cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Resultado do exame da Farbar Recovery Scan Tool (FRST) (x64) Versão:24-05-2016
Executado por tlssa (administrador) em DESKTOP-EB41LQM (24-05-2016 15:18:54)
Executando a partir de C:\Users\tlssa\Desktop
Perfis Carregados: tlssa (Perfis Disponíveis: tlssa)
Platform: Windows 10 Home Single Language Versão 1511 (X64) Idioma: Português (Brasil)
Internet Explorer Versão 11 (Navegador padrão: Edge)
Modo da Inicialização: Normal
Tutorial da Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processos (Whitelisted) =================

(Se uma entrada for incluída na fixlist, o processo será fechado. O arquivo não será movido.)

(GAS Tecnologia) C:\Program Files (x86)\GbPlugin\GbpSv.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(Advanced Micro Devices, Inc.) C:\Windows\syswow64\tbaseprovisioning.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
() C:\Program Files (x86)\5B4F747F-1464034689-39B6-0C3D-A4EFE8BE21AD\jnsg68CC.tmp
() C:\ProgramData\CloudPrinter\CloudPrinter.exe
() C:\Program Files (x86)\5B4F747F-1464034689-39B6-0C3D-A4EFE8BE21AD\hnsm9DD8.tmp
(pdfforge GmbH) C:\Program Files\PDF Architect 4\creator-ws.exe
(GAS Tecnologia LTDA) C:\Program Files\Diebold\Warsaw\core.exe
() C:\Users\tlssa\AppData\Roaming\Nadfik\Nadfik.exe
() C:\Users\tlssa\AppData\Roaming\Nadfik\Uydhquam.exe
() C:\Users\tlssa\AppData\Roaming\Nadfik\Gedfieyua.exe
(GAS Tecnologia) C:\Program Files (x86)\GbPlugin\GbpSv.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
() C:\Users\tlssa\AppData\Local\SunnyDay21\usun.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(GAS Tecnologia LTDA) C:\Program Files\Diebold\Warsaw\core.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_IATILDE.EXE
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\ProgramData\WindowsMsg\osmsg.exe
(Microsoft Corporation) C:\Windows\syswow64\dllhost.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\CSISYNCCLIENT.EXE
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\HelpPane.exe
() C:\Windows\Temp\FACC.tmp
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
() C:\Users\tlssa\AppData\Local\Apps\2.0\abril.exe
() C:\Program Files (x86)\5B4F747F-1464034689-39B6-0C3D-A4EFE8BE21AD\knsr56A3.tmp
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registro (Whitelisted) ===========================

(Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8790264 2016-03-29] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1416440 2016-03-29] (Realtek Semiconductor)
HKLM\...\Run: [Diebold - Warsaw] => C:\Program Files\Diebold\Warsaw\core.exe [904928 2015-11-04] (GAS Tecnologia LTDA)
HKLM\...\Run: [Sound+] => "C:\Program Files\Sound+\Sound+.exe"
HKLM\...\Run: [IDSCCOMNNC] => "C:\Program Files\Sound+\idsccom_NNC.exe"
HKLM-x32\...\Run: [sun21] => [X]
HKLM\...\RunOnce: [WINDOWS_SCREEN_MANAGER_UPDATER_1] => C:\Users\tlssa\AppData\Roaming\Hg1jb\Windows screen manage updater.exe [16896 2016-05-24] (Wizzservices)
HKLM-x32\...\RunOnce: [usun.exe] => C:\Users\tlssa\AppData\Local\SunnyDay21\usun.exe [3316224 2016-05-23] ()
HKLM-x32\...\RunOnce: [Update] => C:\Users\tlssa\AppData\Roaming\YSPackage\YSPackage.exe /runonce
Winlogon\Notify\ GbPluginCef: C:\Program Files (x86)\GbPlugin\gbiehCef.dll [2015-09-22] (Caixa Economica Federal)
HKU\S-1-5-21-3285026292-2124995477-3479667861-1001\...\Run: [EPLTarget\P0000000000000000] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATILDE.EXE [297024 2014-12-02] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-3285026292-2124995477-3479667861-1001\...\Run: [osmsg] => C:\ProgramData\WindowsMsg\osmsg.exe [2036224 2016-02-09] ()
HKU\S-1-5-21-3285026292-2124995477-3479667861-1001\...\RunOnce: [Uninstall C:\Users\tlssa\AppData\Local\Microsoft\OneDrive\17.3.6281.1202_1\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\tlssa\AppData\Local\Microsoft\OneDrive\17.3.6281.1202_1\amd64"
ShellExecuteHooks-x32: GbPluginObj Class - {E37CB5F0-51F5-4395-A808-5FA49E399003} - C:\Program Files (x86)\GbPlugin\gbiehcef.dll [1888480 2015-09-22] (Caixa Economica Federal)

==================== Internet (Whitelisted) ====================

(Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.)

AutoConfigURL: [S-1-5-21-3285026292-2124995477-3479667861-1001] => hxxp://unstops.biz/wpad.dat?da73761a801e29fe6fd8b5829499759010369169
Hosts: Há mais de uma entrada no Hosts. Veja a seção Hosts do Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{1cc7be83-4f1b-49d8-9b1c-f569306f0316}: [NameServer] 104.197.191.4
Tcpip\..\Interfaces\{2540a56c-1b0b-11e6-bafe-806e6f6e6963}: [NameServer] 104.197.191.4
Tcpip\..\Interfaces\{59643e05-5c0b-4c6e-9c64-00ba80fec0d4}: [NameServer] 104.197.191.4
Tcpip\..\Interfaces\{59643e05-5c0b-4c6e-9c64-00ba80fec0d4}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{97014cb7-0b83-415f-bdc1-e262278eeb71}: [NameServer] 104.197.191.4
Tcpip\..\Interfaces\{ac5399b6-1e9b-44cb-994f-477c06f8c674}: [NameServer] 104.197.191.4
Tcpip\..\Interfaces\{cb88d376-e19a-4de3-bd40-d410663542e9}: [NameServer] 104.197.191.4
ManualProxies: 0hxxp://unstops.biz/wpad.dat?da73761a801e29fe6fd8b5829499759010369169

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://br.hao123.com/?tn=sdkc_inner_hp_09_hao123_br&guid=4563067a8ac33f2185c5fa3d15ec91ee
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://br.hao123.com/?tn=sdkc_inner_hp_09_hao123_br&guid=4563067a8ac33f2185c5fa3d15ec91ee
HKU\S-1-5-21-3285026292-2124995477-3479667861-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBSiA1rEAocN4PQUCgaTJmbpk8E9Eu6ZCbL--mJjw_bvmj9S7q6F3boQiCR0I3Af8nOkY6FHFnz8uXmmtim6vqISuNhQJ_sUElJMdk1TyNVWPtz2AcVS8-klq23pG5ENjTcY2nNi5S6J0nZIqF_8gzV_1fHa39Gbg-pWPFrLRfcnrOSE40f4OjIM4s,&q={searchTerms}
HKU\S-1-5-21-3285026292-2124995477-3479667861-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://br.hao123.com/?tn=sdkc_inner_hp_09_hao123_br&guid=4563067a8ac33f2185c5fa3d15ec91ee
HKU\S-1-5-21-3285026292-2124995477-3479667861-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBSiA1rEAocN4PQUCgaTJmbpk8E9Eu6ZCbL--mJjw_bvmj9S7q6F3boQiCR0I3Af8nOkY6FHFnz8uXmmtim6vqISuNhQJ_sUElJMdk1TyNVWPtz2AcVS8-klq23pG5ENjTcY2nNi5S6J0nZIqF_8gzV_1fHa39Gbg-pWPFrLRfcnrOSE40f4OjIM4s,&q={searchTerms}
HKU\S-1-5-21-3285026292-2124995477-3479667861-1001\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBSiA1rEAocN4PQUCgaTJmbpk8E9Eu6ZCbL--mJjw_bvmj9S7q6F3boQiCR0I3Af8nOkY6FHFnz8uXmmtim6vqISuNhQJ_sUElJMdk1TyNVWPtz2AcVS8-klq23pG5ENjTcY2nNi5S6J0nZIqF_8gzV_1fHa39Gbg-pWPFrLRfcnrOSE40f4OjIM4s,&q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {ielnksrch} URL =
SearchScopes: HKLM-x32 -> ielnksrch URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBSiA1rEAocN4PQUCgaTJmbpk8E9Eu6ZCbL--mJjw_bvmj9S7q6F3boQiCR0I3Af8nOkY6FHFnz8uXmmtim6vqISuNhQJ_sUElJMdk1TyNVWPtz2AcVS8-klq23pG5ENjTcY2nNi5S6J0nZIqF_8gzV_1fHa39Gbg-pWPFrLRfcnrOSE40f4OjIM4s,&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3285026292-2124995477-3479667861-1001 -> {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBSiA1rEAocN4PQUCgaTJmbpk8E9Eu6ZCbL--mJjw_bvmj9S7q6F3boQiCR0I3Af8nOkY6FHFnz8uXmmtim6vqISuNhQJ_sUElJMdk1TyNVWPtz2AcVS8-klq23pG5ENjTcY2nNi5S6J0nZIqF_8gzV_1fHa39Gbg-pWPFrLRfcnrOSE40f4OjIM4s,&q={searchTerms}
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2016-05-15] (Microsoft Corporation)
BHO-x32: PDF Architect 4 Helper -> {38279E1A-7019-40C1-B579-E99DFB3312E8} -> C:\Program Files (x86)\PDF Architect 4\creator-ie-helper.dll [2016-05-04] (pdfforge GmbH)
BHO-x32: GbIehObj Class -> {C41A1C0E-EA6C-11D4-B1B8-444553540003} -> C:\Program Files (x86)\GbPlugin\gbiehcef.dll [2015-09-22] (Caixa Economica Federal)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL [2016-05-15] (Microsoft Corporation)
Toolbar: HKLM-x32 - PDF Architect 4 Toolbar - {23FD9C33-A9E1-48A1-8404-E5925CF1C8E1} - C:\Program Files (x86)\PDF Architect 4\creator-ie-plugin.dll [2016-05-04] (pdfforge GmbH)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2016-05-15] (Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2016-05-15] (Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2016-05-15] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2016-05-15] (Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2016-05-15] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2016-05-15] (Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2016-05-15] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2016-05-15] (Microsoft Corporation)

FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2016-05-15] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2016-05-15] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-15] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-15] (Google Inc.)
FF HKLM\...\Firefox\Extensions: [pdf_architect_4_conv@pdfarchitect.org] - C:\Program Files\PDF Architect 4\resources\pdfarchitect4firefoxextension
FF Extension: PDF Architect 4 Creator - C:\Program Files\PDF Architect 4\resources\pdfarchitect4firefoxextension [2016-05-23] [não assinado]

Chrome:
=======
CHR HomePage: ChromeDefaultData -> search.mpc.am
CHR StartupUrls: ChromeDefaultData -> "search.mpc.am"
CHR DefaultSearchURL: ChromeDefaultData -> hxxp://search.mpc.am?q={searchTerms}&cx=partner-pub-3796753109442372:3837783968
CHR DefaultSearchKeyword: ChromeDefaultData -> mpc safe search

==================== Serviços (Whitelisted) ========================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2911472 2016-05-15] (Microsoft Corporation)
R2 CloudPrinter; C:\ProgramData\\CloudPrinter\\CloudPrinter.exe [947712 2016-05-24] () [Arquivo não assinado]
R2 dowidoly; C:\Program Files (x86)\5B4F747F-1464034689-39B6-0C3D-A4EFE8BE21AD\jnsg68CC.tmp [244224 2016-05-23] () [Arquivo não assinado]
R2 GbpSv; C:\Program Files (x86)\GbPlugin\GbpSv.exe [593120 2015-09-22] (GAS Tecnologia)
S3 PDF Architect 4; C:\Program Files\PDF Architect 4\ws.exe [2438368 2016-05-04] (pdfforge GmbH)
S3 PDF Architect 4 CrashHandler; C:\Program Files\PDF Architect 4\crash-handler-ws.exe [1038048 2016-05-04] (pdfforge GmbH)
R2 PDF Architect 4 Creator; C:\Program Files\PDF Architect 4\creator-ws.exe [851168 2016-05-04] (pdfforge GmbH)
S2 plscmmService; C:\Program Files (x86)\Plsesh\plscmmService.exe [985752 2016-05-23] ()
R2 Pousvuo; C:\Users\tlssa\AppData\Roaming\Nadfik\Nadfik.exe [170496 2016-05-23] () [Arquivo não assinado]
S2 prhMngSrv; C:\Program Files (x86)\Prehuph\prhMngSrv.exe [984216 2016-05-23] ()
R2 ProntSpooler; C:\Users\tlssa\AppData\Local\Apps\2.0\abril.exe [130048 2016-04-23] () [Arquivo não assinado]
R2 rijufoze; C:\Program Files (x86)\5B4F747F-1464034689-39B6-0C3D-A4EFE8BE21AD\hnsm9DD8.tmp [138240 2016-05-23] () [Arquivo não assinado]
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [316152 2016-03-29] (Realtek Semiconductor)
R2 tbaseprovisioning; C:\Windows\SysWOW64\tbaseprovisioning.exe [60432 2015-06-23] (Advanced Micro Devices, Inc.)
R2 Warsaw Technology; C:\Program Files\Diebold\Warsaw\core.exe [904928 2015-11-04] (GAS Tecnologia LTDA)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
R2 wopoxyryzbt; C:\Program Files (x86)\5B4F747F-1464034689-39B6-0C3D-A4EFE8BE21AD\knsr56A3.tmp [144896 2016-05-24] () [Arquivo não assinado]
S2 Pojdh; "C:\Users\tlssa\AppData\Roaming\AtijLoep\Ukipp.exe" -cms [X]

===================== Drivers (Whitelisted) ==========================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

S3 amdkmcsp; C:\Windows\System32\drivers\amdkmcsp.sys [101104 2015-06-23] (Advanced Micro Devices, Inc. )
R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36608 2013-12-14] (Advanced Micro Devices, Inc.)
R0 amdpsp; C:\Windows\System32\drivers\amdpsp.sys [277240 2015-06-23] (Advanced Micro Devices, Inc. )
R3 athr; C:\Windows\System32\drivers\athw10x.sys [4318760 2015-08-28] (Qualcomm Atheros Communications, Inc.)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWT6.sys [102912 2015-05-28] (Advanced Micro Devices)
R1 cherimoya; C:\Windows\System32\drivers\cherimoya.sys [65344 2016-05-23] (Windows (R) Win 7 DDK provider)
S3 dg_ssudbus; C:\Windows\System32\drivers\ssudbus.sys [129152 2016-04-25] (Samsung Electronics Co., Ltd.)
R3 GBPRCM; C:\Program Files (x86)\GbPlugin\gbprcm64.sys [29912 2015-12-08] (GAS Tecnologia)
R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [311552 2015-11-04] (Realtek Semiconductor Corp.)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [943864 2016-03-23] (Realtek )
S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [221824 2016-04-25] (Samsung Electronics Co., Ltd.)
S3 ssudqcfilter; C:\Windows\System32\drivers\ssudqcfilter.sys [57648 2015-12-08] (QUALCOMM Incorporated)
S3 ssudserd; C:\Windows\System32\drivers\ssudserd.sys [221824 2016-04-25] (Samsung Electronics Co., Ltd.)
R3 Warsaw_PP; C:\Program Files (x86)\GbPlugin\wsftprp64.sys [24792 2015-12-08] (GAS Tecnologia LTDA)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
R4 WinDivert1.1; C:\Program Files\Diebold\Warsaw\WinDivert64.sys [38104 2015-07-07] (Basil)
R1 wsddfac; C:\Windows\System32\drivers\wsddfac.sys [101080 2016-05-24] (GAS Tecnologia)
R1 wsddpp; C:\WINDOWS\system32\drivers\wsddpp.sys [103640 2015-03-18] (GAS Tecnologia)
S1 gbpddfac; system32\drivers\gbpddfac64.sys [X]
S0 gbpddreg; system32\drivers\gbpddreg64.sys [X]
R1 MPCKpt; system32\DRIVERS\MPCKpt.sys [X]

