Jump to content

extra explorer.exe and csrss.exe, winlogon.exe in task manager with no descriptions


Recommended Posts

Hi, just yesterday or the day before I noticed how slow my computer was.  I opened up task manager and saw there was an extra explorer.exe process running along with multiple weird processes, abhqft.exe?, described as google chrome when google chrome wasn't running.  I uninstalled google chrome and the processes still existed.  I scanned with Microsoft Security Essentials and deleted the viruses it found.  I also did an internet search and found websites like this and tried following along with other people's problems and downloaded malwarebytes.  It seemed to get rid of the abhqft.exe google chrome processes but the extra explorer.exe still remains and takes up a ton of memory sometimes.  I also have csrss.exe and winlogon.exe files with no description and didn't know if they have anything to do with all of this or if they are legit.  Please help.  Thanks.

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 28-12-2014
Ran by Kaz (administrator) on KAZ-PC on 28-12-2014 15:50:17
Running from D:\Users\Kaz\Desktop
Loaded Profile: Kaz (Available profiles: Kaz)
Platform: Microsoft Windows 7 Professional  Service Pack 1 (X86) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) D:\Program Files\Microsoft Security Client\MsMpEng.exe
(Apple Inc.) D:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) D:\Program Files\Bonjour\mDNSResponder.exe
(Foxit Software Inc.) D:\Program Files\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe
(Microsoft Corp.) D:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) D:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) D:\Windows\System32\igfxtray.exe
(Intel Corporation) D:\Windows\System32\hkcmd.exe
(Intel Corporation) D:\Windows\System32\igfxpers.exe
(Alps Electric Co., Ltd.) D:\Program Files\DellTPad\Apoint.exe
(Alps Electric Co., Ltd.) D:\Program Files\DellTPad\ApMsgFwd.exe
(Alps Electric Co., Ltd.) D:\Program Files\DellTPad\hidfind.exe
(Piriform Ltd) D:\Program Files\CCleaner\CCleaner.exe
(Mozilla Corporation) D:\Program Files\Mozilla Firefox\firefox.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [MSC] => D:\Program Files\Microsoft Security Client\msseces.exe [974432 2014-08-22] (Microsoft Corporation)
HKLM\...\Run: [Apoint] => D:\Program Files\DellTPad\Apoint.exe [288040 2010-04-05] (Alps Electric Co., Ltd.)
HKLM\...\Run: [iTSecMng] => D:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe [80840 2011-04-01] (TOSHIBA CORPORATION)
HKU\S-1-5-21-268619972-1601856392-350134406-1000\...\Run: [CCleaner Monitoring] => D:\Program Files\CCleaner\CCleaner.exe [5489944 2014-12-12] (Piriform Ltd)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-268619972-1601856392-350134406-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-268619972-1601856392-350134406-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-268619972-1601856392-350134406-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab
Handler: WSAMVCUchrome - {086BD280-4613-43B5 -  No File
Winsock: Catalog5 07 D:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 72.240.13.7 72.240.13.5

FireFox:
========
FF ProfilePath: D:\Users\Kaz\AppData\Roaming\Mozilla\Firefox\Profiles\gkkm8ux6.default
FF Plugin: @adobe.com/FlashPlayer -> D:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_235.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> D:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> D:\PROGRAM FILES\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @microsoft.com/WLPG,version=16.4.3528.0331 -> D:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Extension: Adblock Plus - D:\Users\Kaz\AppData\Roaming\Mozilla\Firefox\Profiles\gkkm8ux6.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-11-18]
FF HKLM\...\Firefox\Extensions: [AMVCU@Aimersoft.com] - D:\ProgramData\Aimersoft\Video Converter Ultimate\AMVCU@Aimersoft.com

Chrome:
=======
CHR HomePage: Default -> 3CF18FBF7D03DE8DA97748A5D140B1BBEB2F4445C0067F4AAC825BF369F56159
CHR Profile: D:\Users\Kaz\AppData\Local\Google\Chrome\User Data\Default

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 FoxitCloudUpdateService; D:\PROGRAM FILES\FOXIT SOFTWARE\FOXIT READER\Foxit Cloud\FCUpdateService.exe [242912 2014-09-11] (Foxit Software Inc.)
R2 MsMpSvc; d:\Program Files\Microsoft Security Client\MsMpEng.exe [22192 2014-08-22] (Microsoft Corporation)
S3 NisSrv; d:\Program Files\Microsoft Security Client\NisSrv.exe [288120 2014-08-22] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R0 MpFilter; D:\Windows\System32\DRIVERS\MpFilter.sys [231800 2014-07-17] (Microsoft Corporation)
S3 pwdrvio; D:\Windows\system32\pwdrvio.sys [15688 2013-09-30] ()
S3 pwdspio; D:\Windows\system32\pwdspio.sys [10320 2013-09-30] ()
R3 yukonw7; D:\Windows\System32\DRIVERS\yk62x86.sys [315392 2009-09-28] ()
U3 catchme; \??\D:\Users\Kaz\AppData\Local\Temp\catchme.sys [X]
S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [X]
S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [X]
S2 VBoxDRV; \??\G:\Portable-VirtualBox\app32\drivers\VBoxDrv\VBoxDrv.sys [X]
S2 VBoxUSBMon; \??\G:\Portable-VirtualBox\app32\drivers\USB\filter\VBoxUSBMon.sys [X]
U3 mbr; \??\D:\ComboFix\mbr.sys [X]

