CHR - Extension: Google Mail = C:\Users\romy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
O1 HOSTS File: ([2010.05.13 22:53:40 | 000,001,204 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: ::1 localhost
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {3E1201F4-1707-409F-BB45-A5F192381DA0} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [Logitech Download Assistant] C:\Windows\System32\LogiLDA.dll (Logitech, Inc.)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NSU_agent] C:\Program Files\Nokia\Nokia Software Updater\nsu3ui_agent.exe ()
O4 - HKLM..\Run: [snp2uvc] C:\Windows\vsnp2uvc.exe (Sonix)
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe ()
O4 - HKLM..\Run: [YouCam Mirror Tray icon] C:\Program Files\CyberLink\YouCam\YouCamTray.exe (CyberLink Corp.)
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [MyTomTomSA.exe] C:\Program Files\MyTomTom 3\MyTomTomSA.exe (TomTom)
O4 - Startup: C:\Users\romy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CDTray.exe.lnk = C:\Program Files\CDTray\CDTray.exe ()
O4 - Startup: C:\Users\romy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Produktregistrierung.lnk = C:\Program Files\Common Files\LogiShrd\eReg\SetPoint\eReg.exe (Leader Technologies/Logitech)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O13 - gopher Prefix: missing
O16 - DPF: {0067DBFC-A752-458C-AE6E-B9C7E63D4824}
http://www.logitech.com/devicedetector/plugins/LogitechDeviceDetection32.cab (Geräteerkennung)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/downl...-4117-8430-A67417AA88CD/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9}
http://ax.emsisoft.com/emsisoft_webscan.cab (Emsisoft Web Malware Scan)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A7809B7E-2F4D-4D95-8C5D-256454614890}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F8969EC8-F810-4747-A25B-C71EDE050B3F}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{a25b6185-1ab0-11e2-a62f-9e20dfaf8edd}\Shell - = AutoRun
O33 - MountPoints2\{a25b6185-1ab0-11e2-a62f-9e20dfaf8edd}\Shell\AutoRun\command - = L:\Start_eBanking_Login-Stick_Win.exe
O33 - MountPoints2\{af470ec5-e1af-11df-a170-bddb786e51a9}\Shell - = AutoRun
O33 - MountPoints2\{af470ec5-e1af-11df-a170-bddb786e51a9}\Shell\AutoRun\command - = L:\Start_eBanking_Login-Stick_Win.exe
O33 - MountPoints2\R\Shell - = AutoRun
O33 - MountPoints2\R\Shell\AutoRun\command - = R:\Win32\AppWizard.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (OODBS)
O35 - HKLM\..comfile [open] -- %1 %*
O35 - HKLM\..exefile [open] -- %1 %*
O37 - HKLM\...com [@ = comfile] -- %1 %*
O37 - HKLM\...exe [@ = exefile] -- %1 %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2012.11.11 11:41:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2012.11.09 10:26:50 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\romy\Desktop\OTL.exe
[2012.10.30 21:32:53 | 000,000,000 | ---D | C] -- C:\Users\romy\AppData\Roaming\Acronis
[2012.10.30 21:31:40 | 000,601,408 | ---- | C] (Acronis) -- C:\Windows\System32\drivers\timntr.sys
[2012.10.30 21:31:33 | 000,125,472 | ---- | C] (Acronis) -- C:\Windows\System32\drivers\vididr.sys
[2012.10.30 21:31:31 | 000,083,392 | ---- | C] (Acronis) -- C:\Windows\System32\drivers\vsflt53.sys
[2012.10.30 21:31:29 | 000,169,088 | ---- | C] (Acronis) -- C:\Windows\System32\drivers\snapman.sys
[2012.10.30 21:31:28 | 000,000,000 | ---D | C] -- C:\Users\romy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Acronis
[2012.10.30 21:31:15 | 000,000,000 | ---D | C] -- C:\Program Files\Acronis
[2012.10.29 17:33:51 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2012.10.29 17:33:22 | 000,246,760 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaws.exe
[2012.10.29 17:33:14 | 000,174,056 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
