Users shortcut scan result (x64) Version:27-01-2016 Ran by Administrator (2016-02-03 12:19:07) Running from C:\Users\administrator\Desktop Boot Mode: Normal ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) Shortcut: C:\Users\admin\Links\Desktop.lnk -> C:\Users\administrator\Desktop () Shortcut: C:\Users\admin\Links\Downloads.lnk -> C:\Users\administrator\Downloads () Shortcut: C:\Users\admin\Desktop\µTorrent.lnk -> C:\Users\administrator\AppData\Roaming\uTorrent\uTorrent.exe (No File) Shortcut: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk -> C:\Users\administrator\AppData\Roaming\uTorrent\uTorrent.exe (No File) Shortcut: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk -> C:\Users\administrator\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Corporation) Shortcut: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\Console RAR manual.lnk -> C:\Program Files\WinRAR\Rar.txt () Shortcut: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\What is new in the latest version.lnk -> C:\Program Files\WinRAR\WhatsNew.txt () Shortcut: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR help.lnk -> C:\Program Files\WinRAR\WinRAR.chm () Shortcut: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk -> C:\Program Files\WinRAR\WinRAR.exe (Alexander Roshal) Shortcut: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Longman\Longman Advanced American Dictionary\Longman Advanced American Dictionary.lnk -> C:\Program Files\Longman\Longman Advanced American Dictionary\laad.exe (mozilla.org) Shortcut: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Longman\Longman Advanced American Dictionary\Uninstall.lnk -> C:\Program Files\Longman\Longman Advanced American Dictionary\uninstall.exe () Shortcut: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation) Shortcut: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation) Shortcut: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation) Shortcut: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation) Shortcut: C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk -> C:\Users\administrator\AppData\Roaming\uTorrent\uTorrent.exe (No File) Shortcut: C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (No File) Shortcut: C:\Users\admin\AppData\Local\Microsoft\Windows\WinX\Group3\01 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\admin\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\admin\AppData\Local\Microsoft\Windows\WinX\Group3\02 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\admin\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\admin\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\Windows\System32\compmgmt.msc () Shortcut: C:\Users\admin\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\Windows\System32\diskmgmt.msc () Shortcut: C:\Users\admin\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\Windows\System32\eventvwr.exe (Microsoft Corporation) Shortcut: C:\Users\admin\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation) Shortcut: C:\Users\admin\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) Shortcut: C:\Users\administrator\Links\Desktop.lnk -> C:\Users\administrator\Desktop () Shortcut: C:\Users\administrator\Links\Downloads.lnk -> C:\Users\administrator\Downloads () Shortcut: C:\Users\administrator\Desktop\BitTorrent.lnk -> C:\Users\administrator\AppData\Roaming\BitTorrent\BitTorrent.exe (BitTorrent Inc.) Shortcut: C:\Users\administrator\Desktop\UnHackMe.lnk -> C:\Program Files (x86)\UnHackMe\Unhackme.exe (Greatis Software) Shortcut: C:\Users\administrator\Desktop\short cutz\Adobe Reader XI.lnk -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe (Adobe Systems Incorporated) Shortcut: C:\Users\administrator\Desktop\short cutz\Advanced SystemCare 8.lnk -> C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASC.exe (No File) Shortcut: C:\Users\administrator\Desktop\short cutz\AIMP3.lnk -> C:\Program Files (x86)\AIMP3\AIMP3.exe (AIMP DevTeam) Shortcut: C:\Users\administrator\Desktop\short cutz\Apps.lnk -> C:\Users\Public\Libraries\Apps.library-ms () Shortcut: C:\Users\administrator\Desktop\short cutz\Ashampoo Burning Studio 14.lnk -> C:\Program Files (x86)\Ashampoo\Ashampoo Burning Studio 14\burningstudio14.exe (Ashampoo) Shortcut: C:\Users\administrator\Desktop\short cutz\Autodesk DWF Viewer.lnk -> C:\Program Files (x86)\Autodesk\Autodesk DWF Viewer\DWFViewer.exe (No File) Shortcut: C:\Users\administrator\Desktop\short cutz\Avast Free Antivirus.lnk -> C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software) Shortcut: C:\Users\administrator\Desktop\short cutz\BlueStacks.lnk -> C:\ProgramData\BlueStacksGameManager\BlueStacks.exe (BlueStack Systems, Inc.) Shortcut: C:\Users\administrator\Desktop\short cutz\EaseUS Partition Master 10.0.lnk -> C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.0\bin\EPMStartLoader.exe () Shortcut: C:\Users\administrator\Desktop\short cutz\Format Factory.lnk -> C:\Program Files (x86)\FreeTime\FormatFactory\FormatFactory.exe (No File) Shortcut: C:\Users\administrator\Desktop\short cutz\Ge'ez 10.lnk -> C:\Program Files (x86)\Power Ge'ez 2010\pg2010.exe (Concepts Data Systems PLC) Shortcut: C:\Users\administrator\Desktop\short cutz\Google Chrome.lnk -> C:\Users\administrator\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) Shortcut: C:\Users\administrator\Desktop\short cutz\IObit Uninstaller.lnk -> C:\Program Files (x86)\IObit\IObit Uninstaller\Uninstaler_SkipUac.exe (IObit) Shortcut: C:\Users\administrator\Desktop\short cutz\Iota.lnk -> C:\Program Files (x86)\Iota\iota.exe () Shortcut: C:\Users\administrator\Desktop\short cutz\KMPlayer.lnk -> C:\KMPlayer\KMPlayer.exe (PandoraTV) Shortcut: C:\Users\administrator\Desktop\short cutz\Longman Advanced American Dictionary.lnk -> C:\Program Files\Longman\Longman Advanced American Dictionary\laad.exe (mozilla.org) Shortcut: C:\Users\administrator\Desktop\short cutz\Maxthon Cloud Browser.lnk -> C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe (Maxthon International ltd.) Shortcut: C:\Users\administrator\Desktop\short cutz\Mobogenie3.lnk -> C:\Program Files (x86)\Mobogenie3\Mobogenie.exe (No File) Shortcut: C:\Users\administrator\Desktop\short cutz\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (No File) Shortcut: C:\Users\administrator\Desktop\short cutz\Nitro Pro 9.lnk -> C:\Program Files\Nitro\Pro 9\NitroPDF.exe (Nitro PDF) Shortcut: C:\Users\administrator\Desktop\short cutz\Notepad++.lnk -> C:\Program Files (x86)\Notepad++\notepad++.exe (Don HO don.h@free.fr) Shortcut: C:\Users\administrator\Desktop\short cutz\Picasa 3.lnk -> C:\Program Files (x86)\Google\Picasa3\Picasa3.exe (Google Inc.) Shortcut: C:\Users\administrator\Desktop\short cutz\PowerISO.lnk -> C:\Program Files (x86)\PowerISO\PowerISO.exe (Power Software Ltd) Shortcut: C:\Users\administrator\Desktop\short cutz\ROX Player.lnk -> C:\Users\administrator\AppData\Local\ROX Player\roxplayer.exe (PS Pay Solutions UG) Shortcut: C:\Users\administrator\Desktop\short cutz\SMADΔV.lnk -> C:\Program Files (x86)\SMADAV\SMΔRTP.exe (No File) Shortcut: C:\Users\administrator\Desktop\short cutz\Start BlueStacks.lnk -> C:\Program Files (x86)\BlueStacks\HD-StartLauncher.exe (BlueStack Systems, Inc.) Shortcut: C:\Users\administrator\Desktop\short cutz\TeamViewer 10.lnk -> C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH) Shortcut: C:\Users\administrator\Desktop\short cutz\VLC media player.lnk -> C:\Program Files (x86)\VideoLAN\VLC\vlc.exe (VideoLAN) Shortcut: C:\Users\administrator\Desktop\short cutz\VMware Workstation Pro.lnk -> C:\Program Files (x86)\VMware\VMware Workstation\vmware.exe (VMware, Inc.) Shortcut: C:\Users\administrator\Desktop\short cutz\Wondershare Filmora.lnk -> C:\Program Files (x86)\Wondershare\Filmora\Filmora.exe (Wondershare Software) Shortcut: C:\Users\administrator\Desktop\short cutz\µTorrent.lnk -> C:\Users\administrator\AppData\Roaming\uTorrent\uTorrent.exe (No File) Shortcut: C:\Users\administrator\Desktop\proj-data\2015\2015 Wendo\www_wgarc_gov_et\rs\Library\Computers\Programming\Computer programming in_files\Desktop.lnk -> C:\Users\administrator\Desktop () Shortcut: C:\Users\administrator\Desktop\proj-data\2015\2015 Wendo\www_wgarc_gov_et\Library\Computers\Programming\Computer programming in_files\Desktop.lnk -> C:\Users\administrator\Desktop () Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Windows\Start Menu\BitTorrent.lnk -> C:\Users\administrator\AppData\Roaming\BitTorrent\BitTorrent.exe (BitTorrent Inc.) Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Windows\Start Menu\BlueStacks.lnk -> C:\ProgramData\BlueStacksGameManager\BlueStacks.exe (BlueStack Systems, Inc.) Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk -> C:\Users\administrator\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Corporation) Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ROX Player.lnk -> C:\Users\administrator\AppData\Local\ROX Player\roxplayer.exe (PS Pay Solutions UG) Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The KMPlayer\KMPlayer Setup Wizard.lnk -> C:\KMPlayer\KMPSetup.exe (hxxp://www.kmplayer.com) Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The KMPlayer\KMPlayer.lnk -> C:\KMPlayer\KMPlayer.exe (PandoraTV) Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The KMPlayer\Uninstall KMPlayer.lnk -> C:\KMPlayer\uninstall.exe (PandoraTV) Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter\Uninstall.lnk -> C:\Users\administrator\AppData\Roaming\Enigma Software Group\sh_installer.exe (No File) Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RARBG Player\RARBG Player.lnk -> C:\Program Files (x86)\RARBG Player\RARBG Player.exe (No File) Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RARBG Player\Uninstall.lnk -> C:\Program Files (x86)\RARBG Player\Uninstall.exe (No File) Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Users\administrator\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory\FormatFactory.lnk -> C:\Program Files (x86)\FreeTime\FormatFactory\FormatFactory.exe (No File) Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory\Help.lnk -> C:\Program Files (x86)\FreeTime\FormatFactory\FormatFactory.exe (No File) Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory\Uninstall.lnk -> C:\Program Files (x86)\FreeTime\FormatFactory\uninst.exe (No File) Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation) Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation) Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation) Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation) Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Windows\SendTo\Bluetooth File Transfer.LNK -> C:\Windows\System32\fsquirt.exe (Microsoft Corporation) Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Windows\SendTo\Format Factory.lnk -> C:\Program Files (x86)\FreeTime\FormatFactory\FormatFactory.exe (No File) Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\BitTorrent.lnk -> C:\Users\administrator\AppData\Roaming\BitTorrent\BitTorrent.exe (BitTorrent Inc.) Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\EaseUS Partition Master 10.0.lnk -> C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.0\bin\EPMStartLoader.exe () Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Users\administrator\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mobogenie3.lnk -> C:\Program Files (x86)\Mobogenie3\Mobogenie.exe (No File) Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Perfect Uninstaller.lnk -> C:\Program Files\Perfect Uninstaller\PU.exe (No File) Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\WampServer.lnk -> C:\wamp\wampmanager.exe (Aestan Software) Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Adobe Photoshop CC (64 Bit).lnk -> C:\Program Files\Adobe\Adobe Photoshop CC (64 Bit)\Photoshop.exe (Adobe Systems, Incorporated) Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\KMPlayer.lnk -> C:\KMPlayer\KMPlayer.exe (PandoraTV) Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Maxthon Cloud Browser.lnk -> C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe (Maxthon International ltd.) Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Outlook 2013.lnk -> C:\Windows\Installer\{90150000-0011-0000-1000-0000000FF1CE}\outicon.exe () Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Paint.lnk -> C:\Windows\System32\mspaint.exe (Microsoft Corporation) Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\ROX Player.lnk -> C:\Users\administrator\AppData\Local\ROX Player\roxplayer.exe (PS Pay Solutions UG) Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\VLC media player.lnk -> C:\Program Files (x86)\VideoLAN\VLC\vlc.exe (VideoLAN) Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\VMware Workstation Pro.lnk -> C:\Program Files (x86)\VMware\VMware Workstation\vmware.exe (VMware, Inc.) Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Word 2013.lnk -> C:\Windows\Installer\{90150000-0011-0000-1000-0000000FF1CE}\wordicon.exe () Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Maxthon Cloud Browser (2).lnk -> C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe (Maxthon International ltd.) Shortcut: C:\Users\administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Maxthon Cloud Browser.lnk -> C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe (Maxthon International ltd.) Shortcut: C:\Users\administrator\AppData\Local\Microsoft\Windows\WinX\Group3\01 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\administrator\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\administrator\AppData\Local\Microsoft\Windows\WinX\Group3\02 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\administrator\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\administrator\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\Windows\System32\compmgmt.msc () Shortcut: C:\Users\administrator\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\Windows\System32\diskmgmt.msc () Shortcut: C:\Users\administrator\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\Windows\System32\eventvwr.exe (Microsoft Corporation) Shortcut: C:\Users\administrator\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation) Shortcut: C:\Users\administrator\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) Shortcut: C:\Users\administrator\AppData\Local\Microsoft\Windows\Application Shortcuts\BlueStacks\cn.xender.lnk -> C:\ProgramData\BlueStacks\UserData\TileData\000021\Launcher.vbs () Shortcut: C:\Users\administrator\AppData\Local\Microsoft\Windows\Application Shortcuts\BlueStacks\com.amazon.venezia.lnk -> C:\ProgramData\BlueStacks\UserData\TileData\000002\Launcher.vbs () Shortcut: C:\Users\administrator\AppData\Local\Microsoft\Windows\Application Shortcuts\BlueStacks\com.bubblegalaxy.bubble4.lnk -> C:\ProgramData\BlueStacks\UserData\TileData\000019\Launcher.vbs () Shortcut: C:\Users\administrator\AppData\Local\Microsoft\Windows\Application Shortcuts\BlueStacks\com.facebook.katana.lnk -> C:\ProgramData\BlueStacks\UserData\TileData\000000\Launcher.vbs () Shortcut: C:\Users\administrator\AppData\Local\Microsoft\Windows\Application Shortcuts\BlueStacks\com.google.android.apps.photos.lnk -> C:\ProgramData\BlueStacks\UserData\TileData\000024\Launcher.vbs () Shortcut: C:\Users\administrator\AppData\Local\Microsoft\Windows\Application Shortcuts\BlueStacks\com.google.android.youtube.lnk -> C:\ProgramData\BlueStacks\UserData\TileData\000027\Launcher.vbs () Shortcut: C:\Users\administrator\AppData\Local\Microsoft\Windows\Application Shortcuts\BlueStacks\com.imo.android.imoim.lnk -> C:\ProgramData\BlueStacks\UserData\TileData\000007\Launcher.vbs () Shortcut: C:\Users\administrator\AppData\Local\Microsoft\Windows\Application