==================== NetSvcs (Whitelisted) ===================


(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-12-28 15:50 - 2014-12-28 15:50 - 00006848 _____ () D:\Users\Kaz\Desktop\FRST.txt
2014-12-28 15:50 - 2014-12-28 15:50 - 00000000 ____D () D:\FRST
2014-12-28 15:48 - 2014-12-28 15:49 - 01114624 _____ (Farbar) D:\Users\Kaz\Desktop\FRST.exe
2014-12-28 15:45 - 2014-12-28 15:46 - 20447072 _____ (Malwarebytes Corporation ) D:\Users\Kaz\Downloads\mbam-setup-2.0.4.1028(1).exe
2014-12-28 15:36 - 2014-12-28 15:36 - 00009984 _____ () D:\ComboFix.txt
2014-12-28 15:22 - 2014-12-28 15:36 - 00000000 ____D () D:\Qoobox
2014-12-28 15:22 - 2011-06-26 01:45 - 00256000 _____ () D:\Windows\PEV.exe
2014-12-28 15:22 - 2010-11-07 12:20 - 00208896 _____ () D:\Windows\MBR.exe
2014-12-28 15:22 - 2009-04-19 23:56 - 00060416 _____ (NirSoft) D:\Windows\NIRCMD.exe
2014-12-28 15:22 - 2000-08-30 19:00 - 00518144 _____ (SteelWerX) D:\Windows\SWREG.exe
2014-12-28 15:22 - 2000-08-30 19:00 - 00406528 _____ (SteelWerX) D:\Windows\SWSC.exe
2014-12-28 15:22 - 2000-08-30 19:00 - 00098816 _____ () D:\Windows\sed.exe
2014-12-28 15:22 - 2000-08-30 19:00 - 00080412 _____ () D:\Windows\grep.exe
2014-12-28 15:22 - 2000-08-30 19:00 - 00068096 _____ () D:\Windows\zip.exe
2014-12-28 15:21 - 2014-12-28 15:35 - 00000000 ____D () D:\Windows\erdnt
2014-12-28 15:19 - 2014-12-28 15:19 - 05603624 ____R (Swearware) D:\Users\Kaz\Desktop\ComboFix.exe
2014-12-28 15:06 - 2014-12-28 15:06 - 00000056 _____ () D:\Windows\setupact.log
2014-12-28 15:06 - 2014-12-28 15:06 - 00000000 _____ () D:\Windows\setuperr.log
2014-12-28 15:03 - 2014-12-28 15:04 - 04187592 _____ (Kaspersky Lab ZAO) D:\Users\Kaz\Downloads\tdsskiller.exe
2014-12-28 14:31 - 2014-12-28 14:31 - 00701616 _____ (Adobe Systems Incorporated) D:\Windows\system32\FlashPlayerApp.exe
2014-12-28 14:31 - 2014-12-28 14:31 - 00071344 _____ (Adobe Systems Incorporated) D:\Windows\system32\FlashPlayerCPLApp.cpl
2014-12-28 03:54 - 2014-12-28 07:22 - 00000000 ____D () D:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-12-28 03:54 - 2014-12-28 07:22 - 00000000 ____D () D:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-12-28 03:53 - 2014-12-28 07:22 - 00000000 ____D () D:\Users\Kaz\Desktop\mbar
2014-12-28 03:51 - 2014-12-28 03:52 - 16448208 _____ (Malwarebytes Corp.) D:\Users\Kaz\Downloads\mbar-1.08.2.1001.exe
2014-12-28 03:39 - 2014-12-28 03:39 - 00000000 ____D () D:\Users\Kaz\Downloads\ProcessExplorer
2014-12-28 03:38 - 2014-12-28 03:38 - 01188194 _____ () D:\Users\Kaz\Downloads\ProcessExplorer.zip
2014-12-27 23:20 - 2014-12-27 23:20 - 00000000 ____D () D:\Windows\pss
2014-12-27 22:50 - 2014-12-28 01:31 - 00000000 ____D () D:\AdwCleaner
2014-12-27 20:28 - 2014-12-28 15:46 - 00114904 _____ (Malwarebytes Corporation) D:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-12-27 20:27 - 2014-12-27 20:27 - 00001060 _____ () D:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-12-27 20:27 - 2014-12-27 20:27 - 00000000 ____D () D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-12-27 20:27 - 2014-12-27 20:27 - 00000000 ____D () D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-12-27 20:26 - 2014-12-28 07:27 - 00079576 _____ (Malwarebytes Corporation) D:\Windows\system32\Drivers\mbamchameleon.sys
2014-12-27 20:26 - 2014-12-27 20:27 - 00000000 ____D () D:\Program Files\Malwarebytes Anti-Malware
2014-12-27 20:26 - 2014-12-27 20:26 - 00000000 ____D () D:\ProgramData\Malwarebytes
2014-12-27 20:26 - 2014-12-27 20:26 - 00000000 ____D () D:\ProgramData\Malwarebytes
2014-12-27 20:26 - 2014-11-21 06:14 - 00051928 _____ (Malwarebytes Corporation) D:\Windows\system32\Drivers\mwac.sys
2014-12-27 20:26 - 2014-11-21 06:14 - 00023256 _____ (Malwarebytes Corporation) D:\Windows\system32\Drivers\mbam.sys
2014-12-27 20:24 - 2014-12-27 20:25 - 02173952 _____ () D:\Users\Kaz\Downloads\AdwCleaner.exe
2014-12-27 20:23 - 2014-12-27 20:25 - 20447072 _____ (Malwarebytes Corporation ) D:\Users\Kaz\Downloads\mbam-setup-2.0.4.1028.exe
2014-12-27 04:41 - 2014-12-27 04:41 - 03148854 _____ () D:\Users\Kaz\Downloads\Decrypt All Files dbkpkmg.bmp
2014-12-27 04:37 - 2014-12-27 22:45 - 00000000 ____D () D:\ProgramData\PacefTazuv
2014-12-27 04:37 - 2014-12-27 22:45 - 00000000 ____D () D:\ProgramData\PacefTazuv
2014-12-26 01:16 - 2014-12-28 15:36 - 00000000 ___HD () D:\ProgramData\{D9E629DC-CB1C-4A97-9900-81922B4EFFD4}
2014-12-26 01:16 - 2014-12-28 15:36 - 00000000 ___HD () D:\ProgramData\{D9E629DC-CB1C-4A97-9900-81922B4EFFD4}
2014-12-23 16:16 - 2014-12-23 16:16 - 03725842 _____ () D:\Users\Kaz\Downloads\2015 Porsche Cayenne Commercial Lunch With the New Porsche Cayenne.flv
2014-12-22 11:15 - 2014-12-22 11:17 - 52228181 _____ () D:\Users\Kaz\Downloads\Halo 3 Main Menu Music - HD 1080p.mp4
2014-12-22 01:48 - 2014-12-22 01:48 - 01221261 _____ () D:\Users\Kaz\Downloads\AT&T Commercial - Zero.flv
2014-12-21 20:59 - 2014-12-21 20:59 - 00672752 _____ () D:\Users\Kaz\Downloads\Olivia-Munn-1.jpeg
2014-12-21 06:36 - 2014-12-21 06:36 - 00038958 _____ () D:\Users\Kaz\Downloads\654vsad.jpeg
2014-12-21 06:36 - 2014-12-21 06:36 - 00029107 _____ () D:\Users\Kaz\Downloads\187vsda.jpeg
2014-12-21 06:26 - 2014-12-21 06:26 - 00045985 _____ () D:\Users\Kaz\Downloads\274.jpeg
2014-12-19 02:15 - 2014-12-27 04:46 - 00000000 ____D () D:\Users\Kaz\Downloads\Infinite Prosperity Blog tom russel r8 v10_files
2014-12-19 02:15 - 2014-12-19 02:15 - 00039299 _____ () D:\Users\Kaz\Downloads\Infinite Prosperity Blog tom russel r8 v10.htm
2014-12-19 01:47 - 2014-12-19 01:47 - 01090375 _____ () D:\Users\Kaz\Downloads\Infinite Prosperity Pro Traders Journal.zip
2014-12-19 01:45 - 2014-12-27 04:51 - 00000000 ____D () D:\Users\Kaz\Downloads\Active Trader_files
2014-12-19 01:45 - 2014-12-19 01:45 - 00051488 _____ () D:\Users\Kaz\Downloads\Active Trader.htm
2014-12-19 01:36 - 2014-12-27 04:51 - 00000000 ____D () D:\Users\Kaz\Downloads\Infinite Prosperity Active Trader_files
2014-12-19 01:36 - 2014-12-19 01:36 - 00052910 _____ () D:\Users\Kaz\Downloads\Infinite Prosperity Active Trader.htm
2014-12-19 01:35 - 2014-12-27 04:51 - 00000000 ____D () D:\Users\Kaz\Downloads\Lesson 10 - Moving Forward_files
2014-12-19 01:35 - 2014-12-19 01:35 - 00177310 _____ () D:\Users\Kaz\Downloads\Lesson 10 - Moving Forward.htm
2014-12-19 01:18 - 2014-12-27 04:51 - 00000000 ____D () D:\Users\Kaz\Downloads\Strategy 3 - Reversals_files
2014-12-19 01:18 - 2014-12-19 01:18 - 00107808 _____ () D:\Users\Kaz\Downloads\Strategy 3 - Reversals.htm
2014-12-19 01:16 - 2014-12-27 04:51 - 00000000 ____D () D:\Users\Kaz\Downloads\Strategy 2 - Bounces_files
2014-12-19 01:16 - 2014-12-19 01:16 - 00105061 _____ () D:\Users\Kaz\Downloads\Strategy 2 - Bounces.htm
2014-12-19 01:14 - 2014-12-27 04:51 - 00000000 ____D () D:\Users\Kaz\Downloads\Strategy 1 - Power Trends_files
2014-12-19 01:14 - 2014-12-19 01:14 - 00089752 _____ () D:\Users\Kaz\Downloads\Strategy 1 - Power Trends.htm
2014-12-19 01:05 - 2014-12-27 04:51 - 00000000 ____D () D:\Users\Kaz\Downloads\Lesson 9 - Journaling_files
2014-12-19 01:05 - 2014-12-19 01:05 - 00074666 _____ () D:\Users\Kaz\Downloads\Lesson 9 - Journaling.htm
2014-12-19 01:03 - 2014-12-27 04:51 - 00000000 ____D () D:\Users\Kaz\Downloads\Lesson 8 - Goal Setting_files
2014-12-19 01:03 - 2014-12-19 01:03 - 00122880 _____ () D:\Users\Kaz\Downloads\Lesson 8 - Goal Setting.htm
2014-12-19 00:39 - 2014-12-27 04:51 - 00000000 ____D () D:\Users\Kaz\Downloads\Lesson 7 - Mindset_files
2014-12-19 00:39 - 2014-12-19 00:39 - 00128402 _____ () D:\Users\Kaz\Downloads\Lesson 7 - Mindset.htm
2014-12-19 00:33 - 2014-12-27 04:51 - 00000000 ____D () D:\Users\Kaz\Downloads\Lesson 6 - Trading an Edge_files
2014-12-19 00:33 - 2014-12-19 00:33 - 00131603 _____ () D:\Users\Kaz\Downloads\Lesson 6 - Trading an Edge.htm
2014-12-19 00:31 - 2014-12-27 04:51 - 00000000 ____D () D:\Users\Kaz\Downloads\Lesson 5 - Using FXCM_files
2014-12-19 00:31 - 2014-12-19 00:31 - 00169343 _____ () D:\Users\Kaz\Downloads\Lesson 5 - Using FXCM.htm
2014-12-19 00:29 - 2014-12-27 04:51 - 00000000 ____D () D:\Users\Kaz\Downloads\Lesson 4 - Technical Analysis_files
2014-12-19 00:29 - 2014-12-19 00:29 - 00134146 _____ () D:\Users\Kaz\Downloads\Lesson 4 - Technical Analysis.htm
2014-12-19 00:26 - 2014-12-27 04:51 - 00000000 ____D () D:\Users\Kaz\Downloads\Lesson 3 - Risk Management_files
2014-12-19 00:26 - 2014-12-19 00:26 - 00155884 _____ () D:\Users\Kaz\Downloads\Lesson 3 - Risk Management.htm
2014-12-19 00:19 - 2014-12-27 04:51 - 00000000 ____D () D:\Users\Kaz\Downloads\Lesson 2 - Psychology_files
2014-12-19 00:19 - 2014-12-19 00:19 - 00115004 _____ () D:\Users\Kaz\Downloads\Lesson 2 - Psychology.htm
2014-12-19 00:17 - 2014-12-27 04:51 - 00000000 ____D () D:\Users\Kaz\Downloads\Lesson 1 - Introduction to Forex Trading_files
2014-12-19 00:17 - 2014-12-19 00:17 - 00131784 _____ () D:\Users\Kaz\Downloads\Lesson 1 - Introduction to Forex Trading.htm
2014-12-19 00:13 - 2014-12-27 04:51 - 00000000 ____D () D:\Users\Kaz\Downloads\About our Lessons_files
2014-12-19 00:13 - 2014-12-19 00:13 - 00058723 _____ () D:\Users\Kaz\Downloads\About our Lessons.htm
2014-12-18 23:56 - 2014-12-27 04:51 - 00000000 ____D () D:\Users\Kaz\Downloads\Infinite Prosperity - Photosof _ Facebook_files
2014-12-18 23:56 - 2014-12-18 23:56 - 01100913 _____ () D:\Users\Kaz\Downloads\Infinite Prosperity - Photosof _ Facebook.htm
2014-12-18 23:51 - 2014-12-27 04:51 - 00000000 ____D () D:\Users\Kaz\Downloads\Infinite Prosperity - Photos _ Facebook_files
2014-12-18 23:51 - 2014-12-18 23:51 - 01410271 _____ () D:\Users\Kaz\Downloads\Infinite Prosperity - Photos _ Facebook.htm
2014-12-18 23:42 - 2014-12-27 04:51 - 00000000 ____D () D:\Users\Kaz\Downloads\When is it a good idea to take out a loan to invest_files
2014-12-18 23:42 - 2014-12-18 23:42 - 00132567 _____ () D:\Users\Kaz\Downloads\When is it a good idea to take out a loan to invest.htm
2014-12-18 23:15 - 2014-12-27 04:58 - 00000000 ____D () D:\Users\Kaz\Downloads\InfiniteProsperityTV - YouTube_files
2014-12-18 23:15 - 2014-12-18 23:15 - 00196082 _____ () D:\Users\Kaz\Downloads\InfiniteProsperityTV - YouTube.htm
2014-12-18 23:14 - 2014-12-27 04:58 - 00000000 ____D () D:\Users\Kaz\Downloads\Infinite Prosperity _ Facebook_files
2014-12-18 23:14 - 2014-12-18 23:14 - 03639474 _____ () D:\Users\Kaz\Downloads\Infinite Prosperity _ Facebook.htm
2014-12-18 23:02 - 2014-12-18 23:03 - 09867166 _____ () D:\Users\Kaz\Downloads\WorldStarCandy  SEXI MODEL Metafoka Crew..flv
2014-12-18 22:57 - 2014-12-18 22:57 - 11799989 _____ () D:\Users\Kaz\Downloads\Infinite Prosperity - August Web Conference (Snippet).flv
2014-12-18 21:08 - 2014-12-18 21:08 - 53387054 _____ () D:\Users\Kaz\Downloads\GTA 5 Online - MAKE THE JUMP! Playlist [PS4].flv
2014-12-18 20:30 - 2014-12-18 20:30 - 00117011 _____ () D:\Users\Kaz\Downloads\kim-kardashian-and-kris-jenner-for-skechers-shape-ups shape up video game commercial.jpeg
2014-12-18 16:10 - 2014-12-18 16:10 - 00007062 _____ () D:\Users\Kaz\Downloads\198.jpeg
2014-12-18 16:08 - 2014-12-18 16:08 - 00025531 _____ () D:\Users\Kaz\Downloads\324t.jpeg
2014-12-18 16:08 - 2014-12-18 16:08 - 00009677 _____ () D:\Users\Kaz\Downloads\794.jpeg
2014-12-18 04:45 - 2014-12-18 04:45 - 00032796 _____ () D:\Users\Kaz\Downloads\9n6UGcx9.jpeg
2014-12-18 03:56 - 2014-12-18 03:56 - 00058865 _____ () D:\Users\Kaz\Downloads\520 Sporty gal in yoga pants loves than anything on Earth.jpeg
2014-12-18 03:55 - 2014-12-18 03:55 - 00050639 _____ () D:\Users\Kaz\Downloads\795rbb.jpeg
2014-12-18 03:55 - 2014-12-18 03:55 - 00050639 _____ () D:\Users\Kaz\Downloads\795 vsa.jpeg
2014-12-18 03:55 - 2014-12-18 03:55 - 00032304 _____ () D:\Users\Kaz\Downloads\347.jpeg
2014-12-18 03:55 - 2014-12-18 03:55 - 00029107 _____ () D:\Users\Kaz\Downloads\187.jpeg
2014-12-18 03:55 - 2014-12-18 03:55 - 00005902 _____ () D:\Users\Kaz\Downloads\527.jpeg
2014-12-18 03:54 - 2014-12-18 03:54 - 00050639 _____ () D:\Users\Kaz\Downloads\795.jpeg
2014-12-18 03:54 - 2014-12-18 03:54 - 00050134 _____ () D:\Users\Kaz\Downloads\319.jpeg
2014-12-18 03:54 - 2014-12-18 03:54 - 00023527 _____ () D:\Users\Kaz\Downloads\159.jpeg
2014-12-18 03:49 - 2014-12-18 03:49 - 00465703 _____ () D:\Users\Kaz\Downloads\905.jpeg
2014-12-18 03:49 - 2014-12-18 03:49 - 00382014 _____ () D:\Users\Kaz\Downloads\218.jpeg
2014-12-18 03:49 - 2014-12-18 03:49 - 00221502 _____ () D:\Users\Kaz\Downloads\571.jpeg
2014-12-18 03:49 - 2014-12-18 03:49 - 00075632 _____ () D:\Users\Kaz\Downloads\442.jpeg
2014-12-18 03:49 - 2014-12-18 03:49 - 00070273 _____ () D:\Users\Kaz\Downloads\247.jpeg
2014-12-18 03:49 - 2014-12-18 03:49 - 00058865 _____ () D:\Users\Kaz\Downloads\520.jpeg
2014-12-18 03:39 - 2014-12-18 03:39 - 05275298 _____ () D:\Users\Kaz\Downloads\144645973 apt4 relaunchteaser 2.mp4
2014-12-18 03:38 - 2014-12-18 03:38 - 25485713 _____ () D:\Users\Kaz\Downloads\Testobooster by Timofey HD.mp4
2014-12-18 03:37 - 2014-12-18 03:38 - 00630249 _____ () D:\Users\Kaz\Downloads\This woman is pure sexiness! Hot booty ass latina girl.mp4
2014-12-18 03:37 - 2014-12-18 03:37 - 01431983 _____ () D:\Users\Kaz\Downloads\Sex sport girl cool ass.flv
2014-12-18 03:31 - 2014-12-18 03:31 - 00091641 _____ () D:\Users\Kaz\Downloads\hhtrtrhswtrh.jpeg
2014-12-18 03:31 - 2014-12-18 03:31 - 00086881 _____ () D:\Users\Kaz\Downloads\trhhttrrt.jpeg
2014-12-17 22:24 - 2014-12-17 22:24 - 00010226 _____ () D:\Users\Kaz\Desktop\gshdf.xspf
