Suspected Matrix Ransomware. Need help in removing it.

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Malnutrition
    PCHF Moderator
    • Jul 2016
    • 7041

    #16
    FRST Fix.

    Click Here To Download Fixlist.


    Download attached fixlist.txt file and save it to the Desktop. NOTE. It’s important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work. NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system Run FRST/FRST64 and press the Fix button just once and wait. If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run. When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

    Zemana Deep Scan
    [ul]
    [li]
    • [/li][li]Right click on Zemana and run as admin.[/li][/ul]
      [ul]
      [li]Click the Cog/Sproket Wheel, at the top right of Zemana[/li][/ul]
      [ul]
      [li]Select Advanced - I have read the warning and wish to proceed.[/li][/ul]
      [ul]
      [li]Place a tick next to Detect Suspicious (Root CA) Certificates.[/li][/ul]
      [ul]
      [li]Then click the house icon in Zemana.[/li][/ul]
      [ul]
      [li]Then hit your start button at the lower left hand corner of your desktop.[/li][/ul]
      [ul]
      [li]Then left click on Computer.[/li][/ul]
      [ul]
      [li]Drag Local Disk C: or whichever drive you decide to check first.[/li]
      [li]Into the area of Zemana that reads Drag and drop files here to scan them.[/li][/ul]

      [ul]
      [li]http://i.imgur.com/bOVO6lY.png[/li][/ul]

      [ul]
      [li]Once the scan has completed click graph icon on the top right of the programs User interface.[/li][/ul]
      [ul]
      [li]Double click to open the latest log-file.[/li][/ul]
      [ul]
      [li]Copy it to your clipboard.[/li][/ul]
      [ul]
      [li]Post the log here in your next reply.[/li][/ul]

    Comment

    • Malnutrition
      PCHF Moderator
      • Jul 2016
      • 7041

      #17
      When done with the above scans, lets use a tool that looks a little deeper than FRST to check for any remnants.

      ZHP Diag Scan

      Download ZHP Diag to your desktop.
      1. Right Click Run as Admin.
        2. Click the Scanner button.



      When complete please push the report button.
      A notepad will open… copy and paste the report in your next reply.

      Comment

      • Malnutrition
        PCHF Moderator
        • Jul 2016
        • 7041

        #18
        File Search With Everything Search Engine.

        Download and install the Everything Search Engine
        Right Click Run As Admin. Type or Copy Paste .matrix into search window.
        Then Click Edit. >>>Select all.
        Right Click highlighted items>>>>>>>> Copy full name to clipboard.
        Paste content of clipboard, here in your next reply.

        Comment

        • Shrey_Aryan
          PCHF Member
          • Mar 2017
          • 34

          #19
          C:\Users\HP-PC\Music\Europop\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\facebook.com mohitdeenrmx\facebook.com mohitdeenrmx\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Fergie\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Fergie\Fergie as The Dutchess\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Fort Minor\The Rising Tied\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Fort Minor\The Rising Tied\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Fort Minor\The Rising Tied Instrumental\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Gangster\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Good Charlotte\The Young And The Hopeless\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Gorillaz\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Green Day\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Green Day\2009 - 21st Century Breakdown\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Gwen Stefani\Love.Angel.Music.Baby\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Hayley James Scott\Unknown album\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Hindi\Unknown album\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\House to Bring the House Down\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\House to Bring the House Down\Toned Down\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\James Blunt\Unknown album\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Jay Sean\All Or Nothing\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Jay Sean\My Own Way\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Jay-Z + Alicia Keys\Hot 100 Songs\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Jennifer Lopez\I’m Glad [Australia CD #2]\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Jeremih\Unknown album\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Jet\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Joan Baez\In Concert, Pt. 2\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Joe McElderry\Wide Awake 320@BSBT\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Joe Santriani\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\John Mayer\Battle Studies\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Joni Mitchell\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Josh Turner\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Journey\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Justin Timberlake\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Justin Timberlake\FutureSex LoveSounds\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Kanye West\Late Registration\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Kasabian\Club Foot\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Kasabian\Karyme Lozano\Ay, Ay, Ay - Canción de la Semana\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Kasabian\Kasabian\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Katy Perry\California Gurls [Single]\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Katy Perry feat. HYPER CRUSH\Unknown album\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Ke$ha\Animal\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Keane\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Kevin Lyttle\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Kevin Rudolf\To the Sky\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Killing Joke\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Kings of Leon\Radioactive - Single\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Korn\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Labrinth\Let The Sun Shine\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Lady Antebellum\Lady Antebellum\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Lady Antebellum\Need You Now\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Lady GaGa\The Fame\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Lady GaGa\The Fame Monster\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Led Zeppelin\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Lee Ann Womack\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Lee Kernaghan\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Lenny Kravitz\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Lifehouse\No Name Face\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Lighthouse Family\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Lindsay Lohan\A Little More Personal (RAW)\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Lindsay Lohan\Speak\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Linkin Park\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Linkin Park\Minutes to Midnight\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Linkin Park Ft Jay-Z\Gold Hits\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Lloyd & Young Money\Bedrock\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Lost prophets\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Lost prophets\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Madonna feat. Justin Timberlake\Unknown album\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Marilyn Manson\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Marilyn Manson\Antichrist Superstar\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Maroon 5\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Metallica\St Anger\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Metro Station\Metro Station\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Michael Jackson\Dangerous - Special Edition\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Michael Jackson\DARYLO EDIT\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Michael Jackson\History - Past, Present And Future - Book I\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Michael Jackson\Thriller (25th Anniversary Edition)\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Mike Posner\31 Minutes to Takeoff\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\MixFiend.com MixtapeTorrent.com\Bonnie & Clyde\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Moby\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Moby\Hotel\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Moby\Nokia N91 Reclame\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Mohombi\Bumpy Ride\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Muse\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Muse\The Resistance\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Muse\The Twilight Saga New Moon\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\muzicxl.blogspot.com\Action Replayy (2010) (muzicxl.blogspot.com)\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\My Chemical Romance\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Neeraj Shridhar, Sunidhi Chauhan\Love Aaj Kal\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Nelly\5.0\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Nelly Furtado\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Neon Trees\Habits\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Neverending White Lights\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Neverending White Lights\Act I - Goodbye Friends of the Heavenly Bodies\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Nickelback\For All The Right Reasons\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Nicole Scherzinger\Don’t Hold Your Breath - Single\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Oasis\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Oasis\Unknown album\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Ottis Redding\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\P!nk\Greatest Hits… So Far!!!\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\P!nk\Greatest Hits…So Far!!!\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Panic! At the Disco\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Paramore\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Paul Van Dyk\Reflections\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Plain White Ts\Hey There Delilah EP\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Playlists\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Qambrani TiGerZ\Best Of Best Songs\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Rahat Fateh Ali Khan & Shreya Ghoshal\Bodyguard\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Ram Sampath\Delhi Belly\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Regina Spektor\Live in London Disc 2\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Remix-Nation.com\Remix-Nation.com\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Rihanna\Godsup-¤À¨ÉYoU.49öt¼Öºô\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Rihanna\Good Girl Gone Bad\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Rihanna\Good Girl Gone Bad [Reloaded]\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Rihanna\Rated R\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Secondhand Serenade\Spunk’s TOP 200\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Shakira\Unknown album\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Shankar Ehsaan Loy\My Name Is Khan\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Snow Patrol\Spider-Man 3\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Stevie Wonder\Unknown album\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Stromae\Unknown album\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Switchfoot\Unknown album\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Tashan\Tashan @ Fmw11.com\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Taylor Swift\Fearless\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\The Eminem Show\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\The Eminem Show\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Timbaland\Presents Shock Value\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Travis\BBC Radio 1 Live Lounge\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Trey Songz\Hiphopearly.com\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Unknown artist\Enrique\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Unknown artist\Fashion\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Unknown artist\Loser-3doorsdown\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Unknown artist\Unknown album\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Unknown artist\Unknown album\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Usher\HotNewHipHop.com\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Usher\NewJams.net\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\VA\Best Of Dance 1-2009 CDM\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Various Artists\Now 71 [UK Series]\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Various Artists\Pure ‘80s #1s\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\WILL SMITH\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Willie Clayton\No Getting over Me\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Wiz Khalifa\Black and Yellow - Single\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Wiz Khalifa - No Sleep (Gianni Marino Remix) _(musiclife.kz)\Musiclife.kz - Скачать музыку, mp3, песни бесплатно!\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music[www.DJMaza.Com\Dharti](‘djmaza.com’) (2011)\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music[www.DJMaza.Com\Golmaal](‘djmaza.com’) 3 [[\n7p_art\Readme-Matrix.rtf"]www.DJMaza.Com]\n7p_art\Readme-Matrix.rtf](http://www.djmaza.com) Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music[www.djrobsonmichel.com\Dj](‘http://www.djrobsonmichel.com/Dj’) Robson Michel - In The Mix\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music[www.Extreemsongs.com\7](‘http://www.extreemsongs.com/7’) Khoon Maaf (2011) [[\n7p_art\Readme-Matrix.rtf"]www.Extreemsongs.com]\n7p_art\Readme-Matrix.rtf](http://www.extreemsongs.com) Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music[www.Extreemsongs.com\Tanu](‘http://www.extreemsongs.com/Tanu’) Weds Manu (2011) [[\n7p_art\Readme-Matrix.rtf"]www.Extreemsongs.com]\n7p_art\Readme-Matrix.rtf](http://www.extreemsongs.com) Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music[www.Marvin-Vibez.in\Free](‘http://www.marvin-vibez.in/Free’) Wired\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music[www.Songs.PK\Da](‘http://www.songs.pk/Da’) Rap Star\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music[www.Songs.PK\Dum](‘http://www.songs.pk/Dum’) Maaro Dum\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music[www.Songs.PK\F.A.L.T.U\n7p_art\Readme-Matrix.rtf](‘http://www.songs.pk/F.A.L.T.U/n7p_art/Readme-Matrix.rtf’) Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music[www.Songs.PK\Force\n7p_art\Readme-Matrix.rtf](‘http://www.songs.pk/Force/n7p_art/Readme-Matrix.rtf’) Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music[www.Songs.PK\Jihne](‘http://www.songs.pk/Jihne’) Mera Dil Luteya\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music[www.Songs.PK\Party](‘http://www.songs.pk/Party’) Animal’s Vol.2\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music[www.Songs.PK\ROMEO](‘http://www.songs.pk/ROMEO’) JAZZY B\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music[www.Songs.PK\Shaitan\n7p_art\Readme-Matrix.rtf](‘http://www.songs.pk/Shaitan/n7p_art/Readme-Matrix.rtf’) Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music[www.SongsLover.com\Single](‘http://www.songslover.com/Single’) Track\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music[www.SongsLover.pk\Best](‘http://www.songslover.pk/Best’) Of December 2012\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music[www.SongsLover.pk\Best](‘http://www.songslover.pk/Best’) Of November 2012\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music[www.SongsLover.pk\Best](‘http://www.songslover.pk/Best’) Of October SongsLover.pk\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music[www.SongsLover.pk\Step](‘http://www.songslover.pk/Step’) Up Revolution (Music from the Motion Picture)\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music[www.SongsLover.pk\Top](‘http://www.songslover.pk/Top’) 100 SongsLover.pk 2012\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music[www.VibeDesi.com\Imran](‘VibeDesi.com is for sale | HugeDomains’) Khan - Unforgettable - The Album (www.VibeDesi.com)\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music\Zindagi Na Milegi Dobara\Zindagi Na Milegi Dobara\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music{Rodrigo Music}\Unknown album\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Music{www.LatestZone.Net}\Wake Up Sid\n7p_art\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive.picasaoriginals\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\astrophysics\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\astrophysics\clelestial sphere\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\astrophysics\hr diagram\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\astrophysics\luminosity and mass relation\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\astrophysics\measure distance by parallax methoc\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\astrophysics\stellar spectra\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\astrophysics\stellar spectra\order of magnitude\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\astrophysics\types of stars\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Avatar\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Avatar\Common App\D\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Avatar\Supplements\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Avatar\Supplements\Amherst\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Avatar\Supplements\Brown\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Avatar\Supplements\Carnegie Mellon\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Avatar\Supplements\Columbia\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Avatar\Supplements\Dartmouth\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Avatar\Supplements\Duke\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Avatar\Supplements\Harvard\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Avatar\Supplements\Jonhs Hopkins\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Avatar\Supplements\Jonhs Hopkins\Grammarly_files\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Avatar\Supplements\Minessota\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Avatar\Supplements\Princeton\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Avatar\Supplements\Stanford\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Avatar\Supplements\UChicago\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Avatar\Supplements\UPenn\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Avatar\Supplements\Yale\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Avatar\Supplements 2.0\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Background Guides\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Background Guides\DISEC\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\icons\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jdk1.7.0_15\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jdk1.7.0_15\db\lib\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jdk1.7.0_15\include\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jdk1.7.0_15\include\win32\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jdk1.7.0_15\include\win32\bridge \Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jdk1.7.0_15\jre\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jdk1.7.0_15\jre\bin\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jdk1.7.0_15\jre\bin\server\Readm e-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jdk1.7.0_15\jre\lib\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jdk1.7.0_15\jre\lib\cmm\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jdk1.7.0_15\jre\lib\deploy\Readm e-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jdk1.7.0_15\jre\lib\ext\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jdk1.7.0_15\jre\lib\images\curso rs\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jdk1.7.0_15\jre\lib\management\R eadme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jdk1.7.0_15\jre\lib\security\Rea dme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jdk1.7.0_15\jre\lib\servicetag\R eadme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jdk1.7.0_15\lib\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jdk1.7.0_15\lib\visualvm\etc\Rea dme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jdk1.7.0_15\lib\visualvm\platfor m\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jdk1.7.0_15\lib\visualvm\platfor m\core\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jdk1.7.0_15\lib\visualvm\platfor m\core\locale\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jdk1.7.0_15\lib\visualvm\platfor m\lib\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jdk1.7.0_15\lib\visualvm\platfor m\lib\locale\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jdk1.7.0_15\lib\visualvm\platfor m\modules\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jdk1.7.0_15\lib\visualvm\platfor m\modules\ext\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jdk1.7.0_15\lib\visualvm\platfor m\modules\ext\locale\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jdk1.7.0_15\lib\visualvm\platfor m\modules\locale\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jdk1.7.0_15\lib\visualvm\profile r\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jdk1.7.0_15\lib\visualvm\profile r\lib\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jdk1.7.0_15\lib\visualvm\profile r\lib\locale\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jdk1.7.0_15\lib\visualvm\profile r\modules\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jdk1.7.0_15\lib\visualvm\profile r\modules\locale\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jdk1.7.0_15\lib\visualvm\visualv m\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jdk1.7.0_15\lib\visualvm\visualv m\config\Modules\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jdk1.7.0_15\lib\visualvm\visualv m\core\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jdk1.7.0_15\lib\visualvm\visualv m\core\locale\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jdk1.7.0_15\lib\visualvm\visualv m\modules\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jdk1.7.0_15\lib\visualvm\visualv m\modules\locale\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jre7\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jre7\bin\server\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jre7\icons\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jre7\jdk1.7.0_15\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jre7\jdk1.7.0_15\jre\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jre7\jdk1.7.0_15\jre\lib\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jre7\jdk1.7.0_15\lib\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jre7\jdk1.7.0_15\lib\visualvm\et c\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jre7\jdk1.7.0_15\lib\visualvm\pl atform\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jre7\jdk1.7.0_15\lib\visualvm\pl atform\core\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jre7\jdk1.7.0_15\lib\visualvm\pl atform\core\locale\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jre7\jdk1.7.0_15\lib\visualvm\pl atform\lib\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jre7\jdk1.7.0_15\lib\visualvm\pl atform\lib\locale\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jre7\jdk1.7.0_15\lib\visualvm\pl atform\modules\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jre7\jdk1.7.0_15\lib\visualvm\pl atform\modules\ext\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jre7\jdk1.7.0_15\lib\visualvm\pl atform\modules\ext\locale\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jre7\jdk1.7.0_15\lib\visualvm\pl atform\modules\locale\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jre7\jdk1.7.0_15\lib\visualvm\pr ofiler\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jre7\jdk1.7.0_15\lib\visualvm\pr ofiler\lib\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jre7\jdk1.7.0_15\lib\visualvm\pr ofiler\lib\locale\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jre7\jdk1.7.0_15\lib\visualvm\pr ofiler\modules\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jre7\jdk1.7.0_15\lib\visualvm\pr ofiler\modules\locale\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jre7\jdk1.7.0_15\lib\visualvm\vi sualvm\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jre7\jdk1.7.0_15\lib\visualvm\vi sualvm\config\Modules\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jre7\jdk1.7.0_15\lib\visualvm\vi sualvm\core\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jre7\jdk1.7.0_15\lib\visualvm\vi sualvm\core\locale\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jre7\jdk1.7.0_15\lib\visualvm\vi sualvm\modules\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jre7\jdk1.7.0_15\lib\visualvm\vi sualvm\modules\locale\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jre7\lib\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jre7\lib\cmm\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jre7\lib\deploy\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jre7\lib\ext\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jre7\lib\images\cursors\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jre7\lib\management\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jre7\lib\security\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\jre7\lib\servicetag\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\afrikaans\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\afrikaans\templates\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\afrikaans\templates\newclass \Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\catalan\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\catalan\templates\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\catalan\templates\newclass\R eadme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\chinese\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\chinese\templates\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\chinese\templates\newclass\R eadme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\czech\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\czech\templates\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\czech\templates\newclass\Rea dme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\danish\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\danish\templates\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\danish\templates\newclass\Re adme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\dutch\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\dutch\templates\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\dutch\templates\newclass\Rea dme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\english\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\english\templates\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\english\templates\newclass\R eadme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\extensions\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\french\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\french\templates\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\french\templates\newclass\Re adme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\german\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\german\templates\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\german\templates\newclass\Re adme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\greek\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\greek\templates\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\greek\templates\newclass\Rea dme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\images\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\italian\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\italian\templates\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\italian\templates\newclass\R eadme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\japanese\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\japanese\templates\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\japanese\templates\newclass\ Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\korean\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\korean\templates\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\korean\templates\newclass\Re adme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\portuguese\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\portuguese\templates\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\portuguese\templates\newclas s\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\russian\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\russian\templates\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\russian\templates\newclass\R eadme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\slovak\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\slovak\templates\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\slovak\templates\newclass\Re adme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\spanish\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\spanish\templates\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\spanish\templates\newclass\R eadme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\swedish\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\swedish\templates\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\swedish\templates\newclass\R eadme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\BlueJ\lib\userlib\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Books\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Books\NCERT\NCERT CHEMISTRY\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Books\NCERT\NCERT MATHEMATICS\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Books\NCERT\NCERT PHYSICS\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\CALCULUS Single Variable Robert Ghrist Course\Comp Papers\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\CALCULUS Single Variable Robert Ghrist Course\Comp Papers\2001\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\CALCULUS Single Variable Robert Ghrist Course\Comp Papers\2002\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\CALCULUS Single Variable Robert Ghrist Course\Comp Papers\2005\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\CALCULUS Single Variable Robert Ghrist Course\Comp Papers\2007\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\CALCULUS Single Variable Robert Ghrist Course\Comp Papers\2009\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\CALCULUS Single Variable Robert Ghrist Course\Comp Papers\2010\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\CALCULUS Single Variable Robert Ghrist Course\Comp Papers\Computer Science HL & SL\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\CALCULUS Single Variable Robert Ghrist Course\Exams\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\CALCULUS Single Variable Robert Ghrist Course\HW\01 Functions\challenge\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\CALCULUS Single Variable Robert Ghrist Course\HW\01 Functions\core\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\CALCULUS Single Variable Robert Ghrist Course\HW\02 Differentiation\core\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\CALCULUS Single Variable Robert Ghrist Course\VIDEOS\01 Functions\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\CALCULUS Single Variable Robert Ghrist Course\VIDEOS\02 Differentiation\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\CALCULUS Single Variable Robert Ghrist Course\VIDEOS\03 Integration\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\CALCULUS Single Variable Robert Ghrist Course\VIDEOS\04 Applications\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\CALCULUS Single Variable Robert Ghrist Course\VIDEOS\05 Discretization\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\CAS REF\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\CyberLink\LocalStorage_V2\DefaultMembe r\Misc\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\CyberLink\LocalStorage_V2\DefaultMembe r\Movie_00370C00-0002-0002-CAA3-2CF3D3CFE77A\Disc_00370C00-0002-0002-CAA3-2CF3D3CFE77A\Info\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\CyberLink\LocalStorage_V2\LocalData\Di sc_00370C00-0002-0002-CAA3-2CF3D3CFE77A\Chapter\Title00\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\CyberLink\LocalStorage_V2\Misc\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\CyberLink\PowerDVD12\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Documents\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Documents\New folder\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Documents\Python Programmes\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\FIFA 09 Demo\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\hp.system.package.metadata\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\i look like nikunj\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\ACT\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\ACT\ACT Admission Ticket_files\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Adele\25\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Avicii\X You (Vocal Radio Edit) [feat. Wailin’]\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Coldplay\A Rush Of Blood To The Head\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Coldplay\Mylo Xyloto\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Coldplay\X & Y\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Comp\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Comp\IA\DRAFT\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Comp\New folder\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Comp\New folder\Computer science Solution cover page_files\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Comp\New folder\Documentation\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Comp\New folder\Product\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Comp\New folder\Product\doc\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Comp\Notes\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\David Guetta\Baby When the Light - Single\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\David Guetta\Delirious (feat. Tara McDonald)\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\David Guetta\**** Me I’m Famous\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\David Guetta\**** Me I’m Famous Vol. 2\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\David Guetta\Gettin’ Over You (feat. Fergie & LMFAO)\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\David Guetta\Guetta Blaster\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\David Guetta\I Wanna Go Crazy (feat. will.i.am) - Sin\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\David Guetta\In Love with Myself - Single\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\David Guetta\Just A Little More Love\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\David Guetta\Love Is Gone - Single\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\David Guetta\Nothing But the Beat\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\David Guetta\One Love\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\David Guetta\Pop Life\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\David Guetta\Sexy ***** (feat. Akon) - Single\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\David Guetta\Tomorrow Can Wait - Single\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Drake\Views\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Eco\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Eco\Book\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Eco\IA\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Eco\Report finds ‘historic’ share of adults in Oregon don’t have jobs - News - MailTribune.com - Medford, OR_files\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Eco\‘Students have certificates but not the required skills’ - The Hindu_files\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\English\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\English\aUDEN\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\English\Heaney\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\English\IOC\Historical Context-(1 min)\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\English\IOC\Keats\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\English\IOC\Macbeth\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\English\World Lit Essay\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\English\World Lit Essay\Drafts\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\English\World Lit Essay\Ideas\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\English\World Lit Essay\Reflective Statement\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\English\World Lit Essay\Refrences\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\exploration samples\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\exploration samples\Explorations Samples from TSM\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\exploration samples\ISB Journal of Science\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Extended Essay\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\French\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\French\May 2011\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\French\May 2012\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\French\May 2013\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\French\May 2014\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\French\May 2015\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\French\Nov 2011\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\French\Nov 2012\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\French\Nov 2013\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\French\Nov 2014\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\French\Nov 2015\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\French\Pictures\New folder\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\French\Pictures\New folder (2)\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\French\Question Papers\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\French\Question Papers\PAPER 2\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\IB\Comp\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\IB\English\World Lit Essay\Drafts\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Lana Del Rey\Blue Jeans (Remixes) - EP\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Lana Del Rey\Born to Die (Deluxe Version)\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Lana Del Rey\Born to Die (Remixes) - EP\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Lana Del Rey\Honeymoon\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Lana Del Rey\National Anthem (Remixes) - EP\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Lana Del Rey\Paradise\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Lana Del Rey\Ride (Remixes) - EP\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Lana Del Rey\Ultraviolence (Deluxe)\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Lana Del Rey\Video Games Remixes - EP\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Lana Del Rey\West Coast (Radio Mix) - Single\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math FL\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math FL\Discrete\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math FL\Pearson Textbooks\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math FL\Pearson Textbooks\FL Maths Exam Papers\May 01\Exams\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math FL\Pearson Textbooks\FL Maths Exam Papers\May 01\Markschemes\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math FL\Pearson Textbooks\FL Maths Exam Papers\May 02\Exams\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math FL\Pearson Textbooks\FL Maths Exam Papers\May 02\Markschemes\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math FL\Pearson Textbooks\FL Maths Exam Papers\May 03\Exams\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math FL\Pearson Textbooks\FL Maths Exam Papers\May 03\Markschemes\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math FL\Pearson Textbooks\FL Maths Exam Papers\May 04\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math FL\Pearson Textbooks\FL Maths Exam Papers\May 05\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math FL\Pearson Textbooks\FL Maths Exam Papers\May 06\Exams\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math FL\Pearson Textbooks\FL Maths Exam Papers\May 06\Markschemes\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math FL\Pearson Textbooks\FL Maths Exam Papers\May 07\Exams\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math FL\Pearson Textbooks\FL Maths Exam Papers\May 07\Markschemes\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math FL\Pearson Textbooks\FL Maths Exam Papers\May 08\Exams\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math FL\Pearson Textbooks\FL Maths Exam Papers\May 08\Markschemes\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math FL\Pearson Textbooks\FL Maths Exam Papers\May 09\Exams\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math FL\Pearson Textbooks\FL Maths Exam Papers\May 09\Markschemes\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math FL\Pearson Textbooks\FL Maths Exam Papers\May 10\Exams\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math FL\Pearson Textbooks\FL Maths Exam Papers\May 10\Markschemes\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math FL\Pearson Textbooks\FL Maths Exam Papers\May 11\Exams\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math FL\Pearson Textbooks\FL Maths Exam Papers\May 11\Markschemes\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math FL\Pearson Textbooks\FL Maths Exam Papers\May 12\Exams\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math FL\Pearson Textbooks\FL Maths Exam Papers\May 12\Markschemes\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math FL\Pearson Textbooks\FL Maths Exam Papers\May 13\Exams\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math FL\Pearson Textbooks\FL Maths Exam Papers\May 13\Markschemes\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math FL\Pearson Textbooks\FL Maths Exam Papers\May 14\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math FL\Pearson Textbooks\FL Maths Exam Papers\May 15\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math HL\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math HL\Math IA\DRAFTS\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math HL\Math IA\INFO\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math HL\Shrey Past Paper\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math HL\Shrey Past Paper\2007\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math HL\Shrey Past Paper\2008\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math HL\Shrey Past Paper\2008\May 2008\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math HL\Shrey Past Paper\2008\Nov 2008\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math HL\Shrey Past Paper\2009\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math HL\Shrey Past Paper\2009\Math HL May 09\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math HL\Shrey Past Paper\2009\Math HL Nov 09\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math HL\Shrey Past Paper\2010\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math HL\Shrey Past Paper\2010\Math HL May 10\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math HL\Shrey Past Paper\2010\Math HL Nov 10\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math HL\Shrey Past Paper\2011\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math HL\Shrey Past Paper\2011\Math HL May 11\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math HL\Shrey Past Paper\2011\Math HL November 11\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math HL\Shrey Past Paper\2012\Math HL May 12\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math HL\Shrey Past Paper\2012\Math HL Nov 12\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math HL\Shrey Past Paper\2013\MATH HL May 13\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math HL\Shrey Past Paper\2013\Math HL Nov 13\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math HL\Shrey Past Paper\2014\2014 Math HL Papers\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Math HL\Shrey Past Paper\2014\Math HL May 2014\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\oxford\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\papers\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\papers\2007\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\papers\2008\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\papers\2008\May 2008\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\papers\2008\Nov 2008\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\papers\2009\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\papers\2009\Math HL May 09\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\papers\2009\Math HL Nov 09\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\papers\2010\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\papers\2010\Math HL May 10\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\papers\2010\Math HL Nov 10\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\papers\2011\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\papers\2011\Math HL May 11\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\papers\2011\Math HL November 11\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\papers\2012\Math HL May 12\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\papers\2012\Math HL Nov 12\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\papers\2013\MATH HL May 13\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\papers\2013\Math HL Nov 13\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\papers\2014\2014 Math HL Papers\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\papers\2014\Math HL May 2014\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\papers\2015\May\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\papers\2015\Nov\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Physics\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Physics\Exploration\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Physics\PAPER-3\2014 May\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Physics\PAPER-3\2014 Nov\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Physics\PAPER-3\May 2012\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Physics\PAPER-3\May 2013\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Physics\PAPER-3\May 2015\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Physics\PAPER-3\Nov 2012\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Physics\PAPER-3\Nov 2013\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Physics\PAPERS\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Physics\PAPERS\Test Week Question Bank\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Physics\Practicals\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Physics\Practicals\Material Regarding Practicals\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Physics\Practicals\Shrey Labs\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Physics\Practicals\Shrey Labs\Physics Practicals\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Physics\TSOKOS BOOK+ Options\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\Predestination\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB\TOK\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Banks\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Banks\Chemistry\Chemistry Question Bank_Third Edition\PDFs\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Banks\Chemistry\PDFs\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Banks\Mathematics\PDFs\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Banks\Mathematics\PDFs\INFO\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Banks\Physics\PDFs\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Papers\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Papers\May 2007\HL\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Papers\May 2007\SL\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Papers\May 2008\HL\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Papers\May 2008\SL\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Papers\May 2009\HL\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Papers\May 2009\SL\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Papers\May 2010\HL\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Papers\May 2010\SL\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Papers\May 2011\HL\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Papers\May 2011\SL\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Papers\May 2012\HL\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Papers\May 2012\SL\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Papers\May 2013\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Papers\May 2014\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Papers\Nov 2007\HL\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Papers\Nov 2007\SL\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Papers\Nov 2008\HL\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Papers\Nov 2008\SL\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Papers\Nov 2009\HL\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Papers\Nov 2009\SL\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Papers\Nov 2010\ECONOMICS HL\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Papers\Nov 2010\ECONOMICS SL\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Papers\Nov 2011\HL\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Papers\Nov 2011\SL\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Papers\Nov 2012\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Papers\Nov 2012\HL\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Papers\Nov 2012\SL\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Papers\Nov 2013\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Papers\Nov 2013\ECONOMICS HL\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Papers\Nov 2013\ECONOMICS SL\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Papers\PAPER-3\May 2015\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Papers\PAPER-3\May-2013\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Papers\PAPER-3\May-2014\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Papers\PAPER-3\Nov-2013\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Papers\PAPER-3\Nov-2014\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\IB Question Papers\PAPER-3\Nov-2015\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Laksh\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Laksh\Infinity\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Laksh\Ms Office-2007\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Laksh\Ms Office-2007\Admin\de-de\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Laksh\Ms Office-2007\Admin\en-us\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Laksh\Ms Office-2007\Admin\es-es\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Laksh\Ms Office-2007\Admin\fr-fr\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Laksh\Ms Office-2007\Admin\it-it\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Laksh\Ms Office-2007\Admin\ja-jp\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Laksh\Ms Office-2007\Admin\ko-kr\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Laksh\Ms Office-2007\Admin\zh-cn\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Laksh\Ms Office-2007\Admin\zh-tw\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Laksh\Ms Office-2007\Catalog\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Laksh\Ms Office-2007\Colour folder\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Laksh\Ms Office-2007\comands\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Laksh\Ms Office-2007\DeskHedron\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Laksh\Ms Office-2007\Enterprise.WW\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Laksh\Ms Office-2007\Groove.en-us\Groove.en-us\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Laksh\Ms Office-2007\Office.en-us\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Laksh\Ms Office-2007\Recover My Files 3.98 Build 5178 + serial\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Laksh\Ms Office-2007\Recover My Files 3.98 Build 5178 + serial\More Downloads & Additional Resources\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Laksh\Ms Office-2007\Updates\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Papers\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Physics Exploration\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Physics Exploration\Final Experiment\Humidity\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Physics Exploration\Final Experiment\Velocity vs Distance\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Pictures\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Pictures\Camera Roll\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Practise\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Practise\shrey\Dead Poets Society\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Refrence Research Papers\Cooling Paper Drafts\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Refrence Research Papers\Cooling Paper Drafts\data\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Refrence Research Papers\Graph Theory\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Refrence Research Papers\Number Theory Problem 1\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\Refrence Research Papers\Snooker Problem\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\SAT\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\SAT\Predestination\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\SAT\Predestination\predestination-english-yify-30785\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\SAT\shrey\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\SAT\shrey\Actual Sat\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\SAT\shrey\Books With Tests\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\SAT\shrey\College Board Tests\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\SAT\shrey\SAT Reading\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\SAT\shrey\Vocab\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\World Lit Essay\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\World Lit Essay\Drafts\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\World Lit Essay\Ideas\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive\World Lit Essay\Refrences\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive__MACOSX\Background Guides\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\OneDrive__MACOSX\Background Guides\DISEC\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Pictures\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Pictures\Physics expo\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Pictures\Picasa\Screen Captures\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Pictures\Screenshots\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Searches\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Tracing\WPPMedia\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\HP-PC\Videos\Movavi Screen Capture Studio\Projects\ScreenCaptureProject1.mscproj\Read me-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\Public\Documents\CyberLink\CLFaceLogin\Re adme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\Public\Libraries\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\shrey\Downloads\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          C:\Users\shrey\Searches\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          D:\preload\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          D:\preload\FactoryUpdate\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          D:\preload\FactoryUpdate\FU_6_125666_20140414_100A 1\STAGBIOS\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          D:\preload\FactoryUpdate\Part\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          D:\recovery\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          F:\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          F:\183-k\Desktop\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          F:\183-k\Desktop\bin\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          F:\183-k\Desktop\bin\server\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          F:\183-k\Desktop\lib\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          F:\183-k\Desktop\lib\cmm\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          F:\183-k\Desktop\lib\deploy\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          F:\183-k\Desktop\lib\ext\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          F:\183-k\Desktop\lib\images\cursors\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          F:\183-k\Desktop\lib\jfr\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          F:\183-k\Desktop\lib\management\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          F:\183-k\Desktop\lib\security\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          F:\183-k\Documents\hp.system.package.metadata\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          F:\183-k\Favorites\HP\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          F:\183-k\Searches\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted
          F:\ApowersoftRecorderTemp\Readme-Matrix.rtf Win32/Filecoder.NKD trojan deleted

          Comment

          • Shrey_Aryan
            PCHF Member
            • Mar 2017
            • 34

            #20
            I did the search for all files with the extension .matrix using the software you suggested and a .txt file containing all the files is uploaded. (Copying and Pasting always hung my computer so I did not do it).

            Comment

            • Malnutrition
              PCHF Moderator
              • Jul 2016
              • 7041

              #21
              Ok, I’d like to see the FRST fix Zemana log and ZHP log…

              Comment

              • Shrey_Aryan
                PCHF Member
                • Mar 2017
                • 34

                #22
                Zemana AntiMalware 2.72.2.176 (Installed)


                Scan Result : Completed
                Scan Date : 2017-3-20
                Operating System : Windows 8.1 64-bit
                Processor : 4X Intel(R) Core™ i3-4030U CPU @ 1.90GHz
                BIOS Mode : UEFI
                CUID : 12694D99C5D7B145AA10BE
                Scan Type : Custom Scan
                Duration : 146m 55s
                Scanned Objects : 441505
                Detected Objects : 0
                Excluded Objects : 0
                Read Level : Normal
                Auto Upload : Enabled
                Detect All Extensions : Disabled
                Scan Documents : Disabled
                Domain Info : WORKGROUP,0,2
                [HEADING=1]Detected Objects[/HEADING]
                No threats detected

                Comment

                • Shrey_Aryan
                  PCHF Member
                  • Mar 2017
                  • 34

                  #23
                  I ran ZHPDiag twice and each time I got the error:
                  [ATTACH]1863[/ATTACH]

                  What should I do??

                  Comment

                  • Malnutrition
                    PCHF Moderator
                    • Jul 2016
                    • 7041

                    #24
                    Originally posted by Shrey Aryan
                    What should I do??
                    Skip it, run the FRST fix post that log.

                    FRST Fix.

                    Click Here To Download Fixlist.


                    Download attached fixlist.txt file and save it to the Desktop. NOTE. It’s important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work. NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system Run FRST/FRST64 and press the Fix button just once and wait. If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run. When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

                    Comment

                    • Malnutrition
                      PCHF Moderator
                      • Jul 2016
                      • 7041

                      #25
                      If you have trouble running the FRST fix then run it in Safe Mode

                      You are also running FRST from the downloads folder. C:\Users\HP-PC\Downloads You need to run FRST and the fixlist from the desktop, in order for the fix to work.

                      Comment

                      • Shrey_Aryan
                        PCHF Member
                        • Mar 2017
                        • 34

                        #26
                        I am running FRST, but it seems to go on forever. And there is nothing appearing on the Search bar.

                        Comment

                        • Malnutrition
                          PCHF Moderator
                          • Jul 2016
                          • 7041

                          #27
                          Run it in Safe Mode, after you make sure that the fix list and FRST are on the desktop. Also, there is nothing supposed to be in the search bar you are supposed to right click it run as administrator then click Fix.

                          Comment

                          • Malnutrition
                            PCHF Moderator
                            • Jul 2016
                            • 7041

                            #28
                            Security Check Scan.

                            [ul]
                            [li]Download Security Check to your desktop.[/li][li]Right click it run as administrator.[/li][li]When the program completes, the tool will automatically open a log file.[/li][li]Please post that log here in your next post.[/li][/ul]

                            Adware Removal Tool Scan.

                            Download Adware removal tool to your desktop, right click the icon and select Run as Administrator.

                            [MEDIA=imgur]LOr0Gd7[/MEDIA]

                            Hit Ok.

                            [MEDIA=imgur]sYFsqHx[/MEDIA]

                            Hit next make sure to leave all items checked, for removal.

                            [MEDIA=imgur]8NcZjGc[/MEDIA]

                            The Program will close all open programs to complete the removal, so save any work and hit OK. Then hit OK after the removal process is complete, thenOK again to finish up. Post log generated by tool.

                            9-Lab Scan.

                            [ul]
                            [li]Download 9-Lab Removal Tool. [/li][li]CLICK HERE to determine whether you’re running 32-bit or 64-bit for Windows.[/li][li]Disable your antivirus prior to this scan.[/li]
                            [li]Install the program onto your computer, then right click the icon run as administrator.[/li][li]Update the program and then run a Full scan![/li][li]Make sure the program updates, might be better to install it update reboot and check for updates again.[/li][li]You need to make sure the database updates!!![/li][li]Upon Scan Completion Click on Show Results.[/li][li]Then Click On Clean[/li][li]Then Click on Save Log.[/li][li]Save it to your desktop, copy and paste the contents of the log here in your next reply.[/li][/ul]

                            Comment

                            • Shrey_Aryan
                              PCHF Member
                              • Mar 2017
                              • 34

                              #29
                              I have put the FRST and the fixlist files on the desktop and will be running them again.

                              Comment

                              • Shrey_Aryan
                                PCHF Member
                                • Mar 2017
                                • 34

                                #30

                                Fix result of Farbar Recovery Scan Tool (x64) Version: 15-03-2017
                                [/quote]

                                [HEADING=1]Ran by 183-k (20-03-2017 11:35:18) Run:5
                                Running from C:\Users\HP-PC\Desktop
                                Loaded Profiles: HP-PC & 183-k (Available Profiles: HP-PC & shrey & 183-k)
                                Boot Mode: Normal[/HEADING]
                                fixlist content:


                                Start
                                Closeprocesses:
                                CreateRestorePoint:
                                Emptytemp:
                                RemoveProxy:
                                HKLM-x32...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation)
                                HKU\S-1-5-21-1605944295-1278072363-3366277582-1001...\Run: [AZ3Tq5k16l3MBynp] => HKU\S-1-5-21-1605944295-1278072363-3366277582-1001...\Run: [AZ3Tq5k16l3MBynp] => C:\Users\HP-PC\AppData\Roaming\AZ3Tq5k16l3MBynp.hta [35119 2017-03-13] () [35119 2017-03-13] ()
                                C:\Users\HP-PC\AppData\Roaming\AZ3Tq5k16l3MBynp.hta
                                HKU\S-1-5-21-1605944295-1278072363-3366277582-1001...\Run: [GoogleChromeAutoLaunch_7F0416C691E452253BB89BC2BE6 D7727] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [941912 2017-03-09] (Google Inc.)
                                HKU\S-1-5-21-1605944295-1278072363-3366277582-1001...\RunOnce: [Application Restart #7] => C:\Users\HP-PC\AppData\Local\SweetLabs App Platform\Engine\ServiceHostApp.exe --disable-internal-flash --noerrdialogs --no-message-box --disable-extensions --disable-web-security --disable-web-resour (the data entry has 583 more characters).
                                HKU\S-1-5-21-1605944295-1278072363-3366277582-1001...\MountPoints2: {52f96c0f-4b14-11e6-82cb-020046a23e01} - “E:.\StartModem.exe”
                                HKU\S-1-5-21-1605944295-1278072363-3366277582-1001...\MountPoints2: {6d4daa1b-2812-11e4-8266-a02bb859a5c2} - “E:\AutoRun.exe”
                                HKU\S-1-5-21-1605944295-1278072363-3366277582-1001...\MountPoints2: {fddc09cc-da5b-11e3-825b-806e6f6e6963} - “E:\start.exe”
                                HKU\S-1-5-21-1605944295-1278072363-3366277582-1005...\Run: [Pokki] => C:\Windows\system32\rundll32.exe “%LOCALAPPDATA%\Pokki\Engine\Launcher.dll”,RunLaun chPlatform
                                C:\Users\HP-PC\AppData\Local\SweetLabs App Platform
                                ShortcutTarget: RescueTime.lnk → C:\Users\183-k\AppData\Local\RescueTime\RescueTime.exe (No File)
                                Winsock: Catalog5 08 C:\Windows\SysWOW64\wlidNSP.dll [50176 2014-10-29] (Microsoft Corporation)
                                Winsock: Catalog5 09 C:\Windows\SysWOW64\wlidNSP.dll [50176 2014-10-29] (Microsoft Corporation)
                                Winsock: Catalog5-x64 08 C:\Windows\system32\wlidnsp.dll [74240 2014-10-29] (Microsoft Corporation)
                                Winsock: Catalog5-x64 09 C:\Windows\system32\wlidnsp.dll [74240 2014-10-29] (Microsoft Corporation)
                                Tcpip\Parameters: [DhcpNameServer] 192.168.43.1
                                Tcpip..\Interfaces{346CCC8E-0B21-4061-9284-6EAA8587D1B6}: [DhcpNameServer] 192.168.43.1
                                Tcpip..\Interfaces{D8CDCD34-1927-4308-BFA6-CD78629C69FD}: [DhcpNameServer] 192.168.43.1
                                HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
                                HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
                                HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.jp.msn.com/HPALL14/26
                                HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.jp.msn.com/HPALL14/26
                                HKU\S-1-5-21-1605944295-1278072363-3366277582-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.jp.msn.com/HPALL14/26
                                HKU\S-1-5-21-1605944295-1278072363-3366277582-1005\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.jp.msn.com/HPALL14/26
                                SearchScopes: HKU\S-1-5-21-1605944295-1278072363-3366277582-1001 → {ED62CEEF-D711-461D-8D9E-9ACA3F0E3A2A} URL = hxxp://www.google.com/search?q={searchTerms}
                                BHO: Kaspersky Protection → {2E38825B-8815-42CF-9126-C58BC28D4591} → C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\x64\IEExt\ie_plugin.dll [2017-03-14] (AO Kaspersky Lab)
                                BHO: Java™ Plug-In SSV Helper → {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} → C:\Users\183-k\Desktop\bin\ssv.dll [2014-10-22] (Oracle Corporation)
                                BHO: avast! Online Security → {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} → C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-03-14] (AVAST Software)
                                BHO: Java™ Plug-In 2 SSV Helper → {DBC80044-A445-435b-BC74-9C25C1C588A9} → C:\Users\183-k\Desktop\bin\jp2ssv.dll [2014-10-22] (Oracle Corporation)
                                BHO: HP Network Check Helper → {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} → C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckP luginx64.dll [2013-08-28] (Hewlett-Packard)
                                BHO-x32: Kaspersky Protection → {2E38825B-8815-42CF-9126-C58BC28D4591} → C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\IEExt\ie_plugin.dll [2017-03-14] (AO Kaspersky Lab)
                                BHO-x32: Groove GFS Browser Helper → {72853161-30C5-4D22-B7F9-0BBC1D38A37E} → C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2006-10-27] (Microsoft Corporation)
                                BHO-x32: avast! Online Security → {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} → C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-03-14] (AVAST Software)
                                BHO-x32: Evernote extension → {92EF2EAD-A7CE-4424-B0DB-499CF856608E} → C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2014-03-04] (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
                                BHO-x32: HP Network Check Helper → {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} → C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckP lugin.dll [2013-08-28] (Hewlett-Packard)
                                Toolbar: HKLM - Kaspersky Protection Toolbar - {093F479D-712E-46CD-9E06-62E734A05F68} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\x64\IEExt\ie_plugin.dll [2017-03-14] (AO Kaspersky Lab)
                                Toolbar: HKLM-x32 - Kaspersky Protection Toolbar - {093F479D-712E-46CD-9E06-62E734A05F68} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\IEExt\ie_plugin.dll [2017-03-14] (AO Kaspersky Lab)
                                FF ProfilePath: C:\Users\183-k\AppData\Roaming\Profiles\iyrqfjx7.default [not found]
                                FF DefaultSearchEngine: Mozilla\Firefox\Profiles\yt5wm08v.default → Bing
                                FF SelectedSearchEngine: Mozilla\Firefox\Profiles\yt5wm08v.default → Bing
                                FF SearchEngineOrder.3: Mozilla\Firefox\Profiles\yt5wm08v.default → Bing
                                FF Keyword.URL: Mozilla\Firefox\Profiles\yt5wm08v.default → hxxp://www.bing.com/search?FORM=UP22DF&PC=UP22&q=
                                FF Homepage: Mozilla\Firefox\Profiles\yt5wm08v.default → hxxp://www.msn.com/?pc=UP22&ocid=UP22DHP&osmkt=en-in
                                FF SearchPlugin: C:\Users\183-k\AppData\Roaming\Mozilla\Firefox\Profiles\yt5wm08 v.default\searchplugins\bingp.xml [2016-02-07]
                                FF HKLM...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF => not found
                                FF HKLM...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF => not found
                                FF HKLM-x32...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF => not found
                                FF HKLM-x32...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF => not found
                                FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\answers.xml [2009-12-22]
                                FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\creativecommons.xml [2009-12-22]
                                U3 aswbdisk; no ImagePath
                                S3 mdareDriver_48; ??\C:\Program Files (x86)\Fortinet\FortiClient\mdare64_48.sys
                                S3 mdareDriver_52; ??\C:\Program Files (x86)\Fortinet\FortiClient\mdare64_52.sys
                                S3 mdareDriver_53; ??\C:\Program Files (x86)\Fortinet\FortiClient\mdare64_53.sys
                                S3 mdareDriver_60; ??\C:\Program Files (x86)\Fortinet\FortiClient\mdare64_60.sys
                                S3 mdareDriver_61; ??\C:\Program Files (x86)\Fortinet\FortiClient\mdare64_61.sys
                                S3 mdareDriver_62; ??\C:\Program Files (x86)\Fortinet\FortiClient\mdare64_62.sys
                                U3 aswMBR; ??\C:\Users\183-k\AppData\Local\Temp\aswMBR.sys <==== ATTENTION
                                2017-03-14 12:29 - 2017-03-15 00:40 - 00000000 ____D C:\Users\183-k\AppData\Roaming\Enigma Software Group
                                2017-03-14 12:29 - 2017-03-15 00:40 - 00000000 ____D C:\Program Files\Enigma Software Group
                                2017-03-14 12:29 - 2017-03-14 12:29 - 00000000 ____D C:\sh4ldr
                                2017-03-14 01:02 - 2017-03-19 11:47 - 00003096 _____ C:\Windows\System32\Tasks\BDAntiCryptoWallTask
                                2017-03-14 00:58 - 2017-03-14 00:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BDAntiRansomware
                                2017-03-14 00:58 - 2017-03-14 00:58 - 00000000 ____D C:\Program Files\Bitdefender
                                2017-03-13 15:41 - 2017-03-13 15:41 - 00035119 _____ C:\Users\HP-PC\AppData\Roaming\AZ3Tq5k16l3MBynp.hta
                                2017-03-13 15:41 - 2017-03-13 15:41 - 00017624 _____ C:\Users\HP-PC\AppData\Roaming\errlog.txt
                                2017-03-13 15:41 - 2017-03-13 15:41 - 00000000 _____ C:\Users\HP-PC\AppData\Roaming\AZ3Tq5k16l3MBynp.afn
                                2017-03-13 14:33 - 2017-03-13 14:33 - 00000000 _____ C:\Users\HP-PC\AppData\Roaming\AZ3Tq5k16l3MBynp.ast
                                C:\Users\HP-PC\AppData\Roaming\AZ3Tq5k16l3MBynp
                                CustomCLSID: HKU\S-1-5-21-1605944295-1278072363-3366277582-1001_Classes\CLSID{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 → C:\Users\HP-PC\AppData\Local\Google\Update\1.3.25.5\psuser_64. dll => No File
                                CustomCLSID: HKU\S-1-5-21-1605944295-1278072363-3366277582-1001_Classes\CLSID{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 → C:\Users\HP-PC\AppData\Local\Google\Update\1.3.27.5\psuser_64. dll => No File
                                CustomCLSID: HKU\S-1-5-21-1605944295-1278072363-3366277582-1001_Classes\CLSID{590C4387-5EBD-4D46-8A84-CD0BA2EF2856}\InprocServer32 → C:\Users\HP-PC\AppData\Local\Google\Update\1.3.30.3\psuser_64. dll => No File
                                CustomCLSID: HKU\S-1-5-21-1605944295-1278072363-3366277582-1001_Classes\CLSID{59B55F04-DE14-4BB8-92FF-C4A22EF2E5F4}\InprocServer32 → C:\Users\HP-PC\AppData\Local\Google\Update\1.3.31.5\psuser_64. dll => No File
                                CustomCLSID: HKU\S-1-5-21-1605944295-1278072363-3366277582-1001_Classes\CLSID{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 → C:\Users\HP-PC\AppData\Local\Google\Update\1.3.28.1\psuser_64. dll => No File
                                CustomCLSID: HKU\S-1-5-21-1605944295-1278072363-3366277582-1001_Classes\CLSID{78550997-5DEF-4A8A-BAF9-D5774E87AC98}\InprocServer32 → C:\Users\HP-PC\AppData\Local\Google\Update\1.3.28.13\psuser_64 .dll => No File
                                CustomCLSID: HKU\S-1-5-21-1605944295-1278072363-3366277582-1001_Classes\CLSID{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 → C:\Users\HP-PC\AppData\Local\Google\Update\1.3.29.5\psuser_64. dll => No File
                                CustomCLSID: HKU\S-1-5-21-1605944295-1278072363-3366277582-1001_Classes\CLSID{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 → C:\Users\HP-PC\AppData\Local\Google\Update\1.3.24.15\psuser_64 .dll => No File
                                CustomCLSID: HKU\S-1-5-21-1605944295-1278072363-3366277582-1001_Classes\CLSID{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 → C:\Users\HP-PC\AppData\Local\Google\Update\1.3.26.9\psuser_64. dll => No File
                                CustomCLSID: HKU\S-1-5-21-1605944295-1278072363-3366277582-1001_Classes\CLSID{CC182BE1-84CE-4A57-B85C-FD4BBDF78CB2}\InprocServer32 → C:\Users\HP-PC\AppData\Local\Google\Update\1.3.29.1\psuser_64. dll => No File
                                CustomCLSID: HKU\S-1-5-21-1605944295-1278072363-3366277582-1001_Classes\CLSID{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 → C:\Users\HP-PC\AppData\Local\Google\Update\1.3.25.11\psuser_64 .dll => No File
                                CustomCLSID: HKU\S-1-5-21-1605944295-1278072363-3366277582-1001_Classes\CLSID{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 → C:\Users\HP-PC\AppData\Local\Google\Update\1.3.28.15\psuser_64 .dll => No File
                                Task: {0219BF6B-4691-4A8B-B178-56FFF61475DE} - System32\Tasks\YCMServiceAgent => C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe [2014-03-07] (CyberLink Corp.)
                                Task: {1A863726-086B-42F3-ACBC-DF6752958E12} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2014-01-13] (Hewlett-Packard Company)
                                Task: {29A46853-9769-454D-AFF2-430468021DE2} - System32\Tasks\SweetLabs App Platform => %LOCALAPPDATA%\SweetLabs App Platform\Engine\ServiceHostAppUpdater.exe
                                Task: {5F2066DB-0217-4F83-BBE9-E38D888098E9} - System32\Tasks\SDMsgUpdate (TE) => C:\SmartDraw CI\Messages\SDNotify.exe [2012-08-13] ()
                                Task: {61AAE424-B58F-4FD8-821A-6461A83209F1} - System32\Tasks\SDMsgUpdate (Local) => C:\SmartDraw CI\Messages\SDNotify.exe [2012-08-13] ()
                                Task: {8D3CE45B-EA58-4026-9922-10070FD498E3} - System32\Tasks\BDAntiCryptoWallTask => C:\Program Files\Bitdefender\Tools\BDAntiRansomware\BDAntiRan somware.exe [2016-05-16] ()
                                Task: {A1095FFC-DFCF-4D22-BD61-A029EF25DB12} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2012-11-30] (Hewlett-Packard Company)
                                Task: {B69BDAEC-684E-4604-9A48-DF14EC6CCA42} - System32\Tasks\TinyTakeUpgrade => C:\Users\HP-PC\AppData\Local\MangoApps\TinyTake by MangoApps\TinyTake.exe
                                Task: {DF38DFA3-8A2A-4F3D-A6DB-79F757FF401F} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated)
                                Task: {FE079EE5-FAC7-47D1-8254-37B606874DCD} - System32\Tasks\HPCeeScheduleForHP-PC => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2011-07-15] (Hewlett-Packard)
                                HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Min imal\mcpltsvc => “”=“”
                                HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Net work\mcpltsvc => “”=“”
                                C:\Windows\system32\Drivers\etc\hosts
                                hosts:
                                FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
                                FirewallRules: [{64B9D502-F2A9-4D07-B273-49337AF2CD3C}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12.exe
                                FirewallRules: [{D94E5D30-5E92-4364-BBAD-3AA9C3B43892}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DM REngine.exe
                                FirewallRules: [{96188C50-7FD1-4C02-8BEE-F46247AA0F84}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPD VD12.exe
                                FirewallRules: [{F06983FC-8920-4F3D-AD39-3ED40BE5168B}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe
                                FirewallRules: [{D2FB5136-8CCA-4944-B878-5650789950DC}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12ML.exe
                                FirewallRules: [{1B7D9E60-79F4-4183-915B-91634E85450C}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD.exe
                                FirewallRules: [{6D61EDC4-F73B-4414-8D90-AD7972CEB22D}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
                                FirewallRules: [{54CAF249-D498-4C7F-B8C4-C39F2E1BCE20}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
                                FirewallRules: [{99D6E21E-92B1-423B-86AD-FB5FC8517AD8}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDirector10\PDR10.EXE
                                FirewallRules: [TCP Query User{40384E5F-55E0-499D-9AEC-CA92286AD093}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
                                FirewallRules: [UDP Query User{A93C04BE-3839-4F93-8564-C2766514A9AE}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
                                FirewallRules: [{1A4F5393-C5B1-4E5C-AE5B-214DC99F4B70}] => (Allow) C:\Program Files (x86)\Apowersoft\Apowersoft Screen Recorder Pro 2\Apowersoft Screen Recorder Pro 2.exe
                                FirewallRules: [{2517537D-6605-4903-8DCB-68E19BC804FF}] => (Allow) C:\Program Files (x86)\Apowersoft\Apowersoft Screen Recorder Pro 2\Apowersoft Screen Recorder Pro 2.exe
                                FirewallRules: [TCP Query User{65B266A6-66D4-4E10-B23C-3FBD9B576A95}C:\users\hp-pc\appdata\local\google\chrome\application\chrome. exe] => (Block) C:\users\hp-pc\appdata\local\google\chrome\application\chrome. exe
                                FirewallRules: [UDP Query User{0C91A68E-1569-4DA7-8549-70DDEC003B4E}C:\users\hp-pc\appdata\local\google\chrome\application\chrome. exe] => (Block) C:\users\hp-pc\appdata\local\google\chrome\application\chrome. exe
                                FirewallRules: [{316F8418-7F3F-4692-AE72-629A3DA48253}] => (Allow) tunmgr.exe
                                FirewallRules: [{EEC9BDE7-52BB-4B9C-9419-E45B704D5D7C}] => (Allow) tunmgr.exe
                                FirewallRules: [{88E06CDD-9511-494A-BA9D-98F04B1AF38A}] => (Allow) mDNSResponder.exe
                                FirewallRules: [{D17EDF1B-D27C-468B-A50A-8681D0C05702}] => (Allow) mDNSResponder.exe
                                FirewallRules: [{265A663D-1E01-42C0-ADEE-9122EDF880AD}] => (Allow) C:\Program Files (x86)\Common Files\Research In Motion\nginx\nginx.exe
                                FirewallRules: [{6FD288FF-75F9-43D9-BB0C-A6244923910D}] => (Allow) C:\Program Files (x86)\BlackBerry\BlackBerry Blend\desktopinvokeproxy.exe
                                FirewallRules: [TCP Query User{5466A29F-7602-4701-8485-DE54D70CDB43}C:\program files (x86)\common files\research in motion\tunnel manager\peermanager.exe] => (Block) C:\program files (x86)\common files\research in motion\tunnel manager\peermanager.exe
                                FirewallRules: [UDP Query User{AF38A96D-61F4-4485-BB03-843BDED0E84B}C:\program files (x86)\common files\research in motion\tunnel manager\peermanager.exe] => (Block) C:\program files (x86)\common files\research in motion\tunnel manager\peermanager.exe
                                FirewallRules: [{C5281240-DE99-43A1-A5E7-D10E4B3DFAB3}] => (Allow) C:\Program Files (x86)\SHAREit\SHAREit\SHAREit.exe
                                FirewallRules: [{EF832788-1AB2-43F4-A5F7-8623E4B65025}] => (Allow) C:\Program Files (x86)\SHAREit\SHAREit\SHAREit.exe
                                FirewallRules: [TCP Query User{0570EF7A-B81F-438A-9275-00DCFB086E90}C:\program files (x86)\connectify\connectify.exe] => (Allow) C:\program files (x86)\connectify\connectify.exe
                                FirewallRules: [UDP Query User{987B2294-3DF7-431A-94A1-70E71B31D31C}C:\program files (x86)\connectify\connectify.exe] => (Allow) C:\program files (x86)\connectify\connectify.exe
                                FirewallRules: [TCP Query User{599CDD59-2084-42C3-8439-2773CF39318B}C:\users\hp-pc\appdata\local\google\chrome\application\chrome. exe] => (Block) C:\users\hp-pc\appdata\local\google\chrome\application\chrome. exe
                                FirewallRules: [UDP Query User{44A31A6F-A90F-4A86-A40E-3BB028D870D9}C:\users\hp-pc\appdata\local\google\chrome\application\chrome. exe] => (Block) C:\users\hp-pc\appdata\local\google\chrome\application\chrome. exe
                                FirewallRules: [{FC773ECF-F98A-480C-99D5-412EDE318A0D}] => (Allow) %systemroot%\system32\alg.exe
