Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [code]
- HitmanPro 3.7.9.225
- www.hitmanpro.com
- Computer name . . . . : JARED
- Windows . . . . . . . : 6.3.0.9600.X64/6
- User name . . . . . . : JARED\Jtpetch
- UAC . . . . . . . . . : Enabled
- License . . . . . . . : Trial (30 days left)
- Scan date . . . . . . : 2014-10-07 14:44:16
- Scan mode . . . . . . : Normal
- Scan duration . . . . : 5m 20s
- Disk access mode . . : Direct disk access (SRB)
- Cloud . . . . . . . . : Internet
- Reboot . . . . . . . : Yes
- Threats . . . . . . . : 2
- Traces . . . . . . . : 128
- Objects scanned . . . : 1,978,248
- Files scanned . . . . : 71,826
- Remnants scanned . . : 676,202 files / 1,230,220 keys
- Malware _____________________________________________________________________
- C:\ProgramData\GoSavE\Ahrl1GTenAxTQPm.exe -> Quarantined
- Size . . . . . . . : 3,926,016 bytes
- Age . . . . . . . : 4.1 days (2014-10-03 11:15:18)
- Entropy . . . . . : 6.9
- SHA-256 . . . . . : 5D98BD3860712FE27204087B1D93E7A139FE04F817ED6E0525BBFCA141E6AEFD
- > Bitdefender . . . : Gen:Variant.Adware.MPlug.12
- Fuzzy . . . . . . : 108.0
- C:\ProgramData\YoutUbeAdBlocke\I7xHDpzcpod24V4.exe -> Quarantined
- Size . . . . . . . : 3,827,712 bytes
- Age . . . . . . . : 4.1 days (2014-10-03 11:15:31)
- Entropy . . . . . : 6.8
- SHA-256 . . . . . : 7861D0FFF3C0A1B9F99B607F9DC41858D5CCDC48D073053F0A7C31A93F5F3D12
- > Bitdefender . . . : Gen:Variant.Adware.MPlug.12
- Fuzzy . . . . . . : 108.0
- Suspicious files ____________________________________________________________
- C:\Users\Jtpetch\AppData\Local\PunkBuster\APB\pb\dll\wc002327.dll
- Size . . . . . . . : 968,536 bytes
- Age . . . . . . . : 84.8 days (2014-07-14 18:27:57)
- Entropy . . . . . : 7.6
- SHA-256 . . . . . : 5B7AAFE720F6D7E618784C9AC16A6FD2329B7B0170E24B642D0059971B6C5B7A
- RSA Key Size . . . : 2048
- Authenticode . . . : Valid
- Fuzzy . . . . . . : 22.0
- The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
- Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
- Authors name is missing in version info. This is not common to most programs.
- Version control is missing. This file is probably created by an individual. This is not typical for most programs.
- Program contains PE structure anomalies. This is not typical for most programs.
- Program is code signed with a valid Authenticode certificate.
- C:\Users\Jtpetch\AppData\Local\PunkBuster\APB\pb\pbcl.dll
- Size . . . . . . . : 968,536 bytes
- Age . . . . . . . : 84.8 days (2014-07-14 18:42:28)
- Entropy . . . . . : 7.6
- SHA-256 . . . . . : 5B7AAFE720F6D7E618784C9AC16A6FD2329B7B0170E24B642D0059971B6C5B7A
- RSA Key Size . . . : 2048
- Authenticode . . . : Valid
- Fuzzy . . . . . . : 22.0
- The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
- Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
- Authors name is missing in version info. This is not common to most programs.
- Version control is missing. This file is probably created by an individual. This is not typical for most programs.
- Program contains PE structure anomalies. This is not typical for most programs.
- Program is code signed with a valid Authenticode certificate.
- C:\Users\Jtpetch\AppData\Local\PunkBuster\APB\pb\pbclold.dll
- Size . . . . . . . : 968,536 bytes
- Age . . . . . . . : 84.9 days (2014-07-14 18:13:12)
- Entropy . . . . . : 7.6
- SHA-256 . . . . . : 5B7AAFE720F6D7E618784C9AC16A6FD2329B7B0170E24B642D0059971B6C5B7A
- RSA Key Size . . . : 2048
- Authenticode . . . : Valid
- Fuzzy . . . . . . : 22.0
- The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
- Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
- Authors name is missing in version info. This is not common to most programs.
- Version control is missing. This file is probably created by an individual. This is not typical for most programs.
- Program contains PE structure anomalies. This is not typical for most programs.
- Program is code signed with a valid Authenticode certificate.
- C:\Users\Jtpetch\AppData\Local\PunkBuster\APB\pb\PnkBstrK.sys
- Size . . . . . . . : 139,656 bytes
- Age . . . . . . . : 84.9 days (2014-07-14 18:13:24)
- Entropy . . . . . : 7.7
- SHA-256 . . . . . : 0C20AD6DD97FF44B94AF48A1FC7A0FDEB8D94E8727A76333B3453B35F27B628F
- RSA Key Size . . . : 2048
- Authenticode . . . : Valid
- Fuzzy . . . . . . : 22.0
- The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
- Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
- Authors name is missing in version info. This is not common to most programs.
