Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

I have the Poweliks Malware and would like help with removal.


  • This topic is locked This topic is locked
18 replies to this topic

#1 Laserrick

Laserrick

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:06:36 PM

Posted 05 December 2014 - 11:33 AM

Have run FRST here is post

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 03-12-2014
Ran by Kristen (administrator) on KRISTEN-THINK on 05-12-2014 11:10:58
Running from C:\Users\Kristen\Downloads
Loaded Profile: Kristen (Available profiles: Kristen & Kris)
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Lenovo) C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\CamMute.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
(Nitro PDF Software) C:\Program Files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe
(Nalpeiron Ltd.) C:\Windows\SysWOW64\NLSSRV32.EXE
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(LITE-ON TECHNOLOGY CORP.) C:\Program Files\Lenovo\Lenovo Slim USB Keyboard\Skd8821.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TpKnrres.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Message Center Plus\MCPLaunch.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\regsvr32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\NAPSTAT.EXE
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [Skd8821] => C:\Program Files\Lenovo\Lenovo Slim USB Keyboard\Skd8821.exe [384512 2011-03-22] (LITE-ON TECHNOLOGY CORP.)
HKLM\...\Run: [LENOVO.TPKNRRES] => C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe [293672 2013-01-28] (Lenovo Group Limited)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-26] (Intel Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Lenovo Registration] => C:\Program Files (x86)\Lenovo Registration\LenovoReg.exe [4315872 2011-06-01] (Lenovo, Inc.)
HKLM-x32\...\Run: [Fastboot] => C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe [733936 2013-07-02] (Lenovo)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5226600 2014-11-21] (AVAST Software)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1346962788-3022881501-2052787113-1000\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [22869088 2014-10-21] (Google)
HKU\S-1-5-21-1346962788-3022881501-2052787113-1000\...\Run: [146cfa0] => C:\Users\Kristen\AppData\Roaming\146cfa0.exe
HKU\S-1-5-21-1346962788-3022881501-2052787113-1000\...\Run: [GoogleUpdate] => C:\Users\Kristen\AppData\Roaming\FrameworkUpdate7\GoogleUpdate.exe                                                               
HKU\S-1-5-21-1346962788-3022881501-2052787113-1000\...\MountPoints2: {221288c3-cefb-11e3-b33e-806e6f6e6963} - Q:\LenovoQDrive.exe
HKU\S-1-5-21-1346962788-3022881501-2052787113-1000\...A8F59079A8D5}\localserver32: rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf>ktds (the data entry has 239 more characters). <==== Poweliks!
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop (1).ini ()
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
ShellIconOverlayIdentifiers: [SugarSyncBackedUp] -> {0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll No File
ShellIconOverlayIdentifiers: [SugarSyncPending] -> {62CCD8E3-9C21-41E1-B55E-1E26DFC68511} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll No File
ShellIconOverlayIdentifiers: [SugarSyncRoot] -> {A759AFF6-5851-457D-A540-F4ECED148351} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll No File
ShellIconOverlayIdentifiers: [SugarSyncShared] -> {1574C9EF-7D58-488F-B358-8B78C1538F51} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll No File
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKU\S-1-5-21-1346962788-3022881501-2052787113-1000\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://home.lenovo.com
HKU\S-1-5-21-1346962788-3022881501-2052787113-1000\Software\Microsoft\Internet Explorer\Main,Old Start Page = http://search.coupons.com/
HKU\S-1-5-21-1346962788-3022881501-2052787113-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006
HKU\S-1-5-21-1346962788-3022881501-2052787113-1000\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?q={searchTerms}
HKU\S-1-5-21-1346962788-3022881501-2052787113-1000\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
HKU\S-1-5-21-1346962788-3022881501-2052787113-1000\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?trackid=sp-006
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?fr=befhp&type=iehp-3.13-1406
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?trackid=sp-006
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006
SearchScopes: HKLM -> DefaultScope {E0E6A689-D9DC-410D-B9F9-748B9CC78FEB} URL = 
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
SearchScopes: HKLM-x32 -> DefaultScope {EFE522B3-7ABD-49CB-A5C3-A2AFBBA83B9D} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> {EFE522B3-7ABD-49CB-A5C3-A2AFBBA83B9D} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1346962788-3022881501-2052787113-1000 -> DefaultScope {EFE522B3-7ABD-49CB-A5C3-A2AFBBA83B9D} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1346962788-3022881501-2052787113-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-1346962788-3022881501-2052787113-1000 -> {1A02C0CA-3CEC-4EE0-8A04-664373AA3CD4} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1346962788-3022881501-2052787113-1000 -> {229DA86E-0353-40CE-8D8A-B4C253884DC6} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3291325&CUI=UN13422851613163739&UM=2
SearchScopes: HKU\S-1-5-21-1346962788-3022881501-2052787113-1000 -> {513BD094-5D50-4453-8418-F686681C3D33} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1346962788-3022881501-2052787113-1000 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://isearch.avg.com/search?cid={D6F04148-E7CB-493B-91C7-D9379A5FD6AA}&mid=e2862b387edd873c6936bee5f37b60f5-ac53c07b641c479106916844be6a03013a48429b&lang=us&ds=AVG&pr=fr&d=2011-12-11 09:47:27&v=9.0.0.18&sap=dsp&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1346962788-3022881501-2052787113-1000 -> {96bd48dd-741b-41ae-ac4a-aff96ba00f7e} URL = http://www.bing.com/search?FORM=U079DF&PC=U079&q={searchTerms}&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1346962788-3022881501-2052787113-1000 -> {AFDBDDAA-5D3F-42EE-B79C-185A7020515B} URL = 
SearchScopes: HKU\S-1-5-21-1346962788-3022881501-2052787113-1000 -> {C9F13383-82EB-45B1-AED5-387BB9FB6B2D} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3279415&CUI=UN39082197322256974&UM=2
SearchScopes: HKU\S-1-5-21-1346962788-3022881501-2052787113-1000 -> {EFE522B3-7ABD-49CB-A5C3-A2AFBBA83B9D} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1346962788-3022881501-2052787113-1000 -> {F13C5CAF-75D7-4ADC-937C-E3DFEB7D24F3} URL = http://search.coupons.com/search.asp?p=df&q={searchTerms}
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Handler-x32: http - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
 
FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Pro 8\npnitromozilla.dll (Nitro PDF)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1346962788-3022881501-2052787113-1000: @citrixonline.com/appdetectorplugin -> C:\Users\Kristen\AppData\Local\Citrix\Plugins\104\npappdetector.dll (Citrix Online)
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-11-11]
 
Chrome: 
=======
CHR Profile: C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-09-20]
CHR Extension: (Google Docs) - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-09-20]
CHR Extension: (Google Drive) - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-09-20]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-20]
CHR Extension: (YouTube) - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-09-20]
CHR Extension: (Google Search) - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-09-20]
CHR Extension: (Avast SafePrice) - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2014-11-21]
CHR Extension: (Google Sheets) - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-09-20]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2014-11-11]
CHR Extension: (Google Wallet) - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-09-20]
CHR Extension: (Gmail) - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-09-20]
CHR Profile: C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Google Drive) - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-09-20]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-06-28]
CHR Extension: (MixiDJ V30) - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fdkednngfjmpnljkolbapdednncafhen [2013-08-07]
CHR Extension: (Wajam) - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp [2013-08-07]
CHR Extension: (Google Wallet) - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-25]
CHR HKU\S-1-5-21-1346962788-3022881501-2052787113-1000\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - No Path
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2014-11-11]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-11-11]
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-11-11] (AVAST Software)
R2 FastbootService; C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe [140016 2013-07-02] (Lenovo)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [16232 2014-02-26] (Intel Corporation)
R2 Intel® Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [731648 2013-02-13] (Intel® Corporation) [File not signed]
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel® Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [169432 2013-03-12] (Intel Corporation)
R2 NitroDriverReadSpool8; C:\Program Files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe [230408 2013-06-17] (Nitro PDF Software)
S3 Power Manager DBC Service; C:\Program Files (x86)\Lenovo\PowerMgr\PWMDBSVC.EXE [63816 2013-02-26] (Lenovo)
S3 PwmEWSvc; C:\Program Files (x86)\Lenovo\PowerMgr\PWMEWSVC.EXE [186696 2013-02-26] (Lenovo Group Limited)
S4 Sks8821; C:\Program Files\Lenovo\Lenovo Slim USB Keyboard\Sks8821.exe [137216 2010-05-04] () [File not signed]
S4 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [22376 2013-02-04] ()
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5416720 2014-11-28] (TeamViewer GmbH)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-11-11] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [83280 2014-11-11] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-11-11] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-11-11] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2014-11-21] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2014-11-11] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2014-11-11] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2014-11-11] ()
R0 Fastboot; C:\Windows\System32\DRIVERS\fastboot.sys [56048 2013-07-02] (Windows ® Win 7 DDK provider)
R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [28008 2014-02-06] (Intel Corporation)
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-12-05 11:10 - 2014-12-05 11:12 - 00020604 _____ () C:\Users\Kristen\Downloads\FRST.txt
2014-12-05 11:10 - 2014-12-05 11:11 - 00000000 ____D () C:\FRST
2014-12-05 11:09 - 2014-12-05 11:09 - 09741664 _____ (SurfRight B.V.) C:\Users\Kristen\Downloads\HitmanPro_x64.exe
2014-12-05 11:07 - 2014-12-05 11:08 - 01944824 _____ (Bleeping Computer, LLC) C:\Users\Kristen\Downloads\rkill.exe
2014-12-05 11:06 - 2014-12-05 11:07 - 05600479 _____ (Swearware) C:\Users\Kristen\Downloads\ComboFix.exe
2014-12-05 11:05 - 2014-12-05 11:05 - 02117632 _____ (Farbar) C:\Users\Kristen\Downloads\FRST64.exe
2014-12-05 11:04 - 2014-12-05 11:04 - 00602112 _____ (OldTimer Tools) C:\Users\Kristen\Downloads\OTL.exe
2014-12-05 11:02 - 2014-12-05 11:02 - 15196248 _____ () C:\Users\Kristen\Downloads\RogueKiller.exe
2014-12-05 11:01 - 2014-12-05 11:01 - 02153472 _____ () C:\Users\Kristen\Downloads\AdwCleaner.exe
2014-12-05 11:00 - 2014-12-05 11:00 - 01707646 _____ (Thisisu) C:\Users\Kristen\Downloads\JRT.exe
2014-12-05 10:39 - 2014-12-05 10:39 - 00007168 _____ (Microsoft Corporation) C:\Users\Kristen\Downloads\dllhost.exe
2014-12-05 08:58 - 2014-12-05 08:58 - 00000000 ____D () C:\Program Files (x86)\Glary Utilities 5
2014-12-05 08:53 - 2014-12-05 08:56 - 14686064 _____ () C:\Users\Kristen\Downloads\gu5setup.exe
2014-12-03 09:00 - 2014-12-03 09:00 - 00000982 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10 Host.lnk
2014-12-03 09:00 - 2014-12-03 09:00 - 00000970 _____ () C:\Users\Public\Desktop\TeamViewer 10 Host.lnk
2014-12-02 16:19 - 2014-12-02 16:19 - 00002053 _____ () C:\Users\Public\Desktop\Google Slides.lnk
2014-12-02 16:19 - 2014-12-02 16:19 - 00002051 _____ () C:\Users\Public\Desktop\Google Sheets.lnk
2014-12-02 16:19 - 2014-12-02 16:19 - 00002041 _____ () C:\Users\Public\Desktop\Google Docs.lnk
2014-12-02 16:19 - 2014-12-02 16:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2014-12-02 16:18 - 2014-12-02 16:18 - 00880784 _____ (Google Inc.) C:\Users\Kristen\Downloads\googledrivesync (1).exe
2014-11-29 15:55 - 2014-11-29 15:56 - 00000000 ____D () C:\Users\Kristen\Desktop\Kristen Personal
2014-11-29 15:54 - 2014-11-29 15:54 - 00019968 _____ () C:\Users\Kristen\Desktop\Rent Payments.xls
2014-11-21 10:17 - 2014-11-10 22:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-11-21 10:17 - 2014-11-10 22:08 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
2014-11-21 10:17 - 2014-11-10 21:44 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-11-21 10:17 - 2014-11-10 21:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll
2014-11-14 08:29 - 2014-11-14 08:29 - 00000000 __SHD () C:\Users\Kristen\AppData\Local\EmieBrowserModeList
2014-11-12 08:50 - 2014-11-07 14:49 - 00388272 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-11-12 08:50 - 2014-11-07 14:23 - 00341168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-11-12 08:50 - 2014-11-05 23:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-11-12 08:50 - 2014-11-05 23:03 - 25110016 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-11-12 08:50 - 2014-11-05 23:03 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-11-12 08:50 - 2014-11-05 22:47 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-11-12 08:50 - 2014-11-05 22:46 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-11-12 08:50 - 2014-11-05 22:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-11-12 08:50 - 2014-11-05 22:44 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-11-12 08:50 - 2014-11-05 22:43 - 02884096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-11-12 08:50 - 2014-11-05 22:36 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-11-12 08:50 - 2014-11-05 22:35 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-11-12 08:50 - 2014-11-05 22:31 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-11-12 08:50 - 2014-11-05 22:30 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-11-12 08:50 - 2014-11-05 22:30 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-11-12 08:50 - 2014-11-05 22:29 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-11-12 08:50 - 2014-11-05 22:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-11-12 08:50 - 2014-11-05 22:23 - 06040064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-11-12 08:50 - 2014-11-05 22:20 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-11-12 08:50 - 2014-11-05 22:16 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-11-12 08:50 - 2014-11-05 22:13 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-11-12 08:50 - 2014-11-05 22:13 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-11-12 08:50 - 2014-11-05 22:12 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-11-12 08:50 - 2014-11-05 22:10 - 19781632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-11-12 08:50 - 2014-11-05 22:10 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-11-12 08:50 - 2014-11-05 22:07 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-11-12 08:50 - 2014-11-05 22:05 - 02277376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-11-12 08:50 - 2014-11-05 22:04 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-11-12 08:50 - 2014-11-05 22:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-11-12 08:50 - 2014-11-05 22:02 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-11-12 08:50 - 2014-11-05 22:00 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-11-12 08:50 - 2014-11-05 22:00 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-11-12 08:50 - 2014-11-05 21:59 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-11-12 08:50 - 2014-11-05 21:58 