23_2010__20_42_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_24_2010__08_24_58.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_24_2010__09_34_58.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_24_2010__10_04_58.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_24_2010__10_34_58.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_24_2010__11_24_58.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_24_2010__12_23_41.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_24_2010__12_43_41.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_24_2010__13_33_41.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_24_2010__20_03_41.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_24_2010__20_33_41.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_24_2010__21_03_41.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_24_2010__21_33_41.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_25_2010__11_36_47.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_25_2010__12_16_47.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_25_2010__13_06_48.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_25_2010__13_16_48.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_25_2010__14_16_48.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_25_2010__15_36_48.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_25_2010__16_16_49.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_25_2010__18_13_06.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_25_2010__18_43_06.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_25_2010__19_13_06.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_25_2010__20_33_06.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_25_2010__21_53_06.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_26_2010__13_32_01.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_26_2010__14_12_01.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_26_2010__17_08_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_26_2010__17_38_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_26_2010__18_18_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_26_2010__18_28_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_26_2010__18_38_33.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_26_2010__19_18_33.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_26_2010__20_28_33.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_26_2010__20_48_33.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_26_2010__21_38_33.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_27_2010__08_44_16.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_27_2010__09_14_16.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_27_2010__11_34_16.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_27_2010__12_26_16.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_27_2010__12_36_16.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_27_2010__13_26_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_27_2010__14_06_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_27_2010__15_56_32.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_27_2010__17_45_08.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_27_2010__19_05_08.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_27_2010__20_35_08.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_27_2010__21_25_08.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_27_2010__22_45_09.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_17_2010__13_35_26.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_17_2010__22_47_48.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_18_2010__19_42_57.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_19_2010__12_27_53.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_20_2010__12_30_42.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_21_2010__21_02_13.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_22_2010__19_16_00.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_23_2010__13_56_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_24_2010__15_03_41.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_25_2010__14_36_48.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_26_2010__16_02_02.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_27_2010__10_04_16.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_28_2010__12_54_00.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_28_2010__06_34_49.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_28_2010__06_54_49.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_28_2010__09_08_18.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_28_2010__10_38_19.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_28_2010__11_24_00.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_13_2010__20_32_37.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_13_2010__20_42_37.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_13_2010__20_52_37.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_13_2010__21_02_38.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_13_2010__21_12_38.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_13_2010__21_22_38.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_13_2010__21_32_38.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_13_2010__21_42_38.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_13_2010__21_52_38.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_17_2010__06_38_43.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_17_2010__06_48_44.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_17_2010__06_58_44.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_17_2010__07_08_44.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_17_2010__07_18_44.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_22_2010__09_21_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_22_2010__09_41_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_22_2010__09_51_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_22_2010__10_11_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_22_2010__10_41_21.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_03_2010__19_03_46.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_03_2010__19_13_46.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_03_2010__19_33_46.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_03_2010__19_43_46.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_03_2010__19_53_51.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_03_2010__20_13_51.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_03_2010__20_23_51.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_03_2010__20_33_51.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_03_2010__20_53_51.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_06_2010__12_05_11.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_06_2010__13_25_11.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_06_2010__14_35_11.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_06_2010__14_45_11.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_06_2010__15_15_11.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_06_2010__15_45_11.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_09_2010__14_12_41.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_09_2010__14_22_41.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_09_2010__14_42_41.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_09_2010__15_02_41.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_09_2010__15_12_41.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_09_2010__15_22_41.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_09_2010__15_32_41.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_09_2010__15_42_41.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_10_2010__12_01_02.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_10_2010__13_01_02.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_10_2010__13_21_02.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_10_2010__13_31_02.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_10_2010__14_21_03.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_10_2010__15_01_03.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_10_2010__15_11_03.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_11_2010__12_12_58.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_11_2010__12_22_58.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_11_2010__12_32_58.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_11_2010__12_42_58.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_11_2010__13_02_58.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_11_2010__13_22_58.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_11_2010__13_52_58.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_15_2010__13_03_06.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_15_2010__13_43_06.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_15_2010__14_13_06.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_15_2010__14_33_06.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_15_2010__15_03_07.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_15_2010__15_23_07.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_16_2010__13_33_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_16_2010__14_43_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_16_2010__14_53_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_16_2010__15_53_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_16_2010__16_13_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_16_2010__16_23_24.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_17_2010__11_06_48.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_17_2010__11_36_48.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_17_2010__12_16_48.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_17_2010__12_56_49.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_17_2010__13_06_49.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_17_2010__13_36_49.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_17_2010__13_46_49.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_18_2010__12_08_30.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_18_2010__12_18_30.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_18_2010__12_28_30.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_18_2010__13_08_30.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_18_2010__13_18_30.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_18_2010__15_08_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_18_2010__15_18_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_18_2010__15_28_31.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_20_2010__14_31_02.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_20_2010__14_41_02.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_20_2010__15_01_02.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_20_2010__15_11_02.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_20_2010__15_51_03.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_22_2010__14_17_17.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_22_2010__14_27_17.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_22_2010__14_37_17.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_22_2010__15_07_17.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_22_2010__15_37_18.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_22_2010__15_57_18.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_22_2010__17_17_22.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_22_2010__17_57_23.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_01_2010__08_35_05.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_01_2010__09_11_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_01_2010__09_51_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_01_2010__10_11_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_01_2010__10_21_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_01_2010__11_01_54.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_04_2010__10_10_33.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_04_2010__11_20_34.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_04_2010__11_40_34.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_04_2010__11_50_34.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_04_2010__13_30_34.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_04_2010__14_20_34.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_04_2010__14_30_34.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_07_2010__14_44_11.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_07_2010__15_14_11.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_07_2010__15_24_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_07_2010__16_54_12.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_09_2010__14_30_19.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_09_2010__16_20_07.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_09_2010__17_10_07.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_09_2010__17_20_07.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_09_2010__18_00_07.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_09_2010__19_00_07.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_01_2010__10_58_20.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_01_2010__11_38_20.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Sep_01_2010__11_58_20.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_16_2010__14_12_43.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_16_2010__14_22_43.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_16_2010__14_32_43.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_16_2010__14_42_43.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_16_2010__14_52_43.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_16_2010__15_02_43.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_16_2010__15_12_43.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Jul_16_2010__15_22_43.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\TXQK.001 (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\TXQK.002 (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\TXQK.005 (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\TXQK.006 (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\TXQK.007 (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\TXQK.008 (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\TXQK.009 (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_25_2010__19_02_40.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_26_2010__09_53_16.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_27_2010__13_11_02.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_27_2010__22_11_06.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_28_2010__12_36_25.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_28_2010__22_51_56.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_29_2010__15_34_29.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_29_2010__23_04_33.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_30_2010__16_02_56.jpg (Keylogger.Ardamax) -> Delete on reboot.
C:\WINDOWS\system32\28463\Aug_31_2010__15_25_31.jpg (Keylogger.Ardamax) -> Delete on reboot.

Physical Sectors Detected: 0
(No malicious items detected)

(end)

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Odepřený přístup k Antivirům

#15 Příspěvek od vyosek »

:arrow: No vyyyborne :James008:

:arrow: Ted zkuste prosim RKill a ComboFix
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět