[code] HitmanPro 3.7.15.281 www.hitmanpro.com Computer name . . . . : ASUS Windows . . . . . . . : 10.0.0.14393.X64/4 User name . . . . . . : ASUS\Bob UAC . . . . . . . . . : Enabled License . . . . . . . : Trial (30 days left) Scan date . . . . . . : 2017-01-03 09:08:57 Scan mode . . . . . . : Normal Scan duration . . . . : 13m 50s Disk access mode . . : Direct disk access (SRB) Cloud . . . . . . . . : Internet Reboot . . . . . . . : No Threats . . . . . . . : 0 Traces . . . . . . . : 153 Objects scanned . . . : 1 749 923 Files scanned . . . . : 49 767 Remnants scanned . . : 365 661 files / 1 334 495 keys Suspicious files ____________________________________________________________ C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCache\IE\11Z81RD1\FRST64[1].exe Size . . . . . . . : 2 418 176 bytes Age . . . . . . . : 0.3 days (2017-01-03 00:48:38) Entropy . . . . . : 7.6 SHA-256 . . . . . : 7B1EAFF262CB947F39609AA61124E60FD28DCD3CCD592DA5826588D3ECDA1E8F Needs elevation . : Yes Fuzzy . . . . . . : 24.0 Program has no publisher information but prompts the user for permission elevation. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs. Authors name is missing in version info. This is not common to most programs. Version control is missing. This file is probably created by an individual. This is not typical for most programs. Time indicates that the file appeared recently on this computer. Forensic Cluster -90.3s C:\Windows\Prefetch\DLLHOST.EXE-6A829A47.pf -89.2s C:\Windows\Prefetch\DLLHOST.EXE-39233F51.pf -72.3s C:\Windows\Prefetch\DLLHOST.EXE-B8AE989E.pf -41.9s C:\Windows\Prefetch\RUNDLL32.EXE-A3EE2396.pf -40.6s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{A9646391-39F6-449E-A688-16EF65BAA07D} -25.5s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{7FECEB95-E53E-466F-9882-867786591FD3} -3.4s C:\ProgramData\Microsoft\Windows Defender\Scans\MetaStore\2\94\CFAA2FD248A6BBBE.dat -2.6s C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCache\IE\LLV92GBS\82[1].htm -1.6s C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\78GHOEL8.cookie -1.6s C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCache\IE\1ZNO2DMU\82[1].htm -0.8s C:\Users\Bob\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\9EC3B71635F8BA3FC68DE181A104A0EF_F6C39EF89D8A3A72327D8412589658B2 -0.8s C:\Users\Bob\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\9EC3B71635F8BA3FC68DE181A104A0EF_F6C39EF89D8A3A72327D8412589658B2 -0.4s C:\Users\Bob\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\64DCC9872C5635B1B7891B30665E0558_5552C20A2631357820903FD38A8C0F9F -0.4s C:\Users\Bob\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\64DCC9872C5635B1B7891B30665E0558_5552C20A2631357820903FD38A8C0F9F -0.3s C:\Users\Bob\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6AF4EE75E3A4ABA658C0087EB9A0BB5B_556BB0FF4D382D90E7703209690E089E -0.3s C:\Users\Bob\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6AF4EE75E3A4ABA658C0087EB9A0BB5B_556BB0FF4D382D90E7703209690E089E 0.0s C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCache\IE\11Z81RD1\FRST64[1].exe 0.0s C:\Users\Bob\Downloads\fixit\FRST64.exe 4.5s C:\Users\Bob\Downloads\fixit\FRST-OlderVersion\ 5.6s C:\Windows\Prefetch\FRST64.EXE-D28D1902.pf 8.1s C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCache\IE\ZZSF5VIW\up64[2] 9.3s C:\FRST\Logs\ct 9.3s C:\Users\Bob\Downloads\fixit\Fixlog.txt 11.4s C:\FRST\Quarantine\C\ 11.4s C:\FRST\Quarantine\C\Users\Bob\Desktop\ 11.4s C:\FRST\Quarantine\C\Users\ 11.4s C:\FRST\Quarantine\C\Users\Bob\Desktop\Bob\AppData\Roaming\Microsoft\Word\ 11.4s C:\FRST\Quarantine\C\Users\Bob\Desktop\Bob\AppData\Roaming\ 11.4s C:\FRST\Quarantine\C\Users\Bob\Desktop\Bob\AppData\Roaming\Microsoft\Word\662%20rodzic%20bez%20szpitala%2015%25304696493377610516\ 11.4s C:\FRST\Quarantine\C\Users\Bob\Desktop\Bob\ 11.4s C:\FRST\Quarantine\C\Users\Bob\Desktop\Bob\AppData\Roaming\Microsoft\ 11.4s C:\FRST\Quarantine\C\Users\Bob\ 11.4s C:\FRST\Quarantine\C\Users\Bob\Desktop\Bob\AppData\ 11.6s C:\FRST\Quarantine\C\Users\Bob\Desktop\ASUS\ 11.6s C:\FRST\Quarantine\C\Users\Bob\Desktop\ASUS\System tool\ 11.8s C:\FRST\Quarantine\C\Users\Bob\Desktop\ASUS\Business tool\ 12.5s C:\FRST\Quarantine\C\Users\Bob\AppData\Roaming\Skype\ 12.5s C:\FRST\Quarantine\C\Users\Bob\AppData\ 12.5s C:\FRST\Quarantine\C\Users\Bob\AppData\Roaming\ 12.5s C:\FRST\Quarantine\C\Users\Bob\AppData\Roaming\Skype\My Skype Received Files\ 12.5s C:\FRST\Quarantine\C\Users\Bob\AppData\Roaming\Microsoft\Windows\Start Menu\ 12.5s