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-11-12 08:50 - 2014-11-05 21:57 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-11-12 08:50 - 2014-11-05 21:48 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-11-12 08:50 - 2014-11-05 21:42 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-11-12 08:50 - 2014-11-05 21:41 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-11-12 08:50 - 2014-11-05 21:41 - 00716800 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-11-12 08:50 - 2014-11-05 21:39 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-11-12 08:50 - 2014-11-05 21:38 - 02124288 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-11-12 08:50 - 2014-11-05 21:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-11-12 08:50 - 2014-11-05 21:36 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-11-12 08:50 - 2014-11-05 21:34 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-11-12 08:50 - 2014-11-05 21:30 - 14390272 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-11-12 08:50 - 2014-11-05 21:22 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-11-12 08:50 - 2014-11-05 21:21 - 04298240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-11-12 08:50 - 2014-11-05 21:21 - 02051072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-11-12 08:50 - 2014-11-05 21:20 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-11-12 08:50 - 2014-11-05 21:17 - 02365440 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-11-12 08:50 - 2014-11-05 21:04 - 01550336 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-11-12 08:50 - 2014-11-05 21:03 - 12819456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-11-12 08:50 - 2014-11-05 20:53 - 00799232 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-11-12 08:50 - 2014-11-05 20:52 - 01892864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-11-12 08:50 - 2014-11-05 20:48 - 01310208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-11-12 08:50 - 2014-11-05 20:47 - 00708096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-11-12 08:50 - 2014-11-05 12:56 - 00304640 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-11-12 08:50 - 2014-11-05 12:56 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-11-12 08:50 - 2014-11-05 12:52 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-11-12 08:50 - 2014-10-13 21:16 - 00155064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-11-12 08:50 - 2014-10-13 21:13 - 00683520 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-11-12 08:50 - 2014-10-13 21:12 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-11-12 08:50 - 2014-10-13 21:09 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2014-11-12 08:50 - 2014-10-13 21:07 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2014-11-12 08:50 - 2014-10-13 20:47 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2014-11-12 08:50 - 2014-10-13 20:46 - 00681984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2014-11-12 08:49 - 2014-10-13 20:50 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-11-12 08:49 - 2014-10-13 20:49 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-11-12 08:44 - 2014-10-02 21:12 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2014-11-12 08:44 - 2014-10-02 21:11 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2014-11-12 08:44 - 2014-10-02 21:11 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2014-11-12 08:44 - 2014-10-02 21:11 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2014-11-12 08:44 - 2014-10-02 21:11 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2014-11-12 08:44 - 2014-10-02 20:44 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2014-11-12 08:44 - 2014-10-02 20:44 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2014-11-12 08:44 - 2014-10-02 20:44 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2014-11-12 08:44 - 2014-09-19 04:42 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-11-12 08:44 - 2014-09-19 04:42 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-11-12 08:44 - 2014-09-19 04:42 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-11-12 08:44 - 2014-09-19 04:42 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-11-12 08:44 - 2014-09-19 04:42 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-11-12 08:44 - 2014-09-19 04:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-11-12 08:44 - 2014-09-19 04:23 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-11-12 08:44 - 2014-09-19 04:23 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-11-12 08:44 - 2014-09-19 04:23 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-11-12 08:44 - 2014-09-19 04:23 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-11-12 08:44 - 2014-09-19 04:23 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-11-12 08:44 - 2014-09-19 04:23 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-11-12 08:44 - 2014-08-21 01:43 - 01882624 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-11-12 08:44 - 2014-08-21 01:40 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-11-12 08:44 - 2014-08-21 01:26 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-11-12 08:44 - 2014-08-21 01:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-11-12 08:44 - 2014-08-11 21:02 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL
2014-11-12 08:44 - 2014-08-11 20:36 - 00701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10K.DLL
2014-11-12 08:43 - 2014-10-24 20:57 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-11-12 08:43 - 2014-10-24 20:32 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2014-11-12 08:43 - 2014-10-17 21:05 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2014-11-12 08:43 - 2014-10-17 20:33 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2014-11-12 08:43 - 2014-10-13 21:13 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-11-12 08:43 - 2014-10-13 20:50 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-11-12 08:43 - 2014-10-09 19:57 - 03198976 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-11-11 09:22 - 2014-11-11 09:22 - 00000000 ____D () C:\Users\Kristen\AppData\Roaming\Dropbox
2014-11-11 09:10 - 2014-11-11 09:10 - 00001975 _____ () C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2014-11-11 09:10 - 2014-11-11 09:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2014-11-11 09:09 - 2014-12-01 08:19 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-11-11 09:09 - 2014-11-21 21:15 - 01050432 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2014-11-11 09:09 - 2014-11-11 09:09 - 00436624 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2014-11-11 09:09 - 2014-11-11 09:09 - 00364512 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-11-11 09:09 - 2014-11-11 09:09 - 00323616 _____ (Dropbox, Inc.) C:\Users\Public\Desktop\DropboxInstallerAvast.exe
2014-11-11 09:09 - 2014-11-11 09:09 - 00267632 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-11-11 09:09 - 2014-11-11 09:09 - 00116728 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2014-11-11 09:09 - 2014-11-11 09:09 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-11-11 09:09 - 2014-11-11 09:09 - 00083280 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-11-11 09:09 - 2014-11-11 09:09 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-11-11 09:09 - 2014-11-11 09:09 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-11-11 09:09 - 2014-11-11 09:09 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-11-11 09:08 - 2014-11-11 09:08 - 00000000 ____D () C:\Program Files\AVAST Software
2014-11-11 08:28 - 2014-12-03 09:02 - 00000000 ____D () C:\Program Files (x86)\TeamViewer
2014-11-11 08:28 - 2014-11-11 08:28 - 00000000 ____D () C:\Users\Kristen\AppData\Roaming\TeamViewer
2014-11-11 08:25 - 2014-11-11 08:25 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\Kristen\Downloads\mbam-setup-2.0.3.1025.exe
2014-11-09 14:07 - 2014-11-09 14:07 - 00008542 _____ () C:\Users\Kristen\AppData\Roaming\DECRYPT_INSTRUCTION.HTML
2014-11-09 14:07 - 2014-11-09 14:07 - 00008542 _____ () C:\Users\Kristen\AppData\DECRYPT_INSTRUCTION.HTML
2014-11-09 14:07 - 2014-11-09 14:07 - 00004214 _____ () C:\Users\Kristen\AppData\Roaming\DECRYPT_INSTRUCTION.TXT
2014-11-09 14:07 - 2014-11-09 14:07 - 00004214 _____ () C:\Users\Kristen\AppData\DECRYPT_INSTRUCTION.TXT
2014-11-09 14:00 - 2014-11-09 14:00 - 00008542 _____ () C:\Users\Kristen\AppData\Local\DECRYPT_INSTRUCTION.HTML
2014-11-09 14:00 - 2014-11-09 14:00 - 00004214 _____ () C:\Users\Kristen\AppData\Local\DECRYPT_INSTRUCTION.TXT
2014-11-09 13:55 - 2014-11-09 13:55 - 00008542 _____ () C:\ProgramData\DECRYPT_INSTRUCTION.HTML
2014-11-09 13:55 - 2014-11-09 13:55 - 00004214 _____ () C:\ProgramData\DECRYPT_INSTRUCTION.TXT
2014-11-09 11:33 - 2014-11-16 08:43 - 00000000 ____D () C:\ProgramData\ZozatJeqeb
2014-11-09 11:33 - 2014-11-16 08:43 - 00000000 ____D () C:\ProgramData\FamuSehi
2014-11-09 11:32 - 2014-11-10 14:53 - 00000160 ____H () C:\ProgramData\@system3.att
2014-11-09 11:31 - 2014-11-11 09:21 - 00000000 ____D () C:\Users\Kristen\AppData\Roaming\FrameworkUpdate7
2014-11-09 11:31 - 2014-11-10 14:53 - 00000424 _____ () C:\ProgramData\@system.temp
2014-11-09 11:31 - 2014-11-09 11:31 - 00000448 ____H () C:\Users\Kristen\AppData\Roaming\麽鎒駓覜
2014-11-09 11:30 - 2014-11-21 14:47 - 00000000 ___HD () C:\146cfa0
2014-11-05 14:30 - 2014-11-05 14:30 - 00000000 ____D () C:\Users\Default\AppData\Local\Google
2014-11-05 14:30 - 2014-11-05 14:30 - 00000000 ____D () C:\Users\Default User\AppData\Local\Google
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-12-05 10:37 - 2014-09-24 08:52 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-12-05 10:31 - 2009-07-13 23:45 - 00034432 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-12-05 10:31 - 2009-07-13 23:45 - 00034432 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-12-05 10:26 - 2014-09-20 21:29 - 01537526 _____ () C:\Windows\WindowsUpdate.log
2014-12-05 10:22 - 2014-09-20 11:17 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-12-05 10:22 - 2010-11-20 22:47 - 00708708 _____ () C:\Windows\PFRO.log
2014-12-05 10:22 - 2009-07-14 00:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-12-05 10:22 - 2009-07-13 23:51 - 00063527 _____ () C:\Windows\setupact.log
2014-12-05 10:18 - 2014-09-20 11:17 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-12-05 08:38 - 2014-09-20 13:49 - 00000000 ____D () C:\Users\Kristen\AppData\Local\CrashDumps
2014-12-03 09:00 - 2014-09-24 09:11 - 00000000 ____D () C:\Program Files (x86)\Citrix
2014-12-02 16:27 - 2014-09-20 13:47 - 00000000 ____D () C:\MIMS.Net
2014-12-02 16:19 - 2014-09-20 11:17 - 00000000 ____D () C:\Program Files (x86)\Google
2014-11-29 14:45 - 2013-08-03 09:05 - 00000000 ____D () C:\Users\Kristen\AppData\Local\CRE
2014-11-27 12:13 - 2014-09-20 11:18 - 00002194 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-11-27 11:43 - 2014-09-24 08:52 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-11-27 11:42 - 2014-09-24 08:52 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-11-27 11:42 - 2014-09-24 08:52 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-11-21 14:48 - 2012-08-26 07:34 - 00000000 ____D () C:\Users\Kristen\Desktop\Copy of Jared's Photos
2014-11-21 14:48 - 2008-03-01 12:01 - 00000000 ____D () C:\Users\Kristen\AppData\Roaming\U3
2014-11-21 14:48 - 2007-06-29 08:13 - 00000000 ____D () C:\Users\Kristen\AppData\Roaming\Sun
2014-11-21 14:48 - 2007-02-19 11:08 - 00000000 ____D () C:\Users\Kristen\AppData\Roaming\Real
2014-11-21 14:48 - 2007-02-16 08:38 - 00000000 ____D () C:\Users\Kristen\AppData\Roaming\Talkback
2014-11-21 14:47 - 2014-09-27 09:59 - 00000000 ___HD () C:\ProgramData\RICOH_DRV
2014-11-21 14:47 - 2014-09-23 08:13 - 00000000 ____D () C:\Users\Kristen\AppData\Roaming\Nitro
2014-11-21 14:47 - 2014-09-23 08:13 - 00000000 ____D () C:\Users\Kristen\AppData\Roaming\FileOpen
2014-11-21 14:47 - 2014-09-20 21:33 - 00000000 ____D () C:\Users\Kristen\AppData\Roaming\Adobe
2014-11-21 14:47 - 2014-09-20 15:52 - 00000000 ____D () C:\Users\Kristen\AppData\Roaming\Nitro PDF
2014-11-21 14:47 - 2014-09-20 14:19 - 00000000 ____D () C:\Users\Kristen\AppData\Local\Apple Computer
2014-11-21 14:47 - 2014-09-20 13:50 - 00000000 ____D () C:\Users\Kristen\AppData\Roaming\MIMS
2014-11-21 14:47 - 2014-09-20 11:17 - 00000000 ____D () C:\Users\Kristen\AppData\Local\Google
2014-11-21 14:47 - 2014-04-26 11:34 - 00000000 ____D () C:\ProgramData\Lenovo
2014-11-21 14:47 - 2013-08-03 09:05 - 00000000 ____D () C:\Users\Kristen\AppData\Local\Conduit
2014-11-21 14:47 - 2013-07-13 07:01 - 00000000 ____D () C:\Users\Kristen\AppData\Roaming\IObit
2014-11-21 14:47 - 2012-12-12 14:39 - 00000000 ____D () C:\Users\Kristen\AppData\Roaming\Malwarebytes
2014-11-21 14:47 - 2010-12-08 14:13 - 00000000 ____D () C:\Users\Kristen\AppData\Local\Move Networks
2014-11-21 14:47 - 2007-05-21 13:47 - 00000000 ___HD () C:\Users\Kristen\AppData\Roaming\Move Networks
2014-11-21 14:47 - 2007-02-12 16:56 - 00000000 ____D () C:\Users\Kristen\AppData\Roaming\Apple Computer
2014-11-21 14:47 - 2006-04-27 10:01 - 00000000 ____D () C:\Users\Kristen\AppData\Roaming\AdobeAUM
2014-11-21 14:46 - 2014-04-04 08:53 - 00000000 ____D () C:\Users\Kristen\Desktop\Funeral home
2014-11-21 14:46 - 2009-03-16 15:25 - 00000000 ____D () C:\Users\Kristen\Desktop\Jared's Photos
2014-11-18 09:27 - 2014-09-20 13:47 - 00000000 ____D () C:\MIMS
2014-11-16 08:55 - 2009-07-14 00:13 - 00783606 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-11-15 14:09 - 2014-09-20 11:17 - 00003894 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-11-15 14:09 - 2014-09-20 11:17 - 00003642 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-11-13 03:44 - 2009-07-13 23:45 - 00368232 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-11-13 03:40 - 2014-09-20 10:41 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-11-13 03:17 - 2014-09-20 10:02 - 00000000 ____D () C:\Windows\system32\MRT
2014-11-13 03:10 - 2014-09-20 10:02 - 103374192 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-11-11 09:07 - 2014-09-20 21:33 - 00092944 _____ () C:\Users\Kristen\AppData\Local\GDIPFONTCACHEV1.DAT
2014-11-11 08:43 - 2012-12-12 14:39 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-11-09 11:33 - 2006-04-22 10:30 - 00000000 ____D () C:\ProgramData\Windows Genuine Advantage
2014-11-05 14:30 - 2009-07-14 00:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
 
Files to move or delete:
====================
C:\Users\Kris\NTUSER (1).DAT
C:\Users\Kristen\NTUSER (1).DAT
 
 
Some content of TEMP:
====================
C:\Users\Kristen\AppData\Local\Temp\CitrixOnlineLauncher.exe
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2014-11-05 14:57
 
==================== End Of Log ============================


BC AdBot (Login to Remove)

 


#2 B-boy/StyLe/

B-boy/StyLe/

    Bleepin' Freestyler


  • Malware Response Team
  • 8,307 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bulgaria
  • Local time:02:36 AM

Posted 05 December 2014 - 02:23 PM

Hello! Welcome to BleepingComputer Forums! :welcome:
My name is Georgi and and I will be helping you with your computer problems.

Before we begin, please note the following:

  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The logs can take some time to research, so please be patient with me.
  • Stay with the topic until I tell you that your system is clean. Missing symptoms does not mean that everything is okay.
  • Instructions that I give are for your system only!
  • Please do not run any tools until requested ! The reason for this is so I know what is going on with the machine at any time. Some programs can interfere with others and hamper the recovery process.
  • Please perform all steps in the order received. If you can't understand something don't hesitate to ask.
  • Again I would like to remind you to make no further changes to your computer unless I direct you to do so. I will not help you if you do not follow my instructions.

 

 

You forgot to post the Addition.txt log file.

 

 

Regards,

Georgi


cXfZ4wS.png


#3 B-boy/StyLe/

B-boy/StyLe/

    Bleepin' Freestyler


  • Malware Response Team
  • 8,307 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bulgaria
  • Local time:02:36 AM

Posted 08 December 2014 - 04:59 AM

Hi,

 

Are you still around? Just checking. No rush. :)

 

 

Regards,

Georgi


cXfZ4wS.png


#4 Laserrick

Laserrick
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:06:36 PM

Posted 08 December 2014 - 11:17 AM

Hi Georgi
 
Thanks for helping. Here is the additional
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 03-12-2014
Ran by Kristen at 2014-12-05 11:13:12
Running from C:\Users\Kristen\Downloads
Boot Mode: Normal
==========================================================
 