Shortcuts\BlueStacks\com.instagram.android.lnk -> C:\ProgramData\BlueStacks\UserData\TileData\000025\Launcher.vbs () Shortcut: C:\Users\administrator\AppData\Local\Microsoft\Windows\Application Shortcuts\BlueStacks\com.king.candycrushsaga.lnk -> C:\ProgramData\BlueStacks\UserData\TileData\000017\Launcher.vbs () Shortcut: C:\Users\administrator\AppData\Local\Microsoft\Windows\Application Shortcuts\BlueStacks\com.madhead.tos.en.lnk -> C:\ProgramData\BlueStacks\UserData\TileData\000011\Launcher.vbs () Shortcut: C:\Users\administrator\AppData\Local\Microsoft\Windows\Application Shortcuts\BlueStacks\com.magmamobile.game.Plumber.lnk -> C:\ProgramData\BlueStacks\UserData\TileData\000003\Launcher.vbs () Shortcut: C:\Users\administrator\AppData\Local\Microsoft\Windows\Application Shortcuts\BlueStacks\com.magmamobile.game.SpiderSolitaire.lnk -> C:\ProgramData\BlueStacks\UserData\TileData\000004\Launcher.vbs () Shortcut: C:\Users\administrator\AppData\Local\Microsoft\Windows\Application Shortcuts\BlueStacks\com.mesegana.APP.lnk -> C:\ProgramData\BlueStacks\UserData\TileData\000028\Launcher.vbs () Shortcut: C:\Users\administrator\AppData\Local\Microsoft\Windows\Application Shortcuts\BlueStacks\com.naturalmotion.csrracing.lnk -> C:\ProgramData\BlueStacks\UserData\TileData\000023\Launcher.vbs () Shortcut: C:\Users\administrator\AppData\Local\Microsoft\Windows\Application Shortcuts\BlueStacks\com.plants.animals.lnk -> C:\ProgramData\BlueStacks\UserData\TileData\000009\Launcher.vbs () Shortcut: C:\Users\administrator\AppData\Local\Microsoft\Windows\Application Shortcuts\BlueStacks\com.rovio.angrybirds.lnk -> C:\ProgramData\BlueStacks\UserData\TileData\000016\Launcher.vbs () Shortcut: C:\Users\administrator\AppData\Local\Microsoft\Windows\Application Shortcuts\BlueStacks\com.skype.raider.lnk -> C:\ProgramData\BlueStacks\UserData\TileData\000026\Launcher.vbs () Shortcut: C:\Users\administrator\AppData\Local\Microsoft\Windows\Application Shortcuts\BlueStacks\com.supercell.hayday.lnk -> C:\ProgramData\BlueStacks\UserData\TileData\000010\Launcher.vbs () Shortcut: C:\Users\administrator\AppData\Local\Microsoft\Windows\Application Shortcuts\BlueStacks\com.twitter.android.lnk -> C:\ProgramData\BlueStacks\UserData\TileData\000001\Launcher.vbs () Shortcut: C:\Users\administrator\AppData\Local\Microsoft\Windows\Application Shortcuts\BlueStacks\com.viber.voip.lnk -> C:\ProgramData\BlueStacks\UserData\TileData\000005\Launcher.vbs () Shortcut: C:\Users\administrator\AppData\Local\Microsoft\Windows\Application Shortcuts\BlueStacks\com.whats.up.lnk -> C:\ProgramData\BlueStacks\UserData\TileData\000013\Launcher.vbs () Shortcut: C:\Users\administrator\AppData\Local\Microsoft\Windows\Application Shortcuts\BlueStacks\com.yodo1.crossyroad.lnk -> C:\ProgramData\BlueStacks\UserData\TileData\000018\Launcher.vbs () Shortcut: C:\Users\administrator\AppData\Local\Microsoft\Windows\Application Shortcuts\BlueStacks\how.old.Face.Look.lnk -> C:\ProgramData\BlueStacks\UserData\TileData\000020\Launcher.vbs () Shortcut: C:\Users\administrator\AppData\Local\Microsoft\Windows\Application Shortcuts\BlueStacks\jp.naver.line.android.lnk -> C:\ProgramData\BlueStacks\UserData\TileData\000012\Launcher.vbs () Shortcut: C:\Users\administrator\AppData\Local\Microsoft\Windows\Application Shortcuts\BlueStacks\kik.android.lnk -> C:\ProgramData\BlueStacks\UserData\TileData\000008\Launcher.vbs () Shortcut: C:\Users\administrator\AppData\Local\Microsoft\Windows\Application Shortcuts\BlueStacks\livio.pack.lang.en_US.lnk -> C:\ProgramData\BlueStacks\UserData\TileData\000029\Launcher.vbs () Shortcut: C:\Users\Kbekele\Links\Desktop.lnk -> C:\Users\administrator\Desktop () Shortcut: C:\Users\Kbekele\Links\Downloads.lnk -> C:\Users\administrator\Downloads () Shortcut: C:\Users\Kbekele\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\Kbekele\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\Users\Kbekele\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\Users\Kbekele\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\Kbekele\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\Kbekele\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation) Shortcut: C:\Users\Kbekele\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation) Shortcut: C:\Users\Kbekele\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation) Shortcut: C:\Users\Kbekele\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation) Shortcut: C:\Users\Kbekele\AppData\Local\Microsoft\Windows\WinX\Group3\01 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\Kbekele\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\Kbekele\AppData\Local\Microsoft\Windows\WinX\Group3\02 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\Kbekele\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\Kbekele\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\Windows\System32\compmgmt.msc () Shortcut: C:\Users\Kbekele\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\Windows\System32\diskmgmt.msc () Shortcut: C:\Users\Kbekele\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\Windows\System32\eventvwr.exe (Microsoft Corporation) Shortcut: C:\Users\Kbekele\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation) Shortcut: C:\Users\Kbekele\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) Shortcut: C:\Users\petros\Links\Desktop.lnk -> C:\Users\administrator\Desktop () Shortcut: C:\Users\petros\Links\Downloads.lnk -> C:\Users\administrator\Downloads () Shortcut: C:\Users\petros\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk -> C:\Users\administrator\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Corporation) Shortcut: C:\Users\petros\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\petros\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\Users\petros\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\Users\petros\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\petros\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\petros\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation) Shortcut: C:\Users\petros\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation) Shortcut: C:\Users\petros\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation) Shortcut: C:\Users\petros\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation) Shortcut: C:\Users\petros\AppData\Local\Microsoft\Windows\WinX\Group3\01 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\petros\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\petros\AppData\Local\Microsoft\Windows\WinX\Group3\02 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\petros\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\petros\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\Windows\System32\compmgmt.msc () Shortcut: C:\Users\petros\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\Windows\System32\diskmgmt.msc () Shortcut: C:\Users\petros\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\Windows\System32\eventvwr.exe (Microsoft Corporation) Shortcut: C:\Users\petros\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation) Shortcut: C:\Users\petros\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) Shortcut: C:\Users\Public\Desktop\Asoftech Data Recovery.lnk -> C:\Program Files (x86)\Asoftech\Data Recovery\adr.exe (Asoftech) Shortcut: C:\Users\Public\Desktop\AVG Protection.lnk -> C:\Program Files (x86)\AVG\Av\avgui.exe (AVG Technologies CZ, s.r.o.) Shortcut: C:\Users\wondwossen.a\Links\Desktop.lnk -> C:\Users\administrator\Desktop () Shortcut: C:\Users\wondwossen.a\Links\Downloads.lnk -> C:\Users\administrator\Downloads () Shortcut: C:\Users\wondwossen.a\Desktop\ezvid.lnk -> C:\Users\wondwossen.a\AppData\Roaming\Microsoft\Installer\{38C27BF3-6977-4CB1-94C4-A05A9989A137}\_1D9C97E76CA87D762364BF.exe () Shortcut: C:\Users\wondwossen.a\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk -> C:\Users\administrator\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Corporation) Shortcut: C:\Users\wondwossen.a\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\wondwossen.a\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\Users\wondwossen.a\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\Users\wondwossen.a\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\wondwossen.a\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\wondwossen.a\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ezvid\ezvid.lnk -> C:\Users\wondwossen.a\AppData\Roaming\Microsoft\Installer\{38C27BF3-6977-4CB1-94C4-A05A9989A137}\_05ADE8A69B8BDE6448EB59.exe () Shortcut: C:\Users\wondwossen.a\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ezvid\Uninstall ezvid.lnk -> C:\Users\wondwossen.a\AppData\Roaming\Microsoft\Installer\{38C27BF3-6977-4CB1-94C4-A05A9989A137}\_EEF8485205E9EE0709C173.exe () Shortcut: C:\Users\wondwossen.a\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation) Shortcut: C:\Users\wondwossen.a\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation) Shortcut: C:\Users\wondwossen.a\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation) Shortcut: C:\Users\wondwossen.a\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation) Shortcut: C:\Users\wondwossen.a\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\ezvid.lnk -> C:\Users\wondwossen.a\AppData\Roaming\Microsoft\Installer\{38C27BF3-6977-4CB1-94C4-A05A9989A137}\_1D9C97E76CA87D762364BF.exe () Shortcut: C:\Users\wondwossen.a\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (No File) Shortcut: C:\Users\wondwossen.a\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\VLC media player.lnk -> C:\Program Files (x86)\VideoLAN\VLC\vlc.exe (VideoLAN) Shortcut: C:\Users\wondwossen.a\AppData\Local\Microsoft\Windows\WinX\Group3\01 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\wondwossen.a\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\wondwossen.a\AppData\Local\Microsoft\Windows\WinX\Group3\02 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\wondwossen.a\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\wondwossen.a\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\Windows\System32\compmgmt.msc () Shortcut: C:\Users\wondwossen.a\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\Windows\System32\diskmgmt.msc () Shortcut: C:\Users\wondwossen.a\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\Windows\System32\eventvwr.exe (Microsoft Corporation) Shortcut: C:\Users\wondwossen.a\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation) Shortcut: C:\Users\wondwossen.a\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) ShortcutWithArgument: C:\Users\admin\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo ShortcutWithArgument: C:\Users\admin\AppData\Roaming\Microsoft\Windows\SendTo\TeamViewer.lnk -> C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH) -> --sendto ShortcutWithArgument: C:\Users\admin\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - Network Connections.