==================== NetSvcs (Whitelisted) ===================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)


==================== Um Mês Criados arquivos e pastas ========

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2016-05-24 15:18 - 2016-05-24 15:19 - 00017677 _____ C:\Users\tlssa\Desktop\FRST.txt
2016-05-24 15:18 - 2016-05-24 15:18 - 02383360 _____ (Farbar) C:\Users\tlssa\Desktop\FRST64.exe
2016-05-24 15:18 - 2016-05-24 15:18 - 00000000 ____D C:\FRST
2016-05-24 14:08 - 2016-05-16 14:41 - 00000439 _____ C:\WINDOWS\SysWOW64\Cef.snt
2016-05-24 12:59 - 2016-05-24 12:59 - 01183559 _____ C:\WINDOWS\SysWOW64\vns7C4E.tmp
2016-05-24 11:13 - 2016-05-24 11:13 - 00000000 ___HD C:\OneDriveTemp
2016-05-24 10:49 - 2016-05-24 10:49 - 00000000 ____D C:\Users\tlssa\AppData\Roaming\Mozilla
2016-05-24 10:48 - 2016-05-24 10:48 - 06859776 _____ C:\Users\tlssa\AppData\Roaming\agent.dat
2016-05-24 10:48 - 2016-05-24 10:48 - 01756488 _____ C:\Users\tlssa\AppData\Roaming\HomeDax.tst
2016-05-24 10:48 - 2016-05-24 10:48 - 00505600 _____ (JollyMolly Inc) C:\Users\tlssa\AppData\Roaming\S--Tone.bin
2016-05-24 10:48 - 2016-05-24 10:48 - 00126464 _____ C:\Users\tlssa\AppData\Roaming\noah.dat
2016-05-24 10:48 - 2016-05-24 10:48 - 00126464 _____ C:\Users\tlssa\AppData\Roaming\lobby.dat
2016-05-24 10:48 - 2016-05-24 10:48 - 00072827 _____ C:\Users\tlssa\AppData\Roaming\Groovelab.tst
2016-05-24 10:48 - 2016-05-24 10:48 - 00067776 _____ C:\Users\tlssa\AppData\Roaming\Config.xml
2016-05-24 10:48 - 2016-05-24 10:48 - 00054272 _____ C:\Users\tlssa\AppData\Roaming\ApplicationHosting.dat
2016-05-24 10:48 - 2016-05-24 10:48 - 00018432 _____ C:\Users\tlssa\AppData\Roaming\Main.dat
2016-05-24 10:48 - 2016-05-24 10:48 - 00005568 _____ C:\Users\tlssa\AppData\Roaming\md.xml
2016-05-24 10:48 - 2016-05-24 10:48 - 00002397 _____ C:\WINDOWS\SysWOW64\findit.xml
2016-05-24 10:48 - 2016-05-24 10:48 - 00000000 ____D C:\Users\Todos os Usuários\Konksolexs
2016-05-24 10:48 - 2016-05-24 10:48 - 00000000 ____D C:\Users\Todos os Usuários\CloudPrinter
2016-05-24 10:48 - 2016-05-24 10:47 - 00947712 _____ C:\Users\tlssa\AppData\Roaming\HomeDax.exe
2016-05-24 10:48 - 2016-05-24 10:47 - 00947712 _____ C:\Users\tlssa\AppData\Roaming\Groovelab.exe
2016-05-24 10:47 - 2016-05-24 10:47 - 00505640 _____ (JollyMolly Inc) C:\Users\tlssa\AppData\Roaming\SoloLax.bin
2016-05-24 10:45 - 2016-05-24 10:47 - 00017760 _____ C:\Users\tlssa\AppData\Roaming\InstallationConfiguration.xml
2016-05-24 10:45 - 2016-05-24 10:45 - 00848437 _____ C:\Users\tlssa\AppData\Roaming\Singletrax.bin
2016-05-24 10:45 - 2016-05-24 10:45 - 00127488 _____ C:\Users\tlssa\AppData\Roaming\Installer.dat
2016-05-24 10:42 - 2016-05-24 10:42 - 00003122 _____ C:\WINDOWS\System32\Tasks\ttwifi
2016-05-24 10:42 - 2016-05-24 10:42 - 00003016 _____ C:\WINDOWS\System32\Tasks\osTip
2016-05-24 10:42 - 2016-05-24 10:42 - 00000000 ____D C:\Users\Todos os Usuários\WindowsMsg
2016-05-24 10:35 - 2016-05-24 10:35 - 00281180 _____ C:\WINDOWS\Minidump\052416-21796-01.dmp
2016-05-24 10:35 - 2016-05-24 10:35 - 00000000 ____D C:\WINDOWS\Minidump
2016-05-24 10:34 - 2016-05-24 10:34 - 443107118 _____ C:\WINDOWS\MEMORY.DMP
2016-05-24 10:27 - 2016-05-24 10:28 - 00000891 _____ C:\WINDOWS\SysWOW64\${LOGFILE}
2016-05-24 10:26 - 2016-05-24 11:00 - 00003656 _____ C:\WINDOWS\System32\Tasks\CreateExplorerShellUnelevatedTask
2016-05-24 10:26 - 2016-05-24 10:26 - 00003064 _____ C:\WINDOWS\System32\Tasks\svchost
2016-05-24 09:59 - 2016-05-24 15:03 - 00000000 ____D C:\Users\tlssa\AppData\Local\SunnyDay21
2016-05-24 09:59 - 2016-05-24 09:59 - 00000000 ____D C:\Users\tlssa\AppData\Local\csdi_monetize_220160520
2016-05-24 09:57 - 2016-05-24 09:57 - 00000000 ____D C:\Users\tlssa\AppData\Roaming\Hg1jb
2016-05-24 09:51 - 2016-05-24 09:51 - 00025978 _____ C:\Users\tlssa\Downloads\boleto_520AEFA9-F889-4C52-94AB-1651A4D14109.pdf
2016-05-24 09:46 - 2016-05-24 09:46 - 00000000 ____D C:\Users\tlssa\AppData\LocalLow012016E0
2016-05-24 09:46 - 2016-05-24 09:46 - 00000000 ____D C:\Users\tlssa\AppData\LocalLow0000022D5E6424E8
2016-05-23 17:37 - 2016-05-23 17:37 - 00000000 ____D C:\Users\tlssa\AppData\Roaming\MCorp
2016-05-23 17:33 - 2016-05-23 17:33 - 00000000 ____D C:\Users\tlssa\AppData\Local\csdi_monetize_120160522
2016-05-23 17:31 - 2016-05-23 17:31 - 00000000 ____D C:\Users\tlssa\AppData\LocalLow00783DB8
2016-05-23 17:31 - 2016-05-23 17:31 - 00000000 ____D C:\Users\tlssa\AppData\LocalLow0000026075114768
2016-05-23 17:29 - 2016-05-23 17:29 - 00000000 ____D C:\WINDOWS\system32\xiy
2016-05-23 17:20 - 2016-05-23 17:19 - 00001188 _____ C:\WINDOWS\system32\Drivers\etc\hp.bak
2016-05-23 17:18 - 2016-05-24 15:00 - 00000000 ____D C:\Program Files (x86)\5B4F747F-1464034689-39B6-0C3D-A4EFE8BE21AD
2016-05-23 17:16 - 2016-05-23 17:16 - 00000000 ____D C:\Users\tlssa\AppData\LocalLow\Company
2016-05-23 17:16 - 2016-05-23 17:16 - 00000000 ____D C:\Users\tlssa\AppData\LocalLow\{D2020D47-707D-4E26-B4D9-739C4F4C2E9A}
2016-05-23 17:16 - 2016-05-23 17:16 - 00000000 ____D C:\uninst
2016-05-23 17:15 - 2016-05-23 17:16 - 00000000 ____D C:\Users\tlssa\AppData\Roaming\Nadfik
2016-05-23 17:15 - 2016-05-23 17:16 - 00000000 ____D C:\Users\tlssa\AppData\Local\Tempfolder
2016-05-23 17:12 - 2016-05-24 10:28 - 00000000 ____D C:\Users\tlssa\AppData\Roaming\Nosibay
2016-05-23 17:09 - 2016-05-24 11:08 - 00000000 ____D C:\Program Files (x86)\MPC Cleaner
2016-05-23 17:09 - 2016-05-23 17:08 - 00060136 _____ (DotC United Inc) C:\WINDOWS\system32\Drivers\MPCKpt.removed579187
2016-05-23 17:06 - 2016-05-23 17:06 - 00008900 _____ C:\WINDOWS\System32\Tasks\Prehuph Manager
2016-05-23 17:05 - 2016-05-24 10:30 - 00000286 __RSH C:\Users\Todos os Usuários\ntuser.pol
2016-05-23 17:05 - 2016-05-24 10:30 - 00000000 ____D C:\Program Files (x86)\Sicotion
2016-05-23 17:05 - 2016-05-23 17:05 - 00008900 _____ C:\WINDOWS\System32\Tasks\Plsesh Community
2016-05-23 17:04 - 2016-05-23 17:06 - 00000000 ____D C:\Program Files (x86)\Prehuph
2016-05-23 17:04 - 2016-05-23 17:05 - 00000000 ____D C:\Program Files (x86)\Pfelywuru
2016-05-23 17:02 - 2016-05-24 10:30 - 00000000 ____D C:\Program Files (x86)\Druigh
2016-05-23 17:02 - 2016-05-23 17:06 - 00000000 ____D C:\Program Files (x86)\Plsesh
2016-05-23 17:02 - 2016-05-23 17:05 - 00000000 ____D C:\Program Files (x86)\Hqationqwich
2016-05-23 17:02 - 2016-05-23 17:03 - 00000000 ____D C:\Users\tlssa\AppData\Local\3810282D-6C19-47B0-8283-5C6C29A7E108
2016-05-23 17:02 - 2016-05-23 17:02 - 00000000 ____D C:\extensions
2016-05-23 17:00 - 2016-05-23 17:00 - 00000000 ____D C:\Users\tlssa\AppData\Roaming\WinRAR
2016-05-23 16:59 - 2016-05-23 16:59 - 00000000 ____D C:\Users\tlssa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-05-23 16:59 - 2016-05-23 16:59 - 00000000 ____D C:\Program Files\WinRAR
2016-05-23 16:58 - 2016-05-23 16:59 - 03524856 _____ C:\Users\tlssa\Downloads\winrar-x64-531br.exe
2016-05-23 16:56 - 2016-05-23 17:01 - 10705448 _____ (© pdfforge GmbH.) C:\Users\tlssa\Downloads\PDF_Architect_Installer_2.0.17.17507.exe
2016-05-23 16:56 - 2016-05-23 17:01 - 01459124 _____ C:\Users\tlssa\Downloads\PDF Architect 2 Crack.rar
2016-05-23 16:44 - 2016-05-23 16:44 - 59558448 _____ (pdfforge GbR) C:\Users\tlssa\Downloads\PDF_Architect_Installer_1.1.83.exe
2016-05-23 16:42 - 2016-05-23 16:42 - 01022488 _____ (Hociso ) C:\Users\tlssa\Downloads\pdf-architect.exe
2016-05-23 15:09 - 2016-05-23 17:15 - 00065344 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\system32\Drivers\cherimoya.sys
2016-05-23 12:58 - 2016-05-23 12:59 - 00517648 _____ (St.-Louis Blues) C:\Users\tlssa\Downloads\CLAVES PARA ACTIVAR MODULO EDICION PDF ARCHITECT__19733_il80013_26.exe
2016-05-23 12:56 - 2016-05-23 12:57 - 00519680 _____ C:\Users\tlssa\Downloads\CLAVES PARA ACTIVAR MODULO EDICION PDF ARCHITECT (1).rar
2016-05-23 12:48 - 2016-05-23 12:48 - 00000000 ____D C:\Users\tlssa\AppData\Local\Prompt Downloader
2016-05-23 12:25 - 2016-05-23 12:54 - 00000000 ____D C:\Program Files\PDF Architect 4
2016-05-23 12:25 - 2016-05-23 12:29 - 00000000 ____D C:\Program Files (x86)\PDF Architect 4
2016-05-23 12:25 - 2016-05-23 12:25 - 00000000 ____D C:\Users\tlssa\OneDrive\Documents\PDF Architect
2016-05-23 12:18 - 2016-05-23 12:42 - 00519680 _____ C:\Users\tlssa\Downloads\PDFArchitectFull Downloader.rar
2016-05-23 12:10 - 2016-05-23 12:10 - 00000000 ____D C:\Users\Todos os Usuários\pdfforge
2016-05-20 22:59 - 2016-05-20 23:00 - 00026197 _____ C:\Users\tlssa\Downloads\boleto_88EB074E-7594-4A75-BFCA-4C0006ED56A9.pdf
2016-05-20 22:33 - 2016-05-20 22:33 - 00000162 ____H C:\Users\tlssa\Desktop\~$ulista pe.pdf
2016-05-20 22:33 - 2016-05-20 22:33 - 00000162 ____H C:\Users\tlssa\Desktop\~$o de janeiro.pdf
2016-05-20 17:14 - 2016-05-20 17:14 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
2016-05-20 16:59 - 2016-05-20 16:59 - 00000000 ____D C:\Users\tlssa\OneDrive\Documents\PDF Files
2016-05-20 16:58 - 2016-05-20 17:01 - 00000000 ____D C:\Users\tlssa\AppData\Roaming\eXPert PDF 9
2016-05-20 16:58 - 2016-05-20 16:58 - 00000000 ____D C:\Users\tlssa\AppData\Roaming\eXPert PDF Jobs
2016-05-20 16:55 - 2016-05-20 16:57 - 59977040 _____ C:\Users\tlssa\Downloads\expertpdf_v9_pro.exe
2016-05-20 16:42 - 2016-05-20 16:42 - 00434345 _____ C:\Users\tlssa\Downloads\Craagle_4.0 By Cyndita.rar
2016-05-20 16:28 - 2016-05-20 16:28 - 00102912 _____ C:\Users\tlssa\Downloads\Executador.exe
2016-05-20 16:22 - 2016-05-20 16:22 - 00648686 _____ C:\Users\tlssa\Downloads\Crack do FileViewPro.rar
2016-05-20 16:09 - 2016-05-20 16:09 - 00000000 ____D C:\Users\Todos os Usuários\IsolatedStorage
2016-05-20 16:09 - 2016-05-20 16:09 - 00000000 ____D C:\Users\tlssa\AppData\Roaming\IsolatedStorage
2016-05-20 16:09 - 2016-05-20 16:09 - 00000000 ____D C:\Users\tlssa\AppData\Local\FileViewPro
2016-05-20 16:08 - 2016-05-20 16:08 - 00000000 ____D C:\Spacekace
2016-05-20 16:06 - 2016-05-20 16:07 - 02173104 _____ C:\Users\tlssa\Downloads\Setup_FileViewPro_2016.exe
2016-05-20 15:57 - 2016-05-20 15:58 - 02186098 _____ C:\Users\tlssa\Downloads\Keygen_1.5.ace
2016-05-20 15:47 - 2016-05-24 11:13 - 00000000 ____D C:\Program Files (x86)\SrpnFiles
2016-05-20 15:47 - 2016-05-20 15:47 - 00000000 ____D C:\Users\tlssa\AppData\Roaming\SpringFiles
2016-05-20 15:36 - 2016-05-20 15:38 - 04415488 _____ C:\Users\tlssa\Downloads\Code_activation_pdf_architect_module_edit_et_insert.iso
2016-05-20 14:51 - 2016-05-20 14:55 - 00000000 ____D C:\Users\tlssa\Desktop\thaynara
2016-05-20 14:50 - 2016-05-20 14:50 - 06034403 _____ C:\Users\tlssa\Downloads\Setup Incl Crack.zip
2016-05-20 13:29 - 2016-05-20 13:29 - 02186098 _____ C:\Users\tlssa\Downloads\Keygen_1.5.pdf
2016-05-20 13:05 - 2016-05-23 12:38 - 00000000 ____D C:\Users\tlssa\AppData\Roaming\PDF Architect 4
2016-05-20 12:51 - 2016-05-20 13:27 - 00000000 ____D C:\Users\Todos os Usuários\PDF Architect 4
2016-05-20 12:49 - 2016-05-20 12:51 - 05974040 _____ (© pdfforge GmbH.) C:\Users\tlssa\Downloads\PDF_Architect_4_Installer.exe
2016-05-20 12:28 - 2016-05-20 12:28 - 00000000 ____D C:\Program Files (x86)\Foxit Software
2016-05-20 12:26 - 2016-05-20 12:26 - 05113336 _____ (Foxit Corporation) C:\Users\tlssa\Downloads\FoxitPDFEditor221.1119_enu_Setup.exe
2016-05-20 09:29 - 2016-05-20 09:29 - 00038690 _____ C:\Users\tlssa\Downloads\TAIS.darlan.pdf
2016-05-19 17:27 - 2016-05-19 17:27 - 00026093 _____ C:\Users\tlssa\Downloads\boleto_9FE17993-32C2-4C6F-A1CE-09D1F1185483 (1).pdf
2016-05-19 17:23 - 2016-05-19 17:23 - 00026093 _____ C:\Users\tlssa\Downloads\boleto_9FE17993-32C2-4C6F-A1CE-09D1F1185483.pdf
2016-05-18 22:58 - 2016-05-18 23:07 - 00000000 ____D C:\Users\tlssa\OneDrive\Documents\papel de parede
2016-05-18 19:33 - 2016-05-18 19:33 - 00044215 _____ C:\Users\tlssa\Downloads\TAIS.ziad.pdf
2016-05-18 19:31 - 2016-05-18 19:31 - 00044142 _____ C:\Users\tlssa\Downloads\TAIS.ziard-2.pdf
2016-05-18 19:24 - 2016-05-18 19:24 - 00044144 _____ C:\Users\tlssa\Downloads\TAIS.ziard4.pdf
2016-05-18 18:31 - 2016-05-18 18:31 - 00026040 _____ C:\Users\tlssa\Downloads\boleto_9C94F313-E54D-4420-801C-79C22B8A4106.pdf
2016-05-18 18:30 - 2016-05-18 18:30 - 00026151 _____ C:\Users\tlssa\Downloads\boleto_C391B5DA-4744-4142-AD4F-C7062E9D69AB.pdf
2016-05-18 18:29 - 2016-05-18 18:29 - 00026043 _____ C:\Users\tlssa\Downloads\boleto_14A6C023-81CB-4598-BFB2-ECA0AB77C25A.pdf
2016-05-18 18:28 - 2016-05-18 18:28 - 00026151 _____ C:\Users\tlssa\Downloads\boleto_3BE8ED36-7C90-49CC-8F3C-A26DD05C15D0.pdf
2016-05-18 18:27 - 2016-05-18 18:27 - 00026148 _____ C:\Users\tlssa\Downloads\boleto_D95F9A9B-C522-400E-A88C-99D4160E5C26.pdf
2016-05-18 17:26 - 2016-05-18 17:26 - 00026104 _____ C:\Users\tlssa\Downloads\boleto_2520297B-0781-4FEE-965F-0B556178B3EE.pdf
2016-05-18 12:13 - 2016-05-18 12:13 - 00021341 _____ C:\Users\tlssa\Downloads\tabela e-sedex.pdf
2016-05-18 10:14 - 2016-05-18 10:14 - 00026152 _____ C:\Users\tlssa\Downloads\boleto_A2E8C2F4-4C0E-4CD0-8D86-2E23DFC35E54.pdf
2016-05-18 10:12 - 2016-05-18 10:12 - 00026147 _____ C:\Users\tlssa\Downloads\boleto_8F5E0C49-2D9E-4226-8703-7F6DA32A7582.pdf
2016-05-18 10:06 - 2016-05-18 10:06 - 00026175 _____ C:\Users\tlssa\Downloads\boleto_E0770A24-F75E-4260-97CE-42C892D01B11.pdf
2016-05-17 15:56 - 2016-05-17 15:56 - 00097205 _____ C:\Users\tlssa\Downloads\NF_367_ZIAD_SAID_ABBOUD.pdf
2016-05-17 12:45 - 2016-05-17 12:47 - 102605631 _____ C:\Users\tlssa\Downloads\downloads-supplementalcontent.zip
2016-05-17 11:25 - 2016-05-17 11:25 - 00026165 _____ C:\Users\tlssa\Downloads\boleto_7E9E1D11-6260-4CF2-990C-9AF3834D4A82.pdf
2016-05-17 11:18 - 2016-05-17 11:18 - 00000000 ____D C:\Users\tlssa\AppData\LocalLow\Temp
2016-05-16 21:58 - 2016-05-16 21:58 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_WinUSB_01007.Wdf
2016-05-16 21:22 - 2016-05-16 21:22 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2016-05-16 18:57 - 2016-05-16 18:57 - 00001808 _____ C:\Users\tlssa\Desktop\Word 2016.lnk
2016-05-16 18:57 - 2016-05-16 18:57 - 00001792 _____ C:\Users\tlssa\Desktop\Excel 2016.lnk
2016-05-16 17:40 - 2016-05-16 17:40 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2016-05-16 17:35 - 2016-05-16 17:35 - 00000000 ____D C:\Users\tlssa\OneDrive\Documents\Modelos Personalizados do Office
2016-05-16 13:04 - 2016-05-16 13:04 - 00026148 _____ C:\Users\tlssa\Downloads\boleto_25BEB24F-0C84-4F60-B791-B5113AF4C00C.pdf
2016-05-16 11:13 - 2016-05-24 15:13 - 00000951 _____ C:\WINDOWS\Tasks\EPSON XP-211 214 216 Series Update {82420DA2-603F-4902-8DE4-B25EB8C031E9}.job
2016-05-16 11:13 - 2016-05-24 15:13 - 00000765 _____ C:\WINDOWS\Tasks\EPSON XP-211 214 216 Series Invitation {82420DA2-603F-4902-8DE4-B25EB8C031E9}.job
2016-05-16 11:13 - 2016-05-16 13:13 - 00000000 ____D C:\Users\Todos os Usuários\EPSON
2016-05-16 11:13 - 2016-05-16 11:13 - 00004164 _____ C:\WINDOWS\System32\Tasks\EPSON XP-211 214 216 Series Update {82420DA2-603F-4902-8DE4-B25EB8C031E9}
2016-05-16 11:13 - 2016-05-16 11:13 - 00003986 _____ C:\WINDOWS\System32\Tasks\EPSON XP-211 214 216 Series Invitation {82420DA2-603F-4902-8DE4-B25EB8C031E9}
2016-05-16 11:13 - 2016-05-16 11:13 - 00000000 ____D C:\Program Files\Common Files\EPSON
2016-05-15 22:54 - 2016-05-15 22:54 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2016-05-15 22:21 - 2015-10-30 04:17 - 02718208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2016-05-15 22:20 - 2016-05-15 22:20 - 00000000 ____D C:\Users\Todos os Usuários\USOShared
2016-05-15 22:19 - 2016-05-24 11:00 - 00265309 _____ C:\WINDOWS\SysWOW64\rootpa.e2e
2016-05-15 22:19 - 2016-05-15 22:19 - 00000000 ____D C:\WINDOWS\tbaseregistry
2016-05-15 22:19 - 2015-10-30 04:18 - 00418816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IEShims.dll