- Version control is missing. This file is probably created by an individual. This is not typical for most programs.
- Program contains PE structure anomalies. This is not typical for most programs.
- The file is a device driver. Device drivers run as trusted (highly privileged) code.
- Program is code signed with a valid Authenticode certificate.
- C:\Users\Jtpetch\AppData\Local\PunkBuster\BF3\pb\dll\wc002342.dll
- Size . . . . . . . : 969,032 bytes
- Age . . . . . . . : 86.7 days (2014-07-12 22:58:34)
- Entropy . . . . . : 7.6
- SHA-256 . . . . . : FC5702BFEF687EDAF89499C7849E4FDA0AF9D72A5A632C5B4E20F2562468596C
- RSA Key Size . . . : 2048
- Authenticode . . . : Valid
- Fuzzy . . . . . . : 22.0
- The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
- Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
- Authors name is missing in version info. This is not common to most programs.
- Version control is missing. This file is probably created by an individual. This is not typical for most programs.
- Program contains PE structure anomalies. This is not typical for most programs.
- Program is code signed with a valid Authenticode certificate.
- C:\Users\Jtpetch\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
- Size . . . . . . . : 969,032 bytes
- Age . . . . . . . : 77.9 days (2014-07-21 16:40:23)
- Entropy . . . . . : 7.6
- SHA-256 . . . . . : FC5702BFEF687EDAF89499C7849E4FDA0AF9D72A5A632C5B4E20F2562468596C
- RSA Key Size . . . : 2048
- Authenticode . . . : Valid
- Fuzzy . . . . . . : 22.0
- The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
- Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
- Authors name is missing in version info. This is not common to most programs.
- Version control is missing. This file is probably created by an individual. This is not typical for most programs.
- Program contains PE structure anomalies. This is not typical for most programs.
- Program is code signed with a valid Authenticode certificate.
- C:\Users\Jtpetch\AppData\Local\PunkBuster\BF3\pb\pbclold.dll
- Size . . . . . . . : 969,032 bytes
- Age . . . . . . . : 86.9 days (2014-07-12 16:00:36)
- Entropy . . . . . : 7.6
- SHA-256 . . . . . : FC5702BFEF687EDAF89499C7849E4FDA0AF9D72A5A632C5B4E20F2562468596C
- RSA Key Size . . . : 2048
- Authenticode . . . : Valid
- Fuzzy . . . . . . : 22.0
- The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
- Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
- Authors name is missing in version info. This is not common to most programs.
- Version control is missing. This file is probably created by an individual. This is not typical for most programs.
- Program contains PE structure anomalies. This is not typical for most programs.
- Program is code signed with a valid Authenticode certificate.
- C:\Users\Jtpetch\AppData\Local\PunkBuster\BF3\pb\PnkBstrK.sys
- Size . . . . . . . : 140,072 bytes
- Age . . . . . . . : 86.9 days (2014-07-12 16:00:48)
- Entropy . . . . . : 7.7
- SHA-256 . . . . . : CC3F4E453FC246B64C09E81BB73741CECC897C805C13815336647E986A60301E
- RSA Key Size . . . : 2048
- Authenticode . . . : Valid
- Fuzzy . . . . . . : 22.0
- The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
- Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
- Authors name is missing in version info. This is not common to most programs.
- Version control is missing. This file is probably created by an individual. This is not typical for most programs.
- Program contains PE structure anomalies. This is not typical for most programs.
- The file is a device driver. Device drivers run as trusted (highly privileged) code.
- Program is code signed with a valid Authenticode certificate.
- C:\Users\Jtpetch\AppData\Local\PunkBuster\BLR\pb\pbcl.dll
- Size . . . . . . . : 949,190 bytes
- Age . . . . . . . : 60.7 days (2014-08-07 21:33:55)
- Entropy . . . . . : 7.6
- SHA-256 . . . . . : DAF43E93528BEEECC015FA98D6EE6D6FD6D19A049321E47A65665144E4511F41
- Fuzzy . . . . . . : 29.0
- The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
- Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
- Authors name is missing in version info. This is not common to most programs.
- Version control is missing. This file is probably created by an individual. This is not typical for most programs.
- Program contains PE structure anomalies. This is not typical for most programs.
- C:\Users\Jtpetch\AppData\Local\PunkBuster\BLR\pb\PnkBstrK.sys
- Size . . . . . . . : 140,360 bytes
- Age . . . . . . . : 60.7 days (2014-08-07 21:34:09)
- Entropy . . . . . : 7.8
- SHA-256 . . . . . : 0F41B3843E2D2D1BB1ACF8B7CAA293309CC1CF8CF478B1AC86DD6BB214928DC4
- RSA Key Size . . . : 2048
- Authenticode . . . : Valid
- Fuzzy . . . . . . : 22.0
- The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
- Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
- Authors name is missing in version info. This is not common to most programs.
- Version control is missing. This file is probably created by an individual. This is not typical for most programs.
- Program contains PE structure anomalies. This is not typical for most programs.
- The file is a device driver. Device drivers run as trusted (highly privileged) code.