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> ::{7007ACC7-3202-11D1-AAD2-00805FC1270E} ShortcutWithArgument: C:\Users\admin\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DeviceManager ShortcutWithArgument: C:\Users\admin\AppData\Local\Microsoft\Windows\WinX\Group3\06 - System.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.System ShortcutWithArgument: C:\Users\admin\AppData\Local\Microsoft\Windows\WinX\Group3\08 - Power Options.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.PowerOptions ShortcutWithArgument: C:\Users\admin\AppData\Local\Microsoft\Windows\WinX\Group3\10 - Programs and Features.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.ProgramsAndFeatures ShortcutWithArgument: C:\Users\admin\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\admin\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\admin\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1} ShortcutWithArgument: C:\Users\admin\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /0 ShortcutWithArgument: C:\Users\admin\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257} ShortcutWithArgument: C:\Users\administrator\Desktop\short cutz\Adobe Application Manager.lnk -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\core\PDapp.exe (Adobe Systems Incorporated) -> --appletID=CCM_UI --appletVersion=1.0 --workflow=CCM_workflow_launch ShortcutWithArgument: C:\Users\administrator\Desktop\short cutz\Ashampoo Burning Studio 14 Compact Mode.lnk -> C:\Program Files (x86)\Ashampoo\Ashampoo Burning Studio 14\burningstudio14.exe (Ashampoo) -> -compact ShortcutWithArgument: C:\Users\administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter\SpyHunter Emergency Startup.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> "C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.com" ShortcutWithArgument: C:\Users\administrator\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo ShortcutWithArgument: C:\Users\administrator\AppData\Roaming\Microsoft\Windows\SendTo\TeamViewer.lnk -> C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH) -> --sendto ShortcutWithArgument: C:\Users\administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Outlook.lnk -> C:\Program Files\Microsoft Office\Office15\OUTLOOK.EXE (Microsoft Corporation) -> /recycle ShortcutWithArgument: C:\Users\administrator\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - Network Connections.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> ::{7007ACC7-3202-11D1-AAD2-00805FC1270E} ShortcutWithArgument: C:\Users\administrator\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DeviceManager ShortcutWithArgument: C:\Users\administrator\AppData\Local\Microsoft\Windows\WinX\Group3\06 - System.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.System ShortcutWithArgument: C:\Users\administrator\AppData\Local\Microsoft\Windows\WinX\Group3\08 - Power Options.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.PowerOptions ShortcutWithArgument: C:\Users\administrator\AppData\Local\Microsoft\Windows\WinX\Group3\10 - Programs and Features.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.ProgramsAndFeatures ShortcutWithArgument: C:\Users\administrator\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\administrator\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\administrator\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1} ShortcutWithArgument: C:\Users\administrator\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /0 ShortcutWithArgument: C:\Users\administrator\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257} ShortcutWithArgument: C:\Users\Kbekele\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo ShortcutWithArgument: C:\Users\Kbekele\AppData\Roaming\Microsoft\Windows\SendTo\TeamViewer.lnk -> C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH) -> --sendto ShortcutWithArgument: C:\Users\Kbekele\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - Network Connections.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> ::{7007ACC7-3202-11D1-AAD2-00805FC1270E} ShortcutWithArgument: C:\Users\Kbekele\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DeviceManager ShortcutWithArgument: C:\Users\Kbekele\AppData\Local\Microsoft\Windows\WinX\Group3\06 - System.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.System ShortcutWithArgument: C:\Users\Kbekele\AppData\Local\Microsoft\Windows\WinX\Group3\08 - Power Options.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.PowerOptions ShortcutWithArgument: C:\Users\Kbekele\AppData\Local\Microsoft\Windows\WinX\Group3\10 - Programs and Features.