2016-05-15 22:18 - 2016-05-24 10:58 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-05-15 22:18 - 2016-05-15 22:18 - 00000000 _SHDL C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
2016-05-15 22:18 - 2016-05-15 22:18 - 00000000 _SHDL C:\Users\Usuário Padrão\AppData\Local\Histórico
2016-05-15 22:18 - 2016-05-15 22:18 - 00000000 _SHDL C:\Users\Usuário Padrão\AppData\Local\Dados de Aplicativos
2016-05-15 22:18 - 2016-05-15 22:18 - 00000000 _SHDL C:\Users\Usuário Padrão
2016-05-15 22:18 - 2016-05-15 22:18 - 00000000 _SHDL C:\Users\Todos os Usuários\Modelos
2016-05-15 22:18 - 2016-05-15 22:18 - 00000000 _SHDL C:\Users\Todos os Usuários\Menu Iniciar
2016-05-15 22:18 - 2016-05-15 22:18 - 00000000 _SHDL C:\Users\Todos os Usuários\Documentos
2016-05-15 22:18 - 2016-05-15 22:18 - 00000000 _SHDL C:\Users\Todos os Usuários\Dados de Aplicativos
2016-05-15 22:18 - 2016-05-15 22:18 - 00000000 _SHDL C:\Users\Todos os Usuários
2016-05-15 22:18 - 2016-05-15 22:18 - 00000000 _SHDL C:\Users\Default\Modelos
2016-05-15 22:18 - 2016-05-15 22:18 - 00000000 _SHDL C:\Users\Default\Meus Documentos
2016-05-15 22:18 - 2016-05-15 22:18 - 00000000 _SHDL C:\Users\Default\Menu Iniciar
2016-05-15 22:18 - 2016-05-15 22:18 - 00000000 _SHDL C:\Users\Default\Dados de Aplicativos
2016-05-15 22:18 - 2016-05-15 22:18 - 00000000 _SHDL C:\Users\Default\Configurações Locais
2016-05-15 22:18 - 2016-05-15 22:18 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
2016-05-15 22:18 - 2016-05-15 22:18 - 00000000 _SHDL C:\Users\Default\AppData\Local\Histórico
2016-05-15 22:18 - 2016-05-15 22:18 - 00000000 _SHDL C:\Users\Default\AppData\Local\Dados de Aplicativos
2016-05-15 22:18 - 2016-05-15 22:18 - 00000000 _SHDL C:\Users\Default\Ambiente de Rede
2016-05-15 22:18 - 2016-05-15 22:18 - 00000000 _SHDL C:\Users\Default\Ambiente de Impressão
2016-05-15 22:18 - 2016-05-15 22:18 - 00000000 _SHDL C:\Program Files\Common Files\Sistema
2016-05-15 22:18 - 2016-05-15 22:18 - 00000000 _SHDL C:\Program Files\Arquivos Comuns
2016-05-15 22:18 - 2016-05-15 22:18 - 00000000 _SHDL C:\Documents and Settings
2016-05-15 22:18 - 2016-05-15 22:18 - 00000000 _SHDL C:\Arquivos de Programas
2016-05-15 22:13 - 2016-05-15 22:13 - 00000000 ____D C:\WINDOWS\system32\SRSLabs
2016-05-15 22:13 - 2016-05-15 22:13 - 00000000 ____D C:\Program Files\Realtek
2016-05-15 22:13 - 2016-05-15 18:33 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2016-05-15 22:12 - 2016-05-24 10:58 - 00065536 _____ C:\WINDOWS\system32\spu_storage.bin
2016-05-15 22:12 - 2016-05-15 22:12 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_amdpsp_01011.Wdf
2016-05-15 22:12 - 2016-05-15 22:12 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies
2016-05-15 22:12 - 2016-05-15 22:12 - 00000000 ____D C:\Program Files\AMD
2016-05-15 22:12 - 2016-05-15 22:12 - 00000000 _____ C:\WINDOWS\ativpsrm.bin
2016-05-15 22:09 - 2016-05-16 03:40 - 00232584 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-05-15 22:09 - 2016-05-15 22:09 - 00000000 ____D C:\WINDOWS\ServiceProfiles
2016-05-15 21:05 - 2016-05-15 21:05 - 00002246 _____ C:\Users\tlssa\Desktop\WhatsApp.lnk
2016-05-15 21:04 - 2016-05-15 21:05 - 00000000 ____D C:\Users\tlssa\AppData\Local\WhatsApp
2016-05-15 21:00 - 2016-05-24 09:43 - 00000000 ____D C:\Users\tlssa\AppData\Roaming\WhatsApp
2016-05-15 21:00 - 2016-05-15 21:05 - 00000000 ____D C:\Users\tlssa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WhatsApp
2016-05-15 20:58 - 2016-05-15 21:05 - 00000000 ____D C:\Users\tlssa\AppData\Local\SquirrelTemp
2016-05-15 20:49 - 2016-05-15 21:02 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-05-15 20:48 - 2016-05-20 17:11 - 00000000 ____D C:\Program Files\Microsoft Office
2016-05-15 20:48 - 2016-05-15 20:49 - 139319312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-05-15 20:48 - 2016-05-15 20:48 - 00000000 ____D C:\Program Files\Microsoft Office 15
2016-05-15 20:34 - 2016-04-22 04:57 - 00453288 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2016-05-15 19:27 - 2016-05-15 19:27 - 00026171 _____ C:\Users\tlssa\Downloads\boleto_F0C5A84C-345D-46FE-A16C-6E4CBEBFC992.pdf
2016-05-15 19:16 - 2016-05-24 10:59 - 00101080 _____ (GAS Tecnologia) C:\WINDOWS\system32\Drivers\wsddfac.sys
2016-05-15 19:16 - 2016-05-15 19:17 - 00001024 _____ C:\.rnd
2016-05-15 19:16 - 2015-03-18 11:23 - 00103640 ____N (GAS Tecnologia) C:\WINDOWS\system32\Drivers\wsddpp.sys
2016-05-15 19:15 - 2016-05-15 19:15 - 00000000 ___HD C:\Program Files (x86)\GAS Tecnologia
2016-05-15 19:15 - 2016-05-15 19:15 - 00000000 ___HD C:\Program Files (x86)\Diebold
2016-05-15 19:15 - 2016-05-15 19:15 - 00000000 ____D C:\Program Files\Diebold
2016-05-15 19:05 - 2016-05-24 15:17 - 00001108 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-05-15 19:05 - 2016-05-24 11:00 - 00001104 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-05-15 19:05 - 2016-05-15 19:12 - 00004166 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2016-05-15 19:05 - 2016-05-15 19:12 - 00003934 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2016-05-15 19:05 - 2016-05-15 19:06 - 00000000 ____D C:\Program Files (x86)\Google
2016-05-15 19:04 - 2016-05-24 13:23 - 00000000 ____D C:\Users\tlssa\AppData\Local\Apps\2.0
2016-05-15 19:04 - 2016-05-15 20:09 - 00000000 ____D C:\Users\tlssa\AppData\Local\Google
2016-05-15 19:04 - 2016-05-15 19:04 - 00000000 ____D C:\Users\tlssa\AppData\Local\Deployment
2016-05-15 18:47 - 2016-05-15 18:47 - 00000000 ____D C:\Users\tlssa\AppData\Roaming\Macromedia
2016-05-15 18:46 - 2016-05-15 18:46 - 00000000 ____D C:\Users\tlssa\AppData\Local\ElevatedDiagnostics
2016-05-15 18:43 - 2016-05-15 18:43 - 00000000 ____D C:\Users\tlssa\AppData\Local\NetworkTiles
2016-05-15 18:41 - 2016-05-24 10:58 - 00000000 ____D C:\Program Files (x86)\GbPlugin
2016-05-15 18:41 - 2016-05-24 09:44 - 00000000 ____D C:\Users\Todos os Usuários\GbPlugin
2016-05-15 18:41 - 2016-05-15 18:41 - 00000000 ____D C:\Users\Todos os Usuários\GAS Tecnologia
2016-05-15 18:35 - 2016-05-24 12:26 - 00004184 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{7C2A6D90-8B49-431E-BBCF-636D2C0E1839}
2016-05-15 18:30 - 2016-05-24 11:13 - 00000000 ___RD C:\Users\tlssa\OneDrive
2016-05-15 18:30 - 2016-05-19 18:32 - 00002381 _____ C:\Users\tlssa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-05-15 18:29 - 2016-05-15 18:47 - 00000000 ____D C:\Users\tlssa\AppData\Local\MicrosoftEdge
2016-05-15 18:29 - 2016-05-15 18:29 - 00000000 ____D C:\Users\Todos os Usuários\Microsoft OneDrive
2016-05-15 18:27 - 2016-05-15 18:27 - 00000000 ____D C:\Users\tlssa\AppData\Local\Comms
2016-05-15 18:27 - 2016-05-15 18:27 - 00000000 ____D C:\Users\tlssa\AppData\Local\ActiveSync
2016-05-15 18:26 - 2016-05-15 18:26 - 00000000 ____D C:\Users\tlssa\AppData\Local\Publishers
2016-05-15 18:24 - 2016-05-24 11:05 - 01819274 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-05-15 18:24 - 2016-05-16 10:19 - 00000000 ____D C:\Users\tlssa\AppData\Local\Packages
2016-05-15 18:24 - 2016-05-16 09:30 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-05-15 18:24 - 2016-05-15 18:49 - 00000000 ____D C:\Users\tlssa\AppData\Local\VirtualStore
2016-05-15 18:24 - 2016-05-15 18:24 - 00000000 ____D C:\Users\tlssa\AppData\Roaming\Adobe
2016-05-15 18:24 - 2016-05-15 18:24 - 00000000 ____D C:\Users\tlssa\AppData\Local\TileDataLayer
2016-05-15 18:23 - 2016-05-24 10:35 - 00000000 ____D C:\Users\tlssa
2016-05-15 18:23 - 2016-05-15 18:23 - 00000020 ___SH C:\Users\tlssa\ntuser.ini
2016-05-15 18:23 - 2016-05-15 18:23 - 00000000 _SHDL C:\Users\tlssa\Modelos
2016-05-15 18:23 - 2016-05-15 18:23 - 00000000 _SHDL C:\Users\tlssa\Meus Documentos
2016-05-15 18:23 - 2016-05-15 18:23 - 00000000 _SHDL C:\Users\tlssa\Menu Iniciar
2016-05-15 18:23 - 2016-05-15 18:23 - 00000000 _SHDL C:\Users\tlssa\Dados de Aplicativos
2016-05-15 18:23 - 2016-05-15 18:23 - 00000000 _SHDL C:\Users\tlssa\Configurações Locais
2016-05-15 18:23 - 2016-05-15 18:23 - 00000000 _SHDL C:\Users\tlssa\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
2016-05-15 18:23 - 2016-05-15 18:23 - 00000000 _SHDL C:\Users\tlssa\AppData\Local\Histórico
2016-05-15 18:23 - 2016-05-15 18:23 - 00000000 _SHDL C:\Users\tlssa\AppData\Local\Dados de Aplicativos
2016-05-15 18:23 - 2016-05-15 18:23 - 00000000 _SHDL C:\Users\tlssa\Ambiente de Rede
2016-05-15 18:23 - 2016-05-15 18:23 - 00000000 _SHDL C:\Users\tlssa\Ambiente de Impressão
2016-05-15 18:08 - 2016-05-15 18:08 - 00000000 _____ C:\Recovery.txt
2016-05-15 15:45 - 2016-05-15 18:21 - 00000000 ___DC C:\WINDOWS\Panther
2016-05-15 15:45 - 2016-05-15 15:45 - 00000000 ____D C:\WINDOWS\InfusedApps
2016-05-15 15:44 - 2016-05-15 15:44 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
2016-05-15 15:38 - 2016-05-15 15:38 - 00000000 ____D C:\WINDOWS\Setup
2016-05-15 15:33 - 2016-05-15 15:33 - 00000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
2016-05-15 15:33 - 2016-05-15 15:33 - 00000000 ____D C:\WINDOWS\OCR
2016-05-15 15:33 - 2016-05-15 15:33 - 00000000 ____D C:\Program Files\Reference Assemblies
2016-05-15 15:33 - 2016-05-15 15:33 - 00000000 ____D C:\Program Files\MSBuild
2016-05-15 15:33 - 2016-05-15 15:33 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2016-05-15 15:33 - 2016-05-15 15:33 - 00000000 ____D C:\Program Files (x86)\MSBuild
2016-05-15 15:32 - 2016-05-24 11:05 - 00785262 _____ C:\WINDOWS\system32\prfh0416.dat
2016-05-15 15:32 - 2016-05-24 11:05 - 00154048 _____ C:\WINDOWS\system32\prfc0416.dat
2016-05-15 15:32 - 2016-05-15 15:32 - 00000000 ____D C:\WINDOWS\SysWOW64\winrm
2016-05-15 15:32 - 2016-05-15 15:32 - 00000000 ____D C:\WINDOWS\SysWOW64\WCN
2016-05-15 15:32 - 2016-05-15 15:32 - 00000000 ____D C:\WINDOWS\SysWOW64\sysprep
2016-05-15 15:32 - 2016-05-15 15:32 - 00000000 ____D C:\WINDOWS\SysWOW64\slmgr
2016-05-15 15:32 - 2016-05-15 15:32 - 00000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts
2016-05-15 15:32 - 2016-05-15 15:32 - 00000000 ____D C:\WINDOWS\SysWOW64\0409
2016-05-15 15:32 - 2016-05-15 15:32 - 00000000 ____D C:\WINDOWS\system32\winrm
2016-05-15 15:32 - 2016-05-15 15:32 - 00000000 ____D C:\WINDOWS\system32\WCN
2016-05-15 15:32 - 2016-05-15 15:32 - 00000000 ____D C:\WINDOWS\system32\slmgr
2016-05-15 15:32 - 2016-05-15 15:31 - 00328354 _____ C:\WINDOWS\system32\prfi0416.dat
2016-05-15 15:32 - 2016-05-15 15:31 - 00040752 _____ C:\WINDOWS\system32\prfd0416.dat
2016-05-15 15:31 - 2016-05-15 15:31 - 00000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts
2016-05-15 15:31 - 2016-05-15 15:31 - 00000000 ____D C:\WINDOWS\system32\0409
2016-05-15 15:31 - 2016-05-15 15:31 - 00000000 ____D C:\WINDOWS\DigitalLocker
2016-05-15 15:24 - 2016-05-11 16:57 - 00829944 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-05-15 15:24 - 2016-05-11 16:57 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-05-15 15:20 - 2016-05-24 15:13 - 00000000 ____D C:\WINDOWS\system32\FxsTmp
2016-05-15 15:20 - 2016-05-24 11:43 - 00000000 ___HD C:\Program Files\WindowsApps
2016-05-15 15:20 - 2016-05-24 11:43 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-05-15 15:20 - 2016-05-23 17:04 - 00000000 ___HD C:\WINDOWS\system32\GroupPolicy
2016-05-15 15:20 - 2016-05-23 17:04 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
2016-05-15 15:20 - 2016-05-20 17:14 - 00000000 ____D C:\Users\Todos os Usuários\regid.1991-06.com.microsoft
2016-05-15 15:20 - 2016-05-20 17:14 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2016-05-15 15:20 - 2016-05-18 18:57 - 00000000 ____D C:\WINDOWS\rescache
2016-05-15 15:20 - 2016-05-18 11:43 - 00000000 ____D C:\WINDOWS\system32\NDF
2016-05-15 15:20 - 2016-05-16 09:32 - 00000000 ____D C:\WINDOWS\appcompat
2016-05-15 15:20 - 2016-05-16 03:36 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
2016-05-15 15:20 - 2016-05-16 03:35 - 00000000 ___SD C:\WINDOWS\system32\F12
2016-05-15 15:20 - 2016-05-16 03:35 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2016-05-15 15:20 - 2016-05-16 03:35 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2016-05-15 15:20 - 2016-05-16 03:35 - 00000000 ____D C:\WINDOWS\system32\oobe
2016-05-15 15:20 - 2016-05-16 03:35 - 00000000 ____D C:\WINDOWS\system32\Dism
2016-05-15 15:20 - 2016-05-16 03:35 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-05-15 15:20 - 2016-05-16 03:34 - 00000000 __RSD C:\WINDOWS\Media
2016-05-15 15:20 - 2016-05-16 03:34 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
2016-05-15 15:20 - 2016-05-16 03:34 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2016-05-15 15:20 - 2016-05-16 03:34 - 00000000 ____D C:\WINDOWS\Provisioning
2016-05-15 15:20 - 2016-05-16 03:34 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2016-05-15 15:20 - 2016-05-16 03:34 - 00000000 ____D C:\WINDOWS\bcastdvr
2016-05-15 15:20 - 2016-05-16 03:34 - 00000000 ____D C:\Program Files\Windows Portable Devices
2016-05-15 15:20 - 2016-05-16 03:34 - 00000000 ____D C:\Program Files\Windows Multimedia Platform
2016-05-15 15:20 - 2016-05-16 03:34 - 00000000 ____D C:\Program Files\Windows Journal
2016-05-15 15:20 - 2016-05-16 03:34 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices
2016-05-15 15:20 - 2016-05-16 03:34 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2016-05-15 15:20 - 2016-05-16 03:32 - 00015703 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml
2016-05-15 15:20 - 2016-05-15 22:21 - 00000000 ____D C:\WINDOWS\system32\spool
2016-05-15 15:20 - 2016-05-15 22:20 - 00000000 ____D C:\Users\Todos os Usuários\USOPrivate
2016-05-15 15:20 - 2016-05-15 22:18 - 00000000 ____D C:\Program Files\Windows NT
2016-05-15 15:20 - 2016-05-15 22:16 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2016-05-15 15:20 - 2016-05-15 20:59 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2016-05-15 15:20 - 2016-05-15 18:44 - 00000000 ___RD C:\WINDOWS\DevicesFlow
2016-05-15 15:20 - 2016-05-15 18:25 - 00000000 ___RD C:\WINDOWS\PrintDialog
2016-05-15 15:20 - 2016-05-15 18:25 - 00000000 ___RD C:\WINDOWS\MiracastView
2016-05-15 15:20 - 2016-05-15 18:23 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
2016-05-15 15:20 - 2016-05-15 18:08 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
2016-05-15 15:20 - 2016-05-15 15:33 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI
2016-05-15 15:20 - 2016-05-15 15:33 - 00000000 ____D C:\WINDOWS\system32\MUI
2016-05-15 15:20 - 2016-05-15 15:32 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2016-05-15 15:20 - 2016-05-15 15:32 - 00000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2016-05-15 15:20 - 2016-05-15 15:32 - 00000000 ____D C:\WINDOWS\SysWOW64\setup
2016-05-15 15:20 - 2016-05-15 15:32 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe
2016-05-15 15:20 - 2016-05-15 15:32 - 00000000 ____D C:\WINDOWS\SysWOW64\Com
2016-05-15 15:20 - 2016-05-15 15:32 - 00000000 ____D C:\WINDOWS\system32\setup
2016-05-15 15:20 - 2016-05-15 15:31 - 00000000 ___SD C:\WINDOWS\system32\dsc
2016-05-15 15:20 - 2016-05-15 15:31 - 00000000 ___SD C:\WINDOWS\system32\DiagSvcs
2016-05-15 15:20 - 2016-05-15 15:31 - 00000000 ____D C:\WINDOWS\system32\migwiz
2016-05-15 15:20 - 2016-05-15 15:31 - 00000000 ____D C:\WINDOWS\system32\Com
2016-05-15 15:20 - 2016-05-15 15:31 - 00000000 ____D C:\WINDOWS\IME
2016-05-15 15:20 - 2016-05-15 15:31 - 00000000 ____D C:\WINDOWS\Help
2016-05-15 15:20 - 2016-05-15 15:31 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2016-05-15 15:20 - 2016-05-15 15:31 - 00000000 ____D C:\Program Files\Windows Defender
2016-05-15 15:20 - 2016-05-15 15:31 - 00000000 ____D C:\Program Files\Common Files\System
2016-05-15 15:20 - 2016-05-15 15:31 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2016-05-15 15:20 - 2016-05-15 15:31 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 __SHD C:\Program Files\Windows Sidebar
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 __RHD C:\Users\Public\Libraries
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ___SD C:\WINDOWS\SysWOW64\Nui
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ___SD C:\WINDOWS\SysWOW64\Configuration
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ___SD C:\WINDOWS\system32\Nui
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ___SD C:\WINDOWS\system32\Configuration
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ___SD C:\WINDOWS\Downloaded Program Files
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ___RD C:\WINDOWS\Offline Web Pages
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ___RD C:\WINDOWS\DesktopTileResources
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\Web
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\Vss
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\tracing
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\TAPI
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\SysWOW64\SMI
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\SysWOW64\ras
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\SysWOW64\NDF
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\SysWOW64\MsDtc
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\SysWOW64\migwiz
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\SysWOW64\MailContactsCalendarSync
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\SysWOW64\Ipmi
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\SysWOW64\InputMethod
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\SysWOW64\IME
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\SysWOW64\icsxml
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicyUsers
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\SysWOW64\FxsTmp
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\SysWOW64\downlevel
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\SysWOW64\Bthprops
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\SysWOW64\AppLocker
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\SystemResources
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\SystemApps
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\system32\WinMetadata
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\system32\winevt
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\system32\ras
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\system32\ProximityToast
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\system32\PointOfService
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\system32\MsDtc
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\system32\MailContactsCalendarSync
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\system32\Macromed
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\system32\Ipmi
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\system32\InputMethod
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\system32\IME
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\system32\icsxml
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\system32\ias
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\system32\GroupPolicyUsers
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\system32\downlevel
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\system32\config\Journal
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\system32\Bthprops
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\system32\AppLocker
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\System
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\SKB
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\ShellNew
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\security
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\schemas
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\SchCache
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\Resources
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\Registration
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\PLA
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\Performance
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\ModemLogs
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\L2Schemas
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\InputMethod
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\Globalization
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\Cursors
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\Branding
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\addins
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\Users\Todos os Usuários\Comms
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\Program Files\Common Files\Services
2016-05-15 15:20 - 2016-05-15 15:20 - 00000000 ____D C:\Program Files (x86)\Windows NT
2016-05-15 15:20 - 2016-05-15 15:13 - 00230912 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2016-05-15 15:20 - 2016-05-15 15:13 - 00215943 _____ C:\WINDOWS\SysWOW64\dssec.dat
2016-05-15 15:20 - 2016-05-15 15:13 - 00215943 _____ C:\WINDOWS\system32\dssec.dat
2016-05-15 15:20 - 2016-05-15 15:13 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
2016-05-15 15:20 - 2016-05-15 15:13 - 00017463 _____ C:\WINDOWS\system32\Drivers\etc\services
2016-05-15 15:20 - 2016-05-15 15:13 - 00008798 _____ C:\WINDOWS\SysWOW64\icrav03.rat
2016-05-15 15:20 - 2016-05-15 15:13 - 00008798 _____ C:\WINDOWS\system32\icrav03.rat
2016-05-15 15:20 - 2016-05-15 15:13 - 00003683 _____ C:\WINDOWS\system32\Drivers\etc\lmhosts.sam
2016-05-15 15:20 - 2016-05-15 15:13 - 00001988 _____ C:\WINDOWS\SysWOW64\ticrf.rat
2016-05-15 15:20 - 2016-05-15 15:13 - 00001988 _____ C:\WINDOWS\system32\ticrf.rat
2016-05-15 15:20 - 2016-05-15 15:13 - 00001358 _____ C:\WINDOWS\system32\Drivers\etc\protocol
2016-05-15 15:20 - 2016-05-15 15:13 - 00000858 _____ C:\WINDOWS\system32\DefaultQuestions.json
2016-05-15 15:20 - 2016-05-15 15:13 - 00000741 _____ C:\WINDOWS\SysWOW64\NOISE.DAT
2016-05-15 15:20 - 2016-05-15 15:13 - 00000741 _____ C:\WINDOWS\system32\NOISE.DAT
2016-05-15 15:20 - 2016-05-15 15:13 - 00000407 _____ C:\WINDOWS\system32\Drivers\etc\networks
2016-05-15 15:20 - 2016-05-15 15:13 - 00000389 _____ C:\WINDOWS\system32\AutoWorkplace.exe.config
2016-05-15 15:20 - 2016-05-15 15:12 - 00000219 _____ C:\WINDOWS\system.ini
2016-05-15 15:20 - 2016-05-15 15:12 - 00000092 _____ C:\WINDOWS\win.ini
2016-05-15 15:15 - 2016-05-24 11:05 - 00000000 ____D C:\WINDOWS\INF
2016-05-15 14:55 - 2016-05-15 21:08 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-05-15 14:35 - 2016-05-24 10:58 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2016-05-15 14:35 - 2016-05-15 22:20 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
2016-05-15 14:35 - 2016-05-15 15:31 - 00000000 ____D C:\WINDOWS\servicing
2016-05-15 14:35 - 2016-05-15 15:20 - 00000000 ____D C:\WINDOWS\system32\SMI
2016-05-15 14:35 - 2015-10-30 03:33 - 00000164 _____ C:\WINDOWS\system32\config\FP
2016-05-15 14:21 - 2016-05-15 18:08 - 00000000 ___HD C:\$SysReset
2016-05-10 16:51 - 2016-04-23 01:28 - 16984576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-05-10 16:51 - 2016-04-23 01:26 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll
2016-05-10 16:51 - 2016-04-23 01:25 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
2016-05-10 16:51 - 2016-04-23 01:22 - 00460800 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2016-05-10 16:51 - 2016-04-23 01:19 - 01056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2016-05-10 16:51 - 2016-04-23 01:19 - 00853504 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2016-05-10 16:51 - 2016-04-23 01:18 - 00349696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2016-05-10 16:51 - 2016-04-23 01:16 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2016-05-10 16:51 - 2016-04-23 01:13 - 07200256 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2016-05-10 16:51 - 2016-04-23 01:09 - 02582016 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2016-05-10 16:51 - 2016-04-23 01:08 - 02061824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2016-05-10 16:51 - 2016-04-23 01:07 - 05205504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2016-05-10 16:50 - 2016-04-23 02:09 - 22561256 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2016-05-10 16:50 - 2016-04-23 01:31 - 13018112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2016-05-10 16:50 - 2016-04-23 01:30 - 22379008 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-05-10 16:50 - 2016-04-23 01:23 - 11545088 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-05-10 16:50 - 2016-04-23 01:20 - 19344384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-05-10 16:50 - 2016-04-23 01:20 - 18676224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-05-10 16:50 - 2016-04-23 01:19 - 07977472 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2016-05-10 16:50 - 2016-04-23 01:19 - 00970752 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2016-05-10 16:50 - 2016-04-23 01:19 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2016-05-10 16:50 - 2016-04-23 01:18 - 24604672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-05-10 16:50 - 2016-04-23 01:18 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
2016-05-10 16:50 - 2016-04-23 01:18 - 00939520 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2016-05-10 16:50 - 2016-04-23 01:18 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2016-05-10 16:50 - 2016-04-23 01:15 - 00792064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2016-05-10 16:50 - 2016-04-23 01:15 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
2016-05-10 16:50 - 2016-04-23 01:14 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2016-05-10 16:50 - 2016-04-23 01:13 - 06295552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2016-05-10 16:49 - 2016-04-30 03:42 - 01387520 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2016-05-10 16:49 - 2016-04-30 03:31 - 03591168 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-05-10 16:49 - 2016-04-23 03:12 - 01401024 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2016-05-10 16:49 - 2016-04-23 03:12 - 01184960 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2016-05-10 16:49 - 2016-04-23 03:12 - 00713920 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2016-05-10 16:49 - 2016-04-23 03:12 - 00514752 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2016-05-10 16:49 - 2016-04-23 03:12 - 00294592 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2016-05-10 16:49 - 2016-04-23 03:12 - 00190144 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2016-05-10 16:49 - 2016-04-23 03:12 - 00046784 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2016-05-10 16:49 - 2016-04-23 02:28 - 01557768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2016-05-10 16:49 - 2016-04-23 02:28 - 01542816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2016-05-10 16:49 - 2016-04-23 02:24 - 07474528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-05-10 16:49 - 2016-04-23 02:24 - 01997328 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2016-05-10 16:49 - 2016-04-23 02:24 - 01819208 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2016-05-10 16:49 - 2016-04-23 02:24 - 00754664 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2016-05-10 16:49 - 2016-04-23 02:12 - 00925064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2016-05-10 16:49 - 2016-04-23 02:12 - 00451928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll
2016-05-10 16:49 - 2016-04-23 02:12 - 00413536 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifitask.exe
2016-05-10 16:49 - 2016-04-23 02:11 - 01092464 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2016-05-10 16:49 - 2016-04-23 02:11 - 00498960 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
2016-05-10 16:49 - 2016-04-23 02:10 - 03673424 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2016-05-10 16:49 - 2016-04-23 02:10 - 02919832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2016-05-10 16:49 - 2016-04-23 02:09 - 21123320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2016-05-10 16:49 - 2016-04-23 02:09 - 05240960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2016-05-10 16:49 - 2016-04-23 02:09 - 04074160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2016-05-10 16:49 - 2016-04-23 02:09 - 00303216 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
2016-05-10 16:49 - 2016-04-23 02:09 - 00255168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe
2016-05-10 16:49 - 2016-04-23 02:08 - 06605504 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2016-05-10 16:49 - 2016-04-23 02:08 - 04515256 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2016-05-10 16:49 - 2016-04-23 02:01 - 01996640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2016-05-10 16:49 - 2016-04-23 02:01 - 00650304 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2016-05-10 16:49 - 2016-04-23 02:01 - 00577368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2016-05-10 16:49 - 2016-04-23 02:01 - 00522176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2016-05-10 16:49 - 2016-04-23 02:00 - 01372304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2016-05-10 16:49 - 2016-04-23 01:39 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
2016-05-10 16:49 - 2016-04-23 01:32 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
2016-05-10 16:49 - 2016-04-23 01:31 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
2016-05-10 16:49 - 2016-04-23 01:30 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2016-05-10 16:49 - 2016-04-23 01:29 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
2016-05-10 16:49 - 2016-04-23 01:26 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
2016-05-10 16:49 - 2016-04-23 01:24 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2016-05-10 16:49 - 2016-04-23 01:22 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2016-05-10 16:49 - 2016-04-23 01:21 - 00314880 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll
2016-05-10 16:49 - 2016-04-23 01:20 - 00606720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2016-05-10 16:49 - 2016-04-23 01:18 - 00804352 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2016-05-10 16:49 - 2016-04-23 01:18 - 00605184 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2016-05-10 16:49 - 2016-04-23 01:18 - 00585728 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2016-05-10 16:49 - 2016-04-23 01:18 - 00471552 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2016-05-10 16:49 - 2016-04-23 01:17 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2016-05-10 16:49 - 2016-04-23 01:17 - 00529920 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2016-05-10 16:49 - 2016-04-23 01:16 - 01319424 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2016-05-10 16:49 - 2016-04-23 01:16 - 00848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2016-05-10 16:49 - 2016-04-23 01:15 - 01073152 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2016-05-10 16:49 - 2016-04-23 01:15 - 00865792 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2016-05-10 16:49 - 2016-04-23 01:15 - 00673280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2016-05-10 16:49 - 2016-04-23 01:15 - 00348672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2016-05-10 16:49 - 2016-04-23 01:14 - 13383168 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-05-10 16:49 - 2016-04-23 01:14 - 00870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2016-05-10 16:49 - 2016-04-23 01:14 - 00821760 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2016-05-10 16:49 - 2016-04-23 01:14 - 00647680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2016-05-10 16:49 - 2016-04-23 01:14 - 00354304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2016-05-10 16:49 - 2016-04-23 01:13 - 00705536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2016-05-10 16:49 - 2016-04-23 01:13 - 00489984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2016-05-10 16:49 - 2016-04-23 01:13 - 00434688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll
2016-05-10 16:49 - 2016-04-23 01:10 - 12125696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-05-10 16:49 - 2016-04-23 01:10 - 00639488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2016-05-10 16:49 - 2016-04-23 01:09 - 03666432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2016-05-10 16:49 - 2016-04-23 01:08 - 05324288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2016-05-10 16:49 - 2016-04-23 01:07 - 02598912 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2016-05-10 16:49 - 2016-04-23 01:07 - 01500160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-05-10 16:49 - 2016-04-23 01:06 - 06974464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2016-05-10 16:49 - 2016-04-23 01:05 - 05502976 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2016-05-10 16:49 - 2016-04-23 01:05 - 02166784 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-05-10 16:49 - 2016-04-23 01:05 - 02066432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2016-05-10 16:49 - 2016-04-23 01:05 - 01946112 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2016-05-10 16:49 - 2016-04-23 01:05 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2016-05-10 16:49 - 2016-04-23 01:05 - 00613376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
2016-05-10 16:49 - 2016-04-23 01:04 - 04759040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2016-05-10 16:49 - 2016-04-23 01:04 - 01731072 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-05-10 16:49 - 2016-04-23 01:03 - 05660160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-05-10 16:49 - 2016-04-23 01:03 - 04894208 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2016-05-10 16:49 - 2016-04-23 01:03 - 02280960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-05-10 16:49 - 2016-04-23 01:03 - 02000896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2016-05-10 16:49 - 2016-04-23 01:03 - 00754176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2016-05-10 16:49 - 2016-04-23 01:02 - 07832576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-05-10 16:49 - 2016-04-23 01:02 - 02444288 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2016-05-10 16:49 - 2016-04-23 01:00 - 01390080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2016-05-10 16:49 - 2016-04-23 01:00 - 00984576 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2016-05-10 16:48 - 2016-05-06 01:53 - 00095072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdport.sys
2016-05-10 16:48 - 2016-05-06 01:05 - 00241664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll
2016-05-10 16:48 - 2016-05-06 01:03 - 00649216 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2016-05-10 16:48 - 2016-05-06 00:53 - 00351232 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnr.dll
2016-05-10 16:48 - 2016-05-06 00:49 - 00289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnrSvc.dll
2016-05-10 16:48 - 2016-05-06 00:44 - 00582656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll
2016-05-10 16:48 - 2016-05-06 00:43 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll
2016-05-10 16:48 - 2016-05-06 00:23 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcpopkeysrv.dll
2016-05-10 16:48 - 2016-04-23 03:12 - 00092352 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2016-05-10 16:48 - 2016-04-23 02:26 - 00707608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2016-05-10 16:48 - 2016-04-23 02:24 - 00638816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys
2016-05-10 16:48 - 2016-04-23 02:24 - 00335712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys
2016-05-10 16:48 - 2016-04-23 02:24 - 00099680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2016-05-10 16:48 - 2016-04-23 02:22 - 01161120 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2016-05-10 16:48 - 2016-04-23 02:18 - 00026408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2016-05-10 16:48 - 2016-04-23 02:13 - 00502104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
2016-05-10 16:48 - 2016-04-23 02:13 - 00306832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanapi.dll
2016-05-10 16:48 - 2016-04-23 02:13 - 00084832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
2016-05-10 16:48 - 2016-04-23 02:11 - 00696672 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
2016-05-10 16:48 - 2016-04-23 02:11 - 00390496 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll
2016-05-10 16:48 - 2016-04-23 02:11 - 00131424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ufxsynopsys.sys
2016-05-10 16:48 - 2016-04-23 02:11 - 00115040 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
2016-05-10 16:48 - 2016-04-23 02:10 - 00330072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2016-05-10 16:48 - 2016-04-23 02:09 - 00569744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SHCore.dll
2016-05-10 16:48 - 2016-04-23 02:09 - 00565600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2016-05-10 16:48 - 2016-04-23 02:09 - 00465760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2016-05-10 16:48 - 2016-04-23 02:08 - 00725776 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHCore.dll
2016-05-10 16:48 - 2016-04-23 02:07 - 01848072 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll
2016-05-10 16:48 - 2016-04-23 02:07 - 01536088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll
2016-05-10 16:48 - 2016-04-23 02:07 - 00204048 _____ (Microsoft Corporation) C:\WINDOWS\system32\rsaenh.dll
2016-05-10 16:48 - 2016-04-23 02:07 - 00183904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rsaenh.dll
2016-05-10 16:48 - 2016-04-23 02:06 - 00291360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininit.exe
2016-05-10 16:48 - 2016-04-23 02:02 - 00188256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2016-05-10 16:48 - 2016-04-23 02:01 - 00619296 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10level9.dll
2016-05-10 16:48 - 2016-04-23 02:01 - 00513368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10level9.dll
2016-05-10 16:48 - 2016-04-23 02:01 - 00393568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2016-05-10 16:48 - 2016-04-23 02:01 - 00217440 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2016-05-10 16:48 - 2016-04-23 02:00 - 01776768 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2016-05-10 16:48 - 2016-04-23 02:00 - 01594920 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2016-05-10 16:48 - 2016-04-23 02:00 - 01522152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2016-05-10 16:48 - 2016-04-23 02:00 - 01399224 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2016-05-10 16:48 - 2016-04-23 02:00 - 01337240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2016-05-10 16:48 - 2016-04-23 02:00 - 00550656 _____ (Microsoft Corporation) C:\WINDOWS\system32\directmanipulation.dll
2016-05-10 16:48 - 2016-04-23 02:00 - 00453472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\directmanipulation.dll
2016-05-10 16:48 - 2016-04-23 02:00 - 00058208 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwminit.dll
2016-05-10 16:48 - 2016-04-23 01:56 - 00534872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2016-05-10 16:48 - 2016-04-23 01:35 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosHostClient.dll
2016-05-10 16:48 - 2016-04-23 01:34 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbser.sys
2016-05-10 16:48 - 2016-04-23 01:34 - 00059392 _____ (Microsoft Corporation) C:\WINDOWS\system32\hmkd.dll
2016-05-10 16:48 - 2016-04-23 01:34 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2016-05-10 16:48 - 2016-04-23 01:33 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll
2016-05-10 16:48 - 2016-04-23 01:33 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshbth.dll
2016-05-10 16:48 - 2016-04-23 01:33 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\UcmCx.sys
2016-05-10 16:48 - 2016-04-23 01:33 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\system32\ByteCodeGenerator.exe
2016-05-10 16:48 - 2016-04-23 01:32 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\wificonnapi.dll
2016-05-10 16:48 - 2016-04-23 01:32 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseDesktopAppMgmtCSP.dll
2016-05-10 16:48 - 2016-04-23 01:30 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosHostClient.dll
2016-05-10 16:48 - 2016-04-23 01:29 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2016-05-10 16:48 - 2016-04-23 01:29 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
2016-05-10 16:48 - 2016-04-23 01:29 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\filecrypt.sys
2016-05-10 16:48 - 2016-04-23 01:29 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe
2016-05-10 16:48 - 2016-04-23 01:29 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hmkd.dll
2016-05-10 16:48 - 2016-04-23 01:29 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ByteCodeGenerator.exe
2016-05-10 16:48 - 2016-04-23 01:29 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll
2016-05-10 16:48 - 2016-04-23 01:28 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudDomainJoinDataModelServer.dll
2016-05-10 16:48 - 2016-04-23 01:28 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEDataLayerHelpers.dll
2016-05-10 16:48 - 2016-04-23 01:28 - 00104448 _____ (Microsoft Corporation) C:\WINDOWS\system32\BluetoothApis.dll
2016-05-10 16:48 - 2016-04-23 01:28 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
2016-05-10 16:48 - 2016-04-23 01:28 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wshbth.dll
2016-05-10 16:48 - 2016-04-23 01:27 - 00155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidclass.sys
2016-05-10 16:48 - 2016-04-23 01:27 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfdprov.dll
2016-05-10 16:48 - 2016-04-23 01:26 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdbusenum.dll
2016-05-10 16:48 - 2016-04-23 01:25 - 00630784 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
2016-05-10 16:48 - 2016-04-23 01:25 - 00617984 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2016-05-10 16:48 - 2016-04-23 01:25 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2016-05-10 16:48 - 2016-04-23 01:25 - 00207360 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2016-05-10 16:48 - 2016-04-23 01:24 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-05-10 16:48 - 2016-04-23 01:24 - 00292864 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2016-05-10 16:48 - 2016-04-23 01:24 - 00287232 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2016-05-10 16:48 - 2016-04-23 01:24 - 00181248 _____ (Microsoft Corporation) C:\WINDOWS\system32\shacct.dll
2016-05-10 16:48 - 2016-04-23 01:24 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\SubscriptionMgr.dll
2016-05-10 16:48 - 2016-04-23 01:24 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEDataLayerHelpers.dll
2016-05-10 16:48 - 2016-04-23 01:23 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2016-05-10 16:48 - 2016-04-23 01:23 - 00279040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ListSvc.dll
2016-05-10 16:48 - 2016-04-23 01:23 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\BrowserSettingSync.dll
2016-05-10 16:48 - 2016-04-23 01:23 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BluetoothApis.dll
2016-05-10 16:48 - 2016-04-23 01:22 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll
2016-05-10 16:48 - 2016-04-23 01:21 - 00479232 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2016-05-10 16:48 - 2016-04-23 01:20 - 00497152 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll
2016-05-10 16:48 - 2016-04-23 01:20 - 00484352 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll
2016-05-10 16:48 - 2016-04-23 01:20 - 00356864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
2016-05-10 16:48 - 2016-04-23 01:20 - 00307200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2016-05-10 16:48 - 2016-04-23 01:20 - 00137728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shacct.dll
2016-05-10 16:48 - 2016-04-23 01:19 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlansec.dll
2016-05-10 16:48 - 2016-04-23 01:19 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BrowserSettingSync.dll
2016-05-10 16:48 - 2016-04-23 01:18 - 00988672 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2016-05-10 16:48 - 2016-04-23 01:18 - 00515072 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2016-05-10 16:48 - 2016-04-23 01:18 - 00436736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2016-05-10 16:48 - 2016-04-23 01:18 - 00219648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll
2016-05-10 16:48 - 2016-04-23 01:17 - 00388608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2016-05-10 16:48 - 2016-04-23 01:17 - 00337920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanmsm.dll
2016-05-10 16:48 - 2016-04-23 01:15 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll
2016-05-10 16:48 - 2016-04-23 01:14 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2016-05-10 16:48 - 2016-04-23 01:14 - 00342528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2016-05-10 16:48 - 2016-04-23 01:12 - 00667648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll
2016-05-10 16:48 - 2016-04-23 01:07 - 00848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2016-05-10 16:48 - 2016-04-23 01:05 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
2016-05-10 16:48 - 2016-04-23 01:05 - 00103936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll
2016-05-10 16:48 - 2016-04-23 01:03 - 02193408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2016-05-10 16:48 - 2016-04-23 01:03 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
2016-05-10 16:48 - 2016-04-23 01:01 - 04775424 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2016-05-10 16:48 - 2016-04-23 00:45 - 00461824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2016-05-10 16:48 - 2016-04-22 23:10 - 00215040 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2016-05-10 16:48 - 2016-04-22 23:10 - 00002186 _____ C:\WINDOWS\system32\AppxProvisioning.xml
2016-05-10 16:48 - 2016-04-18 19:30 - 00002186 _____ C:\WINDOWS\SysWOW64\AppxProvisioning.xml
2016-05-02 09:16 - 2016-05-02 09:16 - 00635120 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp140.dll
2016-05-02 09:16 - 2016-05-02 09:16 - 00439528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcp140.dll
2016-05-02 09:16 - 2016-05-02 09:16 - 00390400 _____ (Microsoft Corporation) C:\WINDOWS\system32\vccorlib140.dll
2016-05-02 09:16 - 2016-05-02 09:16 - 00333080 _____ (Microsoft Corporation) C:\WINDOWS\system32\concrt140.dll
2016-05-02 09:16 - 2016-05-02 09:16 - 00267008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vccorlib140.dll
2016-05-02 09:16 - 2016-05-02 09:16 - 00243480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\concrt140.dll
2016-05-02 09:16 - 2016-05-02 09:16 - 00088816 _____ (Microsoft Corporation) C:\WINDOWS\system32\vcruntime140.dll
2016-05-02 09:16 - 2016-05-02 09:16 - 00085232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vcruntime140.dll
2016-04-25 00:36 - 2016-04-25 00:36 - 01499408 _____ (Microsoft Corporation) C:\WINDOWS\system32\WdfCoInstaller01007.dll
2016-04-25 00:36 - 2016-04-25 00:36 - 00716928 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinUSBCoInstaller.dll