                                FirewallRules: [TCP Query User{4D4B1086-6642-4F0E-89FC-D3ED5034BA6E}C:\program files (x86)\common files\research in motion\tunnel manager\peermanager.exe] => (Block) C:\program files (x86)\common files\research in motion\tunnel manager\peermanager.exe
                                FirewallRules: [UDP Query User{FD67FAE2-2BC5-42EC-B297-027A5F1BE508}C:\program files (x86)\common files\research in motion\tunnel manager\peermanager.exe] => (Block) C:\program files (x86)\common files\research in motion\tunnel manager\peermanager.exe
                                FirewallRules: [{0AF9D8E7-9842-41AE-95F2-9FBC5A93E355}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                                Shortcut: C:\Users\183-k\Links\RecentPlaces.lnk → L ᐁ À 䘀 耟穭⊇㞡䘚낑�깚馼 ă ꀀv 匱卐뜥䟯ယ怂麌곫-
                                ἀ ฀ 刀攀挀攀渀琀 瀀氀愀挀攀猀 ⴀ Ѐ System Folder 匱卐檦⡣锽ᇒ횵쀀�퀘e ἀ ⤀ 㨀㨀笀㈀㈀㠀㜀㜀䄀㘀䐀ⴀ㌀㜀䄀㄀ⴀ㐀㘀㄀䄀ⴀ㤀㄀䈀 ⴀ䐀䈀䐀䄀㔀䄀䄀䔀䈀䌀㤀㤀紀
                                Shortcut: C:\Users\183-k\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\QuickTime Player.lnk → C:\Windows\Installer{08CA9554-B5FE-4313-938F-D4A417B81175}\QTPlayer.ico (No File)
                                Shortcut: C:\Users\183-k\AppData\Local\Microsoft\Windows\Application Shortcuts\microsoft.windowscommunicationsapps_8wek yb3d8bbwe\Microsoft.WindowsLive.Calendar.lnk → [LFz1SPSU(Ly9K-u2microsoft.windowscommunicationsapps_8wekyb3d8bbw eGmicrosoft.windowscommunicationsapps_17.5.9600.20 911_x64__8wekyb3d8bbweQmicrosoft.windowscommunicat ionsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Calen dardC:\Program Files\WindowsApps\microsoft.windowscommunicationsa pps_17.5.9600.20911_x64__8wekyb3d8bbwe1SPSMԆi<DTQ ModernCalendar\CalendarLogo.pngU!ModernCalendar\Ca lendarBadge.png]%ModernCalendar\CalendarSmallLogo.pngY$ModernCalen dar\CalendarWideLogo.pngQ3]%ModernCalendar\CalendarLargeLogo.pngMms-resource:calendarAppTitleY$ModernCalendar\Calendar TinyLogo.pngi1SPS0%G[ICODE]Mms-resource:calendarAppTitle-1SPSwlE[([8װY1SPSOYMGm=Microsoft Corporation] (No File) Shortcut: C:\Users\183-k\AppData\Local\Microsoft\Windows\Application Shortcuts\microsoft.windowscommunicationsapps_8wek yb3d8bbwe\Microsoft.WindowsLive.Mail.lnk -> [LF1SPSU(Ly9K-u2microsoft.windowscommunicationsapps_8wekyb3d8bbw eGmicrosoft.windowscommunicationsapps_17.5.9600.20 911_x64__8wekyb3d8bbweMmicrosoft.windowscommunicat ionsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Maild C:\Program Files\WindowsApps\microsoft.windowscommunicationsa pps_17.5.9600.20911_x64__8wekyb3d8bbwev1SPSMԆi<D*T IModernMail\Res\MailLogo.pngMModernMail\Res\MailBa dge.pngU!ModernMail\Res\MailSmallLogo.pngQ ModernMail\Res\MailWideLogo.pngrU!ModernMail\Res\M ailLargeLogo.pngEms-resource:mailAppTitleQ ModernMail\Res\MailTinyLogo.pnga1SPS0%G[/ICODE]Ems-resource:mailAppTitleq1SPS}@H1U!ms-resource:mailShareDescription-1SPSwlE[([8װY1SPSOYMGm=Microsoft Corporation] (No File)
                                Shortcut: C:\Users\183-k\AppData\Local\Microsoft\Windows\Application Shortcuts\microsoft.windowscommunicationsapps_8wek yb3d8bbwe\Microsoft.WindowsLive.People.lnk → [LFr1SPSU(Ly9K-u2microsoft.windowscommunicationsapps_8wekyb3d8bbw eGmicrosoft.windowscommunicationsapps_17.5.9600.20 911_x64__8wekyb3d8bbweOmicrosoft.windowscommunicat ionsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Peopl edC:\Program Files\WindowsApps\microsoft.windowscommunicationsa pps_17.5.9600.20911_x64__8wekyb3d8bbwe1SPSMԆi<D
                                TAModernPeople\People.pngMModernPeople\PeopleSmall .pngIModernPeople\PeopleWide.pngG&MModernPeople\Pe opleLarge.png]%ms-resource:///strings/peopleAppNameIModernPeople\PeopleTiny.pngy1SPS0%G[ICODE]]%ms-resource:///strings/peopleAppName1SPS}@H1e*ms-resource:///strings/raShareDescription-1SPSwlE[([8װY1SPSOYMGm=Microsoft Corporation] (No File) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Productivity and Tools\7-Zip File Manager.lnk -> C:\Program Files\7-Zip\7zFM.exe (No File) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Productivity and Tools\7-Zip Help.lnk -> C:\Program Files\7-Zip\7-zip.chm (No File) Shortcut: C:\Users\HP-PC\OneDrive\Google Chrome.lnk -> C:\Users\HP-PC\AppData\Local\Google\Chrome\Application\chrome. exe (No File) Shortcut: C:\Users\HP-PC\OneDrive\BlueJ\Select VM.lnk -> I:\BlueJ\bluej.exe (No File) Shortcut: C:\Users\HP-PC\Links\RecentPlaces.lnk -> L ᐁ À 䘀 耟穭⊇㞡䘚낑�깚馼 ă ꀀv 匱卐뜥䟯ယ怂麌곫- ἀ ฀ 刀攀挀攀渀琀 瀀氀愀挀攀猀 ⴀ Ѐ System Folder 匱卐檦⡣锽ᇒ횵쀀�퀘e ἀ ⤀ 㨀㨀笀㈀㈀㠀㜀㜀䄀㘀䐀ⴀ㌀㜀䄀㄀ⴀ㐀㘀㄀䄀ⴀ㤀㄀䈀 ⴀ䐀䈀䐀䄀㔀䄀䄀䔀䈀䌀㤀㤀紀 Shortcut: C:\Users\HP-PC\Documents\Corel\CorelDRAW X7 Samples\target.lnk -> C:\Program Files\Corel\CorelDRAW Graphics Suite X7\Draw\Samples (No File) Shortcut: C:\Users\HP-PC\Documents\Corel\Corel PHOTO-PAINT X7 Samples\target.lnk -> C:\Program Files\Corel\CorelDRAW Graphics Suite X7\PHOTO-PAINT\Samples (No File) Shortcut: C:\Users\HP-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk -> C:\Users\HP-PC\AppData\Local\SweetLabs App Platform\Engine\ServiceHostApp.exe (No File) Shortcut: C:\Users\HP-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Menu.lnk -> C:\Users\HP-PC\AppData\Local\SweetLabs App Platform\Engine\ServiceHostApp.exe (No File) Shortcut: C:\Users\HP-PC\AppData\Local\Microsoft\Windows\ConnectedSearch \History\set_127180276_en-us.lnk -> C:\Windows\System32\powercpl.dll,- (No File) Shortcut: C:\Users\HP-PC\AppData\Local\Microsoft\Windows\ConnectedSearch \History\set_1281075515_en-us.lnk -> [LF5#1SPS՜.+,7AutoListBprop4294967295N8ᭊN{x^aMh 2item1IkLICSettings9$AutolistCacheTime"p5G"Autolis tCacheKeySettings0tY^Hg3(gs3EJ.* 1SPSiI~+.{F29F85E0-4FF9-1068-AB91-08002B27B3D9},6*{B725F130-47EF-101A-A5F1-02608C9EEBAC},101SPS_ǵZeMJuEg$<ISettingsPageRestor eRestoreC1SPSU(Ly9K-1SPStk\;Co,oud1AAA_SettingsPageRestoreRestore.sett ingcontent-msU1SPS<I]@;l9d.settingcontent-ms-1SPSoOM'rT<1SPSjc(=O]C:\Users\HP-PC\AppData\Local\Packages\windows.immersivecontrol panel_cw5n1h2txyewy\LocalState\Indexed\Settings\en-US\AAA_SettingsPageRestoreRestore.settingcontent-ms9.settingcontent-msy f^aMh 2PJ 0UCEJQ1SPSOh+'5Recovery optionsy1SPSLX㈷ZJ ZDɬ]C:\Users\HP-PC\AppData\Local\Packages\windows.immersivecontrol panel_cw5n1h2txyewy\LocalState\Indexed\Settings\en-US\AAA_SettingsPageRestoreRestore.settingcontent-ms1SPSjc(=O9.settingcontent-ms]C:\Users\HP-PC\AppData\Local\Packages\windows.immersivecontrol panel_cw5n1h2txyewy\LocalState\Indexed\Settings\en-US\AAA_SettingsPageRestoreRestore.settingcontent-msw1SPS0%G[/ICODE] 5Recovery options@X1SPStk;Co,oud1AAA_SettingsPageRestoreRest ore.settingcontent-ms1SPSiI~+.{F29F85E0-4FF9-1068-AB91-08002B27B3D9},6*{B725F130-47EF-101A-A5F1-02608C9EEBAC},10U1SPS<I]@;l9d.settingcontent-mse1SPS_ǵZeMJuEg$<ISettingsPageRestoreRestore1SPS@ >+lG7*“]C:\Users\HP-PC\AppData\Local\Packages\windows.immersivecontrol panel_cw5n1h2txyewy\LocalState\Indexed\Settings\en-US\AAA_SettingsPageRestoreRestore.settingcontent-msu1{1685D4AB-A51B-4AF1-A4E5-CEE87002431D}.Merge Any1SPSOh+'5Recovery options)1SPSMԆi<DT)1SPSZAZHY$dy1SPSLX㈷ZJ ZDɬ]C:\Users\HP-PC\AppData\Local\Packages\windows.immersivecontrol panel_cw5n1h2txyewy\LocalState\Indexed\Settings\en-US\AAA_SettingsPageRestoreRestore.settingcontent-ms-1SPS[l#J[ICODE]'Hdw1SPS0%G[/ICODE] @X5Recovery options)1SPS՜.+,)1SPSmDpHH@.=xd]Q1SPSOh+'5Recovery options] (No File)
                                Shortcut: C:\Users\HP-PC\AppData\Local\Microsoft\Windows\ConnectedSearch \History\set_2747713814_en-us.lnk → C:\Windows\System32\usercpl.dll,- (No File)
                                Shortcut: C:\Users\HP-PC\AppData\Local\Microsoft\Windows\ConnectedSearch \History\set_3839032144_en-us.lnk → C:\Program Files\Windows Photo Viewer\ImagingDevices.ex (No File)
                                Shortcut: C:\Users\HP-PC\AppData\Local\Microsoft\Windows\ConnectedSearch \History\txt_2093339993_en-US.lnk → 䰀 ĔȀ 쀀 F耀 Ā 蘀 ऀ 䤀 ㅓ偓鿲累栐ꮑࠀ⬧동ⴀ Ȁ
                                presentation 1 1卐卸杈祯䳞䶼反奃ᆯ餕 ἀ Ā
                                Shortcut: C:\Users\HP-PC\AppData\Local\Microsoft\Windows\ConnectedSearch \History\txt_2119866019_en-US.lnk → 䰀 ĔȀ 쀀 F耀 Ā 蘀 ऀ 䤀 ㅓ偓鿲累栐ꮑࠀ⬧동ⴀ Ȁ
                                power point 1 1卐卸杈祯䳞䶼反奃ᆯ餕 ἀ Ā
                                Shortcut: C:\Users\HP-PC\AppData\Local\Microsoft\Windows\ConnectedSearch \History\txt_2436336599_en-US.lnk → 䰀 ĔȀ 쀀 F耀 Ā 縀 ऀ 䄀 ㅓ偓鿲累栐ꮑࠀ⬧동─ Ȁ
                                bob dylan 1 1卐卸杈祯䳞䶼反奃ᆯ餕 ἀ Ā
                                Shortcut: C:\Users\HP-PC\AppData\Local\Microsoft\Windows\ConnectedSearch \History\txt_2674333138_en-US.lnk → 䰀 ĔȀ 쀀 F耀 Ā 縀 ऀ 䄀 ㅓ偓鿲累栐ꮑࠀ⬧동─ Ȁ
                                Math type 1 1卐卸杈祯䳞䶼反奃ᆯ餕 ἀ Ā
                                Shortcut: C:\Users\HP-PC\AppData\Local\Microsoft\Windows\ConnectedSearch \History\txt_989337498_en-US.lnk → 䰀 ĔȀ 쀀 F耀 Ā 縀 ऀ 䄀 ㅓ偓鿲累栐ꮑࠀ⬧동─ Ȁ
                                Mathtype 1 1卐卸杈祯䳞䶼反奃ᆯ餕 ἀ Ā
                                Shortcut: C:\Users\HP-PC\AppData\Local\Microsoft\Windows\Application Shortcuts\Microsoft.WindowsReadingList_8wekyb3d8bb we\Microsoft.WindowsReadingList.lnk → Tile and icon assets
                                Shortcut: C:\Users\HP-PC\AppData\Local\Microsoft\Windows\Application Shortcuts\microsoft.windowscommunicationsapps_8wek yb3d8bbwe\Microsoft.WindowsLive.Calendar.lnk → [LFz1SPSU(Ly9K-u2microsoft.windowscommunicationsapps_8wekyb3d8bbw eGmicrosoft.windowscommunicationsapps_17.5.9600.20 911_x64__8wekyb3d8bbweQmicrosoft.windowscommunicat ionsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Calen dardC:\Program Files\WindowsApps\microsoft.windowscommunicationsa pps_17.5.9600.20911_x64__8wekyb3d8bbwe1SPSMԆi<D
                                TQ ModernCalendar\CalendarLogo.pngU!ModernCalendar\Ca lendarBadge.png]%ModernCalendar\CalendarSmallLogo.pngY$ModernCalen dar\CalendarWideLogo.pngQ3]%ModernCalendar\CalendarLargeLogo.pngMms-resource:calendarAppTitleY$ModernCalendar\Calendar TinyLogo.pngi1SPS0%G[ICODE]Mms-resource:calendarAppTitle-1SPSwlE[([8װY1SPSOYMGm=Microsoft Corporation] (No File) Shortcut: C:\Users\HP-PC\AppData\Local\Microsoft\Windows\Application Shortcuts\microsoft.windowscommunicationsapps_8wek yb3d8bbwe\Microsoft.WindowsLive.Mail.lnk -> [LF1SPSU(Ly9K-u2microsoft.windowscommunicationsapps_8wekyb3d8bbw eGmicrosoft.windowscommunicationsapps_17.5.9600.20 911_x64__8wekyb3d8bbweMmicrosoft.windowscommunicat ionsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Maild C:\Program Files\WindowsApps\microsoft.windowscommunicationsa pps_17.5.9600.20911_x64__8wekyb3d8bbwev1SPSMԆi<D*T IModernMail\Res\MailLogo.pngMModernMail\Res\MailBa dge.pngU!ModernMail\Res\MailSmallLogo.pngQ ModernMail\Res\MailWideLogo.pngrU!ModernMail\Res\M ailLargeLogo.pngEms-resource:mailAppTitleQ ModernMail\Res\MailTinyLogo.pnga1SPS0%G[/ICODE]Ems-resource:mailAppTitleq1SPS}@H1U!ms-resource:mailShareDescription-1SPSwlE[([8װY1SPSOYMGm=Microsoft Corporation] (No File)
                                Shortcut: C:\Users\HP-PC\AppData\Local\Microsoft\Windows\Application Shortcuts\microsoft.windowscommunicationsapps_8wek yb3d8bbwe\Microsoft.WindowsLive.People.lnk → [LFr1SPSU(Ly9K-u2microsoft.windowscommunicationsapps_8wekyb3d8bbw eGmicrosoft.windowscommunicationsapps_17.5.9600.20 911_x64__8wekyb3d8bbweOmicrosoft.windowscommunicat ionsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Peopl edC:\Program Files\WindowsApps\microsoft.windowscommunicationsa pps_17.5.9600.20911_x64__8wekyb3d8bbwe1SPSMԆi<DTAModernPeople\People.pngMModernPeople\PeopleSmall .pngIModernPeople\PeopleWide.pngG&MModernPeople\Pe opleLarge.png]%ms-resource:///strings/peopleAppNameIModernPeople\PeopleTiny.pngy1SPS0%G[ICODE]]%ms-resource:///strings/peopleAppName1SPS}@H1e*ms-resource:///strings/raShareDescription-1SPSwlE[([8װY1SPSOYMGm=Microsoft Corporation] (No File) Shortcut: C:\Users\HP-PC\AppData\Local\Microsoft\Windows\Application Shortcuts\57405F7AB8904.MathLogicalTest_b55ywndse5 f8y\App.lnk -> [LFKY1SPSU(Ly9K-i,57405F7AB8904.MathLogicalTest_b55ywndse5f8y=5740 5F7AB8904.MathLogicalTest_1.0.0.0_neutral__b55ywnd se5f8yq057405F7AB8904.MathLogicalTest_b55ywndse5f8 y!AppZC:\Program Files\WindowsApps\57405F7AB8904.MathLogicalTest_1. 0.0.0_neutral__b55ywndse5f8y+1SPSMԆi<D*T1Assets\Lo go.jpg=Assets\SmallLogo.jpg9Assets\WideLogo.jpgFFF 5Math Logical TestQ1SPS0%G[/ICODE]5Math Logical Test-1SPSwlE[([8װ=1SPSOYMGm!Hsn Ch.] (No File)
                                Shortcut: C:\Users\shrey\Links\RecentPlaces.lnk → L ᐁ À 䘀 耟穭⊇㞡䘚낑�깚馼 ă ꀀv 匱卐뜥䟯ယ怂麌곫-
                                ἀ ฀ 刀攀挀攀渀琀 瀀氀愀挀攀猀 ⴀ Ѐ System Folder 匱卐檦⡣锽ᇒ횵쀀�퀘e ἀ ⤀ 㨀㨀笀㈀㈀㠀㜀㜀䄀㘀䐀ⴀ㌀㜀䄀㄀ⴀ㐀㘀㄀䄀ⴀ㤀㄀䈀 ⴀ䐀䈀䐀䄀㔀䄀䄀䔀䈀䌀㤀㤀紀
                                Shortcut: C:\Users\shrey\AppData\Local\Microsoft\Windows\Con nectedSearch\History\set_1076774695_en-us.lnk → [LF5#1SPS՜.+,7AutoListBprop4294967295N8ᭊN{x^aMh 2item1IkLICSettings9$AutolistCacheTime\iG"Autolist CacheKeySettings0tY^Hg3(gs3EJ.
                                F1SPSiI~+.{F29F85E0-4FF9-1068-AB91-08002B27B3D9},6*{F29F85E0-4FF9-1068-AB91-08002B27B3D9},24*{B725F130-47EF-101A-A5F1-02608C9EEBAC},101SPS_ǵZeMJuEg$<MSettingsPagePCSyst emBluetoothC1SPSU(Ly9K-1SPStk;Co,oyd4AAA_SettingsPagePCSystemBluetooth.se ttingcontent-msU1SPS<I]@;l9d.settingcontent-ms-1SPSoOM’rTL1SPSjc(=OaC:\Users\shrey\AppData\Local\ Packages\windows.immersivecontrolpanel_cw5n1h2txye wy\LocalState\Indexed\Settings\en-US\AAA_SettingsPagePCSystemBluetooth.settingconten t-ms9.settingcontent-ms q^aMh 2[U
                                ;UCEJ1SPSOh+'9Bluetooth settingsYadd addsbluetoothdevice devicesdisable disablesenable enablespair pairs print printer printers printingremove removessmartunpairaudiodiscover discoverskeyboard keyboardsMouse micephone phonesradio radiosspeaker speakerswireless-find finds}1SPSLX㈷ZJ ZDɬaC:\Users\shrey\AppData\Local\Packages\windows. immersivecontrolpanel_cw5n1h2txyewy\LocalState\Ind exed\Settings\en-US\AAA_SettingsPagePCSystemBluetooth.settingconten t-ms1SPSjc(=O9.settingcontent-msaC:\Users\shrey\AppData\Local\Packages\windows.i mmersivecontrolpanel_cw5n1h2txyewy\LocalState\Inde xed\Settings\en-US\AAA_SettingsPagePCSystemBluetooth.settingconten t-ms{1SPS0%G[ICODE]9Bluetooth settings @X1SPStk\;Co,oyd4AAA_SettingsPagePCSystemBluetooth .settingcontent-msF1SPSiI~+.{F29F85E0-4FF9-1068-AB91-08002B27B3D9},6*{F29F85E0-4FF9-1068-AB91-08002B27B3D9},24*{B725F130-47EF-101A-A5F1-02608C9EEBAC},10U1SPS<I]@;l9d.settingcontent-msi1SPS_ǵZeMJuEg$<MSettingsPagePCSystemBluetooth1S PS@>+lG7*"aC:\Users\shrey\AppData\Local\Packages\w indows.immersivecontrolpanel_cw5n1h2txyewy\LocalSt ate\Indexed\Settings\en-US\AAA_SettingsPagePCSystemBluetooth.settingconten t-msu1{1685D4AB-A51B-4AF1-A4E5-CEE87002431D}.Merge Any1SPSOh+'Yadd addsbluetoothdevice devicesdisable disablesenable enablespair pairs print printer printers printingremove removessmartunpairaudiodiscover discoverskeyboard keyboardsMouse micephone phonesradio radiosspeaker speakerswireless9Bluetooth settings-find finds)1SPSMԆi<D*T)1SPSZAZHY$d}1SPSLX㈷ZJ ZDɬaC:\Users\shrey\AppData\Local\Packages\windows. immersivecontrolpanel_cw5n1h2txyewy\LocalState\Ind exed\Settings\en-US\AAA_SettingsPagePCSystemBluetooth.settingconten t-ms-1SPS[l#J[/ICODE]’Hd{1SPS0%G[ICODE] @X9Bluetooth settings)1SPS՜.+,)1SPSmDpHH@.=xdaU1SPSOh+'9Bluetoo th settings] (No File) Shortcut: C:\Users\shrey\AppData\Local\Microsoft\Windows\Con nectedSearch\History\set_3054665329_en-us.lnk -> C:\Windows\system32\rundll32.exe shell32.dll,Control_RunDLL bthprops.cpl,, (No File) Shortcut: C:\Users\shrey\AppData\Local\Microsoft\Windows\App lication Shortcuts\microsoft.windowscommunicationsapps_8wek yb3d8bbwe\Microsoft.WindowsLive.Calendar.lnk -> [LFz1SPSU(Ly9K-u2microsoft.windowscommunicationsapps_8wekyb3d8bbw eGmicrosoft.windowscommunicationsapps_17.5.9600.20 911_x64__8wekyb3d8bbweQmicrosoft.windowscommunicat ionsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Calen dardC:\Program Files\WindowsApps\microsoft.windowscommunicationsa pps_17.5.9600.20911_x64__8wekyb3d8bbwe1SPSMԆi<D*TQ ModernCalendar\CalendarLogo.pngU!ModernCalendar\Ca lendarBadge.png]%ModernCalendar\CalendarSmallLogo.pngY$ModernCalen dar\CalendarWideLogo.pngQ3]%ModernCalendar\CalendarLargeLogo.pngMms-resource:calendarAppTitleY$ModernCalendar\Calendar TinyLogo.pngi1SPS0%G[/ICODE]Mms-resource:calendarAppTitle-1SPSwlE[([8װY1SPSOYMGm=Microsoft Corporation] (No File)
                                Shortcut: C:\Users\shrey\AppData\Local\Microsoft\Windows\App lication Shortcuts\microsoft.windowscommunicationsapps_8wek yb3d8bbwe\Microsoft.WindowsLive.Mail.lnk → [LF1SPSU(Ly9K-u2microsoft.windowscommunicationsapps_8wekyb3d8bbw eGmicrosoft.windowscommunicationsapps_17.5.9600.20 911_x64__8wekyb3d8bbweMmicrosoft.windowscommunicat ionsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Maild C:\Program Files\WindowsApps\microsoft.windowscommunicationsa pps_17.5.9600.20911_x64__8wekyb3d8bbwev1SPSMԆi<DTIModernMail\Res\MailLogo.pngMModernMail\Res\MailB adge.pngU!ModernMail\Res\MailSmallLogo.pngQ ModernMail\Res\MailWideLogo.pngrU!ModernMail\Res\M ailLargeLogo.pngEms-resource:mailAppTitleQ ModernMail\Res\MailTinyLogo.pnga1SPS0%G[ICODE]Ems-resource:mailAppTitleq1SPS}@H1U!ms-resource:mailShareDescription-1SPSwlE[([8װY1SPSOYMGm=Microsoft Corporation] (No File) Shortcut: C:\Users\shrey\AppData\Local\Microsoft\Windows\App lication Shortcuts\microsoft.windowscommunicationsapps_8wek yb3d8bbwe\Microsoft.WindowsLive.People.lnk -> [LFr1SPSU(Ly9K-u2microsoft.windowscommunicationsapps_8wekyb3d8bbw eGmicrosoft.windowscommunicationsapps_17.5.9600.20 911_x64__8wekyb3d8bbweOmicrosoft.windowscommunicat ionsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Peopl edC:\Program Files\WindowsApps\microsoft.windowscommunicationsa pps_17.5.9600.20911_x64__8wekyb3d8bbwe1SPSMԆi<D*TA ModernPeople\People.pngMModernPeople\PeopleSmall.p ngIModernPeople\PeopleWide.pngG&MModernPeople\Peop leLarge.png]%ms-resource:///strings/peopleAppNameIModernPeople\PeopleTiny.pngy1SPS0%G[/ICODE]]%ms-resource:///strings/peopleAppName1SPS}@H1ems-resource:///strings/raShareDescription-1SPSwlE[([8װY1SPSOYMGm=Microsoft Corporation] (No File)
                                ShortcutWithArgument: C:\Users\183-k\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk → C:\Windows\System32\WFS.exe (Microsoft Corporation) → /SendTo
                                ShortcutWithArgument: C:\Users\183-k\AppData\Roaming\Microsoft\Windows\SendTo\Skype.l nk → C:\Program Files (x86)\Skype\Phone\Skype.exe (Skype Technologies S.A.) → /sendto:
                                ShortcutWithArgument: C:\Users\183-k\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Start Menu.lnk → C:\Users\183-k\AppData\Local\Pokki\Engine\HostAppService.exe (Pokki) → /OPEN"menu”
                                ShortcutWithArgument: C:\Users\183-k\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - Network Connections.lnk → C:\Windows\explorer.exe (Microsoft Corporation) → ::{7007ACC7-3202-11D1-AAD2-00805FC1270E}
                                ShortcutWithArgument: C:\Users\183-k\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk → C:\Windows\System32\control.exe (Microsoft Corporation) → /name Microsoft.DeviceManager
                                ShortcutWithArgument: C:\Users\183-k\AppData\Local\Microsoft\Windows\WinX\Group3\06 - System.lnk → C:\Windows\System32\control.exe (Microsoft Corporation) → /name Microsoft.System
                                ShortcutWithArgument: C:\Users\183-k\AppData\Local\Microsoft\Windows\WinX\Group3\08 - Power Options.lnk → C:\Windows\System32\control.exe (Microsoft Corporation) → /name Microsoft.PowerOptions
                                ShortcutWithArgument: C:\Users\183-k\AppData\Local\Microsoft\Windows\WinX\Group3\10 - Programs and Features.lnk → C:\Windows\System32\control.exe (Microsoft Corporation) → /name Microsoft.ProgramsAndFeatures
                                ShortcutWithArgument: C:\Users\183-k\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk → C:\Windows\explorer.exe (Microsoft Corporation) → shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}
                                ShortcutWithArgument: C:\Users\183-k\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk → C:\Windows\explorer.exe (Microsoft Corporation) → shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0}
                                ShortcutWithArgument: C:\Users\183-k\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk → C:\Windows\explorer.exe (Microsoft Corporation) → /e,::{20D04FE0-3AEA-1069-A2D8-08002B30309D}
                                ShortcutWithArgument: C:\Users\183-k\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk → C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) → /0
                                ShortcutWithArgument: C:\Users\183-k\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk → C:\Windows\explorer.exe (Microsoft Corporation) → shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257}
                                ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\VIDLE for VPython.lnk → C:\Python27\pythonw.exe () → C:\Python27\Lib\site-packages\vidle\idle.py
                                ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office.lnk → C:\Program Files (x86)\Microsoft Office\Office15\FIRSTRUN.EXE (Microsoft Corporation) → /OEM
                                ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk → C:\Users\183-k\AppData\Local\Pokki\Engine\HostAppService.exe (Pokki) → /OPEN"f22abfeae27a67446927d078890381efc546d3e1"
                                ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk → C:\Windows\System32\rundll32.exe (Microsoft Corporation) → -sta {C90FB8CA-3295-4462-A721-2935E83694BA}
