Call Of Duty Modern Warfare 3 Patch Update SP-MP - AviaRa - PC ##HOT##
Download >>> https://urlgoal.com/2t7DXB
Start:: CloseProcesses: AlternateDataStreams: C:\ProgramData:NT [40] AlternateDataStreams: C:\ProgramData:NT2 [650] AlternateDataStreams: C:\Windows\system32\config\systemprofile:.repos [616620] AlternateDataStreams: C:\Users\All Users:NT [40] AlternateDataStreams: C:\Users\All Users:NT2 [650] AlternateDataStreams: C:\ProgramData\Application Data:NT [40] AlternateDataStreams: C:\ProgramData\Application Data:NT2 [650] AlternateDataStreams: C:\ProgramData\MTA San Andreas All:NT [40] AlternateDataStreams: C:\ProgramData\MTA San Andreas All:NT2 [650] AlternateDataStreams: C:\ProgramData\TEMP:7FAE3E0D [131] AlternateDataStreams: C:\Users\User\Application Data:NT [40] AlternateDataStreams: C:\Users\User\Application Data:NT2 [650] AlternateDataStreams: C:\Users\User\AppData\Roaming:NT [40] AlternateDataStreams: C:\Users\User\AppData\Roaming:NT2 [650] HKLM\...\Run: [] => [X] HKU\S-1-5-21-2212257518-1748600259-2655236700-1000\...\Run: [] => [X] S2 WinDefender; C:\Windows\windefender.exe [X] No File C:\ProgramData\ApprelronSIFEO\ApprelronS.exe: [GlobalFlag] C:\ProgramData\Windows Monitor\Monitor.exe %i deviceId=bcb75194-6908-2bd5-8c52-1ea6ae8d8908 channelId=777 distributer=APSFFreeSS processName=ApprelronS.exe statsAddress=hxxp://stats.utyuytjn.com/StatisticsService.svc/V1/JSON/LogEvent HKLM\...\SilentProcessExit\ApprelronS.exe: [MonitorProcess] C:\ProgramData\Windows Monitor\Monitor.exe %i deviceId=bcb75194-6908-2bd5-8c52-1ea6ae8d8908 channelId=777 distributer=APSFFreeSS processName=ApprelronS.exe statsAddress=hxxp://stats.utyuytjn.com/StatisticsService.svc/V1/JSON/LogEvent IFEO\ApService.exe: [GlobalFlag] C:\ProgramData\Windows Monitor\Monitor.exe %i deviceId=bcb75194-6908-2bd5-8c52-1ea6ae8d8908 channelId=999 distributer=defaultap processName=ApService.exe statsAddress=hxxps://stats.grkpv.com/StatisticsService.svc/V1/JSON/LogEvent HKLM\...\SilentProcessExit\ApService.exe: [MonitorProcess] C:\ProgramData\Windows Monitor\Monitor.exe %i deviceId=bcb75194-6908-2bd5-8c52-1ea6ae8d8908 channelId=999 distributer=defaultap processName=ApService.exe statsAddress=hxxps://stats.grkpv.com/StatisticsService.svc/V1/JSON/LogEvent IFEO\Snorler.exe: [GlobalFlag] C:\ProgramData\Windows Monitor\Monitor.exe %i deviceId=bcb75194-6908-2bd5-8c52-1ea6ae8d8908 channelId=3 distributer=APSFFreeSS processName=Snorler.exe statsAddress=hxxp://stats.utyuytjn.com/StatisticsService.svc/V1/JSON/LogEvent HKLM\...\SilentProcessExit\Snorler.exe: [MonitorProcess] C:\ProgramData\Windows Monitor\Monitor.exe %i deviceId=bcb75194-6908-2bd5-8c52-1ea6ae8d8908 channelId=3 distributer=APSFFreeSS processName=Snorler.exe statsAddress=hxxp://stats.utyuytjn.com/StatisticsService.svc/V1/JSON/LogEvent Task: {0008C22E-3745-4CE0-95F2-DEDF3A56E8AB} - System32\Tasks\psv_AlphaGobam => cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Sanhotlax.reg" & del "C:\ProgramData\Snorler\Sanhotlax.reg" & SCHTASKS /Delete /TN "psv_AlphaGobam" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Techfind.reg" & del "C:\ProgramData\Snorler\Techfind.reg" & SCHTASKS /Delete /TN "psv_Lexitam" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Strongdax.reg" & del "C:\ProgramData\Snorler\Strongdax.reg" & SCHTASKS /Delete /TN "psv_Zaam-Flex" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Fresh-Zap.reg" & del "C:\ProgramData\Snorler\Fresh-Zap.reg" & SCHTASKS /Delete /TN "psv_Con-Lam" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Joytom.reg" & del "C:\ProgramData\Snorler\Joytom.reg" & SCHTASKS /Delete /TN "psv_Quotedox" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Fix-Tech.reg" & del "C:\ProgramData\Snorler\Fix-Tech.reg" & SCHTASKS /Delete /TN "psv_GrooveFind" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Unodex.reg" & del "C:\ProgramData\Snorler\Unodex.reg" & SCHTASKS /Delete /TN "psv_InDontrax" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\HatTone.reg" & del "C:\ProgramData\Snorler\HatTone.reg" & SCHTASKS /Delete /TN "psv_FlexFan" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Siltough.reg" & del "C:\ProgramData\Snorler\Siltough.reg" & SCHTASKS /Delete /TN "psv_Dentokix" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\VoltSoft.reg" & del "C:\ProgramData\Snorler\VoltSoft.reg" & SCHTASKS /Delete /TN "psv_Strongfax" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Danfan.reg" & del "C:\ProgramData\Snorler\Danfan.reg" & SCHTASKS /Delete /TN "psv_Stockkix" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Zonetip.reg" & del "C:\ProgramData\Snorler\Zonetip.reg" & SCHTASKS /Delete /TN "psv_Xxx-Flex" /F cmd.exe /c regedit.exe /s "C:\ProgramData\ApprelronS\Y-ex.reg" & del "C:\ProgramData\ApprelronS\Y-ex.reg" & SCHTASKS /Delete /TN "psv_Unodex" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Techwarm.reg" & del "C:\ProgramData\Snorler\Techwarm.reg" & SCHTASKS /Delete /TN "psv_TipHold" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Kaystring.reg" & del "C:\ProgramData\Snorler\Kaystring.reg" & SCHTASKS /Delete /TN "psv_Zath-Strong" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Geotintrax.reg" & del "C:\ProgramData\Snorler\Geotintrax.reg" & SCHTASKS /Delete /TN "psv_Stantough" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Overtex.reg" & del "C:\ProgramData\Snorler\Overtex.reg" & SCHTASKS /Delete /TN "psv_Xxx-remfan" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Temp-Touch.reg" & del "C:\ProgramData\Snorler\Temp-Touch.reg" & SCHTASKS /Delete /TN "psv_Dingzozfind" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Soloing.reg" & del "C:\ProgramData\Snorler\Soloing.reg" & SCHTASKS /Delete /TN "psv_Summatfind" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Don-Soft.reg" & del "C:\ProgramData\Snorler\Don-Soft.reg" & SCHTASKS /Delete /TN "psv_Zuncom" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Runtam.reg" & del "C:\ProgramData\Snorler\Runtam.reg" & SCHTASKS /Delete /TN "psv_Homelex" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\SubFind.reg" & del "C:\ProgramData\Snorler\SubFind.reg" & SCHTASKS /Delete /TN "psv_Sunlex" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Ventodox.reg" & del "C:\ProgramData\Snorler\Ventodox.reg" & SCHTASKS /Delete /TN "psv_Tonjob" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\BioFix.reg" & del "C:\ProgramData\Snorler\BioFix.reg" & SCHTASKS /Delete /TN "psv_Rundom" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Vento-Hold.reg" & del "C:\ProgramData\Snorler\Vento-Hold.reg" & SCHTASKS /Delete /TN "psv_Sailstring" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\DanMatcof.reg" & del "C:\ProgramData\Snorler\DanMatcof.reg" & SCHTASKS /Delete /TN "psv_Duocore" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Freshtough.reg" & del "C:\ProgramData\Snorler\Freshtough.reg" & SCHTASKS /Delete /TN "psv_FixZap" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\DanOvetip.reg" & del "C:\ProgramData\Snorler\DanOvetip.reg" & SCHTASKS /Delete /TN "psv_TinCanit" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Zonela.reg" & del "C:\ProgramData\Snorler\Zonela.reg" & SCHTASKS /Delete /TN "psv_Solfax" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Labzentop.reg" & del "C:\ProgramData\Snorler\Labzentop.reg" & SCHTASKS /Delete /TN "psv_BigTamsing" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Coffind.reg" & del "C:\ProgramData\Snorler\Coffind.reg" & SCHTASKS /Delete /TN "psv_Villacom" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Fintrax.reg" & del "C:\ProgramData\Snorler\Fintrax.reg" & SCHTASKS /Delete /TN "psv_Recore" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Zathtax.reg" & del "C:\ProgramData\Snorler\Zathtax.reg" & SCHTASKS /Delete /TN "psv_Rantom" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Doublefresh.reg" & del "C:\ProgramData\Snorler\Doublefresh.reg" & SCHTASKS /Delete /TN "psv_Opestring" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Zooquojob.reg" & del "C:\ProgramData\Snorler\Zooquojob.reg" & SCHTASKS /Delete /TN "psv_Touchfind" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Tresit.reg" & del "C:\ProgramData\Snorler\Tresit.reg" & SCHTASKS /Delete /TN "psv_Daltit" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Tamron.reg" & del "C:\ProgramData\Snorler\Tamron.reg" & SCHTASKS /Delete /TN "psv_Tinin" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Stronglight.reg" & del "C:\ProgramData\Snorler\Stronglight.reg" & SCHTASKS /Delete /TN "psv_Dancore" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Physwarm.reg" & del "C:\ProgramData\Snorler\Physwarm.reg" & SCHTASKS /Delete /TN "psv_Saildax" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Zummahold.reg" & del "C:\ProgramData\Snorler\Zummahold.reg" & SCHTASKS /Delete /TN "psv_Dentoplus" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\X-Tinlax.reg" & del "C:\ProgramData\Snorler\X-Tinlax.reg" & SCHTASKS /Delete /TN "psv_Tontom" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\ZonKeystrong.reg" & del "C:\ProgramData\Snorler\ZonKeystrong.reg" & SCHTASKS /Delete /TN "psv_Haycof" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Gravedom.reg" & del "C:\ProgramData\Snorler\Gravedom.reg" & SCHTASKS /Delete /TN "psv_ZaamTip" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Blueron.reg" & del "C:\ProgramData\Snorler\Blueron.reg" & SCHTASKS /Delete /TN "psv_ApJob" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\LexiLex.reg" & del "C:\ProgramData\Snorler\LexiLex.reg" & SCHTASKS /Delete /TN "psv_Unafax" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Bamtough.reg" & del "C:\ProgramData\Snorler\Bamtough.reg" & SCHTASKS /Delete /TN "psv_Ranit" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Voyaair.reg" & del "C:\ProgramData\Snorler\Voyaair.reg" & SCHTASKS /Delete /TN "psv_Danla" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Alphaity.reg" & del "C:\ProgramData\Snorler\Alphaity.reg" & SCHTASKS /Delete /TN "psv_Voyasaoair" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Lexiity.reg" & del "C:\ProgramData\Snorler\Lexiity.reg" & SCHTASKS /Delete /TN "psv_InchDom" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Tampflex.reg" & del "C:\ProgramData\Snorler\Tampflex.reg" & SCHTASKS /Delete /TN "psv_QuadAnstrong" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Joylex.reg" & del "C:\ProgramData\Snorler\Joylex.reg" & SCHTASKS /Delete /TN "psv_Inchtax" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Sonlux.reg" & del "C:\ProgramData\Snorler\Sonlux.reg" & SCHTASKS /Delete /TN "psv_OverIs" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\K-sing.reg" & del "C:\ProgramData\Snorler\K-sing.reg" & SCHTASKS /Delete /TN "psv_Itdax" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\RedDomstring.reg" & del "C:\ProgramData\Snorler\RedDomstring.reg" & SCHTASKS /Delete /TN "psv_Treehome" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\K-home.reg" & del "C:\ProgramData\Snorler\K-home.reg" & SCHTASKS /Delete /TN "psv_Biocom" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\DongLotfix.reg" & del "C:\ProgramData\Snorler\DongLotfix.reg" & SCHTASKS /Delete /TN "psv_Goodtax" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Lothold.reg" & del "C:\ProgramData\Snorler\Lothold.reg" & SCHTASKS /Delete /TN "psv_Med-Trax" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Holdron.reg" & del "C:\ProgramData\Snorler\Holdron.reg" & SCHTASKS /Delete /TN "psv_Hatflex" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\LexiRemstring.reg" & del "C:\ProgramData\Snorler\LexiRemstring.reg" & SCHTASKS /Delete /TN "psv_Strongkeytough" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Contone.reg" & del "C:\ProgramData\Snorler\Contone.reg" & SCHTASKS /Delete /TN "psv_SuperDublex" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Biolax.reg" & del "C:\ProgramData\Snorler\Biolax.reg" & SCHTASKS /Delete /TN "psv_VoyaRanfix" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Ventozap.reg" & del "C:\ProgramData\Snorler\Ventozap.reg" & SCHTASKS /Delete /TN "psv_Subfax" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Tinaplax.reg" & del "C:\ProgramData\Snorler\Tinaplax.reg" & SCHTASKS /Delete /TN "psv_Itnix" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Ittax.reg" & del "C:\ProgramData\Snorler\Ittax.reg" & SCHTASKS /Delete /TN "psv_Warmphase" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Sanplus.reg" & del "C:\ProgramData\Snorler\Sanplus.reg" & SCHTASKS /Delete /TN "psv_Tancof" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Touch-Soft.reg" & del "C:\ProgramData\Snorler\Touch-Soft.reg" & SCHTASKS /Delete /TN "psv_Lot-Tone" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Zim-Stock.reg" & del "C:\ProgramData\Snorler\Zim-Stock.reg" & SCHTASKS /Delete /TN "psv_Suntip" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\X-Tantech.reg" & del "C:\ProgramData\Snorler\X-Tantech.reg" & SCHTASKS /Delete /TN "psv_Hotdax" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\ZooFax.reg" & del "C:\ProgramData\Snorler\ZooFax.reg" & SCHTASKS /Delete /TN "psv_Kansing" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\GeoOtex.reg" & del "C:\ProgramData\Snorler\GeoOtex.reg" & SCHTASKS /Delete /TN "psv_Isfind" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Zersoft.reg" & del "C:\ProgramData\Snorler\Zersoft.reg" & SCHTASKS /Delete /TN "psv_StanStatbam" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Doubleis.reg" & del "C:\ProgramData\Snorler\Doubleis.reg" & SCHTASKS /Delete /TN "psv_Bluefind" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Vilazap.reg" & del "C:\ProgramData\Snorler\Vilazap.reg" & SCHTASKS /Delete /TN "psv_Ozertop" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Con-Tom.reg" & del "C:\ProgramData\Snorler\Con-Tom.reg" & SCHTASKS /Delete /TN "psv_TrustQuaddox" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Faxfind.reg" & del "C:\ProgramData\Snorler\Faxfind.reg" & SCHTASKS /Delete /TN "psv_WhiteLight" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\KonkJob.reg" & del "C:\ProgramData\Snorler\KonkJob.reg" & SCHTASKS /Delete /TN "psv_Trustzap" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\KayTraxjob.reg" & del "C:\ProgramData\Snorler\KayTraxjob.reg" & SCHTASKS /Delete /TN "psv_Strongla" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\GraveJaysing.reg" & del "C:\ProgramData\Snorler\GraveJaysing.reg" & SCHTASKS /Delete /TN "psv_Opetouch" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Unait.reg" & del "C:\ProgramData\Snorler\Unait.reg" & SCHTASKS /Delete /TN "psv_Mathla" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Singlehotlab.reg" & del "C:\ProgramData\Snorler\Singlehotlab.reg" & SCHTASKS /Delete /TN "psv_JobKeytech" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Quotetrax.reg" & del "C:\ProgramData\Snorler\Quotetrax.reg" & SCHTASKS /Delete /TN "psv_Superhatin" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Blueex.reg" & del "C:\ProgramData\Snorler\Blueex.reg" & SCHTASKS /Delete /TN "psv_Duokix" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Stringlux.reg" & del "C:\ProgramData\Snorler\Stringlux.reg" & SCHTASKS /Delete /TN "psv_Trusttraxlab" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Konla.reg" & del "C:\ProgramData\Snorler\Konla.reg" & SCHTASKS /Delete /TN "psv_Joying" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\SilverNamfax.reg" & del "C:\ProgramData\Snorler\SilverNamfax.reg" & SCHTASKS /Delete /TN "psv_DonTraxing" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Substock.reg" & del "C:\ProgramData\Snorler\Substock.reg" & SCHTASKS /Delete /TN "psv_Hotis" /F cmd.exe /c regedit.exe /s "C:\ProgramData\ApprelronS\Blueit.reg" & del "C:\ProgramData\ApprelronS\Blueit.reg" & SCHTASKS /Delete /TN "psv_Donhome" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Zamnix.reg" & del "C:\ProgramData\Snorler\Zamnix.reg" & SCHTASKS /Delete /TN "psv_JayNamlax" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Kanfresh.reg" & del "C:\ProgramData\Snorler\Kanfresh.reg" & SCHTASKS /Delete /TN "psv_Tiptex" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Zerlight.reg" & del "C:\ProgramData\Snorler\Zerlight.reg" & SCHTASKS /Delete /TN "psv_Vilaity" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\StatStrong.reg" & del "C:\ProgramData\Snorler\StatStrong.reg" & SCHTASKS /Delete /TN "psv_Sailwarm" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Tripplephase.reg" & del "C:\ProgramData\Snorler\Tripplephase.reg" & SCHTASKS /Delete /TN "psv_Sanfintone" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Zoo-Eco.reg" & del "C:\ProgramData\Snorler\Zoo-Eco.reg" & SCHTASKS /Delete /TN "psv_Ventodax" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Movestock.reg" & del "C:\ProgramData\Snorler\Movestock.reg" & SCHTASKS /Delete /TN "psv_Tranwarm" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\U-tech.reg" & del "C:\ProgramData\Snorler\U-tech.reg" & SCHTASKS /Delete /TN "psv_Ozersing" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Lexidex.reg" & del "C:\ProgramData\Snorler\Lexidex.reg" & SCHTASKS /Delete /TN "psv_Daltex" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Dongzap.reg" & del "C:\ProgramData\Snorler\Dongzap.reg" & SCHTASKS /Delete /TN "psv_Homedax" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Kaydex.reg" & del "C:\ProgramData\Snorler\Kaydex.reg" & SCHTASKS /Delete /TN "psv_Doublefax" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Konkfresh.reg" & del "C:\ProgramData\Snorler\Konkfresh.reg" & SCHTASKS /Delete /TN "psv_KayTondox" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Ozerfax.reg" & del "C:\ProgramData\Snorler\Ozerfax.reg" & SCHTASKS /Delete /TN "psv_Pluszumdox" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\TrippleKix.reg" & del "C:\ProgramData\Snorler\TrippleKix.reg" & SCHTASKS /Delete /TN "psv_Volsanhold" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Sun-Light.reg" & del "C:\ProgramData\Snorler\Sun-Light.reg" & SCHTASKS /Delete /TN "psv_Finlight" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Homesoft.reg" & del "C:\ProgramData\Snorler\Homesoft.reg" & SCHTASKS /Delete /TN "psv_SilverDom" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\NimTone.reg" & del "C:\ProgramData\Snorler\NimTone.reg" & SCHTASKS /Delete /TN "psv_X-tax" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Haylight.reg" & del "C:\ProgramData\Snorler\Haylight.reg" & SCHTASKS /Delete /TN "psv_Tip-Dox" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Daltfix.reg" & del "C:\ProgramData\Snorler\Daltfix.reg" & SCHTASKS /Delete /TN "psv_Joyity" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Randintom.reg" & del "C:\ProgramData\Snorler\Randintom.reg" & SCHTASKS /Delete /TN "psv_Geotam" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Freenix.reg" & del "C:\ProgramData\Snorler\Freenix.reg" & SCHTASKS /Delete /TN "psv_Xxx-lam" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Keyeco.reg" & del "C:\ProgramData\Snorler\Keyeco.reg" & SCHTASKS /Delete /TN "psv_Ronnix" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Daltdonlam.reg" & del "C:\ProgramData\Snorler\Daltdonlam.reg" & SCHTASKS /Delete /TN "psv_InchOzetex" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\VilaQuois.reg" & del "C:\ProgramData\Snorler\VilaQuois.reg" & SCHTASKS /Delete /TN "psv_Soldom" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Dansanair.reg" & del "C:\ProgramData\Snorler\Dansanair.reg" & SCHTASKS /Delete /TN "psv_Ventolattrax" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Ranstock.reg" & del "C:\ProgramData\Snorler\Ranstock.reg" & SCHTASKS /Delete /TN "psv_Volsing" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\DonZap.reg" & del "C:\ProgramData\Snorler\DonZap.reg" & SCHTASKS /Delete /TN "psv_Stringfix" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Techkix.reg" & del "C:\ProgramData\Snorler\Techkix.reg" & SCHTASKS /Delete /TN "psv_Unodax" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Nimdox.reg" & del "C:\ProgramData\Snorler\Nimdox.reg" & SCHTASKS /Delete /TN "psv_HayOvedax" /F cmd.exe /c regedit.exe /s "C:\ProgramData\ApprelronS\Dentocom.reg" & del "C:\ProgramData\ApprelronS\Dentocom.reg" & SCHTASKS /Delete /TN "psv_Voljob" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Opeity.reg" & del "C:\ProgramData\Snorler\Opeity.reg" & SCHTASKS /Delete /TN "psv_Geotax" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Truedubity.reg" & del "C:\ProgramData\Snorler\Truedubity.reg" & SCHTASKS /Delete /TN "psv_Tiptam" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Xxx-Eco.reg" & del "C:\ProgramData\Snorler\Xxx-Eco.reg" & SCHTASKS /Delete /TN "psv_Drip-Com" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Mat-It.reg" & del "C:\ProgramData\Snorler\Mat-It.reg" & SCHTASKS /Delete /TN "psv_Airfix" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Ozer-Tone.reg" & del "C:\ProgramData\Snorler\Ozer-Tone.reg" & SCHTASKS /Delete /TN "psv_Faxnamhold" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\RanIng.reg" & del "C:\ProgramData\Snorler\RanIng.reg" & SCHTASKS /Delete /TN "psv_Keylex" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Dongdex.reg" & del "C:\ProgramData\Snorler\Dongdex.reg" & SCHTASKS /Delete /TN "psv_Concof" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Yeartouch.reg" & del "C:\ProgramData\Snorler\Yeartouch.reg" & SCHTASKS /Delete /TN "psv_U-fan" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Ton-Kix.reg" & del "C:\ProgramData\Snorler\Ton-Kix.reg" & SCHTASKS /Delete /TN "psv_Tamredlux" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Tech-Dex.reg" & del "C:\ProgramData\Snorler\Tech-Dex.reg" & SCHTASKS /Delete /TN "psv_Fixsing" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Sollight.reg" & del "C:\ProgramData\Snorler\Sollight.reg" & SCHTASKS /Delete /TN "psv_U-lottouch" /F cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Groovetex.reg" & del "C:\ProgramData\Snorler\Groovetex.reg" & SCHTASKS /Delete /TN "psv_DongZap" /F C:\Users\User\AppData\Local\Temp\haleng. No File FirewallRules: [{88C926CB-BE9E-4C08-B422-96D612C873B1}] => (Block) C:\Program Files\Avira\SoftwareUpdater\avirasoftwareupdatertoastnotificationsbridge.exe => No File FirewallRules: [{7C3D9229-8B80-4A3A-9F5C-27675AFF8874}] => (Allow) C:\Program Files\Avira\SoftwareUpdater\avirasoftwareupdatertoastnotificationsbridge.exe => No File FirewallRules: [{E30F2FEB-0DA8-4898-8AD0-EE3CB70F58A0}] => (Allow) C:\Program Files\Avira\SoftwareUpdater\avirasoftwareupdatertoastnotificationsbridge.exe => No File FirewallRules: [{ED898B5E-8D1A-4F23-A8D7-2CF55F3F4F26}] => (Allow) C:\Program Files\Steam\Steam.exe => No File FirewallRules: [{1A6D0E09-CBD3-49CD-BC15-5215CD1B1DE4}] => (Allow) C:\Program Files\Steam\Steam.exe => No File FirewallRules: [{D0FA6F23-A154-4BEE-BE0B-0F2DC2E2D78E}] => (Allow) C:\Program Files\Steam\bin\cef\cef.win7\steamwebhelper.exe => No File FirewallRules: [{62EA0F2B-EC13-4F3B-BD6B-4EFCB7F74FBA}] => (Allow) C:\Program Files\Steam\bin\cef\cef.win7\steamwebhelper.exe => No File FirewallRules: [TCP Query User{BBAA9F3B-248E-486C-A5A5-6656AC6CAB94}C:\new folder (2)\call of duty 2 full game mp - sp -=aviara=-\call of duty 2\cod2mp_s.exe] => (Allow) C:\new folder (2)\call of duty 2 full game mp - sp -=aviara=-\call of duty 2\cod2mp_s.exe => No File FirewallRules: [UDP Query User{6DF12A18-C1F2-4351-97AB-424DDB416257}C:\new folder (2)\call of duty 2 full game mp - sp -=aviara=-\call of duty 2\cod2mp_s.exe] => (Allow) C:\new folder (2)\call of duty 2 full game mp - sp -=aviara=-\call of duty 2\cod2mp_s.exe => No File FirewallRules: [{C22CB595-96C6-40EE-8836-3E05042776F2}] => (Allow) C:\Program Files\EA GAMES\Battlefield 2 Demo\BF2.exe => No File FirewallRules: [{F3F7739C-2353-4083-BAF2-1A93165A937A}] => (Allow) C:\Program Files\EA GAMES\Battlefield 2 Demo\BF2.exe => No File FirewallRules: [{11F5EB06-6D99-4605-9730-B1B53673D899}] => (Allow) C:\Program Files\EA GAMES\Battlefield 2 Demo\BF2ServerLauncher.exe => No File FirewallRules: [{33D9EFCE-8C39-40F9-AFC7-992AA2F994C1}] => (Allow) C:\Program Files\EA GAMES\Battlefield 2 Demo\BF2ServerLauncher.exe => No File FirewallRules: [{C1E96057-3E2A-4ADE-B602-C57576E0035F}] => (Allow) C:\Program Files\EA GAMES\Battlefield 2 Demo\BF2ServerLauncher.exe => No File FirewallRules: [{602EE056-4DB1-442B-B330-F0B576DAF82A}] => (Allow) C:\Program Files\EA GAMES\Battlefield 2 Demo\BF2ServerLauncher.exe => No File FirewallRules: [{3C3507B6-2650-4583-B245-838F6722230B}] => (Allow) C:\Program Files\Mr DJ\Need For Speed Most Wanted Black Edition\speed.exe => No File FirewallRules: [{C69D2E17-99C7-41EF-A24E-00775402BE33}] => (Allow) C:\Program Files\Mr DJ\Need For Speed Most Wanted Black Edition\speed.exe => No File FirewallRules: [TCP Query User{228F669A-521D-4F7D-80E2-96EA6C3B7D33}C:\program files\java\jre1.8.0_151\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_151\bin\javaw.exe => No File FirewallRules: [UDP Query User{C5FE6051-1286-4BC1-97B1-3A80630D3D9E}C:\program files\java\jre1.8.0_151\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_151\bin\javaw.exe => No File FirewallRules: [TCP Query User{F3DD7752-2FA4-4C39-837B-CA9569DF482C}C:\temp\txgamedownload\component\gamedownloadforfix.exe] => (Block) C:\temp\txgamedownload\component\gamedownloadforfix.exe => No File FirewallRules: [UDP Query User{93089970-D5A6-4011-BA95-501F88C3124D}C:\temp\txgamedownload\component\gamedownloadforfix.exe] => (Block) C:\temp\txgamedownload\component\gamedownloadforfix.exe => No File FirewallRules: [{314E61D6-C197-441E-A7E1-3DA4F2537EBE}] => (Allow) C:\Program