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.ProgramsAndFeatures ShortcutWithArgument: C:\Users\Kbekele\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\Kbekele\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\Kbekele\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1} ShortcutWithArgument: C:\Users\Kbekele\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /0 ShortcutWithArgument: C:\Users\Kbekele\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257} ShortcutWithArgument: C:\Users\petros\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo ShortcutWithArgument: C:\Users\petros\AppData\Roaming\Microsoft\Windows\SendTo\TeamViewer.lnk -> C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH) -> --sendto ShortcutWithArgument: C:\Users\petros\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - Network Connections.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> ::{7007ACC7-3202-11D1-AAD2-00805FC1270E} ShortcutWithArgument: C:\Users\petros\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DeviceManager ShortcutWithArgument: C:\Users\petros\AppData\Local\Microsoft\Windows\WinX\Group3\06 - System.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.System ShortcutWithArgument: C:\Users\petros\AppData\Local\Microsoft\Windows\WinX\Group3\08 - Power Options.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.PowerOptions ShortcutWithArgument: C:\Users\petros\AppData\Local\Microsoft\Windows\WinX\Group3\10 - Programs and Features.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.ProgramsAndFeatures ShortcutWithArgument: C:\Users\petros\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\petros\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\petros\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1} ShortcutWithArgument: C:\Users\petros\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /0 ShortcutWithArgument: C:\Users\petros\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257} ShortcutWithArgument: C:\Users\wondwossen.a\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo ShortcutWithArgument: C:\Users\wondwossen.a\AppData\Roaming\Microsoft\Windows\SendTo\TeamViewer.lnk -> C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH) -> --sendto ShortcutWithArgument: C:\Users\wondwossen.a\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - Network Connections.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> ::{7007ACC7-3202-11D1-AAD2-00805FC1270E} ShortcutWithArgument: C:\Users\wondwossen.a\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DeviceManager ShortcutWithArgument: C:\Users\wondwossen.a\AppData\Local\Microsoft\Windows\WinX\Group3\06 - System.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.System ShortcutWithArgument: C:\Users\wondwossen.a\AppData\Local\Microsoft\Windows\WinX\Group3\08 - Power Options.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.PowerOptions ShortcutWithArgument: C:\Users\wondwossen.a\AppData\Local\Microsoft\Windows\WinX\Group3\10 - Programs and Features.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.ProgramsAndFeatures ShortcutWithArgument: C:\Users\wondwossen.a\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\wondwossen.a\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\wondwossen.a\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1} ShortcutWithArgument: C:\Users\wondwossen.a\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /0 ShortcutWithArgument: C:\Users\wondwossen.a\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257} InternetURL: C:\Users\admin\Favorites\Bing.url -> hxxp://go.microsoft.com/fwlink/p/?LinkId=255142 InternetURL: C:\Users\administrator\Favorites\Bing.url -> hxxp://go.microsoft.com/fwlink/p/?LinkId=255142 InternetURL: C:\Users\administrator\Favorites\Download IObit Freeware.url -> hxxp://www.iobit.com/ InternetURL: C:\Users\administrator\Downloads\Programs\activator\KMSpico 10.1.8.2 FINAL + Portable (Office and Windows 10 Activator) [TechTools.NET]\KMSpico.10.1.8.2 FINAL [TechTools.net]\TechTools.NET.URL -> hxxp://www.techtools.net/ InternetURL: C:\Users\administrator\Desktop\x-mas\Autodesk AutoCAD 2016 SP1 (x64 & X86) Incl.Keygen\Fullstuff.net.url -> hxxp://www.fullstufff.net/ InternetURL: C:\Users\administrator\Desktop\x-mas\Autodesk AutoCAD 2016 SP1 (x64 & X86) Incl.Keygen\64 Bit {X64}\Fullstuff.net.url -> hxxp://www.fullstufff.net/ InternetURL: C:\Users\administrator\Desktop\x-mas\Autodesk AutoCAD 2016 SP1 (x64 & X86) Incl.Keygen\64 Bit {X64}\Setup\Fullstuff.net.url -> hxxp://www.fullstufff.net/ InternetURL: C:\Users\administrator\Desktop\x-mas\Autodesk AutoCAD 2016 SP1 (x64 & X86) Incl.Keygen\64 Bit {X64}\Keygen\Fullstuff.net.url -> hxxp://www.fullstufff.net/ InternetURL: C:\Users\administrator\Desktop\x-mas\Autodesk AutoCAD 2016 SP1 (x64 & X86) Incl.Keygen\32 Bit {X86}\Fullstuff.net.url -> hxxp://www.fullstufff.net/ InternetURL: C:\Users\administrator\Desktop\x-mas\Autodesk AutoCAD 2016 SP1 (x64 & X86) Incl.Keygen\32 Bit {X86}\Setup\Fullstuff.net.url -> hxxp://www.fullstufff.net/ InternetURL: C:\Users\administrator\Desktop\x-mas\Autodesk AutoCAD 2016 SP1 (x64 & X86) Incl.Keygen\32 Bit {X86}\Keygen\Fullstuff.net.url -> hxxp://www.fullstufff.net/ InternetURL: C:\Users\administrator\Desktop\short cutz\Your Software Deals.url -> hxxp://linktarget.ashampoo.com/linktarget/?target=marketplace&edition=eid=11113&utm_medium=desktop&x-pos=desktop