                                ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Start Menu.lnk → C:\Users\183-k\AppData\Local\Pokki\Engine\HostAppService.exe (Pokki) → /OPEN"menu"
                                ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Default Programs.lnk → C:\Windows\System32\control.exe (Microsoft Corporation) → /name Microsoft.DefaultPrograms
                                ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Task Manager.lnk → C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) → /7
                                ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 2.7\IDLE (Python GUI).lnk → C:\Windows\Installer{79F081BF-7454-43DB-BD8F-9EE596813232}\python_icon.exe () → “C:\Python27\Lib\idlelib\idle.pyw”
                                ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 2.7\Module Docs.lnk → C:\Windows\Installer{79F081BF-7454-43DB-BD8F-9EE596813232}\python_icon.exe () → “C:\Python27\Tools\scripts\pydocgui.pyw”
                                ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 2.7\Uninstall Python.lnk → C:\Windows\SysWOW64\msiexec.exe (Microsoft Corporation) → /x{79F081BF-7454-43DB-BD8F-9EE596813232}
                                ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picasa 3\Configure Picasa Photo Viewer.lnk → C:\Program Files (x86)\Google\Picasa3\PicasaPhotoViewer.exe (Google Inc.) → /reconfig
                                ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox\Mozilla Firefox (Safe Mode).lnk → C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) →
                                ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox\Mozilla Firefox.lnk → C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) →
                                ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MathType 6\Equation Conversion Manager.lnk → C:\Program Files (x86)\MathType\Setup.exe (Design Science, Inc.) → -OLEMGR
                                ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MathType 6\MathType Server.lnk → C:\Program Files (x86)\MathType\MathType.exe (Design Science, Inc.) → -server
                                ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MathType 6\Remove MathType.lnk → C:\Program Files (x86)\MathType\Setup.exe (Design Science, Inc.) → -R
                                ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Total Security\Remove Kaspersky Total Security.lnk → C:\Windows\SysWOW64\msiexec.exe (Microsoft Corporation) → /i{E27B1D7B-3B34-43A2-9FC0-9828D5DF46E2} REMOVE=ALL
                                ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Secure Connection\Kaspersky Secure Connection.lnk → C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksdeui.exe (AO Kaspersky Lab) → -navigate ksde://mainwindow
                                ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Secure Connection\Remove Kaspersky Secure Connection.lnk → C:\Windows\SysWOW64\msiexec.exe (Microsoft Corporation) → /i{1CF84962-50F8-48CA-9082-B70F3A02C686} REMOVE=ALL
                                ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\About Java.lnk → C:\Users\183-k\Desktop\bin\javacpl.exe (Oracle Corporation) → -tab about
                                ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Check For Updates.lnk → C:\Users\183-k\Desktop\bin\javacpl.exe (Oracle Corporation) → -tab update
                                ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IB Questionbank\Questionbank Maths HL.lnk → C:\Program Files (x86)\IB Questionbank32\IB Questionbank32.exe () → IB_MH
                                ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IB Questionbank\Questionbank Physics.lnk → C:\Program Files (x86)\IB Questionbank32\IB Questionbank32.exe () → IB_PH
                                ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support\HP Recovery Manager\HP Recovery Media Creation.lnk → C:\Program Files (x86)\Hewlett-Packard\HP Recovery Manager\rebecca.exe (Hewlett-Packard Development Company, L.P.) → \CRM
                                ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueJ\Select BlueJ VM.lnk → C:\Program Files (x86)\BlueJ\BlueJ.exe () → /select
                                ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autograph 3.3\Help.lnk → C:\Program Files (x86)\Autograph 3.3\LocalisedLauncher.exe (Eastmond Publishing Ltd.(UK)) → WebHelp\Autograph_Help.htm
                                ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autograph 3.3\Manual.lnk → C:\Program Files (x86)\Autograph 3.3\LocalisedLauncher.exe (Eastmond Publishing Ltd.(UK)) → Autograph Manual.pdf
                                ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Computer Management.lnk → C:\Windows\System32\compmgmt.msc () → /s
                                ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk → C:\Windows\System32\eventvwr.msc () → /s
                                ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk → C:\Windows\System32\perfmon.msc () → /s
                                ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Resource Monitor.lnk → C:\Windows\System32\perfmon.exe (Microsoft Corporation) → /res
                                ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk → C:\Windows\System32\taskschd.msc () → /s
                                ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Media Player.lnk → C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation) → /prefetch:1
                                ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility\Speech Recognition.lnk → C:\Windows\Speech\Common\sapisvr.exe (Microsoft Corporation) → -SpeechUX
                                ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\GameExplorer{d58e ecb0-0816-11de-8c30-0800200c9a66}\PlayTasks\0\provider.lnk → C:\Program Files (x86)\WildTangent Games\Game Explorer Categories - genres\provider.exe (WildTangent) → /id=d58eecb0-0816-11de-8c30-0800200c9a66 /src gameexploreroem
                                ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\GameExplorer{b0e4 3195-dbe0-4647-8e23-84fc3b08cee9}\PlayTasks\0\web.lnk → C:\Program Files (x86)\WildTangent Games\Web Link - Dragons Of Atlantis\launcher.exe (WildTangent) → /src gameexploreroem
                                ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\GameExplorer{977b 5905-4d14-47f1-bbbf-7b92f596695d}\PlayTasks\0\provider.lnk → C:\Program Files (x86)\WildTangent Games\Game Explorer Categories - main\provider.exe (WildTangent) → /id=977b5905-4d14-47f1-bbbf-7b92f596695d /src gameexploreroem
                                ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\GameExplorer{7e00 8ca2-08ab-4789-af23-36da87658f74}\PlayTasks\0\web.lnk → C:\Program Files (x86)\WildTangent Games\Web Link - DoubleDown Casino\launcher.exe (WildTangent) → /src gameexploreroem
                                ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\GameExplorer{3eda 1e54-8889-41f5-a649-5a306789b7ef}\PlayTasks\0\provider.lnk → C:\Program Files (x86)\WildTangent Games\Game Explorer Categories - genres\provider.exe (WildTangent) → /id=3eda1e54-8889-41f5-a649-5a306789b7ef /src gameexploreroem
                                ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\GameExplorer{2635 2374-af55-4b53-b07b-6b0288ed97df}\PlayTasks\0\provider.lnk → C:\Program Files (x86)\WildTangent Games\Game Explorer Categories - genres\provider.exe (WildTangent) → /id=26352374-af55-4b53-b07b-6b0288ed97df /src gameexploreroem
                                ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\GameExplorer{000d 96f5-8034-4b74-a429-b6f0b04c75f4}\PlayTasks\0\provider.lnk → C:\Program Files (x86)\WildTangent Games\Game Explorer Categories - genres\provider.exe (WildTangent) → /id=000d96f5-8034-4b74-a429-b6f0b04c75f4 /src gameexploreroem
                                ShortcutWithArgument: C:\ProgramData\Hewlett-Packard\Recovery\Links\Apps.lnk → C:\Program Files (x86)\Hewlett-Packard\HP Recovery Manager\rebecca.exe (Hewlett-Packard Development Company, L.P.) → \SWR
                                ShortcutWithArgument: C:\ProgramData\Hewlett-Packard\Recovery\Links\BTR.lnk → C:\Program Files (x86)\Hewlett-Packard\HP Recovery Manager\rebecca.exe (Hewlett-Packard Development Company, L.P.) → \BTR
                                ShortcutWithArgument: C:\ProgramData\Hewlett-Packard\Recovery\Links\Driver.lnk → C:\Program Files (x86)\Hewlett-Packard\HP Recovery Manager\rebecca.exe (Hewlett-Packard Development Company, L.P.) → \SWR
                                ShortcutWithArgument: C:\ProgramData\Hewlett-Packard\Recovery\Links\RMC.lnk → C:\Program Files (x86)\Hewlett-Packard\HP Recovery Manager\rebecca.exe (Hewlett-Packard Development Company, L.P.) → \CRM
                                ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows \SendTo\Fax Recipient.lnk → C:\Windows\System32\WFS.exe (Microsoft Corporation) → /SendTo
                                ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\W inX\Group3\04-1 - Network Connections.lnk → C:\Windows\explorer.exe (Microsoft Corporation) → ::{7007ACC7-3202-11D1-AAD2-00805FC1270E}
                                ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\W inX\Group3\05 - Device Manager.lnk → C:\Windows\System32\control.exe (Microsoft Corporation) → /name Microsoft.DeviceManager
                                ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\W inX\Group3\06 - System.lnk → C:\Windows\System32\control.exe (Microsoft Corporation) → /name Microsoft.System
                                ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\W inX\Group3\08 - Power Options.lnk → C:\Windows\System32\control.exe (Microsoft Corporation) → /name Microsoft.PowerOptions
                                ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\W inX\Group3\10 - Programs and Features.lnk → C:\Windows\System32\control.exe (Microsoft Corporation) → /name Microsoft.ProgramsAndFeatures
                                ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\W inX\Group2\1 - Run.lnk → C:\Windows\explorer.exe (Microsoft Corporation) → shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}
                                ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\W inX\Group2\2 - Search.lnk → C:\Windows\explorer.exe (Microsoft Corporation) → shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0}
                                ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\W inX\Group2\3 - Windows Explorer.lnk → C:\Windows\explorer.exe (Microsoft Corporation) → /e,::{20D04FE0-3AEA-1069-A2D8-08002B30309D}
                                ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\W inX\Group2\5 - Task Manager.lnk → C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) → /0
                                ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\W inX\Group1\1 - Desktop.lnk → C:\Windows\explorer.exe (Microsoft Corporation) → shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257}
                                ShortcutWithArgument: C:\Users\HP-PC\OneDrive\IB Question Banks\Questionbank Chemistry.lnk → C:\Program Files (x86)\IB Questionbank32\IB Questionbank32.exe () → IB_CH
                                ShortcutWithArgument: C:\Users\HP-PC\OneDrive\IB Question Banks\Questionbank Maths HL.lnk → C:\Program Files (x86)\IB Questionbank32\IB Questionbank32.exe () → IB_MH
                                ShortcutWithArgument: C:\Users\HP-PC\OneDrive\IB Question Banks\Questionbank Physics.lnk → C:\Program Files (x86)\IB Questionbank32\IB Questionbank32.exe () → IB_PH
                                ShortcutWithArgument: C:\Users\HP-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SML of New Jersey (2).lnk → C:\Program Files (x86)\SMLNJ\bin.run\run.x86-win32.exe () → “@SMLload=C:\Program Files (x86)\SMLNJ\bin.heap\sml”
                                ShortcutWithArgument: C:\Users\HP-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SML of New Jersey.lnk → C:\Program Files (x86)\SMLNJ\bin.run\run.x86-win32.exe () → “@SMLload=C:\Program Files (x86)\SMLNJ\bin.heap\sml”
                                ShortcutWithArgument: C:\Users\HP-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk → C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) → /tsr
                                ShortcutWithArgument: C:\Users\HP-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RescueTime.lnk → C:\Users\HP-PC\AppData\Local\RescueTime\RescueTime.exe (RescueTime, Inc.) →
                                ShortcutWithArgument: C:\Users\HP-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MiKTeX 2.9\Maintenance\MiKTeX Update.lnk → C:\Users\HP-PC\AppData\Local\Programs\MiKTeX 2.9\miktex\bin\internal\copystart.exe () → “C:\Users\HP-PC\AppData\Local\Programs\MiKTeX 2.9\miktex/bin/internal\miktex-update.exe”
                                ShortcutWithArgument: C:\Users\HP-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Multi messenger.lnk → C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) →
                                ShortcutWithArgument: C:\Users\HP-PC\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk → C:\Windows\System32\WFS.exe (Microsoft Corporation) → /SendTo
                                ShortcutWithArgument: C:\Users\HP-PC\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk → C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) →
                                ShortcutWithArgument: C:\Users\HP-PC\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Media Player.lnk → C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation) → /prefetch:1
                                ShortcutWithArgument: C:\Users\HP-PC\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - Network Connections.lnk → C:\Windows\explorer.exe (Microsoft Corporation) → ::{7007ACC7-3202-11D1-AAD2-00805FC1270E}
                                ShortcutWithArgument: C:\Users\HP-PC\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk → C:\Windows\System32\control.exe (Microsoft Corporation) → /name Microsoft.DeviceManager
                                ShortcutWithArgument: C:\Users\HP-PC\AppData\Local\Microsoft\Windows\WinX\Group3\06 - System.lnk → C:\Windows\System32\control.exe (Microsoft Corporation) → /name Microsoft.System
                                ShortcutWithArgument: C:\Users\HP-PC\AppData\Local\Microsoft\Windows\WinX\Group3\08 - Power Options.lnk → C:\Windows\System32\control.exe (Microsoft Corporation) → /name Microsoft.PowerOptions
                                ShortcutWithArgument: C:\Users\HP-PC\AppData\Local\Microsoft\Windows\WinX\Group3\10 - Programs and Features.lnk → C:\Windows\System32\control.exe (Microsoft Corporation) → /name Microsoft.ProgramsAndFeatures
                                ShortcutWithArgument: C:\Users\HP-PC\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk → C:\Windows\explorer.exe (Microsoft Corporation) → shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}
                                ShortcutWithArgument: C:\Users\HP-PC\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk → C:\Windows\explorer.exe (Microsoft Corporation) → shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0}
                                ShortcutWithArgument: C:\Users\HP-PC\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk → C:\Windows\explorer.exe (Microsoft Corporation) → /e,::{20D04FE0-3AEA-1069-A2D8-08002B30309D}
                                ShortcutWithArgument: C:\Users\HP-PC\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk → C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) → /0
                                ShortcutWithArgument: C:\Users\HP-PC\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk → C:\Windows\explorer.exe (Microsoft Corporation) → shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257}
                                ShortcutWithArgument: C:\Users\Public\Desktop\Kaspersky Secure Connection.lnk → C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksdeui.exe (AO Kaspersky Lab) → -navigate ksde://mainwindow
                                ShortcutWithArgument: C:\Users\Public\Desktop\Mozilla Firefox.lnk → C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) →
                                ShortcutWithArgument: C:\Users\Public\Desktop\Questionbank Maths HL.lnk → C:\Program Files (x86)\IB Questionbank32\IB Questionbank32.exe () → IB_MH
                                ShortcutWithArgument: C:\Users\Public\Desktop\Questionbank Physics.lnk → C:\Program Files (x86)\IB Questionbank32\IB Questionbank32.exe () → IB_PH
                                ShortcutWithArgument: C:\Users\Public\Desktop\Safe Money.lnk → C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\avpui.exe (AO Kaspersky Lab) → -safebanking
                                ShortcutWithArgument: C:\Users\Public\Desktop\VIDLE for VPython.lnk → C:\Python27\pythonw.exe () → C:\Python27\Lib\site-packages\vidle\idle.py
                                ShortcutWithArgument: C:\Users\shrey\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\FarmVille 2.lnk → C:\Users\shrey\AppData\Local\SweetLabs App Platform\Engine\ServiceHostApp.exe (Pokki) → /OPEN"34e8f5c0c9e5744bf2cdb514283762dd0524776b"
                                ShortcutWithArgument: C:\Users\shrey\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\PC App Store.lnk → C:\Users\shrey\AppData\Local\SweetLabs App Platform\Engine\ServiceHostApp.exe (Pokki) → /OPEN"f22abfeae27a67446927d078890381efc546d3e1"
                                ShortcutWithArgument: C:\Users\shrey\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Start Menu.lnk → C:\Users\shrey\AppData\Local\SweetLabs App Platform\Engine\ServiceHostApp.exe (Pokki) → /OPEN"menu"
                                ShortcutWithArgument: C:\Users\shrey\AppData\Roaming\Microsoft\Windows\S endTo\Fax Recipient.lnk → C:\Windows\System32\WFS.exe (Microsoft Corporation) → /SendTo
                                ShortcutWithArgument: C:\Users\shrey\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Start Menu.lnk → C:\Users\shrey\AppData\Local\SweetLabs App Platform\Engine\ServiceHostApp.exe (Pokki) → /OPEN"menu"
                                ShortcutWithArgument: C:\Users\shrey\AppData\Local\Microsoft\Windows\Win X\Group3\04-1 - Network Connections.lnk → C:\Windows\explorer.exe (Microsoft Corporation) → ::{7007ACC7-3202-11D1-AAD2-00805FC1270E}
                                ShortcutWithArgument: C:\Users\shrey\AppData\Local\Microsoft\Windows\Win X\Group3\05 - Device Manager.lnk → C:\Windows\System32\control.exe (Microsoft Corporation) → /name Microsoft.DeviceManager
                                ShortcutWithArgument: C:\Users\shrey\AppData\Local\Microsoft\Windows\Win X\Group3\06 - System.lnk → C:\Windows\System32\control.exe (Microsoft Corporation) → /name Microsoft.System
                                ShortcutWithArgument: C:\Users\shrey\AppData\Local\Microsoft\Windows\Win X\Group3\08 - Power Options.lnk → C:\Windows\System32\control.exe (Microsoft Corporation) → /name Microsoft.PowerOptions
                                ShortcutWithArgument: C:\Users\shrey\AppData\Local\Microsoft\Windows\Win X\Group3\10 - Programs and Features.lnk → C:\Windows\System32\control.exe (Microsoft Corporation) → /name Microsoft.ProgramsAndFeatures
                                ShortcutWithArgument: C:\Users\shrey\AppData\Local\Microsoft\Windows\Win X\Group2\1 - Run.lnk → C:\Windows\explorer.exe (Microsoft Corporation) → shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}
                                ShortcutWithArgument: C:\Users\shrey\AppData\Local\Microsoft\Windows\Win X\Group2\2 - Search.lnk → C:\Windows\explorer.exe (Microsoft Corporation) → shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0}
                                ShortcutWithArgument: C:\Users\shrey\AppData\Local\Microsoft\Windows\Win X\Group2\3 - Windows Explorer.lnk → C:\Windows\explorer.exe (Microsoft Corporation) → /e,::{20D04FE0-3AEA-1069-A2D8-08002B30309D}
                                ShortcutWithArgument: C:\Users\shrey\AppData\Local\Microsoft\Windows\Win X\Group2\5 - Task Manager.lnk → C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) → /0
                                ShortcutWithArgument: C:\Users\shrey\AppData\Local\Microsoft\Windows\Win X\Group1\1 - Desktop.lnk → C:\Windows\explorer.exe (Microsoft Corporation) → shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257}
                                CMD: netsh advfirewall reset
                                CMD: ipconfig /flushdns
                                CMD: netsh winsock reset catalog
                                CMD: netsh int ip reset c:\resetlog.txt
                                CMD: ipconfig /release
                                CMD: ipconfig /renew
                                CMD: netsh int ipv4 reset
                                CMD: netsh int ipv6 reset
                                CMD: bitsadmin /reset /allusers
                                reboot:
                                End