2014-12-17 22:12 - 2014-12-17 22:12 - 00102028 _____ () D:\Users\Kaz\Downloads\da-dianna-agron-s-breasts-are-too-rude-for-the-internet.jpeg
2014-12-17 22:10 - 2014-12-17 22:10 - 00079740 _____ () D:\Users\Kaz\Downloads\900x900px-LL-f6a59794_SASHA-GREY-ASS-TOP10-PICTURES-EVER.jpeg
2014-12-17 22:10 - 2014-12-17 22:10 - 00075195 _____ () D:\Users\Kaz\Downloads\900x900px-LL-a59b9e74_MAYBE-BEST-ASS-EVER.jpeg
2014-12-17 22:10 - 2014-12-17 22:10 - 00060205 _____ () D:\Users\Kaz\Downloads\900x900px-LL-36860260_maria_sharapova_ASS-beach_175-2.jpeg
2014-12-17 22:10 - 2014-12-17 22:10 - 00057457 _____ () D:\Users\Kaz\Downloads\900x900px-LL-a0229469_Elisha-Cuthbert-SEXY-AS-HELL-elisha-cuthbert-13579852-1200-1527.jpeg
2014-12-17 20:40 - 2014-12-17 20:40 - 00147098 _____ () D:\Users\Kaz\Downloads\JbccLQAs.jpeg
2014-12-17 20:40 - 2014-12-17 20:40 - 00033755 _____ () D:\Users\Kaz\Downloads\adfa92f1d78fa572106d6e2b9f538354.jpeg
2014-12-17 20:40 - 2014-12-17 20:40 - 00032796 _____ () D:\Users\Kaz\Downloads\bf015dfcdfb2e135a98172199c0acbd2.jpeg
2014-12-17 20:40 - 2014-12-17 20:40 - 00024875 _____ () D:\Users\Kaz\Downloads\fF9YJ1ip.jpeg
2014-12-17 20:39 - 2014-12-17 20:39 - 00024875 _____ () D:\Users\Kaz\Downloads\aCq7jrCi.jpeg
2014-12-17 18:29 - 2014-12-12 22:33 - 00115712 _____ (Microsoft Corporation) D:\Windows\system32\ieUnatt.exe
2014-12-17 07:30 - 2014-12-17 07:30 - 00015888 _____ () D:\Users\Kaz\Desktop\uygihij.xspf
2014-12-17 06:21 - 2014-12-17 06:21 - 03638794 _____ () D:\Users\Kaz\Downloads\Star of Wonder  - Sara Groves.flv
2014-12-17 04:42 - 2014-12-17 04:55 - 70190147 _____ () D:\Users\Kaz\Downloads\2015 Mercedes-Benz GLA45 AMG 4Matic Start Up, Exhaust, and In Depth Review.flv
2014-12-16 23:53 - 2014-12-16 23:53 - 00000000 ____D () D:\Users\Kaz\Documents\My ooVoo
2014-12-16 21:56 - 2014-12-16 22:28 - 127159029 _____ () D:\Users\Kaz\Downloads\Amy Sangster and Lewis Mocker - What We Do.flv
2014-12-16 21:38 - 2014-12-27 04:58 - 00000000 ____D () D:\Users\Kaz\Downloads\New York Yankees GM Brian Cashman  Alex Rodriguez now a full-time DH - ESPN New York_files
2014-12-16 21:38 - 2014-12-16 21:38 - 00102100 _____ () D:\Users\Kaz\Downloads\New York Yankees GM Brian Cashman  Alex Rodriguez now a full-time DH - ESPN New York.htm
2014-12-16 20:35 - 2014-12-16 20:37 - 12016270 _____ () D:\Users\Kaz\Downloads\Insanity Max 30 Test Group Week 2 Confession.flv
2014-12-16 20:09 - 2014-12-16 20:09 - 00040787 _____ () D:\Users\Kaz\Downloads\d3ed4096085a64973dc4589468be03951260369556.jpeg
2014-12-16 18:54 - 2014-12-16 18:54 - 22972038 _____ () D:\Users\Kaz\Downloads\1340246_10153316697725001_46149_n.mp4
2014-12-16 18:46 - 2014-12-16 18:51 - 92215660 _____ () D:\Users\Kaz\Downloads\10433813_1530789507179315_1470349348_n insanity max 30.mp4
2014-12-16 00:22 - 2014-12-16 00:23 - 05934408 _____ () D:\Users\Kaz\Downloads\Baywatch Season 1 Opening Credits To  I'll Be Ready  Theme Song.flv
2014-12-16 00:17 - 2014-12-27 04:57 - 00000000 ____D () D:\Users\Kaz\Downloads\Insanity Max 30 Cast Member _ jessicabowsernelson.com_files
2014-12-16 00:17 - 2014-12-16 00:17 - 00101211 _____ () D:\Users\Kaz\Downloads\Insanity Max 30 Cast Member _ jessicabowsernelson.com.htm
2014-12-15 21:27 - 2014-12-15 21:27 - 00030070 _____ () D:\Users\Kaz\Downloads\teenslifebitchezr.htm
2014-12-15 21:26 - 2014-12-15 21:26 - 00030070 _____ () D:\Users\Kaz\Downloads\teenslifebitchez.htm
2014-12-15 21:26 - 2014-12-15 21:26 - 00003360 _____ () D:\Users\Kaz\Downloads\bbrnghher.htm
2014-12-15 21:09 - 2014-12-15 21:11 - 11455445 _____ () D:\Users\Kaz\Downloads\P90X Results and BodyBeast Transformation - TeamFitOne.com.flv
2014-12-14 22:01 - 2014-12-14 22:01 - 11628589 _____ () D:\Users\Kaz\Downloads\Kobe Bryant Gets Standing Ovation After Passing Mi.mp4
2014-12-14 18:36 - 2014-12-14 18:43 - 37600105 _____ () D:\Users\Kaz\Downloads\Gang Beasts Round 3 with Simon Honeydew!.flv
2014-12-14 17:56 - 2014-12-14 18:02 - 31455202 _____ () D:\Users\Kaz\Downloads\Q & A Session!.flv
2014-12-14 17:48 - 2014-12-14 17:48 - 00168456 _____ () D:\Users\Kaz\Downloads\Mercedes-Benz-G63-AMG-3.jpeg
2014-12-14 17:24 - 2014-12-14 17:25 - 10384810 _____ () D:\Users\Kaz\Downloads\Hitler Finds out Chuck Norris is Coming - [Episode Four].flv
2014-12-14 17:16 - 2014-12-14 17:18 - 09447589 _____ () D:\Users\Kaz\Downloads\Hitler Reacts to the Reds Losing to the Giants.flv
2014-12-14 16:59 - 2014-12-14 17:03 - 20111548 _____ () D:\Users\Kaz\Downloads\What Motivates Me....flv
2014-12-14 16:25 - 2014-12-14 16:25 - 00063418 _____ () D:\Users\Kaz\Downloads\nullg.jpeg
2014-12-14 16:25 - 2014-12-14 16:25 - 00024786 _____ () D:\Users\Kaz\Downloads\null.jpeg
2014-12-14 16:24 - 2014-12-14 16:24 - 00089289 _____ () D:\Users\Kaz\Downloads\http _hss-prod.hss.aol.com_hss_storage_midas_e2043a0d678100dd9ed86ebcc5e7aff2_201235330_cde5f0c2c9924619818442de586aa66f.jpeg
2014-12-14 16:22 - 2014-12-28 12:16 - 00000000 ____D () D:\Users\Kaz\Downloads\Given the way he prepares, Tom Brady won't be slowing down anytime soon _ SI.com_files
2014-12-14 16:22 - 2014-12-14 16:23 - 00825383 _____ () D:\Users\Kaz\Downloads\Given the way he prepares, Tom Brady won't be slowing down anytime soon _ SI.com.htm
2014-12-14 15:04 - 2014-12-14 15:12 - 42388258 _____ () D:\Users\Kaz\Downloads\Minecraft RFTW Team 2 #4- Cave of Hate.flv
2014-12-14 15:03 - 2014-12-14 15:14 - 60182633 _____ () D:\Users\Kaz\Downloads\Trials Evolution - Meat Grinder!.flv
2014-12-14 02:18 - 2014-12-14 02:27 - 51445127 _____ () D:\Users\Kaz\Downloads\Simple Simon Ep 3 Ft. Hat Films - Polaris.flv
2014-12-14 00:31 - 2014-12-14 00:31 - 22116511 _____ () D:\Users\Kaz\Downloads\Nothing From Nothing - Billy Preston.mp4
2014-12-13 22:39 - 2014-12-13 22:39 - 13170653 _____ () D:\Users\Kaz\Downloads\INSANITY MAX 30 DAY 5.mp4
2014-12-13 22:37 - 2014-12-13 22:37 - 09099680 _____ () D:\Users\Kaz\Downloads\INSANITY Max 30 Day 2 Review.mp4
2014-12-13 22:35 - 2014-12-13 22:35 - 10141756 _____ () D:\Users\Kaz\Downloads\INSANITY MAX 30 DAY 4.mp4
2014-12-13 21:28 - 2014-12-13 21:29 - 10306181 _____ () D:\Users\Kaz\Downloads\♪ Carrot For A Cock.flv
2014-12-13 20:45 - 2014-12-13 20:45 - 00086406 _____ () D:\Users\Kaz\Downloads\8224d3c662aef843b60ecbc1ec4aa173.jpeg
2014-12-13 20:31 - 2014-12-13 20:31 - 00066515 _____ () D:\Users\Kaz\Downloads\900x900px-LL-32661ce5_tumblr_nfqfstecst1qc5fpbo1_1280.jpeg
2014-12-13 20:30 - 2014-12-13 20:30 - 00014773 _____ () D:\Users\Kaz\Downloads\900x900px-LL-e9b70689_10844188_1523374784596950_114044614_a.jpeg
2014-12-13 03:15 - 2014-12-13 03:19 - 19550712 _____ () D:\Users\Kaz\Downloads\Bonfire - Sweet Home Alabama.mp4
2014-12-13 03:15 - 2014-12-13 03:15 - 23947170 _____ () D:\Users\Kaz\Downloads\Van Halen - Poundcake.mp4
2014-12-13 03:15 - 2014-12-13 03:15 - 14358844 _____ () D:\Users\Kaz\Downloads\Ratt - You're In Love.mp4
2014-12-13 03:14 - 2014-12-13 03:15 - 19681117 _____ () D:\Users\Kaz\Downloads\Judas Priest - Hot For Love.mp4
2014-12-13 03:14 - 2014-12-13 03:14 - 21102340 _____ () D:\Users\Kaz\Downloads\Van Halen - I'll Wait.mp4
2014-12-13 03:14 - 2014-12-13 03:14 - 19252920 _____ () D:\Users\Kaz\Downloads\Van Halen - Honeybabysweetiedoll.mp4
2014-12-12 20:04 - 2014-12-12 20:05 - 05653996 _____ () D:\Users\Kaz\Downloads\Inside Out Trailer 2 UK - Official Disney Pixar - HD.flv
2014-12-12 20:03 - 2014-12-12 20:08 - 24482620 _____ () D:\Users\Kaz\Downloads\INSANITY MAX -30. Day 5 Friday Fight Rd. 1. NC FIT CLUB.flv
2014-12-12 17:55 - 2014-12-12 17:55 - 12350537 _____ () D:\Users\Kaz\Downloads\Limp Bizkit - Rollin' (Air Raid Vehicle).flv
2014-12-12 17:50 - 2014-12-12 17:51 - 51191390 _____ () D:\Users\Kaz\Downloads\INSANITY MAX -30 Test Group Day 12 w-Shaun T.  NC FIT CLUB.mp4
2014-12-12 14:51 - 2014-12-12 14:51 - 00024875 _____ () D:\Users\Kaz\Downloads\3efdde7af1ab8cbd9b0e9fab138d2890.jpeg
2014-12-12 02:59 - 2014-12-12 03:07 - 43833347 _____ () D:\Users\Kaz\Downloads\A Fireside Hat - Livestream Announcement.flv
2014-12-12 02:35 - 2014-12-27 04:55 - 00000000 ____D () D:\Users\Kaz\Downloads\Los Angeles Lakers star Kobe Bryant critical of teammates during heated scrimmage - ESPN Los Angeles_files
2014-12-12 02:35 - 2014-12-12 02:35 - 00111309 _____ () D:\Users\Kaz\Downloads\Los Angeles Lakers star Kobe Bryant critical of teammates during heated scrimmage - ESPN Los Angeles.htm
2014-12-11 22:31 - 2014-12-11 22:31 - 00694557 _____ () D:\Users\Kaz\Downloads\wind-picture.jpeg
2014-12-11 21:24 - 2014-12-11 21:24 - 05006832 _____ (Adobe Systems Inc.) D:\Users\Kaz\Downloads\Shockwave_Installer_Slim.exe
2014-12-11 20:15 - 2014-12-11 20:15 - 00070574 _____ () D:\Users\Kaz\Downloads\transform+your+life+with+better+habits.jpeg
2014-12-11 17:28 - 2014-12-11 17:40 - 61734333 _____ () D:\Users\Kaz\Downloads\The Secret - First 20 mins.flv
2014-12-11 01:24 - 2014-12-11 01:24 - 04138848 _____ () D:\Users\Kaz\Downloads\Trisha demos the Back Hook Spin.mp4
2014-12-10 18:25 - 2014-12-10 18:35 - 55559326 _____ () D:\Users\Kaz\Downloads\GTA 5 Online - Vertigo (Not The U2 Song) - Playlist [PS4].flv
2014-12-10 17:42 - 2014-12-10 17:42 - 25460835 _____ () D:\Users\Kaz\Downloads\San Andreas - Official Teaser Trailer [HD].mp4
2014-12-10 17:27 - 2014-12-10 17:27 - 03188849 _____ () D:\Users\Kaz\Downloads\Picard - Make it So   - Let It Snow.mp4
2014-12-10 17:07 - 2014-12-10 17:07 - 00031616 _____ () D:\Users\Kaz\Downloads\50de23f79b8943f68c64a324ca5df0aa.jpeg
2014-12-10 17:03 - 2014-12-10 17:03 - 00154570 _____ () D:\Users\Kaz\Downloads\pippa-middleton-2013-wallpaper.jpeg
2014-12-10 15:00 - 2014-12-10 15:00 - 01650364 _____ () D:\Users\Kaz\Downloads\Эротика-сиськи-Emily-Ratajkowski-1045855.jpeg
2014-12-10 11:10 - 2014-12-10 11:10 - 00014242 _____ () D:\Users\Kaz\Downloads\n-HEALTHY-CITIES-2014-medium.jpeg
2014-12-10 02:43 - 2014-12-10 02:44 - 39289433 _____ () D:\Users\Kaz\Downloads\Karen McDougal.mp4
2014-12-10 02:35 - 2014-12-10 02:35 - 16986232 _____ () D:\Users\Kaz\Downloads\INSANITY MAX-30 is Now Available!.mp4
2014-12-10 02:26 - 2014-12-10 02:32 - 12932806 _____ () D:\Users\Kaz\Downloads\No Doubt - Don't Speak live.flv
2014-12-10 02:25 - 2014-12-10 02:25 - 00036170 _____ () D:\Users\Kaz\Downloads\photo_1341507018081-1-0.jpeg
2014-12-10 01:53 - 2014-11-26 20:10 - 00342200 _____ (Microsoft Corporation) D:\Windows\system32\iedkcs32.dll
2014-12-10 01:53 - 2014-11-21 21:22 - 19749376 _____ (Microsoft Corporation) D:\Windows\system32\mshtml.dll
2014-12-10 01:53 - 2014-11-21 21:20 - 02724864 _____ (Microsoft Corporation) D:\Windows\system32\mshtml.tlb
2014-12-10 01:53 - 2014-11-21 21:20 - 00004096 _____ (Microsoft Corporation) D:\Windows\system32\ieetwcollectorres.dll
2014-12-10 01:53 - 2014-11-21 21:07 - 00501248 _____ (Microsoft Corporation) D:\Windows\system32\vbscript.dll
2014-12-10 01:53 - 2014-11-21 21:07 - 00062464 _____ (Microsoft Corporation) D:\Windows\system32\iesetup.dll
2014-12-10 01:53 - 2014-11-21 21:06 - 00047616 _____ (Microsoft Corporation) D:\Windows\system32\ieetwproxystub.dll
2014-12-10 01:53 - 2014-11-21 21:05 - 00064000 _____ (Microsoft Corporation) D:\Windows\system32\MshtmlDac.dll
2014-12-10 01:53 - 2014-11-21 21:01 - 02277888 _____ (Microsoft Corporation) D:\Windows\system32\iertutil.dll
2014-12-10 01:53 - 2014-11-21 20:59 - 00047104 _____ (Microsoft Corporation) D:\Windows\system32\jsproxy.dll
2014-12-10 01:53 - 2014-11-21 20:58 - 00030720 _____ (Microsoft Corporation) D:\Windows\system32\iernonce.dll
2014-12-10 01:53 - 2014-11-21 20:56 - 00478208 _____ (Microsoft Corporation) D:\Windows\system32\ieui.dll
2014-12-10 01:53 - 2014-11-21 20:55 - 00102912 _____ (Microsoft Corporation) D:\Windows\system32\ieetwcollector.exe
2014-12-10 01:53 - 2014-11-21 20:54 - 00620032 _____ (Microsoft Corporation) D:\Windows\system32\jscript9diag.dll
2014-12-10 01:53 - 2014-11-21 20:48 - 00667648 _____ (Microsoft Corporation) D:\Windows\system32\MsSpellCheckingFacility.exe
2014-12-10 01:53 - 2014-11-21 20:45 - 00418304 _____ (Microsoft Corporation) D:\Windows\system32\dxtmsft.dll
2014-12-10 01:53 - 2014-11-21 20:40 - 00060416 _____ (Microsoft Corporation) D:\Windows\system32\JavaScriptCollectionAgent.dll
2014-12-10 01:53 - 2014-11-21 20:36 - 00168960 _____ (Microsoft Corporation) D:\Windows\system32\msrating.dll
2014-12-10 01:53 - 2014-11-21 20:35 - 00076288 _____ (Microsoft Corporation) D:\Windows\system32\mshtmled.dll
2014-12-10 01:53 - 2014-11-21 20:33 - 00285696 _____ (Microsoft Corporation) D:\Windows\system32\dxtrans.dll
2014-12-10 01:53 - 2014-11-21 20:29 - 04299264 _____ (Microsoft Corporation) D:\Windows\system32\jscript9.dll
2014-12-10 01:53 - 2014-11-21 20:23 - 00688640 _____ (Microsoft Corporation) D:\Windows\system32\msfeeds.dll
2014-12-10 01:53 - 2014-11-21 20:23 - 00684544 _____ (Microsoft Corporation) D:\Windows\system32\ie4uinit.exe
2014-12-10 01:53 - 2014-11-21 20:22 - 02052096 _____ (Microsoft Corporation) D:\Windows\system32\inetcpl.cpl
2014-12-10 01:53 - 2014-11-21 20:21 - 01155072 _____ (Microsoft Corporation) D:\Windows\system32\mshtmlmedia.dll
2014-12-10 01:53 - 2014-11-21 20:13 - 12836864 _____ (Microsoft Corporation) D:\Windows\system32\ieframe.dll
2014-12-10 01:53 - 2014-11-21 20:00 - 01888256 _____ (Microsoft Corporation) D:\Windows\system32\wininet.dll
2014-12-10 01:53 - 2014-11-21 19:56 - 01307136 _____ (Microsoft Corporation) D:\Windows\system32\urlmon.dll
2014-12-10 01:53 - 2014-11-21 19:54 - 00710144 _____ (Microsoft Corporation) D:\Windows\system32\ieapfltr.dll