InternetURL: C:\Users\administrator\Desktop\proj-data\adv\events design\PSD\Apple iMac info.url -> hxxp://www.no1themes.com/2009/11/apple-imac-front-view-free-psd-template.html InternetURL: C:\Users\administrator\Desktop\proj-data\adv\events design\PSD\Bubbles info.url -> hxxp://www.no1themes.com/2009/12/word-and-thought-chat-bubbles-free-psd.html InternetURL: C:\Users\administrator\Desktop\proj-data\adv\events design\PSD\Color info.url -> hxxp://www.no1themes.com/2009/11/color-free-psd.html InternetURL: C:\Users\administrator\Desktop\proj-data\adv\events design\PSD\More downloads.url -> hxxp://www.no1themes.com/ InternetURL: C:\Users\administrator\Desktop\proj-data\adv\events design\PSD\Precious Heart info.url -> hxxp://www.no1themes.com/2009/12/precious-heart-free-psd-template.html InternetURL: C:\Users\administrator\Desktop\proj-data\adv\events design\PSD\YouTube info.url -> hxxp://www.no1themes.com/2009/11/from-www_28.html InternetURL: C:\Users\administrator\Desktop\proj-data\adv\events design\InDesign CC Digital Classroom - how to design eye-popping layouts for brochures, magazines, e-books, and flyers\InDesign_CC_Digital_Classroom\^ Just one Click to Get More Ebooks Mags.url -> hxxp://www.todaydownloadz.com/ InternetURL: C:\Users\administrator\Desktop\proj-data\adv\events design\InDesign CC Digital Classroom - how to design eye-popping layouts for brochures, magazines, e-books, and flyers\InDesign_CC_Digital_Classroom\~Download More Stuff Here !.url -> hxxp://www.todaydownloadz.com/ InternetURL: C:\Users\administrator\Desktop\proj-data\adv\events design\InDesign CC Digital Classroom - how to design eye-popping layouts for brochures, magazines, e-books, and flyers\InDesign_CC_Digital_Classroom\~Read More Ebooks and Tutorials Online.url -> hxxp://www.todaydownloadz.com/ InternetURL: C:\Users\administrator\Desktop\proj-data\adv\events design\InDesign CC Digital Classroom - how to design eye-popping layouts for brochures, magazines, e-books, and flyers\InDesign_CC_Digital_Classroom\~Get Your Files Here\Get More Ebooks Here.url -> hxxp://www.todaydownloadz.com/ InternetURL: C:\Users\administrator\Desktop\proj-data\adv\events design\8 nice flyers\4th July info.url -> hxxp://no1themes.com/2009/08/4-july/ InternetURL: C:\Users\administrator\Desktop\proj-data\adv\events design\8 nice flyers\Halloween Party info.url -> hxxp://no1themes.com/2009/08/halloween-party-1/ InternetURL: C:\Users\administrator\Desktop\proj-data\adv\events design\8 nice flyers\Open House info.url -> hxxp://no1themes.com/2009/08/open-house-2/ InternetURL: C:\Users\administrator\Desktop\proj-data\adv\events design\8 nice flyers\Painting Workshop info.url -> hxxp://no1themes.com/2009/08/painting-workshop/ InternetURL: C:\Users\administrator\Desktop\proj-data\adv\events design\8 nice flyers\Special Event info.url -> hxxp://no1themes.com/2009/08/special-event/ InternetURL: C:\Users\administrator\Desktop\proj-data\adv\events design\8 nice flyers\Springtime info.url -> hxxp://no1themes.com/2009/08/springtime/ InternetURL: C:\Users\administrator\Desktop\proj-data\adv\events design\8 nice flyers\Tear Off Tabs info.url -> hxxp://no1themes.com/2009/08/tear-tabs/ InternetURL: C:\Users\administrator\Desktop\proj-data\adv\events design\8 nice flyers\Vibrant info.url -> hxxp://no1themes.com/2009/08/vibrant-2/ InternetURL: C:\Users\administrator\Desktop\proj-data\adv\events design\20 Amazing flyer design fonts [ SXP ]\BLOG & PC TIPS AND TWEAKS.url -> hxxp://www.tipsxplore.blogspot.com/ InternetURL: C:\Users\administrator\Desktop\proj-data\adv\events design\20 Amazing flyer design fonts [ SXP ]\More software.url -> hxxp://www.softxplore.blogspot.com/ InternetURL: C:\Users\administrator\Desktop\proj-data\adv\events design\20 Amazing flyer design fonts [ SXP ]\More Wallpapers.url -> hxxp://www.wallpapersxplore.blogspot.com/ InternetURL: C:\Users\administrator\Desktop\proj-data\2015\2015 WEB-\wordpress\theme2\Over 200 Great WordPress Themes\More free downloads....url -> hxxp://www.no1themes.com/ InternetURL: C:\Users\administrator\Desktop\proj-data\2015\2015 WEB-\wordpress\theme2\Over 200 Great WordPress Themes\More free wordpress downloads....url -> hxxp://www.no1themes.com/search/label/wordpress InternetURL: C:\Users\administrator\Desktop\adv\add - photoshop\- shapes\sexy-fashion-girls\Design Freebies Heven.url -> hxxp://dezignus.com/ InternetURL: C:\Users\administrator\Desktop\adv\add - photoshop\- shapes\Adobe Photoshop CC Master Shapes folder\skeletons\FreeGrunge.url -> hxxp://vectorartbox.com/ InternetURL: C:\Users\administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The KMPlayer\KMPlayer Home Page.url -> hxxp://www.kmplayer.com/forums InternetURL: C:\Users\administrator\AppData\Local\AviraResume\en-us\weblink.url -> hxxp://www.avira.com InternetURL: C:\Users\Kbekele\Favorites\Bing.url -> hxxp://go.microsoft.com/fwlink/p/?LinkId=255142 InternetURL: C:\Users\petros\Favorites\Bing.url -> hxxp://go.microsoft.com/fwlink/p/?LinkId=255142 InternetURL: C:\Users\wondwossen.a\Favorites\Bing.url -> hxxp://go.microsoft.com/fwlink/p/?LinkId=255142 ==================== End of Shortcut.txt =============================