C:\FRST\Quarantine\C\Users\Bob\AppData\Roaming\Microsoft\Windows\ 12.5s C:\FRST\Quarantine\C\Users\Bob\AppData\Roaming\Microsoft\ 12.5s C:\FRST\Quarantine\C\Users\Bob\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ 12.5s C:\FRST\Quarantine\C\Users\Bob\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ 19.8s C:\Windows\Prefetch\PRESENTATIONFONTCACHE.EXE-E2702CF2.pf 19.8s C:\Windows\Prefetch\DASHOST.EXE-38AAABF0.pf 24.5s C:\Windows\Prefetch\SPOOLSV.EXE-AC422BB0.pf 28.0s C:\Windows\Prefetch\DLLHOST.EXE-6E31253B.pf 31.8s C:\Users\Bob\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db 31.8s C:\Users\Bob\AppData\Local\Microsoft\Windows\Explorer\iconcache_16.db 31.8s C:\Users\Bob\AppData\Local\Microsoft\Windows\Explorer\iconcache_32.db 31.8s C:\Users\Bob\AppData\Local\Microsoft\Windows\Explorer\iconcache_48.db 31.8s C:\Users\Bob\AppData\Local\Microsoft\Windows\Explorer\iconcache_96.db 31.8s C:\Users\Bob\AppData\Local\Microsoft\Windows\Explorer\iconcache_256.db 31.8s C:\Users\Bob\AppData\Local\Microsoft\Windows\Explorer\iconcache_768.db 31.8s C:\Users\Bob\AppData\Local\Microsoft\Windows\Explorer\iconcache_1280.db 31.8s C:\Users\Bob\AppData\Local\Microsoft\Windows\Explorer\iconcache_1920.db 31.8s C:\Users\Bob\AppData\Local\Microsoft\Windows\Explorer\iconcache_2560.db 31.8s C:\Users\Bob\AppData\Local\Microsoft\Windows\Explorer\iconcache_sr.db 31.8s C:\Users\Bob\AppData\Local\Microsoft\Windows\Explorer\iconcache_wide.db 31.8s C:\Users\Bob\AppData\Local\Microsoft\Windows\Explorer\iconcache_exif.db 31.8s C:\Users\Bob\AppData\Local\Microsoft\Windows\Explorer\iconcache_wide_alternate.db 31.8s C:\Users\Bob\AppData\Local\Microsoft\Windows\Explorer\iconcache_custom_stream.db C:\Users\Bob\Downloads\fixit\FRST-OlderVersion\FRST64.exe Size . . . . . . . : 2 420 736 bytes Age . . . . . . . : 5.6 days (2016-12-28 18:10:25) Entropy . . . . . : 7.6 SHA-256 . . . . . : E58ADE7FA354A1F256B4608AFD698C379E33FF23D5F62C95BDFC33995C230745 Needs elevation . : Yes Fuzzy . . . . . . : 24.0 Program has no publisher information but prompts the user for permission elevation. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs. Authors name is missing in version info. This is not common to most programs. Version control is missing. This file is probably created by an individual. This is not typical for most programs. Time indicates that the file appeared recently on this computer. C:\Users\Bob\Downloads\fixit\FRST64.exe Size . . . . . . . : 2 418 176 bytes Age . . . . . . . : 0.3 days (2017-01-03 00:48:38) Entropy . . . . . : 7.6 SHA-256 . . . . . : 7B1EAFF262CB947F39609AA61124E60FD28DCD3CCD592DA5826588D3ECDA1E8F Needs elevation . : Yes Fuzzy . . . . . . : 24.0 Program has no publisher information but prompts the user for permission elevation. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs. Authors name is missing in version info. This is not common to most programs. Version control is missing. This file is probably created by an individual. This is not typical for most programs. Time indicates that the file appeared recently on this computer. Forensic Cluster -90.3s C:\Windows\Prefetch\DLLHOST.EXE-6A829A47.pf -89.2s C:\Windows\Prefetch\DLLHOST.EXE-39233F51.pf -72.3s C:\Windows\Prefetch\DLLHOST.EXE-B8AE989E.pf -41.9s C:\Windows\Prefetch\RUNDLL32.EXE-A3EE2396.pf -40.6s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{A9646391-39F6-449E-A688-16EF65BAA07D} -25.5s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{7FECEB95-E53E-466F-9882-867786591FD3} -3.4s C:\ProgramData\Microsoft\Windows Defender\Scans\MetaStore\2\94\CFAA2FD248A6BBBE.dat -2.6s C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCache\IE\LLV92GBS\82[1].htm -1.6s C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\78GHOEL8.cookie -1.6s C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCache\IE\1ZNO2DMU\82[1].htm -0.8s C:\Users\Bob\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\9EC3B71635F8BA3FC68DE181A104A0EF_F6C39EF89D8A3A72327D8412589658B2 -0.8s C:\Users\Bob\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\9EC3B71635F8BA3FC68DE181A104A0EF_F6C39EF89D8A3A72327D8412589658B2 -0.5s C:\Users\Bob\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\64DCC9872C5635B1B7891B30665E0558_5552C20A2631357820903FD38A8C0F9F -0.4s C:\Users\Bob\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\64DCC9872C5635B1B7891B30665E0558_5552C20A2631357820903FD38A8C0F9F -0.3s C:\Users\Bob\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6AF4EE75E3A4ABA658C0087EB9A0BB5B_556BB0FF4D382D90E7703209690E089E -0.3s