2014-12-10 01:53 - 2014-11-10 21:44 - 01230336 _____ (Microsoft Corporation) D:\Windows\system32\WindowsCodecs.dll
2014-12-09 21:55 - 2014-12-09 21:55 - 00130208 _____ () D:\Users\Kaz\Downloads\171763_192743537411332_8088309_o2.jpeg
2014-12-09 21:52 - 2014-12-09 21:52 - 00028633 _____ () D:\Users\Kaz\Downloads\edd04042_karen_mcdougal23.jpeg
2014-12-09 21:34 - 2014-12-09 21:34 - 10277345 _____ () D:\Users\Kaz\Downloads\Tranquilizer to the Jugular - Old School (8-9) Movie CLIP (2003) HD.mp4
2014-12-09 21:29 - 2014-12-09 21:29 - 04142496 _____ () D:\Users\Kaz\Downloads\Joe Dirt poop scene.mp4
2014-12-09 21:28 - 2014-12-09 21:29 - 06759765 _____ () D:\Users\Kaz\Downloads\Snakes and Sparklers - Joe Dirt (3-8) Movie CLIP (2001) HD.flv
2014-12-09 20:57 - 2014-12-09 20:57 - 00129784 _____ () D:\Users\Kaz\Downloads\http _hss-prod.hss.aol.com_hss_storage_midas_7e8d0cec8962745ad5123d3646188f2e_201221303_a2d339ff00cc400c97463575833cb5f3.jpeg
2014-12-09 20:44 - 2014-12-09 20:44 - 00003411 _____ () D:\Users\Kaz\Desktop\vtgvg.xspf
2014-12-09 20:38 - 2014-12-09 20:38 - 00024267 _____ () D:\Users\Kaz\Downloads\JDd9S3eT_400x400.jpeg
2014-12-09 19:49 - 2014-12-09 19:54 - 27172438 _____ () D:\Users\Kaz\Downloads\Best Movies That Take Place In A Single Room.flv
2014-12-09 19:34 - 2014-12-09 19:34 - 01080054 _____ () D:\Users\Kaz\Downloads\energy.bmp
2014-12-09 18:56 - 2014-12-09 18:56 - 21659313 _____ () D:\Users\Kaz\Downloads\Technotronic - Pump Up The Jam.flv
2014-12-09 18:50 - 2014-12-09 18:51 - 07652110 _____ () D:\Users\Kaz\Downloads\THE POWER new book by Rhonda Byrne.mp4
2014-12-09 18:46 - 2014-12-09 18:46 - 56448925 _____ () D:\Users\Kaz\Downloads\Best self talk - talk to God Ever - Abraham Esther Hicks.mp4
2014-12-09 18:45 - 2014-12-09 18:45 - 16088682 _____ () D:\Users\Kaz\Downloads\Abraham-Hicks getting in vortex positives music subliminals part 2.mp4
2014-12-09 18:38 - 2014-12-09 18:43 - 27509964 _____ () D:\Users\Kaz\Downloads\GMod Boats #7 - Parasailing Simon (Garry's Mod).flv
2014-12-09 16:12 - 2014-12-09 16:12 - 04239195 _____ () D:\Users\Kaz\Downloads\12 Angry Men 1957 - Movie trailer.mp4
2014-12-09 15:17 - 2014-12-09 15:17 - 00337750 _____ () D:\Users\Kaz\Downloads\1758_1375884046u.bmp
2014-12-09 15:08 - 2014-12-09 15:08 - 00124112 _____ () D:\Users\Kaz\Downloads\52676490059.jpeg
2014-12-09 15:05 - 2014-12-09 15:05 - 00337750 _____ () D:\Users\Kaz\Downloads\1758_1375884046.bmp
2014-12-09 01:25 - 2014-12-27 04:51 - 00000000 ____D () D:\Users\Kaz\Downloads\How much can be made_files
2014-12-09 01:25 - 2014-12-09 01:26 - 00065578 _____ () D:\Users\Kaz\Downloads\How much can be made.htm
2014-12-09 01:03 - 2014-12-09 01:12 - 51508677 _____ () D:\Users\Kaz\Downloads\The G Factor (Garry's Mod Sandbox Montage).flv
2014-12-09 00:33 - 2014-12-09 00:39 - 36376809 _____ () D:\Users\Kaz\Downloads\GTA 5 Online - Freestyle Fun! Playlist [PS4].flv
2014-12-08 22:06 - 2014-12-08 22:06 - 06262382 _____ () D:\Users\Kaz\Downloads\Lets Ride by Said Energizer.mp4
2014-12-08 22:05 - 2014-12-08 22:06 - 10941311 _____ () D:\Users\Kaz\Downloads\Helga Lovekaty - Modelo Rusa (+18).mp4
2014-12-08 22:00 - 2014-12-08 22:00 - 00069352 _____ () D:\Users\Kaz\Downloads\1384980387_qw6r0gmkpvmqnho.jpeg
2014-12-08 20:19 - 2014-12-08 20:21 - 12329621 _____ () D:\Users\Kaz\Downloads\Why America is NOT the greatest country in the world, anymore..flv
2014-12-08 20:12 - 2014-12-08 20:12 - 11091690 _____ () D:\Users\Kaz\Downloads\Substitute Teacher - Key & Peele.mp4
2014-12-08 14:35 - 2014-12-27 04:55 - 00000000 ____D () D:\Users\Kaz\Downloads\White Noise Download white noise mp3s dot com victoria falls_files
2014-12-08 14:35 - 2014-12-08 14:35 - 00334454 _____ () D:\Users\Kaz\Downloads\White Noise Download white noise mp3s dot com victoria falls.htm
2014-12-08 14:30 - 2014-12-27 04:55 - 00000000 ____D () D:\Users\Kaz\Downloads\White Noise Download_files
2014-12-08 14:30 - 2014-12-08 14:31 - 00286608 _____ () D:\Users\Kaz\Downloads\White Noise Download.htm
2014-12-08 14:29 - 2014-12-08 14:29 - 07282819 _____ () D:\Users\Kaz\Downloads\How To Please Your Man!.mp4
2014-12-08 14:28 - 2014-12-08 14:28 - 00131162 _____ () D:\Users\Kaz\Downloads\Christine-Teigen---Sports-Illustrated-2013-Swimsuit-Issue-27-560x840.jpeg
2014-12-08 14:21 - 2014-12-08 14:21 - 14938658 _____ () D:\Users\Kaz\Downloads\You Want To Know How We DO It.mp4
2014-12-08 14:21 - 2014-12-08 14:21 - 05758303 _____ () D:\Users\Kaz\Downloads\WHAT ACTUALLY HAPPENS AT SLEEPOVERS ....mp4
2014-12-08 07:42 - 2014-12-08 07:42 - 00921127 _____ () D:\Users\Kaz\Downloads\AFADF9EFEA1153438021178290176_38916d2d78c.1.1.3836938253198270653 rams football nfl.mp4
2014-12-08 04:23 - 2014-12-08 04:23 - 14917702 _____ () D:\Users\Kaz\Downloads\Gym Class Heroes- Stereo Hearts (MattyBRaps Cover ft Skylar Stecker).mp4
2014-12-08 04:22 - 2014-12-08 04:23 - 17971504 _____ () D:\Users\Kaz\Downloads\MattyB - I Just Wanna Love You (feat. John-Robert Rimel).mp4
2014-12-08 04:09 - 2014-12-08 04:09 - 17146653 _____ () D:\Users\Kaz\Downloads\Remote Control Alligator Prank.mp4
2014-12-08 04:08 - 2014-12-08 04:09 - 12332479 _____ () D:\Users\Kaz\Downloads\Girl Pranks - Wanna See My Rack.mp4
2014-12-08 04:08 - 2014-12-08 04:08 - 43934743 _____ () D:\Users\Kaz\Downloads\Getting Robbed by Seagulls!.mp4
2014-12-08 04:08 - 2014-12-08 04:08 - 21218879 _____ () D:\Users\Kaz\Downloads\Professional Twerker- Jessica Vanessa, Vine's Most Famous Booty Shaker.mp4
2014-12-08 04:07 - 2014-12-08 04:07 - 04419349 _____ () D:\Users\Kaz\Downloads\Surprise Phone Call From My Favorite YouTubers!.mp4
2014-12-08 00:55 - 2014-12-08 00:57 - 12306663 _____ () D:\Users\Kaz\Downloads\The Assistant Highlights - Andy Dick.flv
2014-12-08 00:10 - 2014-12-08 00:10 - 00032796 _____ () D:\Users\Kaz\Downloads\OXUVJHdt.jpeg
2014-12-07 23:14 - 2014-12-07 23:16 - 06677055 _____ () D:\Users\Kaz\Downloads\The Carpenters - Home for the Holidays.flv
2014-12-07 22:55 - 2014-12-07 23:16 - 33397713 _____ () D:\Users\Kaz\Downloads\'Joking Bad' - Late Night with Jimmy Fallon (Late Night with Jimmy Fallon).flv
2014-12-06 19:07 - 2014-12-06 19:07 - 00436343 _____ () D:\Users\Kaz\Downloads\20141203_202918(1).3gp
2014-12-06 18:22 - 2014-12-06 18:22 - 00898175 _____ () D:\Users\Kaz\Downloads\Gabriella Lenzi Saloon Fitness.mp4
2014-12-06 18:09 - 2014-12-06 18:09 - 66447058 _____ () D:\Users\Kaz\Downloads\30-Day Burpee Challenge _ ACTIVE stacy fitness
2014-12-06 17:10 - 2014-12-06 17:20 - 48909660 _____ () D:\Users\Kaz\Downloads\EARLY CHRISTMAS PRESENT!.flv
2014-12-06 16:48 - 2014-12-06 17:30 - 158673968 _____ () D:\Users\Kaz\Downloads\Infinite Prosperity- Q&A with Amy Sangster and Lewis Mocker.flv
2014-12-06 16:16 - 2014-12-06 16:29 - 76267045 _____ () D:\Users\Kaz\Downloads\HOW TO SURF BEHIND A BOAT!.mp4
2014-12-06 16:16 - 2014-12-06 16:22 - 29042967 _____ () D:\Users\Kaz\Downloads\SHAYTARDS THANKSGIVING!.flv
2014-12-06 14:56 - 2014-12-06 14:58 - 06607790 _____ () D:\Users\Kaz\Downloads\john krasinski making high pitched noises.mp4
2014-12-06 14:06 - 2014-12-06 14:06 - 00373296 _____ () D:\Users\Kaz\Downloads\IMG_0011 baseball batting practice.MOV
2014-12-06 02:57 - 2014-12-06 02:57 - 00168135 _____ () D:\Users\Kaz\Downloads\MENS_Article-Tom-Brady_Getty_455881204.jpeg
2014-12-05 16:37 - 2014-12-05 16:37 - 00000000 ____D () D:\Program Files\Mozilla Firefox
2014-12-04 19:56 - 2014-12-04 19:56 - 00013174 _____ () D:\Users\Kaz\Downloads\12329465.jpeg
2014-12-04 19:54 - 2014-12-04 19:54 - 00198393 _____ () D:\Users\Kaz\Downloads\andressa-urach-pelada-cristiano-ronaldo-paint.jpeg
2014-12-04 19:53 - 2014-12-04 19:53 - 00079589 _____ () D:\Users\Kaz\Downloads\286848-600x600-1.jpeg
2014-12-04 18:51 - 2014-12-04 18:51 - 00436343 _____ () D:\Users\Kaz\Downloads\20141203_202918.3gp
2014-12-03 22:31 - 2014-12-03 22:31 - 05552440 _____ () D:\Users\Kaz\Downloads\Baywatch - I'm always here.mp4
2014-12-03 22:28 - 2014-12-03 22:29 - 11610662 _____ () D:\Users\Kaz\Downloads\Jimi Jamison - I'm Always Here (Baywatch OST) HQ.mp4
2014-12-03 21:00 - 2014-12-03 21:02 - 21153719 _____ () D:\Users\Kaz\Downloads\DJ Earworm Mashup - United State of Pop 2014 (Do What You Wanna Do).mp4
2014-12-03 20:43 - 2014-12-03 20:43 - 00240544 _____ () D:\Users\Kaz\Downloads\ariana-grande.jpeg
2014-12-03 03:31 - 2014-12-03 03:39 - 49383856 _____ () D:\Users\Kaz\Downloads\Minecraft RFTW Team 1 #1- Go Go Go!.flv
2014-12-03 00:52 - 2014-12-03 00:52 - 02846330 _____ () D:\Users\Kaz\Downloads\tartar sauce.mp4
2014-12-02 23:57 - 2014-12-27 04:46 - 00000000 ____D () D:\Users\Kaz\Downloads\Student Journey _ Infinite Prosperity Blog_files
2014-12-02 23:57 - 2014-12-02 23:58 - 03677601 _____ () D:\Users\Kaz\Downloads\Student Journey _ Infinite Prosperity Blog.htm
2014-12-02 23:46 - 2014-12-27 04:46 - 00000000 ____D () D:\Users\Kaz\Downloads\Our Most Successful Student! _ Infinite Prosperity Blog_files
2014-12-02 23:46 - 2014-12-02 23:46 - 04299626 _____ () D:\Users\Kaz\Downloads\Our Most Successful Student! _ Infinite Prosperity Blog.htm
2014-12-02 23:42 - 2014-12-27 04:46 - 00000000 ____D () D:\Users\Kaz\Downloads\Infinite Prosperity Blog_files
2014-12-02 23:42 - 2014-12-02 23:42 - 00034021 _____ () D:\Users\Kaz\Downloads\Infinite Prosperity Blog.htm
2014-12-02 23:27 - 2014-12-02 23:27 - 00023325 _____ () D:\Users\Kaz\Downloads\5705438c83b8a5921c95c012c236f187_400x400.jpeg
2014-12-02 23:07 - 2014-12-02 23:12 - 34573713 _____ () D:\Users\Kaz\Downloads\Pictionary with Martin Short, Jerry Seinfeld and Miranda Sings.mp4
2014-12-02 23:07 - 2014-12-02 23:09 - 13644762 _____ () D:\Users\Kaz\Downloads\Rashida Jones Is Co-Writing Toy Story 4.mp4
2014-12-02 22:09 - 2014-12-02 22:09 - 00075013 _____ () D:\Users\Kaz\Downloads\How I bought a Lamborghini at 22.htm
2014-12-02 22:08 - 2014-12-27 04:51 - 00000000 ____D () D:\Users\Kaz\Downloads\How I bought a Lamborghini at 22_files
2014-12-02 22:02 - 2014-12-27 04:51 - 00000000 ____D () D:\Users\Kaz\Downloads\Student Results_files
2014-12-02 22:02 - 2014-12-02 22:02 - 00050422 _____ () D:\Users\Kaz\Downloads\Student Results.htm
2014-12-02 21:59 - 2014-12-27 04:51 - 00000000 ____D () D:\Users\Kaz\Downloads\Membership Inclusions_files
2014-12-02 21:59 - 2014-12-02 21:59 - 00166852 _____ () D:\Users\Kaz\Downloads\Membership Inclusions.htm
2014-12-02 21:56 - 2014-12-27 04:55 - 00000000 ____D () D:\Users\Kaz\Downloads\Amy Sangster _ Why I teach others_files
2014-12-02 21:56 - 2014-12-02 21:56 - 00053547 _____ () D:\Users\Kaz\Downloads\Amy Sangster _ Why I teach others.htm
2014-12-02 21:45 - 2014-12-27 04:51 - 00000000 ____D () D:\Users\Kaz\Downloads\Frequently Asked Questions _ Infinite Prosperity_files
2014-12-02 21:45 - 2014-12-02 21:45 - 00080843 _____ () D:\Users\Kaz\Downloads\Frequently Asked Questions _ Infinite Prosperity.htm
2014-12-02 21:38 - 2014-12-27 04:51 - 00000000 ____D () D:\Users\Kaz\Downloads\Free Introduction Lesson_files
2014-12-02 21:38 - 2014-12-02 21:38 - 00126508 _____ () D:\Users\Kaz\Downloads\Free Introduction Lesson.htm
2014-12-02 21:28 - 2014-12-02 21:28 - 00023215 _____ () D:\Users\Kaz\Downloads\EminemDaughter.jpeg
2014-12-02 21:10 - 2014-12-02 21:10 - 00000304 _____ () D:\Users\Kaz\Downloads\jKrpuOxsZdxx._500x500.jpg.cb_watermark.JPG.dbkpkmg
2014-12-02 16:54 - 2014-12-27 04:57 - 00000000 ____D () D:\Users\Kaz\Downloads\Ascension _ Process  2014_files
2014-12-02 16:54 - 2014-12-02 16:54 - 00238394 _____ () D:\Users\Kaz\Downloads\Ascension _ Process  2014.htm
2014-12-02 16:06 - 2014-12-02 16:06 - 00000000 ____D () D:\Windows\system32\appmgmt
2014-12-02 14:59 - 2014-12-02 14:59 - 00059686 _____ () D:\Users\Kaz\Downloads\yoga-pants-replace.jpeg
2014-12-02 14:55 - 2014-12-02 14:55 - 00143795 _____ () D:\Users\Kaz\Downloads\971.jpeg
2014-12-02 14:55 - 2014-12-02 14:55 - 00008971 _____ () D:\Users\Kaz\Downloads\911.jpeg
2014-12-02 04:13 - 2014-12-02 04:14 - 00002635 _____ () D:\Users\Kaz\Desktop\klkbl.xspf
2014-12-02 03:57 - 2014-12-02 03:57 - 00024803 _____ () D:\Users\Kaz\Downloads\UD3ZnC3E_400x400k.jpeg
2014-12-02 03:56 - 2014-12-02 03:56 - 00024803 _____ () D:\Users\Kaz\Downloads\UD3ZnC3E_400x400.jpeg
2014-12-02 03:08 - 2014-12-02 03:08 - 00101292 _____ () D:\Users\Kaz\Downloads\197.jpeg
2014-12-02 03:08 - 2014-12-02 03:08 - 00008261 _____ () D:\Users\Kaz\Downloads\232.jpeg
2014-12-02 02:23 - 2014-12-27 04:51 - 00000000 ____D () D:\Users\Kaz\Downloads\Lesson 2 - Sneak Peak_files
2014-12-02 02:23 - 2014-12-02 02:23 - 00112010 _____ () D:\Users\Kaz\Downloads\Lesson 2 - Sneak Peak.htm
2014-12-01 23:19 - 2014-12-01 23:19 - 00178255 _____ () D:\Users\Kaz\Downloads\cq5dam.web.1322.1322.jpeg
2014-12-01 21:45 - 2014-12-01 21:45 - 00150245 _____ () D:\Users\Kaz\Downloads\624vsda.jpeg
2014-11-29 03:42 - 2014-12-27 04:58 - 00000000 ____D () D:\Users\Kaz\Downloads\The REAL Truth About Amy Sangster & Robert Himler_files
2014-11-29 03:42 - 2014-11-29 03:42 - 00096980 _____ () D:\Users\Kaz\Downloads\The REAL Truth About Amy Sangster & Robert Himler.htm
2014-11-28 15:47 - 2014-12-27 04:51 - 00000000 ____D () D:\Users\Kaz\Downloads\Interview  Tom Russell_files
2014-11-28 15:47 - 2014-11-28 15:47 - 00066097 _____ () D:\Users\Kaz\Downloads\Interview  Tom Russell.htm
2014-11-28 00:12 - 2014-11-28 00:12 - 00000000 __SHD () D:\Users\Kaz\AppData\Local\EmieBrowserModeList
2014-11-28 00:01 - 2014-11-28 00:02 - 10256168 _____ () D:\Users\Kaz\Downloads\Miggy shakes a fan's hand on his way on deck.mp4