Files\BlueStacks\HD-Player.exe => No File FirewallRules: [{7B5D732E-6B36-4AF5-9FCE-827BB53C4D01}] => (Allow) C:\Program Files\EA GAMES\Battlefield 2\BF2.exe => No File FirewallRules: [{6DE64D53-730B-4D0C-8EA8-871705E0EE58}] => (Allow) C:\Program Files\EA GAMES\Battlefield 2\BF2.exe => No File FirewallRules: [TCP Query User{88B4E42D-6F1B-4E85-85C8-C4F5483CBA0A}C:\program files\call of duty 4 modern warfare\iw3mp.exe] => (Allow) C:\program files\call of duty 4 modern warfare\iw3mp.exe => No File FirewallRules: [UDP Query User{CD3B19F4-6CC4-4D5F-AD93-EC1E8BBEA723}C:\program files\call of duty 4 modern warfare\iw3mp.exe] => (Allow) C:\program files\call of duty 4 modern warfare\iw3mp.exe => No File FirewallRules: [{C822C2EE-7886-4160-ACB3-41A7F144FAF7}] => (Allow) C:\Users\User\AppData\Roaming\Zoom\bin\airhost.exe => No File FirewallRules: [{6BF69621-4C7E-4E59-BB09-86BBF5B45023}] => (Allow) C:\Program Files\Mr DJ\Assassins Creed Brotherhood\ACBSP.exe => No File FirewallRules: [{CCB52AC4-9F3D-494B-AC7B-CE71E4CBD315}] => (Allow) C:\Program Files\Mr DJ\Assassins Creed Brotherhood\ACBSP.exe => No File FirewallRules: [TCP Query User{0BC29392-AC32-470A-9591-890446260EA3}C:\xampp\apache\bin\httpd.exe] => (Allow) C:\xampp\apache\bin\httpd.exe => No File FirewallRules: [UDP Query User{33E6002D-36D9-4314-BCC6-A102D84031B6}C:\xampp\apache\bin\httpd.exe] => (Allow) C:\xampp\apache\bin\httpd.exe => No File FirewallRules: [{D4A74849-BA61-4498-841C-138C4B2BF78A}] => (Allow) C:\Program Files\PC Remote Receiver\MonectServerService.exe => No File FirewallRules: [{223C5BD9-F7E5-43AC-9C22-607EEA5482BF}] => (Allow) C:\Program Files\PC Remote Receiver\MonectMediaCenter.exe => No File FirewallRules: [{C167C026-F0C0-4F8A-9B66-C37457DC0F6F}] => (Allow) C:\Program Files\PC Remote Receiver\PCRemoteReceiver.exe => No File FirewallRules: [{E1BB2CE7-7900-4C4A-84A7-7F02E506D475}] => (Allow) C:\Program Files\PC Remote Receiver\PCRemoteReceiver.exe => No File FirewallRules: [{AFEF697F-A4B8-4C12-83B1-6F1CDF0412C3}] => (Allow) C:\Program Files\PC Remote Receiver\PCRemoteReceiver.exe => No File FirewallRules: [{0567C4CF-370D-419B-9DA5-117BE7AB7F69}] => (Allow) C:\Program Files\PC Remote Receiver\PCRemoteReceiver.exe => No File FirewallRules: [TCP Query User{727875B0-D12C-4994-BE85-FE760295E548}C:\cod 1\game\codmp.exe] => (Allow) C:\cod 1\game\codmp.exe => No File FirewallRules: [UDP Query User{20917C70-5B40-4016-8E39-7216AF67E25C}C:\cod 1\game\codmp.exe] => (Allow) C:\cod 1\game\codmp.exe => No File FirewallRules: [TCP Query User{11D4A0A8-D3B2-4037-A67A-F676ABD10C30}C:\call of duty\codmp.exe] => (Allow) C:\call of duty\codmp.exe => No File FirewallRules: [UDP Query User{C0ACAF19-DD28-4D26-BCEE-DE32A1A1D1D9}C:\call of duty\codmp.exe] => (Allow) C:\call of duty\codmp.exe => No File FirewallRules: [TCP Query User{BA2F67E5-E1A1-4AB5-ACDE-E78C70EE5B04}C:\call of duty\codmp.exe] => (Allow) C:\call of duty\codmp.exe => No File FirewallRules: [UDP Query User{CC2FCD72-DCF7-499B-9DF8-4525D2A611D6}C:\call of duty\codmp.exe] => (Allow) C:\call of duty\codmp.exe => No File FirewallRules: [{CDEF2CDE-DF49-484B-B398-3D23997155E9}] => (Allow) C:\Program Files\Andy\andy.exe => No File FirewallRules: [{41DA4923-5477-4EA1-AF0A-05D007ABDE1B}] => (Allow) C:\Program Files\Andy\andy.exe => No File FirewallRules: [{1B9A8FB7-192B-48BB-936A-7EDBD6B55D3B}] => (Allow) C:\Program Files\Andy\AndyConsole.exe => No File FirewallRules: [{BA1D1B6E-7729-4574-95EB-54605EA5A40B}] => (Allow) C:\Program Files\Andy\AndyConsole.exe => No File FirewallRules: [{35FC7886-5649-4CF7-8A5A-1B8DC629BC66}] => (Allow) C:\Program Files\Andy\HandyAndy.exe => No File FirewallRules: [{F6ABFA9E-D43E-4DA7-A902-1A6A6961BA15}] => (Allow) C:\Program Files\Andy\HandyAndy.exe => No File FirewallRules: [{89F80CB0-A39D-499A-BDF7-A3A7C118FF4B}] => (Allow) C:\Program Files\Andy\SetupFiles\Uninstall.exe => No File FirewallRules: [{BF41018E-0E39-4D7E-8925-23798D39B2EE}] => (Allow) C:\Program Files\Andy\SetupFiles\Uninstall.exe => No File FirewallRules: [{966FA03D-086F-4B8A-BF01-A631B4AD044C}] => (Allow) C:\Users\User\AppData\Local\Temp\RemoveTemp.exe => No File FirewallRules: [{16985C4B-42FF-4C16-BDB9-E05C2DEFA1C9}] => (Allow) C:\Users\User\AppData\Local\Temp\RemoveTemp.exe => No File