C:\Users\Bob\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6AF4EE75E3A4ABA658C0087EB9A0BB5B_556BB0FF4D382D90E7703209690E089E -0.0s C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCache\IE\11Z81RD1\FRST64[1].exe 0.0s C:\Users\Bob\Downloads\fixit\FRST64.exe 4.5s C:\Users\Bob\Downloads\fixit\FRST-OlderVersion\ 5.6s C:\Windows\Prefetch\FRST64.EXE-D28D1902.pf 8.1s C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCache\IE\ZZSF5VIW\up64[2] 9.3s C:\FRST\Logs\ct 9.3s C:\Users\Bob\Downloads\fixit\Fixlog.txt 11.4s C:\FRST\Quarantine\C\ 11.4s C:\FRST\Quarantine\C\Users\Bob\Desktop\ 11.4s C:\FRST\Quarantine\C\Users\ 11.4s C:\FRST\Quarantine\C\Users\Bob\Desktop\Bob\AppData\Roaming\Microsoft\Word\ 11.4s C:\FRST\Quarantine\C\Users\Bob\Desktop\Bob\AppData\Roaming\ 11.4s C:\FRST\Quarantine\C\Users\Bob\Desktop\Bob\AppData\Roaming\Microsoft\Word\662%20rodzic%20bez%20szpitala%2015%25304696493377610516\ 11.4s C:\FRST\Quarantine\C\Users\Bob\Desktop\Bob\ 11.4s C:\FRST\Quarantine\C\Users\Bob\Desktop\Bob\AppData\Roaming\Microsoft\ 11.4s C:\FRST\Quarantine\C\Users\Bob\ 11.4s C:\FRST\Quarantine\C\Users\Bob\Desktop\Bob\AppData\ 11.6s C:\FRST\Quarantine\C\Users\Bob\Desktop\ASUS\ 11.6s C:\FRST\Quarantine\C\Users\Bob\Desktop\ASUS\System tool\ 11.8s C:\FRST\Quarantine\C\Users\Bob\Desktop\ASUS\Business tool\ 12.5s C:\FRST\Quarantine\C\Users\Bob\AppData\Roaming\Skype\ 12.5s C:\FRST\Quarantine\C\Users\Bob\AppData\ 12.5s C:\FRST\Quarantine\C\Users\Bob\AppData\Roaming\ 12.5s C:\FRST\Quarantine\C\Users\Bob\AppData\Roaming\Skype\My Skype Received Files\ 12.5s C:\FRST\Quarantine\C\Users\Bob\AppData\Roaming\Microsoft\Windows\Start Menu\ 12.5s C:\FRST\Quarantine\C\Users\Bob\AppData\Roaming\Microsoft\Windows\ 12.5s C:\FRST\Quarantine\C\Users\Bob\AppData\Roaming\Microsoft\ 12.5s C:\FRST\Quarantine\C\Users\Bob\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ 12.5s C:\FRST\Quarantine\C\Users\Bob\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ 19.8s C:\Windows\Prefetch\PRESENTATIONFONTCACHE.EXE-E2702CF2.pf 19.8s C:\Windows\Prefetch\DASHOST.EXE-38AAABF0.pf 24.5s C:\Windows\Prefetch\SPOOLSV.EXE-AC422BB0.pf 28.0s C:\Windows\Prefetch\DLLHOST.EXE-6E31253B.pf 31.8s C:\Users\Bob\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db 31.8s C:\Users\Bob\AppData\Local\Microsoft\Windows\Explorer\iconcache_16.db 31.8s C:\Users\Bob\AppData\Local\Microsoft\Windows\Explorer\iconcache_32.db 31.8s C:\Users\Bob\AppData\Local\Microsoft\Windows\Explorer\iconcache_48.db 31.8s C:\Users\Bob\AppData\Local\Microsoft\Windows\Explorer\iconcache_96.db 31.8s C:\Users\Bob\AppData\Local\Microsoft\Windows\Explorer\iconcache_256.db 31.8s C:\Users\Bob\AppData\Local\Microsoft\Windows\Explorer\iconcache_768.db 31.8s C:\Users\Bob\AppData\Local\Microsoft\Windows\Explorer\iconcache_1280.db 31.8s C:\Users\Bob\AppData\Local\Microsoft\Windows\Explorer\iconcache_1920.db 31.8s C:\Users\Bob\AppData\Local\Microsoft\Windows\Explorer\iconcache_2560.db 31.8s C:\Users\Bob\AppData\Local\Microsoft\Windows\Explorer\iconcache_sr.db 31.8s C:\Users\Bob\AppData\Local\Microsoft\Windows\Explorer\iconcache_wide.db 31.8s C:\Users\Bob\AppData\Local\Microsoft\Windows\Explorer\iconcache_exif.db 31.8s C:\Users\Bob\AppData\Local\Microsoft\Windows\Explorer\iconcache_wide_alternate.db 31.8s C:\Users\Bob\AppData\Local\Microsoft\Windows\Explorer\iconcache_custom_stream.db C:\Users\Bob\OneDrive\FRST64.exe Size . . . . . . . : 2 420 736 bytes Age . . . . . . . : 5.6 days (2016-12-28 18:07:57) Entropy . . . . . : 7.6 SHA-256 . . . . . : E58ADE7FA354A1F256B4608AFD698C379E33FF23D5F62C95BDFC33995C230745 Needs elevation . : Yes Fuzzy . . . . . . : 24.0 Program has no publisher information but prompts the user for permission elevation. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs. Authors name is missing in version info. This is not common to most programs. Version control is missing. This file is probably created by an individual. This is not typical for most programs. Time indicates that the file appeared recently on this computer. Potential Unwanted Programs _________________________________________________ HKLM\SOFTWARE\WOW6432Node\Conduit\ (Conduit) -> Deleted HKU\S-1-5-21-3865186189-997488633-1609009381-1001\SOFTWARE\Conduit\ (Conduit) -> Deleted Cookies _____________________________________________________________________ C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\22M5QUP1.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\2T93BCSY.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\3JCX5U87.