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-12-28 15:36 - 2014-01-26 19:03 - 00000000 ____D () D:\Users\Zachary
2014-12-28 15:36 - 2014-01-26 19:01 - 00000000 __SHD () D:\Users\NetworkService.NT AUTHORITY
2014-12-28 15:36 - 2014-01-26 19:01 - 00000000 __SHD () D:\Users\LocalService.NT AUTHORITY
2014-12-28 15:36 - 2014-01-26 13:41 - 00000000 ___HD () D:\Users\Default User.WINDOWS2
2014-12-28 15:36 - 2014-01-26 13:41 - 00000000 ____D () D:\Users\All Users.WINDOWS2
2014-12-28 15:36 - 2011-03-03 14:15 - 00000000 ___SD () D:\Users\TEMP
2014-12-28 15:36 - 2010-09-17 17:40 - 00000000 ___HD () D:\Users\Zach
2014-12-28 15:36 - 2010-09-17 17:38 - 00000000 __SHD () D:\Users\LocalService
2014-12-28 15:36 - 2010-09-17 17:37 - 00000000 __SHD () D:\Users\NetworkService
2014-12-28 15:36 - 2009-07-13 21:37 - 00000000 __RHD () D:\Users\Default
2014-12-28 15:36 - 2009-07-13 21:37 - 00000000 ___RD () D:\Users\Public
2014-12-28 15:34 - 2009-07-13 21:04 - 00000215 _____ () D:\Windows\system.ini
2014-12-28 15:14 - 2009-07-13 23:34 - 00021904 ____H () D:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-12-28 15:14 - 2009-07-13 23:34 - 00021904 ____H () D:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-12-28 15:10 - 2014-01-28 17:06 - 00079943 _____ () D:\Windows\WindowsUpdate.log
2014-12-28 15:07 - 2009-07-13 23:53 - 00000006 ____H () D:\Windows\Tasks\SA.DAT
2014-12-28 14:31 - 2014-10-17 14:03 - 00000000 ____D () D:\Users\Kaz\AppData\Local\Adobe
2014-12-28 13:48 - 2014-07-26 21:52 - 00000000 ____D () D:\Users\Kaz\AppData\Roaming\vlc
2014-12-28 12:16 - 2014-11-22 00:38 - 00000000 ____D () D:\Users\Kaz\Downloads\Moberly02_46932d27 jeep srt 2015
2014-12-28 12:16 - 2014-11-17 20:20 - 00000000 ____D () D:\ProgramData\mfijdhoahjlleclhkjplcbnakbkcpclm
2014-12-28 12:16 - 2014-11-17 20:20 - 00000000 ____D () D:\ProgramData\mfijdhoahjlleclhkjplcbnakbkcpclm
2014-12-27 22:45 - 2009-07-13 21:37 - 00000000 ____D () D:\Windows\TAPI
2014-12-27 20:09 - 2014-01-28 19:48 - 00000000 ____D () D:\Program Files\Google
2014-12-27 18:05 - 2014-01-28 20:02 - 00000000 ____D () D:\Windows\Minidump
2014-12-27 17:38 - 2014-11-16 16:29 - 00000000 ____D () D:\Users\Kaz\AppData\Roaming\DAEMON Tools Lite
2014-12-27 17:38 - 2014-04-13 16:13 - 00000000 ____D () D:\Users\Kaz\AppData\Roaming\uTorrent
2014-12-27 17:08 - 2014-01-31 00:47 - 00000000 ____D () D:\Program Files\CCleaner
2014-12-27 17:08 - 2012-10-07 11:14 - 00000000 ____D () D:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-12-27 17:08 - 2012-10-07 11:14 - 00000000 ____D () D:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-12-27 04:46 - 2014-10-25 20:23 - 00000000 ____D () D:\Users\Zach\Desktop\test_files
2014-12-27 04:44 - 2011-08-06 13:43 - 00000000 ____D () D:\Users\Zach\.frostwire5
2014-12-27 04:42 - 2014-11-09 03:33 - 00000000 ____D () D:\Users\Kaz\Documents\bootitng
2014-12-27 04:41 - 2014-11-17 15:08 - 00000000 ____D () D:\Users\Kaz\Documents\Novicorp_WinToFlash
2014-12-27 04:41 - 2014-04-21 22:50 - 00000784 _____ () D:\Users\Kaz\Downloads\Decrypt All Files dbkpkmg.TXT.dbkpkmg
2014-12-27 04:37 - 2014-09-15 12:13 - 00000000 ____D () D:\Users\Kaz\AppData\Local\Foxit Reader
2014-12-27 04:35 - 2014-03-13 12:51 - 00000000 ____D () D:\Program Files\Warcraft III
2014-12-27 04:27 - 2012-01-26 22:45 - 00000000 ____D () D:\ProgramData\NaturalSoft Co. Ltd
2014-12-27 04:27 - 2012-01-26 22:45 - 00000000 ____D () D:\ProgramData\NaturalSoft Co. Ltd
2014-12-26 01:17 - 2010-09-17 21:18 - 00000000 ____D () D:\ProgramData\Windows Genuine Advantage
2014-12-26 01:17 - 2010-09-17 21:18 - 00000000 ____D () D:\ProgramData\Windows Genuine Advantage
2014-12-24 03:28 - 2014-09-27 23:58 - 00001872 _____ () D:\Users\Kaz\Downloads\index6hy6.JPG.dbkpkmg
2014-12-23 16:15 - 2014-09-27 23:58 - 00002944 _____ () D:\Users\Kaz\Downloads\indexergheha.JPG.dbkpkmg
2014-12-22 20:18 - 2014-09-27 23:58 - 00001776 _____ () D:\Users\Kaz\Downloads\index Watch Nina Dream Ass BVRfwea.JPG.dbkpkmg
2014-12-22 20:18 - 2014-09-27 23:58 - 00001776 _____ () D:\Users\Kaz\Downloads\index Watch Nina Dream Ass BVR.JPG.dbkpkmg
2014-12-22 20:17 - 2014-09-27 23:58 - 00001776 _____ () D:\Users\Kaz\Downloads\indexukj7u.JPG.dbkpkmg
2014-12-22 20:14 - 2014-09-27 23:58 - 00001824 _____ () D:\Users\Kaz\Downloads\index Cherie Southern Charms.JPG.dbkpkmg
2014-12-22 20:04 - 2014-09-27 23:58 - 00003424 _____ () D:\Users\Kaz\Downloads\meandmyprincessuygyuu.JPG.dbkpkmg
2014-12-22 19:59 - 2014-09-27 23:58 - 00003248 _____ () D:\Users\Kaz\Downloads\slutysandragreg.JPG.dbkpkmg
2014-12-22 19:53 - 2014-09-27 23:58 - 00003040 _____ () D:\Users\Kaz\Downloads\slutysandraergher.JPG.dbkpkmg
2014-12-22 11:38 - 2014-09-27 23:58 - 00003600 _____ () D:\Users\Kaz\Downloads\indexergrg.JPG.dbkpkmg
2014-12-22 02:32 - 2014-09-27 23:58 - 00003184 _____ () D:\Users\Kaz\Downloads\indexgty.JPG.dbkpkmg
2014-12-22 02:32 - 2014-09-27 23:58 - 00001936 _____ () D:\Users\Kaz\Downloads\indexvvv.JPG.dbkpkmg
2014-12-22 02:25 - 2014-09-27 23:58 - 00001920 _____ () D:\Users\Kaz\Downloads\index madd.JPG.dbkpkmg
2014-12-22 01:59 - 2014-09-27 23:58 - 00003344 _____ () D:\Users\Kaz\Downloads\sophiesticatederg.JPG.dbkpkmg
2014-12-21 06:37 - 2014-09-27 23:58 - 00001568 _____ () D:\Users\Kaz\Downloads\index gyp xha.JPG.dbkpkmg
2014-12-21 04:57 - 2014-09-27 23:58 - 00003488 _____ () D:\Users\Kaz\Downloads\rubyfameft5.JPG.dbkpkmg
2014-12-21 04:54 - 2014-09-27 23:58 - 00003408 _____ () D:\Users\Kaz\Downloads\rubyfamevsa.JPG.dbkpkmg
2014-12-19 04:26 - 2014-09-27 23:58 - 00002160 _____ () D:\Users\Kaz\Downloads\indexjtjy.JPG.dbkpkmg
2014-12-18 23:02 - 2014-09-27 23:58 - 00002672 _____ () D:\Users\Kaz\Downloads\imagesrbrb.JPG.dbkpkmg
2014-12-18 21:44 - 2014-09-27 23:58 - 00002032 _____ () D:\Users\Kaz\Downloads\ji0iBrm8V2nDp4_250x80.JPG.dbkpkmg
2014-12-18 21:44 - 2014-09-27 23:58 - 00002016 _____ () D:\Users\Kaz\Downloads\sb08XwuavCRUwwnuV_250x80.JPG.dbkpkmg
2014-12-18 21:19 - 2014-09-27 23:58 - 00003488 _____ () D:\Users\Kaz\Downloads\miastone_ftf.JPG.dbkpkmg
2014-12-18 16:20 - 2014-09-27 23:58 - 00002800 _____ () D:\Users\Kaz\Downloads\indexhyts.JPG.dbkpkmg
2014-12-18 16:19 - 2014-09-27 23:58 - 00001568 _____ () D:\Users\Kaz\Downloads\indexujuy.JPG.dbkpkmg
2014-12-18 16:19 - 2014-09-27 23:58 - 00001568 _____ () D:\Users\Kaz\Downloads\index Grey yoga pants x.JPG.dbkpkmg
2014-12-18 16:14 - 2014-09-27 23:58 - 00002976 _____ () D:\Users\Kaz\Downloads\avatar_820395_s_1344030041.JPG.dbkpkmg
2014-12-18 15:47 - 2014-09-27 23:58 - 00002848 _____ () D:\Users\Kaz\Downloads\indexerhhyr.JPG.dbkpkmg
2014-12-18 15:47 - 2014-09-27 23:58 - 00002816 _____ () D:\Users\Kaz\Downloads\indexwefwv.JPG.dbkpkmg
2014-12-18 15:47 - 2014-09-27 23:58 - 00002448 _____ () D:\Users\Kaz\Downloads\indexreeeere.JPG.dbkpkmg
2014-12-18 15:47 - 2014-09-27 23:58 - 00002432 _____ () D:\Users\Kaz\Downloads\indexwefwa.JPG.dbkpkmg
2014-12-18 15:47 - 2014-09-27 23:58 - 00001936 _____ () D:\Users\Kaz\Downloads\indextytyt.JPG.dbkpkmg
2014-12-18 15:46 - 2014-09-27 23:58 - 00002704 _____ () D:\Users\Kaz\Downloads\indexytjty.JPG.dbkpkmg
2014-12-18 15:46 - 2014-09-27 23:58 - 00001920 _____ () D:\Users\Kaz\Downloads\indexjuytty.JPG.dbkpkmg
2014-12-18 03:56 - 2014-09-27 23:58 - 00002816 _____ () D:\Users\Kaz\Downloads\indextrhrth.JPG.dbkpkmg
2014-12-18 03:56 - 2014-09-27 23:58 - 00002816 _____ () D:\Users\Kaz\Downloads\index Sporty gal in yoga pants loves than anything on Earth.JPG.dbkpkmg
2014-12-18 03:54 - 2014-09-27 23:58 - 00003248 _____ () D:\Users\Kaz\Downloads\imagesbbteerre.JPG.dbkpkmg
2014-12-17 20:52 - 2014-09-27 23:58 - 00002448 _____ () D:\Users\Kaz\Downloads\defaultrgergr.JPG.dbkpkmg
2014-12-17 19:10 - 2014-09-27 23:58 - 00003072 _____ () D:\Users\Kaz\Downloads\defaulthntrh.JPG.dbkpkmg
2014-12-17 19:05 - 2014-09-27 23:58 - 00002352 _____ () D:\Users\Kaz\Downloads\indextynty.JPG.dbkpkmg
2014-12-17 03:52 - 2013-08-18 11:17 - 00000000 ____D () D:\Users\Zach\Desktop\Insanity with Asylum 1 & 2 x264 MP4 DVDrip
2014-12-17 01:33 - 2014-07-16 15:00 - 00000000 ____D () D:\Users\Kaz\AppData\Local\Windows Live
2014-12-16 21:15 - 2014-09-27 23:58 - 00003472 _____ () D:\Users\Kaz\Downloads\defaultynyhnh.JPG.dbkpkmg
2014-12-16 21:15 - 2014-09-27 23:58 - 00003184 _____ () D:\Users\Kaz\Downloads\defaulttbrtbbrt.JPG.dbkpkmg
2014-12-16 20:08 - 2014-09-27 23:58 - 00003504 _____ () D:\Users\Kaz\Downloads\Profile_U_R12a.JPG.dbkpkmg
2014-12-16 20:06 - 2014-09-27 23:58 - 00003120 _____ () D:\Users\Kaz\Downloads\Profile_U_R12.JPG.dbkpkmg
2014-12-16 17:10 - 2014-04-21 22:50 - 00001616 _____ () D:\Users\Kaz\Downloads\10430907_679263542194298_1910000731918017268_n.JPG.dbkpkmg
2014-12-16 17:10 - 2014-04-21 22:50 - 00001504 _____ () D:\Users\Kaz\Downloads\10458875_719816204728183_7300002925468744285_n.JPG.dbkpkmg
2014-12-16 05:53 - 2014-09-27 23:58 - 00003360 _____ () D:\Users\Kaz\Downloads\indexdrdc.JPG.dbkpkmg
2014-12-16 05:47 - 2014-09-27 23:58 - 00002016 _____ () D:\Users\Kaz\Downloads\indextgvvgt.JPG.dbkpkmg
2014-12-16 05:46 - 2014-09-27 23:58 - 00002384 _____ () D:\Users\Kaz\Downloads\indextrtr.JPG.dbkpkmg
2014-12-16 05:46 - 2014-09-27 23:58 - 00002080 _____ () D:\Users\Kaz\Downloads\indexvgtvg.JPG.dbkpkmg
2014-12-16 05:37 - 2014-09-27 23:58 - 00002224 _____ () D:\Users\Kaz\Downloads\graceewilleyy.JPG.dbkpkmg
2014-12-15 20:28 - 2014-09-27 23:58 - 00002912 _____ () D:\Users\Kaz\Downloads\defaultrrtrt.JPG.dbkpkmg
2014-12-15 20:28 - 2014-09-27 23:58 - 00001824 _____ () D:\Users\Kaz\Downloads\defaulth4rh.JPG.dbkpkmg
2014-12-15 15:53 - 2014-09-27 23:58 - 00003120 _____ () D:\Users\Kaz\Downloads\indexthrw.JPG.dbkpkmg
2014-12-15 15:53 - 2014-09-27 23:58 - 00002176 _____ () D:\Users\Kaz\Downloads\indexnr5yr.JPG.dbkpkmg
2014-12-15 15:33 - 2014-09-27 23:58 - 00003408 _____ () D:\Users\Kaz\Downloads\emmaloveeuyguyg.JPG.dbkpkmg
2014-12-15 15:26 - 2014-09-27 23:58 - 00003424 _____ () D:\Users\Kaz\Downloads\adriananicolaeg.JPG.dbkpkmg
2014-12-15 03:07 - 2014-09-27 23:58 - 00003152 _____ () D:\Users\Kaz\Downloads\indexwega.JPG.dbkpkmg
2014-12-14 22:44 - 2014-09-27 23:58 - 00001408 _____ () D:\Users\Kaz\Downloads\imagesrgnrt.JPG.dbkpkmg
2014-12-14 21:12 - 2014-07-11 02:30 - 00047648 _____ () D:\Users\Kaz\Desktop\class registration for spring 2015 enmu.DOCX.dbkpkmg
2014-12-14 21:08 - 2014-07-16 03:33 - 00000448 _____ () D:\Users\Kaz\Desktop\New Text Document (2).TXT.dbkpkmg
2014-12-14 17:23 - 2014-09-27 23:58 - 00002352 _____ () D:\Users\Kaz\Downloads\defaulttrnjrt.JPG.dbkpkmg
2014-12-14 04:35 - 2009-07-13 21:37 - 00000000 ____D () D:\Windows\system32\NDF
2014-12-13 23:34 - 2014-09-27 23:58 - 00002256 _____ () D:\Users\Kaz\Downloads\CFL5MyHzl0Y.JPG.dbkpkmg
2014-12-13 22:34 - 2014-09-27 23:58 - 00003232 _____ () D:\Users\Kaz\Downloads\default5ftt5.JPG.dbkpkmg
2014-12-13 21:02 - 2014-09-27 23:58 - 00002000 _____ () D:\Users\Kaz\Downloads\indexhnthn.JPG.dbkpkmg
2014-12-13 20:00 - 2014-09-27 23:58 - 00003104 _____ () D:\Users\Kaz\Downloads\defaulttrhnrt.JPG.dbkpkmg
2014-12-13 18:58 - 2014-09-27 23:58 - 00002864 _____ () D:\Users\Kaz\Downloads\defaulttbt4.JPG.dbkpkmg
2014-12-13 18:58 - 2014-09-27 23:58 - 00002704 _____ () D:\Users\Kaz\Downloads\defaulttb4r5.JPG.dbkpkmg
2014-12-13 03:13 - 2014-09-27 23:58 - 00003472 _____ () D:\Users\Kaz\Downloads\defaultrtnr.JPG.dbkpkmg
2014-12-13 03:12 - 2014-09-27 23:58 - 00003104 _____ () D:\Users\Kaz\Downloads\defaultbht4.JPG.dbkpkmg
2014-12-13 03:12 - 2014-09-27 23:58 - 00002672 _____ () D:\Users\Kaz\Downloads\defaultjn5.JPG.dbkpkmg
2014-12-13 03:11 - 2014-09-27 23:58 - 00003568 _____ () D:\Users\Kaz\Downloads\defaultrtnw.JPG.dbkpkmg
2014-12-13 03:10 - 2014-09-27 23:58 - 00003568 _____ () D:\Users\Kaz\Downloads\defaulterherbhw.JPG.dbkpkmg
2014-12-13 03:06 - 2014-09-27 23:58 - 00002912 _____ () D:\Users\Kaz\Downloads\defaultwthethet.JPG.dbkpkmg
2014-12-13 02:54 - 2014-09-27 23:58 - 00003408 _____ () D:\Users\Kaz\Downloads\defaultbebe.JPG.dbkpkmg
2014-12-13 02:54 - 2014-09-27 23:58 - 00003376 _____ () D:\Users\Kaz\Downloads\default World Weightlifting Championships. women.JPG.dbkpkmg