[2012.10.29 17:33:14 | 000,174,056 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\java.exe
[2012.10.29 17:33:14 | 000,093,672 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll
[2012.10.29 17:32:57 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2012.10.19 15:46:44 | 000,000,000 | ---D | C] -- C:\Users\romy\AppData\Local\ElevatedDiagnostics
[2012.10.16 19:53:40 | 000,000,000 | ---D | C] -- C:\Users\romy\AppData\Roaming\Ashampoo Slideshow Studio HD 2
[2012.10.16 19:53:30 | 000,000,000 | ---D | C] -- C:\Users\romy\AppData\Local\ashampoo
[2012.10.16 19:53:30 | 000,000,000 | ---D | C] -- C:\ProgramData\ashampoo
[2010.09.07 20:16:01 | 007,760,687 | ---- | C] (Boraxsoft) -- C:\Users\romy\AppData\Roaming\SetupGFD.exe
[2010.09.07 20:15:33 | 004,284,535 | ---- | C] (ffdshow ) -- C:\Users\romy\AppData\Roaming\ffdshow.exe
[2010.09.07 20:15:29 | 000,642,685 | ---- | C] (Xvid team ) -- C:\Users\romy\AppData\Roaming\xvid.exe
[2010.09.07 20:15:17 | 002,169,915 | ---- | C] (LIGHTNING UK!) -- C:\Users\romy\AppData\Roaming\Imgburn.exe
[2010.09.07 20:14:59 | 004,182,178 | ---- | C] (The Public) -- C:\Users\romy\AppData\Roaming\Avisynth.exe
[3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[2 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012.11.12 20:38:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.11.12 20:15:00 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.11.12 19:21:30 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.11.12 15:13:09 | 000,657,660 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.11.12 15:13:09 | 000,618,936 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.11.12 15:13:09 | 000,131,032 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.11.12 15:13:09 | 000,107,256 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.11.12 10:30:16 | 000,015,792 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.11.12 10:30:16 | 000,015,792 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.11.12 10:23:16 | 000,001,090 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.11.12 10:22:51 | 2415,370,240 | -HS- | M] () -- C:\hiberfil.sys
[2012.11.12 10:22:50 | 001,875,913 | ---- | M] () -- C:\Windows\System32\oodbs.lor
[2012.11.11 12:18:35 | 000,002,290 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2012.11.11 11:40:14 | 000,697,272 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2012.11.11 11:40:14 | 000,073,656 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012.11.09 10:26:50 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\romy\Desktop\OTL.exe
[2012.11.08 20:20:44 | 000,541,569 | ---- | M] () -- C:\Users\romy\Desktop\adwcleaner.exe
[2012.10.31 14:57:24 | 000,001,294 | ---- | M] () -- C:\Users\romy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Produktregistrierung.lnk
[2012.10.30 21:31:42 | 000,001,185 | ---- | M] () -- C:\Users\romy\Desktop\Acronis True Image WD Edition.lnk
[2012.10.30 21:31:40 | 000,601,408 | ---- | M] (Acronis) -- C:\Windows\System32\drivers\timntr.sys
[2012.10.30 21:31:33 | 000,125,472 | ---- | M] (Acronis) -- C:\Windows\System32\drivers\vididr.sys
[2012.10.30 21:31:31 | 000,083,392 | ---- | M] (Acronis) -- C:\Windows\System32\drivers\vsflt53.sys
[2012.10.30 21:31:29 | 000,169,088 | ---- | M] (Acronis) -- C:\Windows\System32\drivers\snapman.sys
[2012.10.29 17:33:07 | 000,093,672 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll
[2012.10.29 17:33:04 | 000,246,760 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaws.exe
[2012.10.29 17:33:04 | 000,174,056 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
[2012.10.29 17:33:03 | 000,174,056 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\java.exe
[2012.10.29 17:33:02 | 000,821,736 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\npDeployJava1.dll
