HKU\Nick\...\Run: [KekjOzofe] => regsvr32.exe "C:\ProgramData\KekjOzofe\CoyegVelfo.mro" C:\ProgramData\KekjOzofe 2015-05-30 23:30 - 2015-05-30 23:30 - 00000000 ___HD () C:\Users\Nick\AppData\Roaming\466A1A04 2015-05-30 14:09 - 2015-05-31 08:58 - 00000000 __SHD () C:\Users\Nick\AppData\Local\EmieUserList 2015-05-30 14:09 - 2015-05-31 08:58 - 00000000 __SHD () C:\Users\Nick\AppData\Local\EmieSiteList 2015-05-30 14:05 - 2015-05-30 14:07 - 00000000 ____D () C:\ProgramData\KekjOzofe 2015-05-08 06:42 - 2015-05-08 06:42 - 02181358 _____ () C:\Users\Nick\Desktop\HELP_RESTORE_FILES.bmp