2014-12-13 02:54 - 2014-09-27 23:58 - 00003296 _____ () D:\Users\Kaz\Downloads\default  World Weightlifting Championships. women.JPG.dbkpkmg
2014-12-13 02:54 - 2014-09-27 23:58 - 00002624 _____ () D:\Users\Kaz\Downloads\default   World Weightlifting Championships. women.JPG.dbkpkmg
2014-12-13 02:51 - 2014-09-27 23:58 - 00003056 _____ () D:\Users\Kaz\Downloads\indexbner.JPG.dbkpkmg
2014-12-13 02:51 - 2014-09-27 23:58 - 00002720 _____ () D:\Users\Kaz\Downloads\indexeber.JPG.dbkpkmg
2014-12-13 02:51 - 2014-09-27 23:58 - 00002464 _____ () D:\Users\Kaz\Downloads\indexrberbrq.JPG.dbkpkmg
2014-12-13 02:51 - 2014-09-27 23:58 - 00002368 _____ () D:\Users\Kaz\Downloads\indexrber.JPG.dbkpkmg
2014-12-13 02:51 - 2014-09-27 23:58 - 00001856 _____ () D:\Users\Kaz\Downloads\indexbregqrw3.JPG.dbkpkmg
2014-12-12 21:05 - 2014-09-27 23:58 - 00003104 _____ () D:\Users\Kaz\Downloads\defaultrebvrew.JPG.dbkpkmg
2014-12-12 21:01 - 2014-09-27 23:58 - 00002976 _____ () D:\Users\Kaz\Downloads\default stephanie davies.JPG.dbkpkmg
2014-12-12 14:53 - 2014-09-27 23:58 - 00003248 _____ () D:\Users\Kaz\Downloads\index Hot Asses Paradise.JPG.dbkpkmg
2014-12-12 14:52 - 2014-09-27 23:58 - 00003248 _____ () D:\Users\Kaz\Downloads\indexewg.JPG.dbkpkmg
2014-12-12 14:52 - 2014-09-27 23:58 - 00002368 _____ () D:\Users\Kaz\Downloads\indextbet.JPG.dbkpkmg
2014-12-12 14:52 - 2014-09-27 23:58 - 00002368 _____ () D:\Users\Kaz\Downloads\index Hot colombiana Alone.JPG.dbkpkmg
2014-12-12 14:52 - 2014-09-27 23:58 - 00001728 _____ () D:\Users\Kaz\Downloads\indexadsfgrwe.JPG.dbkpkmg
2014-12-12 14:52 - 2014-09-27 23:58 - 00001728 _____ () D:\Users\Kaz\Downloads\index  Hot colombiana Alone.JPG.dbkpkmg
2014-12-12 03:03 - 2014-09-27 23:58 - 00003072 _____ () D:\Users\Kaz\Downloads\indexjkgukhlj.JPG.dbkpkmg
2014-12-11 21:50 - 2014-09-27 23:58 - 00003440 _____ () D:\Users\Kaz\Downloads\defaultrebre.JPG.dbkpkmg
2014-12-11 21:50 - 2014-09-27 23:58 - 00003360 _____ () D:\Users\Kaz\Downloads\defaultqwefgfw.JPG.dbkpkmg
2014-12-11 21:50 - 2014-09-27 23:58 - 00003280 _____ () D:\Users\Kaz\Downloads\defaultrgwgw.JPG.dbkpkmg
2014-12-11 21:50 - 2014-09-27 23:58 - 00002992 _____ () D:\Users\Kaz\Downloads\defaultasdgvwe.JPG.dbkpkmg
2014-12-11 20:10 - 2014-09-27 23:58 - 00002608 _____ () D:\Users\Kaz\Downloads\defaulthntrt.JPG.dbkpkmg
2014-12-11 16:10 - 2014-09-27 23:58 - 00003552 _____ () D:\Users\Kaz\Downloads\th_11585_ezssolbvrj_123_162lo.JPG.dbkpkmg
2014-12-11 16:09 - 2014-09-27 23:58 - 00003456 _____ () D:\Users\Kaz\Downloads\th_13441_c84kqwp4jf_123_170lo.JPG.dbkpkmg
2014-12-11 16:09 - 2014-09-27 23:58 - 00002240 _____ () D:\Users\Kaz\Downloads\indexrntrn.JPG.dbkpkmg
2014-12-11 15:58 - 2014-09-27 23:58 - 00003296 _____ () D:\Users\Kaz\Downloads\srpthumb-p268639-100x100-no.JPG.dbkpkmg
2014-12-11 00:27 - 2014-09-27 23:58 - 00002576 _____ () D:\Users\Kaz\Downloads\imagesrgvba.JPG.dbkpkmg
2014-12-10 23:51 - 2014-09-27 23:58 - 00003232 _____ () D:\Users\Kaz\Downloads\135x80-viper-media-999877c9-aa3e-4eaf-b55a-abd99297e155-jpeg-b6c385d4-1007-4edb-ac0a-3e3a28c8479e_0.JPG.dbkpkmg
2014-12-10 23:51 - 2014-09-27 23:58 - 00002976 _____ () D:\Users\Kaz\Downloads\135x80-viper-media-999877c9-aa3e-4eaf-b55a-abd99297e155-jpeg-1948a1c9-9321-4720-b276-dd4490987b4e_0.JPG.dbkpkmg
2014-12-10 23:51 - 2014-04-21 22:50 - 00002560 _____ () D:\Users\Kaz\Downloads\98x73-ds-photo-getty-article-227-50-rbrb_2798_XS.JPG.dbkpkmg
2014-12-10 23:21 - 2014-09-27 23:58 - 00003040 _____ () D:\Users\Kaz\Downloads\Revision_wide.JPG.dbkpkmg
2014-12-10 02:44 - 2014-09-27 23:58 - 00003456 _____ () D:\Users\Kaz\Downloads\movie-wallpapers.JPG.dbkpkmg
2014-12-10 02:34 - 2014-09-27 23:58 - 00003344 _____ () D:\Users\Kaz\Downloads\defaultrttr.JPG.dbkpkmg
2014-12-10 02:34 - 2014-09-27 23:58 - 00002960 _____ () D:\Users\Kaz\Downloads\defaulttbht.JPG.dbkpkmg
2014-12-10 02:34 - 2014-09-27 23:58 - 00002896 _____ () D:\Users\Kaz\Downloads\defaulttbrtb.JPG.dbkpkmg
2014-12-10 02:22 - 2014-09-27 23:58 - 00002848 _____ () D:\Users\Kaz\Downloads\indexnyny.JPG.dbkpkmg
2014-12-10 02:08 - 2014-01-28 20:34 - 00000000 ____D () D:\ProgramData\Microsoft Help
2014-12-10 02:08 - 2014-01-28 20:34 - 00000000 ____D () D:\ProgramData\Microsoft Help
2014-12-10 02:05 - 2014-01-28 15:06 - 00000000 ____D () D:\Windows\system32\MRT
2014-12-10 02:01 - 2014-01-28 15:06 - 109818608 _____ (Microsoft Corporation) D:\Windows\system32\MRT.exe
2014-12-09 21:44 - 2014-09-27 23:58 - 00003184 _____ () D:\Users\Kaz\Downloads\MV5BNDA4NDg1MzQ1OV5BMl5BanBnXkFtZTYwNTM0OTUz._V1_SX99_CR0,0,99,99_AL_.JPG.dbkpkmg
2014-12-09 21:37 - 2014-09-27 23:58 - 00003168 _____ () D:\Users\Kaz\Downloads\150x200rbr.JPG.dbkpkmg
2014-12-09 21:34 - 2014-09-27 23:58 - 00003520 _____ () D:\Users\Kaz\Downloads\defaultrvav.JPG.dbkpkmg
2014-12-09 21:34 - 2014-09-27 23:58 - 00003472 _____ () D:\Users\Kaz\Downloads\defaultvreas.JPG.dbkpkmg
2014-12-09 21:34 - 2014-09-27 23:58 - 00002768 _____ () D:\Users\Kaz\Downloads\defaultvreava.JPG.dbkpkmg
2014-12-09 20:23 - 2014-09-27 23:58 - 00003104 _____ () D:\Users\Kaz\Downloads\sweeetadyrftr.JPG.dbkpkmg
2014-12-09 20:09 - 2014-09-27 23:58 - 00003120 _____ () D:\Users\Kaz\Downloads\sweeetadyrcf.JPG.dbkpkmg
2014-12-09 18:51 - 2014-09-27 23:58 - 00003376 _____ () D:\Users\Kaz\Downloads\defaultrgwa.JPG.dbkpkmg
2014-12-09 18:42 - 2014-09-27 23:58 - 00003472 _____ () D:\Users\Kaz\Downloads\001thet.JPG.dbkpkmg
2014-12-09 16:20 - 2014-09-27 23:58 - 00002800 _____ () D:\Users\Kaz\Downloads\indexeva.JPG.dbkpkmg
2014-12-09 15:08 - 2014-09-27 23:58 - 00002048 _____ () D:\Users\Kaz\Downloads\thumb-13318422.JPG.dbkpkmg
2014-12-09 01:50 - 2014-09-27 23:58 - 00003344 _____ () D:\Users\Kaz\Downloads\latinpunanijk.JPG.dbkpkmg
2014-12-09 01:50 - 2014-09-27 23:58 - 00002576 _____ () D:\Users\Kaz\Downloads\indexkjkjjjj.JPG.dbkpkmg
2014-12-08 21:39 - 2014-09-27 23:58 - 00003488 _____ () D:\Users\Kaz\Downloads\photobtrbrw.JPG.dbkpkmg
2014-12-08 21:38 - 2014-09-27 23:58 - 00002096 _____ () D:\Users\Kaz\Downloads\indexrbrew.JPG.dbkpkmg
2014-12-08 21:37 - 2014-09-27 23:58 - 00002992 _____ () D:\Users\Kaz\Downloads\unnamedrger.JPG.dbkpkmg
2014-12-08 21:07 - 2014-09-27 23:58 - 00002912 _____ () D:\Users\Kaz\Downloads\jennaleehennessy.JPG.dbkpkmg
2014-12-08 15:24 - 2014-09-27 23:58 - 00002368 _____ () D:\Users\Kaz\Downloads\defaultrthe.JPG.dbkpkmg
2014-12-08 14:31 - 2014-09-27 23:58 - 00002480 _____ () D:\Users\Kaz\Downloads\defaultssvas.JPG.dbkpkmg
2014-12-08 14:31 - 2014-09-27 23:58 - 00002128 _____ () D:\Users\Kaz\Downloads\default karen ramirez.JPG.dbkpkmg
2014-12-08 08:50 - 2009-07-13 21:37 - 00000000 ____D () D:\Windows\rescache
2014-12-08 05:03 - 2014-09-27 23:58 - 00003472 _____ () D:\Users\Kaz\Downloads\defaultjjk.JPG.dbkpkmg
2014-12-08 00:04 - 2014-09-27 23:58 - 00003072 _____ () D:\Users\Kaz\Downloads\tianastaxx.JPG.dbkpkmg
2014-12-07 16:27 - 2014-09-27 23:58 - 00002784 _____ () D:\Users\Kaz\Downloads\avatar.90x90tvgtv.JPG.dbkpkmg
2014-12-07 16:27 - 2014-09-27 23:58 - 00002352 _____ () D:\Users\Kaz\Downloads\avatar.90x90rvf.JPG.dbkpkmg
2014-12-07 16:27 - 2014-09-27 23:58 - 00001856 _____ () D:\Users\Kaz\Downloads\avatar.90x90rvfvr.JPG.dbkpkmg
2014-12-07 16:27 - 2014-09-27 23:58 - 00001472 _____ () D:\Users\Kaz\Downloads\avatar.90x90vvrf.JPG.dbkpkmg
2014-12-07 16:26 - 2014-09-27 23:58 - 00002944 _____ () D:\Users\Kaz\Downloads\avatar.90x90tvgt.JPG.dbkpkmg
2014-12-07 16:26 - 2014-09-27 23:58 - 00002448 _____ () D:\Users\Kaz\Downloads\avatar.90x90vtg.JPG.dbkpkmg
2014-12-07 16:26 - 2014-09-27 23:58 - 00002176 _____ () D:\Users\Kaz\Downloads\avatar.90x90tgtgv.JPG.dbkpkmg
2014-12-07 16:26 - 2014-09-27 23:58 - 00001760 _____ () D:\Users\Kaz\Downloads\avatar.90x90vtgvt.JPG.dbkpkmg
2014-12-07 16:23 - 2014-09-27 23:58 - 00002928 _____ () D:\Users\Kaz\Downloads\indexfr.JPG.dbkpkmg
2014-12-06 18:33 - 2014-08-01 16:04 - 00000000 ____D () D:\Program Files\Mozilla Maintenance Service
2014-12-06 18:29 - 2014-09-27 23:58 - 00003152 _____ () D:\Users\Kaz\Downloads\defaultgiuhi.JPG.dbkpkmg
2014-12-06 17:34 - 2014-09-27 23:58 - 00002320 _____ () D:\Users\Kaz\Downloads\indexfhedg.JPG.dbkpkmg
2014-12-05 13:01 - 2014-09-27 23:58 - 00002768 _____ () D:\Users\Kaz\Downloads\indexjvbkjnm.JPG.dbkpkmg
2014-12-05 12:58 - 2014-09-27 23:58 - 00002480 _____ () D:\Users\Kaz\Downloads\indexjgkjl.JPG.dbkpkmg
2014-12-04 22:02 - 2014-09-27 23:58 - 00003472 _____ () D:\Users\Kaz\Downloads\indexgrege.JPG.dbkpkmg
2014-12-04 19:52 - 2014-09-27 23:58 - 00002144 _____ () D:\Users\Kaz\Downloads\indexdsvsav.JPG.dbkpkmg
2014-12-04 19:40 - 2014-09-27 23:58 - 00003456 _____ () D:\Users\Kaz\Downloads\luisalatinaxx1.JPG.dbkpkmg
2014-12-04 18:59 - 2014-09-27 23:58 - 00003072 _____ () D:\Users\Kaz\Downloads\212dva.JPG.dbkpkmg
2014-12-03 22:20 - 2014-04-21 22:50 - 00001520 _____ () D:\Users\Kaz\Downloads\38957_105034202888100_7248787_n.JPG.dbkpkmg
2014-12-03 20:51 - 2014-09-27 23:58 - 00002576 _____ () D:\Users\Kaz\Downloads\avatar.90x90vsdad.JPG.dbkpkmg
2014-12-03 01:15 - 2014-09-27 23:58 - 00002384 _____ () D:\Users\Kaz\Downloads\defaultsadvasdv.JPG.dbkpkmg
2014-12-03 00:40 - 2014-09-27 23:58 - 00002752 _____ () D:\Users\Kaz\Downloads\defaultvasvs.JPG.dbkpkmg
2014-12-02 21:10 - 2014-04-21 22:50 - 00000304 _____ () D:\Users\Kaz\Downloads\5nOqdgOVN6Rf._500x500.jpg.cb_watermark.JPG.dbkpkmg
2014-12-02 17:57 - 2014-09-27 23:58 - 00003584 _____ () D:\Users\Kaz\Downloads\photocfef.JPG.dbkpkmg
2014-12-02 16:10 - 2014-01-28 19:48 - 00096856 _____ () D:\Users\Kaz\AppData\Local\GDIPFONTCACHEV1.DAT
2014-12-02 16:09 - 2009-07-13 23:33 - 00370760 _____ () D:\Windows\system32\FNTCACHE.DAT
2014-12-02 14:55 - 2014-09-27 23:58 - 00002592 _____ () D:\Users\Kaz\Downloads\indexvavasd.JPG.dbkpkmg
2014-12-02 14:55 - 2014-09-27 23:58 - 00002160 _____ () D:\Users\Kaz\Downloads\indexvsdasd.JPG.dbkpkmg
2014-12-02 14:55 - 2014-09-27 23:58 - 00002112 _____ () D:\Users\Kaz\Downloads\indexvsdv.JPG.dbkpkmg
2014-12-02 13:43 - 2014-09-27 23:58 - 00002480 _____ () D:\Users\Kaz\Downloads\tunderosefds.JPG.dbkpkmg
2014-12-02 00:16 - 2014-09-27 23:58 - 00003216 _____ () D:\Users\Kaz\Downloads\unnamedtmu.JPG.dbkpkmg
2014-12-02 00:07 - 2014-09-27 23:58 - 00003072 _____ () D:\Users\Kaz\Downloads\indexghdfujkl.JPG.dbkpkmg
2014-12-02 00:06 - 2014-09-27 23:58 - 00002144 _____ () D:\Users\Kaz\Downloads\indexglkhjl.JPG.dbkpkmg
2014-12-01 23:37 - 2014-09-27 23:58 - 00002176 _____ () D:\Users\Kaz\Downloads\indexrgaer.JPG.dbkpkmg
2014-12-01 23:29 - 2014-09-27 23:58 - 00003264 _____ () D:\Users\Kaz\Downloads\defaultsdva.JPG.dbkpkmg
2014-12-01 23:29 - 2014-09-27 23:58 - 00003216 _____ () D:\Users\Kaz\Downloads\defaultvasdv.JPG.dbkpkmg
2014-12-01 23:29 - 2014-09-27 23:58 - 00002768 _____ () D:\Users\Kaz\Downloads\defaultvdsa.JPG.dbkpkmg
2014-12-01 23:00 - 2014-09-27 23:58 - 00003488 _____ () D:\Users\Kaz\Downloads\defaultrgqaer.JPG.dbkpkmg
2014-12-01 23:00 - 2014-09-27 23:58 - 00003216 _____ () D:\Users\Kaz\Downloads\defaultdsgvawe.JPG.dbkpkmg
2014-12-01 22:19 - 2014-09-27 23:58 - 00002864 _____ () D:\Users\Kaz\Downloads\defaultgagadfa.JPG.dbkpkmg
2014-12-01 21:49 - 2014-09-27 23:58 - 00002224 _____ () D:\Users\Kaz\Downloads\indexsdva.JPG.dbkpkmg
2014-12-01 21:25 - 2014-09-27 23:58 - 00002400 _____ () D:\Users\Kaz\Downloads\indexbvrewvga.JPG.dbkpkmg
2014-12-01 21:25 - 2014-09-27 23:58 - 00002304 _____ () D:\Users\Kaz\Downloads\indexsvdad.JPG.dbkpkmg
2014-12-01 21:25 - 2014-09-27 23:58 - 00002016 _____ () D:\Users\Kaz\Downloads\indexvdsav.JPG.dbkpkmg
2014-12-01 20:41 - 2014-09-27 23:58 - 00002240 _____ () D:\Users\Kaz\Downloads\indextrjhwtr.JPG.dbkpkmg
2014-12-01 20:33 - 2014-09-27 23:58 - 00003408 _____ () D:\Users\Kaz\Downloads\d735cbb50d840b27debb4ac29a0045c8.JPG.dbkpkmg
2014-12-01 20:33 - 2014-09-27 23:58 - 00003120 _____ () D:\Users\Kaz\Downloads\fb87a5e91a4cdd5daba987d9ef38b8de.JPG.dbkpkmg
2014-12-01 16:41 - 2014-09-27 23:58 - 00003424 _____ () D:\Users\Kaz\Downloads\pambigassfa.JPG.dbkpkmg
2014-11-28 15:18 - 2014-09-27 23:58 - 00002976 _____ () D:\Users\Kaz\Downloads\indexlgyug.JPG.dbkpkmg
2014-11-28 00:24 - 2009-07-13 23:53 - 00032586 _____ () D:\Windows\Tasks\SCHEDLGU.TXT