==================== Um Mês Modificados arquivos e pastas ========

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2016-05-23 17:29 - 2016-04-13 12:44 - 00686976 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2016-05-23 17:29 - 2016-04-13 12:44 - 00535080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2016-05-16 03:32 - 2016-03-09 17:42 - 01087488 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2016-05-16 03:32 - 2016-03-09 17:42 - 00304752 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2016-04-25 00:36 - 2015-12-08 04:01 - 00221824 _____ (Samsung Electronics Co., Ltd.) C:\WINDOWS\system32\Drivers\ssudserd.sys
2016-04-25 00:35 - 2015-12-08 04:00 - 00221824 _____ (Samsung Electronics Co., Ltd.) C:\WINDOWS\system32\Drivers\ssudmdm.sys
2016-04-25 00:35 - 2015-12-08 04:00 - 00129152 _____ (Samsung Electronics Co., Ltd.) C:\WINDOWS\system32\Drivers\ssudbus.sys

==================== Arquivos na raiz de alguns diretórios =======

2016-05-24 10:48 - 2016-05-24 10:48 - 6859776 _____ () C:\Users\tlssa\AppData\Roaming\agent.dat
2016-05-24 10:48 - 2016-05-24 10:48 - 0054272 _____ () C:\Users\tlssa\AppData\Roaming\ApplicationHosting.dat
2016-05-23 17:10 - 2016-05-23 17:10 - 0001251 _____ () C:\Users\tlssa\AppData\Roaming\Bubble Dock.boostrap.log
2016-05-23 17:10 - 2016-05-23 17:15 - 0005714 _____ () C:\Users\tlssa\AppData\Roaming\Bubble Dock.installation.log
2016-05-24 10:48 - 2016-05-24 10:48 - 0067776 _____ () C:\Users\tlssa\AppData\Roaming\Config.xml
2016-05-24 10:48 - 2016-05-24 10:47 - 0947712 _____ () C:\Users\tlssa\AppData\Roaming\Groovelab.exe
2016-05-24 10:48 - 2016-05-24 10:48 - 0072827 _____ () C:\Users\tlssa\AppData\Roaming\Groovelab.tst
2016-05-24 10:48 - 2016-05-24 10:47 - 0947712 _____ () C:\Users\tlssa\AppData\Roaming\HomeDax.exe
2016-05-24 10:48 - 2016-05-24 10:48 - 1756488 _____ () C:\Users\tlssa\AppData\Roaming\HomeDax.tst
2016-05-24 10:45 - 2016-05-24 10:47 - 0017760 _____ () C:\Users\tlssa\AppData\Roaming\InstallationConfiguration.xml
2016-05-24 10:45 - 2016-05-24 10:45 - 0127488 _____ () C:\Users\tlssa\AppData\Roaming\Installer.dat
2016-05-24 10:48 - 2016-05-24 10:48 - 0126464 _____ () C:\Users\tlssa\AppData\Roaming\lobby.dat
2016-05-24 10:48 - 2016-05-24 10:48 - 0018432 _____ () C:\Users\tlssa\AppData\Roaming\Main.dat
2016-05-24 10:48 - 2016-05-24 10:48 - 0005568 _____ () C:\Users\tlssa\AppData\Roaming\md.xml
2016-05-24 10:48 - 2016-05-24 10:48 - 0126464 _____ () C:\Users\tlssa\AppData\Roaming\noah.dat
2016-05-24 10:48 - 2016-05-24 10:48 - 0505600 _____ (JollyMolly Inc) C:\Users\tlssa\AppData\Roaming\S--Tone.bin
2016-05-24 10:45 - 2016-05-24 10:45 - 0848437 _____ () C:\Users\tlssa\AppData\Roaming\Singletrax.bin
2016-05-24 10:47 - 2016-05-24 10:47 - 0505640 _____ (JollyMolly Inc) C:\Users\tlssa\AppData\Roaming\SoloLax.bin
2016-05-24 10:48 - 2016-05-24 10:48 - 0032038 _____ () C:\Users\tlssa\AppData\Roaming\uninstall_temp.ico
2016-05-23 17:10 - 2016-05-23 17:10 - 0000097 _____ () C:\Users\tlssa\AppData\Roaming\WindApp.boostrap.log