FirewallRules: [{2C5E9FB1-0467-484C-BFCD-E25B43FC23C3}] => (Allow) C:\Program Files\Andy\SetupFiles\VMwareCheck.exe => No File FirewallRules: [{19AD3C47-C3BB-407D-B0A5-90B26F34651C}] => (Allow) C:\Program Files\Andy\SetupFiles\VMwareCheck.exe => No File FirewallRules: [{4F55506A-3A50-494E-931F-6AA2AAE699AD}] => (Allow) C:\Program Files\Andy\SetupFiles\AndyDoctor.exe => No File FirewallRules: [{D051EBE7-4C00-40D9-AB3E-F7480FCC7591}] => (Allow) C:\Program Files\Andy\SetupFiles\AndyDoctor.exe => No File FirewallRules: [{9D6A5251-EDAB-4F13-9BC5-8F367F5D452C}] => (Allow) C:\Users\User\AppData\Local\Temp\andy-x86\Setup.exe => No File FirewallRules: [{F16D135E-6ABC-4B72-9302-DFB9F1E5A7B7}] => (Allow) C:\Users\User\AppData\Local\Temp\andy-x86\Setup.exe => No File FirewallRules: [TCP Query User{ADF09589-4326-4D34-A760-3E54AB9A4773}C:\new folder (2)\call of duty - modern warfare 2\iw4mp.exe] => (Allow) C:\new folder (2)\call of duty - modern warfare 2\iw4mp.exe => No File FirewallRules: [UDP Query User{A53D8DF8-FA1E-4A1A-91CD-6C557796EA7D}C:\new folder (2)\call of duty - modern warfare 2\iw4mp.exe] => (Allow) C:\new folder (2)\call of duty - modern warfare 2\iw4mp.exe => No File FirewallRules: [TCP Query User{BF97380D-F536-4D4F-AF93-A21F66DB7D84}C:\new folder (2)\call of duty - modern warfare 2\iw4x.exe] => (Allow) C:\new folder (2)\call of duty - modern warfare 2\iw4x.exe => No File FirewallRules: [UDP Query User{2ACD4C8E-76EC-4E20-8CAC-883E4FE5C56F}C:\new folder (2)\call of duty - modern warfare 2\iw4x.exe] => (Allow) C:\new folder (2)\call of duty - modern warfare 2\iw4x.exe => No File FirewallRules: [{D5E81273-136C-440A-A6E1-359730185943}] => (Allow) C:\Program Files\Mr DJ\Need for Speed Carbon Collectors Edition\NFSC.exe => No File FirewallRules: [{3C79282D-02DF-45D0-83A0-09CA9FB7BA72}] => (Allow) C:\Program Files\Mr DJ\Need for Speed Carbon Collectors Edition\NFSC.exe => No File FirewallRules: [TCP Query User{D4B6066C-CA22-422F-890E-ADDCE3C7B80F}C:\program files\java\jre1.8.0_271\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_271\bin\javaw.exe => No File FirewallRules: [UDP Query User{F4A9998B-044C-4B2A-BBD4-EA3CDC741730}C:\program files\java\jre1.8.0_271\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_271\bin\javaw.exe => No File FirewallRules: [{651E0198-8F99-4D32-9945-F34FC9FE318B}] => (Allow) C:\Windows\rss\csrss.exe => No File FirewallRules: [{D3AA13E9-9E9A-4246-AE54-30F52F6606D3}] => (Allow) C:\Windows\rss\csrss.exe => No File FirewallRules: [{9A6DA2C9-D12E-4581-AAA8-14CCE4C9BF52}] => (Allow) C:\Users\User\AppData\Roaming\d260b1c77550\d260b1c77550.exe => No File FirewallRules: [{24B7C84E-EC8D-4142-A285-CFEF4172C32D}] => (Allow) C:\Users\User\AppData\Roaming\d260b1c77550\d260b1c77550.exe => No File HKLM\...\Run: [haleng] => C:\Users\User\AppData\Local\Temp\haleng. "C:\Users\User\AppData\Local\Temp\is-TL743.tmp\Kamnira.exe" /VERYSILENT (Allow) C:\Users\User\AppData\Local\Temp\RemoveTemp.exe => No File FirewallRules: [{16985C4B-42FF-4C16-BDB9-E05C2DEFA1C9}] => (Allow) C:\Users\User\AppData\Local\Temp\RemoveTemp.exe => No File FirewallRules: [{9D6A5251-EDAB-4F13-9BC5-8F367F5D452C}] => (Allow) C:\Users\User\AppData\Local\Temp\andy-x86\Setup.exe => No File FirewallRules: [{F16D135E-6ABC-4B72-9302-DFB9F1E5A7B7}] => (Allow) C:\Users\User\AppData\Local\Temp\andy-x86\Setup.exe => No File HKLM\...\Run: [haleng] => C:\Users\User\AppData\Local\Temp\haleng. "C:\Users\User\AppData\Local\Temp\is-TL743.tmp\Kamnira.exe" /VERYSILENT cmd.exe /c regedit.exe /s "C:\ProgramData\Snorler\Temp-Touch.reg" & del "C:\ProgramData\Snorler\Temp-Touch.reg" & SCHTASKS /Delete /TN "psv_Dingzozfind" /F (Allow) C:\Users\User\AppData\Local\Temp\RemoveTemp.exe => No File FirewallRules: [{16985C4B-42FF-4C16-BDB9-E05C2DEFA1C9}] => (Allow) C:\Users\User\AppData\Local\Temp\RemoveTemp.exe => No File FirewallRules: [{9D6A5251-EDAB-4F13-9BC5-8F367F5D452C}] => (Allow) C:\Users\User\AppData\Local\Temp\andy-x86\Setup.exe => No File FirewallRules: [{F16D135E-6ABC-4B72-9302-DFB9F1E5A7B7}] => (Allow) C:\Users\User\AppData\Local\Temp\andy-x86\Setup.exe => No File HKU\S-1-5-21-2212257518-1748600259-2655236700-1000\...\Run: [5635619] => "C:\Users\User\AppData\Local\Temp\is-TL743.tmp\Kamnira.exe" /VERYSILENT 2b1af7f3a8