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

D:\Windows\explorer.exe => File is digitally signed
D:\Windows\system32\winlogon.exe => File is digitally signed
D:\Windows\system32\wininit.exe => File is digitally signed
D:\Windows\system32\svchost.exe => File is digitally signed
D:\Windows\system32\services.exe => File is digitally signed
D:\Windows\system32\User32.dll => File is digitally signed
D:\Windows\system32\userinit.exe => File is digitally signed
D:\Windows\system32\rpcss.dll => File is digitally signed
D:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-12-24 07:21

==================== End Of Log ============================

 

 

 

 

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 28-12-2014
Ran by Kaz at 2014-12-28 15:57:09
Running from D:\Users\Kaz\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Disabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
AS: Microsoft Security Essentials (Disabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-268619972-1601856392-350134406-1000\...\uTorrent) (Version: 3.4.2.34024 - BitTorrent Inc.)
7-Zip 9.20 (HKLM\...\7-Zip) (Version:  - )
Adobe Flash Player 16 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 16.0.0.235 - Adobe Systems Incorporated)
Any Video Converter 5.7.3 (HKLM\...\Any Video Converter_is1) (Version:  - Any-Video-Converter.com)
Apple Application Support (HKLM\...\{A922C4B7-50E0-4787-A94C-59DBF3C65DBE}) (Version: 3.0 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{10E3A6DD-84D8-4D8A-BB11-5E5314BCA7FD}) (Version: 7.1.0.32 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Bluetooth Stack for Windows by Toshiba (HKLM\...\{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}) (Version: v9.10.01 - TOSHIBA CORPORATION)
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 5.01 - Piriform)
D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden
Dell Touchpad (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 7.1007.115.102 - ALPS ELECTRIC CO., LTD.)
Ezvid (HKLM\...\{F96D619D-99D6-4C9C-A393-0CD22DE1CA66}_is1) (Version: 0982 - Ezvid, inc.)
Foxit Cloud (HKLM\...\{41914D8B-9D6E-4764-A1F9-BC43FB6782C1}_is1) (Version: 2.1.32.905 - Foxit Software Inc.)
Foxit Reader (HKLM\...\Foxit Reader_is1) (Version: 7.0.3.916 - Foxit Software Inc.)
HandBrake 0.9.9.1 (HKLM\...\HandBrake) (Version: 0.9.9.1 - )
HP Deskjet 3510 series Basic Device Software (HKLM\...\{9F1F6E90-519F-4217-9A4B-466632D5CCCB}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
iDealshare VideoGo 5.4.3.5410 (HKLM\...\{CC4C06C4-7C78-4aab-B5AF-33FB11CCD829}_is1) (Version:  - iDealshare Corporation)
iTunes (HKLM\...\{616445AF-BBCF-41C1-A4D6-8CFF171C182D}) (Version: 11.1.4.62 - Apple Inc.)
Malwarebytes Anti-Malware version 2.0.4.1028 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Movie Maker (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 34.0 (x86 en-US) (HKLM\...\Mozilla Firefox 34.0 (x86 en-US)) (Version: 34.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 31.0 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
OpenOffice 4.1.1 (HKLM\...\{9395F41D-0F80-432E-9A59-B8E477E7E163}) (Version: 4.11.9775 - Apache Software Foundation)
PC Sleep (HKLM\...\{11BD0F20-27DC-4584-AD10-9E99F32F8501}) (Version: 2.2.0 - www.pc-sleep.com)
Pinnacle VideoSpin (HKLM\...\{FEB15887-0932-4D2D-BB85-6AC03FBF1AA8}) (Version: 2.0.0.669 - Pinnacle Systems)
Realtek USB 2.0 Card Reader (HKLM\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7100.30087 - Realtek Semiconductor Corp.)
swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
TorrentRover v0.21.10 beta (HKLM\...\{3E0B69D1-525B-4DEE-BF9A-E87EAB5A9EBA}) (Version: 0.21.10 - John Loper II (All Rights Reserved))
Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN)
Warcraft III (HKLM\...\Warcraft III) (Version:  - )
Warcraft III: All Products (HKU\S-1-5-21-268619972-1601856392-350134406-1000\...\Warcraft III) (Version:  - )
Windows Live Essentials (HKLM\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-268619972-1601856392-350134406-1000_Classes\CLSID\{56CBD3CF-BF99-4DF5-851F-F5B9B57496A1}\InprocServer32 -> D:\ProgramData\{D9E629DC-CB1C-4A97-9900-81922B4EFFD4}\dbghelp.dll (Microsoft Corporation)

==================== Restore Points  =========================


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 21:04 - 2014-12-28 15:33 - 00000027 ____A D:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {1BB26A15-FDB0-4724-AB0D-D05F921280D7} - System32\Tasks\Apple\AppleSoftwareUpdate => D:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {8A7FC6A6-E181-458F-B152-1BB232894AE5} - System32\Tasks\CCleanerSkipUAC => D:\Program Files\CCleaner\CCleaner.exe [2014-12-12] (Piriform Ltd)
Task: {B4833BCF-1B70-45F4-A00F-BB2549DF25D0} - \wvyxffc No Task File <==== ATTENTION

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Loaded Modules (whitelisted) =============

2014-01-20 13:17 - 2014-01-20 13:17 - 00073544 _____ () D:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2014-01-20 13:16 - 2014-01-20 13:16 - 01044808 _____ () D:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2014-12-05 16:37 - 2014-12-05 16:37 - 03758192 _____ () D:\Program Files\Mozilla Firefox\mozjs.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)


==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: D:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth Manager.lnk => D:\Windows\pss\Bluetooth Manager.lnk.CommonStartup
MSCONFIG\startupreg: Aimersoft Helper Compact.exe => D:\Program Files\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe
MSCONFIG\startupreg: HP Deskjet 3510 series (NET) => "D:\Program Files\HP\HP Deskjet 3510 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN36S1NHCR05Y7:NW" -scfn "HP Deskjet 3510 series (NET)" -AutoStart 1
MSCONFIG\startupreg: iTunesHelper => "D:\Program Files\iTunes\iTunesHelper.exe"

========================= Accounts: ==========================

Administrator (S-1-5-21-268619972-1601856392-350134406-500 - Administrator - Disabled)
Guest (S-1-5-21-268619972-1601856392-350134406-501 - Limited - Disabled)
Kaz (S-1-5-21-268619972-1601856392-350134406-1000 - Administrator - Enabled) => D:\Users\Kaz

==================== Faulty Device Manager Devices =============

Name: PortableVBoxDRV
Description: PortableVBoxDRV
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: VBoxDRV
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Event log errors: =========================

Application errors:
==================
Error: (12/28/2014 03:22:39 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point (Process = D:\Windows\system32\wbem\wmiprvse.exe; Description = ComboFix created restore point; Error = 0x80070422).