[2012.10.22 12:21:26 | 000,001,270 | ---- | M] () -- C:\Users\Public\Desktop\Ashampoo Slideshow Studio HD 2.lnk
[2012.10.20 14:23:02 | 245,439,962 | ---- | M] () -- C:\registry-20121020_15.22h.reg
[2012.10.20 14:14:31 | 245,396,624 | ---- | M] () -- C:\registry-20121020_15.13h.reg
[2012.10.17 20:36:08 | 244,928,614 | ---- | M] () -- C:\registry-20121017_21.36h.reg
[2012.10.17 20:36:08 | 244,928,614 | ---- | M] () -- C:\registry-20121017.reg
[3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[2 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012.11.11 11:41:23 | 000,002,290 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2012.11.08 20:20:43 | 000,541,569 | ---- | C] () -- C:\Users\romy\Desktop\adwcleaner.exe
[2012.10.31 14:57:24 | 000,001,294 | ---- | C] () -- C:\Users\romy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Produktregistrierung.lnk
[2012.10.30 21:31:42 | 000,001,185 | ---- | C] () -- C:\Users\romy\Desktop\Acronis True Image WD Edition.lnk
[2012.10.20 14:22:27 | 245,439,962 | ---- | C] () -- C:\registry-20121020_15.22h.reg
[2012.10.20 14:14:20 | 245,396,624 | ---- | C] () -- C:\registry-20121020_15.13h.reg
[2012.10.17 21:46:47 | 244,928,614 | ---- | C] () -- C:\registry-20121017_21.36h.reg
[2012.10.17 20:35:56 | 244,928,614 | ---- | C] () -- C:\registry-20121017.reg
[2012.10.16 19:53:29 | 000,001,270 | ---- | C] () -- C:\Users\Public\Desktop\Ashampoo Slideshow Studio HD 2.lnk
[2012.09.04 20:17:43 | 000,000,132 | ---- | C] () -- C:\Users\romy\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2012.01.02 11:24:34 | 000,011,264 | ---- | C] () -- C:\Users\romy\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.04.04 14:26:24 | 000,003,485 | ---- | C] () -- C:\Users\romy\.recently-used.xbel
[2011.02.08 17:36:07 | 003,486,336 | ---- | C] () -- C:\Windows\System32\drivers\snp2uvc.sys
[2011.02.08 17:36:07 | 000,241,664 | ---- | C] ( ) -- C:\Windows\System32\rsnp2uvc.dll
[2011.02.08 17:36:07 | 000,196,608 | ---- | C] ( ) -- C:\Windows\System32\csnp2uvc.dll
[2011.02.08 17:36:07 | 000,028,544 | ---- | C] () -- C:\Windows\System32\drivers\sncduvc.sys
[2011.02.08 17:36:07 | 000,015,497 | ---- | C] () -- C:\Windows\snp2uvc.ini
[2011.02.08 17:36:06 | 000,172,103 | ---- | C] () -- C:\Windows\BM.exe
[2011.02.08 16:29:07 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2011.01.07 19:54:29 | 000,016,968 | ---- | C] () -- C:\Windows\System32\drivers\hitmanpro35.sys
[2010.12.17 18:32:29 | 000,000,132 | ---- | C] () -- C:\Users\romy\AppData\Roaming\Adobe GIF Format CS5 Prefs
[2010.09.07 20:15:43 | 005,243,208 | ---- | C] ( ) -- C:\Users\romy\AppData\Roaming\AvsP.exe
[2010.03.19 23:56:40 | 000,007,679 | ---- | C] () -- C:\Users\romy\AppData\Local\Resmon.ResmonCfg
[2010.03.16 11:37:45 | 000,696,277 | ---- | C] () -- C:\Users\romy\AppData\Roaming\unins000.exe
[2010.03.16 11:37:45 | 000,001,270 | ---- | C] () -- C:\Users\romy\AppData\Roaming\unins000.dat
[2009.11.04 23:27:52 | 000,002,925 | ---- | C] () -- C:\Users\romy\pspbrwse.jbf
[2009.10.16 00:40:19 | 000,224,917 | ---- | C] () -- C:\Users\romy\artur01.jpg
========== ZeroAccess Check ==========
[2009.07.14 05:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
= %SystemRoot%\system32\shell32.dll -- [2012.06.09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
ThreadingModel = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
= %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
ThreadingModel = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
= %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 02:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
ThreadingModel = Both
========== Alternate Data Streams ==========
@Alternate Data Stream - 4264 bytes -> C:\Users\romy\artur01.jpg:Q30lsldxJoudresxAaaqpcawXc
< End of report >