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\3SRL99FH.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\7X03EGNW.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\89TBY5HE.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\96FAFM6J.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\9RQTEYEG.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\9X5Z5ZZ9.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\CE6QTYJF.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\DA2DJTM9.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\FS4E4JNV.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\HXS99UH8.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\KAB0ZI2G.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\00W16EP2.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\0N2970DH.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\0OA729R0.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\0TCTV8LQ.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\1CLT50EW.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\1LUBXQQZ.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\2FNJ7YHF.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\2ZJIULMZ.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\31OILH2Q.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\35Y3S1N1.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\3BXA8UT0.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\3EWW4D29.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\3MCQLS19.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\41LEL665.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\4A9E7HTB.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\4BX6U8OY.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\4DTMYVWE.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\4MA6G691.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\4MUD2T9W.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\54DVRVEV.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\58NNR7QF.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\61EU06NT.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\67FFMWXC.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\6BE18CVX.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\6RXQSRMX.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\6ZH1TOQB.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\7DPNURA1.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\7LAJ1ZR7.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\7S60URY1.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\8BKPDJI6.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\8MOV2A41.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\8NKTDRUH.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\8OEZ35KJ.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\8PO6G3TB.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\8UJ1RJW8.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\95T2B32L.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\966TTBL9.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\9SJHLUHH.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\9ZIXNDJU.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\9ZNA52AF.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\A9ZJMA6N.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\AHPNQKZK.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\ATEG9HA5.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\AZWNIKMA.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\BER32TB5.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\BIUEAKYK.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\BMWIAT2A.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\C5N2SDL8.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\C63BKOIX.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\CAGQ1M4Q.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\CTH4BQ0N.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\CZNC0HQQ.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\DPES9S8A.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\EDCBWULW.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\EL3UE4RX.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\EN0A68WH.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\EV30DHSA.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\FF6G0CI1.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\FRR11EX3.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\FWF0JVHG.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\G22ZA1UT.