Error: (12/28/2014 03:08:36 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (12/28/2014 02:06:33 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (12/28/2014 03:36:49 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (12/28/2014 02:01:41 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (12/28/2014 01:35:15 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (12/27/2014 11:40:36 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: mbam.exe, version: 1.0.1.711, time stamp: 0x542b53ec
Faulting module name: mbamcore.dll, version: 1.1.20.0, time stamp: 0x5425b0dd
Exception code: 0xc0000005
Fault offset: 0x0003ec9b
Faulting process id: 0x330
Faulting application start time: 0xmbam.exe0
Faulting application path: mbam.exe1
Faulting module path: mbam.exe2
Report Id: mbam.exe3

Error: (12/27/2014 11:12:14 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (12/27/2014 11:06:36 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 9594

Error: (12/27/2014 11:06:36 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 9594


System errors:
=============
Error: (12/28/2014 03:34:01 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: The PEVSystemStart service is marked as an interactive service.  However, the system is configured to not allow interactive services.  This service may not function properly.

Error: (12/28/2014 03:30:49 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: The PEVSystemStart service is marked as an interactive service.  However, the system is configured to not allow interactive services.  This service may not function properly.

Error: (12/28/2014 03:25:34 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: The PEVSystemStart service is marked as an interactive service.  However, the system is configured to not allow interactive services.  This service may not function properly.

Error: (12/28/2014 03:08:24 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

Error: (12/28/2014 03:08:11 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (Using LRPC)

Error: (12/28/2014 03:07:11 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The PortableVBoxUSBMon service failed to start due to the following error:
%%3

Error: (12/28/2014 03:07:11 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The PortableVBoxDRV service failed to start due to the following error:
%%3

Error: (12/28/2014 03:06:41 PM) (Source: Ntfs) (EventID: 137) (User: )
Description: The default transaction resource manager on volume Z: encountered a non-retryable error and could not start.  The data contains the error code.

Error: (12/28/2014 02:06:14 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

Error: (12/28/2014 02:06:06 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (Using LRPC)


Microsoft Office Sessions:
=========================

==================== Memory info ===========================

Processor: Intel® Core2 Duo CPU T6400 @ 2.00GHz
Percentage of memory in use: 66%
Total physical RAM: 2008.36 MB
Available physical RAM: 682.39 MB
Total Pagefile: 4016.73 MB
Available Pagefile: 2607.04 MB
Total Virtual: 2047.88 MB
Available Virtual: 1885.09 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:113.91 GB) (Free:61.73 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: () (Fixed) (Total:184.17 GB) (Free:17 GB) NTFS
Drive z: () (Fixed) (Total:0.01 GB) (Free:0 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 000E32CC)
Partition 1: (Active) - (Size=113.9 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=184.2 GB) - (Type=OF Extended)

==================== End Of Log ============================

Link to post
Share on other sites

Welcome to the forum. (Do what you can)

General P2P/Piracy Warning:

 

1. If you're using Peer 2 Peer software such uTorrent, BitTorrent or similar you must either fully uninstall it or completely disable it from running while being assisted here.

2. If you have illegal/cracked software (MS Office, Adobe Products), cracks, keygens, custom (Adobe) host file, etc. on the system, please remove or uninstall them now and read the policy on Piracy.

Failure to remove such software will result in your topic being closed and no further assistance being provided.

1. Please run a Threat Scan with Malwarebytes

Start Malwarebytes 2.0..........

Click on Settings > Detection and Protection > Non-Malware Protection > PUP (Potentially Unwanted Program) detections > Make sure it's set to Treat detections as malware

Same for PUM (Potentially Unwanted Modifications)

Quarantine all that's found

Post the log (save the log as a .txt file not .xml)

Then......

2. Please download and run RogueKiller 32 bit to your desktop.

RogueKiller<---use this one for 64 bit systems

Which system am I using?

Quit all running programs.

For Windows XP, double-click to start.

For Vista or Windows 7-8, do a right-click on the program, select Run as Administrator to start, & when prompted Allow to run.

Wait for the Prescan to finish

Click Scan to scan the system.

When the scan completes > Don't Fix anything! > Click on the Report Button and post the Report back here.

Don't run any other options, they're not all bad!!!!!!!

RogueKiller logs will also be located here:

%programdata%/RogueKiller/Logs <-------W7

C:\Documents and Settings\All Users\Application Data\RogueKiller\Logs <-------XP

(please don't put logs in code or quotes and use the default font)

MrC

Note:

Please read all of my instructions completely including these.

Make sure system restore is turned on and running. Create a new restore point

Make sure you're subscribed to this topic: Click on the Follow This Topic Button (at the top right of this page), make sure that the Receive notification box is checked and that it is set to Instantly

Removing malware can be unpredictable...unlikely but things can go very wrong! Backup any files that cannot be replaced. You can copy them to a CD/DVD, external drive or a pen drive

<+>Please don't run any other scans, download, install or uninstall any programs while I'm working with you.

<+>The removal of malware isn't instantaneous, please be patient.

<+>When we are done, I'll give to instructions on how to cleanup all the tools and logs

<+>Please stick with me until I give you the "all clear".

------->Your topic will be closed if you haven't replied within 3 days!<--------

If I don't respond within 24 hours, please send me a PM

Link to post
Share on other sites

Do you know what these files are with these strange extentions:

D:\Users\Kaz\Downloads\indextgvvgt.JPG.dbkpkmg
D:\Users\Kaz\Downloads\indexbregqrw3.JPG.dbkpkmg
D:\Users\Kaz\Desktop\uygihij.xspf
D:\Users\Kaz\Desktop\vtgvg.xspf

What this folder is for:
D:\ProgramData\PacefTazuv

================================

Download the attached fixlist.txt to the same folder as FRST.exe/FRST64.exe.
Run FRST.exe/FRST64.exe and click Fix only once and wait
The tool will create a log (Fixlog.txt) in the folder, please post it to your reply.

===============================

Let me know how it is, MrC

fixlist.txt

Link to post
Share on other sites

These two files were downloaded images, not sure what the .dbkpkmg extension is.  I noticed quite a few of my files in my downloads folder has recently got them too.  Also I had some important text documents on my desktop that recently received that extension on them and I am unable to open them with notepad.

D:\Users\Kaz\Downloads\indextgvvgt.JPG.dbkpkmg
D:\Users\Kaz\Downloads\indexbregqrw3.JPG.dbkpkmg

 

These files are two of many vlc media player saved playlists, extension is normal I believe.

D:\Users\Kaz\Desktop\uygihij.xspf
D:\Users\Kaz\Desktop\vtgvg.xspf


I do not know what this folder is or is for.  I opened it and looked at its properties and appears empty.
D:\ProgramData\PacefTazuv

Fixlog.txt

Link to post
Share on other sites

It is a picture saying my files are encrypted by CTB-Locker.  I took a screenshot of the picture and saved it in paint as another image and attached it.

 

I tried removing some of those dbkpkmg extensions from pictures in my downloads folder and although the picture would now try to open up in windows photo viewer, it said it could not due to unsupported file format or outdated photo viewer (but I think it's up to date).  Next I tried to remove an extension off of one of my desktop text documents, and although it would finally open up in notepad, it consisted of a full line of weird symbols (chinese/japanese?).

post-180675-0-54602800-1420134187_thumb.

Link to post
Share on other sites

A few days ago I realized my system restore was off for some reason.  It is on now but probably pointless as it's been on after infection.  How do I access this file?  %MyDocuments%\<random>.html  I'm a little confused by the percentage signs, is it just a file that should be in my documents?  If so, I do not see it.  Supposedly it contains a list of all my encrypted files.

 

In my case I think only a file recovery software could work that they suggest.  What would you suggest?  Is the main infection gone at least?  I noticed the extra explorer.exe process is no longer prevalent.

Link to post
Share on other sites

How do I access this file? %MyDocuments%\<random>.html I'm a little confused by the percentage signs, is it just a file that should be in my documents? If so, I do not see it. (I don't see it also) Supposedly it contains a list of all my encrypted files.

Should be this:
D:\Users\Kaz\Documents

In my case I think only a file recovery software could work that they suggest. What would you suggest?
They list 2 programs to use


Is the main infection gone at least? I noticed the extra explorer.exe process is no longer prevalent.

Yes but I would like to run some other programs also.

MrC

Link to post
Share on other sites

Make sure you have created that system restore point before you continue!

Please read the directions carefully so you don't end up deleting something that is good!!

If in doubt about an entry....please ask or choose Skip!!!!

Don't Delete anything unless instructed to!

If you get the warning about a file UnsignedFile.Multi.Generic or LockedFile.Multi.Generic please choose

Skip and click on Continue

If a suspicious object is detected, the default action will be Skip, click on Continue

Please note that TDSSKiller can be run in safe mode if needed.

Please download the latest version of TDSSKiller from HERE and save it to your Desktop.

  • Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters. (Leave the KSN box checked)

    tds2.jpg

  • Put a checkmark beside loaded modules.

    13040712472913819.png

  • A reboot will be needed to apply the changes. Do it.
  • TDSSKiller will launch automatically after the reboot. Also your computer may seem very slow and unusable. This is normal. Give it enough time to load your background programs.
  • Then click on Change parameters in TDSSKiller.
  • Check all boxes then click OK.

    clip.jpg

  • Click the Start Scan button.

    tds2.jpg

  • The scan should take no longer than 2 minutes.
  • If a suspicious object is detected, the default action will be Skip, click on Continue.

    tdsskiller_guide_5.gif

    Any entries like this: \Device\Harddisk0\DR0 ( TDSS File System ) - please choose Skip.

    If in doubt about an entry....please ask or choose Skip

  • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.

    Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.

    tdsskiller_guide_3.gif

    Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.

  • A report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here. There may be 3 logs > so post or attach all of them.
  • Sometimes these logs can be very large, in that case please attach it or zip it up and attach it.

Here's a summary of what to do if you would like to print it out:

If in doubt about an entry....please ask or choose Skip

Don't Delete anything unless instructed to!

If a suspicious object is detected, the default action will be Skip, click on Continue

If you get the warning about a file UnsignedFile.Multi.Generic or LockedFile.Multi.Generic please choose

Skip and click on Continue

Any entries like this: \Device\Harddisk0\DR0 ( TDSS File System ) - please choose Skip.

If malicious objects are found, they will show in the Scan results and offer three (3) options.

Ensure Cure is selected, then click Continue => Reboot now to finish the cleaning process.

Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.

~~~~~~~~~~~~~~~~~~~~

You can attach the logs if they're too long:

Bottom right corner of this page.

reply1.jpg

New window that comes up.

replyer1.jpg

Then...........

Please download and run ComboFix.

The most important things to remember when running it is to disable all your malware programs and run Combofix from your desktop.

Please visit this webpage for download links, and instructions for running ComboFix

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

http://www.bleepingcomputer.com/download/combofix/dl/12/<---ComboFix direct download

Please make sure you click download buttons that look similar to this, not "sponsored ad links":

bleep-crop.jpg

Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Information on disabling your malware programs can be found Here.

Make sure you run ComboFix from your desktop.

Give it at least 30-45 minutes to finish if needed.

Please include the C:\ComboFix.txt in your next reply for further review.

---------->NOTE<----------

If you get the message Illegal operation attempted on registry key that has been marked for deletion after you run ComboFix....please reboot the computer, this should resolve the problem. You may have to do this several times if needed.

Last:

Clean out temp files:

Download TFC from here and save it to your desktop.

http://oldtimer.geekstogo.com/TFC.exe

http://www.bleepingcomputer.com/download/tfc/dl/92/

Close any open programs and Internet browsers.

Double click TFC.exe to run it on XP (for Vista and Windows 7 right click and choose "Run as administrator") and once it opens click on the Start button on the lower left of the program to allow it to begin cleaning.

Please be patient as clearing out temp files may take a while.

Once it completes you may be prompted to restart your computer, please do so.

Once it's finished you may delete TFC.exe from your desktop or save it for later use for the cleaning of temporary files.

MrC

Link to post
Share on other sites

They look OK.....if there's no other problems:

Lets check your computers security before you go and we have a little cleanup to do also:

Download Security Check by screen317 from HERE or HERE.

  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • If you get Unsupported operating system. Aborting now, just reboot and try again.
  • A Notepad document should open automatically called checkup.txt.
  • Please Post the contents of that document.
  • If you can't post it, attach it
MrC
Link to post
Share on other sites

 Results of screen317's Security Check version 0.99.93  
 Windows 7 Service Pack 1 x86 (UAC is enabled)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:``````````````
 Windows Firewall Enabled!  
Microsoft Security Essentials   
 Antivirus up to date!  
`````````Anti-malware/Other Utilities Check:`````````
 CCleaner     
 Adobe Flash Player     16.0.0.235  
 Mozilla Firefox (34.0)
````````Process Check: objlist.exe by Laurent````````  
 Microsoft Security Essentials MSMpEng.exe
 Microsoft Security Essentials msseces.exe
`````````````````System Health check`````````````````
 Total Fragmentation on Drive D: 2%
````````````````````End of Log``````````````````````
 

Link to post
Share on other sites

That Looks Good.....

A little clean up to do....

Please Uninstall ComboFix: (------->if you used it<-------)

Press the Windows logo key + R to bring up the "run box"

Copy and paste next command in the field:

ComboFix /uninstall

Make sure there's a space between Combofix and /

cf2.jpg

Then hit enter. (it may look like CF is re-installing but it's not)

This will uninstall Combofix, delete its related folders and files, hide file extensions, hide the system/hidden files and clears System Restore cache and create new Restore point

(If that doesn't work.....you can simply rename ComboFix.exe to Uninstall.exe and double click it to complete the uninstall or download and run the uninstaller)

---------------------------------

bwebb7v.jpgDownload Delfix from here and save it to your desktop. (you may already have this)

  • Ensure Remove disinfection tools is checked.
  • Click the Run button.
  • Reboot
Any other programs or logs that are still remaining, you can manually delete. (right click.....Delete)

IE: RogueKiller.exe, RKreport.txt, RK_Quarantine folder, C:\FRST folder, FRST-OlderVersion folder, MBAR folder, etc....AdwCleaner > just run the program and click uninstall.

Note:

If you used FRST and can't delete the quarantine folder:

Download the fixlist.txt to the same folder as FRST.exe.

Run FRST.exe and click Fix only once and wait

That will delete the quarantine folder created by FRST.

The rest you can manually delete.

-------------------------------

Any questions...please post back.

If you think I've helped you, please leave a comment > click on my avatar picture > click Profile Feed.

Take a look at My Preventive Maintenance to avoid being infected again.

Good Luck and Thanks for using the forum, MrC

Link to post
Share on other sites

  • Root Admin

Glad we could help. :)

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.