                                Processes closed successfully.
                                Restore point was successfully created.

                                ========= RemoveProxy: =========

                                HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\Curren tVersion\Internet Settings\Connections\DefaultConnectionSettings => value removed successfully
                                HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\Curren tVersion\Internet Settings\Connections\SavedLegacySettings => value removed successfully
                                HKU.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVers ion\Internet Settings\Connections\DefaultConnectionSettings => value removed successfully
                                HKU.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVers ion\Internet Settings\Connections\SavedLegacySettings => value removed successfully
                                HKU\S-1-5-21-1605944295-1278072363-3366277582-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Int ernet Settings\Connections\DefaultConnectionSettings => value removed successfully
                                HKU\S-1-5-21-1605944295-1278072363-3366277582-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Int ernet Settings\Connections\SavedLegacySettings => value removed successfully
                                HKU\S-1-5-21-1605944295-1278072363-3366277582-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Int ernet Settings\Connections\DefaultConnectionSettings => value removed successfully
                                HKU\S-1-5-21-1605944295-1278072363-3366277582-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Int ernet Settings\Connections\SavedLegacySettings => value removed successfully

                                ========= End of RemoveProxy: =========

                                HKLM\Software\WOW6432Node\Microsoft\Windows\Curren tVersion\Run\SunJavaUpdateSched => value removed successfully
                                HKU\S-1-5-21-1605944295-1278072363-3366277582-1001\Software\Microsoft\Windows\CurrentVersion\Run \AZ3Tq5k16l3MBynp => value not found.
                                “C:\Users\HP-PC\AppData\Roaming\AZ3Tq5k16l3MBynp.hta” => not found.
                                HKU\S-1-5-21-1605944295-1278072363-3366277582-1001\Software\Microsoft\Windows\CurrentVersion\Run \GoogleChromeAutoLaunch_7F0416C691E452253BB89BC2BE 6D7727 => value removed successfully
                                HKU\S-1-5-21-1605944295-1278072363-3366277582-1001\Software\Microsoft\Windows\CurrentVersion\Run Once\Application Restart #7 => value removed successfully
                                HKU\S-1-5-21-1605944295-1278072363-3366277582-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\MountPoints2{52f96c0f-4b14-11e6-82cb-020046a23e01} => key removed successfully
                                HKCR\CLSID{52f96c0f-4b14-11e6-82cb-020046a23e01} => key not found.
                                HKU\S-1-5-21-1605944295-1278072363-3366277582-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\MountPoints2{6d4daa1b-2812-11e4-8266-a02bb859a5c2} => key removed successfully
                                HKCR\CLSID{6d4daa1b-2812-11e4-8266-a02bb859a5c2} => key not found.
                                HKU\S-1-5-21-1605944295-1278072363-3366277582-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\MountPoints2{fddc09cc-da5b-11e3-825b-806e6f6e6963} => key removed successfully
                                HKCR\CLSID{fddc09cc-da5b-11e3-825b-806e6f6e6963} => key not found.
                                HKU\S-1-5-21-1605944295-1278072363-3366277582-1005\Software\Microsoft\Windows\CurrentVersion\Run \Pokki => value not found.
                                “C:\Users\HP-PC\AppData\Local\SweetLabs App Platform” => not found.
                                C:\Users\183-k\AppData\Local\RescueTime\RescueTime.exe => not found.
                                HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Pa rameters\NameSpace_Catalog5\Catalog_Entries\000000 000008 => key removed successfully
                                HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Pa rameters\NameSpace_Catalog5\Catalog_Entries\000000 000009 => key removed successfully
                                HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Pa rameters\NameSpace_Catalog5\Catalog_Entries64\0000 00000008 => key removed successfully
                                HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Pa rameters\NameSpace_Catalog5\Catalog_Entries64\0000 00000009 => key removed successfully
                                HKLM\System\CurrentControlSet\Services\Tcpip\Param eters\DhcpNameServer => value removed successfully
                                HKLM\System\CurrentControlSet\Services\Tcpip\Param eters\Interfaces{346CCC8E-0B21-4061-9284-6EAA8587D1B6}\DhcpNameServer => value not found.
                                HKLM\System\CurrentControlSet\Services\Tcpip\Param eters\Interfaces{D8CDCD34-1927-4308-BFA6-CD78629C69FD}\DhcpNameServer => value removed successfully
                                HKLM\Software\Microsoft\Internet Explorer\Main\Start Page => value restored successfully
                                HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\Start Page => value restored successfully
                                HKLM\Software\Microsoft\Internet Explorer\Main\Default_Page_URL => value restored successfully
                                HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\Default_Page_URL => value restored successfully
                                HKU\S-1-5-21-1605944295-1278072363-3366277582-1001\Software\Microsoft\Internet Explorer\Main\Default_Page_URL => value restored successfully
                                HKU\S-1-5-21-1605944295-1278072363-3366277582-1005\Software\Microsoft\Internet Explorer\Main\Default_Page_URL => value restored successfully
                                HKU\S-1-5-21-1605944295-1278072363-3366277582-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes{ED62CEEF-D711-461D-8D9E-9ACA3F0E3A2A} => key removed successfully
                                HKCR\CLSID{ED62CEEF-D711-461D-8D9E-9ACA3F0E3A2A} => key not found.
                                HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects{2E38825B-8815-42CF-9126-C58BC28D4591} => key removed successfully
                                HKCR\CLSID{2E38825B-8815-42CF-9126-C58BC28D4591} => key not found.
                                HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} => key removed successfully
                                HKCR\CLSID{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} => key not found.
                                HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} => key not found.
                                HKCR\CLSID{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} => key not found.
                                HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects{DBC80044-A445-435b-BC74-9C25C1C588A9} => key removed successfully
                                HKCR\CLSID{DBC80044-A445-435b-BC74-9C25C1C588A9} => key not found.
                                HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects{E76FD755-C1BA-4DCB-9F13-99BD91223ADE} => key removed successfully
                                HKCR\CLSID{E76FD755-C1BA-4DCB-9F13-99BD91223ADE} => key not found.
                                HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\Curren tVersion\Explorer\Browser Helper Objects{2E38825B-8815-42CF-9126-C58BC28D4591} => key removed successfully
                                HKCR\Wow6432Node\CLSID{2E38825B-8815-42CF-9126-C58BC28D4591} => key not found.
                                HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\Curren tVersion\Explorer\Browser Helper Objects{72853161-30C5-4D22-B7F9-0BBC1D38A37E} => key removed successfully
                                HKCR\Wow6432Node\CLSID{72853161-30C5-4D22-B7F9-0BBC1D38A37E} => key not found.
                                HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\Curren tVersion\Explorer\Browser Helper Objects{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} => key not found.
                                HKCR\Wow6432Node\CLSID{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} => key not found.
                                HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\Curren tVersion\Explorer\Browser Helper Objects{92EF2EAD-A7CE-4424-B0DB-499CF856608E} => key removed successfully
                                HKCR\Wow6432Node\CLSID{92EF2EAD-A7CE-4424-B0DB-499CF856608E} => key not found.
                                HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\Curren tVersion\Explorer\Browser Helper Objects{E76FD755-C1BA-4DCB-9F13-99BD91223ADE} => key removed successfully
                                HKCR\Wow6432Node\CLSID{E76FD755-C1BA-4DCB-9F13-99BD91223ADE} => key not found.
                                HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{093F479D-712E-46CD-9E06-62E734A05F68} => value removed successfully
                                HKCR\CLSID{093F479D-712E-46CD-9E06-62E734A05F68} => key not found.
                                HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{093F479D-712E-46CD-9E06-62E734A05F68} => value removed successfully
                                HKCR\Wow6432Node\CLSID{093F479D-712E-46CD-9E06-62E734A05F68} => key not found.
                                C:\Users\183-k\AppData\Roaming\Profiles\iyrqfjx7.default => path removed successfully
                                Firefox DefaultSearchEngine removed successfully
                                Firefox SelectedSearchEngine removed successfully
                                Firefox SearchEngineOrder.3 removed successfully
                                Firefox “Keyword.URL” removed successfully
                                Firefox “homepage” removed successfully
                                “C:\Users\183-k\AppData\Roaming\Mozilla\Firefox\Profiles\yt5wm08 v.default\searchplugins\bingp.xml” => not found.
                                HKLM\Software\Mozilla\Firefox\Extensions\wrc@avast.com => value not found.
                                HKLM\Software\Mozilla\Firefox\Extensions\sp@avast.com => value not found.
                                HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensio ns\wrc@avast.com => value not found.
                                HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensio ns\sp@avast.com => value not found.
                                C:\Program Files (x86)\mozilla firefox\searchplugins\answers.xml => moved successfully
                                C:\Program Files (x86)\mozilla firefox\searchplugins\creativecommons.xml => moved successfully
                                HKLM\System\CurrentControlSet\Services\aswbdisk => key removed successfully
                                aswbdisk => service removed successfully
                                HKLM\System\CurrentControlSet\Services\mdareDriver _48 => key removed successfully
                                mdareDriver_48 => service removed successfully
                                HKLM\System\CurrentControlSet\Services\mdareDriver _52 => key removed successfully
                                mdareDriver_52 => service removed successfully
                                HKLM\System\CurrentControlSet\Services\mdareDriver _53 => key removed successfully
                                mdareDriver_53 => service removed successfully
                                HKLM\System\CurrentControlSet\Services\mdareDriver _60 => key removed successfully
                                mdareDriver_60 => service removed successfully
                                HKLM\System\CurrentControlSet\Services\mdareDriver _61 => key removed successfully
                                mdareDriver_61 => service removed successfully
                                HKLM\System\CurrentControlSet\Services\mdareDriver _62 => key removed successfully
                                mdareDriver_62 => service removed successfully
                                aswMBR => service not found.
                                “C:\Users\183-k\AppData\Roaming\Enigma Software Group” => not found.
                                “C:\Program Files\Enigma Software Group” => not found.
                                C:\sh4ldr => moved successfully
                                C:\Windows\System32\Tasks\BDAntiCryptoWallTask => moved successfully
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BDAntiRansomware => moved successfully
                                C:\Program Files\Bitdefender => moved successfully
                                “C:\Users\HP-PC\AppData\Roaming\AZ3Tq5k16l3MBynp.hta” => not found.
                                C:\Users\HP-PC\AppData\Roaming\errlog.txt => moved successfully
                                C:\Users\HP-PC\AppData\Roaming\AZ3Tq5k16l3MBynp.afn => moved successfully
                                C:\Users\HP-PC\AppData\Roaming\AZ3Tq5k16l3MBynp.ast => moved successfully
                                “C:\Users\HP-PC\AppData\Roaming\AZ3Tq5k16l3MBynp” => not found.
                                HKU\S-1-5-21-1605944295-1278072363-3366277582-1001_Classes\CLSID{0F22A205-CFB0-4679-8499-A6F44A80A208} => key removed successfully
                                HKU\S-1-5-21-1605944295-1278072363-3366277582-1001_Classes\CLSID{1423F872-3F7F-4E57-B621-8B1A9D49B448} => key removed successfully
                                HKU\S-1-5-21-1605944295-1278072363-3366277582-1001_Classes\CLSID{590C4387-5EBD-4D46-8A84-CD0BA2EF2856} => key removed successfully
                                HKU\S-1-5-21-1605944295-1278072363-3366277582-1001_Classes\CLSID{59B55F04-DE14-4BB8-92FF-C4A22EF2E5F4} => key removed successfully
                                HKU\S-1-5-21-1605944295-1278072363-3366277582-1001_Classes\CLSID{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E} => key removed successfully
                                HKU\S-1-5-21-1605944295-1278072363-3366277582-1001_Classes\CLSID{78550997-5DEF-4A8A-BAF9-D5774E87AC98} => key removed successfully
                                HKU\S-1-5-21-1605944295-1278072363-3366277582-1001_Classes\CLSID{793EE463-1304-471C-ADF1-68C2FFB01247} => key removed successfully
                                HKU\S-1-5-21-1605944295-1278072363-3366277582-1001_Classes\CLSID{90B3DFBF-AF6A-4EA0-8899-F332194690F8} => key removed successfully
                                HKU\S-1-5-21-1605944295-1278072363-3366277582-1001_Classes\CLSID{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A} => key removed successfully
                                HKU\S-1-5-21-1605944295-1278072363-3366277582-1001_Classes\CLSID{CC182BE1-84CE-4A57-B85C-FD4BBDF78CB2} => key removed successfully
                                HKU\S-1-5-21-1605944295-1278072363-3366277582-1001_Classes\CLSID{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9} => key removed successfully
                                HKU\S-1-5-21-1605944295-1278072363-3366277582-1001_Classes\CLSID{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF} => key removed successfully
                                HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon{0219BF6 B-4691-4A8B-B178-56FFF61475DE} => key removed successfully
                                HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{0219BF6 B-4691-4A8B-B178-56FFF61475DE} => key removed successfully
                                C:\Windows\System32\Tasks\YCMServiceAgent => moved successfully
                                HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\YCMServi ceAgent => key removed successfully
                                HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon{1A86372 6-086B-42F3-ACBC-DF6752958E12} => key removed successfully
                                HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{1A86372 6-086B-42F3-ACBC-DF6752958E12} => key removed successfully
                                C:\Windows\System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => moved successfully
                                HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => key removed successfully
                                HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{29A4685 3-9769-454D-AFF2-430468021DE2} => key not found.
                                C:\Windows\System32\Tasks\SweetLabs App Platform => not found.
                                HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SweetLab s App Platform => key not found.
                                HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{5F2066D B-0217-4F83-BBE9-E38D888098E9} => key removed successfully
                                HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{5F2066D B-0217-4F83-BBE9-E38D888098E9} => key removed successfully
                                C:\Windows\System32\Tasks\SDMsgUpdate (TE) => moved successfully
                                HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SDMsgUpd ate (TE) => key removed successfully
                                HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{61AAE42 4-B58F-4FD8-821A-6461A83209F1} => key removed successfully
                                HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{61AAE42 4-B58F-4FD8-821A-6461A83209F1} => key removed successfully
                                C:\Windows\System32\Tasks\SDMsgUpdate (Local) => moved successfully
                                HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SDMsgUpd ate (Local) => key removed successfully
                                HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon{8D3CE45 B-EA58-4026-9922-10070FD498E3} => key removed successfully
                                HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{8D3CE45 B-EA58-4026-9922-10070FD498E3} => key removed successfully
                                C:\Windows\System32\Tasks\BDAntiCryptoWallTask => not found.
                                HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BDAntiCr yptoWallTask => key removed successfully
                                HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{A1095FF C-DFCF-4D22-BD61-A029EF25DB12} => key removed successfully
                                HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{A1095FF C-DFCF-4D22-BD61-A029EF25DB12} => key removed successfully
                                C:\Windows\System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => moved successfully
                                HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Hewlett-Packard\HP Support Assistant\Update Check => key removed successfully
                                HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{B69BDAE C-684E-4604-9A48-DF14EC6CCA42} => key removed successfully
                                HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{B69BDAE C-684E-4604-9A48-DF14EC6CCA42} => key removed successfully
                                C:\Windows\System32\Tasks\TinyTakeUpgrade => moved successfully
                                HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\TinyTake Upgrade => key removed successfully
                                HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon{DF38DFA 3-8A2A-4F3D-A6DB-79F757FF401F} => key removed successfully
                                HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{DF38DFA 3-8A2A-4F3D-A6DB-79F757FF401F} => key removed successfully
                                C:\Windows\System32\Tasks\Adobe Acrobat Update Task => moved successfully
                                HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Acrobat Update Task => key removed successfully
                                HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{FE079EE 5-FAC7-47D1-8254-37B606874DCD} => key removed successfully
                                HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{FE079EE 5-FAC7-47D1-8254-37B606874DCD} => key removed successfully
                                C:\Windows\System32\Tasks\HPCeeScheduleForHP-PC => moved successfully
                                HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HPCeeSch eduleForHP-PC => key removed successfully
                                HKLM\System\CurrentControlSet\Control\SafeBoot\Min imal\mcpltsvc => key removed successfully
                                HKLM\System\CurrentControlSet\Control\SafeBoot\Net work\mcpltsvc => key removed successfully
                                C:\Windows\system32\Drivers\etc\hosts => moved successfully
                                Hosts restored successfully.
                                HKLM\SYSTEM\CurrentControlSet\services\SharedAcces s\Parameters\FirewallPolicy\FirewallRules\vm-monitoring-nb-session => value removed successfully
                                HKLM\SYSTEM\CurrentControlSet\services\SharedAcces s\Parameters\FirewallPolicy\FirewallRules\{64B9D50 2-F2A9-4D07-B273-49337AF2CD3C} => value removed successfully
                                HKLM\SYSTEM\CurrentControlSet\services\SharedAcces s\Parameters\FirewallPolicy\FirewallRules\{D94E5D3 0-5E92-4364-BBAD-3AA9C3B43892} => value removed successfully
                                HKLM\SYSTEM\CurrentControlSet\services\SharedAcces s\Parameters\FirewallPolicy\FirewallRules\{96188C5 0-7FD1-4C02-8BEE-F46247AA0F84} => value removed successfully
                                HKLM\SYSTEM\CurrentControlSet\services\SharedAcces s\Parameters\FirewallPolicy\FirewallRules\{F06983F C-8920-4F3D-AD39-3ED40BE5168B} => value removed successfully
                                HKLM\SYSTEM\CurrentControlSet\services\SharedAcces s\Parameters\FirewallPolicy\FirewallRules\{D2FB513 6-8CCA-4944-B878-5650789950DC} => value removed successfully
                                HKLM\SYSTEM\CurrentControlSet\services\SharedAcces s\Parameters\FirewallPolicy\FirewallRules\{1B7D9E6 0-79F4-4183-915B-91634E85450C} => value removed successfully
                                HKLM\SYSTEM\CurrentControlSet\services\SharedAcces s\Parameters\FirewallPolicy\FirewallRules\{6D61EDC 4-F73B-4414-8D90-AD7972CEB22D} => value removed successfully
                                HKLM\SYSTEM\CurrentControlSet\services\SharedAcces s\Parameters\FirewallPolicy\FirewallRules\{54CAF24 9-D498-4C7F-B8C4-C39F2E1BCE20} => value removed successfully
                                HKLM\SYSTEM\CurrentControlSet\services\SharedAcces s\Parameters\FirewallPolicy\FirewallRules\{99D6E21 E-92B1-423B-86AD-FB5FC8517AD8} => value removed successfully
                                HKLM\SYSTEM\CurrentControlSet\services\SharedAcces s\Parameters\FirewallPolicy\FirewallRules\TCP Query User{40384E5F-55E0-499D-9AEC-CA92286AD093}C:\program files (x86)\skype\phone\skype.exe => value removed successfully
                                HKLM\SYSTEM\CurrentControlSet\services\SharedAcces s\Parameters\FirewallPolicy\FirewallRules\UDP Query User{A93C04BE-3839-4F93-8564-C2766514A9AE}C:\program files (x86)\skype\phone\skype.exe => value removed successfully
                                HKLM\SYSTEM\CurrentControlSet\services\SharedAcces s\Parameters\FirewallPolicy\FirewallRules\{1A4F539 3-C5B1-4E5C-AE5B-214DC99F4B70} => value removed successfully
                                HKLM\SYSTEM\CurrentControlSet\services\SharedAcces s\Parameters\FirewallPolicy\FirewallRules\{2517537 D-6605-4903-8DCB-68E19BC804FF} => value removed successfully
                                HKLM\SYSTEM\CurrentControlSet\services\SharedAcces s\Parameters\FirewallPolicy\FirewallRules\TCP Query User{65B266A6-66D4-4E10-B23C-3FBD9B576A95}C:\users\hp-pc\appdata\local\google\chrome\application\chrome. exe => value removed successfully
                                HKLM\SYSTEM\CurrentControlSet\services\SharedAcces s\Parameters\FirewallPolicy\FirewallRules\UDP Query User{0C91A68E-1569-4DA7-8549-70DDEC003B4E}C:\users\hp-pc\appdata\local\google\chrome\application\chrome. exe => value removed successfully
                                HKLM\SYSTEM\CurrentControlSet\services\SharedAcces s\Parameters\FirewallPolicy\FirewallRules\{316F841 8-7F3F-4692-AE72-629A3DA48253} => value removed successfully
                                HKLM\SYSTEM\CurrentControlSet\services\SharedAcces s\Parameters\FirewallPolicy\FirewallRules\{EEC9BDE 7-52BB-4B9C-9419-E45B704D5D7C} => value removed successfully
                                HKLM\SYSTEM\CurrentControlSet\services\SharedAcces s\Parameters\FirewallPolicy\FirewallRules\{88E06CD D-9511-494A-BA9D-98F04B1AF38A} => value removed successfully
                                HKLM\SYSTEM\CurrentControlSet\services\SharedAcces s\Parameters\FirewallPolicy\FirewallRules\{D17EDF1 B-D27C-468B-A50A-8681D0C05702} => value removed successfully
                                HKLM\SYSTEM\CurrentControlSet\services\SharedAcces s\Parameters\FirewallPolicy\FirewallRules\{265A663 D-1E01-42C0-ADEE-9122EDF880AD} => value removed successfully
                                HKLM\SYSTEM\CurrentControlSet\services\SharedAcces s\Parameters\FirewallPolicy\FirewallRules\{6FD288F F-75F9-43D9-BB0C-A6244923910D} => value removed successfully