Alguns arquivos em TEMP:
====================
C:\Users\tlssa\AppData\Local\Temp\100D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\101E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\102F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1030.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1050.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1051.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1061.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1062.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1073.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1074.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1075.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1086.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1087.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1097.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1098.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\10A9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\10AA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\10CA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\10CB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\10DC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\10DD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\10DE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\10FE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\10FF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1100.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1111.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1112.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1122.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1123.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1134.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1135.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1146.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1156.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1167.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1177.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1188.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\119.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\11A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\11A8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\11A9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\11B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\11CA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\11CB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\11CC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\11DC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\11ED.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\11EE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\11FE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\11FF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1200.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1211.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1222.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1223.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1233.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1234.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1255.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1256.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1257.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1267.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1278.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1279.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\127A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\128A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\129B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\129C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\12AD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\12AE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\12BE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\12C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\12CF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\12D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\12D0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\12E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\12E1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\12E2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\12F2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\12F3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1304.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1305.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1315.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1316.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1327.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1328.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1329.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\133A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\133B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\134B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\134C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\135D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\135E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\136F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1370.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1380.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1381.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1382.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1393.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1394.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\13A4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\13A5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\13B6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\13B7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\13C8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\13C9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\13D9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\13FA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\13FB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\140B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\142B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\143C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\144D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\144E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\144F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\145F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1470.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1481.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1491.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1492.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1493.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\14C3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\14C4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\14D5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\14D6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\14E6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\14E7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\14E8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\14F9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\14FA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\14FB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\152B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\152C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\155C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\155D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\156D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\156E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\157F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1580.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1591.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1592.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\15A2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\15A3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\15A4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\15B5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\15B6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\15C6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\15C7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\15F7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\15F8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1609.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\160A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\161B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\161C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\162C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\164C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\164D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\165E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\165F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1670.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1671.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1672.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1682.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1683.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1694.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1695.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\16C5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\16C6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\16D6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\16D7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\16D8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\16E9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\16EA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\170A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\170B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\170C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\171D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\171E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\172F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1730.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1731.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1741.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1742.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1753.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1754.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1764.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1765.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1776.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1777.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1778.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1789.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\178A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\179A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\179B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\179C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\17AD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\17AE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\17BF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\17C0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\17D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\17E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\17E0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\17E1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\17F1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\17F2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\17F3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1804.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1805.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1806.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1817.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1818.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1828.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1829.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\182A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\183B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\183C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\186C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\186D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\187D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\187E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\189F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\18BF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\18C0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\18F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\18F0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\190.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1920.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1930.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1931.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1952.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1953.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1963.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1964.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1975.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1976.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1986.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1987.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1988.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1999.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\199A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\19AB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\19AC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\19AD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\19BD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\19BE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\19CF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\19D0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\19E1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\19E2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\19E3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1A0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1A1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1A12.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1A13.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1A24.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1A25.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1A45.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1A66.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1A76.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1A77.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1A88.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1A89.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1A99.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1AAA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1AAB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1AEB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1AEC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1AFC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1AFD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1B0E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1B0F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1B1F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1B2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1B3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1B30.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1B4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1B70.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1B80.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1B91.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1BA1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1BA2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1BB3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1BC4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1BC5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1BD5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1BD6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1BE7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1BE8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1BF9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1C09.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1C1A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1C1B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1C2B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1C4C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1C5C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1C6D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1C8D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1C8E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1C9F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1CA0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1CC0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1CC1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1CD2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1CD3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1CE3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1CE4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1CF5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1CF6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1D07.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1D08.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1D37.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1D77.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1DA7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1E06.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1E16.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1E46.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1E47.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1E77.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1E88.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1EA8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1EA9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1EB9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1EDA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1EDB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1EEB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1F1B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1F3B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1F4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1F4C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1F4D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1F5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1F5E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1F5F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1F6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1F6F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1F80.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1F81.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1F92.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1F93.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1FA3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1FA4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1FB5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1FB6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1FC6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1FC7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1FD8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1FE9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1FEA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1FFA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\1FFB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\20.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\200C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\201D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\201E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\202E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\203F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2040.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2050.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2051.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2062.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2063.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2064.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2075.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2085.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2096.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\20A7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\20A8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\20B8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\20B9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\20BA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\20DA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\20DB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\20EC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\20ED.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\20FE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\20FF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\21.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\210F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2110.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2121.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2122.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2123.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2153.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2163.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2164.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2185.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2186.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2196.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2197.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\21A8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\21B9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\21BA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\21CA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\21CB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\21DC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\21DD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\21ED.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\21EE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\21FF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\221F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2230.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\225.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\226.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2260.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2280.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2281.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2292.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2293.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\22B3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\22C4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\22D4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\22D5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\22E6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\22E7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\22F7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2308.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2319.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\231A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\232A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\233B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\234C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\235C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\235D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\236E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\236F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\237.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\237F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\238.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2380.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2391.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\23B1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\23C2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\23D3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\23D4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\23D5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\23E5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\23E6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\23F7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2465.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2476.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2477.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2487.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2488.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2499.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\249A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\249B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\24BB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\24CC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\24DD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\24DE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\24FE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\250E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\250F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2520.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2521.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2522.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2542.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2553.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2554.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2555.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2566.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2567.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2568.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2578.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2579.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2599.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\259A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\25AB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\25AC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\25AD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\25BE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\25BF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\25DF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\25F0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\25F1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2601.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2602.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2613.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2614.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2615.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2625.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2626.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2647.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2667.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2678.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\26F6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2716.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2717.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2727.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2728.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2768.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2769.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\278.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2789.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\278A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\279B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\279C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\27EB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\27EC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\27FD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\27FE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\27FF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\280F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2810.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2821.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2851.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2852.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2862.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2863.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2874.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2875.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\288.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\289.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\28D4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\28E4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\28E5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2906.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2916.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2917.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2918.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2929.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2959.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\295A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\296A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\296B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\297C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\298D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\298E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\299E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\29A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\29B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\29C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\29CE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\29DF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\29EF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\29F0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\29F1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2A02.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2A13.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2A23.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2A34.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2A35.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2A45.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2A46.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2A57.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2A58.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2A69.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2A6A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2A6B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2A7B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2A7C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2A8D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2A9E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2A9F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2AAF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2AC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2AC0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2AC1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2AD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2AD1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2AD2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2AE3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2AF4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2AF5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2B05.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2B06.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2B17.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2B18.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2B29.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2B2A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2B3A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2B3B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2B5B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2B7C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2B8C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2B9D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2B9E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2BAF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2BB0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2BC0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2BC1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2BD2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2BD3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2BE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2BE3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2BF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2BF4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2BF5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2C06.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2C07.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2C17.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2C18.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2C29.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2C68.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2C79.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2C7A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2C8B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2C9B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2C9C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2C9D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2CDD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2CDE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2CEE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2CEF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2D0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2D00.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2D01.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2D1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2D12.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2D22.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2D33.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2D44.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2D54.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2D65.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2D66.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2D76.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2D77.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2D88.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2D89.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2D8A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2D9B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2DAB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2DAC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2DBD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2DCE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2DCF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2DDF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2DE0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2E00.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2E01.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2E1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2E12.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2E13.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2E14.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2E2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2E25.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2E26.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2E27.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2E47.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2E58.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2E59.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2E5A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2E6A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2E6B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2E6C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2E7D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2E7E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2E8E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2E9F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2EA0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2EA1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2EB2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2EB3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2EC3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2EC4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2EC5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2ED6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2ED7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2ED8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2EE9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2EEA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2EFA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2EFB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2F0C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2F0D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2F1D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2F1E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2F2F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2F3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2F4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2F40.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2F41.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2F5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2F51.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2F52.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2F53.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2F64.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2F65.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2F76.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2F77.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2F87.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2F88.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2F89.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2F9A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2F9B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2F9C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2FAC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2FAD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2FBE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2FBF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2FC0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2FD1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2FE1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2FE2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2FE3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2FF4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\2FF5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3006.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3007.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3008.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3018.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3019.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\301A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\302B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\302C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\303C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\303D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\303E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\304F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3050.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3051.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3062.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3063.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3073.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3074.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3075.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3086.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3087.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3098.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3099.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\309A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\30AA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\30AB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\30AC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\30BD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\30BE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\30BF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\30CF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\30D0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\30E1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\30E2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\30E3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\30F4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\30F5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3105.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3116.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3117.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3118.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3129.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\312A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\313A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\313B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\313C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\314D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\314E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\315E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\315F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3160.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3171.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3172.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3173.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3184.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3194.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3195.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\31A6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\31A7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\31B8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\31B9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\31C9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\31CA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\31EA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\31EB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\31FC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\31FD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\32.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\320E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\320F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\321F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3220.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3221.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3232.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3233.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3244.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3245.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3246.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3256.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3267.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3268.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3278.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3279.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\327A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\328B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\328C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\329D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\329E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\32AE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\32AF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\32C0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\32C1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\32D2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\32D3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\32D4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\32E4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\32E5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\32F6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\32F7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\33.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3307.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3308.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3319.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\331A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\331B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\332C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\332D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\333D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\333E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\334.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\334F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3350.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3351.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3362.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3363.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3373.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3374.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3375.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3395.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3396.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3397.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\33A8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\33B9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\33BA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\33CA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\33CB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\33CC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\33DD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\33DE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\33EF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\33F0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\33F1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\34.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3401.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3402.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3413.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3414.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3415.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3425.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3426.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3427.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3438.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3439.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\344A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\344B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\345.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\345B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\345C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\345D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\346E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\346F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3480.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3481.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3482.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3492.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3493.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\34A4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\34A5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\34A6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\34C6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\34D7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\34D8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\34E8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\34E9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\34FA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\34FB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\350C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\350D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\351D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\351E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\352F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3530.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3531.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3541.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3542.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3553.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3554.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3555.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\356.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3566.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3567.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3568.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\357.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3578.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3579.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\358A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\358B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\358C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\359D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\359E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\359F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\35AF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\35B0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\35C1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\35C2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\35C3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\35D3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\35D4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\35D5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\35E6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\35F7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\35F8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3608.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3609.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\360A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\361B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\361C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\361D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\362D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\362E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\363E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\363F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3650.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3660.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3661.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3672.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3673.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3674.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3685.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3686.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3687.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3697.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3698.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3699.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\36AA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\36AB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\36AC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\36BD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\36BE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\36BF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\36CF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\36D0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\36E1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\36F1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\36F2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3703.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3704.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3705.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3716.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3717.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3727.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3728.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3729.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\373A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\373B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\374C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\374D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\375D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\375E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\376F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3770.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3780.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3781.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3792.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3793.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\37A4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\37A5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\37B5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\37B6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\37C7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\37C8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\37D9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\37DA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\37DB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\37EB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\37EC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\37FD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\37FE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\380E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\380F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3810.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3821.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3822.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3833.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3834.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3835.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3845.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3846.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3847.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3858.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3859.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\386A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\386B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\387.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\387B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\387C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\388D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\389D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\389E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\38AF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\38B0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\38C1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\38C2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\38C3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\38D3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\38D4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\38E5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\38E6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\38E7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\38F8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\38F9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3909.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\390A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\390B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\391C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\391D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\391E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\392E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\392F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3940.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3941.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3942.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3953.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3954.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3955.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3965.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3966.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\397.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3977.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3978.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\398.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3989.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\398A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\398B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\399.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\399B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\399C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\399D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\39AE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\39AF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\39BF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\39C0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\39C1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\39D2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\39D3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\39D4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\39E5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\39E6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\39E7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\39F7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\39F8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3A09.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3A0A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3A0B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3A1C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3A1D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3A2D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3A2E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3A2F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3A40.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3A41.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3A42.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3A52.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3A53.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3A64.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3A65.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3A66.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3A77.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3A78.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3A79.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3A89.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3A8A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3A9B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3A9C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3A9D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3AA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3AAE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3AAF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3AB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3AB0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3AC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3AC0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3AC1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3AD2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3AD3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3AD4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3AE4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3AE5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3AF6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3AF7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3AF8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3B09.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3B0A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3B0B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3B1B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3B1C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3B2D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3B2E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3B2F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3B40.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3B41.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3B42.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3B52.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3B53.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3B54.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3B65.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3B66.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3B76.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3B77.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3B78.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3B89.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3B8A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3B9B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3B9C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3B9D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3BAD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3BAE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3BAF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3BC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3BC0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3BC1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3BD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3BD2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3BD3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3BD4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3BE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3BE4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3BE5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3BE6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3BF7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3BF8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3BF9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3C09.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3C0A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3C1B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3C2C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3C2D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3C2E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3C3E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3C3F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3C50.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3C51.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3C62.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3C63.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3C64.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3C74.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3C75.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3C76.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3C87.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3C88.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3C98.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3C99.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3C9A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3CAB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3CAC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3CBD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3CBE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3CCE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3CCF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3CE0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3CE1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3CF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3CF2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3CF3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3CF4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3D0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3D04.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3D05.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3D16.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3D17.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3D18.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3D28.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3D29.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3D3A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3D3B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3D3C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3D4D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3D4E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3D4F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3D5F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3D60.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3D61.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3D67.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3D72.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3D73.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3D84.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3D85.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3D95.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3D96.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3DA7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3DA8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3DB8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3DB9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3DBA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3DCB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3DCC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3DDD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3DDE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3DEE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3DEF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3E00.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3E01.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3E21.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3E41.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3E52.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3E53.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3E64.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3E74.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3E85.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3E86.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3E97.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3E98.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3EA8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3EA9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3EBA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3EBB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3ECB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3ECC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3ECD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3EDE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3EDF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3EF0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3EF1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3F0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3F1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3F2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3F21.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3F22.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3F32.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3F33.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3F44.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3F45.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3F55.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3F66.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3F77.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3F78.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3F88.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3F89.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3F8A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3F9B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3F9C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3FAD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3FBD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3FBE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3FBF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3FD0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3FD1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3FE1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3FE2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\3FF3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4004.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4005.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4015.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4016.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4027.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4028.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4029.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\403.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\403A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\403B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\404B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\404C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\404D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\405E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\405F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4060.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4070.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4071.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4082.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4083.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4084.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4095.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\40A5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\40A6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\40A7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\40B8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\40B9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\40CA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\40CB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\40CC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\40DC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\40DD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\40EE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\40EF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\40F0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4100.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4101.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4112.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4113.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4124.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4125.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4135.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\414.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4146.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4147.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\415.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\416.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4167.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4187.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4188.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4199.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\419A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\41AB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\41AC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\41BC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\41BD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\41CE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\41DF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\41EF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\41F0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4201.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4211.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4222.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4223.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4224.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4235.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4245.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4246.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4257.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4258.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4269.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\426A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\426B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\427B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\427C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\428D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\429D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\429E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\429F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\42B0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\42B1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\42C2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\42C3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\42D3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\42D4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\42D5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\42E6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\42E7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\42E8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\42f0-14b7-2af0-f3ea.exe
C:\Users\tlssa\AppData\Local\Temp\42F9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\42FA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\430A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\430B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\430C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\431D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\431E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\431F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\432F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4330.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4341.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4342.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4343.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4354.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4355.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4365.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4366.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4367.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4378.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4379.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\438A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\438B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\438C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\439C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\439D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\43AE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\43AF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\43BF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\43C0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\43C1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\43D2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\43D3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\43D4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\43E5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\43E6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\43E7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\43F7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\43F8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\44.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4409.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\440A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\440B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\441C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\441D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\441E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\442E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\442F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4430.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4441.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4442.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4452.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4453.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4454.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4465.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4466.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4477.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4478.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4479.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4489.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\448A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\449B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\44AC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\44BC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\44BD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\44BE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\44DE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\44DF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\44F0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\44F1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\44F2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4503.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4523.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4534.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4535.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4545.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4556.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4557.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4558.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4568.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4569.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\456A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\457B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\457C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\458D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\458E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\458F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\459F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\45A0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\45A1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\45B2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\45B3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\45C4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\45C5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\45C6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\45D6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\45E7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\45E8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\45F8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\45F9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\460A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\460B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\461C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\461D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\462D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\462E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\463F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4640.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4651.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4690.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4691.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4692.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\46A3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\46A4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\46A5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\46B5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\46C6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\46C7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\46C8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\46D9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\46DA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\46EA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\46EB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\46FC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\46FD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\46FE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\470E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\470F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4720.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4721.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4722.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4733.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4734.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\474.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4744.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4745.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4756.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4757.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4768.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4769.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4779.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\477A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\478B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\478C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\47AC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\47BD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\47BE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\47EE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\47EF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\47FF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4800.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4811.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4812.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4813.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4823.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4824.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4835.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4836.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4837.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4838.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4849.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\484A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\485A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\485B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\485C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\486D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\486E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\487F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\489F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\48CF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\48DF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\48F0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\48F1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4921.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4922.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4932.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4933.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4934.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4945.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4946.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\495.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4957.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4958.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4959.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4969.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\496A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\496B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\497C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\498D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\498E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\498F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\499F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\49A0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\49B1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\49B2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\49C2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\49C3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\49D4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\49D5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\49E6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\49E7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\49E8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\49F8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\49F9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4A0A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4A0B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4A1C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4A2C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4A2D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4A3E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4A3F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4A4F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4A50.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4A61.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4A62.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4A63.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4A74.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4A75.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4A76.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4A86.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4A97.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4A98.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4A99.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4AAA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4AAB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4ABB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4ADB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4B5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4C82.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4E5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4E6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4EC5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4ED6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4ED7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4ED8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4EE9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4EEA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4EFA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4EFB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4F0C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4F0D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4F1E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4F1F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4F20.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4F30.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4F31.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4F42.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4F43.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4F44.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4F54.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4F6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4F65.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4F66.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4F67.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4F78.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4F79.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4F7A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4F8A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4F8B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4F8C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4F9D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\4FEC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\507.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\508.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\50A9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\50D8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5108.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5119.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\511A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\512B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\512C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\513C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\514D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\514E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\515E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\515F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5160.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5171.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5182.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5183.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5184.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\519.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5194.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5195.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\51A6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\51A7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\51A8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\51B9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\51BA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\51BB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\51CB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\51CC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\51CD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\51DE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\51DF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\51EF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\51F0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5211.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5212.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5213.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5223.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5224.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5235.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5236.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5237.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5248.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5249.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5259.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\525A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\525B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\526C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\526D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\527D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\527E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\527F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5290.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5291.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5292.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\52A3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\52B3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\52B4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\52C5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\52C6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\52D7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\52D8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\52E8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\52E9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\52FA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\52FB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\530B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\530C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\530D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\531E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\531F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5330.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5331.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5341.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5342.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5353.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5364.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5365.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5366.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5376.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5387.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5397.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5398.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5399.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\53AA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\53CA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\53CB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\53CC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\53D9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\53DD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\53DE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\53EF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\53F0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5400.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5401.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5402.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5413.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5414.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5424.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5435.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5446.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5456.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5467.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5478.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5488.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5499.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\549A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\54AA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\54CB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\54CC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\54DC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\54DD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\54EE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\54EF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\54F0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5501.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5502.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5503.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5513.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5514.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5554.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5564.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5565.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\558.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5595.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5596.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\55A7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\55A8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\55B8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\55B9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\55CA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\55CB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\55DC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\55DD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\55DE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\55EE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\55EF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\55F0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5601.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5612.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5613.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5614.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5624.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5635.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5636.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5646.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5647.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5658.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5659.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\566A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\566B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\566C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\567C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\567D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\568E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\568F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5690.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\56A1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\56A2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\56B2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\56B3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\56B4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\56C5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\56C6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\56E6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\56E7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\5CB1KSW36H.exe
C:\Users\tlssa\AppData\Local\Temp\60bc-f9ba-9f36-c9ec.exe
C:\Users\tlssa\AppData\Local\Temp\672.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\673.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\684.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\685.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\696.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\697.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\6B7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\6be6-eafe-fb37-9b98.exe
C:\Users\tlssa\AppData\Local\Temp\6C7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\6C8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\6d5f-5eaa-54c1-38d1.exe
C:\Users\tlssa\AppData\Local\Temp\6D9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\6DA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\6EB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\6FB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\6FC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\70D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\70E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\70F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\720.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\721.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\731.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\732.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\743.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\744.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\7460.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\7491.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\764.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\775.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\776.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\777.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\787.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\788.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\799.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\79A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\79B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\7a69-c9e9-112c-66ad.exe
C:\Users\tlssa\AppData\Local\Temp\7AC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\7BC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\7BD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\7CE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\7CF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\7D0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\7F0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\7F1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\802.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\803.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\804.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\814.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\815.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\826.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\827.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\828.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\839.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\83A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\84.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\84A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\84B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\84C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\85D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\85E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\86E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\86F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\87EB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\880.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\881.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\882.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\893.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\894.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\8A4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\8A5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\8A6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\8B7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\8B8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\8C9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\8CA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\8CB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\8DB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\8DC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\8ED.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\8FD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\90E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\90F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\92F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\930.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\94.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\95.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\97F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\980.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\981.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\992.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\9bcd-2206-e88c-52e0.exe
C:\Users\tlssa\AppData\Local\Temp\9E1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\9F2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\A02.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\A03.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\A14.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\A15.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\A26.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\A27.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\A28.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\A38.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\A39.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\A4A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\A4B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\A4C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\A6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\A7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\A8B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\A9C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\AA93.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\AAD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\AAE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\ABE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\ABF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\AFF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\B00.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\B01.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\B11.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\B12.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\B23.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\B34.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\B35.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\B45.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\B46.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\B57.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\b63f-27cb-417a-a0be.exe
C:\Users\tlssa\AppData\Local\Temp\B68.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\B69.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\B6A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\B7A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\B7B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\B8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\B9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\BAB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\BAC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\BBD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\BBE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\BCE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\BCF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\BE0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\be02-4123-cad4-82e3.exe
C:\Users\tlssa\AppData\Local\Temp\BE1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\BE2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\BF3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\BF4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\C04.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\C05.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\C06.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\C17.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\C18.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\C19.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\C29.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\C2A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\c2f0-c572-a8ea-f044.exe
C:\Users\tlssa\AppData\Local\Temp\C3B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\C3C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\C3D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\C4E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\C5E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\C5F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\C60.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\C81.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\C82.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\C83.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\C9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\C93.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\C94.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\C95.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\CA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\CA6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\CA7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\CA8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\CB8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\CB9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\CCA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\CCB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\CCC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\CDD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\CDE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\cdea-bfda-bfab-25ff.exe
C:\Users\tlssa\AppData\Local\Temp\CEE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\CEF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\CF14.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\D1F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\D30.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\D50.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\D80.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\D81.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\D92.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\D93.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\DA3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\DB4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\DB5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\DC5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\DC6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\DC7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\DD8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\DD9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\DF9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\downloader.dll
C:\Users\tlssa\AppData\Local\Temp\E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E032.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E0A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E0B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E1C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E1D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E2D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E2E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E428.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E448.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E458.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E459.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E45A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E46B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E46C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E46D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E47E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E47F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E48F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E490.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E491.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E4A2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E4A3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E4A4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E4B5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E4B6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E4B7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E4C7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E4C8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E4C9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E4DA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E4DB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E4DC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E4EC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E4ED.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E4EE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E4FF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E500.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E501.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E512.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E513.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E514.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E524.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E525.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E526.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E537.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E538.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E539.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E53A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E54B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E54C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E54D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E55D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E55E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E55F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E570.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E571.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E572.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E582.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E583.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E594.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E595.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E596.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E5A7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E5A8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E5A9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E5B9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E5BA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E5BB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E5CC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E5CD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E5CE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E5DF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E5E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E5E0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E5E1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E5F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E5F1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E5F2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E60.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E603.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E604.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E605.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E615.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E616.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E617.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E628.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E629.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E62A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E63B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E64B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E64C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E65D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E65E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E66F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E670.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E671.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E681.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E682.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E683.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E694.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E695.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E696.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E6A6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E6A7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E6B8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E6B9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E6BA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E6CB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E6CC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E6CD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E6DD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E6DE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E6DF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E6F0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E6F1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E6F2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E703.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E704.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E71.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E714.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E715.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E716.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E727.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E728.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E738.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E739.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E73A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E74B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E74C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E74D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E75E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E75F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E76F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E770.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E771.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E782.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E783.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E784.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E795.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E796.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E7A6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E7A7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E7A8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E7B9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E7BA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E7BB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E7CB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E7CC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E7CD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E7DE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E7DF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E7F0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E7F1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E7F2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E802.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E803.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E814.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E815.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E816.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E827.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E828.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E829.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E839.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E83A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E83B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E84C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E84D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E84E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E85E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E85F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E860.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E871.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E872.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E873.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E884.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E885.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E895.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E896.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E8A7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E8A8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E8B9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E8BA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E8CA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E8CB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E8CC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E8DD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E8DE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E8EE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E8EF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E900.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E901.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E912.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E913.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E914.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E924.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E925.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E936.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E947.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E967.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\E9F4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EA05.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EA06.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EA07.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EA18.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EA19.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EA29.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EA2A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EA4B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EA5B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EA5C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EA6D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EA6E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EA7E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EA7F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EA90.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EA91.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EAA1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EAA2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EAB2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EAB3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EAC4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EB23.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EB53.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EBA2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EBD2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EBD3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EBE3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EBE4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EBE5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EBF6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EC16.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EC17.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EC28.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EC29.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EC39.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EC3A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EC5B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EC5C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EC6C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EC6D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EC7E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EC7F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EC8F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EC90.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\ECA1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\ECA2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\ECB3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\ECC3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\ECC4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\ECC5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\ECD6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\ECD7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\ECE8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\ECE9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\ECF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\ECF9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\ECFA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\ECFB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\ED0C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\ED0D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\ED1D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\ED2E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\ED2F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\ED40.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\ED50.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\ED61.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\ED62.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\ED73.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\ED74.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\ED84.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\ED85.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\ED86.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\ED97.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\ED98.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EDA8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EDA9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EDBA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EDBB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EDBC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EDCD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EDCE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EDDE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EDEF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EE0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EE00.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EE1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EE10.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EE21.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EE31.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EE32.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EE43.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EE44.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EE45.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EE56.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EE57.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EE58.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EE68.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EE69.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EE7A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EE7B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EE7C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EE8D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EE9D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EEAE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EEAF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EEBF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EEC0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EED1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EEE2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EEE3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EEE4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EEF4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EEF5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EF06.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EF07.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EF08.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EF19.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EF1A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EF2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EF2A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EF2B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EF2C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EF3D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EF3E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EF4E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EF4F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EF50.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EF61.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EF62.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EF73.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EF74.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EF84.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EF85.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EF96.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EF97.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EF98.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EFA9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EFAA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EFBA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EFBB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EFBC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EFCD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EFCE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EFDE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EFDF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EFE0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EFF1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\EFF2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F003.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F004.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F014.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F02.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F025.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F026.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F03.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F037.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F038.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F039.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F049.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F04A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F05B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F05C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F05D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F06D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F06E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F07F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F080.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F081.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F092.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F093.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F0A3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F0A4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F0A5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F0B6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F0B7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F0C8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F0C9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F0CA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F0DA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F0DB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F0EC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F0ED.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F0EE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F0FE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F0FF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F100.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F111.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F112.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F113.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F124.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F125.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F135.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F136.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F137.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F14.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F148.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F149.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F15.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F15A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F15B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F15C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F16C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F16D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F17E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F17F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F180.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F190.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F191.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F192.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F1A3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F1A4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F1B5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F1C5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F1C6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F1D7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F1D8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F1E9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F1EA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F1FA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F1FB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F20C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F20D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F20E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F21E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F21F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F230.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F231.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F232.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F243.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F244.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F245.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F255.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F256.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F257.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F26.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F268.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F27.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F2B7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F2B8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F2B9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F2CA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F2CB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F2FB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F31B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F32B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F32C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F36C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F36D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F37.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F37E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F37F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F38.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F38F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F3A0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F3A1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F3B1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F3C2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F3D3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F3D4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F3E4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F3F5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F406.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F416.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F417.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F428.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F458.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F459.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F469.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F48A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F49A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F4AB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F4AC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F4BC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F4BD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F4CE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F4CF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F4E0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F4E1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F4F1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F4F2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F503.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F504.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F505.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F516.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F517.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F527.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F528.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F529.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F53A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F54A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F55B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F56C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F57C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F57D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F58E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F58F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F590.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F5A1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F5A2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F5B2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F5B3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F5C4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F5C5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F5C6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F5D6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F5E7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F5F8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F608.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F609.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F60A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F61B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F61C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F62D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F62E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F63E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F63F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F650.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F651.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F652.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F662.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F663.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F674.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F675.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F686.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F687.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F697.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F6B8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F6C8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F6C9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F6CA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F6DB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F6DC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F6EC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F6ED.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F6EE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F6FF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F700.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F711.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F712.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F722.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F723.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F724.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F735.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F736.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F737.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F748.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F749.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F759.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F75A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F75B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F76C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F76D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F77D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F77E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F77F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F790.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F791.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F7A2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F7A3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F7A4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F7B4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F7B5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F7B6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F7C7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F7D8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F7D9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F7E9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F819.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F81A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F82B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F83B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F83C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F84D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F85E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F85F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F860.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F880.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F890.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F8A1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F8B2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F8B3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F8B4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F8C4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F8D5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F8D6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\f8dd-3ea4-4d20-bc2e.exe
C:\Users\tlssa\AppData\Local\Temp\F8E7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F8E8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F8E9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F8F9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F8FA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F90B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F90C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F91C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F91D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F91E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F92F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F930.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F941.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F942.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F943.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F953.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F954.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F965.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F966.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F967.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F978.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F979.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F97A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F98A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F99B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F9AB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F9BC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F9BD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F9BE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F9CF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F9DF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F9E0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F9F1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F9F2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\F9F3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FA04.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FA05.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FA15.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FA16.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FA27.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FA28.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FA29.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FA39.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FA3A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FA3B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FA4C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FA6C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FA6D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FA6E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FA7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FA7F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FA80.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FA91.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FA92.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FAA2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FAA3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FAA4.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FAB5.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FAB6.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FAB7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FB06.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FB07.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FB18.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FB19.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FB29.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FB2A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FB3B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FB3C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FB7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FB8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FB8B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FB9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FBDA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FBEB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FC0B.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FC1C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FC2C.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FC2D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FC3E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FC3F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FC40.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FC50.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FC61.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FC72.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FC73.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FC74.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FC84.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FC85.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FC96.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FCA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FCA7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FCB7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FCB8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FCC9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FCCA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FCCB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FCDB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FCDC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FCED.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FCEE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FCFF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FD00.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FD01.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FD11.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FD12.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FD61.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FD72.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FD73.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FD84.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FD85.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FD95.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FD96.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FDA7.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FDA8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FDC8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FDD9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FDE9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FDEA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FDFB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FDFC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FE0D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FE1D.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FE2E.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FE2F.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FE30.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FE41.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FE42.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FE52.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FE53.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FE54.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FE65.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FE66.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FE76.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FE77.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FE78.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FEA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FEA8.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FEA9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FEAA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FEBB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FEBC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FEBD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FECE.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FECF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FEDF.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FEE0.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FEE1.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FEF2.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FEF3.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FF03.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FF04.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FF25.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FF26.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FF36.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FF37.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FF48.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FF49.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FF98.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FFA9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FFB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FFC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FFD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FFD9.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FFDA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FFEA.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FFEB.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FFFC.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FFFD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\FGY51Y7I8H.exe
C:\Users\tlssa\AppData\Local\Temp\InstallHelper.exe
C:\Users\tlssa\AppData\Local\Temp\M1NABM8W1F.exe
C:\Users\tlssa\AppData\Local\Temp\nsl56CD.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\nsp848A.tmp.exe
C:\Users\tlssa\AppData\Local\Temp\Setup__15200_i1919455024_il483405.exe
C:\Users\tlssa\AppData\Local\Temp\Setup__2140_il37143.exe
C:\Users\tlssa\AppData\Local\Temp\WJVS2YP9QV.exe


==================== Bamital & volsnap =================

(Não há correção automática para arquivos que não passaram na verificação.)

C:\WINDOWS\system32\winlogon.exe => O arquivo é assinado digitalmente
C:\WINDOWS\system32\wininit.exe => O arquivo é assinado digitalmente
C:\WINDOWS\explorer.exe => O arquivo é assinado digitalmente
C:\WINDOWS\SysWOW64\explorer.exe => O arquivo é assinado digitalmente
C:\WINDOWS\system32\svchost.exe => O arquivo é assinado digitalmente
C:\WINDOWS\SysWOW64\svchost.exe => O arquivo é assinado digitalmente
C:\WINDOWS\system32\services.exe => O arquivo é assinado digitalmente
C:\WINDOWS\system32\User32.dll => O arquivo é assinado digitalmente
C:\WINDOWS\SysWOW64\User32.dll => O arquivo é assinado digitalmente
C:\WINDOWS\system32\userinit.exe => O arquivo é assinado digitalmente
C:\WINDOWS\SysWOW64\userinit.exe => O arquivo é assinado digitalmente
C:\WINDOWS\system32\rpcss.dll => O arquivo é assinado digitalmente
C:\WINDOWS\system32\dnsapi.dll
[2016-04-13 12:44] - [2016-05-23 17:29] - 0686976 ____A (Microsoft Corporation) CF3383FDCF3C71BA336EA0B26F6D52BF

C:\WINDOWS\SysWOW64\dnsapi.dll
[2016-04-13 12:44] - [2016-05-23 17:29] - 0535080 ____A (Microsoft Corporation) 5EC400A743B289E17D8200BC3F55EB66

C:\WINDOWS\system32\Drivers\volsnap.sys => O arquivo é assinado digitalmente


LastRegBack: 2016-05-24 11:21

==================== Fim de FRST.txt ============================

Publicité


Signaler le contenu de ce document

Publicité