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\G3CWBG4S.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\GX5FF5NJ.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\GZ9HMBTE.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\H4N2PDJP.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\H7V8Z06D.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\H8LLV5TX.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\I29PU4TC.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\IK29DAWU.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\JB3TD1RF.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\JERMXDS8.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\JFNCQB82.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\JP1YJLAN.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\JRFM8PBQ.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\JWLI071J.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\K9KF5SZS.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\KPWZBQWG.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\KVXRDTMF.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\L6FPB04C.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\MJGC9LFR.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\MN3RRRAW.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\MWFXCR43.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\N1ZIGTTQ.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\NKR42E93.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\NL17WV2B.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\NSNJO7KX.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\O38ZG2I8.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\OUVRAB1V.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\OYXWH0KU.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\P6O3BNGP.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\PP2L1D4K.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\PQO7OBM8.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\QA08SHJM.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\QDW5QJO1.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\QV5S21YL.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\S03I1I0B.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\S7QLU8RS.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\S9PSH0R6.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\SNY76SEJ.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\SSA4RXO6.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\SUVHXHU1.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\SVS72V2L.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\SY25X45Q.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\TEFPBVL8.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\TRWXV6UO.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\TSNPVE17.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\U43KFLXL.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\U4SYOQS4.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\U6DCCXTX.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\V4K0RVFO.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\V890OUOU.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\VKW7QMF5.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\W63E1T37.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\WGD1HTL4.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\X0DOBGUE.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\XK4D5LUH.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\XL1C434D.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\XZE3O8ZJ.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\Y4Y0T6YJ.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\Y6WYWFHQ.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\YGXAD45K.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\YHJ7WJMP.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\YPUBE8AV.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\YXRCLFI2.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\Z2W5I5LN.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\ZM99P4EG.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\Low\ZT2VBQ9U.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\LTQZBVBN.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\N9ZH7AVW.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\NFB73OVG.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\P61WALV7.cookie C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\PE8RU59A.txt C:\Users\Bob\AppData\Local\Microsoft\Windows\INetCookies\W9D54WAR.cookie [/code]