                                HKLM\SYSTEM\CurrentControlSet\services\SharedAcces s\Parameters\FirewallPolicy\FirewallRules\TCP Query User{5466A29F-7602-4701-8485-DE54D70CDB43}C:\program files (x86)\common files\research in motion\tunnel manager\peermanager.exe => value removed successfully
                                HKLM\SYSTEM\CurrentControlSet\services\SharedAcces s\Parameters\FirewallPolicy\FirewallRules\UDP Query User{AF38A96D-61F4-4485-BB03-843BDED0E84B}C:\program files (x86)\common files\research in motion\tunnel manager\peermanager.exe => value removed successfully
                                HKLM\SYSTEM\CurrentControlSet\services\SharedAcces s\Parameters\FirewallPolicy\FirewallRules\{C528124 0-DE99-43A1-A5E7-D10E4B3DFAB3} => value removed successfully
                                HKLM\SYSTEM\CurrentControlSet\services\SharedAcces s\Parameters\FirewallPolicy\FirewallRules\{EF83278 8-1AB2-43F4-A5F7-8623E4B65025} => value removed successfully
                                HKLM\SYSTEM\CurrentControlSet\services\SharedAcces s\Parameters\FirewallPolicy\FirewallRules\TCP Query User{0570EF7A-B81F-438A-9275-00DCFB086E90}C:\program files (x86)\connectify\connectify.exe => value removed successfully
                                HKLM\SYSTEM\CurrentControlSet\services\SharedAcces s\Parameters\FirewallPolicy\FirewallRules\UDP Query User{987B2294-3DF7-431A-94A1-70E71B31D31C}C:\program files (x86)\connectify\connectify.exe => value removed successfully
                                HKLM\SYSTEM\CurrentControlSet\services\SharedAcces s\Parameters\FirewallPolicy\FirewallRules\TCP Query User{599CDD59-2084-42C3-8439-2773CF39318B}C:\users\hp-pc\appdata\local\google\chrome\application\chrome. exe => value removed successfully
                                HKLM\SYSTEM\CurrentControlSet\services\SharedAcces s\Parameters\FirewallPolicy\FirewallRules\UDP Query User{44A31A6F-A90F-4A86-A40E-3BB028D870D9}C:\users\hp-pc\appdata\local\google\chrome\application\chrome. exe => value removed successfully
                                HKLM\SYSTEM\CurrentControlSet\services\SharedAcces s\Parameters\FirewallPolicy\FirewallRules\{FC773EC F-F98A-480C-99D5-412EDE318A0D} => value removed successfully
                                HKLM\SYSTEM\CurrentControlSet\services\SharedAcces s\Parameters\FirewallPolicy\FirewallRules\TCP Query User{4D4B1086-6642-4F0E-89FC-D3ED5034BA6E}C:\program files (x86)\common files\research in motion\tunnel manager\peermanager.exe => value removed successfully
                                HKLM\SYSTEM\CurrentControlSet\services\SharedAcces s\Parameters\FirewallPolicy\FirewallRules\UDP Query User{FD67FAE2-2BC5-42EC-B297-027A5F1BE508}C:\program files (x86)\common files\research in motion\tunnel manager\peermanager.exe => value removed successfully
                                HKLM\SYSTEM\CurrentControlSet\services\SharedAcces s\Parameters\FirewallPolicy\FirewallRules\{0AF9D8E 7-9842-41AE-95F2-9FBC5A93E355} => value removed successfully
                                C:\Users\183-k\Links\RecentPlaces.lnk => moved successfully
                                ἀ ฀ 刀攀挀攀渀琀 瀀氀愀挀攀猀 ⴀ Ѐ System Folder 匱卐檦⡣锽ᇒ횵쀀�퀘e ἀ ⤀ 㨀㨀笀㈀㈀㠀㜀㜀䄀㘀䐀ⴀ㌀㜀䄀㄀ⴀ㐀㘀㄀䄀ⴀ㤀㄀䈀 ⴀ䐀䈀䐀䄀㔀䄀䄀䔀䈀䌀㤀㤀紀 => Error: No automatic fix found for this entry.
                                C:\Users\183-k\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\QuickTime Player.lnk => moved successfully
                                C:\Users\183-k\AppData\Local\Microsoft\Windows\Application Shortcuts\microsoft.windowscommunicationsapps_8wek yb3d8bbwe\Microsoft.WindowsLive.Calendar.lnk => moved successfully
                                C:\Users\183-k\AppData\Local\Microsoft\Windows\Application Shortcuts\microsoft.windowscommunicationsapps_8wek yb3d8bbwe\Microsoft.WindowsLive.Mail.lnk => moved successfully
                                C:\Users\183-k\AppData\Local\Microsoft\Windows\Application Shortcuts\microsoft.windowscommunicationsapps_8wek yb3d8bbwe\Microsoft.WindowsLive.People.lnk => moved successfully
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Productivity and Tools\7-Zip File Manager.lnk => moved successfully
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Productivity and Tools\7-Zip Help.lnk => moved successfully
                                C:\Users\HP-PC\OneDrive\Google Chrome.lnk => moved successfully
                                C:\Users\HP-PC\OneDrive\BlueJ\Select VM.lnk => moved successfully
                                C:\Users\HP-PC\Links\RecentPlaces.lnk => moved successfully
                                ἀ ฀ 刀攀挀攀渀琀 瀀氀愀挀攀猀 ⴀ Ѐ System Folder 匱卐檦⡣锽ᇒ횵쀀�퀘e ἀ ⤀ 㨀㨀笀㈀㈀㠀㜀㜀䄀㘀䐀ⴀ㌀㜀䄀㄀ⴀ㐀㘀㄀䄀ⴀ㤀㄀䈀 ⴀ䐀䈀䐀䄀㔀䄀䄀䔀䈀䌀㤀㤀紀 => Error: No automatic fix found for this entry.
                                C:\Users\HP-PC\Documents\Corel\CorelDRAW X7 Samples\target.lnk => moved successfully
                                C:\Users\HP-PC\Documents\Corel\Corel PHOTO-PAINT X7 Samples\target.lnk => moved successfully
                                C:\Users\HP-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk => not found.
                                C:\Users\HP-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Menu.lnk => moved successfully
                                C:\Users\HP-PC\AppData\Local\Microsoft\Windows\ConnectedSearch \History\set_127180276_en-us.lnk => moved successfully
                                C:\Users\HP-PC\AppData\Local\Microsoft\Windows\ConnectedSearch \History\set_1281075515_en-us.lnk => moved successfully
                                0UCEJQ1SPSOh+'5Recovery optionsy1SPSLX㈷ZJ ZDɬ]C:\Users\HP-PC\AppData\Local\Packages\windows.immersivecontrol panel_cw5n1h2txyewy\LocalState\Indexed\Settings\en-US\AAA_SettingsPageRestoreRestore.settingcontent-ms1SPSjc(=O9.settingcontent-ms]C:\Users\HP-PC\AppData\Local\Packages\windows.immersivecontrol panel_cw5n1h2txyewy\LocalState\Indexed\Settings\en-US\AAA_SettingsPageRestoreRestore.settingcontent-msw1SPS0%G[ICODE] 5Recovery options@X1SPStk\;Co,oud1AAA_SettingsPageRestoreRes tore.settingcontent-ms1SPSiI~+.{F29F85E0-4FF9-1068-AB91-08002B27B3D9},6*{B725F130-47EF-101A-A5F1-02608C9EEBAC},10U1SPS<I]@;l9d.settingcontent-mse1SPS_ǵZeMJuEg$<ISettingsPageRestoreRestore1SPS@ >+lG7*"]C:\Users\HP-PC\AppData\Local\Packages\windows.immersivecontrol panel_cw5n1h2txyewy\LocalState\Indexed\Settings\en-US\AAA_SettingsPageRestoreRestore.settingcontent-msu1{1685D4AB-A51B-4AF1-A4E5-CEE87002431D}.Merge Any1SPSOh+'5Recovery options)1SPSMԆi<D*T)1SPSZAZHY$dy1SPSLX㈷ZJ ZDɬ]C:\Users\HP-PC\AppData\Local\Packages\windows.immersivecontrol panel_cw5n1h2txyewy\LocalState\Indexed\Settings\en-US\AAA_SettingsPageRestoreRestore.settingcontent-ms-1SPS[l#J[/ICODE]’Hdw1SPS0%G[ICODE] @X5Recovery options)1SPS՜.+,)1SPSmDpHH@.=xd]Q1SPSOh+'5Recovery options] (No File) => Error: No automatic fix found for this entry. C:\Users\HP-PC\AppData\Local\Microsoft\Windows\ConnectedSearch \History\set_2747713814_en-us.lnk => moved successfully C:\Users\HP-PC\AppData\Local\Microsoft\Windows\ConnectedSearch \History\set_3839032144_en-us.lnk => moved successfully C:\Users\HP-PC\AppData\Local\Microsoft\Windows\ConnectedSearch \History\txt_2093339993_en-US.lnk => moved successfully presentation 1 1卐卸杈祯䳞䶼反奃ᆯ餕 ἀ Ā => Error: No automatic fix found for this entry. C:\Users\HP-PC\AppData\Local\Microsoft\Windows\ConnectedSearch \History\txt_2119866019_en-US.lnk => moved successfully power point 1 1卐卸杈祯䳞䶼反奃ᆯ餕 ἀ Ā => Error: No automatic fix found for this entry. C:\Users\HP-PC\AppData\Local\Microsoft\Windows\ConnectedSearch \History\txt_2436336599_en-US.lnk => moved successfully bob dylan 1 1卐卸杈祯䳞䶼反奃ᆯ餕 ἀ Ā => Error: No automatic fix found for this entry. C:\Users\HP-PC\AppData\Local\Microsoft\Windows\ConnectedSearch \History\txt_2674333138_en-US.lnk => moved successfully Math type 1 1卐卸杈祯䳞䶼反奃ᆯ餕 ἀ Ā => Error: No automatic fix found for this entry. C:\Users\HP-PC\AppData\Local\Microsoft\Windows\ConnectedSearch \History\txt_989337498_en-US.lnk => moved successfully Mathtype 1 1卐卸杈祯䳞䶼反奃ᆯ餕 ἀ Ā => Error: No automatic fix found for this entry. C:\Users\HP-PC\AppData\Local\Microsoft\Windows\Application Shortcuts\Microsoft.WindowsReadingList_8wekyb3d8bb we\Microsoft.WindowsReadingList.lnk => moved successfully C:\Users\HP-PC\AppData\Local\Microsoft\Windows\Application Shortcuts\microsoft.windowscommunicationsapps_8wek yb3d8bbwe\Microsoft.WindowsLive.Calendar.lnk => moved successfully C:\Users\HP-PC\AppData\Local\Microsoft\Windows\Application Shortcuts\microsoft.windowscommunicationsapps_8wek yb3d8bbwe\Microsoft.WindowsLive.Mail.lnk => moved successfully C:\Users\HP-PC\AppData\Local\Microsoft\Windows\Application Shortcuts\microsoft.windowscommunicationsapps_8wek yb3d8bbwe\Microsoft.WindowsLive.People.lnk => moved successfully C:\Users\HP-PC\AppData\Local\Microsoft\Windows\Application Shortcuts\57405F7AB8904.MathLogicalTest_b55ywndse5 f8y\App.lnk => moved successfully C:\Users\shrey\Links\RecentPlaces.lnk => moved successfully ἀ ฀ 刀攀挀攀渀琀 瀀氀愀挀攀猀 ⴀ Ѐ System Folder 匱卐檦⡣锽ᇒ횵쀀�퀘e ἀ ⤀ 㨀㨀笀㈀㈀㠀㜀㜀䄀㘀䐀ⴀ㌀㜀䄀㄀ⴀ㐀㘀㄀䄀ⴀ㤀㄀䈀 ⴀ䐀䈀䐀䄀㔀䄀䄀䔀䈀䌀㤀㤀紀 => Error: No automatic fix found for this entry. C:\Users\shrey\AppData\Local\Microsoft\Windows\Con nectedSearch\History\set_1076774695_en-us.lnk => moved successfully ;UCEJ1SPSOh+'9Bluetooth settingsYadd addsbluetoothdevice devicesdisable disablesenable enablespair pairs print printer printers printingremove removessmartunpairaudiodiscover discoverskeyboard keyboardsMouse micephone phonesradio radiosspeaker speakerswireless-find finds}1SPSLX㈷ZJ ZDɬaC:\Users\shrey\AppData\Local\Packages\windows. immersivecontrolpanel_cw5n1h2txyewy\LocalState\Ind exed\Settings\en-US\AAA_SettingsPagePCSystemBluetooth.settingconten t-ms1SPSjc(=O9.settingcontent-msaC:\Users\shrey\AppData\Local\Packages\windows.i mmersivecontrolpanel_cw5n1h2txyewy\LocalState\Inde xed\Settings\en-US\AAA_SettingsPagePCSystemBluetooth.settingconten t-ms{1SPS0%G[/ICODE]9Bluetooth settings @X1SPStk;Co,oyd4AAA_SettingsPagePCSystemBluetooth. settingcontent-msF1SPSiI~+.{F29F85E0-4FF9-1068-AB91-08002B27B3D9},6*{F29F85E0-4FF9-1068-AB91-08002B27B3D9},24*{B725F130-47EF-101A-A5F1-02608C9EEBAC},10U1SPS<I]@;l9d.settingcontent-msi1SPS_ǵZeMJuEg$<MSettingsPagePCSystemBluetooth1S PS@>+lG7*"aC:\Users\shrey\AppData\Local\Packages\w indows.immersivecontrolpanel_cw5n1h2txyewy\LocalSt ate\Indexed\Settings\en-US\AAA_SettingsPagePCSystemBluetooth.settingconten t-msu1{1685D4AB-A51B-4AF1-A4E5-CEE87002431D}.Merge Any1SPSOh+'Yadd addsbluetoothdevice devicesdisable disablesenable enablespair pairs print printer printers printingremove removessmartunpairaudiodiscover discoverskeyboard keyboardsMouse micephone phonesradio radiosspeaker speakerswireless9Bluetooth settings-find finds)1SPSMԆi<D*T)1SPSZAZHY$d}1SPSLX㈷ZJ ZDɬaC:\Users\shrey\AppData\Local\Packages\windows. immersivecontrolpanel_cw5n1h2txyewy\LocalState\Ind exed\Settings\en-US\AAA_SettingsPagePCSystemBluetooth.settingconten t-ms-1SPS[l#J[ICODE]'Hd{1SPS0%G[/ICODE] @X9Bluetooth settings)1SPS՜.+,)1SPSmDpHH@.=xdaU1SPSOh+'9Bluetoo th settings] (No File) => Error: No automatic fix found for this entry.
                                C:\Users\shrey\AppData\Local\Microsoft\Windows\Con nectedSearch\History\set_3054665329_en-us.lnk => moved successfully
                                C:\Users\shrey\AppData\Local\Microsoft\Windows\App lication Shortcuts\microsoft.windowscommunicationsapps_8wek yb3d8bbwe\Microsoft.WindowsLive.Calendar.lnk => moved successfully
                                C:\Users\shrey\AppData\Local\Microsoft\Windows\App lication Shortcuts\microsoft.windowscommunicationsapps_8wek yb3d8bbwe\Microsoft.WindowsLive.Mail.lnk => moved successfully
                                C:\Users\shrey\AppData\Local\Microsoft\Windows\App lication Shortcuts\microsoft.windowscommunicationsapps_8wek yb3d8bbwe\Microsoft.WindowsLive.People.lnk => moved successfully
                                C:\Users\183-k\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk => Shortcut argument removed successfully.
                                C:\Users\183-k\AppData\Roaming\Microsoft\Windows\SendTo\Skype.l nk => Shortcut argument removed successfully.
                                C:\Users\183-k\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Start Menu.lnk => not found.
                                C:\Users\183-k\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - Network Connections.lnk => Shortcut argument removed successfully.
                                C:\Users\183-k\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk => Shortcut argument removed successfully.
                                C:\Users\183-k\AppData\Local\Microsoft\Windows\WinX\Group3\06 - System.lnk => Shortcut argument removed successfully.
                                C:\Users\183-k\AppData\Local\Microsoft\Windows\WinX\Group3\08 - Power Options.lnk => Shortcut argument removed successfully.
                                C:\Users\183-k\AppData\Local\Microsoft\Windows\WinX\Group3\10 - Programs and Features.lnk => Shortcut argument removed successfully.
                                C:\Users\183-k\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk => Shortcut argument removed successfully.
                                C:\Users\183-k\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk => Shortcut argument removed successfully.
                                C:\Users\183-k\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk => Shortcut argument removed successfully.
                                C:\Users\183-k\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk => Shortcut argument removed successfully.
                                C:\Users\183-k\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Microsoft\Windows\Start Menu\VIDLE for VPython.lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office.lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk => not found.
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Start Menu.lnk => not found.
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Default Programs.lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Task Manager.lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 2.7\IDLE (Python GUI).lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 2.7\Module Docs.lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 2.7\Uninstall Python.lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picasa 3\Configure Picasa Photo Viewer.lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox\Mozilla Firefox (Safe Mode).lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox\Mozilla Firefox.lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MathType 6\Equation Conversion Manager.lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MathType 6\MathType Server.lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MathType 6\Remove MathType.lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Total Security\Remove Kaspersky Total Security.lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Secure Connection\Kaspersky Secure Connection.lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Secure Connection\Remove Kaspersky Secure Connection.lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\About Java.lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Check For Updates.lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IB Questionbank\Questionbank Maths HL.lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IB Questionbank\Questionbank Physics.lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support\HP Recovery Manager\HP Recovery Media Creation.lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueJ\Select BlueJ VM.lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autograph 3.3\Help.lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autograph 3.3\Manual.lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Computer Management.lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Resource Monitor.lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Media Player.lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility\Speech Recognition.lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Microsoft\Windows\GameExplorer{d58e ecb0-0816-11de-8c30-0800200c9a66}\PlayTasks\0\provider.lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Microsoft\Windows\GameExplorer{b0e4 3195-dbe0-4647-8e23-84fc3b08cee9}\PlayTasks\0\web.lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Microsoft\Windows\GameExplorer{977b 5905-4d14-47f1-bbbf-7b92f596695d}\PlayTasks\0\provider.lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Microsoft\Windows\GameExplorer{7e00 8ca2-08ab-4789-af23-36da87658f74}\PlayTasks\0\web.lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Microsoft\Windows\GameExplorer{3eda 1e54-8889-41f5-a649-5a306789b7ef}\PlayTasks\0\provider.lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Microsoft\Windows\GameExplorer{2635 2374-af55-4b53-b07b-6b0288ed97df}\PlayTasks\0\provider.lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Microsoft\Windows\GameExplorer{000d 96f5-8034-4b74-a429-b6f0b04c75f4}\PlayTasks\0\provider.lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Hewlett-Packard\Recovery\Links\Apps.lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Hewlett-Packard\Recovery\Links\BTR.lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Hewlett-Packard\Recovery\Links\Driver.lnk => Shortcut argument removed successfully.
                                C:\ProgramData\Hewlett-Packard\Recovery\Links\RMC.lnk => Shortcut argument removed successfully.
                                C:\Users\Default\AppData\Roaming\Microsoft\Windows \SendTo\Fax Recipient.lnk => Shortcut argument removed successfully.
                                C:\Users\Default\AppData\Local\Microsoft\Windows\W inX\Group3\04-1 - Network Connections.lnk => Shortcut argument removed successfully.
                                C:\Users\Default\AppData\Local\Microsoft\Windows\W inX\Group3\05 - Device Manager.lnk => Shortcut argument removed successfully.
                                C:\Users\Default\AppData\Local\Microsoft\Windows\W inX\Group3\06 - System.lnk => Shortcut argument removed successfully.
                                C:\Users\Default\AppData\Local\Microsoft\Windows\W inX\Group3\08 - Power Options.lnk => Shortcut argument removed successfully.
                                C:\Users\Default\AppData\Local\Microsoft\Windows\W inX\Group3\10 - Programs and Features.lnk => Shortcut argument removed successfully.
                                C:\Users\Default\AppData\Local\Microsoft\Windows\W inX\Group2\1 - Run.lnk => Shortcut argument removed successfully.
                                C:\Users\Default\AppData\Local\Microsoft\Windows\W inX\Group2\2 - Search.lnk => Shortcut argument removed successfully.
                                C:\Users\Default\AppData\Local\Microsoft\Windows\W inX\Group2\3 - Windows Explorer.lnk => Shortcut argument removed successfully.
                                C:\Users\Default\AppData\Local\Microsoft\Windows\W inX\Group2\5 - Task Manager.lnk => Shortcut argument removed successfully.
                                C:\Users\Default\AppData\Local\Microsoft\Windows\W inX\Group1\1 - Desktop.lnk => Shortcut argument removed successfully.
                                C:\Users\HP-PC\OneDrive\IB Question Banks\Questionbank Chemistry.lnk => Shortcut argument removed successfully.
                                C:\Users\HP-PC\OneDrive\IB Question Banks\Questionbank Maths HL.lnk => Shortcut argument removed successfully.
                                C:\Users\HP-PC\OneDrive\IB Question Banks\Questionbank Physics.lnk => Shortcut argument removed successfully.
                                C:\Users\HP-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SML of New Jersey (2).lnk => Shortcut argument removed successfully.
                                C:\Users\HP-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SML of New Jersey.lnk => Shortcut argument removed successfully.
                                C:\Users\HP-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk => Shortcut argument removed successfully.
                                C:\Users\HP-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RescueTime.lnk => Shortcut argument removed successfully.
                                C:\Users\HP-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MiKTeX 2.9\Maintenance\MiKTeX Update.lnk => Shortcut argument removed successfully.
                                C:\Users\HP-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Multi messenger.lnk => Shortcut argument removed successfully.
                                C:\Users\HP-PC\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk => Shortcut argument removed successfully.
                                C:\Users\HP-PC\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk => Shortcut argument removed successfully.
                                C:\Users\HP-PC\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Media Player.lnk => Shortcut argument removed successfully.
                                C:\Users\HP-PC\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - Network Connections.lnk => Shortcut argument removed successfully.
                                C:\Users\HP-PC\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk => Shortcut argument removed successfully.
                                C:\Users\HP-PC\AppData\Local\Microsoft\Windows\WinX\Group3\06 - System.lnk => Shortcut argument removed successfully.
                                C:\Users\HP-PC\AppData\Local\Microsoft\Windows\WinX\Group3\08 - Power Options.lnk => Shortcut argument removed successfully.
                                C:\Users\HP-PC\AppData\Local\Microsoft\Windows\WinX\Group3\10 - Programs and Features.lnk => Shortcut argument removed successfully.
                                C:\Users\HP-PC\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk => Shortcut argument removed successfully.
                                C:\Users\HP-PC\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk => Shortcut argument removed successfully.
                                C:\Users\HP-PC\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk => Shortcut argument removed successfully.
                                C:\Users\HP-PC\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk => Shortcut argument removed successfully.
                                C:\Users\HP-PC\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk => Shortcut argument removed successfully.
                                C:\Users\Public\Desktop\Kaspersky Secure Connection.lnk => Shortcut argument removed successfully.
                                C:\Users\Public\Desktop\Mozilla Firefox.lnk => Shortcut argument removed successfully.
                                C:\Users\Public\Desktop\Questionbank Maths HL.lnk => Shortcut argument removed successfully.
                                C:\Users\Public\Desktop\Questionbank Physics.lnk => Shortcut argument removed successfully.
                                C:\Users\Public\Desktop\Safe Money.lnk => Shortcut argument removed successfully.
                                C:\Users\Public\Desktop\VIDLE for VPython.lnk => Shortcut argument removed successfully.
                                C:\Users\shrey\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\FarmVille 2.lnk => Shortcut argument removed successfully.
                                C:\Users\shrey\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\PC App Store.lnk => not found.
                                C:\Users\shrey\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Start Menu.lnk => Shortcut argument removed successfully.
                                C:\Users\shrey\AppData\Roaming\Microsoft\Windows\S endTo\Fax Recipient.lnk => Shortcut argument removed successfully.
                                C:\Users\shrey\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Start Menu.lnk => Shortcut argument removed successfully.
                                C:\Users\shrey\AppData\Local\Microsoft\Windows\Win X\Group3\04-1 - Network Connections.lnk => Shortcut argument removed successfully.
                                C:\Users\shrey\AppData\Local\Microsoft\Windows\Win X\Group3\05 - Device Manager.lnk => Shortcut argument removed successfully.
                                C:\Users\shrey\AppData\Local\Microsoft\Windows\Win X\Group3\06 - System.lnk => Shortcut argument removed successfully.
                                C:\Users\shrey\AppData\Local\Microsoft\Windows\Win X\Group3\08 - Power Options.lnk => Shortcut argument removed successfully.
                                C:\Users\shrey\AppData\Local\Microsoft\Windows\Win X\Group3\10 - Programs and Features.lnk => Shortcut argument removed successfully.
                                C:\Users\shrey\AppData\Local\Microsoft\Windows\Win X\Group2\1 - Run.lnk => Shortcut argument removed successfully.
                                C:\Users\shrey\AppData\Local\Microsoft\Windows\Win X\Group2\2 - Search.lnk => Shortcut argument removed successfully.
                                C:\Users\shrey\AppData\Local\Microsoft\Windows\Win X\Group2\3 - Windows Explorer.lnk => Shortcut argument removed successfully.
                                C:\Users\shrey\AppData\Local\Microsoft\Windows\Win X\Group2\5 - Task Manager.lnk => Shortcut argument removed successfully.
                                C:\Users\shrey\AppData\Local\Microsoft\Windows\Win X\Group1\1 - Desktop.lnk => Shortcut argument removed successfully.

                                ========= netsh advfirewall reset =========

                                Initialization Function InitHelperDll in NSHHTTP.DLL failed to start with error code 11003
                                Ok.

                                ========= End of CMD: =========

                                ========= ipconfig /flushdns =========

                                Windows IP Configuration

                                Successfully flushed the DNS Resolver Cache.

                                ========= End of CMD: =========

                                ========= netsh winsock reset catalog =========

                                Initialization Function InitHelperDll in NSHHTTP.DLL failed to start with error code 11003

                                Sucessfully reset the Winsock Catalog.
                                You must restart the computer in order to complete the reset.

                                ========= End of CMD: =========

                                ========= netsh int ip reset c:\resetlog.txt =========

                                Initialization Function InitHelperDll in NSHHTTP.DLL failed to start with error code 11003
                                Resetting Global, OK!
                                Resetting Interface, OK!
                                Resetting Unicast Address, OK!
                                Resetting Neighbor, OK!
                                Resetting Path, OK!
                                Resetting , failed.
                                Access is denied.

                                Resetting , OK!
                                Restart the computer to complete this action.

                                ========= End of CMD: =========

                                ========= ipconfig /release =========

                                Windows IP Configuration

                                No operation can be performed on Ethernet 2 while it has its media disconnected.
                                No operation can be performed on Local Area Connection 3 while it has its media disconnected.
                                No operation can be performed on Ethernet while it has its media disconnected.

                                Ethernet adapter Ethernet 2:

                                Media State . . . . . . . . . . . : Media disconnected
                                Connection-specific DNS Suffix . :

                                Tunnel adapter Local Area Connection 3:

                                Media State . . . . . . . . . . . : Media disconnected
                                Connection-specific DNS Suffix . :

                                Ethernet adapter Ethernet:

                                Media State . . . . . . . . . . . : Media disconnected
                                Connection-specific DNS Suffix . :

                                Wireless LAN adapter Wi-Fi:

                                Connection-specific DNS Suffix . :
                                Default Gateway . . . . . . . . . :

                                ========= End of CMD: =========

                                ========= ipconfig /renew =========

                                Windows IP Configuration

                                No operation can be performed on Ethernet 2 while it has its media disconnected.
                                No operation can be performed on Local Area Connection 3 while it has its media disconnected.
                                No operation can be performed on Ethernet while it has its media disconnected.

                                Ethernet adapter Ethernet 2:

                                Media State . . . . . . . . . . . : Media disconnected
                                Connection-specific DNS Suffix . :

                                Tunnel adapter Local Area Connection 3:

                                Media State . . . . . . . . . . . : Media disconnected
                                Connection-specific DNS Suffix . :

                                Ethernet adapter Ethernet:

                                Media State . . . . . . . . . . . : Media disconnected
                                Connection-specific DNS Suffix . :

                                Wireless LAN adapter Wi-Fi:

                                Connection-specific DNS Suffix . : dlink.router
                                IPv4 Address. . . . . . . . . . . : 192.168.0.100
                                Subnet Mask . . . . . . . . . . . : 255.255.255.0
                                Default Gateway . . . . . . . . . : 192.168.0.1

                                ========= End of CMD: =========

                                ========= netsh int ipv4 reset =========

                                Initialization Function InitHelperDll in NSHHTTP.DLL failed to start with error code 11003
                                Resetting Interface, OK!
                                Resetting , failed.
                                Access is denied.

                                Restart the computer to complete this action.

                                ========= End of CMD: =========

                                ========= netsh int ipv6 reset =========

                                Initialization Function InitHelperDll in NSHHTTP.DLL failed to start with error code 11003
                                Resetting Interface, OK!
                                Resetting Neighbor, OK!
                                Resetting Path, OK!
                                Resetting , failed.
                                Access is denied.

                                Resetting , OK!
                                Resetting , OK!
                                Restart the computer to complete this action.

                                ========= End of CMD: =========

                                ========= bitsadmin /reset /allusers =========

                                BITSADMIN version 3.0 [ 7.7.9600 ]
                                BITS administration utility.
                                (C) Copyright 2000-2006 Microsoft Corp.

                                BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
                                Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

                                0 out of 0 jobs canceled.

                                ========= End of CMD: =========

                                =========== EmptyTemp: ==========

                                BITS transfer queue => 8388608 B
                                DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 28796747 B
                                Java, Flash, Steam htmlcache => 506 B
                                Windows/system/drivers => 362374133 B
                                Edge => 0 B
                                Chrome => 34470875 B
                                Firefox => 3248565 B
                                Opera => 0 B

                                Temp, IE cache, history, cookies, recent:
                                Default => 0 B
                                Users => 0 B
                                ProgramData => 0 B
                                Public => 0 B
                                systemprofile => 128 B
                                systemprofile32 => 129 B
                                LocalService => 3045644 B
                                NetworkService => 2993294 B
                                HP-PC => 3341559634 B
                                shrey => 593034863 B
                                183-k => 434309709 B

                                RecycleBin => 836827 B
                                EmptyTemp: => 4.5 GB temporary data Removed.

                                ================================

                                The system needed a reboot.

                                ==== End of Fixlog 11:37:45 ====

                                Comment

                                Working...