- Program is code signed with a valid Authenticode certificate.
- C:\Windows\SysWOW64\GameMon.des
- Size . . . . . . . : 3,191,392 bytes
- Age . . . . . . . : 47.1 days (2014-08-21 12:33:25)
- Entropy . . . . . : 8.0
- SHA-256 . . . . . : F65AF9FAF6899F7A8EC472FE24732F871B1E6F2FE9095DE9F4CF5CA1FF18D5ED
- Product . . . . . : nProtect Game Monitor
- Publisher . . . . : INCA Internet Co., Ltd.
- Description . . . : nProtect Game Monitor Rev 2090
- Version . . . . . : 2014.5.16.1
- RSA Key Size . . . : 2048
- Service . . . . . : npggsvc
- LanguageID . . . . : 1042
- Authenticode . . . : Valid
- Fuzzy . . . . . . : 25.0
- The file name extension of this program is not common.
- Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
- The file is located in a folder that contains core operating system files from Windows. This is not typical for most programs and is only common to system tools, drivers and hacking utilities.
- Starts automatically as a service during system bootup.
- Program is code signed with a valid Authenticode certificate.
- Startup
- HKLM\SYSTEM\CurrentControlSet\Services\npggsvc\
- Potential Unwanted Programs _________________________________________________
- homepage
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Preferences
- HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}\ (PCOptimizerPro) -> Deleted
- HKLM\SOFTWARE\Classes\s\ (Softonic) -> Deleted
- HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}\ (PCOptimizerPro) -> Deleted
- HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}\ (AdBlocker) -> Deleted
- HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}\ (iPumper) -> Deleted
- HKLM\SOFTWARE\Wow6432Node\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}\ (FLV Player) -> Deleted
- HKLM\SOFTWARE\Wow6432Node\{5F189DF5-2D05-472B-9091-84D9848AE48B}\ (PCOptimizerPro) -> Deleted
- HKLM\SOFTWARE\Wow6432Node\{77D46E27-0E41-4478-87A6-AABE6FBCF252}\ (PCBooster) -> Deleted
- HKU\.DEFAULT\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\ (PCOptimizerPro) -> Deleted
- HKU\S-1-5-18\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\ (PCOptimizerPro) -> PendingDelete
- HKU\S-1-5-19\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\ (PCOptimizerPro) -> Deleted
- HKU\S-1-5-21-1704732030-4174627178-266599957-1001\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\ (PCOptimizerPro) -> Deleted
- Cookies _____________________________________________________________________
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:247realmedia.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:2o7.net
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:a1.interclick.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.360yield.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.mlnadvertising.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.newegg.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.propellerads.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:adlegend.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.ad4game.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.altitude-arena.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.creative-serving.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.dragonfru.it
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.mediade.sk
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.nexage.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.ookla.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.p161.net
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.pointroll.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.pubmatic.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.servebom.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.stickyadstv.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.undertone.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.yahoo.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:adserve.atedra.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:adserver.adreactor.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:adserverf1d263next.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:adtech.de
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:adtechus.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:advertising.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:advertlets.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:ar.atwola.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:at.atwola.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:atdmt.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:atwola.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:bs.serving-sys.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:burstnet.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:casalemedia.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:chitika.net
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:collective-media.net
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:dmtracker.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:doubleclick.net
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:emjcd.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:fastclick.net
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:googleadservices.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:in.getclicky.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:interclick.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:kontera.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:media6degrees.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:mediaplex.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:microsoftsto.112.2o7.net
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:mm.chitika.net
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:oracle.112.2o7.net
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:pcworldcommunication.122.2o7.net
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:pointroll.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:questionmarket.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:realmedia.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:revsci.net
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:ru4.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:server.cpmstar.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:serving-sys.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:smartadserver.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:specificclick.net
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:statcounter.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:statse.webtrendslive.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:survey.g.doubleclick.net
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:tacoda.at.atwola.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:tacoda.net
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:track.adform.net
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:track.hubrus.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:track.strife.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:tribalfusion.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:weborama.fr
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:www.googleadservices.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:xiti.com
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:yadro.ru
- C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:zedo.com
- C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\217ZFWNT.txt
- C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\2LQ1QKF2.txt
- C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\31WH9ZLQ.txt
- C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\47UVMVI6.txt
- C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\4BYL75ZY.txt
- C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\7YO171A5.txt
- C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\84GP545L.txt
- C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\8E6FD3XO.txt
- C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\9YBJM827.txt
- C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\ANKQFI7L.txt
- C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\FL402LV1.txt
- C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\HP0J27SJ.txt
- C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\KP23Z79H.txt
- C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\LTXFF4QK.txt
- C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\N8MSIPC9.txt
- C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\NFKILWCH.txt
- C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\NTA2NWAQ.txt
- C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\ORE6KCLB.txt
- C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\QGSZBGOV.txt
- C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\R3VRNTFQ.txt
- C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\RM1WOWAK.txt
- C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\TT7L3SW6.txt
- C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\TT9OPTKG.txt
- C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\XCV86MEM.txt
- C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\XG8HMF21.txt
- C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\YU7LWHC5.txt
- [/code]
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement