PDA

View Full Version : dllhost.exe*32 problems Logs posted



gurleygirl
2014-11-12, 02:07
On top of the multiple threads in my task manager for the COM surrogate dllhost.exe*32, I recently discovered the following in almost every folder in my documents folder in my library:

What happened to your files ?
All of your files were protected by a strong encryption with RSA-2048 using CryptoWall 2.0.
More information about the encryption keys using RSA-2048 can be found here: http://en.wikipedia.org/wiki/RSA_(cryptosystem)

What does this mean ?
This means that the structure and data within your files have been irrevocably changed, you will not be able to work with them, read them or see them,
it is the same thing as losing them forever, but with our help, you can restore them.

How did this happen ?
Especially for you, on our server was generated the secret key pair RSA-2048 - public and private.
All your files were encrypted with the public key, which has been transferred to your computer via the Internet.
Decrypting of your files is only possible with the help of the private key and decrypt program, which is on our secret server.

What do I do ?
Alas, if you do not take the necessary measures for the specified time then the conditions for obtaining the private key will be changed.
If you really value your data, then we suggest you do not waste valuable time searching for other solutions because they do not exist.


Admin edit- disabled urls.
For more specific instructions, please visit your personal home page, there are a few different addresses pointing to your page below:
1.http: //paytordmbdekmizq.bortor. com/1RYjjmz
2.http: //paytordmbdekmizq.torpacho. com/1RYjjmz
3.http: //paytordmbdekmizq.torsanctions. com/1RYjjmz
4.http: //paytordmbdekmizq.torwild. com/1RYjjmz

If for some reasons the addresses are not available, follow these steps:
1.Download and install tor-browser: http: // www.torproject.org/projects/torbrowser.html.en
2.After a successful installation, run the browser and wait for initialization.
3.Type in the address bar: pay tord mbdekmizq.onion/1RYjjmz
4.Follow the instructions on the site.

I installed Spybot on Friday and ran a full scan. Found 710 threats and quarantined them all (I think)

I hope someone can help! It is impossible to do anything right now!!!! Below are my logs:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-11-2014
Ran by Melissa (administrator) on LAPTOP on 11-11-2014 17:48:04
Running from C:\Users\Melissa\Desktop
Loaded Profile: Melissa (Available profiles: Melissa & QBDataServiceUser21)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Stardock Corporation) C:\Program Files\Dell\DellDock\DockLogin.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Windstream) C:\Program Files (x86)\Windstream\Diagnostic Tools\HsdService.exe
(LeapFrog Enterprises, Inc.) C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe
(Alcatel-Lucent) C:\Program Files (x86)\Common Files\Motive\McciCMService.exe
(Alcatel-Lucent) C:\Program Files\Common Files\Motive\McciCMService.exe
(Intuit) C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
(Intuit Inc.) C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
(Radialpoint SafeCare Inc.) C:\Program Files (x86)\Windstream\Service Agent\ServicepointService.exe
(SoftThinks SAS) C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApntEx.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\hidfind.exe
() C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Windstream) C:\Program Files (x86)\Windstream\Service Agent\Windstream Service Agent.exe
(LeapFrog Enterprises, Inc.) C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Intuit Inc.) C:\Program Files (x86)\Intuit\QuickBooks 2012\QBW32.EXE
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(PC-Doctor, Inc.) C:\Program Files\My Dell\uaclauncher.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\ielowutil.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [QuickSet] => C:\Program Files\Dell\QuickSet\QuickSet.exe [3200672 2010-06-30] (Dell Inc.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10918504 2010-06-14] (Realtek Semiconductor)
HKLM\...\Run: [Apoint] => C:\Program Files\DellTPad\Apoint.exe [392048 2010-06-04] (Alps Electric Co., Ltd.)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-06-08] (Intel Corporation)
HKLM-x32\...\Run: [Windstream Service Agent.exe] => C:\Program Files (x86)\Windstream\Service Agent\Windstream Service Agent.exe [10204472 2011-10-13] (Windstream)
HKLM-x32\...\Run: [Monitor] => C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe [298376 2012-09-28] (LeapFrog Enterprises, Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2011-05-10] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
HKLM-x32\...\RunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] => C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe [560128 2011-09-19] (Dell)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...D6A79037F57F\InprocServer32: [Default-fastprox] C:\$Recycle.Bin\S-1-5-18\$3b99f81f31d5dbab1bcf87d0107a285a\o. ATTENTION! ====> ZeroAccess?
HKU\S-1-5-21-3154378874-1875084861-2286133563-1001\...\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [4566952 2014-06-24] (Safer-Networking Ltd.)
HKU\S-1-5-21-3154378874-1875084861-2286133563-1001\...\MountPoints2: {6e8cc5bf-7b93-11e2-bb1d-f04da291e1f2} - E:\TLBootstrap_WPP.exe
HKU\S-1-5-21-3154378874-1875084861-2286133563-1001\...\MountPoints2: {8b9c99fc-401b-11e1-9a06-061bb1456f9c} - E:\LaunchU3.exe
HKU\S-1-5-21-3154378874-1875084861-2286133563-1001\...409d6c4515e9\InprocServer32: [Default-shell32] C:\$Recycle.Bin\S-1-5-21-3154378874-1875084861-2286133563-1001\$3b99f81f31d5dbab1bcf87d0107a285a\n. ATTENTION! ====> ZeroAccess?
HKU\S-1-5-21-3154378874-1875084861-2286133563-1001\...A8F59079A8D5}\localserver32: rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf>ktds (the data entry has 239 more characters). <==== Poweliks!
HKU\S-1-5-18\...\Run: [3e3266] => C:\3e3266e\3e3266e.exe [274500 2014-11-11] ( )
HKU\S-1-5-18\...\Run: [3e3266e] => C:\Users\Melissa\AppData\Roaming\3e3266e.exe [274500 2014-11-11] ( )
AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll => C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll File Not Found
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Intuit Data Protect.lnk
ShortcutTarget: Intuit Data Protect.lnk -> C:\Program Files (x86)\Common Files\Intuit\DataProtect\IntuitDataProtect.exe (Intuit Inc.)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Melissa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\3e3266e.exe ( )
Startup: C:\Users\QBDataServiceUser21\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
BootExecute: autocheck autochk * sdnclean64.exebddel.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
URLSearchHook: HKCU - Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
SearchScopes: HKCU - DefaultScope {114DB5FA-0AFB-BB92-A75B-F44D3CE875CD} URL = http://www.trovi.com/Results.aspx?gd=&ctid=CT3330390&octid=EB_ORIGINAL_CTID&ISID=M3D70D438-989F-4ECB-BA82-CCA300550E22&SearchSource=58&CUI=&UM=6&UP=SPD3324CD6-0783-4263-9C08-267860FCEFE1&q={searchTerms}&SSPV=
SearchScopes: HKCU - {114DB5FA-0AFB-BB92-A75B-F44D3CE875CD} URL = http://www.trovi.com/Results.aspx?gd=&ctid=CT3330390&octid=EB_ORIGINAL_CTID&ISID=M3D70D438-989F-4ECB-BA82-CCA300550E22&SearchSource=58&CUI=&UM=6&UP=SPD3324CD6-0783-4263-9C08-267860FCEFE1&q={searchTerms}&SSPV=
SearchScopes: HKCU - {38E8554E-EFF1-4E7A-A9FA-700C7D4C906D} URL = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=ie8
SearchScopes: HKCU - {4989EE16-E9A9-4D8E-B14C-7303338FE56F} URL = http://www.flickr.com/search/?q={searchTerms}
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
SearchScopes: HKCU - {B298DA9B-6161-4E52-A5E0-C37F9266DD75} URL = http://delicious.com/search?p={searchTerms}
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: &Yahoo! Toolbar Helper -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO-x32: Search Helper -> {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} -> C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: SingleInstance Class -> {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} -> C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM-x32 - Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
Toolbar: HKU\S-1-5-21-3154378874-1875084861-2286133563-1001 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
DPF: HKLM-x32 {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: HKLM-x32 {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20614.www2.hp.com/ediags/gmd/Install/Cab/hpdetect119b.cab
DPF: HKLM-x32 {BEA7310D-06C4-4339-A784-DC3804819809} http://www.cvsphoto.com/upload/activex/v3_0_0_7/PhotoCenter_ActiveX_Control.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: intu-help-qb5 - {867FCB77-9823-4cd6-8210-D85F968D466F} - No File
Handler: intu-help-qb6 - {6898B29B-BF49-43cb-A0B1-D0B9496AF491} - No File
Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - No File
Handler-x32: intu-help-qb5 - {867FCB77-9823-4cd6-8210-D85F968D466F} - C:\Program Files (x86)\Intuit\QuickBooks 2012\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
Handler-x32: intu-help-qb6 - {6898B29B-BF49-43cb-A0B1-D0B9496AF491} - No File
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Handler-x32: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.254.254

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_223.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @radialpoint.com/SPA,version=1 -> C:\Program Files (x86)\Windstream\Service Agent\nprpspa.dll (Windstream)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_223.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=1.6.0_35 -> C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @Motive.com/NpMotive,version=1.0 -> C:\Program Files (x86)\Common Files\Motive\npMotive.dll (Alcatel-Lucent)
FF Plugin-x32: @radialpoint.com/SPA,version=1 -> C:\Program Files (x86)\Windstream\Service Agent\nprpspa.dll (Windstream)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3154378874-1875084861-2286133563-1001: @nds.com/PCShowPlugin -> C:\Users\Melissa\AppData\Local\DIRECTV Player\npPCShowPlugin.dll No File
FF Plugin HKU\S-1-5-21-3154378874-1875084861-2286133563-1001: @nds.com/PlayerPlugin -> C:\Users\Melissa\AppData\Local\DIRECTV Player\npPlayerPlugin.dll (DIRECTV)
FF Plugin HKU\S-1-5-21-3154378874-1875084861-2286133563-1001: amazon.com/AmazonMP3DownloaderPlugin -> C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101752.dll (Amazon.com, Inc.)
FF Plugin HKU\S-1-5-21-3154378874-1875084861-2286133563-1001: NDS.com/PlayerPlugin -> C:\Users\Melissa\AppData\Local\DIRECTV Player\npPlayerPlugin.dll (DIRECTV)
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010-12-08]

Chrome:
=======
CHR Profile: C:\Users\Melissa\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Melissa\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-11-20]
CHR Extension: (Google Drive) - C:\Users\Melissa\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-11-20]
CHR Extension: (YouTube) - C:\Users\Melissa\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-11-20]
CHR Extension: (Google Search) - C:\Users\Melissa\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-11-20]
CHR Extension: (Radialpoint SPD Extension) - C:\Users\Melissa\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmmhpfbhngkongobaoibpmnijjokabmj [2012-09-19]
CHR Extension: (Google Wallet) - C:\Users\Melissa\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-20]
CHR Extension: (Gmail) - C:\Users\Melissa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-11-20]
CHR HKLM-x32\...\Chrome\Extension: [lmmhpfbhngkongobaoibpmnijjokabmj] - C:\Program Files (x86)\Windstream\Service Agent\ChromeExtension.crx [2012-03-26]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2436280 2014-09-25] (Microsoft Corporation)
R2 DockLoginService; C:\Program Files\Dell\DellDock\DockLogin.exe [155648 2009-06-09] (Stardock Corporation) [File not signed]
R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-05-21] (Hewlett-Packard Co.) [File not signed]
R2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1039360 2010-10-22] (Hewlett-Packard Co.) [File not signed]
R2 HsdService; C:\Program Files (x86)\Windstream\Diagnostic Tools\HsdService.exe [1393976 2011-04-25] (Windstream)
R2 McciCMService; C:\Program Files (x86)\Common Files\Motive\McciCMService.exe [319488 2010-05-13] (Alcatel-Lucent) [File not signed]
R2 McciCMService64; C:\Program Files\Common Files\Motive\McciCMService.exe [517632 2010-05-13] (Alcatel-Lucent) [File not signed]
S2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
S2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
R2 QBCFMonitorService; C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe [45056 2013-11-08] (Intuit) [File not signed]
S3 QBFCService; C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe [61440 2012-01-10] (Intuit Inc.) [File not signed]
R2 QBVSS; C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe [1248256 2012-01-10] (Intuit Inc.) [File not signed]
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1740760 2014-09-03] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
S2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
R2 ServicepointService; C:\Program Files (x86)\Windstream\Service Agent\ServicepointService.exe [10315064 2011-10-13] (Radialpoint SafeCare Inc.)
S2 CltMngSvc; C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 FlyUsb; C:\Windows\System32\DRIVERS\FlyUsb.sys [24576 2008-04-01] (LeapFrog)
S3 MREMP50; C:\Program Files (x86)\Common Files\Motive\MREMP50.sys [21248 2010-03-02] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
S3 MRESP50; C:\Program Files (x86)\Common Files\Motive\MRESP50.sys [20096 2010-03-02] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
S3 Normandy; C:\Windows\SysWow64\Drivers\Normandy.sys [34560 2010-11-18] () [File not signed]
R1 SDHookDriver; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHookDrv64.sys [64160 2014-04-25] ()
S3 sscdserd; C:\Windows\System32\DRIVERS\sscdserd.sys [114856 2007-07-03] (MCCI Corporation)
S3 MREMP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS [X]
S3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [X]
S3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [X]
S3 MRESP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [X]
S3 SPPD; \??\C:\Windows\system32\drivers\SPPD.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-11-11 17:48 - 2014-11-11 17:54 - 00023204 _____ () C:\Users\Melissa\Desktop\FRST.txt
2014-11-11 17:46 - 2014-11-11 17:49 - 00000000 ____D () C:\FRST
2014-11-11 17:44 - 2014-11-11 17:44 - 02116096 _____ (Farbar) C:\Users\Melissa\Desktop\FRST64.exe
2014-11-11 17:37 - 2014-11-11 17:37 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-LAPTOP-Microsoft-Windows-7-Home-Premium-(64-bit).dat
2014-11-11 17:33 - 2014-11-11 17:33 - 17926832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-11-11 17:29 - 2014-11-11 17:29 - 00000000 ____D () C:\RegBackup
2014-11-11 17:27 - 2014-11-11 17:27 - 00002201 _____ () C:\Users\Public\Desktop\Tweaking.com - Registry Backup.lnk
2014-11-11 17:27 - 2014-11-11 17:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2014-11-11 17:27 - 2014-11-11 17:27 - 00000000 ____D () C:\Program Files (x86)\Tweaking.com
2014-11-11 17:24 - 2014-11-11 17:25 - 04215584 _____ () C:\Users\Melissa\Desktop\tweaking.com_registry_backup_setup.exe
2014-11-11 13:52 - 2014-11-11 13:52 - 00008538 _____ () C:\Users\Melissa\Downloads\DECRYPT_INSTRUCTION.HTML
2014-11-11 13:52 - 2014-11-11 13:52 - 00004212 _____ () C:\Users\Melissa\Downloads\DECRYPT_INSTRUCTION.TXT
2014-11-11 13:52 - 2014-11-11 13:52 - 00000268 _____ () C:\Users\Melissa\Downloads\DECRYPT_INSTRUCTION.URL
2014-11-11 13:51 - 2014-11-11 13:51 - 00008538 _____ () C:\Users\Melissa\Documents\DECRYPT_INSTRUCTION.HTML
2014-11-11 13:51 - 2014-11-11 13:51 - 00004212 _____ () C:\Users\Melissa\Documents\DECRYPT_INSTRUCTION.TXT
2014-11-11 13:51 - 2014-11-11 13:51 - 00000268 _____ () C:\Users\Melissa\Documents\DECRYPT_INSTRUCTION.URL
2014-11-11 13:33 - 2014-11-11 13:33 - 00008538 _____ () C:\Users\Melissa\AppData\Roaming\DECRYPT_INSTRUCTION.HTML
2014-11-11 13:33 - 2014-11-11 13:33 - 00008538 _____ () C:\Users\Melissa\AppData\DECRYPT_INSTRUCTION.HTML
2014-11-11 13:33 - 2014-11-11 13:33 - 00004212 _____ () C:\Users\Melissa\AppData\Roaming\DECRYPT_INSTRUCTION.TXT
2014-11-11 13:33 - 2014-11-11 13:33 - 00004212 _____ () C:\Users\Melissa\AppData\DECRYPT_INSTRUCTION.TXT
2014-11-11 13:33 - 2014-11-11 13:33 - 00000268 _____ () C:\Users\Melissa\AppData\Roaming\DECRYPT_INSTRUCTION.URL
2014-11-11 13:33 - 2014-11-11 13:33 - 00000268 _____ () C:\Users\Melissa\AppData\DECRYPT_INSTRUCTION.URL
2014-11-11 13:31 - 2014-11-11 13:31 - 00008538 _____ () C:\Users\Melissa\AppData\Local\DECRYPT_INSTRUCTION.HTML
2014-11-11 13:31 - 2014-11-11 13:31 - 00004212 _____ () C:\Users\Melissa\AppData\Local\DECRYPT_INSTRUCTION.TXT
2014-11-11 13:31 - 2014-11-11 13:31 - 00000268 _____ () C:\Users\Melissa\AppData\Local\DECRYPT_INSTRUCTION.URL
2014-11-11 13:23 - 2014-11-11 13:23 - 00008538 _____ () C:\ProgramData\DECRYPT_INSTRUCTION.HTML
2014-11-11 13:23 - 2014-11-11 13:23 - 00004212 _____ () C:\ProgramData\DECRYPT_INSTRUCTION.TXT
2014-11-11 13:23 - 2014-11-11 13:23 - 00000268 _____ () C:\ProgramData\DECRYPT_INSTRUCTION.URL
2014-11-11 13:03 - 2014-11-11 13:03 - 00274500 _____ ( ) C:\Users\Melissa\AppData\Roaming\3e3266e.exe
2014-11-11 13:03 - 2014-11-11 13:03 - 00000000 ___HD () C:\3e3266e
2014-11-11 13:03 - 2014-11-11 13:03 - 00000000 ____D () C:\ProgramData\Windows Genuine Advantage
2014-11-07 22:27 - 2014-11-08 09:13 - 00002222 _____ () C:\Windows\wininit.ini
2014-11-07 19:08 - 2014-11-08 07:59 - 00047082 _____ () C:\Windows\SysWOW64\bddel.dat
2014-11-07 18:40 - 2014-11-08 07:43 - 00000000 ____D () C:\Program Files (x86)\Browser Features
2014-11-07 18:40 - 2014-11-07 18:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Browser Features
2014-11-07 18:38 - 2014-11-08 07:41 - 00000000 ____D () C:\Users\Melissa\AppData\Local\SearchProtect
2014-11-07 18:38 - 2014-11-07 22:30 - 00000000 ____D () C:\Program Files (x86)\Browser Enhancements
2014-11-07 18:38 - 2014-11-07 22:27 - 00000000 ____D () C:\Program Files (x86)\SearchProtect
2014-11-07 18:38 - 2014-11-07 18:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Browser Enhancements
2014-11-07 18:36 - 2014-11-07 18:36 - 00000000 ____D () C:\Users\Melissa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-11-07 11:46 - 2009-06-10 16:00 - 00000824 _____ () C:\Windows\system32\Drivers\etc\hosts.20141107-114626.backup
2014-11-06 12:50 - 2014-11-06 12:50 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-11-06 12:49 - 2014-11-06 12:49 - 00001357 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2014-11-06 12:49 - 2014-11-06 12:49 - 00001345 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2014-11-06 12:49 - 2014-11-06 12:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2014-11-06 12:47 - 2014-11-11 13:23 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-11-06 12:47 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe
2014-11-06 11:39 - 2014-11-06 11:40 - 00560968 _____ (Safer-Networking Ltd. ) C:\Users\Melissa\Downloads\spybot2-license.exe
2014-11-06 11:34 - 2014-11-06 13:15 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-11-06 09:35 - 2014-11-06 09:45 - 00000046 _____ () C:\Users\Melissa\AppData\Roaming\FactoryInstaller.xml
2014-11-06 09:35 - 2014-11-06 09:35 - 00000000 ____D () C:\Users\Melissa\AppData\Local\Absolute_Software
2014-11-05 12:21 - 2014-11-05 12:21 - 00000000 ____D () C:\Windows\pss
2014-11-05 12:04 - 2014-03-19 22:24 - 00114688 _____ () C:\Users\Melissa\AppData\Local\ChromeHitoryDB
2014-11-04 08:50 - 2014-11-07 21:54 - 00004974 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for Laptop-Melissa Laptop
2014-10-18 07:25 - 2014-10-18 07:27 - 00019968 ___SH () C:\Users\Melissa\Documents\Thumbs.db
2014-10-18 07:25 - 2014-10-18 07:26 - 00000000 ____D () C:\Users\Melissa\AppData\Local\{19D1A341-988F-4F90-8893-504C640BA873}
2014-10-18 07:14 - 2014-10-18 07:14 - 00000000 ____D () C:\Users\Melissa\AppData\Local\{0C8F4456-1BB7-4103-9258-84AA0A6EF203}

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-11-11 17:59 - 2011-04-07 12:23 - 00000000 ____D () C:\Users\Melissa\Documents\MAdrac Farms
2014-11-11 17:48 - 2012-03-26 13:20 - 00000000 ____D () C:\ProgramData\Radialpoint
2014-11-11 17:47 - 2009-07-13 23:45 - 00013872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-11-11 17:47 - 2009-07-13 23:45 - 00013872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-11-11 17:34 - 2012-04-03 16:13 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-11-11 17:34 - 2012-04-03 16:13 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-11-11 17:34 - 2012-04-03 16:13 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-11-11 17:34 - 2011-05-21 15:29 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-11-11 16:41 - 2011-06-23 15:10 - 00000000 ____D () C:\Users\Melissa\Documents\Outlook Files
2014-11-11 16:40 - 2010-10-25 08:43 - 00000000 ____D () C:\Users\Melissa\Documents\personal
2014-11-11 16:25 - 2010-09-18 13:05 - 00000000 ____D () C:\Program Files (x86)\Dell DataSafe Local Backup
2014-11-11 16:24 - 2009-07-14 00:13 - 00006320 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-11-11 13:51 - 2011-04-15 07:58 - 00000000 ____D () C:\Users\Melissa\Documents\Taxes
2014-11-11 13:51 - 2010-10-25 08:43 - 00000000 ____D () C:\Users\Melissa\Documents\WBENC
2014-11-11 13:51 - 2010-10-25 08:43 - 00000000 ____D () C:\Users\Melissa\Documents\pics
2014-11-11 13:48 - 2011-10-18 09:23 - 00000000 ____D () C:\Users\Melissa\Documents\OLD jobs
2014-11-11 13:44 - 2011-09-26 11:01 - 00000000 ____D () C:\Users\Melissa\Documents\OgeeChee
2014-11-11 13:43 - 2010-12-17 11:52 - 00000000 ____D () C:\Users\Melissa\Documents\My Scans
2014-11-11 13:40 - 2014-06-12 10:52 - 00000000 ____D () C:\Users\Melissa\Documents\Invoices
2014-11-11 13:40 - 2012-02-10 12:51 - 00000000 ____D () C:\Users\Melissa\Documents\Largo Tibet
2014-11-11 13:39 - 2014-02-10 08:16 - 00000000 ____D () C:\Users\Melissa\Documents\Guerry
2014-11-11 13:39 - 2013-05-06 15:15 - 00000000 ____D () C:\Users\Melissa\Documents\Heard elementary
2014-11-11 13:39 - 2011-08-10 10:29 - 00000000 ____D () C:\Users\Melissa\Documents\HAAF engagement
2014-11-11 13:38 - 2013-04-02 10:52 - 00000000 ____D () C:\Users\Melissa\Documents\gaffney's cheap seats
2014-11-11 13:38 - 2012-08-09 16:14 - 00000000 ____D () C:\Users\Melissa\Documents\FT. Stewart Training Facility
2014-11-11 13:37 - 2014-04-08 13:00 - 00000000 ____D () C:\Users\Melissa\Documents\Contractors
2014-11-11 13:37 - 2011-11-28 11:16 - 00000000 ____D () C:\Users\Melissa\Documents\Countryside
2014-11-11 13:36 - 2010-10-25 08:42 - 00000000 ____D () C:\Users\Melissa\Documents\commercial bids
2014-11-11 13:35 - 2012-09-05 15:29 - 00000000 ____D () C:\Users\Melissa\Documents\Coffee bluff Marina
2014-11-11 13:35 - 2010-10-25 08:43 - 00000000 ____D () C:\Users\Melissa\Documents\business forms
2014-11-11 13:34 - 2012-10-31 10:52 - 00000000 ____D () C:\Users\Melissa\Documents\Amazon MP3
2014-11-11 13:34 - 2012-09-05 09:51 - 00000000 ____D () C:\Users\Melissa\Documents\Bible Lutheran
2014-11-11 13:34 - 2011-11-28 16:42 - 00000000 ____D () C:\Users\Melissa\Desktop\Visualizations
2014-11-11 13:34 - 2011-11-28 16:42 - 00000000 ____D () C:\Users\Melissa\Desktop\Sequences
2014-11-11 13:34 - 2011-11-28 16:42 - 00000000 ____D () C:\Users\Melissa\Desktop\Audio
2014-11-11 13:34 - 2010-10-25 08:42 - 00000000 ____D () C:\Users\Melissa\Documents\Bell computer
2014-11-11 13:33 - 2011-05-21 15:38 - 00000000 ____D () C:\Users\Melissa\AppData\Roaming\PCDr
2014-11-11 13:33 - 2010-10-15 18:30 - 00000000 ____D () C:\Users\Melissa\AppData\Roaming\Skype
2014-11-11 13:32 - 2014-05-16 10:41 - 00000000 ____D () C:\Users\Melissa\AppData\OICE_15_974FA576_32C1D314_1139
2014-11-11 13:32 - 2013-08-27 12:47 - 00000000 ____D () C:\Users\Melissa\AppData\OICE_15_974FA576_32C1D314_2CDE
2014-11-11 13:32 - 2012-10-31 10:52 - 00000000 ____D () C:\Users\Melissa\AppData\Roaming\Amazon
2014-11-11 13:32 - 2010-12-08 16:35 - 00000000 ____D () C:\Users\Melissa\AppData\Roaming\HP
2014-11-11 13:32 - 2010-10-11 16:45 - 00000000 ____D () C:\Users\Melissa\AppData\Roaming\Adobe
2014-11-11 13:32 - 2010-10-11 16:42 - 00000000 ____D () C:\Users\Melissa\AppData\Roaming\Dell
2014-11-11 13:31 - 2010-12-03 17:13 - 00000000 ____D () C:\Users\Melissa\AppData\Local\Microsoft Games
2014-11-11 13:24 - 2014-03-25 22:12 - 00000000 ____D () C:\Users\Melissa\AppData\Local\DIRECTV Player
2014-11-11 13:24 - 2014-01-12 21:11 - 00000000 ____D () C:\Users\Melissa\AppData\Local\Apple Computer
2014-11-11 13:24 - 2010-10-21 13:38 - 00000000 ____D () C:\Users\Melissa\AppData\Local\Google
2014-11-11 13:24 - 2010-10-12 14:14 - 00000000 ____D () C:\Users\Melissa\AppData\Local\Intuit
2014-11-11 13:23 - 2012-03-26 13:20 - 00000000 ____D () C:\ProgramData\Windstream
2014-11-11 13:23 - 2010-09-18 12:57 - 00000000 ____D () C:\ProgramData\Skype
2014-11-11 13:23 - 2010-09-18 12:43 - 00000000 ____D () C:\ProgramData\Sonic
2014-11-11 13:22 - 2010-09-18 12:41 - 00000000 ____D () C:\ProgramData\PCDr
2014-11-11 13:19 - 2012-03-26 13:18 - 00000000 ____D () C:\ProgramData\Motive
2014-11-11 13:19 - 2011-11-28 16:20 - 00000000 ____D () C:\ProgramData\Light-O-Rama
2014-11-11 13:19 - 2010-11-28 15:15 - 00000000 ____D () C:\ProgramData\Leapfrog
2014-11-11 13:19 - 2010-10-12 14:03 - 00000000 ____D () C:\ProgramData\Intuit
2014-11-11 13:19 - 2010-09-18 12:42 - 00000000 ____D () C:\ProgramData\Macrovision
2014-11-11 13:08 - 2010-12-08 16:18 - 00000000 ____D () C:\ProgramData\HP
2014-11-11 13:07 - 2014-02-24 12:26 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-11-11 13:07 - 2010-09-18 16:16 - 00000000 ____D () C:\Dell
2014-11-11 13:07 - 2010-09-18 12:32 - 00000000 ____D () C:\ProgramData\Dell
2014-11-11 10:33 - 2012-03-26 13:20 - 00000000 ____D () C:\Users\Melissa\AppData\Roaming\Radialpoint
2014-11-10 16:06 - 2010-09-18 11:58 - 02081760 _____ () C:\Windows\WindowsUpdate.log
2014-11-10 16:02 - 2013-05-22 13:17 - 00003440 _____ () C:\Windows\System32\Tasks\PCDEventLauncherTask
2014-11-09 13:14 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-11-09 13:13 - 2013-11-20 09:24 - 00000476 _____ () C:\Windows\Tasks\SDMsgUpdate (TE).job
2014-11-09 13:11 - 2010-10-11 16:41 - 00000000 ____D () C:\Users\Default\AppData\Local\SoftThinks
2014-11-09 13:11 - 2010-10-11 16:41 - 00000000 ____D () C:\Users\Default User\AppData\Local\SoftThinks
2014-11-09 13:09 - 2013-11-20 09:24 - 00000484 _____ () C:\Windows\Tasks\SDMsgUpdate (Local).job
2014-11-09 13:08 - 2010-10-11 17:14 - 00452548 _____ () C:\Windows\PFRO.log
2014-11-09 13:08 - 2009-07-14 00:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-11-09 13:08 - 2009-07-13 23:51 - 00067532 _____ () C:\Windows\setupact.log
2014-11-08 07:46 - 2014-09-02 20:23 - 00000000 ____D () C:\Program Files (x86)\FUPM Browser
2014-11-07 19:02 - 2010-10-11 18:00 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-11-07 18:56 - 2013-03-18 08:45 - 00000000 ____D () C:\Program Files\Microsoft Office 15
2014-11-06 13:32 - 2013-03-18 09:36 - 00000000 ___RD () C:\Users\Melissa\SkyDrive
2014-11-06 11:03 - 2012-06-12 18:19 - 02656768 ___SH () C:\Users\Melissa\Desktop\Thumbs.db
2014-11-05 12:10 - 2012-09-19 09:58 - 00000000 ____D () C:\Program Files (x86)\Google
2014-10-24 07:45 - 2012-09-19 09:59 - 00003894 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA

ZeroAccess:
C:\$Recycle.Bin\S-1-5-21-3154378874-1875084861-2286133563-1001\$3b99f81f31d5dbab1bcf87d0107a285a

ZeroAccess:
C:\$Recycle.Bin\S-1-5-18\$3b99f81f31d5dbab1bcf87d0107a285a

Some content of TEMP:
====================
C:\Users\Melissa\AppData\Local\Temp\bs.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-11-05 10:31

==================== End Of Log ============================

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-11-2014
Ran by Melissa at 2014-11-11 18:05:37
Running from C:\Users\Melissa\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

4500_G510nz_Help (x32 Version: 000.0.439.000 - Hewlett-Packard) Hidden
4500G510nz (x32 Version: 000.0.439.000 - Hewlett-Packard) Hidden
4500G510nz_Software_Min (x32 Version: 000.0.423.000 - Hewlett-Packard) Hidden
64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden
ABBYY FineReader 6.0 Sprint (HKLM-x32\...\{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}) (Version: 6.00.1990.41618 - ABBYY Software House)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 2.0.4.13090 - Adobe Systems Inc.)
Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.223 - Adobe Systems Incorporated)
Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.223 - Adobe Systems Incorporated)
Adobe Reader X (10.1.8) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.8 - Adobe Systems Incorporated)
Advanced Audio FX Engine (HKLM-x32\...\Advanced Audio FX Engine) (Version: 1.12.05 - Creative Technology Ltd)
Amazon MP3 Downloader 1.0.17 (HKLM-x32\...\Amazon MP3 Downloader) (Version: 1.0.17 - Amazon Services LLC)
Apple Application Support (HKLM-x32\...\{21FC2093-6E43-460B-B9B0-5F5AA35BBB0F}) (Version: 3.0 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{FE86CB0C-FCB3-4358-B4B0-B0A41E33B3DD}) (Version: 7.1.0.32 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Browser Enhancements version 3.17 (HKLM-x32\...\{85A37836-5888-4152-8990-EF4502A5EFB1}}_is1) (Version: 3.17 - Browser Enhancements)
Browser Features version 2.22 (HKLM-x32\...\{6C250DDC-A10E-4F36-95B4-59A76592DA20}}_is1) (Version: 2.22 - Browser Features)
BufferChm (x32 Version: 130.0.331.000 - Hewlett-Packard) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Dell DataSafe Local Backup - Support Software (HKLM-x32\...\{A9668246-FB70-4103-A1E3-66C9BC2EFB49}) (Version: 9.4.60 - Dell)
Dell DataSafe Local Backup (HKLM-x32\...\{0ED7EE95-6A97-47AA-AD73-152C08A15B04}) (Version: 9.4.60 - Dell)
Dell DataSafe Online (HKLM-x32\...\{13766F76-6C8C-4E57-A9F3-3212D1C6E0D1}) (Version: 1.2.0011 - Dell, Inc.)
Dell Dock (HKLM-x32\...\Dell Dock) (Version: - Stardock Corporation)
Dell Dock (Version: 2.0 - Stardock Corporation) Hidden
Dell Getting Started Guide (HKLM-x32\...\{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}) (Version: 1.00.0000 - Dell Inc.)
Dell Touchpad (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 7.1107.101.209 - ALPS ELECTRIC CO., LTD.)
Dell Webcam Central (HKLM-x32\...\Dell Webcam Central) (Version: 1.40.05 - Creative Technology Ltd)
Destinations (x32 Version: 130.0.0.0 - Hewlett-Packard) Hidden
DeviceDiscovery (x32 Version: 130.0.372.000 - Hewlett-Packard) Hidden
DIRECTV Player (HKLM-x32\...\{a1bb9be6-729f-4049-a36a-aad335c86c01}) (Version: 9.2 - DIRECTV)
DocMgr (x32 Version: 130.0.000.000 - Hewlett-Packard) Hidden
DocProc (x32 Version: 13.0.0.0 - Hewlett-Packard) Hidden
Fax (x32 Version: 130.0.418.000 - Hewlett-Packard) Hidden
FUPM Browser version 1.2.1 (HKLM-x32\...\{B86A5F28-E714-49DD-9C61-6DC5BB867255}}_is1) (Version: 1.2.1 - Find Ultra Premium Merchants)
GPBaseService2 (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
HP Customer Participation Program 13.0 (HKLM\...\HPExtendedCapabilities) (Version: 13.0 - HP)
HP Document Manager 2.0 (HKLM\...\HP Document Manager) (Version: 2.0 - HP)
HP Imaging Device Functions 13.0 (HKLM\...\HP Imaging Device Functions) (Version: 13.0 - HP)
HP Officejet 4500 G510n-z (HKLM\...\{7E0E61CC-1C99-429D-BEA7-C4DD5B898D2A}) (Version: 13.0 - HP)
HP Product Detection (HKLM-x32\...\{4F38594F-2C4A-4C42-B2C4-505E225F6F80}) (Version: 11.14.0004 - HP)
HP Smart Web Printing 4.5 (HKLM\...\HP Smart Web Printing) (Version: 4.5 - HP)
HP Solution Center 13.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP)
HP Update (HKLM-x32\...\{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}) (Version: 5.003.001.001 - Hewlett-Packard)
HPDiagnosticAlert (x32 Version: 1.00.0000 - Microsoft) Hidden
HPProductAssistant (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: 8.15.10.2202 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 9.6.4.1002 - Intel Corporation)
iTunes (HKLM\...\{96B53CA8-5ABB-49D8-96F1-F6C0D73A76C6}) (Version: 11.1.4.62 - Apple Inc.)
Java(TM) 6 Update 18 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86416018F0}) (Version: 6.0.180 - Sun Microsystems, Inc.)
Java(TM) 6 Update 20 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86416020FF}) (Version: 6.0.200 - Sun Microsystems, Inc.)
Java(TM) 6 Update 35 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216035FF}) (Version: 6.0.350 - Oracle)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
LeapFrog Connect (HKLM-x32\...\UPCShell) (Version: 4.2.9.15649 - LeapFrog)
LeapFrog Connect (x32 Version: 4.2.9.15649 - LeapFrog) Hidden
LeapFrog LeapPad Explorer Plugin (x32 Version: 4.2.11.15696 - LeapFrog) Hidden
LeapFrog Tag Plugin (x32 Version: 4.2.9.15649 - LeapFrog) Hidden
Light-O-Rama (HKLM-x32\...\{E744BFEA-E027-441E-83A2-36202F661E31}) (Version: 3.0.2 - Light-O-Rama)
LoJack Factory Installer (HKLM-x32\...\{40F4FF7A-B214-4453-B973-080B09CED019}) (Version: 1.0.0 - Absolute Software)
MarketResearch (x32 Version: 130.0.374.000 - Hewlett-Packard) Hidden
Microsoft .NET Framework 2.0 SDK (x64) - ENU (HKLM\...\Microsoft .NET Framework 2.0 SDK (x64) - ENU) (Version: - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Office 2010 Service Pack 1 (SP1) (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE}) (Version: - Microsoft)
Microsoft Office 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 15.0.4659.1001 - Microsoft Corporation)
Microsoft Office Home and Student 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.6029.1000 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3154378874-1875084861-2286133563-1001\...\OneDriveSetup.exe) (Version: 17.3.1229.0918 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable - KB2467175 (HKLM-x32\...\{a0fe116e-9a8a-466f-aee0-625cb7c207e3}) (Version: 8.0.51011 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{052bac4a-6f79-46d4-a024-1ce1b4f73cd4}) (Version: 8.0.58299 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{820B6609-4C97-3A2B-B644-573B06A0F0CC}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.31007 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP2 Parser and SDK (HKLM-x32\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
My Dell (HKLM\...\PC-Doctor for Windows) (Version: 3.5.6426.22 - PC-Doctor, Inc.)
Network64 (Version: 130.0.374.000 - Hewlett-Packard) Hidden
Network64 (Version: 140.0.221.000 - Hewlett-Packard) Hidden
OCR Software by I.R.I.S. 13.0 (HKLM\...\HPOCR) (Version: 13.0 - HP)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4659.1001 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4659.1001 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4659.1001 - Microsoft Corporation) Hidden
QuickBooks (x32 Version: 22.0.4015.2206 - Intuit Inc.) Hidden
QuickBooks Pro 2012 (HKLM-x32\...\{22057D8D-7CC8-46FF-AD8C-9BD24F9014F3}) (Version: 22.0.4015.2206 - Intuit Inc.)
Quickset64 (HKLM\...\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 10.06.02 - Dell Inc.)
Radialpoint Security Advisor 2.5.15 (x32 Version: 2.5.15 - Radialpoint SafeCare Inc.) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6136 - Realtek Semiconductor Corp.)
Roxio Burn (HKLM-x32\...\{B2E47DE7-800B-40BB-BD1F-9F221C3AEE87}) (Version: 1.01 - Roxio)
SAMSUNG Mobile Modem Driver Set (HKLM\...\SAMSUNG Mobile Modem) (Version: - )
Samsung Mobile phone USB driver Software (HKLM\...\Samsung Mobile phone USB driver) (Version: - )
SAMSUNG Mobile USB Modem 1.0 Software (HKLM\...\SAMSUNG Mobile USB Modem 1.0) (Version: - )
SAMSUNG Mobile USB Modem Software (HKLM\...\SAMSUNG Mobile USB Modem) (Version: - )
Samsung PC Studio 3 USB Driver Installer (HKLM-x32\...\{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}) (Version: 3.2.0.70701 - Samsung Electronics Co., Ltd.)
Scan (x32 Version: 13.0.0.0 - Hewlett-Packard) Hidden
Skype™ 5.10 (HKLM-x32\...\{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}) (Version: 5.10.116 - Skype Technologies S.A.)
SmartWebPrinting (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden
SolutionCenter (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.)
Status (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden
SupportSoft Assisted Service (HKLM-x32\...\{5A3F6A80-7913-475E-8B96-477A952CFA43}) (Version: 15 - SupportSoft)
System Requirements Lab (HKLM-x32\...\SystemRequirementsLab) (Version: - )
Toolbox (x32 Version: 130.0.648.000 - Hewlett-Packard) Hidden
TrayApp (x32 Version: 130.0.376.000 - Hewlett-Packard) Hidden
Tweaking.com - Registry Backup (HKLM-x32\...\Tweaking.com - Registry Backup) (Version: 1.10.1 - Tweaking.com)
Use the entry named LeapFrog Connect to uninstall (LeapFrog LeapPad Explorer Plugin) (HKLM-x32\...\LeapPadExplorerPlugin) (Version: - LeapFrog)
Use the entry named LeapFrog Connect to uninstall (LeapFrog Tag Plugin) (HKLM-x32\...\TagPlugin) (Version: 4.2.9.15649 - LeapFrog)
Visual Studio Tools for the Office system 3.0 Runtime Service Pack 1 (KB949258) (HKLM-x32\...\{8FB53850-246A-3507-8ADE-0060093FFEA6}.KB949258) (Version: 1 - Microsoft Corporation)
WebReg (x32 Version: 130.0.132.017 - Hewlett-Packard) Hidden
Windows Driver Package - LeapFrog (FlyUsb) USB (11/05/2008 1.1.1.0) (HKLM\...\781745E87AFF80C0C1388CFF79D19ECAB2E9BB47) (Version: 11/05/2008 1.1.1.0 - LeapFrog)
Windows Driver Package - Leapfrog (Leapfrog-USBLAN) Net (09/10/2009 02.03.05.012) (HKLM\...\8F14F2ECEDE68D26EA515B48DC25B39103C4FE8D) (Version: 09/10/2009 02.03.05.012 - Leapfrog)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Live Sync (HKLM-x32\...\{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}) (Version: 14.0.8089.726 - Microsoft Corporation)
Windstream Diagnostic Tools 3.0.21 (x32 Version: 3.0.21 - Windstream) Hidden
Windstream Service Agent 4.1.15 (HKLM-x32\...\RadialpointClientGateway_is1) (Version: 4.1.15 - Windstream)
Yahoo! Detect (HKLM-x32\...\YTdetect) (Version: - )
Yahoo! Toolbar (HKLM-x32\...\Yahoo! Companion) (Version: - )

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-3154378874-1875084861-2286133563-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Melissa\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-3154378874-1875084861-2286133563-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Melissa\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-3154378874-1875084861-2286133563-1001_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Melissa\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3154378874-1875084861-2286133563-1001_Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\localserver32 -> rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf>ktds (the data entry has 247 more characters). <==== Poweliks?
CustomCLSID: HKU\S-1-5-21-3154378874-1875084861-2286133563-1001_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Melissa\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3154378874-1875084861-2286133563-1001_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\Melissa\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3154378874-1875084861-2286133563-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Melissa\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-3154378874-1875084861-2286133563-1001_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Melissa\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3154378874-1875084861-2286133563-1001_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Melissa\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\FileSyncApi64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3154378874-1875084861-2286133563-1001_Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InprocServer32 -> C:\$Recycle.Bin ()

==================== Restore Points =========================

03-11-2014 21:59:09 Scheduled Checkpoint
08-11-2014 14:12:38 Cleaner (Spybot - Search & Destroy+AV 2.4, administrator privile

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 21:34 - 2014-11-07 11:46 - 00450713 ____R C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 www.007guard.com (http://www.007guard.com)
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com (http://www.008k.com)
127.0.0.1 008k.com
127.0.0.1 www.00hq.com (http://www.00hq.com)
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com (http://www.032439.com)
127.0.0.1 032439.com
127.0.0.1 www.0scan.com (http://www.0scan.com)
127.0.0.1 0scan.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1000gratisproben.com (http://www.1000gratisproben.com)
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com (http://www.1001namen.com)
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com (http://www.100888290cs.com)
127.0.0.1 www.100sexlinks.com (http://www.100sexlinks.com)
127.0.0.1 100sexlinks.com
127.0.0.1 10sek.com
127.0.0.1 www.10sek.com (http://www.10sek.com)
127.0.0.1 www.1-2005-search.com (http://www.1-2005-search.com)
127.0.0.1 1-2005-search.com
127.0.0.1 123fporn.info
127.0.0.1 www.123fporn.info (http://www.123fporn.info)
127.0.0.1 123haustiereundmehr.com
127.0.0.1 www.123haustiereundmehr.com (http://www.123haustiereundmehr.com)
127.0.0.1 123moviedownload.com

There are 1000 more lines.


==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {03AFC8D3-C38E-4AAF-92C7-E9381AD98AD3} - System32\Tasks\LoJack for Laptops Install => C:\Program Files (x86)\Absolute Software\LoJack Install\FactoryInstaller.exe [2009-11-26] (Absolute Software)
Task: {18C6765E-5D46-4C5F-8848-72EF568C4659} - System32\Tasks\SDMsgUpdate (Local) => C:\Program Files (x86)\SmartDraw CI\Messages\SDNotify.exe [2012-08-13] ()
Task: {36C156F5-C7A4-4C99-B5BB-09282CBEE9FF} - System32\Tasks\LaunchSignup => C:\Program Files (x86)\MyPC Backup\Signup Wizard.exe <==== ATTENTION
Task: {3E48F351-0754-4911-83AA-353F3119CA4F} - System32\Tasks\Microsoft Office 15 Sync Maintenance for Laptop-Melissa Laptop => C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe [2014-10-19] (Microsoft Corporation)
Task: {5AC44A0B-3312-4E1D-9BF7-3C2E821F64C0} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-11] (Adobe Systems Incorporated)
Task: {62616662-CF62-4526-A7A6-CED697EC2426} - System32\Tasks\IHUninstallTrackingTASK => CMD
Task: {683A5625-6256-47DA-9826-603CA72B75B6} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\My Dell\uaclauncher.exe [2014-01-31] (PC-Doctor, Inc.)
Task: {7956B706-6AF6-46AC-93E3-CD43C90CFA00} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2014-09-25] (Microsoft Corporation)
Task: {93076A17-E729-42E1-9755-C1279D093CA1} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {9CC368BA-943A-4114-9FC4-A624E96FA95C} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDUpdate.exe
Task: {A5452B19-D4D6-414C-8816-F8FA28ABD812} - System32\Tasks\SDMsgUpdate (TE) => C:\Program Files (x86)\SmartDraw CI\Messages\SDNotify.exe [2012-08-13] ()
Task: {ABE4E42F-B172-4B4C-A399-FE26F426F5A4} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDScan.exe
Task: {B5F2B017-85B0-471B-A3E4-8D437BE2ADD8} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe [2014-10-19] (Microsoft Corporation)
Task: {BB2C18C8-08A9-4BA7-8A70-71A878A6E49E} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\My Dell\sessionchecker.exe [2014-01-31] (PC-Doctor, Inc.)
Task: {BF8469D9-CF86-4312-AB10-4DEE368B374D} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDImmunize.exe
Task: {CF448ED9-A4F5-4B3D-8B26-CEBAF27DC871} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {DA59EBEE-9F99-4A87-9BD1-D11E4D367E4B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: {E037F955-36E3-41F5-946A-B2A2370049C3} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\SDMsgUpdate (Local).job => C:\PROGRA~2\SMARTD~1\Messages\SDNotify.exe
Task: C:\Windows\Tasks\SDMsgUpdate (TE).job => C:\PROGRA~2\SMARTD~1\Messages\SDNotify.exe

==================== Loaded Modules (whitelisted) =============

2014-11-07 18:53 - 2014-05-20 09:19 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2014-01-15 12:19 - 2014-10-19 12:58 - 08896160 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2010-09-18 13:05 - 2011-08-18 10:05 - 02751808 _____ () C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE
2014-02-06 00:52 - 2014-02-06 00:52 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-02-06 00:52 - 2014-02-06 00:52 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2014-11-06 12:47 - 2014-05-13 12:04 - 00109400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2014-11-06 12:47 - 2014-05-13 12:04 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
2014-11-06 12:47 - 2014-05-13 12:04 - 00167768 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2014-11-06 12:47 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll
2014-11-06 12:47 - 2012-04-03 17:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll
2012-05-12 02:45 - 2012-05-12 02:45 - 00170496 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\97d05107b8c95b1a62a45a87a7c8165f\IsdiInterop.ni.dll
2010-09-18 12:32 - 2010-06-08 10:44 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2013-11-08 08:48 - 2013-11-08 08:48 - 00269128 _____ () C:\Program Files (x86)\Intuit\QuickBooks 2012\boost_regex-vc90-mt-p-1_33.dll
2013-11-08 08:48 - 2013-11-08 08:48 - 00021320 _____ () C:\Program Files (x86)\Intuit\QuickBooks 2012\QBCompressor.dll
2012-01-10 09:56 - 2012-01-10 09:56 - 00059904 _____ () C:\Program Files (x86)\Intuit\QuickBooks 2012\zlib1.dll
2013-11-08 08:48 - 2013-11-08 08:48 - 00380744 _____ () C:\Program Files (x86)\Intuit\QuickBooks 2012\BackupLib.dll
2013-11-08 08:48 - 2013-11-08 08:48 - 00138568 _____ () C:\Program Files (x86)\Intuit\QuickBooks 2012\QBMAPILibrary.dll
2013-11-08 08:48 - 2013-11-08 08:48 - 00176968 _____ () C:\Program Files (x86)\Intuit\QuickBooks 2012\boost_serialization-vc90-mt-p-1_33.dll
2013-11-08 08:48 - 2013-11-08 08:48 - 00042824 _____ () C:\Program Files (x86)\Intuit\QuickBooks 2012\mbpopup.dll
2013-11-08 08:49 - 2013-11-08 08:49 - 00121672 _____ () C:\Program Files (x86)\Intuit\QuickBooks 2012\ReportBridge.dll
2013-11-08 08:48 - 2013-11-08 08:48 - 00070472 _____ () C:\Program Files (x86)\Intuit\QuickBooks 2012\QB2WPFBridge.dll
2013-11-08 08:48 - 2013-11-08 08:48 - 00400200 _____ () C:\Program Files (x86)\Intuit\QuickBooks 2012\FeaturesBridge.dll
2013-11-08 08:48 - 2013-11-08 08:48 - 00083272 _____ () C:\Program Files (x86)\Intuit\QuickBooks 2012\IPDWidgetBridge.dll
2013-11-08 08:48 - 2013-11-08 08:48 - 00093512 _____ () C:\Program Files (x86)\Intuit\QuickBooks 2012\IPDWidgetInterop.dll
2013-11-08 08:49 - 2013-11-08 08:49 - 00110920 _____ () C:\Program Files (x86)\Intuit\QuickBooks 2012\Webification.dll
2013-11-08 08:48 - 2013-11-08 08:48 - 00058184 _____ () C:\Program Files (x86)\Intuit\QuickBooks 2012\htmlhelper.dll
2014-09-25 14:49 - 2014-09-25 14:49 - 00081056 _____ () C:\Users\Melissa\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\LoggingPlatform.DLL
2014-03-16 05:56 - 2014-10-19 12:53 - 00122024 _____ () C:\Program Files\Microsoft Office 15\root\Office15\JitV.dll
2014-04-11 11:19 - 2014-10-19 12:47 - 00316576 _____ () C:\Program Files\Microsoft Office 15\root\Office15\AppVIsvStream32.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)


==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HsdService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ServicepointService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\HsdService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ntrexeservice => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NTRSupport => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ServicepointService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => C:\Windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk => C:\Windows\pss\QuickBooks Update Agent.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^QuickBooks_Standard_21.lnk => C:\Windows\pss\QuickBooks_Standard_21.lnk.CommonStartup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: Dell DataSafe Online => "C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m
MSCONFIG\startupreg: Dell Webcam Central => "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
MSCONFIG\startupreg: DellSupportCenter => "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
MSCONFIG\startupreg: Desktop Disc Tool => "C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe"
MSCONFIG\startupreg: DiagnosticTools.exe => "C:\Program Files (x86)\Windstream\Diagnostic Tools\DiagnosticTools.exe" /AUTORUN
MSCONFIG\startupreg: Intuit SyncManager => C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe startup
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"

========================= Accounts: ==========================

Administrator (S-1-5-21-3154378874-1875084861-2286133563-500 - Administrator - Disabled)
Guest (S-1-5-21-3154378874-1875084861-2286133563-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3154378874-1875084861-2286133563-1002 - Limited - Enabled)
Melissa (S-1-5-21-3154378874-1875084861-2286133563-1001 - Administrator - Enabled) => C:\Users\Melissa
QBDataServiceUser21 (S-1-5-21-3154378874-1875084861-2286133563-1003 - Limited - Enabled) => C:\Users\QBDataServiceUser21

==================== Faulty Device Manager Devices =============

Name: Officejet 4500 G510n-z
Description: Officejet 4500 G510n-z
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: Officejet 4500 G510n-z
Description: Officejet 4500 G510n-z
Class Guid: {4d36e971-e325-11ce-bfc1-08002be10318}
Manufacturer: HP
Service:
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (11/11/2014 06:02:37 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: pcdrcui.exe, version: 6.0.6426.22, time stamp: 0x52cfadb3
Faulting module name: KERNELBASE.dll, version: 6.1.7601.18015, time stamp: 0x50b8479b
Exception code: 0xe0434352
Fault offset: 0x0000000000009e5d
Faulting process id: 0xa9c8
Faulting application start time: 0xpcdrcui.exe0
Faulting application path: pcdrcui.exe1
Faulting module path: pcdrcui.exe2
Report Id: pcdrcui.exe3

Error: (11/11/2014 06:02:28 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: pcdrcui.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: Pcd.DataStore.DatabaseError
Stack:
at wpfview.Program.StartController_HandelAsapiAuthenticationErrors(System.String[])
at wpfview.Program.Main(System.String[])

Error: (11/11/2014 05:06:41 PM) (Source: QuickBooks) (EventID: 4) (User: )
Description: An unexpected error has occured in "QuickBooks Pro Plus 2012":
DBConnPool::HandleConnectionError errorCode:-6069, dbCode:-103 from file:'.\.\src\ConnPool.cpp' at line 1038 from function:'DBMgr::DBConnPool::init'

Error: (11/11/2014 05:06:41 PM) (Source: QuickBooks) (EventID: 4) (User: )
Description: An unexpected error has occured in "QuickBooks Pro Plus 2012":
Connection String:CON=QBConnectionPool-Probe-QB_data_engine_22; ;DBF=C:\Documents and Settings\All Users\Documents\Intuit\QuickBooks\Company Files\Gaffney's Cheap Seats 1.QBW;ENG=QB_data_engine_22;DBN=6c298313e375462cb8a279d8c50ecf34

Error: (11/11/2014 05:06:41 PM) (Source: QuickBooks) (EventID: 4) (User: )
Description: An unexpected error has occured in "QuickBooks Pro Plus 2012":
Connection Error:Invalid user ID or password

Error: (11/11/2014 04:49:55 PM) (Source: QuickBooks) (EventID: 4) (User: )
Description: An unexpected error has occured in "QuickBooks Pro Plus 2012":
DMError Information:-6069Additional Info:An Invalid Id or password was specified.

Error: (11/11/2014 04:49:55 PM) (Source: QuickBooks) (EventID: 4) (User: )
Description: An unexpected error has occured in "QuickBooks Pro Plus 2012":
DBConnPool::HandleConnectionError errorCode:-6069, dbCode:-103 from file:'.\.\src\ConnPool.cpp' at line 1038 from function:'DBMgr::DBConnPool::init'

Error: (11/11/2014 04:49:55 PM) (Source: QuickBooks) (EventID: 4) (User: )
Description: An unexpected error has occured in "QuickBooks Pro Plus 2012":
Connection String:CON=QBConnectionPool-Probe-QB_data_engine_22; ;DBF=C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Rahn's Electric.qbw;ENG=QB_data_engine_22;DBN=b07cd0a6b825403cbbf680344b4c72a6

Error: (11/11/2014 04:49:55 PM) (Source: QuickBooks) (EventID: 4) (User: )
Description: An unexpected error has occured in "QuickBooks Pro Plus 2012":
Connection Error:Invalid user ID or password

Error: (11/11/2014 04:49:35 PM) (Source: QuickBooks) (EventID: 4) (User: )
Description: An unexpected error has occured in "QuickBooks Pro Plus 2012":
DBConnPool::HandleConnectionError errorCode:-6069, dbCode:-103 from file:'.\.\src\ConnPool.cpp' at line 1038 from function:'DBMgr::DBConnPool::init'


System errors:
=============
Error: (11/11/2014 05:37:47 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Dnscache service.

Error: (11/11/2014 05:37:22 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The HomeGroup Provider service depends on the Function Discovery Resource Publication service which failed to start because of the following error:
%%-2147024891

Error: (11/11/2014 05:37:22 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Function Discovery Resource Publication service terminated with the following error:
%%-2147024891

Error: (11/11/2014 03:40:31 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Function Discovery Resource Publication service terminated with the following error:
%%-2147024891

Error: (11/11/2014 03:40:31 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The HomeGroup Provider service depends on the Function Discovery Resource Publication service which failed to start because of the following error:
%%-2147024891

Error: (11/11/2014 00:53:51 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Function Discovery Resource Publication service terminated with the following error:
%%-2147024891

Error: (11/11/2014 00:53:51 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The HomeGroup Provider service depends on the Function Discovery Resource Publication service which failed to start because of the following error:
%%-2147024891

Error: (11/11/2014 00:53:48 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Function Discovery Resource Publication service terminated with the following error:
%%-2147024891

Error: (11/11/2014 00:53:48 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The HomeGroup Provider service depends on the Function Discovery Resource Publication service which failed to start because of the following error:
%%-2147024891

Error: (11/11/2014 00:48:09 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Function Discovery Resource Publication service terminated with the following error:
%%-2147024891


Microsoft Office Sessions:
=========================
Error: (11/11/2014 06:02:37 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: pcdrcui.exe6.0.6426.2252cfadb3KERNELBASE.dll6.1.7601.1801550b8479be04343520000000000009e5da9c801cffe0356499ae7C:\Program Files\My Dell\pcdrcui.exeC:\Windows\system32\KERNELBASE.dlld3a3a084-69f6-11e4-945d-f04da291e1f2

Error: (11/11/2014 06:02:28 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: pcdrcui.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: Pcd.DataStore.DatabaseError
Stack:
at wpfview.Program.StartController_HandelAsapiAuthenticationErrors(System.String[])
at wpfview.Program.Main(System.String[])

Error: (11/11/2014 05:06:41 PM) (Source: QuickBooks) (EventID: 4) (User: )
Description: QuickBooks Pro Plus 2012DBConnPool::HandleConnectionError errorCode:-6069, dbCode:-103 from file:'.\.\src\ConnPool.cpp' at line 1038 from function:'DBMgr::DBConnPool::init'

Error: (11/11/2014 05:06:41 PM) (Source: QuickBooks) (EventID: 4) (User: )
Description: QuickBooks Pro Plus 2012Connection String:CON=QBConnectionPool-Probe-QB_data_engine_22; ;DBF=C:\Documents and Settings\All Users\Documents\Intuit\QuickBooks\Company Files\Gaffney's Cheap Seats 1.QBW;ENG=QB_data_engine_22;DBN=6c298313e375462cb8a279d8c50ecf34

Error: (11/11/2014 05:06:41 PM) (Source: QuickBooks) (EventID: 4) (User: )
Description: QuickBooks Pro Plus 2012Connection Error:Invalid user ID or password

Error: (11/11/2014 04:49:55 PM) (Source: QuickBooks) (EventID: 4) (User: )
Description: QuickBooks Pro Plus 2012DMError Information:-6069Additional Info:An Invalid Id or password was specified.

Error: (11/11/2014 04:49:55 PM) (Source: QuickBooks) (EventID: 4) (User: )
Description: QuickBooks Pro Plus 2012DBConnPool::HandleConnectionError errorCode:-6069, dbCode:-103 from file:'.\.\src\ConnPool.cpp' at line 1038 from function:'DBMgr::DBConnPool::init'

Error: (11/11/2014 04:49:55 PM) (Source: QuickBooks) (EventID: 4) (User: )
Description: QuickBooks Pro Plus 2012Connection String:CON=QBConnectionPool-Probe-QB_data_engine_22; ;DBF=C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Rahn's Electric.qbw;ENG=QB_data_engine_22;DBN=b07cd0a6b825403cbbf680344b4c72a6

Error: (11/11/2014 04:49:55 PM) (Source: QuickBooks) (EventID: 4) (User: )
Description: QuickBooks Pro Plus 2012Connection Error:Invalid user ID or password

Error: (11/11/2014 04:49:35 PM) (Source: QuickBooks) (EventID: 4) (User: )
Description: QuickBooks Pro Plus 2012DBConnPool::HandleConnectionError errorCode:-6069, dbCode:-103 from file:'.\.\src\ConnPool.cpp' at line 1038 from function:'DBMgr::DBConnPool::init'


CodeIntegrity Errors:
===================================
Date: 2014-11-11 08:42:38.405
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\Spybot - Search & Destroy 2\SDHook64.dll because the set of per-page image hashes could not be found on the system.

Date: 2014-11-11 08:34:20.527
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\Spybot - Search & Destroy 2\SDHook64.dll because the set of per-page image hashes could not be found on the system.

Date: 2014-11-10 19:54:00.930
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\Spybot - Search & Destroy 2\SDHook64.dll because the set of per-page image hashes could not be found on the system.

Date: 2014-11-10 10:54:19.358
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\Spybot - Search & Destroy 2\SDHook64.dll because the set of per-page image hashes could not be found on the system.

Date: 2014-11-10 10:29:29.983
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\Spybot - Search & Destroy 2\SDHook64.dll because the set of per-page image hashes could not be found on the system.

Date: 2014-11-10 09:28:50.013
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\Spybot - Search & Destroy 2\SDHook64.dll because the set of per-page image hashes could not be found on the system.

Date: 2014-11-10 09:13:24.943
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\Spybot - Search & Destroy 2\SDHook64.dll because the set of per-page image hashes could not be found on the system.

Date: 2014-11-10 09:02:43.345
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\Spybot - Search & Destroy 2\SDHook64.dll because the set of per-page image hashes could not be found on the system.

Date: 2014-11-09 20:33:57.444
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\Spybot - Search & Destroy 2\SDHook64.dll because the set of per-page image hashes could not be found on the system.

Date: 2014-11-09 20:12:01.115
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\Spybot - Search & Destroy 2\SDHook64.dll because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Processor: Pentium(R) Dual-Core CPU T4500 @ 2.30GHz
Percentage of memory in use: 70%
Total physical RAM: 4058.36 MB
Available physical RAM: 1190.91 MB
Total Pagefile: 8114.91 MB
Available Pagefile: 3800.8 MB
Total Virtual: 8192 MB
Available Virtual: 8191.81 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:451.01 GB) (Free:295.88 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive y: (Recovery) (Fixed) (Total:14.65 GB) (Free:8.21 GB) NTFS ==>[System with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 51ED4EC9)
Partition 1: (Not Active) - (Size=100 MB) - (Type=DE)
Partition 2: (Active) - (Size=14.6 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=451 GB) - (Type=07 NTFS)

==================== End Of Log ============================

aswMBR version 1.0.1.2201 Copyright(c) 2014 AVAST Software
Run date: 2014-11-11 18:51:33
-----------------------------
18:51:33.407 OS Version: Windows x64 6.1.7601 Service Pack 1
18:51:33.407 Number of processors: 2 586 0x170A
18:51:33.407 ComputerName: LAPTOP UserName:
18:51:37.853 Initialize success
18:51:37.994 VM: initialized successfully
18:51:37.994 VM: Intel CPU virtualization not supported
18:52:15.493 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
18:52:15.509 Disk 0 Vendor: WDC_WD50 01.0 Size: 476940MB BusType: 3
18:52:16.180 Disk 0 MBR read successfully
18:52:16.180 Disk 0 MBR scan
18:52:16.180 Disk 0 Windows 7 default MBR code
18:52:16.195 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 100 MB offset 2048
18:52:16.211 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 15000 MB offset 206848
18:52:16.226 Disk 0 Boot: NTFS code=1
18:52:16.258 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 461838 MB offset 30926848
18:52:17.646 Disk 0 scanning C:\Windows\system32\drivers
18:52:32.918 Service scanning
18:53:31.387 Modules scanning
18:53:31.902 Disk 0 trace - called modules:
18:53:31.918 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
18:53:31.933 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004458060]
18:53:31.933 3 CLASSPNP.SYS[fffff88001b7443f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa80040f9050]
18:53:31.933 Disk 0 statistics 95791/0/0 @ 3.51 MB/s
18:53:31.949 Scan finished successfully
18:58:01.055 Disk 0 MBR has been saved successfully to "C:\Users\Melissa\Desktop\MBR.dat"
18:58:01.066 The log file has been saved successfully to "C:\Users\Melissa\Desktop\aswMBR.txt"

Juliet
2014-11-13, 01:53
I see no Antivirus?

Let me tell you what all has been found on your computer.

Absolute_Software
SearchProtect
ZeroAccess?
Poweliks!
cryptowall-ransomware <--can be removed but the encrypted files cannot
CryptoDefense <--can be removed but the encrypted files cannot

http://www.bleepingcomputer.com/virus-removal/cryptowall-ransomware-information

http://www.bleepingcomputer.com/forums/t/527937/cryptodefense-newest-cryptolocker-variant-details-inside/
CryptoDefense - Newest cryptolocker variant - Details inside, extensive reading about this infection.

Your computer is quite infected.

Backdoor Trojan is a category of trojan viruses rather than an individual virus name. These viruses are the most common, the most widespread and the most dangerous. Backdoor Trojans allow the owner(hacker) of the virus remote administrator access to a victims computer. These viruses install, launch and run invisibly without the knowledge of the user. Once installed the Backdoor Trojans can be instructed to send, receive, execute and delete files. Not only can it manipulate physical files on your hard drive but delicate and personal information can he obtained from the victims PC.

You should change your passwords from a clean computer in order to secure your accounts.


Download, extract and run this tool (http://www.bleepstatic.com/fhost/uploads/3/idtool.zip) to identify the ransomware that has infected your computer.

BleepingComputer.com has created a small utility that will find the Registry key created by CryptoWall and then export its list of encrypted files to a text file for you. Please download the ListCWall (http://www.bleepingcomputer.com/download/listcwall/) tool and post its report.

After identifying which version you have please know, I can not remove or help redo the encryption on the folders/files it has effected.

gurleygirl
2014-11-13, 03:09
Thanks Juliet for responding! I'm a little lost when it comes to all this, but I get that I am way infected. I'm guessing that list is everything that is infecting my computer? I bought and installed Spybot Home on Thursday of last week and thought I quarantined everything it found. I didn't start having problems until last week with anything!

Also, could this be related to my home having internet issues as well - kicking us off the internet multiple times a day from several different devices? I will get right on the scans and post them ASAP.

Thanks so much!!

gurleygirl
2014-11-13, 03:14
Ransomware tool

Infection Detection Tool v1.6 - Nathan Scott
--------------------------------------------
Date/Time: 11/12/2014 8:13:03 PM
Operating System: Windows 7
Service Pack: Service Pack 1
Version Number: 6.1
Product Type: Workstation
--------------------------------------------
[Detected Flags]
1.| Possible CryptoWall Flag , HKCU\Software\3E3266E18B8CBFB1449948FE42FBFE40\0244444899BEEFFF
2.| Possible CryptoWall Flag , C:\Users\Melissa\Pictures\DECRYPT_INSTRUCTION.HTML

gurleygirl
2014-11-13, 03:19
ListCWall 1.0.0 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2014 BleepingComputer.com
More Information about the CryptoWall Ransomware can be found here:
http://www.bleepingcomputer.com/forums/t/533715/cryptowall-a-new-ransomware-from-the-creators-of-cryptodefense/

Windows Version: Windows 7 Home Premium Service Pack 1
Program started at: 11/12/2014 08:17:51 PM.


No CryptoWall encrypted file list found.

0 encrypted files found.

Program finished at: 11/12/2014 08:17:51 PM
Execution time: 0 hours(s), 0 minute(s), and 0 seconds(s)

Juliet
2014-11-13, 13:22
Also, could this be related to my home having internet issues as well - kicking us off the internet multiple times a day from several different devices? I will get right on the scans and post them ASAP.

No, I don't think so that should be a problem with your ISP.

If I can have a couple of hours to tend to a sick baby I'll be back with a fix.

Is this version of SpyBot have an antivirus software included?

Juliet
2014-11-13, 13:43
Open notepad. Please copy the contents of the quote box below. To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)



start
CloseProcesses:
HKLM\...D6A79037F57F\InprocServer32: [Default-fastprox] C:\$Recycle.Bin\S-1-5-18\$3b99f81f31d5dbab1bcf87d0107a285a\o. ATTENTION! ====> ZeroAccess?
HKU\S-1-5-21-3154378874-1875084861-2286133563-1001\...\MountPoints2: {6e8cc5bf-7b93-11e2-bb1d-f04da291e1f2} - E:\TLBootstrap_WPP.exe
HKU\S-1-5-21-3154378874-1875084861-2286133563-1001\...\MountPoints2: {8b9c99fc-401b-11e1-9a06-061bb1456f9c} - E:\LaunchU3.exe
HKU\S-1-5-21-3154378874-1875084861-2286133563-1001\...409d6c4515e9\InprocServer32: [Default-shell32] C:\$Recycle.Bin\S-1-5-21-3154378874-1875084861-2286133563-1001\$3b99f81f31d5dbab1bcf87d0107a285a\n. ATTENTION! ====> ZeroAccess?
HKU\S-1-5-21-3154378874-1875084861-2286133563-1001\...A8F59079A8D5}\localserver32: rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf>ktds (the data entry has 239 more characters). <==== Poweliks!
HKU\S-1-5-18\...\Run: [3e3266] => C:\3e3266e\3e3266e.exe [274500 2014-11-11] ( )
HKU\S-1-5-18\...\Run: [3e3266e] => C:\Users\Melissa\AppData\Roaming\3e3266e.exe [274500 2014-11-11] ( )
AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll => C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll File Not Found
Startup: C:\Users\Melissa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\3e3266e.exe ( )
SearchScopes: HKCU - DefaultScope {114DB5FA-0AFB-BB92-A75B-F44D3CE875CD} URL = http://www.trovi.com/Results.aspx?gd=&ctid=CT3330390&octid=EB_ORIGINAL_CTID&ISID=M3D70D438-989F-4ECB-BA82-CCA300550E22&SearchSource=58&CUI=&UM=6&UP=SPD3324CD6-0783-4263-9C08-267860FCEFE1&q={searchTerms}&SSPV=
SearchScopes: HKCU - {114DB5FA-0AFB-BB92-A75B-F44D3CE875CD} URL = http://www.trovi.com/Results.aspx?gd=&ctid=CT3330390&octid=EB_ORIGINAL_CTID&ISID=M3D70D438-989F-4ECB-BA82-CCA300550E22&SearchSource=58&CUI=&UM=6&UP=SPD3324CD6-0783-4263-9C08-267860FCEFE1&q={searchTerms}&SSPV=
SearchScopes: HKCU - {4989EE16-E9A9-4D8E-B14C-7303338FE56F} URL = http://www.flickr.com/search/?q={searchTerms}
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
SearchScopes: HKCU - {B298DA9B-6161-4E52-A5E0-C37F9266DD75} URL = http://delicious.com/search?p={searchTerms}
Handler: intu-help-qb5 - {867FCB77-9823-4cd6-8210-D85F968D466F} - No File
Handler: intu-help-qb6 - {6898B29B-BF49-43cb-A0B1-D0B9496AF491} - No File
Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - No File
Handler-x32: intu-help-qb6 - {6898B29B-BF49-43cb-A0B1-D0B9496AF491} - No File
CHR HKLM-x32\...\Chrome\Extension: [lmmhpfbhngkongobaoibpmnijjokabmj] - C:\Program Files (x86)\Windstream\Service Agent\ChromeExtension.crx [2012-03-26]
S2 CltMngSvc; C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe [X]
2014-11-11 13:52 - 2014-11-11 13:52 - 00008538 _____ () C:\Users\Melissa\Downloads\DECRYPT_INSTRUCTION.HTML
2014-11-11 13:52 - 2014-11-11 13:52 - 00004212 _____ () C:\Users\Melissa\Downloads\DECRYPT_INSTRUCTION.TXT
2014-11-11 13:52 - 2014-11-11 13:52 - 00000268 _____ () C:\Users\Melissa\Downloads\DECRYPT_INSTRUCTION.URL
2014-11-11 13:51 - 2014-11-11 13:51 - 00008538 _____ () C:\Users\Melissa\Documents\DECRYPT_INSTRUCTION.HTML
2014-11-11 13:51 - 2014-11-11 13:51 - 00004212 _____ () C:\Users\Melissa\Documents\DECRYPT_INSTRUCTION.TXT
2014-11-11 13:51 - 2014-11-11 13:51 - 00000268 _____ () C:\Users\Melissa\Documents\DECRYPT_INSTRUCTION.URL
2014-11-11 13:33 - 2014-11-11 13:33 - 00008538 _____ () C:\Users\Melissa\AppData\Roaming\DECRYPT_INSTRUCTION.HTML
2014-11-11 13:33 - 2014-11-11 13:33 - 00008538 _____ () C:\Users\Melissa\AppData\DECRYPT_INSTRUCTION.HTML
2014-11-11 13:33 - 2014-11-11 13:33 - 00004212 _____ () C:\Users\Melissa\AppData\Roaming\DECRYPT_INSTRUCTION.TXT
2014-11-11 13:33 - 2014-11-11 13:33 - 00004212 _____ () C:\Users\Melissa\AppData\DECRYPT_INSTRUCTION.TXT
2014-11-11 13:33 - 2014-11-11 13:33 - 00000268 _____ () C:\Users\Melissa\AppData\Roaming\DECRYPT_INSTRUCTION.URL
2014-11-11 13:33 - 2014-11-11 13:33 - 00000268 _____ () C:\Users\Melissa\AppData\DECRYPT_INSTRUCTION.URL
2014-11-11 13:31 - 2014-11-11 13:31 - 00008538 _____ () C:\Users\Melissa\AppData\Local\DECRYPT_INSTRUCTION.HTML
2014-11-11 13:31 - 2014-11-11 13:31 - 00004212 _____ () C:\Users\Melissa\AppData\Local\DECRYPT_INSTRUCTION.TXT
2014-11-11 13:31 - 2014-11-11 13:31 - 00000268 _____ () C:\Users\Melissa\AppData\Local\DECRYPT_INSTRUCTION.URL
2014-11-11 13:23 - 2014-11-11 13:23 - 00008538 _____ () C:\ProgramData\DECRYPT_INSTRUCTION.HTML
2014-11-11 13:23 - 2014-11-11 13:23 - 00004212 _____ () C:\ProgramData\DECRYPT_INSTRUCTION.TXT
2014-11-11 13:23 - 2014-11-11 13:23 - 00000268 _____ () C:\ProgramData\DECRYPT_INSTRUCTION.URL
2014-11-11 13:03 - 2014-11-11 13:03 - 00274500 _____ ( ) C:\Users\Melissa\AppData\Roaming\3e3266e.exe
2014-11-11 13:03 - 2014-11-11 13:03 - 00000000 ___HD () C:\3e3266e
2014-11-07 18:38 - 2014-11-08 07:41 - 00000000 ____D () C:\Users\Melissa\AppData\Local\SearchProtect
2014-11-07 18:38 - 2014-11-07 22:27 - 00000000 ____D () C:\Program Files (x86)\SearchProtect
ZeroAccess:
C:\$Recycle.Bin\S-1-5-21-3154378874-1875084861-2286133563-1001\$3b99f81f31d5dbab1bcf87d0107a285a
ZeroAccess:
C:\$Recycle.Bin\S-1-5-18\$3b99f81f31d5dbab1bcf87d0107a285a
C:\Users\Melissa\AppData\Local\Temp\bs.exe
CustomCLSID: HKU\S-1-5-21-3154378874-1875084861-2286133563-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Melissa\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-3154378874-1875084861-2286133563-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Melissa\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-3154378874-1875084861-2286133563-1001_Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\localserver32 -> rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf>ktds (the data entry has 247 more characters). <==== Poweliks?
CustomCLSID: HKU\S-1-5-21-3154378874-1875084861-2286133563-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Melissa\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-3154378874-1875084861-2286133563-1001_Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InprocServer32 -> C:\$Recycle.Bin ()
DeleteKey:HKCU\Software\3E3266E18B8CBFB1449948FE42FBFE40\0244444899BEEFFF}
EmptyTemp:
Hosts:
CMD: ipconfig /flushdns
CMD: netsh winsock reset all
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
End


Open FRST/FRST64 and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

~~~~~~~~~~~~~~~~~

-AdwCleaner-by Xplode

Click on this link to download : ADWCleaner (http://www.bleepingcomputer.com/download/adwcleaner/)
Click on ONE of the Two Blue Download Now buttons That have a blue arrow beside them and save it to your desktop.

Do not click on any links in the top Advertisment.


http://thespykiller.co.uk/files/adwcleaner_download.png

Close all open programs and internet browsers.
Double click on AdwCleaner.exe to run the tool.
Click on Scan.
After the scan is complete click on "Clean"
Confirm each time with Ok.
Your computer will be rebooted automatically. A text file will open after the restart.
Please post the content of that logfile with your next answer.
You can find the logfile at C:\AdwCleaner[S1].txt as well.
NOTE: If you see AVG Secure Search being targeted for deletion, Here's Why (http://www.im-infected.com/hijacker/isearch-avg-comsearch-hijacker.html) and Here (http://nojesusnopeas.blogspot.com/2012/08/sorry-but-avg-secure-search-is-malware.html). You can always Reinstall (http://www.avg.com/us-en/secure-search) it.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


http://imageshack.us/a/img841/7292/thisisujrt.gif
Please download Junkware Removal Tool (http://www.bleepingcomputer.com/download/junkware-removal-tool/) to your desktop.

Shut down your protection software now to avoid potential conflicts.
Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
The tool will open and start scanning your system.
Please be patient as this can take a while to complete depending on your system's specifications.
On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
Post the contents of JRT.txt into your next message.

please post
Fixlog.txt
C:\AdwCleaner.txt
JRT.txt

gurleygirl
2014-11-13, 19:17
Juliet, I'm waiting for FRST to finish "fixing." It's been running for over 2 hours. Is this normal? Want to make sure I'm doing every accurately.

Thanks!

Juliet
2014-11-13, 21:56
Open task manager, right click at the bottom on the tool bar
search FRST.exe, right click on it and select end process.

I might should had asked you go into safe mode
http://www.bleepingcomputer.com/tutorials/how-to-start-windows-in-safe-mode/
scroll to windows 7

save the fixlist.txt and run from safe mode.

gurleygirl
2014-11-13, 23:25
My version of Spybot should have included antivirus...in fact it says live protection: on, Internet protection: full. So how did this ransomware get through?

I hope below is my fix log - let me know if I need to run it again. - Melissa

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 10-11-2014
Ran by Melissa at 2014-11-13 08:59:40 Run:1
Running from C:\Users\Melissa\Desktop
Loaded Profile: Melissa (Available profiles: Melissa & QBDataServiceUser21)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
start
CloseProcesses:
HKLM\...D6A79037F57F\InprocServer32: [Default-fastprox] C:\$Recycle.Bin\S-1-5-18\$3b99f81f31d5dbab1bcf87d0107a285a\o. ATTENTION! ====> ZeroAccess?
HKU\S-1-5-21-3154378874-1875084861-2286133563-1001\...\MountPoints2: {6e8cc5bf-7b93-11e2-bb1d-f04da291e1f2} - E:\TLBootstrap_WPP.exe
HKU\S-1-5-21-3154378874-1875084861-2286133563-1001\...\MountPoints2: {8b9c99fc-401b-11e1-9a06-061bb1456f9c} - E:\LaunchU3.exe
HKU\S-1-5-21-3154378874-1875084861-2286133563-1001\...409d6c4515e9\InprocServer32: [Default-shell32] C:\$Recycle.Bin\S-1-5-21-3154378874-1875084861-2286133563-1001\$3b99f81f31d5dbab1bcf87d0107a285a\n. ATTENTION! ====> ZeroAccess?
HKU\S-1-5-21-3154378874-1875084861-2286133563-1001\...A8F59079A8D5}\localserver32: rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf>ktds (the data entry has 239 more characters). <==== Poweliks!
HKU\S-1-5-18\...\Run: [3e3266] => C:\3e3266e\3e3266e.exe [274500 2014-11-11] ( )
HKU\S-1-5-18\...\Run: [3e3266e] => C:\Users\Melissa\AppData\Roaming\3e3266e.exe [274500 2014-11-11] ( )
AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll => C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll File Not Found
Startup: C:\Users\Melissa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\3e3266e.exe ( )
SearchScopes: HKCU - DefaultScope {114DB5FA-0AFB-BB92-A75B-F44D3CE875CD} URL = http://www.trovi.com/Results.aspx?gd=&ctid=CT3330390&octid=EB_ORIGINAL_CTID&ISID=M3D70D438-989F-4ECB-BA82-CCA300550E22&SearchSource=58&CUI=&UM=6&UP=SPD3324CD6-0783-4263-9C08-267860FCEFE1&q={searchTerms}&SSPV=
SearchScopes: HKCU - {114DB5FA-0AFB-BB92-A75B-F44D3CE875CD} URL = http://www.trovi.com/Results.aspx?gd=&ctid=CT3330390&octid=EB_ORIGINAL_CTID&ISID=M3D70D438-989F-4ECB-BA82-CCA300550E22&SearchSource=58&CUI=&UM=6&UP=SPD3324CD6-0783-4263-9C08-267860FCEFE1&q={searchTerms}&SSPV=
SearchScopes: HKCU - {4989EE16-E9A9-4D8E-B14C-7303338FE56F} URL = http://www.flickr.com/search/?q={searchTerms}
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
SearchScopes: HKCU - {B298DA9B-6161-4E52-A5E0-C37F9266DD75} URL = http://delicious.com/search?p={searchTerms}
Handler: intu-help-qb5 - {867FCB77-9823-4cd6-8210-D85F968D466F} - No File
Handler: intu-help-qb6 - {6898B29B-BF49-43cb-A0B1-D0B9496AF491} - No File
Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - No File
Handler-x32: intu-help-qb6 - {6898B29B-BF49-43cb-A0B1-D0B9496AF491} - No File
CHR HKLM-x32\...\Chrome\Extension: [lmmhpfbhngkongobaoibpmnijjokabmj] - C:\Program Files (x86)\Windstream\Service Agent\ChromeExtension.crx [2012-03-26]
S2 CltMngSvc; C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe [X]
2014-11-11 13:52 - 2014-11-11 13:52 - 00008538 _____ () C:\Users\Melissa\Downloads\DECRYPT_INSTRUCTION.HTML
2014-11-11 13:52 - 2014-11-11 13:52 - 00004212 _____ () C:\Users\Melissa\Downloads\DECRYPT_INSTRUCTION.TXT
2014-11-11 13:52 - 2014-11-11 13:52 - 00000268 _____ () C:\Users\Melissa\Downloads\DECRYPT_INSTRUCTION.URL
2014-11-11 13:51 - 2014-11-11 13:51 - 00008538 _____ () C:\Users\Melissa\Documents\DECRYPT_INSTRUCTION.HTML
2014-11-11 13:51 - 2014-11-11 13:51 - 00004212 _____ () C:\Users\Melissa\Documents\DECRYPT_INSTRUCTION.TXT
2014-11-11 13:51 - 2014-11-11 13:51 - 00000268 _____ () C:\Users\Melissa\Documents\DECRYPT_INSTRUCTION.URL
2014-11-11 13:33 - 2014-11-11 13:33 - 00008538 _____ () C:\Users\Melissa\AppData\Roaming\DECRYPT_INSTRUCTION.HTML
2014-11-11 13:33 - 2014-11-11 13:33 - 00008538 _____ () C:\Users\Melissa\AppData\DECRYPT_INSTRUCTION.HTML
2014-11-11 13:33 - 2014-11-11 13:33 - 00004212 _____ () C:\Users\Melissa\AppData\Roaming\DECRYPT_INSTRUCTION.TXT
2014-11-11 13:33 - 2014-11-11 13:33 - 00004212 _____ () C:\Users\Melissa\AppData\DECRYPT_INSTRUCTION.TXT
2014-11-11 13:33 - 2014-11-11 13:33 - 00000268 _____ () C:\Users\Melissa\AppData\Roaming\DECRYPT_INSTRUCTION.URL
2014-11-11 13:33 - 2014-11-11 13:33 - 00000268 _____ () C:\Users\Melissa\AppData\DECRYPT_INSTRUCTION.URL
2014-11-11 13:31 - 2014-11-11 13:31 - 00008538 _____ () C:\Users\Melissa\AppData\Local\DECRYPT_INSTRUCTION.HTML
2014-11-11 13:31 - 2014-11-11 13:31 - 00004212 _____ () C:\Users\Melissa\AppData\Local\DECRYPT_INSTRUCTION.TXT
2014-11-11 13:31 - 2014-11-11 13:31 - 00000268 _____ () C:\Users\Melissa\AppData\Local\DECRYPT_INSTRUCTION.URL
2014-11-11 13:23 - 2014-11-11 13:23 - 00008538 _____ () C:\ProgramData\DECRYPT_INSTRUCTION.HTML
2014-11-11 13:23 - 2014-11-11 13:23 - 00004212 _____ () C:\ProgramData\DECRYPT_INSTRUCTION.TXT
2014-11-11 13:23 - 2014-11-11 13:23 - 00000268 _____ () C:\ProgramData\DECRYPT_INSTRUCTION.URL
2014-11-11 13:03 - 2014-11-11 13:03 - 00274500 _____ ( ) C:\Users\Melissa\AppData\Roaming\3e3266e.exe
2014-11-11 13:03 - 2014-11-11 13:03 - 00000000 ___HD () C:\3e3266e
2014-11-07 18:38 - 2014-11-08 07:41 - 00000000 ____D () C:\Users\Melissa\AppData\Local\SearchProtect
2014-11-07 18:38 - 2014-11-07 22:27 - 00000000 ____D () C:\Program Files (x86)\SearchProtect
ZeroAccess:
C:\$Recycle.Bin\S-1-5-21-3154378874-1875084861-2286133563-1001\$3b99f81f31d5dbab1bcf87d0107a285a
ZeroAccess:
C:\$Recycle.Bin\S-1-5-18\$3b99f81f31d5dbab1bcf87d0107a285a
C:\Users\Melissa\AppData\Local\Temp\bs.exe
CustomCLSID: HKU\S-1-5-21-3154378874-1875084861-2286133563-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Melissa\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-3154378874-1875084861-2286133563-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Melissa\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-3154378874-1875084861-2286133563-1001_Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\localserver32 -> rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf>ktds (the data entry has 247 more characters). <==== Poweliks?
CustomCLSID: HKU\S-1-5-21-3154378874-1875084861-2286133563-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Melissa\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-3154378874-1875084861-2286133563-1001_Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InprocServer32 -> C:\$Recycle.Bin ()
DeleteKey:HKCU\Software\3E3266E18B8CBFB1449948FE42FBFE40\0244444899BEEFFF}
EmptyTemp:
Hosts:
CMD: ipconfig /flushdns
CMD: netsh winsock reset all
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
End
*****************

Processes closed successfully.
HKLM\Software\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InprocServer32\\Default => Value was restored successfully.
"HKU\S-1-5-21-3154378874-1875084861-2286133563-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6e8cc5bf-7b93-11e2-bb1d-f04da291e1f2}" => Key deleted successfully.
"HKCR\CLSID\{6e8cc5bf-7b93-11e2-bb1d-f04da291e1f2}" => Key not found.
"HKU\S-1-5-21-3154378874-1875084861-2286133563-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8b9c99fc-401b-11e1-9a06-061bb1456f9c}" => Key deleted successfully.
"HKCR\CLSID\{8b9c99fc-401b-11e1-9a06-061bb1456f9c}" => Key not found.
"HKU\S-1-5-21-3154378874-1875084861-2286133563-1001\Software\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}" => Key deleted successfully.
"HKU\S-1-5-21-3154378874-1875084861-2286133563-1001\Software\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\localserver32" => Key Deleted Successfully.
"HKU\S-1-5-21-3154378874-1875084861-2286133563-1001\Software\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}" => Key deleted successfully.
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run\\3e3266 => Value not found.
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run\\3e3266e => Value not found.
"C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll" => Value Data removed successfully.
C:\Users\Melissa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\3e3266e.exe not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{114DB5FA-0AFB-BB92-A75B-F44D3CE875CD}" => Key deleted successfully.
"HKCR\CLSID\{114DB5FA-0AFB-BB92-A75B-F44D3CE875CD}" => Key not found.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{4989EE16-E9A9-4D8E-B14C-7303338FE56F}" => Key deleted successfully.
"HKCR\CLSID\{4989EE16-E9A9-4D8E-B14C-7303338FE56F}" => Key not found.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" => Key deleted successfully.
"HKCR\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" => Key not found.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B298DA9B-6161-4E52-A5E0-C37F9266DD75}" => Key deleted successfully.
"HKCR\CLSID\{B298DA9B-6161-4E52-A5E0-C37F9266DD75}" => Key not found.
"HKCR\PROTOCOLS\Handler\intu-help-qb5" => Key deleted successfully.
"HKCR\CLSID\{867FCB77-9823-4cd6-8210-D85F968D466F}" => Key not found.
"HKCR\PROTOCOLS\Handler\intu-help-qb6" => Key deleted successfully.
"HKCR\CLSID\{6898B29B-BF49-43cb-A0B1-D0B9496AF491}" => Key not found.
"HKCR\PROTOCOLS\Handler\qbwc" => Key deleted successfully.
"HKCR\CLSID\{FC598A64-626C-4447-85B8-53150405FD57}" => Key not found.
"HKCR\Wow6432Node\PROTOCOLS\Handler\intu-help-qb6" => Key not found.
"HKCR\Wow6432Node\CLSID\{6898B29B-BF49-43cb-A0B1-D0B9496AF491}" => Key not found.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\lmmhpfbhngkongobaoibpmnijjokabmj" => Key deleted successfully.
C:\Program Files (x86)\Windstream\Service Agent\ChromeExtension.crx => Moved successfully.
CltMngSvc => Service deleted successfully.
C:\Users\Melissa\Downloads\DECRYPT_INSTRUCTION.HTML => Moved successfully.
C:\Users\Melissa\Downloads\DECRYPT_INSTRUCTION.TXT => Moved successfully.
C:\Users\Melissa\Downloads\DECRYPT_INSTRUCTION.URL => Moved successfully.
C:\Users\Melissa\Documents\DECRYPT_INSTRUCTION.HTML => Moved successfully.
C:\Users\Melissa\Documents\DECRYPT_INSTRUCTION.TXT => Moved successfully.
C:\Users\Melissa\Documents\DECRYPT_INSTRUCTION.URL => Moved successfully.
C:\Users\Melissa\AppData\Roaming\DECRYPT_INSTRUCTION.HTML => Moved successfully.
C:\Users\Melissa\AppData\DECRYPT_INSTRUCTION.HTML => Moved successfully.
C:\Users\Melissa\AppData\Roaming\DECRYPT_INSTRUCTION.TXT => Moved successfully.
C:\Users\Melissa\AppData\DECRYPT_INSTRUCTION.TXT => Moved successfully.
C:\Users\Melissa\AppData\Roaming\DECRYPT_INSTRUCTION.URL => Moved successfully.
C:\Users\Melissa\AppData\DECRYPT_INSTRUCTION.URL => Moved successfully.
C:\Users\Melissa\AppData\Local\DECRYPT_INSTRUCTION.HTML => Moved successfully.
C:\Users\Melissa\AppData\Local\DECRYPT_INSTRUCTION.TXT => Moved successfully.
C:\Users\Melissa\AppData\Local\DECRYPT_INSTRUCTION.URL => Moved successfully.
C:\ProgramData\DECRYPT_INSTRUCTION.HTML => Moved successfully.
C:\ProgramData\DECRYPT_INSTRUCTION.TXT => Moved successfully.
C:\ProgramData\DECRYPT_INSTRUCTION.URL => Moved successfully.
"C:\Users\Melissa\AppData\Roaming\3e3266e.exe" => File/Directory not found.
"C:\3e3266e" => File/Directory not found.
C:\Users\Melissa\AppData\Local\SearchProtect => Moved successfully.
C:\Program Files (x86)\SearchProtect => Moved successfully.
ZeroAccess: => Error: No automatic fix found for this entry.
C:\$Recycle.Bin\S-1-5-21-3154378874-1875084861-2286133563-1001\$3b99f81f31d5dbab1bcf87d0107a285a => Moved successfully.
ZeroAccess: => Error: No automatic fix found for this entry.
C:\$Recycle.Bin\S-1-5-18\$3b99f81f31d5dbab1bcf87d0107a285a => Moved successfully.
C:\Users\Melissa\AppData\Local\Temp\bs.exe => Moved successfully.
"HKU\S-1-5-21-3154378874-1875084861-2286133563-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}" => Key deleted successfully.
"HKU\S-1-5-21-3154378874-1875084861-2286133563-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}" => Key deleted successfully.
"HKU\S-1-5-21-3154378874-1875084861-2286133563-1001_Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}" => Key not found.
"HKU\S-1-5-21-3154378874-1875084861-2286133563-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}" => Key deleted successfully.
"HKU\S-1-5-21-3154378874-1875084861-2286133563-1001_Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}" => Key not found.
HKCU\Software\3E3266E18B8CBFB1449948FE42FBFE40\0244444899BEEFFF} => Key not found.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.

========= ipconfig /flushdns =========


Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========= End of CMD: =========


========= netsh winsock reset all =========


Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.


========= End of CMD: =========


========= netsh int ipv4 reset =========

Reseting Global, OK!
Reseting Interface, OK!
Restart the computer to complete this action.


========= End of CMD: =========


========= netsh int ipv6 reset =========

Reseting Interface, OK!
Restart the computer to complete this action.


========= End of CMD: =========

Juliet
2014-11-13, 23:35
My version of Spybot should have included antivirus...in fact it says live protection: on, Internet protection: full. So how did this ransomware get through?
How long was the computer without an antivirus and, no antivirus can protect against user's clicking on email attachments or open exploits for out of date applications.

Do you have these logs?
C:\AdwCleaner.txt
JRT.txt

gurleygirl
2014-11-13, 23:52
I thought I was protected, but apparently not. An IT friend suggested Spybot. I purchased and installed on 11/6, but the ransonware didn't "Activate" (maybe that isn't the right word) until 11/11.

Please note I have to change my Internet Security settings back to default everytime I download one of the programs you ask me to run. Also, when I finished with the adware removal just now the computer rebooted. After turning back on, it immediately opened up IE and went to the ransomware payment page. Thought I would mention those. Here's the adware log...working on the last right now.

# AdwCleaner v4.101 - Report created 13/11/2014 at 16:31:58
# Updated 09/11/2014 by Xplode
# Database : 2014-11-12.2 [Live]
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Melissa - LAPTOP
# Running from : C:\Users\Melissa\Desktop\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****

[#] Service Deleted : CltMngSvc
Service Deleted : SPPD

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\374311380
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Browser Enhancements
Folder Deleted : C:\Program Files (x86)\Browser Enhancements
Folder Deleted : C:\Users\Melissa\AppData\LocalLow\HPAppData
Folder Deleted : C:\Users\Melissa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage

***** [ Scheduled Tasks ] *****

Task Deleted : LaunchSignup

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF780F87-FF2B-4DF8-92D0-73DB16A1543A}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EF99BD32-C1FB-11D2-892F-0090271D4F88}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{EF99BD32-C1FB-11D2-892F-0090271D4F88}]
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKCU\Software\UpdateFiles
Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ask.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\delta.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\deltavacations.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\durable-tech.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\sweetadditions.net
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.sweetadditions.net

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16428


-\\ Google Chrome v

[C:\Users\Melissa\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.aol.com/aol/search?query={searchTerms}
[C:\Users\Melissa\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
[C:\Users\Melissa\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3330390&octid=EB_ORIGINAL_CTID&ISID=M3D70D438-989F-4ECB-BA82-CCA300550E22&SearchSource=58&CUI=&UM=6&UP=SPD3324CD6-0783-4263-9C08-267860FCEFE1&q={searchTerms}&SSPV=
[C:\Users\Melissa\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3330390&octid=EB_ORIGINAL_CTID&ISID=M3D70D438-989F-4ECB-BA82-CCA300550E22&SearchSource=58&CUI=&UM=6&UP=SPD3324CD6-0783-4263-9C08-267860FCEFE1&q={searchTerms}&SSPV=
[C:\Users\Melissa\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Startup_URLs] : hxxp://www.trovi.com/?gd=&ctid=CT3330390&octid=EB_ORIGINAL_CTID&ISID=M3D70D438-989F-4ECB-BA82-CCA300550E22&SearchSource=55&CUI=&UM=6&UP=SPD3324CD6-0783-4263-9C08-267860FCEFE1&SSPV=
[C:\Users\Melissa\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Startup_URLs] : hxxp://www.trovi.com/?gd=&ctid=CT3330390&octid=EB_ORIGINAL_CTID&ISID=M3D70D438-989F-4ECB-BA82-CCA300550E22&SearchSource=55&CUI=&UM=6&UP=SPD3324CD6-0783-4263-9C08-267860FCEFE1&SSPV=

*************************

AdwCleaner[R0].txt - [5103 octets] - [13/11/2014 16:29:41]
AdwCleaner[S0].txt - [5004 octets] - [13/11/2014 16:31:58]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5064 octets] ##########

gurleygirl
2014-11-14, 00:04
Youre going to think I'm a moron, but I have no idea how to disable Spybot before I run the last scan! Instruction please!

Juliet
2014-11-14, 00:12
http://www.safer-networking.org/shop/
Can you tell me which version of Spybot you installed?


I thought I was protected, but apparently not. An IT friend suggested Spybot. I purchased and installed on 11/6, but the ransonware didn't "Activate" (maybe that isn't the right word) until 11/11.
You were already infected by that time. Looking back over the logs, seriously.

You could disable or uninstall Live protection.
If you open Spybot start center,checkmark advanced mode,click Settings(saying Yes to UAC,if applicable),click the Live Protection tab,then you click Show Live Protection Advanced Control,you can see two options to deactivate Live Protection,or uninstall Live Protection.
That deactivates or uninstalls(depending on which you pick)real-time protection,

The system scan will still search using antivirus definitions when you scan after disabling Live Protection,but there isn't much chance of conflict that way,so that should be okay.


Also, when I finished with the adware removal just now the computer rebooted. After turning back on, it immediately opened up IE and went to the ransomware payment page. Thought I would mention those.
We can still run other scans and attempt to remove what we can but, early on I mentioned I cannot remove the damage done by the CryptoWall (variant) done to your machine.
cryptowall-ransomware <--can be removed but the encrypted files cannot
CryptoDefense <--can be removed but the encrypted files cannot

http://www.bleepingcomputer.com/virus-removal/cryptowall-ransomware-information

http://www.bleepingcomputer.com/forums/t/527937/cryptodefense-newest-cryptolocker-variant-details-inside/
CryptoDefense - Newest cryptolocker variant - Details inside, extensive reading about this infection.

gurleygirl
2014-11-14, 18:41
I have Spybot + Antivirus Home Edition.

Also, let the JRT.exe run overnight but woke up this morning to it being still open. Restarted computer and am running again. No log was posted so I'm not sure what happened! Will post ASAP!

gurleygirl
2014-11-14, 18:52
So, now what to venture onto? Thanks again for all your help!

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.3.7 (11.08.2014:1)
OS: Windows 7 Home Premium x64
Ran by Melissa on Fri 11/14/2014 at 11:38:32.48
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Fri 11/14/2014 at 11:49:24.43
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Juliet
2014-11-14, 20:55
Please download Malwarebytes AntiRootkit (http://www.malwarebytes.org/products/mbar/) and save it to your desktop.

Full instructions how to use MBAR (http://www.bleepingcomputer.com/virus-removal/how-to-use-malwarebytes-anti-rootkit)
Please note: This is a beta version so please be sure to read the disclaimer and note of it.

• Unzip/unrar MBAR in a folder to your Desktop and MBAM shall run ...

• Click on Next > then on Update button to download fresh definitions.
https://dl.dropboxusercontent.com/u/73555776/mbar_update.JPG

• When database updates click Next

• In the following window ensure "Targets" scan for Drivers; Sectors; System are ticked. Then select "Scan button"
https://dl.dropboxusercontent.com/u/73555776/mbarscan.JPG

• If an infection/s are found ensure "Create Restore Point" is checked, then select the "Cleanup Button" to remove threats.
Or if you are sure any entries should be kept, just untick them. A list of infected files will be listed.


• The Clean up procedure will be Scheduled for process.
• When complete pop-up will show you. Select the Yes button and the system should re-boot to complete the cleaning process.

>> Please attach the two following logs from the mbar folder:

system-log.txt
and
mbar-log-year-month-day (hour-minute-second).txt.

~~~~~~~~~~~~~~~~~~~~`


What we can do now is run an online scan with Eset, for the time being it is our most trusted scanner.
Most reliable and thorough.
The settings I suggest will show us items located in quarantine folders so don't be alarmed with this, also, in case of a false positive I ask that you not allow it to delete what it does find.
This scanner can take quite a bit of time to run, depending of course how full your computer is.


Go here (http://www.eset.com/us/online-scanner/) to run an online scannner from ESET. Windows Vista/Windows 7/Windows 8 users will need to right click on their Internet Explorer shortcut, and select Run as Administrator

Note:
For browsers other than Internet Explorer, you will be prompted to download and install esetsmartinstaller_enu.exe. Click on the link and save the file to a convenient location. Double click on it to install and a new window will open. Follow the prompts.
Turn off the real time scanner of any existing antivirus program while performing the online scan. Here's how (http://www.techsupportforum.com/forums/f50/how-to-disable-your-security-applications-490111.html).
Click the blue Run ESET Online Scanner button
Tick the box next to YES, I accept the Terms of Use.
Click Start
When asked, allow the program to install the "OnlineScanner.cab" activex control by clicking the Install button
Once the activex control is installed, on the next screen click on Enable detection of potentially unwanted applications
Click on Advanced Settings
Make sure that the option Remove found threats is unticked.
Ensure these options are ticked

Scan archives
Scan for potentially unsafe applications
Enable Anti-Stealth technology


Click [b]Start[/b
Wait for the scan to finish
When the scan is done, if it shows a screen that says "Threats found!", then click "List of found threats", and then click "Export to text file..."
Save that text file on your desktop. Copy and paste the contents of that log as a reply to this topic.
Close the ESET online scan.


*************************************

Please post
mbar logs
Eset logs

How is your computer now?

gurleygirl
2014-11-14, 23:14
Malwarebytes Anti-Rootkit BETA 1.08.1.1001
www.malwarebytes.org

Database version: v2014.11.14.08

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16428
Melissa :: LAPTOP [administrator]

11/14/2014 3:22:56 PM
mbar-log-2014-11-14 (15-22-56).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 374966
Time elapsed: 25 minute(s), 52 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 7
C:\Users\Melissa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DECRYPT_INSTRUCTION.HTML (CryptoWall.Trace) -> Delete on reboot. [8e22a7946d0fdc5a83cf261b50b3c43c]
C:\Users\Melissa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DECRYPT_INSTRUCTION.TXT (CryptoWall.Trace) -> Delete on reboot. [b4fc89b2e29ac175ce841e238e75cf31]
C:\Users\Melissa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DECRYPT_INSTRUCTION.URL (CryptoWall.Trace) -> Delete on reboot. [b5fb52e9067686b02032172a9a695ba5]
C:\Users\Melissa\Desktop\DECRYPT_INSTRUCTION.HTML (CryptoWall.Trace) -> Delete on reboot. [2e8253e8cab2af87e2711829ce35847c]
C:\Users\Melissa\Desktop\DECRYPT_INSTRUCTION.TXT (CryptoWall.Trace) -> Delete on reboot. [eac6a5961d5fa98d57fcd17041c21ce4]
C:\Users\Melissa\Desktop\DECRYPT_INSTRUCTION.URL (CryptoWall.Trace) -> Delete on reboot. [c6ea1823f88460d65df6023f4db6e719]
C:\Users\Melissa\AppData\Roaming\Microsoft\stor.cfg (Malware.Trace) -> Delete on reboot. [87297fbc136980b65264138e7c871de3]

Physical Sectors Detected: 0
(No malicious items detected)

(end)

---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.08.1.1001

(c) Malwarebytes Corporation 2011-2012

OS version: 6.1.7601 Windows 7 Service Pack 1 x64

Account is Administrative

Internet Explorer version: 11.0.9600.16428

Java version: 1.6.0_35

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 2.294000 GHz
Memory total: 4255502336, free: 2301657088

Downloaded database version: v2014.11.14.08
Downloaded database version: v2014.11.12.01
=======================================
Initializing...
------------ Kernel report ------------
11/14/2014 15:22:39
------------ Loaded modules -----------
\SystemRoot\system32\ntoskrnl.exe
\SystemRoot\system32\hal.dll
\SystemRoot\system32\kdcom.dll
\SystemRoot\system32\mcupdate_GenuineIntel.dll
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\CLFS.SYS
\SystemRoot\system32\CI.dll
\SystemRoot\system32\drivers\Wdf01000.sys
\SystemRoot\system32\drivers\WDFLDR.SYS
\SystemRoot\system32\drivers\ACPI.sys
\SystemRoot\system32\drivers\WMILIB.SYS
\SystemRoot\system32\drivers\msisadrv.sys
\SystemRoot\system32\drivers\pci.sys
\SystemRoot\system32\drivers\vdrvroot.sys
\SystemRoot\System32\drivers\partmgr.sys
\SystemRoot\system32\DRIVERS\compbatt.sys
\SystemRoot\system32\DRIVERS\BATTC.SYS
\SystemRoot\system32\drivers\volmgr.sys
\SystemRoot\System32\drivers\volmgrx.sys
\SystemRoot\System32\drivers\mountmgr.sys
\SystemRoot\system32\DRIVERS\iaStor.sys
\SystemRoot\system32\drivers\atapi.sys
\SystemRoot\system32\drivers\ataport.SYS
\SystemRoot\system32\drivers\msahci.sys
\SystemRoot\system32\drivers\PCIIDEX.SYS
\SystemRoot\system32\drivers\amdxata.sys
\SystemRoot\system32\drivers\fltmgr.sys
\SystemRoot\system32\drivers\fileinfo.sys
\SystemRoot\System32\Drivers\PxHlpa64.sys
\SystemRoot\System32\Drivers\Ntfs.sys
\SystemRoot\System32\Drivers\msrpc.sys
\SystemRoot\System32\Drivers\ksecdd.sys
\SystemRoot\System32\Drivers\cng.sys
\SystemRoot\System32\drivers\pcw.sys
\SystemRoot\System32\Drivers\Fs_Rec.sys
\SystemRoot\system32\drivers\ndis.sys
\SystemRoot\system32\drivers\NETIO.SYS
\SystemRoot\System32\Drivers\ksecpkg.sys
\SystemRoot\System32\drivers\tcpip.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\system32\drivers\volsnap.sys
\SystemRoot\System32\Drivers\spldr.sys
\SystemRoot\System32\drivers\rdyboost.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\System32\drivers\hwpolicy.sys
\SystemRoot\System32\DRIVERS\fvevol.sys
\SystemRoot\system32\DRIVERS\disk.sys
\SystemRoot\system32\DRIVERS\CLASSPNP.SYS
\SystemRoot\system32\DRIVERS\cdrom.sys
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\drivers\VIDEOPRT.SYS
\SystemRoot\System32\drivers\watchdog.sys
\SystemRoot\System32\DRIVERS\RDPCDD.sys
\SystemRoot\system32\drivers\rdpencdd.sys
\SystemRoot\system32\drivers\rdprefmp.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\system32\DRIVERS\tdx.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\system32\drivers\afd.sys
\SystemRoot\system32\DRIVERS\wfplwf.sys
\SystemRoot\system32\DRIVERS\pacer.sys
\SystemRoot\system32\DRIVERS\vwififlt.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\DRIVERS\wanarp.sys
\SystemRoot\system32\drivers\termdd.sys
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\drivers\nsiproxy.sys
\SystemRoot\system32\drivers\mssmbios.sys
\SystemRoot\System32\drivers\discache.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\system32\DRIVERS\blbdrive.sys
\SystemRoot\system32\DRIVERS\tunnel.sys
\SystemRoot\system32\DRIVERS\igdkmd64.sys
\SystemRoot\System32\drivers\dxgkrnl.sys
\SystemRoot\System32\drivers\dxgmms1.sys
\SystemRoot\system32\DRIVERS\usbuhci.sys
\SystemRoot\system32\DRIVERS\USBPORT.SYS
\SystemRoot\system32\DRIVERS\usbehci.sys
\SystemRoot\system32\drivers\HDAudBus.sys
\SystemRoot\system32\DRIVERS\athrx.sys
\SystemRoot\system32\DRIVERS\vwifibus.sys
\SystemRoot\system32\DRIVERS\L1C62x64.sys
\SystemRoot\system32\drivers\i8042prt.sys
\SystemRoot\system32\DRIVERS\Apfiltr.sys
\SystemRoot\system32\drivers\mouclass.sys
\SystemRoot\system32\drivers\kbdclass.sys
\SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
\SystemRoot\system32\DRIVERS\CmBatt.sys
\SystemRoot\system32\drivers\wmiacpi.sys
\SystemRoot\system32\DRIVERS\intelppm.sys
\SystemRoot\system32\drivers\CompositeBus.sys
\SystemRoot\system32\DRIVERS\serscan.sys
\SystemRoot\system32\DRIVERS\CtClsFlt.sys
\SystemRoot\system32\DRIVERS\ks.sys
\SystemRoot\system32\drivers\ksthunk.sys
\SystemRoot\system32\DRIVERS\AgileVpn.sys
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\rassstp.sys
\SystemRoot\system32\drivers\swenum.sys
\SystemRoot\system32\DRIVERS\umbus.sys
\SystemRoot\system32\DRIVERS\usbhub.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\system32\drivers\RTKVHD64.sys
\SystemRoot\system32\drivers\portcls.sys
\SystemRoot\system32\drivers\drmk.sys
\SystemRoot\system32\DRIVERS\usbccgp.sys
\SystemRoot\system32\DRIVERS\USBD.SYS
\SystemRoot\System32\Drivers\usbvideo.sys
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\system32\DRIVERS\hidusb.sys
\SystemRoot\system32\DRIVERS\HIDCLASS.SYS
\SystemRoot\system32\DRIVERS\HIDPARSE.SYS
\SystemRoot\system32\drivers\kbdhid.sys
\SystemRoot\system32\DRIVERS\mouhid.sys
\SystemRoot\System32\Drivers\crashdmp.sys
\SystemRoot\System32\Drivers\dump_iaStor.sys
\SystemRoot\System32\Drivers\dump_dumpfve.sys
\SystemRoot\system32\DRIVERS\monitor.sys
\SystemRoot\System32\TSDDD.dll
\SystemRoot\System32\cdd.dll
\SystemRoot\system32\drivers\luafv.sys
\SystemRoot\system32\drivers\WudfPf.sys
\SystemRoot\system32\DRIVERS\lltdio.sys
\SystemRoot\system32\DRIVERS\nwifi.sys
\SystemRoot\system32\DRIVERS\ndisuio.sys
\SystemRoot\system32\DRIVERS\rspndr.sys
\SystemRoot\system32\drivers\HTTP.sys
\SystemRoot\system32\DRIVERS\bowser.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\system32\DRIVERS\mrxsmb10.sys
\SystemRoot\system32\DRIVERS\mrxsmb20.sys
\SystemRoot\system32\DRIVERS\vwifimp.sys
\SystemRoot\system32\drivers\peauth.sys
\SystemRoot\System32\Drivers\secdrv.SYS
\SystemRoot\System32\DRIVERS\srvnet.sys
\SystemRoot\System32\drivers\tcpipreg.sys
\SystemRoot\System32\DRIVERS\srv2.sys
\SystemRoot\System32\DRIVERS\srv.sys
\SystemRoot\System32\Drivers\fastfat.SYS
\SystemRoot\system32\DRIVERS\asyncmac.sys
\??\C:\Windows\system32\drivers\mbamchameleon.sys
\??\C:\Windows\system32\drivers\MBAMSwissArmy.sys
\Windows\System32\ntdll.dll
\Windows\System32\smss.exe
\Windows\System32\apisetschema.dll
----------- End -----------
Done!
<<<1>>>
Upper Device Name: \Device\Harddisk0\DR0
Upper Device Object: 0xfffffa800451b400
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\Ide\IAAStorageDevice-1\
Lower Device Object: 0xfffffa800411b050
Lower Device Driver Name: \Driver\iaStor\
<<<2>>>
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xfffffa800451b400, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa800451c040, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa800451b400, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa800411b050, DeviceName: \Device\Ide\IAAStorageDevice-1\, DriverName: \Driver\iaStor\
------------ End ----------
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
Done!
Drive 0
This is a System drive
Scanning MBR on drive 0...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 51ED4EC9

Partition information:

Partition 0 type is Other (0xde)
Partition is NOT ACTIVE.
Partition starts at LBA: 2048 Numsec = 204800

Partition 1 type is Primary (0x7)
Partition is ACTIVE.
Partition starts at LBA: 206848 Numsec = 30720000
Partition file system is NTFS
Partition is bootable

Partition 2 type is Primary (0x7)
Partition is NOT ACTIVE.
Partition starts at LBA: 30926848 Numsec = 945844272

Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Disk Size: 500107862016 bytes
Sector size: 512 bytes

Done!
Infected: C:\Users\Melissa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DECRYPT_INSTRUCTION.HTML --> [CryptoWall.Trace]
Infected: C:\Users\Melissa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DECRYPT_INSTRUCTION.TXT --> [CryptoWall.Trace]
Infected: C:\Users\Melissa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DECRYPT_INSTRUCTION.URL --> [CryptoWall.Trace]
Infected: C:\Users\Melissa\Desktop\DECRYPT_INSTRUCTION.HTML --> [CryptoWall.Trace]
Infected: C:\Users\Melissa\Desktop\DECRYPT_INSTRUCTION.TXT --> [CryptoWall.Trace]
Infected: C:\Users\Melissa\Desktop\DECRYPT_INSTRUCTION.URL --> [CryptoWall.Trace]
Infected: C:\Users\Melissa\AppData\Roaming\Microsoft\stor.cfg --> [Malware.Trace]
Scan finished
Creating System Restore point...
Cleaning up...
Removal successful. No system shutdown is required.
=======================================


Removal queue found; removal started
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\VBR-0-1-206848-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-r.mbam...
Removal finished

Juliet
2014-11-14, 23:51
I see you let it delete what was found.

online scan with Eset?

I expect to see several infected files, lines saying
DECRYPT_INSTRUCTION.HTML
DECRYPT_INSTRUCTION.TXT
DECRYPT_INSTRUCTION.URL

gurleygirl
2014-11-15, 01:52
Eset is still scanning and working properly...going on 2 hr 27 minutes, 831 threats found. Problem is I have to leave to go on a short trip but will be back Sunday. I didn't mean to delete those threats...It didn't give me a pop up to do a scheduled deletion. I will let you know Sunday how it goes! Thanks again for everything, have a great weekend!

Melissa

Juliet
2014-11-15, 03:45
It's a mistake to leave your computer on and running while your gone.

You should had canceled the scan.

gurleygirl
2014-11-17, 02:57
ESET Scan:

C:\Program Files (x86)\Dell DataSafe Local Backup\hstart.exe a variant of Win32/HiddenStart.A potentially unsafe application
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\hstart.exe a variant of Win32/HiddenStart.A potentially unsafe application
C:\ProgramData\Dell\DellDock\Shortcuts\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\HP\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\HP\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT\Data\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT\Data\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT\Data\Models\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT\Data\Models\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT\Data\Models\Images\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT\Data\Models\Images\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT\Data\Models\Images\B8500\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT\Data\Models\Images\B8500\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT\Data\Models\Images\B8800\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT\Data\Models\Images\B8800\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT\Data\Models\Images\C5300\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT\Data\Models\Images\C5300\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT\Data\Models\Images\C5500\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT\Data\Models\Images\C5500\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT\Data\Models\Images\C6300\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT\Data\Models\Images\C6300\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT\Data\Models\Images\D2500\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT\Data\Models\Images\D2500\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT\Data\Models\Images\D730\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT\Data\Models\Images\D730\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT\Data\Models\Images\generic\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT\Data\Models\Images\generic\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT\Data\Models\Images\J4500\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT\Data\Models\Images\J4500\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT\Data\Models\Images\J4660\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT\Data\Models\Images\J4660\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT\Data\Models\Images\J4680\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT\Data\Models\Images\J4680\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT\Data\Models\Images\J6400\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT\Data\Models\Images\J6400\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT\Data\Models\Movies\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT\Data\Models\Movies\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT\Data\Templates\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT\Data\Templates\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT\Data\Templates\Images\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT\Data\Templates\Images\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT 2.0\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT 2.0\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT 2.0\data\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT 2.0\data\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT 2.0\data\Models\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT 2.0\data\Models\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT 2.0\data\Models\HP Officejet 4500 G510n-z\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT 2.0\data\Models\HP Officejet 4500 G510n-z\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT 2.0\data\Models\HP Officejet 4500 G510n-z\Images\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT 2.0\data\Models\HP Officejet 4500 G510n-z\Images\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT 2.0\data\sessions\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT 2.0\data\sessions\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT 2.0\data\templates\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT 2.0\data\templates\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT 2.0\data\templates\Images\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\HP\LGT 2.0\data\templates\Images\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\Entitlement Client\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\Entitlement Client\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\Entitlement Client\v5\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\Entitlement Client\v5\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\Entitlement Client\v6.0\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\Entitlement Client\v6.0\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\Entitlement Client\v8\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\Entitlement Client\v8\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks\ReportCenter\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks\ReportCenter\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2008\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2008\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2008\Components\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2008\Components\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Message\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Message\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Message\.update\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Message\.update\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Message\.update\.target\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Message\.update\.target\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Message\.update\.target\85216424\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Message\.update\.target\85216424\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Message\.update\.target\85216424\content\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Message\.update\.target\85216424\content\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Patch\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Patch\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Profile\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Profile\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Profile\.update\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Profile\.update\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Profile\.update\.target\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Profile\.update\.target\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Profile\.update\.target\85216424\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Profile\.update\.target\85216424\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Profile\.update\.target\85216424\content\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Profile\.update\.target\85216424\content\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DataProtect\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DataProtect\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DataProtect\OCD\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DataProtect\OCD\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DataProtect\ROLLBACK\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DataProtect\ROLLBACK\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Message\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Message\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Message\.update\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Message\.update\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Message\.update\.target\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Message\.update\.target\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Message\.update\.target\85216424\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Message\.update\.target\85216424\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Message\.update\.target\85216424\content\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Message\.update\.target\85216424\content\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\NewFeatures\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\NewFeatures\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\NewFeatures\.update\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\NewFeatures\.update\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\NewFeatures\.update\.target\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\NewFeatures\.update\.target\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Patch\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Patch\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Payroll\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Payroll\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Payroll\.update\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Payroll\.update\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Payroll\.update\.target\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Payroll\.update\.target\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Profile\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Profile\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Profile\.update\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Profile\.update\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Profile\.update\.target\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Profile\.update\.target\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Profile\.update\.target\85216424\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Profile\.update\.target\85216424\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Profile\.update\.target\85216424\content\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Profile\.update\.target\85216424\content\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\StateForms\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\StateForms\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\StateForms\.update\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\StateForms\.update\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\StateForms\.update\.target\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\StateForms\.update\.target\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\SyncMgr\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\SyncMgr\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\SyncMgr\OCD\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\SyncMgr\OCD\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2012\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2012\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2012\Components\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2012\Components\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2012\Components\DataProtect\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2012\Components\DataProtect\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2012\Components\DataProtect\OCD\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2012\Components\DataProtect\OCD\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2012\Components\DownloadQB22\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2012\Components\DownloadQB22\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2012\Components\DownloadQB22\SPatch\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2012\Components\DownloadQB22\SPatch\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2012\Components\OLB\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2012\Components\OLB\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2012\Components\OLB\branding\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2012\Components\OLB\branding\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2012\Components\OLB\branding\filist\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2012\Components\OLB\branding\filist\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2012\Components\OLB\workflow\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2012\Components\OLB\workflow\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2012\Components\PDFDownload\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2012\Components\PDFDownload\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2012\Components\SyncMgr\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2012\Components\SyncMgr\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2012\Components\SyncMgr\OCD\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2012\Components\SyncMgr\OCD\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2013\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2013\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2013\Components\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2013\Components\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2013\Components\DataProtect\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2013\Components\DataProtect\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2013\Components\DataProtect\OCD\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\QuickBooks 2013\Components\DataProtect\OCD\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\SyncManager\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Intuit\SyncManager\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\LeapPad2\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\LeapPad2\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\LeapPad2\290E220001011026A25A\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\LeapPad2\290E220001011026A25A\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\LeapPad2\2919220001011025F7B3\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\LeapPad2\2919220001011025F7B3\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\AltHomepage\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\AltHomepage\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\AltHomepage\Landing\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\AltHomepage\Landing\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\AltHomepage\Landing\images\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\AltHomepage\Landing\images\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\Homepage\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\Homepage\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\Homepage\Landing\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\Homepage\Landing\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPad2\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPad2\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPad2\Expandables\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPad2\Expandables\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPad2\Landing\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPad2\Landing\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPad2\My Device\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPad2\My Device\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPad2\My Device\images\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPad2\My Device\images\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPadExplorer\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPadExplorer\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPadExplorer\Expandables\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPadExplorer\Expandables\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPadExplorer\Landing\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPadExplorer\Landing\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPadExplorer\My Device\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPadExplorer\My Device\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPadExplorer\My Device\images\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPadExplorer\My Device\images\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\Tag\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\Tag\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\Tag\Landing\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\Tag\Landing\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\Tag\Landing\panels\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\Tag\Landing\panels\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Light-O-Rama\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Light-O-Rama\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Light-O-Rama\Samples\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Light-O-Rama\Samples\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Macrovision\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Macrovision\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Macrovision\FLEXnet Connect\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Macrovision\FLEXnet Connect\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Macrovision\FLEXnet Connect\11\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Macrovision\FLEXnet Connect\11\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Macrovision\FLEXnet Connect\11\ui\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Macrovision\FLEXnet Connect\11\ui\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Macrovision\FLEXnet Connect\11\ui\images\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Macrovision\FLEXnet Connect\11\ui\images\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Microsoft\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Microsoft\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Microsoft\eHome\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Microsoft\eHome\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Microsoft\RAC\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Microsoft\RAC\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Microsoft\RAC\PublishedData\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Microsoft\RAC\PublishedData\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Microsoft\RAC\StateData\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Microsoft\RAC\StateData\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\PCDr\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\PCDr\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\PCDr\6426\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\PCDr\6426\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\PCDr\6426\AddOnContent\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\PCDr\6426\AddOnContent\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\PCDr\6426\AddOnContent\ba005e12-3139-4327-9f7a-9f2ea6a6c841-d3dc259c-4fe5-45a6-a2aa-aaba450ab883\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\PCDr\6426\AddOnContent\ba005e12-3139-4327-9f7a-9f2ea6a6c841-d3dc259c-4fe5-45a6-a2aa-aaba450ab883\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\PCDr\6426\AddOnDownloaderCache\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\PCDr\6426\AddOnDownloaderCache\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\PCDr\6426\datastore\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\PCDr\6426\datastore\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\PCDr\6426\Tonopah\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\PCDr\6426\Tonopah\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\PCDr\6426\Tonopah\db\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\PCDr\6426\Tonopah\db\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\PCDr\6426\Tonopah\manifest\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\PCDr\6426\Tonopah\manifest\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\PCDr\6426\Tonopah\upload\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\PCDr\6426\Tonopah\upload\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\PCDr\Tonopah\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\PCDr\Tonopah\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Skype\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Skype\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Skype\Plugins\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Skype\Plugins\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Skype\Plugins\Local Cache\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Skype\Plugins\Local Cache\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Skype\Plugins\Plugins\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Skype\Plugins\Plugins\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Skype\Plugins\Plugins\F57B48ADF2224F088EDD1A2B9BAD84E8\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Skype\Plugins\Plugins\F57B48ADF2224F088EDD1A2B9BAD84E8\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Skype\Plugins\Plugins\F57B48ADF2224F088EDD1A2B9BAD84E8\Local Cache\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Skype\Plugins\Plugins\F57B48ADF2224F088EDD1A2B9BAD84E8\Local Cache\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Sonic\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Sonic\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Spybot - Search & Destroy\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Spybot - Search & Destroy\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Spybot - Search & Destroy\Logs\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Spybot - Search & Destroy\Logs\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Spybot - Search & Destroy\Quarantine\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Spybot - Search & Destroy\Quarantine\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Windstream\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Windstream\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Windstream\Service Agent\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Windstream\Service Agent\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Windstream\Service Agent\UiSections\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Windstream\Service Agent\UiSections\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Services\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Services\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-PcWarranty\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-PcWarranty\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-PcWarranty\en\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-PcWarranty\en\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-RankingEcare\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-RankingEcare\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-RankingEcare\en\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-RankingEcare\en\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-RankingSecurityAndBackup\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-RankingSecurityAndBackup\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-RankingSecurityAndBackup\en\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-RankingSecurityAndBackup\en\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Upsell\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Upsell\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Upsell\Upsell-Bundles\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Upsell\Upsell-Bundles\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Upsell\Upsell-Bundles\en\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Upsell\Upsell-Bundles\en\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Windstream\Service Agent\UiSections\RADIALPOINT-UI-HSD-1-0-0-A962FBAB\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Windstream\Service Agent\UiSections\RADIALPOINT-UI-HSD-1-0-0-A962FBAB\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Windstream\Service Agent\UiSections\RADIALPOINT-UI-HSD-1-0-0-A962FBAB\en\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Windstream\Service Agent\UiSections\RADIALPOINT-UI-HSD-1-0-0-A962FBAB\en\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\ProgramData\Windstream\Service Agent\UiSections\RADIALPOINT-UI-HSD-1-0-0-A962FBAB\en\help\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\ProgramData\Windstream\Service Agent\UiSections\RADIALPOINT-UI-HSD-1-0-0-A962FBAB\en\help\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Dell\DellDock\Shortcuts\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\HP\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\HP\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT\Data\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT\Data\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT\Data\Models\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT\Data\Models\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT\Data\Models\Images\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT\Data\Models\Images\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT\Data\Models\Images\B8500\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT\Data\Models\Images\B8500\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT\Data\Models\Images\B8800\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT\Data\Models\Images\B8800\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT\Data\Models\Images\C5300\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT\Data\Models\Images\C5300\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT\Data\Models\Images\C5500\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT\Data\Models\Images\C5500\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT\Data\Models\Images\C6300\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT\Data\Models\Images\C6300\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT\Data\Models\Images\D2500\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT\Data\Models\Images\D2500\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT\Data\Models\Images\D730\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT\Data\Models\Images\D730\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT\Data\Models\Images\generic\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT\Data\Models\Images\generic\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT\Data\Models\Images\J4500\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT\Data\Models\Images\J4500\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT\Data\Models\Images\J4660\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT\Data\Models\Images\J4660\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT\Data\Models\Images\J4680\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT\Data\Models\Images\J4680\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT\Data\Models\Images\J6400\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT\Data\Models\Images\J6400\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT\Data\Models\Movies\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT\Data\Models\Movies\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT\Data\Templates\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT\Data\Templates\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT\Data\Templates\Images\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT\Data\Templates\Images\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT 2.0\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT 2.0\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT 2.0\data\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT 2.0\data\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT 2.0\data\Models\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT 2.0\data\Models\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT 2.0\data\Models\HP Officejet 4500 G510n-z\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT 2.0\data\Models\HP Officejet 4500 G510n-z\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT 2.0\data\Models\HP Officejet 4500 G510n-z\Images\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT 2.0\data\Models\HP Officejet 4500 G510n-z\Images\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT 2.0\data\sessions\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT 2.0\data\sessions\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT 2.0\data\templates\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT 2.0\data\templates\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT 2.0\data\templates\Images\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\HP\LGT 2.0\data\templates\Images\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\Entitlement Client\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\Entitlement Client\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\Entitlement Client\v5\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\Entitlement Client\v5\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\Entitlement Client\v6.0\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\Entitlement Client\v6.0\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\Entitlement Client\v8\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\Entitlement Client\v8\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks\ReportCenter\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks\ReportCenter\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2008\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2008\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2008\Components\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2008\Components\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2008\Components\DownloadQB18\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2008\Components\DownloadQB18\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2008\Components\DownloadQB18\Message\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2008\Components\DownloadQB18\Message\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2008\Components\DownloadQB18\Message\.update\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2008\Components\DownloadQB18\Message\.update\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2008\Components\DownloadQB18\Message\.update\.target\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2008\Components\DownloadQB18\Message\.update\.target\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2008\Components\DownloadQB18\Message\.update\.target\85216424\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2008\Components\DownloadQB18\Message\.update\.target\85216424\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2008\Components\DownloadQB18\Message\.update\.target\85216424\content\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2008\Components\DownloadQB18\Message\.update\.target\85216424\content\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2008\Components\DownloadQB18\Patch\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2008\Components\DownloadQB18\Patch\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2008\Components\DownloadQB18\Profile\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2008\Components\DownloadQB18\Profile\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2008\Components\DownloadQB18\Profile\.update\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2008\Components\DownloadQB18\Profile\.update\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2008\Components\DownloadQB18\Profile\.update\.target\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2008\Components\DownloadQB18\Profile\.update\.target\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2008\Components\DownloadQB18\Profile\.update\.target\85216424\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2008\Components\DownloadQB18\Profile\.update\.target\85216424\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2008\Components\DownloadQB18\Profile\.update\.target\85216424\content\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2008\Components\DownloadQB18\Profile\.update\.target\85216424\content\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DataProtect\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DataProtect\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DataProtect\OCD\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DataProtect\OCD\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DataProtect\ROLLBACK\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DataProtect\ROLLBACK\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Message\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Message\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Message\.update\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Message\.update\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Message\.update\.target\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Message\.update\.target\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Message\.update\.target\85216424\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Message\.update\.target\85216424\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Message\.update\.target\85216424\content\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Message\.update\.target\85216424\content\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\NewFeatures\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\NewFeatures\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\NewFeatures\.update\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\NewFeatures\.update\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\NewFeatures\.update\.target\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\NewFeatures\.update\.target\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Patch\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Patch\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Payroll\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Payroll\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Payroll\.update\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Payroll\.update\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Payroll\.update\.target\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Payroll\.update\.target\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Profile\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Profile\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Profile\.update\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Profile\.update\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Profile\.update\.target\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Profile\.update\.target\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Profile\.update\.target\85216424\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Profile\.update\.target\85216424\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Profile\.update\.target\85216424\content\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Profile\.update\.target\85216424\content\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\StateForms\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\StateForms\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\StateForms\.update\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\StateForms\.update\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\StateForms\.update\.target\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\StateForms\.update\.target\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\SyncMgr\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\SyncMgr\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\SyncMgr\OCD\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2011_03.15.04.57\Components\SyncMgr\OCD\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2012\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2012\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2012\Components\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2012\Components\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2012\Components\DataProtect\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2012\Components\DataProtect\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2012\Components\DataProtect\OCD\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2012\Components\DataProtect\OCD\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2012\Components\DownloadQB22\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2012\Components\DownloadQB22\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2012\Components\DownloadQB22\SPatch\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2012\Components\DownloadQB22\SPatch\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2012\Components\OLB\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2012\Components\OLB\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2012\Components\OLB\branding\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2012\Components\OLB\branding\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2012\Components\OLB\branding\filist\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2012\Components\OLB\branding\filist\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2012\Components\OLB\workflow\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2012\Components\OLB\workflow\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2012\Components\PDFDownload\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2012\Components\PDFDownload\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2012\Components\SyncMgr\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2012\Components\SyncMgr\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2012\Components\SyncMgr\OCD\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2012\Components\SyncMgr\OCD\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2013\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2013\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2013\Components\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2013\Components\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2013\Components\DataProtect\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2013\Components\DataProtect\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2013\Components\DataProtect\OCD\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\QuickBooks 2013\Components\DataProtect\OCD\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\SyncManager\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Intuit\SyncManager\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\LeapPad2\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\LeapPad2\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\LeapPad2\290E220001011026A25A\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\LeapPad2\290E220001011026A25A\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\LeapPad2\2919220001011025F7B3\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\LeapPad2\2919220001011025F7B3\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\TempFlashFiles\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\TempFlashFiles\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\TempFlashFiles\AltHomepage\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\TempFlashFiles\AltHomepage\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\TempFlashFiles\AltHomepage\Landing\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\TempFlashFiles\AltHomepage\Landing\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\TempFlashFiles\AltHomepage\Landing\images\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\TempFlashFiles\AltHomepage\Landing\images\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\TempFlashFiles\Homepage\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\TempFlashFiles\Homepage\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\TempFlashFiles\Homepage\Landing\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\TempFlashFiles\Homepage\Landing\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPad2\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPad2\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPad2\Expandables\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPad2\Expandables\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPad2\Landing\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPad2\Landing\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPad2\My Device\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPad2\My Device\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPad2\My Device\images\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPad2\My Device\images\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPadExplorer\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPadExplorer\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPadExplorer\Expandables\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPadExplorer\Expandables\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPadExplorer\Landing\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPadExplorer\Landing\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPadExplorer\My Device\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPadExplorer\My Device\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPadExplorer\My Device\images\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPadExplorer\My Device\images\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\TempFlashFiles\Tag\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\TempFlashFiles\Tag\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\TempFlashFiles\Tag\Landing\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\TempFlashFiles\Tag\Landing\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\TempFlashFiles\Tag\Landing\panels\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Leapfrog\LeapFrog Connect\TempFlashFiles\Tag\Landing\panels\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Light-O-Rama\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Light-O-Rama\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Light-O-Rama\Samples\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Light-O-Rama\Samples\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Macrovision\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Macrovision\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Macrovision\FLEXnet Connect\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Macrovision\FLEXnet Connect\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Macrovision\FLEXnet Connect\11\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Macrovision\FLEXnet Connect\11\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Macrovision\FLEXnet Connect\11\ui\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Macrovision\FLEXnet Connect\11\ui\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Macrovision\FLEXnet Connect\11\ui\images\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Macrovision\FLEXnet Connect\11\ui\images\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Microsoft\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Microsoft\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Microsoft\eHome\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Microsoft\eHome\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Microsoft\RAC\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Microsoft\RAC\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Microsoft\RAC\PublishedData\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Microsoft\RAC\PublishedData\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Microsoft\RAC\StateData\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Microsoft\RAC\StateData\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\PCDr\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\PCDr\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\PCDr\6426\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\PCDr\6426\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\PCDr\6426\AddOnContent\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\PCDr\6426\AddOnContent\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\PCDr\6426\AddOnContent\ba005e12-3139-4327-9f7a-9f2ea6a6c841-d3dc259c-4fe5-45a6-a2aa-aaba450ab883\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\PCDr\6426\AddOnContent\ba005e12-3139-4327-9f7a-9f2ea6a6c841-d3dc259c-4fe5-45a6-a2aa-aaba450ab883\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\PCDr\6426\AddOnDownloaderCache\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\PCDr\6426\AddOnDownloaderCache\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\PCDr\6426\datastore\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\PCDr\6426\datastore\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\PCDr\6426\Tonopah\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\PCDr\6426\Tonopah\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\PCDr\6426\Tonopah\db\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\PCDr\6426\Tonopah\db\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\PCDr\6426\Tonopah\manifest\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\PCDr\6426\Tonopah\manifest\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\PCDr\6426\Tonopah\upload\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\PCDr\6426\Tonopah\upload\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\PCDr\Tonopah\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\PCDr\Tonopah\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Skype\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Skype\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Skype\Plugins\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Skype\Plugins\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Skype\Plugins\Local Cache\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Skype\Plugins\Local Cache\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Skype\Plugins\Plugins\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Skype\Plugins\Plugins\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Skype\Plugins\Plugins\F57B48ADF2224F088EDD1A2B9BAD84E8\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Skype\Plugins\Plugins\F57B48ADF2224F088EDD1A2B9BAD84E8\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Skype\Plugins\Plugins\F57B48ADF2224F088EDD1A2B9BAD84E8\Local Cache\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Skype\Plugins\Plugins\F57B48ADF2224F088EDD1A2B9BAD84E8\Local Cache\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Sonic\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Sonic\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Spybot - Search & Destroy\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Spybot - Search & Destroy\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Spybot - Search & Destroy\Logs\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Spybot - Search & Destroy\Logs\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Spybot - Search & Destroy\Quarantine\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Spybot - Search & Destroy\Quarantine\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Windstream\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Windstream\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Windstream\Service Agent\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Windstream\Service Agent\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Windstream\Service Agent\UiSections\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Windstream\Service Agent\UiSections\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Windstream\Service Agent\UiSections\DataDefinition-Services\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Windstream\Service Agent\UiSections\DataDefinition-Services\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-PcWarranty\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-PcWarranty\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-PcWarranty\en\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-PcWarranty\en\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-RankingEcare\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-RankingEcare\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-RankingEcare\en\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-RankingEcare\en\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-RankingSecurityAndBackup\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-RankingSecurityAndBackup\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-RankingSecurityAndBackup\en\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-RankingSecurityAndBackup\en\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Windstream\Service Agent\UiSections\DataDefinition-Upsell\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Windstream\Service Agent\UiSections\DataDefinition-Upsell\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Windstream\Service Agent\UiSections\DataDefinition-Upsell\Upsell-Bundles\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Windstream\Service Agent\UiSections\DataDefinition-Upsell\Upsell-Bundles\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Windstream\Service Agent\UiSections\DataDefinition-Upsell\Upsell-Bundles\en\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Windstream\Service Agent\UiSections\DataDefinition-Upsell\Upsell-Bundles\en\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Windstream\Service Agent\UiSections\RADIALPOINT-UI-HSD-1-0-0-A962FBAB\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Windstream\Service Agent\UiSections\RADIALPOINT-UI-HSD-1-0-0-A962FBAB\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Windstream\Service Agent\UiSections\RADIALPOINT-UI-HSD-1-0-0-A962FBAB\en\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Windstream\Service Agent\UiSections\RADIALPOINT-UI-HSD-1-0-0-A962FBAB\en\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\All Users\Windstream\Service Agent\UiSections\RADIALPOINT-UI-HSD-1-0-0-A962FBAB\en\help\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\All Users\Windstream\Service Agent\UiSections\RADIALPOINT-UI-HSD-1-0-0-A962FBAB\en\help\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Apple Computer\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Apple Computer\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Apple Computer\iTunes\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Apple Computer\iTunes\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\DIRECTV Player\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\DIRECTV Player\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\DIRECTV Player\Legal\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\DIRECTV Player\Legal\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Google\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Google\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Google\Chrome\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Google\Chrome\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Google\Chrome\User Data\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Google\Chrome\User Data\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Google\Chrome\User Data\Default\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Google\Chrome\User Data\Default\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Google\Chrome\User Data\Default\databases\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Google\Chrome\User Data\Default\databases\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Intuit\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Intuit\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Intuit\QBDataSync_OfflineLogs\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Intuit\QBDataSync_OfflineLogs\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Intuit\QBDataSync_OfflineLogs\CB8D650F50892B47E040900A441A5554_Logs\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Intuit\QBDataSync_OfflineLogs\CB8D650F50892B47E040900A441A5554_Logs\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Intuit\SyncManager\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Intuit\SyncManager\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.2.23.4037\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.2.23.4037\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.4.23.4010\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.4.23.4010\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.4.23.4011\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.4.23.4011\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.5.23.4005\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.5.23.4005\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.5.23.4007\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.5.23.4007\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.6.23.4001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.6.23.4001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.7.23.4002\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.7.23.4002\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.7.23.4007\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.7.23.4007\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.7.23.4016\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.7.23.4016\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Intuit\SyncManager\6.0.24.4009\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Intuit\SyncManager\6.0.24.4009\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Intuit\SyncManager\6.2.24.4107\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Intuit\SyncManager\6.2.24.4107\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Intuit\SyncManager\6.3.24.4012\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Intuit\SyncManager\6.3.24.4012\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Intuit\SyncManager\Current\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Intuit\SyncManager\Current\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Intuit\TempSyncLogs\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Intuit\TempSyncLogs\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\ehome\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\ehome\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Internet Explorer\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Internet Explorer\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Media Player\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Media Player\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Media Player\Art Cache\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Media Player\Art Cache\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Media Player\Art Cache\LocalMLS\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Media Player\Art Cache\LocalMLS\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Messenger\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Messenger\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Office\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Office\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Office\15.0\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Office\15.0\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Office\15.0\OfficeFileCache\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Office\15.0\OfficeFileCache\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Photo Acquisition\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Photo Acquisition\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Windows Live Mail\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Windows Live Mail\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Windows Live Mail\Backup\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Windows Live Mail\Backup\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Windows Live Mail\Backup\new\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Windows Live Mail\Backup\new\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Windows Live Mail\Sentinel\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Windows Live Mail\Sentinel\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Windows Live Photo Acquisition\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Windows Live Photo Acquisition\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Windows Mail\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Windows Mail\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Windows Mail\Backup\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Windows Mail\Backup\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Windows Mail\Backup\old\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Windows Mail\Backup\old\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Windows Mail\Stationery\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Windows Mail\Stationery\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Windows Media\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Windows Media\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Windows Media\12.0\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Windows Media\12.0\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Windows Photo Gallery\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Windows Photo Gallery\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Windows Photo Gallery\Original Images\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft\Windows Photo Gallery\Original Images\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft Games\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft Games\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft Games\FreeCell\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Microsoft Games\FreeCell\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Local\Temp\11544\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HN6ECFET\h5v0iiglnm[1].htm JS/Exploit.Agent.NHX trojan
C:\Users\Melissa\AppData\Local\Temp\7e94\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HN6ECFET\e0kih564qj[1].htm JS/Exploit.Agent.NHY trojan
C:\Users\Melissa\AppData\Local\Temp\9d10\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HN6ECFET\0xgnob24tu[1].htm JS/Exploit.Agent.NHX trojan
C:\Users\Melissa\AppData\Local\Temp\befc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HN6ECFET\shbff1zqit[1].htm JS/Exploit.Agent.NHX trojan
C:\Users\Melissa\AppData\Local\Temp\c054\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\M4DWYY19\87e89ufcaz[1].htm JS/Exploit.Agent.NHX trojan
C:\Users\Melissa\AppData\Local\Temp\cda8\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HN6ECFET\sl4tlkited[1].htm JS/Exploit.Agent.NHX trojan
C:\Users\Melissa\AppData\LocalLow\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Adobe\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Adobe\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Adobe\Acrobat\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Adobe\Acrobat\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Adobe\Acrobat\10.0\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Adobe\Acrobat\10.0\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\DTV\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\DTV\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\DTV\PCShow\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\DTV\PCShow\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\DTV\PCShow\catalogs\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\DTV\PCShow\catalogs\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Microsoft\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Microsoft\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\wbrubsjg.qge\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\wbrubsjg.qge\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\wbrubsjg.qge\dvruwf3b.m52\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\wbrubsjg.qge\dvruwf3b.m52\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\wbrubsjg.qge\dvruwf3b.m52\1\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\wbrubsjg.qge\dvruwf3b.m52\1\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\wbrubsjg.qge\dvruwf3b.m52\1\s\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\wbrubsjg.qge\dvruwf3b.m52\1\s\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\wbrubsjg.qge\dvruwf3b.m52\1\s\eer4rru2aqwqtonnnklwiobyo3um0pgyaz3owxdir1tygg0egsaaacca\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\wbrubsjg.qge\dvruwf3b.m52\1\s\eer4rru2aqwqtonnnklwiobyo3um0pgyaz3owxdir1tygg0egsaaacca\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\wbrubsjg.qge\dvruwf3b.m52\1\s\eer4rru2aqwqtonnnklwiobyo3um0pgyaz3owxdir1tygg0egsaaacca\f\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\wbrubsjg.qge\dvruwf3b.m52\1\s\eer4rru2aqwqtonnnklwiobyo3um0pgyaz3owxdir1tygg0egsaaacca\f\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\wbrubsjg.qge\dvruwf3b.m52\1\s\psld1rq2evnjg2ki2ziatkouhebg2l4klzm3vvurqxwtu41pinaaahda\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\wbrubsjg.qge\dvruwf3b.m52\1\s\psld1rq2evnjg2ki2ziatkouhebg2l4klzm3vvurqxwtu41pinaaahda\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\wbrubsjg.qge\dvruwf3b.m52\1\s\psld1rq2evnjg2ki2ziatkouhebg2l4klzm3vvurqxwtu41pinaaahda\f\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\wbrubsjg.qge\dvruwf3b.m52\1\s\psld1rq2evnjg2ki2ziatkouhebg2l4klzm3vvurqxwtu41pinaaahda\f\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Sun\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Sun\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Sun\Java\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Sun\Java\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\SystemCache\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\SystemCache\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\SystemCache\6.0\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\SystemCache\6.0\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\SystemCache\6.0\11\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\SystemCache\6.0\11\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\SystemCache\6.0\26\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\SystemCache\6.0\26\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\SystemCache\6.0\3\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\SystemCache\6.0\3\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\SystemCache\6.0\32\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\SystemCache\6.0\32\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\SystemCache\6.0\4\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\SystemCache\6.0\4\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\SystemCache\6.0\42\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\SystemCache\6.0\42\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Sun\Java\jre1.6.0_22\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\LocalLow\Sun\Java\jre1.6.0_22\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\OICE_15_974FA576_32C1D314_1139\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\OICE_15_974FA576_32C1D314_1139\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\OICE_15_974FA576_32C1D314_2CDE\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\OICE_15_974FA576_32C1D314_2CDE\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Adobe\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Adobe\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Adobe\Flash Player\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Adobe\Flash Player\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Adobe\Flash Player\AssetCache\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Adobe\Flash Player\AssetCache\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Adobe\Flash Player\AssetCache\T4QJTQHZ\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Adobe\Flash Player\AssetCache\T4QJTQHZ\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Amazon\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Amazon\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Amazon\MP3 Downloader\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Amazon\MP3 Downloader\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Dell\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Dell\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Dell\Dell Stage\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Dell\Dell Stage\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Dell\Dell Stage\{6dedbe25-1baa-49d5-a314-3524143af6f7}\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Dell\Dell Stage\{6dedbe25-1baa-49d5-a314-3524143af6f7}\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\HP\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\HP\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\HP\WebRegLogs\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\HP\WebRegLogs\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Access\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Access\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\DbgClr\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\DbgClr\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\DbgClr\8.0\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\DbgClr\8.0\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Document Building Blocks\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Document Building Blocks\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Document Building Blocks\1033\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Document Building Blocks\1033\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Document Building Blocks\1033\15\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Document Building Blocks\1033\15\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Excel\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Excel\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Excel\2013%20group%20schedule303277132184948787\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Excel\2013%20group%20schedule303277132184948787\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Excel\Field%20trip%20schedule%202014303920862365260351\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Excel\Field%20trip%20schedule%202014303920862365260351\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Excel\Field%20trip%20schedule%202014303970643328640619\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Excel\Field%20trip%20schedule%202014303970643328640619\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Excel\Field%20trip%20schedule%202014304010691630387985\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Excel\Field%20trip%20schedule%202014304010691630387985\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Excel\Field%20trip%20schedule%202014304028803416694882\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Excel\Field%20trip%20schedule%202014304028803416694882\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Excel\Field%20trip%20schedule%202014304039061652633985\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Excel\Field%20trip%20schedule%202014304039061652633985\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Signatures\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Signatures\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\15\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\15\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\15\Managed\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\15\Managed\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\15\Managed\SmartArt Graphics\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\15\Managed\SmartArt Graphics\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\15\Managed\SmartArt Graphics\1033\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\15\Managed\SmartArt Graphics\1033\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\15\Managed\Word Document Building Blocks\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\15\Managed\Word Document Building Blocks\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\15\Managed\Word Document Building Blocks\1033\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\15\Managed\Word Document Building Blocks\1033\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\Word Document Building Blocks\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\Word Document Building Blocks\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\Word Document Building Blocks\1033\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\Word Document Building Blocks\1033\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\PCDr\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\PCDr\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\PCDr\Installer\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\PCDr\Installer\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\PCDr\Installer\Logs\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\PCDr\Installer\Logs\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Skype\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Skype\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Skype\melissa.reagan2\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Skype\melissa.reagan2\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Skype\shared_dynco\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Skype\shared_dynco\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Skype\shared_httpfe\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\AppData\Roaming\Skype\shared_httpfe\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Desktop\Audio\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Desktop\Audio\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Desktop\Sequences\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Desktop\Sequences\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Desktop\Visualizations\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Desktop\Visualizations\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Desktop\Visualizations\Editor\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Desktop\Visualizations\Editor\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Desktop\Visualizations\Editor\LOR Visualizer Tutorial\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Desktop\Visualizations\Editor\LOR Visualizer Tutorial\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Amazon MP3\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Amazon MP3\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Amazon MP3\logs\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Amazon MP3\logs\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Bell computer\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Bell computer\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Bible Lutheran\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Bible Lutheran\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\business forms\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\business forms\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Coffee bluff Marina\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Coffee bluff Marina\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\commercial bids\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\commercial bids\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\commercial bids\Marchesee\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\commercial bids\Marchesee\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Contractors\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Contractors\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Contractors\clay pevey\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Contractors\clay pevey\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Contractors\jen jacs\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Contractors\jen jacs\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Contractors\Long Builders\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Contractors\Long Builders\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Countryside\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Countryside\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\employee documents\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\employee documents\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\FT. Stewart Training Facility\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\FT. Stewart Training Facility\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\gaffney's cheap seats\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\gaffney's cheap seats\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\gaffney's cheap seats\cheap seats\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\gaffney's cheap seats\cheap seats\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\gaffney's cheap seats\Cheap Seats menu landscape_files\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\gaffney's cheap seats\Cheap Seats menu landscape_files\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\gaffney's cheap seats\promos\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\gaffney's cheap seats\promos\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Guerry\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Guerry\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\HAAF engagement\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\HAAF engagement\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Heard elementary\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Heard elementary\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Invoices\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Invoices\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Largo Tibet\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Largo Tibet\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\MAdrac Farms\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\MAdrac Farms\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\MAdrac Farms\2012\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\MAdrac Farms\2012\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\MAdrac Farms\Country Christmas\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\MAdrac Farms\Country Christmas\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\MAdrac Farms\farmers market\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\MAdrac Farms\farmers market\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\MAdrac Farms\newsletters\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\MAdrac Farms\newsletters\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\MAdrac Farms\old stuff\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\MAdrac Farms\old stuff\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\MAdrac Farms\old stuff\bag letters\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\MAdrac Farms\old stuff\bag letters\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\MAdrac Farms\press releases\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\MAdrac Farms\press releases\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\MAdrac Farms\pumpkin chunkin\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\MAdrac Farms\pumpkin chunkin\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\MAdrac Farms\pumpkin patch\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\MAdrac Farms\pumpkin patch\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\MAdrac Farms\pumpkin patch\2014\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\MAdrac Farms\pumpkin patch\2014\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\MAdrac Farms\pumpkin patch\signs\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\MAdrac Farms\pumpkin patch\signs\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\MAdrac Farms\recipes\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\MAdrac Farms\recipes\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\MAdrac Farms\Signs\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\MAdrac Farms\Signs\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\MAdrac Farms\Snow Day 2014_files\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\MAdrac Farms\Snow Day 2014_files\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\MAdrac Farms\taxes\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\MAdrac Farms\taxes\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\My Scans\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\My Scans\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OgeeChee\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OgeeChee\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\1259\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\1259\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\1259\1259 bid documents\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\1259\1259 bid documents\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\1259\CEFS\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\1259\CEFS\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\1259\cerified payroll\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\1259\cerified payroll\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\1259\pay app stuff\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\1259\pay app stuff\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\1259\VNI\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\1259\VNI\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\728A\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\728A\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\AMC inc\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\AMC inc\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\AMC inc\certified payroll\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\AMC inc\certified payroll\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\blackshear\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\blackshear\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\commissary stuff\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\commissary stuff\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\Davita\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\Davita\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\Eff Hospital\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\Eff Hospital\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\Post office\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\Post office\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\certified payroll\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\certified payroll\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\pay application\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\pay application\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\pay application\10.25.10\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\pay application\10.25.10\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\pay application\11.24.10\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\pay application\11.24.10\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\pay application\8.25.10\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\pay application\8.25.10\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\pay application\9.25.10\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\pay application\9.25.10\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\southeastern contract - sub\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\southeastern contract - sub\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\waivers\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\waivers\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\tom triplett park\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\tom triplett park\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\Verizon\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\Verizon\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\WT Dubois\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\OLD jobs\WT Dubois\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\personal\bank statements\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\personal\bank statements\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\personal\blogs\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\personal\blogs\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\personal\resumes\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\personal\resumes\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\pics\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\pics\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\pics\mel&gue\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\pics\mel&gue\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\pics\Rachel\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\pics\Rachel\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\pics\RES photos\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\pics\RES photos\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\pics\wedding\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\pics\wedding\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Scanned Documents\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Scanned Documents\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Taxes\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Taxes\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Taxes\2011\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Taxes\2011\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Taxes\2011\1Q\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Taxes\2011\1Q\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Taxes\2011\2Q\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Taxes\2011\2Q\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Taxes\2011\3Q\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Taxes\2011\3Q\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Taxes\2011\end of year\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Taxes\2011\end of year\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Taxes\2012\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Taxes\2012\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Taxes\2012\1Q\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\Taxes\2012\1Q\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\WBENC\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Documents\WBENC\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Music\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Music\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Music\Amazon MP3\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Music\Amazon MP3\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Music\Amazon MP3\Trans-Siberian Orchestra\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Music\Amazon MP3\Trans-Siberian Orchestra\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Music\Amazon MP3\Trans-Siberian Orchestra\Christmas Eve And Other Stories\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Music\Amazon MP3\Trans-Siberian Orchestra\Christmas Eve And Other Stories\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Music\Amazon MP3\Trans-Siberian Orchestra\The Lost Christmas Eve (U.S. Version)\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Music\Amazon MP3\Trans-Siberian Orchestra\The Lost Christmas Eve (U.S. Version)\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Music\iTunes\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Music\iTunes\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Music\iTunes\iTunes Media\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Music\iTunes\iTunes Media\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Music\iTunes\iTunes Media\Movies\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Music\iTunes\iTunes Media\Movies\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Music\iTunes\iTunes Media\Movies\The Heat\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Music\iTunes\iTunes Media\Movies\The Heat\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Music\iTunes\iTunes Media\TV Shows\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Music\iTunes\iTunes Media\TV Shows\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Music\iTunes\iTunes Media\TV Shows\Grey's Anatomy\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Music\iTunes\iTunes Media\TV Shows\Grey's Anatomy\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Music\iTunes\iTunes Media\TV Shows\Grey's Anatomy\Season 8\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Music\iTunes\iTunes Media\TV Shows\Grey's Anatomy\Season 8\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Music\iTunes\iTunes Media\TV Shows\Grey's Anatomy\Season 9\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Music\iTunes\iTunes Media\TV Shows\Grey's Anatomy\Season 9\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\2009-01-01 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\2009-01-01 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\2009-01-01 002\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\2009-01-01 002\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\2009-01-01 003\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\2009-01-01 003\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\2009-01-01 004\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\2009-01-01 004\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\2009-01-01 005\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\2009-01-01 005\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\2009-11-10 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\2009-11-10 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\2013-10-26 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\2013-10-26 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\2013-12-28 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\2013-12-28 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\2013-12-29 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\2013-12-29 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\2014-02-24 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\2014-02-24 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\2014-02-28 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\2014-02-28 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\2014-02-28 002\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\2014-02-28 002\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\2014-03-08 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\2014-03-08 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\2014-03-08 002\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\2014-03-08 002\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\2014-07-13\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\2014-07-13\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\A Country Christmas 2011\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\A Country Christmas 2011\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\A Country Christmas 2011\2011-11-07 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\A Country Christmas 2011\2011-11-07 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\A Country Christmas 2011\2011-11-30 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\A Country Christmas 2011\2011-11-30 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\A Country Christmas 2011\2011-12-01 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\A Country Christmas 2011\2011-12-01 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\A Country Christmas 2011\2011-12-09 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\A Country Christmas 2011\2011-12-09 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\A Country Christmas 2011\2011-12-09 002\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\A Country Christmas 2011\2011-12-09 002\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\cats\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\cats\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\cats\buddy\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\cats\buddy\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\children's museum NE\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\children's museum NE\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Christmas 2010\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Christmas 2010\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Christmas 2010\2010-12-25 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Christmas 2010\2010-12-25 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\christmas decorations\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\christmas decorations\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Falcons game\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Falcons game\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\fall 2010\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\fall 2010\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\animals\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\animals\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\animals\2009-10-11 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\animals\2009-10-11 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\animals\2011-03-25 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\animals\2011-03-25 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\animals\2012-01-22 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\animals\2012-01-22 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2009-09-28 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2009-09-28 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2011-03-15 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2011-03-15 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2011-03-31 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2011-03-31 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2011-05-02 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2011-05-02 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2011-05-12 002\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2011-05-12 002\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2011-06-09 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2011-06-09 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2011-06-15 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2011-06-15 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2011-06-15 002\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2011-06-15 002\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2011-06-21 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2011-06-21 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2011-06-22 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2011-06-22 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2011-06-30 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2011-06-30 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2011-07-06 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2011-07-06 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2011-07-30 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2011-07-30 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2011-08-05 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2011-08-05 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2011-09-06 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2011-09-06 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2011-09-16 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2011-09-16 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2012-02-01 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2012-02-01 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2012-02-01 001\2012-02-01 002\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2012-02-01 001\2012-02-01 002\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2012-02-07 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2012-02-07 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2012-04-16 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2012-04-16 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2012-04-18 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2012-04-18 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2012-04-19 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\crops\2012-04-19 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\grand opening\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\grand opening\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\grand opening\2011-05-19 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\grand opening\2011-05-19 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\grand opening\2011-06-30 002\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\grand opening\2011-06-30 002\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\LOGO\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\LOGO\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\LOGO\2011-06-13 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\LOGO\2011-06-13 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\LOGO\2011-06-17 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\LOGO\2011-06-17 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\LOGO\2011-06-28 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\LOGO\2011-06-28 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\misc\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\misc\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\misc\2011-03-08 002\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\misc\2011-03-08 002\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\misc\2011-04-13 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\misc\2011-04-13 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\misc\2011-05-12 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\misc\2011-05-12 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\misc\2011-08-13 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\misc\2011-08-13 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\misc\2011-09-04 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\misc\2011-09-04 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\misc\2012-02-14 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Farm photos\misc\2012-02-14 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\fishing oct '10\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\fishing oct '10\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\fishing oct '10\fishing '10\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\fishing oct '10\fishing '10\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\FOR SALE items\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\FOR SALE items\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\FOR SALE items\2009-01-07 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\FOR SALE items\2009-01-07 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\FOR SALE items\2009-09-12 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\FOR SALE items\2009-09-12 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\FOR SALE items\2009-09-12 002\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\FOR SALE items\2009-09-12 002\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\FOR SALE items\2009-09-12 003\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\FOR SALE items\2009-09-12 003\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\FOR SALE items\2009-09-22 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\FOR SALE items\2009-09-22 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\FOR SALE items\2009-10-05 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\FOR SALE items\2009-10-05 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\FOR SALE items\2009-10-08 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\FOR SALE items\2009-10-08 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\gaffneys\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\gaffneys\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\gaffneys\2009-01-12 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\gaffneys\2009-01-12 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\gaffneys\Cheap Seats\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\gaffneys\Cheap Seats\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\gaffneys\food pics\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\gaffneys\food pics\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\guerry\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\guerry\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\halloween 09\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\halloween 09\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\halloween 2010\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\halloween 2010\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Halloween 2011\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Halloween 2011\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\ideas\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\ideas\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Jesse DEA graduation\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Jesse DEA graduation\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\JesseCourtney Wedding\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\JesseCourtney Wedding\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\mady\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\mady\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\mady\2009-03-03 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\mady\2009-03-03 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\mady\2011-01-29 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\mady\2011-01-29 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\mady\2012-01-28 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\mady\2012-01-28 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\mady\mady 1st bday\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\mady\mady 1st bday\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\omaha zoo\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\omaha zoo\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Pumpkin patch 2011\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Pumpkin patch 2011\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Pumpkin patch 2011\2011-08-04 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Pumpkin patch 2011\2011-08-04 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Pumpkin patch 2011\2011-08-28 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Pumpkin patch 2011\2011-08-28 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Pumpkin patch 2011\2011-09-07 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Pumpkin patch 2011\2011-09-07 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Pumpkin patch 2011\2011-09-13 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Pumpkin patch 2011\2011-09-13 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Pumpkin patch 2011\2011-10-05 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Pumpkin patch 2011\2011-10-05 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Pumpkin patch 2011\2011-10-06 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Pumpkin patch 2011\2011-10-06 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Pumpkin patch 2011\2011-10-31 002\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Pumpkin patch 2011\2011-10-31 002\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\pumpkin patch 2012\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\pumpkin patch 2012\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\pumpkin patch 2012\photo contest\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\pumpkin patch 2012\photo contest\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\pumpkin patch 2013\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\pumpkin patch 2013\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\pumpkin patch 2013\2009-11-02 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\pumpkin patch 2013\2009-11-02 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\pumpkin patch NE\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\pumpkin patch NE\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Rachel\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Rachel\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Rachel\2010-11-26 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Rachel\2010-11-26 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Rachel\2010-11-26 002\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\Rachel\2010-11-26 002\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\randon\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\randon\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\randon\2011-03-10 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\randon\2011-03-10 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\randon\2011-09-09 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\randon\2011-09-09 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\randon\2011-09-18 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\randon\2011-09-18 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\randon\2012-01-28 002\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\randon\2012-01-28 002\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\randon\2012-01-29 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\randon\2012-01-29 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\randon\random\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\randon\random\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\RES photos\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\RES photos\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\RES photos\1st self storage gate\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\RES photos\1st self storage gate\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\RES photos\2009-01-09 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\RES photos\2009-01-09 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\RES photos\2009-01-09 002\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\RES photos\2009-01-09 002\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\RES photos\2009-02-08 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\RES photos\2009-02-08 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\RES photos\2011-03-08 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\RES photos\2011-03-08 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\RES photos\2011-03-23 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\RES photos\2011-03-23 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\RES photos\2011-03-23 002\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\RES photos\2011-03-23 002\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\RES photos\mars theatre\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\RES photos\mars theatre\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\snowstorm '10\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\snowstorm '10\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\snowstorm '10\2010-12-26 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\snowstorm '10\2010-12-26 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\snowstorm '10\2011-03-27 001\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\snowstorm '10\2011-03-27 001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\thanksgiving 09\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\Pictures\thanksgiving 09\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Melissa\SkyDrive\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Melissa\SkyDrive\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Gaffney's Cheap Seats 1 - Images\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Gaffney's Cheap Seats 1 - Images\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Madrac Farms LLC Tax Form History\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Madrac Farms LLC Tax Form History\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Madrac Farms LLC Tax Form History\INWKS941\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Madrac Farms LLC Tax Form History\INWKS941\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Fri, Aug 17 2012 10 01 01 PM\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Fri, Aug 17 2012 10 01 01 PM\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Fri, Aug 17 2012 10 01 01 PM\TempCopyBeforeValidate\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Fri, Aug 17 2012 10 01 01 PM\TempCopyBeforeValidate\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Fri, Oct 07 2011 08 21 23 AM\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Fri, Oct 07 2011 08 21 23 AM\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Fri, Oct 07 2011 08 21 23 AM\TempCopyBeforeValidate\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Fri, Oct 07 2011 08 21 23 AM\TempCopyBeforeValidate\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Mon, Feb 11 2013 10 45 24 AM\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Mon, Feb 11 2013 10 45 24 AM\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Mon, Mar 11 2013 12 52 45 PM\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Mon, Mar 11 2013 12 52 45 PM\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Mon, Mar 11 2013 12 52 45 PM\TempCopyBeforeValidate\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Mon, Mar 11 2013 12 52 45 PM\TempCopyBeforeValidate\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Sat, Apr 07 2012 06 01 06 PM\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Sat, Apr 07 2012 06 01 06 PM\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Sun, Aug 03 2014 04 33 38 AM\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Sun, Aug 03 2014 04 33 38 AM\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Sun, Aug 03 2014 04 33 38 AM\TempCopyBeforeValidate\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Sun, Aug 03 2014 04 33 38 AM\TempCopyBeforeValidate\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Thu, Nov 07 2013 09 01 02 AM\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Thu, Nov 07 2013 09 01 02 AM\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Tue, Jun 14 2011 07 42 31 PM\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Tue, Jun 14 2011 07 42 31 PM\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Wed, Jun 12 2013 10 53 21 AM\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Wed, Jun 12 2013 10 53 21 AM\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Wed, Jun 12 2013 10 53 21 AM\TempCopyBeforeValidate\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Wed, Jun 12 2013 10 53 21 AM\TempCopyBeforeValidate\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QuickBooks Letter Templates\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QuickBooks Letter Templates\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QuickBooks Letter Templates\Collection Letters\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QuickBooks Letter Templates\Collection Letters\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QuickBooks Letter Templates\Customer Letters\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QuickBooks Letter Templates\Customer Letters\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QuickBooks Letter Templates\Employee Letters\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QuickBooks Letter Templates\Employee Letters\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QuickBooks Letter Templates\Estimate Letters\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QuickBooks Letter Templates\Estimate Letters\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QuickBooks Letter Templates\Invoice Letters\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QuickBooks Letter Templates\Invoice Letters\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QuickBooks Letter Templates\Other Names Letters\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QuickBooks Letter Templates\Other Names Letters\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QuickBooks Letter Templates\Vendor Letters\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QuickBooks Letter Templates\Vendor Letters\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Rahn's Electric - Images\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Rahn's Electric - Images\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Rahn's Electric Tax Form History\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Rahn's Electric Tax Form History\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Rahn's Electric Tax Form History\GADOL4NI\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Rahn's Electric Tax Form History\GADOL4NI\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Rahn's Electric Tax Form History\INWKS941\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Rahn's Electric Tax Form History\INWKS941\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\Letters_Templates\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\Letters_Templates\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\Letters_Templates\Collection Letters\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\Letters_Templates\Collection Letters\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\Letters_Templates\Customer Letters\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\Letters_Templates\Customer Letters\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\Letters_Templates\Employee Letters\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\Letters_Templates\Employee Letters\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\Letters_Templates\Estimate Letters\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\Letters_Templates\Estimate Letters\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\Letters_Templates\Invoice Letters\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\Letters_Templates\Invoice Letters\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\Letters_Templates\Other Names Letters\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\Letters_Templates\Other Names Letters\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\Letters_Templates\Vendor Letters\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\Letters_Templates\Vendor Letters\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\Letters_Templates\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\Letters_Templates\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\Letters_Templates\Collection Letters\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\Letters_Templates\Collection Letters\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\Letters_Templates\Customer Letters\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\Letters_Templates\Customer Letters\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\Letters_Templates\Employee Letters\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\Letters_Templates\Employee Letters\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\Letters_Templates\Estimate Letters\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\Letters_Templates\Estimate Letters\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\Letters_Templates\Invoice Letters\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\Letters_Templates\Invoice Letters\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\Letters_Templates\Other Names Letters\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\Letters_Templates\Other Names Letters\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\Letters_Templates\Vendor Letters\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\Letters_Templates\Vendor Letters\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Images\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Images\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Letters_Templates\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Letters_Templates\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Letters_Templates\Collection Letters\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Letters_Templates\Collection Letters\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Letters_Templates\Customer Letters\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Letters_Templates\Customer Letters\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Letters_Templates\Employee Letters\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Letters_Templates\Employee Letters\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Letters_Templates\Estimate Letters\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Letters_Templates\Estimate Letters\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Letters_Templates\Invoice Letters\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Letters_Templates\Invoice Letters\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Letters_Templates\Other Names Letters\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Letters_Templates\Other Names Letters\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Letters_Templates\Vendor Letters\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Letters_Templates\Vendor Letters\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Sample Company Files\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Sample Company Files\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Sample Company Files\QuickBooks 2012\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\Intuit\QuickBooks\Sample Company Files\QuickBooks 2012\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\Users\Public\Documents\ntr\DECRYPT_INSTRUCTION.HTML Win32/Filecoder.CR trojan
C:\Users\Public\Documents\ntr\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan

Juliet
2014-11-17, 03:45
Do you realize that you've been hit by an encryption malware?


Open notepad. Please copy the contents of the quote box below. To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)



start
CloseProcesses:
CMD: del /F /Q /S "C:\DECRYPT_INSTRUCTION.HTML"
CMD: del /F /Q /S "C:\DECRYPT_INSTRUCTION.TXT"
CMD: del /F /Q /S "C:\DECRYPT_INSTRUCTION.URL"
EmptyTemp:
End


Open FRST/FRST64 and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.


After you run this please run a new scan with FRST.
http://i739.photobucket.com/albums/xx33/emeraldnzl/FRSTicon.jpg (http://s739.photobucket.com/user/emeraldnzl/media/FRSTicon.jpg.html)
Don´t change the checkboxes just click on Scan.
Logfiles are created on your desktop.
Post the FRST.txt
Please ensure Addition.txt -button has a check next to it.
Please also paste that along with the FRST.txt into your reply.

gurleygirl
2014-11-17, 19:10
I do! And they wanted $500 in bitcoin to give me the encryption code. Not sure what I'm going to get my files back. Most are expendable, but the pics of my kids most important. Scanning now.

gurleygirl
2014-11-17, 21:47
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 16-11-2014 03
Ran by Melissa at 2014-11-17 12:13:53 Run:2
Running from C:\Users\Melissa\Desktop
Loaded Profile: Melissa (Available profiles: Melissa & QBDataServiceUser21)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
start
CloseProcesses:
CMD: del /F /Q /S "C:\DECRYPT_INSTRUCTION.HTML"
CMD: del /F /Q /S "C:\DECRYPT_INSTRUCTION.TXT"
CMD: del /F /Q /S "C:\DECRYPT_INSTRUCTION.URL"
EmptyTemp:
End
*****************

Processes closed successfully.

========= del /F /Q /S "C:\DECRYPT_INSTRUCTION.HTML" =========

Deleted file - C:\ProgramData\HP\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\HP\LGT\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\HP\LGT\Data\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\HP\LGT\Data\Models\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Images\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Images\B8500\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Images\B8800\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Images\C5300\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Images\C5500\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Images\C6300\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Images\D2500\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Images\D730\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Images\generic\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Images\J4500\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Images\J4660\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Images\J4680\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Images\J6400\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Movies\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\HP\LGT\Data\Templates\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\HP\LGT\Data\Templates\Images\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\HP\LGT 2.0\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\HP\LGT 2.0\data\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\HP\LGT 2.0\data\Models\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\HP\LGT 2.0\data\Models\HP Officejet 4500 G510n-z\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\HP\LGT 2.0\data\Models\HP Officejet 4500 G510n-z\Images\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\HP\LGT 2.0\data\sessions\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\HP\LGT 2.0\data\templates\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\HP\LGT 2.0\data\templates\Images\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\Entitlement Client\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\Entitlement Client\v5\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\Entitlement Client\v6.0\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\Entitlement Client\v8\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks\ReportCenter\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\Components\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Message\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Message\.update\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Message\.update\.target\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Message\.update\.target\85216424\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Message\.update\.target\85216424\content\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Patch\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Profile\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Profile\.update\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Profile\.update\.target\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Profile\.update\.target\85216424\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Profile\.update\.target\85216424\content\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DataProtect\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DataProtect\OCD\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DataProtect\ROLLBACK\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Message\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Message\.update\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Message\.update\.target\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Message\.update\.target\85216424\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Message\.update\.target\85216424\content\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\NewFeatures\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\NewFeatures\.update\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\NewFeatures\.update\.target\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Patch\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Payroll\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Payroll\.update\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Payroll\.update\.target\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Profile\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Profile\.update\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Profile\.update\.target\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Profile\.update\.target\85216424\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Profile\.update\.target\85216424\content\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\StateForms\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\StateForms\.update\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\StateForms\.update\.target\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\SyncMgr\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\SyncMgr\OCD\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2012\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2012\Components\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2012\Components\DataProtect\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2012\Components\DataProtect\OCD\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2012\Components\DownloadQB22\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2012\Components\DownloadQB22\SPatch\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2012\Components\OLB\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2012\Components\OLB\branding\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2012\Components\OLB\branding\filist\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2012\Components\OLB\workflow\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2012\Components\PDFDownload\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2012\Components\SyncMgr\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2012\Components\SyncMgr\OCD\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2013\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2013\Components\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2013\Components\DataProtect\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\QuickBooks 2013\Components\DataProtect\OCD\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Intuit\SyncManager\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Leapfrog\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\LeapPad2\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\LeapPad2\290E220001011026A25A\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\LeapPad2\2919220001011025F7B3\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\AltHomepage\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\AltHomepage\Landing\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\AltHomepage\Landing\images\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\Homepage\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\Homepage\Landing\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPad2\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPad2\Expandables\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPad2\Landing\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPad2\My Device\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPad2\My Device\images\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPadExplorer\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPadExplorer\Expandables\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPadExplorer\Landing\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPadExplorer\My Device\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPadExplorer\My Device\images\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\Tag\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\Tag\Landing\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\Tag\Landing\panels\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Light-O-Rama\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Light-O-Rama\Samples\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Macrovision\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Macrovision\FLEXnet Connect\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Macrovision\FLEXnet Connect\11\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Macrovision\FLEXnet Connect\11\ui\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Macrovision\FLEXnet Connect\11\ui\images\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Microsoft\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Microsoft\eHome\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Microsoft\RAC\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Microsoft\RAC\PublishedData\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Microsoft\RAC\StateData\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\PCDr\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\PCDr\6426\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\PCDr\6426\AddOnContent\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\PCDr\6426\AddOnContent\ba005e12-3139-4327-9f7a-9f2ea6a6c841-d3dc259c-4fe5-45a6-a2aa-aaba450ab883\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\PCDr\6426\AddOnDownloaderCache\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\PCDr\6426\datastore\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\PCDr\6426\Tonopah\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\PCDr\6426\Tonopah\db\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\PCDr\6426\Tonopah\manifest\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\PCDr\6426\Tonopah\upload\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\PCDr\Tonopah\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Skype\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Skype\Plugins\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Skype\Plugins\Local Cache\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Skype\Plugins\Plugins\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Skype\Plugins\Plugins\F57B48ADF2224F088EDD1A2B9BAD84E8\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Skype\Plugins\Plugins\F57B48ADF2224F088EDD1A2B9BAD84E8\Local Cache\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Sonic\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Spybot - Search & Destroy\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Spybot - Search & Destroy\Logs\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Spybot - Search & Destroy\Quarantine\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Windstream\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Windstream\Service Agent\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Services\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-PcWarranty\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-PcWarranty\en\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-RankingEcare\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-RankingEcare\en\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-RankingSecurityAndBackup\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-RankingSecurityAndBackup\en\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Upsell\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Upsell\Upsell-Bundles\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Upsell\Upsell-Bundles\en\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\RADIALPOINT-UI-HSD-1-0-0-A962FBAB\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\RADIALPOINT-UI-HSD-1-0-0-A962FBAB\en\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\RADIALPOINT-UI-HSD-1-0-0-A962FBAB\en\help\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Apple Computer\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Apple Computer\iTunes\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\DIRECTV Player\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\DIRECTV Player\Legal\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Google\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Google\Chrome\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Google\Chrome\User Data\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Google\Chrome\User Data\Default\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Google\Chrome\User Data\Default\databases\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\QBDataSync_OfflineLogs\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\QBDataSync_OfflineLogs\CB8D650F50892B47E040900A441A5554_Logs\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.2.23.4037\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.4.23.4010\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.4.23.4011\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.5.23.4005\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.5.23.4007\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.6.23.4001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.7.23.4002\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.7.23.4007\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.7.23.4016\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\6.0.24.4009\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\6.2.24.4107\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\6.3.24.4012\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\Current\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\TempSyncLogs\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\ehome\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Internet Explorer\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Media Player\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Media Player\Art Cache\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Media Player\Art Cache\LocalMLS\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Messenger\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Office\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Office\15.0\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Office\15.0\OfficeFileCache\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Photo Acquisition\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Windows Live Mail\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Windows Live Mail\Backup\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Windows Live Mail\Backup\new\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Windows Live Mail\Sentinel\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Windows Live Photo Acquisition\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Windows Mail\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Windows Mail\Backup\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Windows Mail\Backup\old\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Windows Mail\Stationery\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Windows Media\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Windows Media\12.0\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Windows Photo Gallery\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Windows Photo Gallery\Original Images\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft Games\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft Games\FreeCell\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\LocalLow\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\LocalLow\Adobe\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\LocalLow\Adobe\Acrobat\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\LocalLow\Adobe\Acrobat\10.0\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\LocalLow\DTV\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\LocalLow\DTV\PCShow\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\LocalLow\DTV\PCShow\catalogs\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\LocalLow\Microsoft\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\wbrubsjg.qge\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\wbrubsjg.qge\dvruwf3b.m52\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\wbrubsjg.qge\dvruwf3b.m52\1\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\wbrubsjg.qge\dvruwf3b.m52\1\s\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\wbrubsjg.qge\dvruwf3b.m52\1\s\eer4rru2aqwqtonnnklwiobyo3um0pgyaz3owxdir1tygg0egsaaacca\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\wbrubsjg.qge\dvruwf3b.m52\1\s\eer4rru2aqwqtonnnklwiobyo3um0pgyaz3owxdir1tygg0egsaaacca\f\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\wbrubsjg.qge\dvruwf3b.m52\1\s\psld1rq2evnjg2ki2ziatkouhebg2l4klzm3vvurqxwtu41pinaaahda\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\wbrubsjg.qge\dvruwf3b.m52\1\s\psld1rq2evnjg2ki2ziatkouhebg2l4klzm3vvurqxwtu41pinaaahda\f\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\LocalLow\Sun\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\LocalLow\Sun\Java\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\SystemCache\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\SystemCache\6.0\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\SystemCache\6.0\11\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\SystemCache\6.0\26\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\SystemCache\6.0\3\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\SystemCache\6.0\32\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\SystemCache\6.0\4\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\SystemCache\6.0\42\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\LocalLow\Sun\Java\jre1.6.0_22\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\OICE_15_974FA576_32C1D314_1139\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\OICE_15_974FA576_32C1D314_2CDE\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\Adobe\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\Adobe\Flash Player\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\Adobe\Flash Player\AssetCache\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\Adobe\Flash Player\AssetCache\T4QJTQHZ\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\Amazon\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\Amazon\MP3 Downloader\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\Dell\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\Dell\Dell Stage\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\Dell\Dell Stage\{6dedbe25-1baa-49d5-a314-3524143af6f7}\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\HP\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\HP\WebRegLogs\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Access\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\DbgClr\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\DbgClr\8.0\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Document Building Blocks\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Document Building Blocks\1033\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Document Building Blocks\1033\15\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Excel\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Excel\2013%20group%20schedule303277132184948787\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Excel\Field%20trip%20schedule%202014303920862365260351\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Excel\Field%20trip%20schedule%202014303970643328640619\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Excel\Field%20trip%20schedule%202014304010691630387985\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Excel\Field%20trip%20schedule%202014304028803416694882\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Excel\Field%20trip%20schedule%202014304039061652633985\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Signatures\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\15\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\15\Managed\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\15\Managed\SmartArt Graphics\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\15\Managed\SmartArt Graphics\1033\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\15\Managed\Word Document Building Blocks\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\15\Managed\Word Document Building Blocks\1033\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\Word Document Building Blocks\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\Word Document Building Blocks\1033\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\PCDr\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\PCDr\Installer\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\PCDr\Installer\Logs\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\Skype\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\Skype\melissa.reagan2\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\Skype\shared_dynco\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\AppData\Roaming\Skype\shared_httpfe\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Desktop\Audio\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Desktop\Sequences\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Desktop\Visualizations\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Desktop\Visualizations\Editor\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Desktop\Visualizations\Editor\LOR Visualizer Tutorial\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\Amazon MP3\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\Amazon MP3\logs\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\Bell computer\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\Bible Lutheran\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\business forms\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\Coffee bluff Marina\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\commercial bids\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\commercial bids\Marchesee\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\Contractors\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\Contractors\clay pevey\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\Contractors\jen jacs\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\Contractors\Long Builders\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\Countryside\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\employee documents\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\FT. Stewart Training Facility\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\gaffney's cheap seats\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\gaffney's cheap seats\cheap seats\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\gaffney's cheap seats\Cheap Seats menu landscape_files\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\gaffney's cheap seats\promos\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\Guerry\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\HAAF engagement\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\Heard elementary\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\Invoices\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\Largo Tibet\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\2012\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\Country Christmas\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\farmers market\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\newsletters\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\old stuff\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\old stuff\bag letters\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\press releases\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\pumpkin chunkin\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\pumpkin patch\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\pumpkin patch\2014\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\pumpkin patch\signs\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\recipes\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\Signs\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\Snow Day 2014_files\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\taxes\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\My Scans\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\OgeeChee\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\OLD jobs\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\OLD jobs\1259\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\OLD jobs\1259\1259 bid documents\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\OLD jobs\1259\CEFS\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\OLD jobs\1259\cerified payroll\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\OLD jobs\1259\pay app stuff\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\OLD jobs\1259\VNI\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\OLD jobs\728A\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\OLD jobs\AMC inc\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\OLD jobs\AMC inc\certified payroll\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\OLD jobs\blackshear\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\OLD jobs\commissary stuff\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\OLD jobs\Davita\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\OLD jobs\Eff Hospital\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\OLD jobs\Post office\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\certified payroll\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\pay application\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\pay application\10.25.10\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\pay application\11.24.10\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\pay application\8.25.10\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\pay application\9.25.10\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\southeastern contract - sub\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\waivers\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\OLD jobs\tom triplett park\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\OLD jobs\Verizon\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\OLD jobs\WT Dubois\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\personal\bank statements\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\personal\blogs\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\personal\resumes\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\pics\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\pics\mel&gue\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\pics\Rachel\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\pics\RES photos\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\pics\wedding\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\Scanned Documents\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\Taxes\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\Taxes\2011\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\Taxes\2011\1Q\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\Taxes\2011\2Q\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\Taxes\2011\3Q\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\Taxes\2011\end of year\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\Taxes\2012\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\Taxes\2012\1Q\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Documents\WBENC\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Music\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Music\Amazon MP3\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Music\Amazon MP3\Trans-Siberian Orchestra\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Music\Amazon MP3\Trans-Siberian Orchestra\Christmas Eve And Other Stories\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Music\Amazon MP3\Trans-Siberian Orchestra\The Lost Christmas Eve (U.S. Version)\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Music\iTunes\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Music\iTunes\iTunes Media\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Music\iTunes\iTunes Media\Movies\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Music\iTunes\iTunes Media\Movies\The Heat\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Music\iTunes\iTunes Media\TV Shows\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Music\iTunes\iTunes Media\TV Shows\Grey's Anatomy\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Music\iTunes\iTunes Media\TV Shows\Grey's Anatomy\Season 8\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Music\iTunes\iTunes Media\TV Shows\Grey's Anatomy\Season 9\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\2009-01-01 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\2009-01-01 002\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\2009-01-01 003\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\2009-01-01 004\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\2009-01-01 005\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\2009-11-10 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\2013-10-26 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\2013-12-28 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\2013-12-29 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\2014-02-24 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\2014-02-28 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\2014-02-28 002\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\2014-03-08 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\2014-03-08 002\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\2014-07-13\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\A Country Christmas 2011\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\A Country Christmas 2011\2011-11-07 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\A Country Christmas 2011\2011-11-30 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\A Country Christmas 2011\2011-12-01 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\A Country Christmas 2011\2011-12-09 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\A Country Christmas 2011\2011-12-09 002\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\cats\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\cats\buddy\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\children's museum NE\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Christmas 2010\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Christmas 2010\2010-12-25 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\christmas decorations\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Falcons game\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\fall 2010\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\animals\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\animals\2009-10-11 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\animals\2011-03-25 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\animals\2012-01-22 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2009-09-28 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-03-15 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-03-31 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-05-02 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-05-12 002\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-06-09 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-06-15 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-06-15 002\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-06-21 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-06-22 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-06-30 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-07-06 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-07-30 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-08-05 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-09-06 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-09-16 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2012-02-01 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2012-02-01 001\2012-02-01 002\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2012-02-07 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2012-04-16 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2012-04-18 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2012-04-19 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\grand opening\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\grand opening\2011-05-19 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\grand opening\2011-06-30 002\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\LOGO\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\LOGO\2011-06-13 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\LOGO\2011-06-17 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\LOGO\2011-06-28 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\misc\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\misc\2011-03-08 002\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\misc\2011-04-13 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\misc\2011-05-12 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\misc\2011-08-13 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\misc\2011-09-04 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Farm photos\misc\2012-02-14 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\fishing oct '10\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\fishing oct '10\fishing '10\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\FOR SALE items\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\FOR SALE items\2009-01-07 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\FOR SALE items\2009-09-12 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\FOR SALE items\2009-09-12 002\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\FOR SALE items\2009-09-12 003\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\FOR SALE items\2009-09-22 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\FOR SALE items\2009-10-05 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\FOR SALE items\2009-10-08 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\gaffneys\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\gaffneys\2009-01-12 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\gaffneys\Cheap Seats\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\gaffneys\food pics\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\guerry\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\halloween 09\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\halloween 2010\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Halloween 2011\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\ideas\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Jesse DEA graduation\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\JesseCourtney Wedding\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\mady\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\mady\2009-03-03 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\mady\2011-01-29 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\mady\2012-01-28 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\mady\mady 1st bday\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\omaha zoo\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Pumpkin patch 2011\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Pumpkin patch 2011\2011-08-04 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Pumpkin patch 2011\2011-08-28 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Pumpkin patch 2011\2011-09-07 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Pumpkin patch 2011\2011-09-13 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Pumpkin patch 2011\2011-10-05 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Pumpkin patch 2011\2011-10-06 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Pumpkin patch 2011\2011-10-31 002\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\pumpkin patch 2012\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\pumpkin patch 2012\photo contest\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\pumpkin patch 2013\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\pumpkin patch 2013\2009-11-02 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\pumpkin patch NE\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Rachel\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Rachel\2010-11-26 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\Rachel\2010-11-26 002\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\randon\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\randon\2011-03-10 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\randon\2011-09-09 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\randon\2011-09-18 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\randon\2012-01-28 002\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\randon\2012-01-29 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\randon\random\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\RES photos\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\RES photos\1st self storage gate\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\RES photos\2009-01-09 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\RES photos\2009-01-09 002\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\RES photos\2009-02-08 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\RES photos\2011-03-08 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\RES photos\2011-03-23 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\RES photos\2011-03-23 002\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\RES photos\mars theatre\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\snowstorm '10\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\snowstorm '10\2010-12-26 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\snowstorm '10\2011-03-27 001\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\Pictures\thanksgiving 09\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Melissa\SkyDrive\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Gaffney's Cheap Seats 1 - Images\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Madrac Farms LLC Tax Form History\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Madrac Farms LLC Tax Form History\INWKS941\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Fri, Aug 17 2012 10 01 01 PM\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Fri, Aug 17 2012 10 01 01 PM\TempCopyBeforeValidate\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Fri, Oct 07 2011 08 21 23 AM\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Fri, Oct 07 2011 08 21 23 AM\TempCopyBeforeValidate\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Mon, Feb 11 2013 10 45 24 AM\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Mon, Mar 11 2013 12 52 45 PM\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Mon, Mar 11 2013 12 52 45 PM\TempCopyBeforeValidate\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Sat, Apr 07 2012 06 01 06 PM\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Sun, Aug 03 2014 04 33 38 AM\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Sun, Aug 03 2014 04 33 38 AM\TempCopyBeforeValidate\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Thu, Nov 07 2013 09 01 02 AM\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Tue, Jun 14 2011 07 42 31 PM\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Wed, Jun 12 2013 10 53 21 AM\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Wed, Jun 12 2013 10 53 21 AM\TempCopyBeforeValidate\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QuickBooks Letter Templates\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QuickBooks Letter Templates\Collection Letters\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QuickBooks Letter Templates\Customer Letters\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QuickBooks Letter Templates\Employee Letters\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QuickBooks Letter Templates\Estimate Letters\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QuickBooks Letter Templates\Invoice Letters\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QuickBooks Letter Templates\Other Names Letters\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QuickBooks Letter Templates\Vendor Letters\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Rahn's Electric - Images\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Rahn's Electric Tax Form History\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Rahn's Electric Tax Form History\GADOL4NI\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Rahn's Electric Tax Form History\INWKS941\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\Letters_Templates\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\Letters_Templates\Collection Letters\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\Letters_Templates\Customer Letters\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\Letters_Templates\Employee Letters\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\Letters_Templates\Estimate Letters\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\Letters_Templates\Invoice Letters\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\Letters_Templates\Other Names Letters\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\Letters_Templates\Vendor Letters\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\Letters_Templates\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\Letters_Templates\Collection Letters\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\Letters_Templates\Customer Letters\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\Letters_Templates\Employee Letters\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\Letters_Templates\Estimate Letters\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\Letters_Templates\Invoice Letters\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\Letters_Templates\Other Names Letters\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\Letters_Templates\Vendor Letters\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Images\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Letters_Templates\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Letters_Templates\Collection Letters\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Letters_Templates\Customer Letters\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Letters_Templates\Employee Letters\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Letters_Templates\Estimate Letters\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Letters_Templates\Invoice Letters\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Letters_Templates\Other Names Letters\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Letters_Templates\Vendor Letters\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Sample Company Files\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Sample Company Files\QuickBooks 2012\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Public\Documents\ntr\DECRYPT_INSTRUCTION.HTML

========= End of CMD: =========


========= del /F /Q /S "C:\DECRYPT_INSTRUCTION.TXT" =========

Deleted file - C:\ProgramData\Dell\DellDock\Shortcuts\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\HP\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\HP\LGT\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\HP\LGT\Data\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\HP\LGT\Data\Models\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Images\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Images\B8500\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Images\B8800\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Images\C5300\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Images\C5500\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Images\C6300\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Images\D2500\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Images\D730\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Images\generic\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Images\J4500\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Images\J4660\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Images\J4680\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Images\J6400\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Movies\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\HP\LGT\Data\Templates\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\HP\LGT\Data\Templates\Images\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\HP\LGT 2.0\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\HP\LGT 2.0\data\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\HP\LGT 2.0\data\Models\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\HP\LGT 2.0\data\Models\HP Officejet 4500 G510n-z\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\HP\LGT 2.0\data\Models\HP Officejet 4500 G510n-z\Images\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\HP\LGT 2.0\data\sessions\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\HP\LGT 2.0\data\templates\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\HP\LGT 2.0\data\templates\Images\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\Entitlement Client\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\Entitlement Client\v5\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\Entitlement Client\v6.0\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\Entitlement Client\v8\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks\ReportCenter\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\Components\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Message\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Message\.update\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Message\.update\.target\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Message\.update\.target\85216424\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Message\.update\.target\85216424\content\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Patch\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Profile\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Profile\.update\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Profile\.update\.target\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Profile\.update\.target\85216424\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Profile\.update\.target\85216424\content\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DataProtect\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DataProtect\OCD\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DataProtect\ROLLBACK\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Message\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Message\.update\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Message\.update\.target\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Message\.update\.target\85216424\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Message\.update\.target\85216424\content\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\NewFeatures\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\NewFeatures\.update\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\NewFeatures\.update\.target\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Patch\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Payroll\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Payroll\.update\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Payroll\.update\.target\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Profile\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Profile\.update\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Profile\.update\.target\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Profile\.update\.target\85216424\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Profile\.update\.target\85216424\content\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\StateForms\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\StateForms\.update\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\StateForms\.update\.target\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\SyncMgr\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\SyncMgr\OCD\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2012\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2012\Components\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2012\Components\DataProtect\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2012\Components\DataProtect\OCD\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2012\Components\DownloadQB22\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2012\Components\DownloadQB22\SPatch\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2012\Components\OLB\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2012\Components\OLB\branding\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2012\Components\OLB\branding\filist\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2012\Components\OLB\workflow\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2012\Components\PDFDownload\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2012\Components\SyncMgr\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2012\Components\SyncMgr\OCD\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2013\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2013\Components\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2013\Components\DataProtect\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\QuickBooks 2013\Components\DataProtect\OCD\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Intuit\SyncManager\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Leapfrog\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\LeapPad2\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\LeapPad2\290E220001011026A25A\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\LeapPad2\2919220001011025F7B3\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\AltHomepage\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\AltHomepage\Landing\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\AltHomepage\Landing\images\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\Homepage\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\Homepage\Landing\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPad2\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPad2\Expandables\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPad2\Landing\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPad2\My Device\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPad2\My Device\images\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPadExplorer\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPadExplorer\Expandables\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPadExplorer\Landing\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPadExplorer\My Device\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPadExplorer\My Device\images\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\Tag\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\Tag\Landing\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\Tag\Landing\panels\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Light-O-Rama\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Light-O-Rama\Samples\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Macrovision\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Macrovision\FLEXnet Connect\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Macrovision\FLEXnet Connect\11\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Macrovision\FLEXnet Connect\11\ui\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Macrovision\FLEXnet Connect\11\ui\images\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Microsoft\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Microsoft\eHome\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Microsoft\RAC\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Microsoft\RAC\PublishedData\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Microsoft\RAC\StateData\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\PCDr\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\PCDr\6426\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\PCDr\6426\AddOnContent\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\PCDr\6426\AddOnContent\ba005e12-3139-4327-9f7a-9f2ea6a6c841-d3dc259c-4fe5-45a6-a2aa-aaba450ab883\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\PCDr\6426\AddOnDownloaderCache\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\PCDr\6426\datastore\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\PCDr\6426\Tonopah\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\PCDr\6426\Tonopah\db\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\PCDr\6426\Tonopah\manifest\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\PCDr\6426\Tonopah\upload\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\PCDr\Tonopah\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Skype\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Skype\Plugins\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Skype\Plugins\Local Cache\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Skype\Plugins\Plugins\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Skype\Plugins\Plugins\F57B48ADF2224F088EDD1A2B9BAD84E8\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Skype\Plugins\Plugins\F57B48ADF2224F088EDD1A2B9BAD84E8\Local Cache\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Sonic\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Spybot - Search & Destroy\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Spybot - Search & Destroy\Logs\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Spybot - Search & Destroy\Quarantine\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Windstream\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Windstream\Service Agent\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Services\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-PcWarranty\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-PcWarranty\en\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-RankingEcare\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-RankingEcare\en\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-RankingSecurityAndBackup\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-RankingSecurityAndBackup\en\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Upsell\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Upsell\Upsell-Bundles\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Upsell\Upsell-Bundles\en\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\RADIALPOINT-UI-HSD-1-0-0-A962FBAB\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\RADIALPOINT-UI-HSD-1-0-0-A962FBAB\en\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\RADIALPOINT-UI-HSD-1-0-0-A962FBAB\en\help\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Apple Computer\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Apple Computer\iTunes\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\DIRECTV Player\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\DIRECTV Player\Legal\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Google\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Google\Chrome\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Google\Chrome\User Data\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Google\Chrome\User Data\Default\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Google\Chrome\User Data\Default\databases\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\QBDataSync_OfflineLogs\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\QBDataSync_OfflineLogs\CB8D650F50892B47E040900A441A5554_Logs\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.2.23.4037\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.4.23.4010\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.4.23.4011\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.5.23.4005\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.5.23.4007\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.6.23.4001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.7.23.4002\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.7.23.4007\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.7.23.4016\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\6.0.24.4009\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\6.2.24.4107\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\6.3.24.4012\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\Current\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\TempSyncLogs\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\ehome\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Internet Explorer\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Media Player\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Media Player\Art Cache\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Media Player\Art Cache\LocalMLS\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Messenger\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Office\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Office\15.0\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Office\15.0\OfficeFileCache\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Photo Acquisition\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Windows Live Mail\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Windows Live Mail\Backup\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Windows Live Mail\Backup\new\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Windows Live Mail\Sentinel\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Windows Live Photo Acquisition\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Windows Mail\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Windows Mail\Backup\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Windows Mail\Backup\old\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Windows Mail\Stationery\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Windows Media\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Windows Media\12.0\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Windows Photo Gallery\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Windows Photo Gallery\Original Images\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft Games\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft Games\FreeCell\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\LocalLow\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\LocalLow\Adobe\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\LocalLow\Adobe\Acrobat\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\LocalLow\Adobe\Acrobat\10.0\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\LocalLow\DTV\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\LocalLow\DTV\PCShow\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\LocalLow\DTV\PCShow\catalogs\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\LocalLow\Microsoft\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\wbrubsjg.qge\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\wbrubsjg.qge\dvruwf3b.m52\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\wbrubsjg.qge\dvruwf3b.m52\1\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\wbrubsjg.qge\dvruwf3b.m52\1\s\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\wbrubsjg.qge\dvruwf3b.m52\1\s\eer4rru2aqwqtonnnklwiobyo3um0pgyaz3owxdir1tygg0egsaaacca\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\wbrubsjg.qge\dvruwf3b.m52\1\s\eer4rru2aqwqtonnnklwiobyo3um0pgyaz3owxdir1tygg0egsaaacca\f\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\wbrubsjg.qge\dvruwf3b.m52\1\s\psld1rq2evnjg2ki2ziatkouhebg2l4klzm3vvurqxwtu41pinaaahda\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\wbrubsjg.qge\dvruwf3b.m52\1\s\psld1rq2evnjg2ki2ziatkouhebg2l4klzm3vvurqxwtu41pinaaahda\f\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\LocalLow\Sun\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\LocalLow\Sun\Java\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\SystemCache\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\SystemCache\6.0\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\SystemCache\6.0\11\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\SystemCache\6.0\26\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\SystemCache\6.0\3\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\SystemCache\6.0\32\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\SystemCache\6.0\4\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\SystemCache\6.0\42\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\LocalLow\Sun\Java\jre1.6.0_22\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\OICE_15_974FA576_32C1D314_1139\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\OICE_15_974FA576_32C1D314_2CDE\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\Adobe\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\Adobe\Flash Player\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\Adobe\Flash Player\AssetCache\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\Adobe\Flash Player\AssetCache\T4QJTQHZ\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\Amazon\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\Amazon\MP3 Downloader\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\Dell\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\Dell\Dell Stage\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\Dell\Dell Stage\{6dedbe25-1baa-49d5-a314-3524143af6f7}\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\HP\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\HP\WebRegLogs\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Access\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\DbgClr\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\DbgClr\8.0\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Document Building Blocks\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Document Building Blocks\1033\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Document Building Blocks\1033\15\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Excel\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Excel\2013%20group%20schedule303277132184948787\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Excel\Field%20trip%20schedule%202014303920862365260351\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Excel\Field%20trip%20schedule%202014303970643328640619\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Excel\Field%20trip%20schedule%202014304010691630387985\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Excel\Field%20trip%20schedule%202014304028803416694882\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Excel\Field%20trip%20schedule%202014304039061652633985\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Signatures\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\15\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\15\Managed\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\15\Managed\SmartArt Graphics\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\15\Managed\SmartArt Graphics\1033\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\15\Managed\Word Document Building Blocks\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\15\Managed\Word Document Building Blocks\1033\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\Word Document Building Blocks\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\Word Document Building Blocks\1033\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\PCDr\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\PCDr\Installer\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\PCDr\Installer\Logs\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\Skype\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\Skype\melissa.reagan2\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\Skype\shared_dynco\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\AppData\Roaming\Skype\shared_httpfe\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Desktop\Audio\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Desktop\Sequences\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Desktop\Visualizations\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Desktop\Visualizations\Editor\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Desktop\Visualizations\Editor\LOR Visualizer Tutorial\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\Amazon MP3\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\Amazon MP3\logs\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\Bell computer\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\Bible Lutheran\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\business forms\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\Coffee bluff Marina\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\commercial bids\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\commercial bids\Marchesee\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\Contractors\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\Contractors\clay pevey\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\Contractors\jen jacs\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\Contractors\Long Builders\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\Countryside\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\employee documents\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\FT. Stewart Training Facility\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\gaffney's cheap seats\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\gaffney's cheap seats\cheap seats\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\gaffney's cheap seats\Cheap Seats menu landscape_files\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\gaffney's cheap seats\promos\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\Guerry\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\HAAF engagement\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\Heard elementary\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\Invoices\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\Largo Tibet\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\2012\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\Country Christmas\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\farmers market\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\newsletters\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\old stuff\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\old stuff\bag letters\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\press releases\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\pumpkin chunkin\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\pumpkin patch\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\pumpkin patch\2014\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\pumpkin patch\signs\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\recipes\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\Signs\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\Snow Day 2014_files\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\taxes\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\My Scans\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\OgeeChee\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\OLD jobs\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\OLD jobs\1259\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\OLD jobs\1259\1259 bid documents\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\OLD jobs\1259\CEFS\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\OLD jobs\1259\cerified payroll\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\OLD jobs\1259\pay app stuff\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\OLD jobs\1259\VNI\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\OLD jobs\728A\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\OLD jobs\AMC inc\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\OLD jobs\AMC inc\certified payroll\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\OLD jobs\blackshear\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\OLD jobs\commissary stuff\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\OLD jobs\Davita\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\OLD jobs\Eff Hospital\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\OLD jobs\Post office\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\certified payroll\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\pay application\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\pay application\10.25.10\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\pay application\11.24.10\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\pay application\8.25.10\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\pay application\9.25.10\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\southeastern contract - sub\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\waivers\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\OLD jobs\tom triplett park\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\OLD jobs\Verizon\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\OLD jobs\WT Dubois\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\personal\bank statements\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\personal\blogs\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\personal\resumes\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\pics\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\pics\mel&gue\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\pics\Rachel\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\pics\RES photos\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\pics\wedding\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\Scanned Documents\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\Taxes\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\Taxes\2011\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\Taxes\2011\1Q\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\Taxes\2011\2Q\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\Taxes\2011\3Q\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\Taxes\2011\end of year\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\Taxes\2012\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\Taxes\2012\1Q\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Documents\WBENC\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Music\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Music\Amazon MP3\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Music\Amazon MP3\Trans-Siberian Orchestra\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Music\Amazon MP3\Trans-Siberian Orchestra\Christmas Eve And Other Stories\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Music\Amazon MP3\Trans-Siberian Orchestra\The Lost Christmas Eve (U.S. Version)\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Music\iTunes\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Music\iTunes\iTunes Media\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Music\iTunes\iTunes Media\Movies\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Music\iTunes\iTunes Media\Movies\The Heat\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Music\iTunes\iTunes Media\TV Shows\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Music\iTunes\iTunes Media\TV Shows\Grey's Anatomy\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Music\iTunes\iTunes Media\TV Shows\Grey's Anatomy\Season 8\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Music\iTunes\iTunes Media\TV Shows\Grey's Anatomy\Season 9\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\2009-01-01 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\2009-01-01 002\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\2009-01-01 003\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\2009-01-01 004\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\2009-01-01 005\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\2009-11-10 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\2013-10-26 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\2013-12-28 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\2013-12-29 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\2014-02-24 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\2014-02-28 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\2014-02-28 002\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\2014-03-08 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\2014-03-08 002\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\2014-07-13\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\A Country Christmas 2011\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\A Country Christmas 2011\2011-11-07 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\A Country Christmas 2011\2011-11-30 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\A Country Christmas 2011\2011-12-01 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\A Country Christmas 2011\2011-12-09 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\A Country Christmas 2011\2011-12-09 002\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\cats\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\cats\buddy\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\children's museum NE\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Christmas 2010\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Christmas 2010\2010-12-25 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\christmas decorations\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Falcons game\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\fall 2010\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\animals\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\animals\2009-10-11 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\animals\2011-03-25 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\animals\2012-01-22 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2009-09-28 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-03-15 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-03-31 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-05-02 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-05-12 002\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-06-09 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-06-15 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-06-15 002\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-06-21 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-06-22 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-06-30 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-07-06 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-07-30 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-08-05 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-09-06 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-09-16 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2012-02-01 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2012-02-01 001\2012-02-01 002\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2012-02-07 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2012-04-16 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2012-04-18 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2012-04-19 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\grand opening\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\grand opening\2011-05-19 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\grand opening\2011-06-30 002\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\LOGO\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\LOGO\2011-06-13 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\LOGO\2011-06-17 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\LOGO\2011-06-28 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\misc\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\misc\2011-03-08 002\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\misc\2011-04-13 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\misc\2011-05-12 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\misc\2011-08-13 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\misc\2011-09-04 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Farm photos\misc\2012-02-14 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\fishing oct '10\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\fishing oct '10\fishing '10\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\FOR SALE items\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\FOR SALE items\2009-01-07 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\FOR SALE items\2009-09-12 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\FOR SALE items\2009-09-12 002\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\FOR SALE items\2009-09-12 003\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\FOR SALE items\2009-09-22 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\FOR SALE items\2009-10-05 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\FOR SALE items\2009-10-08 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\gaffneys\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\gaffneys\2009-01-12 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\gaffneys\Cheap Seats\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\gaffneys\food pics\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\guerry\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\halloween 09\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\halloween 2010\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Halloween 2011\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\ideas\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Jesse DEA graduation\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\JesseCourtney Wedding\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\mady\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\mady\2009-03-03 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\mady\2011-01-29 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\mady\2012-01-28 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\mady\mady 1st bday\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\omaha zoo\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Pumpkin patch 2011\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Pumpkin patch 2011\2011-08-04 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Pumpkin patch 2011\2011-08-28 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Pumpkin patch 2011\2011-09-07 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Pumpkin patch 2011\2011-09-13 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Pumpkin patch 2011\2011-10-05 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Pumpkin patch 2011\2011-10-06 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Pumpkin patch 2011\2011-10-31 002\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\pumpkin patch 2012\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\pumpkin patch 2012\photo contest\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\pumpkin patch 2013\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\pumpkin patch 2013\2009-11-02 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\pumpkin patch NE\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Rachel\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Rachel\2010-11-26 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\Rachel\2010-11-26 002\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\randon\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\randon\2011-03-10 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\randon\2011-09-09 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\randon\2011-09-18 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\randon\2012-01-28 002\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\randon\2012-01-29 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\randon\random\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\RES photos\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\RES photos\1st self storage gate\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\RES photos\2009-01-09 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\RES photos\2009-01-09 002\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\RES photos\2009-02-08 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\RES photos\2011-03-08 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\RES photos\2011-03-23 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\RES photos\2011-03-23 002\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\RES photos\mars theatre\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\snowstorm '10\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\snowstorm '10\2010-12-26 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\snowstorm '10\2011-03-27 001\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\Pictures\thanksgiving 09\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Melissa\SkyDrive\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Gaffney's Cheap Seats 1 - Images\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Madrac Farms LLC Tax Form History\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Madrac Farms LLC Tax Form History\INWKS941\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Fri, Aug 17 2012 10 01 01 PM\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Fri, Aug 17 2012 10 01 01 PM\TempCopyBeforeValidate\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Fri, Oct 07 2011 08 21 23 AM\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Fri, Oct 07 2011 08 21 23 AM\TempCopyBeforeValidate\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Mon, Feb 11 2013 10 45 24 AM\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Mon, Mar 11 2013 12 52 45 PM\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Mon, Mar 11 2013 12 52 45 PM\TempCopyBeforeValidate\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Sat, Apr 07 2012 06 01 06 PM\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Sun, Aug 03 2014 04 33 38 AM\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Sun, Aug 03 2014 04 33 38 AM\TempCopyBeforeValidate\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Thu, Nov 07 2013 09 01 02 AM\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Tue, Jun 14 2011 07 42 31 PM\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Wed, Jun 12 2013 10 53 21 AM\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Wed, Jun 12 2013 10 53 21 AM\TempCopyBeforeValidate\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QuickBooks Letter Templates\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QuickBooks Letter Templates\Collection Letters\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QuickBooks Letter Templates\Customer Letters\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QuickBooks Letter Templates\Employee Letters\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QuickBooks Letter Templates\Estimate Letters\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QuickBooks Letter Templates\Invoice Letters\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QuickBooks Letter Templates\Other Names Letters\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QuickBooks Letter Templates\Vendor Letters\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Rahn's Electric - Images\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Rahn's Electric Tax Form History\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Rahn's Electric Tax Form History\GADOL4NI\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Rahn's Electric Tax Form History\INWKS941\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\Letters_Templates\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\Letters_Templates\Collection Letters\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\Letters_Templates\Customer Letters\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\Letters_Templates\Employee Letters\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\Letters_Templates\Estimate Letters\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\Letters_Templates\Invoice Letters\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\Letters_Templates\Other Names Letters\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\Letters_Templates\Vendor Letters\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\Letters_Templates\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\Letters_Templates\Collection Letters\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\Letters_Templates\Customer Letters\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\Letters_Templates\Employee Letters\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\Letters_Templates\Estimate Letters\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\Letters_Templates\Invoice Letters\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\Letters_Templates\Other Names Letters\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\Letters_Templates\Vendor Letters\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Images\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Letters_Templates\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Letters_Templates\Collection Letters\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Letters_Templates\Customer Letters\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Letters_Templates\Employee Letters\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Letters_Templates\Estimate Letters\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Letters_Templates\Invoice Letters\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Letters_Templates\Other Names Letters\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Letters_Templates\Vendor Letters\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Sample Company Files\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Sample Company Files\QuickBooks 2012\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Public\Documents\ntr\DECRYPT_INSTRUCTION.TXT

========= End of CMD: =========


========= del /F /Q /S "C:\DECRYPT_INSTRUCTION.URL" =========

Deleted file - C:\DECRYPT_INSTRUCTION.URL
Deleted file - C:\$Recycle.Bin\DECRYPT_INSTRUCTION.URL
Deleted file - C:\$Recycle.Bin\S-1-5-21-3154378874-1875084861-2286133563-1001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Dell\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Dell\SEULAS\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69\x64\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Dell\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Dell\DellDock\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Dell\DellDock\images\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Dell\DellDock\Shortcuts\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\HP\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\HP\LGT\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\HP\LGT\Data\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\HP\LGT\Data\Models\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Images\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Images\B8500\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Images\B8800\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Images\C5300\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Images\C5500\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Images\C6300\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Images\D2500\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Images\D730\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Images\generic\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Images\J4500\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Images\J4660\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Images\J4680\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Images\J6400\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\HP\LGT\Data\Models\Movies\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\HP\LGT\Data\Templates\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\HP\LGT\Data\Templates\Images\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\HP\LGT 2.0\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\HP\LGT 2.0\data\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\HP\LGT 2.0\data\Models\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\HP\LGT 2.0\data\Models\HP Officejet 4500 G510n-z\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\HP\LGT 2.0\data\Models\HP Officejet 4500 G510n-z\Images\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\HP\LGT 2.0\data\sessions\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\HP\LGT 2.0\data\templates\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\HP\LGT 2.0\data\templates\Images\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\Entitlement Client\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\Entitlement Client\v5\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\Entitlement Client\v6.0\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\Entitlement Client\v8\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks\ReportCenter\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\Components\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Message\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Message\.update\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Message\.update\.target\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Message\.update\.target\85216424\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Message\.update\.target\85216424\content\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Patch\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Profile\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Profile\.update\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Profile\.update\.target\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Profile\.update\.target\85216424\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2008\Components\DownloadQB18\Profile\.update\.target\85216424\content\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DataProtect\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DataProtect\OCD\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DataProtect\ROLLBACK\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Message\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Message\.update\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Message\.update\.target\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Message\.update\.target\85216424\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Message\.update\.target\85216424\content\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\NewFeatures\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\NewFeatures\.update\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\NewFeatures\.update\.target\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Patch\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Payroll\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Payroll\.update\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Payroll\.update\.target\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Profile\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Profile\.update\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Profile\.update\.target\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Profile\.update\.target\85216424\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\Profile\.update\.target\85216424\content\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\StateForms\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\StateForms\.update\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\DownloadQB21\StateForms\.update\.target\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\SyncMgr\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2011_03.15.04.57\Components\SyncMgr\OCD\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2012\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2012\Components\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2012\Components\DataProtect\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2012\Components\DataProtect\OCD\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2012\Components\DownloadQB22\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2012\Components\DownloadQB22\SPatch\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2012\Components\OLB\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2012\Components\OLB\branding\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2012\Components\OLB\branding\filist\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2012\Components\OLB\workflow\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2012\Components\PDFDownload\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2012\Components\SyncMgr\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2012\Components\SyncMgr\OCD\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2013\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2013\Components\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2013\Components\DataProtect\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\QuickBooks 2013\Components\DataProtect\OCD\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Intuit\SyncManager\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Leapfrog\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\LeapPad2\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\LeapPad2\290E220001011026A25A\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\LeapPad2\2919220001011025F7B3\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\AltHomepage\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\AltHomepage\Landing\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\AltHomepage\Landing\images\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\Homepage\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\Homepage\Landing\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPad2\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPad2\Expandables\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPad2\Landing\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPad2\My Device\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPad2\My Device\images\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPadExplorer\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPadExplorer\Expandables\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPadExplorer\Landing\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPadExplorer\My Device\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\LeapPadExplorer\My Device\images\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\Tag\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\Tag\Landing\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Leapfrog\LeapFrog Connect\TempFlashFiles\Tag\Landing\panels\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Light-O-Rama\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Light-O-Rama\Samples\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Macrovision\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Macrovision\FLEXnet Connect\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Macrovision\FLEXnet Connect\11\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Macrovision\FLEXnet Connect\11\ui\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Macrovision\FLEXnet Connect\11\ui\images\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Microsoft\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Microsoft\eHome\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Microsoft\RAC\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Microsoft\RAC\PublishedData\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Microsoft\RAC\StateData\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\PCDr\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\PCDr\6426\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\PCDr\6426\AddOnContent\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\PCDr\6426\AddOnContent\ba005e12-3139-4327-9f7a-9f2ea6a6c841-d3dc259c-4fe5-45a6-a2aa-aaba450ab883\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\PCDr\6426\AddOnDownloaderCache\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\PCDr\6426\datastore\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\PCDr\6426\Tonopah\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\PCDr\6426\Tonopah\db\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\PCDr\6426\Tonopah\manifest\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\PCDr\6426\Tonopah\upload\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\PCDr\Tonopah\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Skype\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Skype\Plugins\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Skype\Plugins\Local Cache\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Skype\Plugins\Plugins\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Skype\Plugins\Plugins\F57B48ADF2224F088EDD1A2B9BAD84E8\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Skype\Plugins\Plugins\F57B48ADF2224F088EDD1A2B9BAD84E8\Local Cache\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Sonic\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Spybot - Search & Destroy\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Spybot - Search & Destroy\Logs\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Spybot - Search & Destroy\Quarantine\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Windstream\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Windstream\Service Agent\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Services\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-PcWarranty\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-PcWarranty\en\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-RankingEcare\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-RankingEcare\en\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-RankingSecurityAndBackup\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Services\Service-RankingSecurityAndBackup\en\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Upsell\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Upsell\Upsell-Bundles\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\DataDefinition-Upsell\Upsell-Bundles\en\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\RADIALPOINT-UI-HSD-1-0-0-A962FBAB\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\RADIALPOINT-UI-HSD-1-0-0-A962FBAB\en\DECRYPT_INSTRUCTION.URL
Deleted file - C:\ProgramData\Windstream\Service Agent\UiSections\RADIALPOINT-UI-HSD-1-0-0-A962FBAB\en\help\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Apple Computer\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Apple Computer\iTunes\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\DIRECTV Player\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\DIRECTV Player\Legal\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Google\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Google\Chrome\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Google\Chrome\User Data\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Google\Chrome\User Data\Default\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Google\Chrome\User Data\Default\databases\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\QBDataSync_OfflineLogs\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\QBDataSync_OfflineLogs\CB8D650F50892B47E040900A441A5554_Logs\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.2.23.4037\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.4.23.4010\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.4.23.4011\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.5.23.4005\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.5.23.4007\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.6.23.4001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.7.23.4002\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.7.23.4007\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\5.7.23.4016\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\6.0.24.4009\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\6.2.24.4107\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\6.3.24.4012\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\SyncManager\Current\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Intuit\TempSyncLogs\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\ehome\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Internet Explorer\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Media Player\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Media Player\Art Cache\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Media Player\Art Cache\LocalMLS\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Messenger\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Office\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Office\15.0\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Office\15.0\OfficeFileCache\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Photo Acquisition\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Windows Live Mail\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Windows Live Mail\Backup\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Windows Live Mail\Backup\new\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Windows Live Mail\Sentinel\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Windows Live Photo Acquisition\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Windows Mail\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Windows Mail\Backup\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Windows Mail\Backup\old\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Windows Mail\Stationery\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Windows Media\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Windows Media\12.0\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Windows Photo Gallery\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft\Windows Photo Gallery\Original Images\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft Games\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Local\Microsoft Games\FreeCell\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\LocalLow\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\LocalLow\Adobe\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\LocalLow\Adobe\Acrobat\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\LocalLow\Adobe\Acrobat\10.0\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\LocalLow\DTV\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\LocalLow\DTV\PCShow\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\LocalLow\DTV\PCShow\catalogs\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\LocalLow\Microsoft\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\wbrubsjg.qge\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\wbrubsjg.qge\dvruwf3b.m52\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\wbrubsjg.qge\dvruwf3b.m52\1\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\wbrubsjg.qge\dvruwf3b.m52\1\s\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\wbrubsjg.qge\dvruwf3b.m52\1\s\eer4rru2aqwqtonnnklwiobyo3um0pgyaz3owxdir1tygg0egsaaacca\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\wbrubsjg.qge\dvruwf3b.m52\1\s\eer4rru2aqwqtonnnklwiobyo3um0pgyaz3owxdir1tygg0egsaaacca\f\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\wbrubsjg.qge\dvruwf3b.m52\1\s\psld1rq2evnjg2ki2ziatkouhebg2l4klzm3vvurqxwtu41pinaaahda\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\LocalLow\Microsoft\Silverlight\is\wbrubsjg.qge\dvruwf3b.m52\1\s\psld1rq2evnjg2ki2ziatkouhebg2l4klzm3vvurqxwtu41pinaaahda\f\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\LocalLow\Sun\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\LocalLow\Sun\Java\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\SystemCache\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\SystemCache\6.0\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\SystemCache\6.0\11\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\SystemCache\6.0\26\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\SystemCache\6.0\3\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\SystemCache\6.0\32\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\SystemCache\6.0\4\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\LocalLow\Sun\Java\Deployment\SystemCache\6.0\42\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\LocalLow\Sun\Java\jre1.6.0_22\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\OICE_15_974FA576_32C1D314_1139\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\OICE_15_974FA576_32C1D314_2CDE\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\Adobe\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\Adobe\Flash Player\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\Adobe\Flash Player\AssetCache\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\Adobe\Flash Player\AssetCache\T4QJTQHZ\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\Amazon\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\Amazon\MP3 Downloader\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\Dell\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\Dell\Dell Stage\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\Dell\Dell Stage\{6dedbe25-1baa-49d5-a314-3524143af6f7}\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\HP\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\HP\WebRegLogs\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Access\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\DbgClr\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\DbgClr\8.0\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Document Building Blocks\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Document Building Blocks\1033\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Document Building Blocks\1033\15\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Excel\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Excel\2013%20group%20schedule303277132184948787\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Excel\Field%20trip%20schedule%202014303920862365260351\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Excel\Field%20trip%20schedule%202014303970643328640619\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Excel\Field%20trip%20schedule%202014304010691630387985\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Excel\Field%20trip%20schedule%202014304028803416694882\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Excel\Field%20trip%20schedule%202014304039061652633985\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Signatures\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\15\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\15\Managed\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\15\Managed\SmartArt Graphics\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\15\Managed\SmartArt Graphics\1033\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\15\Managed\Word Document Building Blocks\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\15\Managed\Word Document Building Blocks\1033\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\Word Document Building Blocks\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\Word Document Building Blocks\1033\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\PCDr\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\PCDr\Installer\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\PCDr\Installer\Logs\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\Skype\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\Skype\melissa.reagan2\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\Skype\shared_dynco\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\AppData\Roaming\Skype\shared_httpfe\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Desktop\Audio\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Desktop\Sequences\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Desktop\Visualizations\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Desktop\Visualizations\Editor\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Desktop\Visualizations\Editor\LOR Visualizer Tutorial\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\Amazon MP3\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\Amazon MP3\logs\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\Bell computer\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\Bible Lutheran\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\business forms\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\Coffee bluff Marina\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\commercial bids\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\commercial bids\Marchesee\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\Contractors\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\Contractors\clay pevey\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\Contractors\jen jacs\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\Contractors\Long Builders\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\Countryside\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\employee documents\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\FT. Stewart Training Facility\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\gaffney's cheap seats\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\gaffney's cheap seats\cheap seats\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\gaffney's cheap seats\Cheap Seats menu landscape_files\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\gaffney's cheap seats\promos\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\Guerry\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\HAAF engagement\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\Heard elementary\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\Invoices\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\Largo Tibet\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\2012\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\Country Christmas\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\farmers market\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\newsletters\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\old stuff\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\old stuff\bag letters\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\press releases\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\pumpkin chunkin\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\pumpkin patch\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\pumpkin patch\2014\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\pumpkin patch\signs\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\recipes\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\Signs\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\Snow Day 2014_files\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\MAdrac Farms\taxes\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\My Scans\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\OgeeChee\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\OLD jobs\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\OLD jobs\1259\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\OLD jobs\1259\1259 bid documents\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\OLD jobs\1259\CEFS\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\OLD jobs\1259\cerified payroll\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\OLD jobs\1259\pay app stuff\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\OLD jobs\1259\VNI\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\OLD jobs\728A\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\OLD jobs\AMC inc\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\OLD jobs\AMC inc\certified payroll\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\OLD jobs\blackshear\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\OLD jobs\commissary stuff\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\OLD jobs\Davita\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\OLD jobs\Eff Hospital\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\OLD jobs\Post office\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\certified payroll\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\pay application\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\pay application\10.25.10\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\pay application\11.24.10\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\pay application\8.25.10\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\pay application\9.25.10\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\southeastern contract - sub\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\OLD jobs\Savannah Fire\waivers\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\OLD jobs\tom triplett park\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\OLD jobs\Verizon\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\OLD jobs\WT Dubois\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\personal\bank statements\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\personal\blogs\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\personal\resumes\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\pics\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\pics\mel&gue\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\pics\Rachel\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\pics\RES photos\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\pics\wedding\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\Scanned Documents\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\Taxes\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\Taxes\2011\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\Taxes\2011\1Q\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\Taxes\2011\2Q\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\Taxes\2011\3Q\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\Taxes\2011\end of year\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\Taxes\2012\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\Taxes\2012\1Q\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Documents\WBENC\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Music\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Music\Amazon MP3\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Music\Amazon MP3\Trans-Siberian Orchestra\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Music\Amazon MP3\Trans-Siberian Orchestra\Christmas Eve And Other Stories\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Music\Amazon MP3\Trans-Siberian Orchestra\The Lost Christmas Eve (U.S. Version)\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Music\iTunes\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Music\iTunes\iTunes Media\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Music\iTunes\iTunes Media\Movies\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Music\iTunes\iTunes Media\Movies\The Heat\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Music\iTunes\iTunes Media\TV Shows\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Music\iTunes\iTunes Media\TV Shows\Grey's Anatomy\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Music\iTunes\iTunes Media\TV Shows\Grey's Anatomy\Season 8\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Music\iTunes\iTunes Media\TV Shows\Grey's Anatomy\Season 9\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\2009-01-01 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\2009-01-01 002\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\2009-01-01 003\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\2009-01-01 004\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\2009-01-01 005\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\2009-11-10 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\2013-10-26 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\2013-12-28 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\2013-12-29 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\2014-02-24 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\2014-02-28 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\2014-02-28 002\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\2014-03-08 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\2014-03-08 002\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\2014-07-13\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\A Country Christmas 2011\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\A Country Christmas 2011\2011-11-07 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\A Country Christmas 2011\2011-11-30 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\A Country Christmas 2011\2011-12-01 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\A Country Christmas 2011\2011-12-09 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\A Country Christmas 2011\2011-12-09 002\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\cats\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\cats\buddy\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\children's museum NE\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Christmas 2010\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Christmas 2010\2010-12-25 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\christmas decorations\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Falcons game\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\fall 2010\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\animals\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\animals\2009-10-11 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\animals\2011-03-25 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\animals\2012-01-22 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2009-09-28 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-03-15 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-03-31 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-05-02 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-05-12 002\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-06-09 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-06-15 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-06-15 002\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-06-21 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-06-22 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-06-30 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-07-06 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-07-30 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-08-05 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-09-06 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2011-09-16 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2012-02-01 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2012-02-01 001\2012-02-01 002\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2012-02-07 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2012-04-16 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2012-04-18 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\crops\2012-04-19 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\grand opening\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\grand opening\2011-05-19 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\grand opening\2011-06-30 002\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\LOGO\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\LOGO\2011-06-13 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\LOGO\2011-06-17 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\LOGO\2011-06-28 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\misc\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\misc\2011-03-08 002\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\misc\2011-04-13 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\misc\2011-05-12 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\misc\2011-08-13 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\misc\2011-09-04 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Farm photos\misc\2012-02-14 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\fishing oct '10\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\fishing oct '10\fishing '10\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\FOR SALE items\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\FOR SALE items\2009-01-07 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\FOR SALE items\2009-09-12 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\FOR SALE items\2009-09-12 002\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\FOR SALE items\2009-09-12 003\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\FOR SALE items\2009-09-22 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\FOR SALE items\2009-10-05 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\FOR SALE items\2009-10-08 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\gaffneys\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\gaffneys\2009-01-12 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\gaffneys\Cheap Seats\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\gaffneys\food pics\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\guerry\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\halloween 09\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\halloween 2010\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Halloween 2011\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\ideas\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Jesse DEA graduation\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\JesseCourtney Wedding\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\mady\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\mady\2009-03-03 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\mady\2011-01-29 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\mady\2012-01-28 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\mady\mady 1st bday\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\omaha zoo\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Pumpkin patch 2011\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Pumpkin patch 2011\2011-08-04 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Pumpkin patch 2011\2011-08-28 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Pumpkin patch 2011\2011-09-07 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Pumpkin patch 2011\2011-09-13 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Pumpkin patch 2011\2011-10-05 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Pumpkin patch 2011\2011-10-06 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Pumpkin patch 2011\2011-10-31 002\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\pumpkin patch 2012\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\pumpkin patch 2012\photo contest\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\pumpkin patch 2013\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\pumpkin patch 2013\2009-11-02 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\pumpkin patch NE\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Rachel\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Rachel\2010-11-26 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\Rachel\2010-11-26 002\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\randon\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\randon\2011-03-10 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\randon\2011-09-09 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\randon\2011-09-18 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\randon\2012-01-28 002\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\randon\2012-01-29 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\randon\random\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\RES photos\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\RES photos\1st self storage gate\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\RES photos\2009-01-09 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\RES photos\2009-01-09 002\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\RES photos\2009-02-08 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\RES photos\2011-03-08 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\RES photos\2011-03-23 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\RES photos\2011-03-23 002\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\RES photos\mars theatre\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\snowstorm '10\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\snowstorm '10\2010-12-26 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\snowstorm '10\2011-03-27 001\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\Pictures\thanksgiving 09\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Melissa\SkyDrive\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Gaffney's Cheap Seats 1 - Images\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Madrac Farms LLC Tax Form History\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Madrac Farms LLC Tax Form History\INWKS941\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Fri, Aug 17 2012 10 01 01 PM\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Fri, Aug 17 2012 10 01 01 PM\TempCopyBeforeValidate\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Fri, Oct 07 2011 08 21 23 AM\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Fri, Oct 07 2011 08 21 23 AM\TempCopyBeforeValidate\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Mon, Feb 11 2013 10 45 24 AM\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Mon, Mar 11 2013 12 52 45 PM\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Mon, Mar 11 2013 12 52 45 PM\TempCopyBeforeValidate\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Sat, Apr 07 2012 06 01 06 PM\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Sun, Aug 03 2014 04 33 38 AM\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Sun, Aug 03 2014 04 33 38 AM\TempCopyBeforeValidate\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Thu, Nov 07 2013 09 01 02 AM\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Tue, Jun 14 2011 07 42 31 PM\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Wed, Jun 12 2013 10 53 21 AM\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QBBackupTemp Wed, Jun 12 2013 10 53 21 AM\TempCopyBeforeValidate\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QuickBooks Letter Templates\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QuickBooks Letter Templates\Collection Letters\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QuickBooks Letter Templates\Customer Letters\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QuickBooks Letter Templates\Employee Letters\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QuickBooks Letter Templates\Estimate Letters\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QuickBooks Letter Templates\Invoice Letters\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QuickBooks Letter Templates\Other Names Letters\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\QuickBooks Letter Templates\Vendor Letters\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Rahn's Electric - Images\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Rahn's Electric Tax Form History\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Rahn's Electric Tax Form History\GADOL4NI\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Rahn's Electric Tax Form History\INWKS941\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\Letters_Templates\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\Letters_Templates\Collection Letters\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\Letters_Templates\Customer Letters\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\Letters_Templates\Employee Letters\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\Letters_Templates\Estimate Letters\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\Letters_Templates\Invoice Letters\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\Letters_Templates\Other Names Letters\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Gaffney's Cheap Seats 1_Files\Letters_Templates\Vendor Letters\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\Letters_Templates\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\Letters_Templates\Collection Letters\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\Letters_Templates\Customer Letters\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\Letters_Templates\Employee Letters\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\Letters_Templates\Estimate Letters\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\Letters_Templates\Invoice Letters\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\Letters_Templates\Other Names Letters\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_melissa & guerry_Files\Letters_Templates\Vendor Letters\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Images\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Letters_Templates\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Letters_Templates\Collection Letters\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Letters_Templates\Customer Letters\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Letters_Templates\Employee Letters\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Letters_Templates\Estimate Letters\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Letters_Templates\Invoice Letters\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Letters_Templates\Other Names Letters\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Restored_Rahn's Electric_Files\Letters_Templates\Vendor Letters\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Sample Company Files\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\Intuit\QuickBooks\Sample Company Files\QuickBooks 2012\DECRYPT_INSTRUCTION.URL
Deleted file - C:\Users\Public\Documents\ntr\DECRYPT_INSTRUCTION.URL

========= End of CMD: =========

EmptyTemp: => Removed 11.5 GB temporary data.


The system needed a reboot.

==== End of Fixlog ====

gurleygirl
2014-11-17, 21:48
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 16-11-2014 03
Ran by Melissa (administrator) on LAPTOP on 17-11-2014 14:36:36
Running from C:\Users\Melissa\Desktop
Loaded Profile: Melissa (Available profiles: Melissa & QBDataServiceUser21)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Stardock Corporation) C:\Program Files\Dell\DellDock\DockLogin.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Windstream) C:\Program Files (x86)\Windstream\Diagnostic Tools\HsdService.exe
(LeapFrog Enterprises, Inc.) C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe
(Alcatel-Lucent) C:\Program Files (x86)\Common Files\Motive\McciCMService.exe
(Alcatel-Lucent) C:\Program Files\Common Files\Motive\McciCMService.exe
(Intuit) C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
(Intuit Inc.) C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
(Radialpoint SafeCare Inc.) C:\Program Files (x86)\Windstream\Service Agent\ServicepointService.exe
(SoftThinks SAS) C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe
() C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
(SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
(Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Windstream) C:\Program Files (x86)\Windstream\Service Agent\Windstream Service Agent.exe
(LeapFrog Enterprises, Inc.) C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApntEx.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\hidfind.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\ielowutil.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil64_15_0_0_223_ActiveX.exe
(Radialpoint SafeCare Inc.) C:\Program Files (x86)\Windstream\Service Agent\Windstream Service AgentComHandler.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intuit, Inc.) C:\Program Files (x86)\Intuit\QuickBooks 2012\QBDBMgr.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [QuickSet] => C:\Program Files\Dell\QuickSet\QuickSet.exe [3200672 2010-06-30] (Dell Inc.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10918504 2010-06-14] (Realtek Semiconductor)
HKLM\...\Run: [Apoint] => C:\Program Files\DellTPad\Apoint.exe [392048 2010-06-04] (Alps Electric Co., Ltd.)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-06-08] (Intel Corporation)
HKLM-x32\...\Run: [Windstream Service Agent.exe] => C:\Program Files (x86)\Windstream\Service Agent\Windstream Service Agent.exe [10204472 2011-10-13] (Windstream)
HKLM-x32\...\Run: [Monitor] => C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe [298376 2012-09-28] (LeapFrog Enterprises, Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2011-05-10] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
HKLM-x32\...\RunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] => C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe [560128 2011-09-19] (Dell)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3154378874-1875084861-2286133563-1001\...\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [4566952 2014-06-24] (Safer-Networking Ltd.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Intuit Data Protect.lnk
ShortcutTarget: Intuit Data Protect.lnk -> C:\Program Files (x86)\Common Files\Intuit\DataProtect\IntuitDataProtect.exe (Intuit Inc.)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\QBDataServiceUser21\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
BootExecute: autocheck autochk * sdnclean64.exebddel.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

ProxyServer: [.DEFAULT] => http=127.0.0.1:50370
HKU\S-1-5-21-3154378874-1875084861-2286133563-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKCU - DefaultScope {38E8554E-EFF1-4E7A-A9FA-700C7D4C906D} URL = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=ie8
SearchScopes: HKCU - {38E8554E-EFF1-4E7A-A9FA-700C7D4C906D} URL = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=ie8
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO-x32: Search Helper -> {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} -> C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: SingleInstance Class -> {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} -> C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKU\S-1-5-21-3154378874-1875084861-2286133563-1001 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
DPF: HKLM-x32 {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: HKLM-x32 {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20614.www2.hp.com/ediags/gmd/Install/Cab/hpdetect119b.cab
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab
DPF: HKLM-x32 {BEA7310D-06C4-4339-A784-DC3804819809} http://www.cvsphoto.com/upload/activex/v3_0_0_7/PhotoCenter_ActiveX_Control.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.254.254

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_223.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @radialpoint.com/SPA,version=1 -> C:\Program Files (x86)\Windstream\Service Agent\nprpspa.dll (Windstream)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_223.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=1.6.0_35 -> C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @Motive.com/NpMotive,version=1.0 -> C:\Program Files (x86)\Common Files\Motive\npMotive.dll (Alcatel-Lucent)
FF Plugin-x32: @radialpoint.com/SPA,version=1 -> C:\Program Files (x86)\Windstream\Service Agent\nprpspa.dll (Windstream)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3154378874-1875084861-2286133563-1001: @nds.com/PCShowPlugin -> C:\Users\Melissa\AppData\Local\DIRECTV Player\npPCShowPlugin.dll No File
FF Plugin HKU\S-1-5-21-3154378874-1875084861-2286133563-1001: @nds.com/PlayerPlugin -> C:\Users\Melissa\AppData\Local\DIRECTV Player\npPlayerPlugin.dll (DIRECTV)
FF Plugin HKU\S-1-5-21-3154378874-1875084861-2286133563-1001: amazon.com/AmazonMP3DownloaderPlugin -> C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101752.dll (Amazon.com, Inc.)
FF Plugin HKU\S-1-5-21-3154378874-1875084861-2286133563-1001: NDS.com/PlayerPlugin -> C:\Users\Melissa\AppData\Local\DIRECTV Player\npPlayerPlugin.dll (DIRECTV)
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010-12-08]

Chrome:
=======
CHR Profile: C:\Users\Melissa\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Melissa\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-11-20]
CHR Extension: (Google Drive) - C:\Users\Melissa\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-11-20]
CHR Extension: (YouTube) - C:\Users\Melissa\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-11-20]
CHR Extension: (Google Search) - C:\Users\Melissa\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-11-20]
CHR Extension: (Radialpoint SPD Extension) - C:\Users\Melissa\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmmhpfbhngkongobaoibpmnijjokabmj [2012-09-19]
CHR Extension: (Google Wallet) - C:\Users\Melissa\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-20]
CHR Extension: (Gmail) - C:\Users\Melissa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-11-20]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2436280 2014-09-25] (Microsoft Corporation)
R2 DockLoginService; C:\Program Files\Dell\DellDock\DockLogin.exe [155648 2009-06-09] (Stardock Corporation) [File not signed]
R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-05-21] (Hewlett-Packard Co.) [File not signed]
R2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1039360 2010-10-22] (Hewlett-Packard Co.) [File not signed]
R2 HsdService; C:\Program Files (x86)\Windstream\Diagnostic Tools\HsdService.exe [1393976 2011-04-25] (Windstream)
R2 McciCMService; C:\Program Files (x86)\Common Files\Motive\McciCMService.exe [319488 2010-05-13] (Alcatel-Lucent) [File not signed]
R2 McciCMService64; C:\Program Files\Common Files\Motive\McciCMService.exe [517632 2010-05-13] (Alcatel-Lucent) [File not signed]
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
R2 QBCFMonitorService; C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe [45056 2013-11-08] (Intuit) [File not signed]
S3 QBFCService; C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe [61440 2012-01-10] (Intuit Inc.) [File not signed]
R2 QBVSS; C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe [1248256 2012-01-10] (Intuit Inc.) [File not signed]
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1740760 2014-09-03] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
S2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
R2 ServicepointService; C:\Program Files (x86)\Windstream\Service Agent\ServicepointService.exe [10315064 2011-10-13] (Radialpoint SafeCare Inc.)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 FlyUsb; C:\Windows\System32\DRIVERS\FlyUsb.sys [24576 2008-04-01] (LeapFrog)
S3 MREMP50; C:\Program Files (x86)\Common Files\Motive\MREMP50.sys [21248 2010-03-02] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
S3 MRESP50; C:\Program Files (x86)\Common Files\Motive\MRESP50.sys [20096 2010-03-02] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
S3 Normandy; C:\Windows\SysWow64\Drivers\Normandy.sys [34560 2010-11-18] () [File not signed]
S3 sscdserd; C:\Windows\System32\DRIVERS\sscdserd.sys [114856 2007-07-03] (MCCI Corporation)
S3 MREMP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS [X]
S3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [X]
S3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [X]
S3 MRESP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-11-17 12:13 - 2014-11-17 12:13 - 00000000 ____D () C:\Users\Melissa\Desktop\FRST-OlderVersion
2014-11-16 19:54 - 2014-11-16 19:54 - 00178405 _____ () C:\Users\Melissa\Desktop\eset.txt
2014-11-14 16:19 - 2014-11-14 16:19 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-11-14 15:22 - 2014-11-14 16:00 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-11-14 15:22 - 2014-11-14 15:22 - 00131800 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-11-14 15:22 - 2014-11-14 15:22 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-11-14 15:21 - 2014-11-14 16:00 - 00000000 ____D () C:\Users\Melissa\Desktop\mbar
2014-11-14 15:21 - 2014-11-14 15:21 - 00096472 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-11-14 15:20 - 2014-11-14 15:20 - 14439696 _____ (Malwarebytes Corp.) C:\Users\Melissa\Desktop\mbar-1.08.1.1001.exe
2014-11-14 11:49 - 2014-11-14 11:49 - 00000635 _____ () C:\Users\Melissa\Desktop\JRT.txt
2014-11-13 17:20 - 2014-11-13 17:20 - 01706808 _____ (Thisisu) C:\Users\Melissa\Desktop\JRT.exe
2014-11-13 17:20 - 2014-11-13 17:20 - 00000000 ____D () C:\Windows\ERUNT
2014-11-13 16:27 - 2014-11-13 16:34 - 00000000 ____D () C:\AdwCleaner
2014-11-13 16:27 - 2014-11-13 16:27 - 02140160 _____ () C:\Users\Melissa\Desktop\AdwCleaner.exe
2014-11-12 20:17 - 2014-11-12 22:56 - 00001178 _____ () C:\Users\Melissa\Desktop\ListCWall.txt
2014-11-12 20:17 - 2014-11-12 20:17 - 00400632 _____ (Bleeping Computer, LLC) C:\Users\Melissa\Desktop\ListCWall.exe
2014-11-12 20:11 - 2014-11-12 20:11 - 02744965 _____ () C:\Users\Melissa\Desktop\idtool.zip
2014-11-11 18:58 - 2014-11-11 18:58 - 00001800 _____ () C:\Users\Melissa\Desktop\aswMBR.txt
2014-11-11 18:58 - 2014-11-11 18:58 - 00000512 _____ () C:\Users\Melissa\Desktop\MBR.dat
2014-11-11 18:16 - 2014-11-11 18:50 - 05194752 _____ (AVAST Software) C:\Users\Melissa\Desktop\aswMBR.exe
2014-11-11 18:05 - 2014-11-11 18:10 - 00041309 _____ () C:\Users\Melissa\Desktop\Addition.txt
2014-11-11 17:48 - 2014-11-17 14:37 - 00019053 _____ () C:\Users\Melissa\Desktop\FRST.txt
2014-11-11 17:46 - 2014-11-17 14:36 - 00000000 ____D () C:\FRST
2014-11-11 17:44 - 2014-11-17 12:13 - 02117120 _____ (Farbar) C:\Users\Melissa\Desktop\FRST64.exe
2014-11-11 17:37 - 2014-11-11 17:37 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-LAPTOP-Microsoft-Windows-7-Home-Premium-(64-bit).dat
2014-11-11 17:33 - 2014-11-11 17:33 - 17926832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-11-11 17:29 - 2014-11-11 17:29 - 00000000 ____D () C:\RegBackup
2014-11-11 17:27 - 2014-11-11 17:27 - 00002201 _____ () C:\Users\Public\Desktop\Tweaking.com - Registry Backup.lnk
2014-11-11 17:27 - 2014-11-11 17:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2014-11-11 17:27 - 2014-11-11 17:27 - 00000000 ____D () C:\Program Files (x86)\Tweaking.com
2014-11-11 17:24 - 2014-11-11 17:25 - 04215584 _____ () C:\Users\Melissa\Desktop\tweaking.com_registry_backup_setup.exe
2014-11-11 13:03 - 2014-11-11 13:03 - 00000000 ____D () C:\ProgramData\Windows Genuine Advantage
2014-11-07 19:08 - 2014-11-08 07:59 - 00047082 _____ () C:\Windows\SysWOW64\bddel.dat
2014-11-07 18:40 - 2014-11-07 18:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Browser Features
2014-11-07 18:36 - 2014-11-07 18:36 - 00000000 ____D () C:\Users\Melissa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-11-07 11:46 - 2009-06-10 16:00 - 00000824 _____ () C:\Windows\system32\Drivers\etc\hosts.20141107-114626.backup
2014-11-06 12:50 - 2014-11-06 12:50 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-11-06 12:49 - 2014-11-06 12:49 - 00001357 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2014-11-06 12:49 - 2014-11-06 12:49 - 00001345 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2014-11-06 12:49 - 2014-11-06 12:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2014-11-06 12:47 - 2014-11-17 12:19 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-11-06 12:47 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe
2014-11-06 11:39 - 2014-11-06 11:40 - 00560968 _____ (Safer-Networking Ltd. ) C:\Users\Melissa\Downloads\spybot2-license.exe
2014-11-06 11:34 - 2014-11-06 13:15 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-11-06 09:35 - 2014-11-06 09:45 - 00000046 _____ () C:\Users\Melissa\AppData\Roaming\FactoryInstaller.xml
2014-11-06 09:35 - 2014-11-06 09:35 - 00000000 ____D () C:\Users\Melissa\AppData\Local\Absolute_Software
2014-11-05 12:21 - 2014-11-05 12:21 - 00000000 ____D () C:\Windows\pss
2014-11-05 12:04 - 2014-03-19 22:24 - 00114688 _____ () C:\Users\Melissa\AppData\Local\ChromeHitoryDB
2014-11-04 08:50 - 2014-11-07 21:54 - 00004974 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for Laptop-Melissa Laptop
2014-10-18 07:25 - 2014-10-18 07:27 - 00019968 ___SH () C:\Users\Melissa\Documents\Thumbs.db

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-11-17 14:34 - 2012-03-26 13:20 - 00000000 ____D () C:\ProgramData\Radialpoint
2014-11-17 14:33 - 2010-10-11 16:41 - 00000000 ____D () C:\Users\Default\AppData\Local\SoftThinks
2014-11-17 14:33 - 2010-10-11 16:41 - 00000000 ____D () C:\Users\Default User\AppData\Local\SoftThinks
2014-11-17 14:33 - 2010-09-18 13:05 - 00000000 ____D () C:\Program Files (x86)\Dell DataSafe Local Backup
2014-11-17 14:32 - 2013-11-20 09:24 - 00000484 _____ () C:\Windows\Tasks\SDMsgUpdate (Local).job
2014-11-17 14:32 - 2013-11-20 09:24 - 00000476 _____ () C:\Windows\Tasks\SDMsgUpdate (TE).job
2014-11-17 14:32 - 2012-04-03 16:13 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-11-17 14:32 - 2010-10-11 17:14 - 00453740 _____ () C:\Windows\PFRO.log
2014-11-17 14:32 - 2009-07-14 00:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-11-17 14:32 - 2009-07-13 23:51 - 00067700 _____ () C:\Windows\setupact.log
2014-11-17 12:20 - 2014-06-12 10:52 - 00000000 ____D () C:\Users\Melissa\Documents\Invoices
2014-11-17 12:20 - 2014-05-16 10:41 - 00000000 ____D () C:\Users\Melissa\AppData\OICE_15_974FA576_32C1D314_1139
2014-11-17 12:20 - 2014-04-08 13:00 - 00000000 ____D () C:\Users\Melissa\Documents\Contractors
2014-11-17 12:20 - 2014-02-10 08:16 - 00000000 ____D () C:\Users\Melissa\Documents\Guerry
2014-11-17 12:20 - 2013-08-27 12:47 - 00000000 ____D () C:\Users\Melissa\AppData\OICE_15_974FA576_32C1D314_2CDE
2014-11-17 12:20 - 2013-05-06 15:15 - 00000000 ____D () C:\Users\Melissa\Documents\Heard elementary
2014-11-17 12:20 - 2013-04-02 10:52 - 00000000 ____D () C:\Users\Melissa\Documents\gaffney's cheap seats
2014-11-17 12:20 - 2013-03-18 09:36 - 00000000 ___RD () C:\Users\Melissa\SkyDrive
2014-11-17 12:20 - 2012-10-31 10:52 - 00000000 ____D () C:\Users\Melissa\Documents\Amazon MP3
2014-11-17 12:20 - 2012-10-31 10:52 - 00000000 ____D () C:\Users\Melissa\AppData\Roaming\Amazon
2014-11-17 12:20 - 2012-09-05 15:29 - 00000000 ____D () C:\Users\Melissa\Documents\Coffee bluff Marina
2014-11-17 12:20 - 2012-09-05 09:51 - 00000000 ____D () C:\Users\Melissa\Documents\Bible Lutheran
2014-11-17 12:20 - 2012-08-09 16:14 - 00000000 ____D () C:\Users\Melissa\Documents\FT. Stewart Training Facility
2014-11-17 12:20 - 2012-02-10 12:51 - 00000000 ____D () C:\Users\Melissa\Documents\Largo Tibet
2014-11-17 12:20 - 2011-11-28 16:42 - 00000000 ____D () C:\Users\Melissa\Desktop\Visualizations
2014-11-17 12:20 - 2011-11-28 16:42 - 00000000 ____D () C:\Users\Melissa\Desktop\Sequences
2014-11-17 12:20 - 2011-11-28 16:42 - 00000000 ____D () C:\Users\Melissa\Desktop\Audio
2014-11-17 12:20 - 2011-11-28 11:16 - 00000000 ____D () C:\Users\Melissa\Documents\Countryside
2014-11-17 12:20 - 2011-10-18 09:23 - 00000000 ____D () C:\Users\Melissa\Documents\OLD jobs
2014-11-17 12:20 - 2011-09-26 11:01 - 00000000 ____D () C:\Users\Melissa\Documents\OgeeChee
2014-11-17 12:20 - 2011-08-10 10:29 - 00000000 ____D () C:\Users\Melissa\Documents\HAAF engagement
2014-11-17 12:20 - 2011-05-21 15:38 - 00000000 ____D () C:\Users\Melissa\AppData\Roaming\PCDr
2014-11-17 12:20 - 2011-04-15 07:58 - 00000000 ____D () C:\Users\Melissa\Documents\Taxes
2014-11-17 12:20 - 2011-04-07 12:23 - 00000000 ____D () C:\Users\Melissa\Documents\MAdrac Farms
2014-11-17 12:20 - 2010-12-17 11:52 - 00000000 ____D () C:\Users\Melissa\Documents\My Scans
2014-11-17 12:20 - 2010-12-08 16:35 - 00000000 ____D () C:\Users\Melissa\AppData\Roaming\HP
2014-11-17 12:20 - 2010-10-25 08:43 - 00000000 ____D () C:\Users\Melissa\Documents\WBENC
2014-11-17 12:20 - 2010-10-25 08:43 - 00000000 ____D () C:\Users\Melissa\Documents\pics
2014-11-17 12:20 - 2010-10-25 08:43 - 00000000 ____D () C:\Users\Melissa\Documents\business forms
2014-11-17 12:20 - 2010-10-25 08:42 - 00000000 ____D () C:\Users\Melissa\Documents\commercial bids
2014-11-17 12:20 - 2010-10-25 08:42 - 00000000 ____D () C:\Users\Melissa\Documents\Bell computer
2014-11-17 12:20 - 2010-10-18 13:32 - 00000000 ____D () C:\Users\Public\Documents\ntr
2014-11-17 12:20 - 2010-10-15 18:30 - 00000000 ____D () C:\Users\Melissa\AppData\Roaming\Skype
2014-11-17 12:20 - 2010-10-12 14:03 - 00000000 ____D () C:\Users\Public\Documents\Intuit
2014-11-17 12:20 - 2010-10-11 16:45 - 00000000 ____D () C:\Users\Melissa\AppData\Roaming\Adobe
2014-11-17 12:20 - 2010-10-11 16:42 - 00000000 ____D () C:\Users\Melissa\AppData\Roaming\Dell
2014-11-17 12:19 - 2014-03-25 22:12 - 00000000 ____D () C:\Users\Melissa\AppData\Local\DIRECTV Player
2014-11-17 12:19 - 2014-02-24 12:26 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-11-17 12:19 - 2014-01-12 21:11 - 00000000 ____D () C:\Users\Melissa\AppData\Local\Apple Computer
2014-11-17 12:19 - 2012-03-26 13:20 - 00000000 ____D () C:\ProgramData\Windstream
2014-11-17 12:19 - 2011-11-28 16:20 - 00000000 ____D () C:\ProgramData\Light-O-Rama
2014-11-17 12:19 - 2010-12-08 16:18 - 00000000 ____D () C:\ProgramData\HP
2014-11-17 12:19 - 2010-12-03 17:13 - 00000000 ____D () C:\Users\Melissa\AppData\Local\Microsoft Games
2014-11-17 12:19 - 2010-11-28 15:15 - 00000000 ____D () C:\ProgramData\Leapfrog
2014-11-17 12:19 - 2010-10-21 13:38 - 00000000 ____D () C:\Users\Melissa\AppData\Local\Google
2014-11-17 12:19 - 2010-10-12 14:14 - 00000000 ____D () C:\Users\Melissa\AppData\Local\Intuit
2014-11-17 12:19 - 2010-10-12 14:03 - 00000000 ____D () C:\ProgramData\Intuit
2014-11-17 12:19 - 2010-10-11 16:38 - 00000000 ____D () C:\Users\Melissa
2014-11-17 12:19 - 2010-09-18 16:16 - 00000000 ____D () C:\Dell
2014-11-17 12:19 - 2010-09-18 12:57 - 00000000 ____D () C:\ProgramData\Skype
2014-11-17 12:19 - 2010-09-18 12:43 - 00000000 ____D () C:\ProgramData\Sonic
2014-11-17 12:19 - 2010-09-18 12:42 - 00000000 ____D () C:\ProgramData\Macrovision
2014-11-17 12:19 - 2010-09-18 12:41 - 00000000 ____D () C:\ProgramData\PCDr
2014-11-17 12:19 - 2010-09-18 12:32 - 00000000 ____D () C:\ProgramData\Dell
2014-11-17 12:09 - 2009-07-14 00:13 - 00006320 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-11-16 18:13 - 2012-03-26 13:20 - 00000000 ____D () C:\Users\Melissa\AppData\Roaming\Radialpoint
2014-11-14 15:59 - 2010-10-18 14:03 - 00000000 ____D () C:\Users\QBDataServiceUser21
2014-11-14 11:42 - 2009-07-13 23:45 - 00013872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-11-14 11:42 - 2009-07-13 23:45 - 00013872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-11-13 11:27 - 2011-06-23 15:10 - 00000000 ____D () C:\Users\Melissa\Documents\Outlook Files
2014-11-11 19:20 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-11-11 18:26 - 2010-10-11 16:58 - 00000000 ____D () C:\Users\Melissa\Tracing
2014-11-11 17:34 - 2012-04-03 16:13 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-11-11 17:34 - 2012-04-03 16:13 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-11-11 17:34 - 2011-05-21 15:29 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-11-11 16:40 - 2010-10-25 08:43 - 00000000 ____D () C:\Users\Melissa\Documents\personal
2014-11-11 13:19 - 2012-03-26 13:18 - 00000000 ____D () C:\ProgramData\Motive
2014-11-10 16:06 - 2010-09-18 11:58 - 02081760 _____ () C:\Windows\WindowsUpdate.log
2014-11-10 16:02 - 2013-05-22 13:17 - 00003440 _____ () C:\Windows\System32\Tasks\PCDEventLauncherTask
2014-11-08 07:46 - 2014-09-02 20:23 - 00000000 ____D () C:\Program Files (x86)\FUPM Browser
2014-11-07 19:02 - 2010-10-11 18:00 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-11-07 18:56 - 2013-03-18 08:45 - 00000000 ____D () C:\Program Files\Microsoft Office 15
2014-11-06 11:03 - 2012-06-12 18:19 - 02656768 ___SH () C:\Users\Melissa\Desktop\Thumbs.db
2014-11-05 12:10 - 2012-09-19 09:58 - 00000000 ____D () C:\Program Files (x86)\Google
2014-10-24 07:45 - 2012-09-19 09:59 - 00003894 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-11-16 19:11

==================== End Of Log ============================

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 16-11-2014 03
Ran by Melissa at 2014-11-17 14:38:26
Running from C:\Users\Melissa\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

4500_G510nz_Help (x32 Version: 000.0.439.000 - Hewlett-Packard) Hidden
4500G510nz (x32 Version: 000.0.439.000 - Hewlett-Packard) Hidden
4500G510nz_Software_Min (x32 Version: 000.0.423.000 - Hewlett-Packard) Hidden
64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden
ABBYY FineReader 6.0 Sprint (HKLM-x32\...\{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}) (Version: 6.00.1990.41618 - ABBYY Software House)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 2.0.4.13090 - Adobe Systems Inc.)
Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.223 - Adobe Systems Incorporated)
Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.223 - Adobe Systems Incorporated)
Adobe Reader X (10.1.8) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.8 - Adobe Systems Incorporated)
Advanced Audio FX Engine (HKLM-x32\...\Advanced Audio FX Engine) (Version: 1.12.05 - Creative Technology Ltd)
Amazon MP3 Downloader 1.0.17 (HKLM-x32\...\Amazon MP3 Downloader) (Version: 1.0.17 - Amazon Services LLC)
Apple Application Support (HKLM-x32\...\{21FC2093-6E43-460B-B9B0-5F5AA35BBB0F}) (Version: 3.0 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{FE86CB0C-FCB3-4358-B4B0-B0A41E33B3DD}) (Version: 7.1.0.32 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Browser Enhancements version 3.17 (HKLM-x32\...\{85A37836-5888-4152-8990-EF4502A5EFB1}}_is1) (Version: 3.17 - Browser Enhancements)
Browser Features version 2.22 (HKLM-x32\...\{6C250DDC-A10E-4F36-95B4-59A76592DA20}}_is1) (Version: 2.22 - Browser Features)
BufferChm (x32 Version: 130.0.331.000 - Hewlett-Packard) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Dell DataSafe Local Backup - Support Software (HKLM-x32\...\{A9668246-FB70-4103-A1E3-66C9BC2EFB49}) (Version: 9.4.60 - Dell)
Dell DataSafe Local Backup (HKLM-x32\...\{0ED7EE95-6A97-47AA-AD73-152C08A15B04}) (Version: 9.4.60 - Dell)
Dell DataSafe Online (HKLM-x32\...\{13766F76-6C8C-4E57-A9F3-3212D1C6E0D1}) (Version: 1.2.0011 - Dell, Inc.)
Dell Dock (HKLM-x32\...\Dell Dock) (Version: - Stardock Corporation)
Dell Dock (Version: 2.0 - Stardock Corporation) Hidden
Dell Getting Started Guide (HKLM-x32\...\{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}) (Version: 1.00.0000 - Dell Inc.)
Dell Touchpad (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 7.1107.101.209 - ALPS ELECTRIC CO., LTD.)
Dell Webcam Central (HKLM-x32\...\Dell Webcam Central) (Version: 1.40.05 - Creative Technology Ltd)
Destinations (x32 Version: 130.0.0.0 - Hewlett-Packard) Hidden
DeviceDiscovery (x32 Version: 130.0.372.000 - Hewlett-Packard) Hidden
DIRECTV Player (HKLM-x32\...\{a1bb9be6-729f-4049-a36a-aad335c86c01}) (Version: 9.2 - DIRECTV)
DocMgr (x32 Version: 130.0.000.000 - Hewlett-Packard) Hidden
DocProc (x32 Version: 13.0.0.0 - Hewlett-Packard) Hidden
ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - )
Fax (x32 Version: 130.0.418.000 - Hewlett-Packard) Hidden
FUPM Browser version 1.2.1 (HKLM-x32\...\{B86A5F28-E714-49DD-9C61-6DC5BB867255}}_is1) (Version: 1.2.1 - Find Ultra Premium Merchants)
GPBaseService2 (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
HP Customer Participation Program 13.0 (HKLM\...\HPExtendedCapabilities) (Version: 13.0 - HP)
HP Document Manager 2.0 (HKLM\...\HP Document Manager) (Version: 2.0 - HP)
HP Imaging Device Functions 13.0 (HKLM\...\HP Imaging Device Functions) (Version: 13.0 - HP)
HP Officejet 4500 G510n-z (HKLM\...\{7E0E61CC-1C99-429D-BEA7-C4DD5B898D2A}) (Version: 13.0 - HP)
HP Product Detection (HKLM-x32\...\{4F38594F-2C4A-4C42-B2C4-505E225F6F80}) (Version: 11.14.0004 - HP)
HP Smart Web Printing 4.5 (HKLM\...\HP Smart Web Printing) (Version: 4.5 - HP)
HP Solution Center 13.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP)
HP Update (HKLM-x32\...\{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}) (Version: 5.003.001.001 - Hewlett-Packard)
HPDiagnosticAlert (x32 Version: 1.00.0000 - Microsoft) Hidden
HPProductAssistant (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: 8.15.10.2202 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 9.6.4.1002 - Intel Corporation)
iTunes (HKLM\...\{96B53CA8-5ABB-49D8-96F1-F6C0D73A76C6}) (Version: 11.1.4.62 - Apple Inc.)
Java(TM) 6 Update 18 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86416018F0}) (Version: 6.0.180 - Sun Microsystems, Inc.)
Java(TM) 6 Update 20 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86416020FF}) (Version: 6.0.200 - Sun Microsystems, Inc.)
Java(TM) 6 Update 35 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216035FF}) (Version: 6.0.350 - Oracle)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
LeapFrog Connect (HKLM-x32\...\UPCShell) (Version: 4.2.9.15649 - LeapFrog)
LeapFrog Connect (x32 Version: 4.2.9.15649 - LeapFrog) Hidden
LeapFrog LeapPad Explorer Plugin (x32 Version: 4.2.11.15696 - LeapFrog) Hidden
LeapFrog Tag Plugin (x32 Version: 4.2.9.15649 - LeapFrog) Hidden
Light-O-Rama (HKLM-x32\...\{E744BFEA-E027-441E-83A2-36202F661E31}) (Version: 3.0.2 - Light-O-Rama)
LoJack Factory Installer (HKLM-x32\...\{40F4FF7A-B214-4453-B973-080B09CED019}) (Version: 1.0.0 - Absolute Software)
MarketResearch (x32 Version: 130.0.374.000 - Hewlett-Packard) Hidden
Microsoft .NET Framework 2.0 SDK (x64) - ENU (HKLM\...\Microsoft .NET Framework 2.0 SDK (x64) - ENU) (Version: - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Office 2010 Service Pack 1 (SP1) (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE}) (Version: - Microsoft)
Microsoft Office 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 15.0.4659.1001 - Microsoft Corporation)
Microsoft Office Home and Student 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.6029.1000 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3154378874-1875084861-2286133563-1001\...\OneDriveSetup.exe) (Version: 17.3.1229.0918 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable - KB2467175 (HKLM-x32\...\{a0fe116e-9a8a-466f-aee0-625cb7c207e3}) (Version: 8.0.51011 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{052bac4a-6f79-46d4-a024-1ce1b4f73cd4}) (Version: 8.0.58299 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{820B6609-4C97-3A2B-B644-573B06A0F0CC}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.31007 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP2 Parser and SDK (HKLM-x32\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
My Dell (HKLM\...\PC-Doctor for Windows) (Version: 3.5.6426.22 - PC-Doctor, Inc.)
Network64 (Version: 130.0.374.000 - Hewlett-Packard) Hidden
Network64 (Version: 140.0.221.000 - Hewlett-Packard) Hidden
OCR Software by I.R.I.S. 13.0 (HKLM\...\HPOCR) (Version: 13.0 - HP)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4659.1001 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4659.1001 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4659.1001 - Microsoft Corporation) Hidden
QuickBooks (x32 Version: 22.0.4015.2206 - Intuit Inc.) Hidden
QuickBooks Pro 2012 (HKLM-x32\...\{22057D8D-7CC8-46FF-AD8C-9BD24F9014F3}) (Version: 22.0.4015.2206 - Intuit Inc.)
Quickset64 (HKLM\...\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 10.06.02 - Dell Inc.)
Radialpoint Security Advisor 2.5.15 (x32 Version: 2.5.15 - Radialpoint SafeCare Inc.) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6136 - Realtek Semiconductor Corp.)
Roxio Burn (HKLM-x32\...\{B2E47DE7-800B-40BB-BD1F-9F221C3AEE87}) (Version: 1.01 - Roxio)
SAMSUNG Mobile Modem Driver Set (HKLM\...\SAMSUNG Mobile Modem) (Version: - )
Samsung Mobile phone USB driver Software (HKLM\...\Samsung Mobile phone USB driver) (Version: - )
SAMSUNG Mobile USB Modem 1.0 Software (HKLM\...\SAMSUNG Mobile USB Modem 1.0) (Version: - )
SAMSUNG Mobile USB Modem Software (HKLM\...\SAMSUNG Mobile USB Modem) (Version: - )
Samsung PC Studio 3 USB Driver Installer (HKLM-x32\...\{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}) (Version: 3.2.0.70701 - Samsung Electronics Co., Ltd.)
Scan (x32 Version: 13.0.0.0 - Hewlett-Packard) Hidden
Skype™ 5.10 (HKLM-x32\...\{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}) (Version: 5.10.116 - Skype Technologies S.A.)
SmartWebPrinting (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden
SolutionCenter (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.)
Status (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden
SupportSoft Assisted Service (HKLM-x32\...\{5A3F6A80-7913-475E-8B96-477A952CFA43}) (Version: 15 - SupportSoft)
System Requirements Lab (HKLM-x32\...\SystemRequirementsLab) (Version: - )
Toolbox (x32 Version: 130.0.648.000 - Hewlett-Packard) Hidden
TrayApp (x32 Version: 130.0.376.000 - Hewlett-Packard) Hidden
Tweaking.com - Registry Backup (HKLM-x32\...\Tweaking.com - Registry Backup) (Version: 1.10.1 - Tweaking.com)
Use the entry named LeapFrog Connect to uninstall (LeapFrog LeapPad Explorer Plugin) (HKLM-x32\...\LeapPadExplorerPlugin) (Version: - LeapFrog)
Use the entry named LeapFrog Connect to uninstall (LeapFrog Tag Plugin) (HKLM-x32\...\TagPlugin) (Version: 4.2.9.15649 - LeapFrog)
Visual Studio Tools for the Office system 3.0 Runtime Service Pack 1 (KB949258) (HKLM-x32\...\{8FB53850-246A-3507-8ADE-0060093FFEA6}.KB949258) (Version: 1 - Microsoft Corporation)
WebReg (x32 Version: 130.0.132.017 - Hewlett-Packard) Hidden
Windows Driver Package - LeapFrog (FlyUsb) USB (11/05/2008 1.1.1.0) (HKLM\...\781745E87AFF80C0C1388CFF79D19ECAB2E9BB47) (Version: 11/05/2008 1.1.1.0 - LeapFrog)
Windows Driver Package - Leapfrog (Leapfrog-USBLAN) Net (09/10/2009 02.03.05.012) (HKLM\...\8F14F2ECEDE68D26EA515B48DC25B39103C4FE8D) (Version: 09/10/2009 02.03.05.012 - Leapfrog)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Live Sync (HKLM-x32\...\{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}) (Version: 14.0.8089.726 - Microsoft Corporation)
Windstream Diagnostic Tools 3.0.21 (x32 Version: 3.0.21 - Windstream) Hidden
Windstream Service Agent 4.1.15 (HKLM-x32\...\RadialpointClientGateway_is1) (Version: 4.1.15 - Windstream)
Yahoo! Detect (HKLM-x32\...\YTdetect) (Version: - )
Yahoo! Toolbar (HKLM-x32\...\Yahoo! Companion) (Version: - )

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-3154378874-1875084861-2286133563-1001_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Melissa\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3154378874-1875084861-2286133563-1001_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Melissa\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3154378874-1875084861-2286133563-1001_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\Melissa\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3154378874-1875084861-2286133563-1001_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Melissa\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3154378874-1875084861-2286133563-1001_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Melissa\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\FileSyncApi64.dll (Microsoft Corporation)

==================== Restore Points =========================

14-11-2014 03:54:59 Scheduled Checkpoint
14-11-2014 20:59:17 Malwarebytes Anti-Rootkit Restore Point

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 21:34 - 2014-11-13 09:01 - 00000035 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {03AFC8D3-C38E-4AAF-92C7-E9381AD98AD3} - System32\Tasks\LoJack for Laptops Install => C:\Program Files (x86)\Absolute Software\LoJack Install\FactoryInstaller.exe [2009-11-26] (Absolute Software)
Task: {18C6765E-5D46-4C5F-8848-72EF568C4659} - System32\Tasks\SDMsgUpdate (Local) => C:\Program Files (x86)\SmartDraw CI\Messages\SDNotify.exe [2012-08-13] ()
Task: {3E48F351-0754-4911-83AA-353F3119CA4F} - System32\Tasks\Microsoft Office 15 Sync Maintenance for Laptop-Melissa Laptop => C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe [2014-10-19] (Microsoft Corporation)
Task: {5AC44A0B-3312-4E1D-9BF7-3C2E821F64C0} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-11] (Adobe Systems Incorporated)
Task: {62616662-CF62-4526-A7A6-CED697EC2426} - System32\Tasks\IHUninstallTrackingTASK => CMD
Task: {63E0ED59-4C66-4CC0-99A3-3DE6FAB83924} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {683A5625-6256-47DA-9826-603CA72B75B6} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\My Dell\uaclauncher.exe [2014-01-31] (PC-Doctor, Inc.)
Task: {7956B706-6AF6-46AC-93E3-CD43C90CFA00} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2014-09-25] (Microsoft Corporation)
Task: {9CC368BA-943A-4114-9FC4-A624E96FA95C} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDUpdate.exe
Task: {A5452B19-D4D6-414C-8816-F8FA28ABD812} - System32\Tasks\SDMsgUpdate (TE) => C:\Program Files (x86)\SmartDraw CI\Messages\SDNotify.exe [2012-08-13] ()
Task: {ABE4E42F-B172-4B4C-A399-FE26F426F5A4} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDScan.exe
Task: {B5F2B017-85B0-471B-A3E4-8D437BE2ADD8} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe [2014-10-19] (Microsoft Corporation)
Task: {BB2C18C8-08A9-4BA7-8A70-71A878A6E49E} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\My Dell\sessionchecker.exe [2014-01-31] (PC-Doctor, Inc.)
Task: {BF8469D9-CF86-4312-AB10-4DEE368B374D} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDImmunize.exe
Task: {CF448ED9-A4F5-4B3D-8B26-CEBAF27DC871} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {DA59EBEE-9F99-4A87-9BD1-D11E4D367E4B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: {E037F955-36E3-41F5-946A-B2A2370049C3} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\SDMsgUpdate (Local).job => C:\PROGRA~2\SMARTD~1\Messages\SDNotify.exe
Task: C:\Windows\Tasks\SDMsgUpdate (TE).job => C:\PROGRA~2\SMARTD~1\Messages\SDNotify.exe

==================== Loaded Modules (whitelisted) =============

2014-11-07 18:53 - 2014-05-20 09:19 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2014-01-15 12:19 - 2014-10-19 12:58 - 08896160 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2010-09-18 13:05 - 2011-08-18 10:05 - 02751808 _____ () C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE
2014-02-06 00:52 - 2014-02-06 00:52 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-02-06 00:52 - 2014-02-06 00:52 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2014-11-06 12:47 - 2014-05-13 12:04 - 00109400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2014-11-06 12:47 - 2014-05-13 12:04 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
2014-11-06 12:47 - 2014-05-13 12:04 - 00167768 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2014-11-06 12:47 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll
2014-11-06 12:47 - 2012-04-03 17:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll
2012-05-12 02:45 - 2012-05-12 02:45 - 00170496 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\97d05107b8c95b1a62a45a87a7c8165f\IsdiInterop.ni.dll
2010-09-18 12:32 - 2010-06-08 10:44 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)


==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HsdService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ServicepointService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\HsdService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ntrexeservice => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NTRSupport => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ServicepointService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => C:\Windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk => C:\Windows\pss\QuickBooks Update Agent.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^QuickBooks_Standard_21.lnk => C:\Windows\pss\QuickBooks_Standard_21.lnk.CommonStartup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: Dell DataSafe Online => "C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m
MSCONFIG\startupreg: Dell Webcam Central => "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
MSCONFIG\startupreg: DellSupportCenter => "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
MSCONFIG\startupreg: Desktop Disc Tool => "C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe"
MSCONFIG\startupreg: DiagnosticTools.exe => "C:\Program Files (x86)\Windstream\Diagnostic Tools\DiagnosticTools.exe" /AUTORUN
MSCONFIG\startupreg: Intuit SyncManager => C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe startup
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"

========================= Accounts: ==========================

Administrator (S-1-5-21-3154378874-1875084861-2286133563-500 - Administrator - Disabled)
Guest (S-1-5-21-3154378874-1875084861-2286133563-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3154378874-1875084861-2286133563-1002 - Limited - Enabled)
Melissa (S-1-5-21-3154378874-1875084861-2286133563-1001 - Administrator - Enabled) => C:\Users\Melissa
QBDataServiceUser21 (S-1-5-21-3154378874-1875084861-2286133563-1003 - Limited - Enabled) => C:\Users\QBDataServiceUser21

==================== Faulty Device Manager Devices =============

Name: Officejet 4500 G510n-z
Description: Officejet 4500 G510n-z
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: Officejet 4500 G510n-z
Description: Officejet 4500 G510n-z
Class Guid: {4d36e971-e325-11ce-bfc1-08002be10318}
Manufacturer: HP
Service:
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (11/17/2014 00:09:22 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

Error: (11/17/2014 00:09:22 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.

Error: (11/16/2014 07:13:13 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (11/16/2014 07:00:01 PM) (Source: Windows Backup) (EventID: 4103) (User: )
Description: The backup did not complete because of an error writing to the backup location E:\. The error is: The backup location cannot be found or is not valid. Review your backup settings and check the backup location. (0x81000006).

Error: (11/16/2014 03:50:12 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: pcdrcui.exe, version: 6.0.6426.22, time stamp: 0x52cfadb3
Faulting module name: KERNELBASE.dll, version: 6.1.7601.18015, time stamp: 0x50b8479b
Exception code: 0xe0434352
Fault offset: 0x0000000000009e5d
Faulting process id: 0x12b8
Faulting application start time: 0xpcdrcui.exe0
Faulting application path: pcdrcui.exe1
Faulting module path: pcdrcui.exe2
Report Id: pcdrcui.exe3

Error: (11/16/2014 03:50:10 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: pcdrcui.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: Pcd.DataStore.DatabaseError
Stack:
at wpfview.Program.StartController_HandelAsapiAuthenticationErrors(System.String[])
at wpfview.Program.Main(System.String[])

Error: (11/16/2014 02:54:47 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

Error: (11/16/2014 02:54:47 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.

Error: (11/14/2014 03:03:18 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: pcdrcui.exe, version: 6.0.6426.22, time stamp: 0x52cfadb3
Faulting module name: KERNELBASE.dll, version: 6.1.7601.18015, time stamp: 0x50b8479b
Exception code: 0xe0434352
Fault offset: 0x0000000000009e5d
Faulting process id: 0x110c
Faulting application start time: 0xpcdrcui.exe0
Faulting application path: pcdrcui.exe1
Faulting module path: pcdrcui.exe2
Report Id: pcdrcui.exe3

Error: (11/14/2014 03:03:18 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: pcdrcui.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: Pcd.DataStore.DatabaseError
Stack:
at Pcd.DataStore.AppStateDataStore..ctor()
at pcd.models.properties.UserSetting.Init()
at pcd.controllers.MainController.InitializeProperties()
at pcd.controllers.MainController.BackgroundStartThread()
at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
at System.Threading.ThreadHelper.ThreadStart()


System errors:
=============
Error: (11/17/2014 02:34:27 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The HomeGroup Provider service depends on the Function Discovery Resource Publication service which failed to start because of the following error:
%%-2147024891

Error: (11/17/2014 02:34:27 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Function Discovery Resource Publication service terminated with the following error:
%%-2147024891

Error: (11/17/2014 02:33:53 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

Error: (11/17/2014 02:33:13 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Computer Browser service terminated with the following error:
%%1060

Error: (11/17/2014 02:33:01 PM) (Source: Service Control Manager) (EventID: 7003) (User: )
Description: The Spybot-S&D 2 Security Center Service service depends the following service: wscsvc. This service might not be installed.

Error: (11/17/2014 02:32:41 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Function Discovery Resource Publication service terminated with the following error:
%%-2147024891

Error: (11/17/2014 02:31:31 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ServicepointService service.

Error: (11/17/2014 00:13:54 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Media Player Network Sharing Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.

Error: (11/17/2014 00:13:54 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.

Error: (11/17/2014 00:13:54 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Intel(R) Rapid Storage Technology service terminated unexpectedly. It has done this 1 time(s).


Microsoft Office Sessions:
=========================
Error: (11/17/2014 00:09:22 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
Description: WmiApRplWmiApRpl8F20300004D070000

Error: (11/17/2014 00:09:22 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: Performance1637070000000000000000000009030000

Error: (11/16/2014 07:13:13 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestc:\program files (x86)\ESET\eset online scanner\ESETSmartInstaller.exe

Error: (11/16/2014 07:00:01 PM) (Source: Windows Backup) (EventID: 4103) (User: )
Description: E:\The backup location cannot be found or is not valid. Review your backup settings and check the backup location. (0x81000006)

Error: (11/16/2014 03:50:12 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: pcdrcui.exe6.0.6426.2252cfadb3KERNELBASE.dll6.1.7601.1801550b8479be04343520000000000009e5d12b801d001deacbfa504C:\Program Files\My Dell\pcdrcui.exeC:\Windows\system32\KERNELBASE.dll28469894-6dd2-11e4-97fd-061bb1456f9c

Error: (11/16/2014 03:50:10 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: pcdrcui.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: Pcd.DataStore.DatabaseError
Stack:
at wpfview.Program.StartController_HandelAsapiAuthenticationErrors(System.String[])
at wpfview.Program.Main(System.String[])

Error: (11/16/2014 02:54:47 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
Description: WmiApRplWmiApRpl8F20300004D070000

Error: (11/16/2014 02:54:47 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: Performance1637070000000000000000000009030000

Error: (11/14/2014 03:03:18 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: pcdrcui.exe6.0.6426.2252cfadb3KERNELBASE.dll6.1.7601.1801550b8479be04343520000000000009e5d110c01d00045ff3dc946C:\Program Files\My Dell\pcdrcui.exeC:\Windows\system32\KERNELBASE.dll461a4ac6-6c39-11e4-97fd-061bb1456f9c

Error: (11/14/2014 03:03:18 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: pcdrcui.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: Pcd.DataStore.DatabaseError
Stack:
at Pcd.DataStore.AppStateDataStore..ctor()
at pcd.models.properties.UserSetting.Init()
at pcd.controllers.MainController.InitializeProperties()
at pcd.controllers.MainController.BackgroundStartThread()
at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
at System.Threading.ThreadHelper.ThreadStart()


CodeIntegrity Errors:
===================================
Date: 2014-11-14 11:29:29.825
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\Spybot - Search & Destroy 2\SDHook64.dll because the set of per-page image hashes could not be found on the system.

Date: 2014-11-14 08:03:31.381
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\Spybot - Search & Destroy 2\SDHook64.dll because the set of per-page image hashes could not be found on the system.

Date: 2014-11-14 01:53:17.783
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\Spybot - Search & Destroy 2\SDHook64.dll because the set of per-page image hashes could not be found on the system.

Date: 2014-11-13 17:16:37.636
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\Spybot - Search & Destroy 2\SDHook64.dll because the set of per-page image hashes could not be found on the system.

Date: 2014-11-13 17:02:33.618
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\Spybot - Search & Destroy 2\SDHook64.dll because the set of per-page image hashes could not be found on the system.

Date: 2014-11-13 16:57:12.830
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\Spybot - Search & Destroy 2\SDHook64.dll because the set of per-page image hashes could not be found on the system.

Date: 2014-11-13 16:21:36.802
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\Spybot - Search & Destroy 2\SDHook64.dll because the set of per-page image hashes could not be found on the system.

Date: 2014-11-13 16:21:36.802
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\Spybot - Search & Destroy 2\SDHook64.dll because the set of per-page image hashes could not be found on the system.

Date: 2014-11-13 11:26:17.216
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\Spybot - Search & Destroy 2\SDHook64.dll because the set of per-page image hashes could not be found on the system.

Date: 2014-11-13 11:26:17.216
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\Spybot - Search & Destroy 2\SDHook64.dll because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Processor: Pentium(R) Dual-Core CPU T4500 @ 2.30GHz
Percentage of memory in use: 38%
Total physical RAM: 4058.36 MB
Available physical RAM: 2487.16 MB
Total Pagefile: 8114.91 MB
Available Pagefile: 6186.46 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:451.01 GB) (Free:336.87 GB) NTFS ==>[Drive with boot components (obtained from BCD)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 51ED4EC9)
Partition 1: (Not Active) - (Size=100 MB) - (Type=DE)
Partition 2: (Active) - (Size=14.6 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=451 GB) - (Type=07 NTFS)

==================== End Of Log ============================

Juliet
2014-11-17, 23:05
Empty flash cache.
http://www.macromedia.com/support/documentation/en/flashplayer/help/settings_manager07.html
<<<>>>

Click the http://www.techsupportforum.com/sectools/tetonbob/StartBtn.gif button. In the Search box, type Command Prompt, and then, in the list of results, double-click Command Prompt.

at the cursor type:
ipconfig /flushdns <-- (A space between g and / is needed)

repeat with
ipconfig /renew

Then hit Enter, type Exit, hit the Enter key.
You may need to run CMD - Command Prompt on Vista - Windows 7/8 with Elevated Privilege
http://www.bleepingcomputer.com/tutorials/windows-elevated-command-prompt/
<<<>>>

If you had backed up any of the photos there is a chance you have copies.
From the applications listed that the infection attached to seems most can be re downloaded.

This is a horrible infection to have on a computer. From here since the infection has been removed is really, to do a reformat of the machine.
If you like, the links I posted previously at BleepingComputers shows the struggles and attempts of other Victims.
To follow or read the links you do not have to join but, if you did have questions you would need to join and create a User ID.

What we can do from here now is to remove the tools and quarantine folders from your computer and I'll post preventive tips.

gurleygirl
2014-11-18, 00:06
I completed the last task, now what can I do? Also, I really need to get into my QB files, but am scared too. I backed them up last Tuesday as I saw the infection coming in, but if I open them (not sure if I can even open QB!) and the backed up files are infected, will it infect my computer all over again?

Most of the pics are saved, just none of my work for 2014. I'm ok with a reformat - which means getting my machine back to all its original hardware/software without any programs/files saved on it? Yes?

Lastly, should I turn on the antivirus?

Thanks again!!!!!

Juliet
2014-11-18, 00:31
I completed the last task, now what can I do? Also, I really need to get into my QB files, but am scared too. I backed them up last Tuesday as I saw the infection coming in, but if I open them (not sure if I can even open QB!) and the backed up files are infected, will it infect my computer all over again?
As far as removing the infection we have, but I cannot remove the damage and stated this when we first started.
If these things had been backed up before seeing an infection you would have them to redownload, and from what I saw in the log results, I say they are probably non-retrievable now. From here the files are encrypted, if you look at the files they will have extensions are just wont open. It shouldn't reinfect you but nothing is impossible.



Most of the pics are saved, just none of my work for 2014. I'm ok with a reformat - which means getting my machine back to all its original hardware/software without any programs/files saved on it? Yes?

Yes. At this point theres nothing more you really can do but, you really should read over the links supplied and read how this infection enters a computer.

Yes, please turn your antivirus back on.

Let's remove tools and quarantine folders now then make sure to read over my preventive tips.

~~~~~~~~~~~~~~~~~~~~~`


Download Delfix from here (http://general-changelog-team.fr/fr/downloads/finish/20-outils-de-xplode/9-delfix)
Ensure Remove disinfection tools is ticked
Also tick:
Create registry backup
Click Run
Purge system restore
http://www.hdrcgb.org.uk/g2g/delfix.jpg

Any other tools and files found can simply be deleted or uninstall via Add/Remove Programs in the Control Panel etc.


~~~~~~~~~~~~~~~~~


Answers to common security questions - Best Practices (http://www.bleepingcomputer.com/forums/t/407147/answers-to-common-security-questions-best-practices/) by quietman7, MVP
How Malware Spreads - How did I get infected? (http://www.bleepingcomputer.com/forums/t/287710/how-malware-spreads-how-did-i-get-infected/) by quietman7, MVP
Simple and easy ways to keep your computer safe and secure on the Internet (http://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/) by Lawrence Abrams, MVP
How to Prevent Malware (http://users.telenet.be/bluepatchy/miekiemoes/prevention.html) by miekiemoes, MVP
How to backup and restore your data using Cobian Backup (http://www.bleepingcomputer.com/tutorials/backup-and-restore-data-with-cobian-backup/) by YourHighness
Slow Computer/browser? It May Not Be Malware (http://www.bleepingcomputer.com/forums/t/87058/slow-computerbrowser-check-here-first;-it-may-not-be-malware/) by quietman7, MVP


The following programmes come highly recommended in the security community.

http://3-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xKsUqI5A.png.pagespeed.ic.vn1Hlvqi8h.jpgAdBlock (https://adblockplus.org/en/firefox) is a browser add-on that blocks annoying banners, pop-ups and video ads.
http://i.imgur.com/E8I37RF.pngCryptoPrevent (https://www.foolishit.com/) places policy restrictions on loading points for ransomware (eg.CryptoPrevent), preventing your files from being encrypted.
Important.
http://i.imgur.com/EG85Vjt.png Malwarebytes Anti-Exploit (https://www.malwarebytes.org/antiexploit/) (MBAE) is designed to prevent zero-day malware from exploiting vulnerable software.
http://3-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/x6YRrgUC.png.pagespeed.ic.HjgFxjvw2Z.jpgMalwarebytes Anti-Malware Premium (https://www.malwarebytes.org/) (MBAM) works in real-time along side your Anti-Virus to prevent malware execution.
http://1-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xjv4nhMJ.png.pagespeed.ic.A5YbWn1eDO.png NoScript (http://noscript.net/) is a Firefox add-on that blocks the actions of malicious scripts by using whitelisting and other technology.
http://i.imgur.com/3O8r9Uq.png (http://www.sandboxie.com/) Sandboxie (http://www.sandboxie.com/) isolates programmes of your choice, preventing files from being written to your HDD unless approved by you.
http://1-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/DgW1XL2.png.pagespeed.ce.v1OlJl_ZAS.png Secuina PSI (http://secunia.com/vulnerability_scanning/personal/) will scan your computer for vulnerable software that is outdated, and automatically find the latest update for you.
http://3-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xj1OLIec.png.pagespeed.ic.k6hhwopU0q.jpg SpywareBlaster (https://www.brightfort.com/spywareblaster.html) is a form of passive protection, designed to block the actions of malicious websites and tracking cookies.
http://3-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xJEP5iWI.png.pagespeed.ic.4tmM1lM7DQ.pngWeb of Trust (https://www.mywot.com/) (WOT) is a browser add-on designed to alert you before interacting with a potentially malicious website.

gurleygirl
2014-11-18, 00:58
Didn't know if you needed this.

# DelFix v10.8 - Logfile created 17/11/2014 at 17:44:27
# Updated 29/07/2014 by Xplode
# Username : Melissa - LAPTOP
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)

~ Removing disinfection tools ...

Deleted : C:\FRST
Deleted : C:\AdwCleaner
Deleted : C:\Users\Melissa\Desktop\FRST-OlderVersion
Deleted : C:\Users\Melissa\Desktop\mbar
Deleted : C:\Users\Melissa\Desktop\Addition.txt
Deleted : C:\Users\Melissa\Desktop\AdwCleaner.exe
Deleted : C:\Users\Melissa\Desktop\aswMBR.exe
Deleted : C:\Users\Melissa\Desktop\aswMBR.txt
Deleted : C:\Users\Melissa\Desktop\Fixlog.txt
Deleted : C:\Users\Melissa\Desktop\FRST.txt
Deleted : C:\Users\Melissa\Desktop\FRST64.exe
Deleted : C:\Users\Melissa\Desktop\JRT.exe
Deleted : C:\Users\Melissa\Desktop\JRT.txt
Deleted : C:\Users\Melissa\Desktop\MBR.dat
Deleted : HKLM\SOFTWARE\AdwCleaner
Deleted : HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWMBR

~ Creating registry backup ... OK

~ Cleaning system restore ...

Deleted : RP #219 [Scheduled Checkpoint | 11/14/2014 03:54:59]
Deleted : RP #220 [Malwarebytes Anti-Rootkit Restore Point | 11/14/2014 20:59:17]

New restore point created !

########## - EOF - ##########

I will review everything you posted. I knew you wouldn't be able to get my files back to normal, but I appreciate all your help in getting me back to as normal as possible. I have a friend coming over to help with reformatting. Let me know if there is anything else I need to do.

Thanks again so much Juliet, you are a talented individual!

Juliet
2014-11-18, 01:07
I will review everything you posted. I knew you wouldn't be able to get my files back to normal, but I appreciate all your help in getting me back to as normal as possible. I have a friend coming over to help with reformatting. Let me know if there is anything else I need to do.

Thanks again so much Juliet, you are a talented individual!

We're glad to help :)

Juliet
2014-11-19, 21:05
Glad we could help. :)http://i204.photobucket.com/albums/bb106/Juliet702/sparkle.gif

Since this issue appears resolved ... this Topic is closed.