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
 PowerDVD Create 10 (x32 Version: 10.0.1.2704 - CyberLink Corp.) Hidden
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.4.0.2710 - Adobe Systems Incorporated)
Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.239 - Adobe Systems Incorporated)
Adobe Reader X (10.1.7) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.7 - Adobe Systems Incorporated)
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.0.2208 - AVAST Software)
Citrix Online Launcher (HKLM-x32\...\{75B8A55E-0762-4676-AAC0-6FDF025B034B}) (Version: 1.0.220 - Citrix)
Compatibility Pack for the 2007 Office system (HKLM-x32\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6514.5001 - Microsoft Corporation)
Create Recovery Media (HKLM-x32\...\{50DC5136-21E8-48BC-97E5-1AD055F6B0B6}) (Version: 1.20.0.00 - Lenovo Group Limited)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 39.0.2171.71 - Google Inc.)
Google Drive (HKLM-x32\...\{C60F3836-333A-4AE2-B526-CFDBA143A9BA}) (Version: 1.18.7821.2489 - Google, Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.0.0.1323 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.18.10.3220 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 13.0.0.1098 - Intel Corporation)
Intel® SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 3.0.0.66956 - Intel Corporation)
Intel® USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 2.5.0.19 - Intel Corporation)
Lenovo Patch Utility 64 bit (HKLM\...\{ABE4638D-D208-4061-9F26-E3E11E3A1E0C}) (Version: 1.3.1.1 - Lenovo Group Limited)
Lenovo Registration (HKLM-x32\...\{6707C034-ED6B-4B6A-B21F-969B3606FBDE}) (Version: 1.0.3 - Lenovo Inc.)
Lenovo Slim USB Keyboard (HKLM\...\{494D80C4-3557-4D73-A153-65FE4B3ECDC3}) (Version: 1.10 - Lenovo)
Lenovo System Update (HKLM-x32\...\{25C64847-B900-48AD-A164-1B4F9B774650}) (Version: 5.02.0007 - Lenovo)
Lenovo User Guide (HKLM-x32\...\{13F59938-C595-479C-B479-F171AB9AF64F}) (Version: 1.0.0008.00 - Lenovo)
Message Center Plus (HKLM\...\{3849486C-FF09-4F5D-B491-3E179D58EE15}) (Version: 3.1.0004.00 - Lenovo Group Limited)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office Professional Edition 2003 (HKLM-x32\...\{90110409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
MIMS Elite Program files (HKLM-x32\...\{8C3EAA6A-1185-427F-99C6-28621ABE96E7}) (Version: 11 - Twin Tiers Technologies)
Nitro Pro 8 (HKLM\...\{07E55FB8-966C-4FA5-815D-D1F5AC8B1D87}) (Version: 8.5.5.2 - Nitro)
Power Manager (HKLM-x32\...\{DAC01CEE-5BAE-42D5-81FC-B687E84E8405}_is1) (Version: 3.01.0004 - Lenovo Group Limited)
PowerDVD Create (HKLM-x32\...\InstallShield_{DE485075-8CD3-4A1E-9ABC-6412EBA44872}) (Version: 10.0 - CyberLink Corp.)
RapidBoot HDD Accelerator (HKLM-x32\...\Fastboot) (Version: 1.1.1.1 - Lenovo)
Realtek Ethernet Controller All-In-One Windows Driver (HKLM-x32\...\{F7E7F0CB-AA41-4D5A-B6F2-8E6738EB063F}) (Version: 7.67.1226.2012 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6844 - Realtek Semiconductor Corp.)
TeamViewer 10 Host (HKLM-x32\...\TeamViewer) (Version: 10.0.36244 - TeamViewer)
ThinkVantage Communications Utility (HKLM\...\{88C6A6D9-324C-46E8-BA87-563D14021442}_is1) (Version: 3.0.42.0 - Lenovo)
View Management Utility (HKLM\...\View Management Utility_is1) (Version: 3.0.1.20120921 - Lenovo Inc.)
WaveEditor (x32 Version: 1.0.1.4514 - CyberLink Corp.) Hidden
Windows Driver Package - Intel Corporation (igfx) Display  (06/24/2013 9.18.10.3220) (HKLM\...\279F572DD6D797E852EE092875A1D4B6A65C48EF) (Version: 06/24/2013 9.18.10.3220 - Intel Corporation)
Windows Driver Package - Intel System  (02/25/2013 9.4.0.1017) (HKLM\...\0A6166936538BB5B864A5723AF3A45E6D54FC14A) (Version: 02/25/2013 9.4.0.1017 - Intel)
Windows Driver Package - Intel System  (02/25/2013 9.4.0.1017) (HKLM\...\AE21626B45E3873B80BDD584D229A19CD48EF2D0) (Version: 02/25/2013 9.4.0.1017 - Intel)
Windows Driver Package - Intel System  (02/25/2013 9.4.0.1017) (HKLM\...\D0BD2762F58C24C10CB784FDD17B9D98FF2470FF) (Version: 02/25/2013 9.4.0.1017 - Intel)
Windows Driver Package - Intel USB  (02/25/2013 9.4.0.1017) (HKLM\...\65AB5CB2D70EB936A3BC424D9E64EF8B676558B4) (Version: 02/25/2013 9.4.0.1017 - Intel)
Windows Driver Package - Intel® Corporation (IntcDAud) MEDIA  (05/22/2013 6.16.00.3112) (HKLM\...\1CD14F8CAAAFF160D1FB8F12ABC0298A517BB394) (Version: 05/22/2013 6.16.00.3112 - Intel® Corporation)
Windows Driver Package - Realtek Semiconductor Corp. HD Audio Driver (02/19/2013 6.0.1.6844) (HKLM\...\2EA098366EBDF7112F40FDC23F33AEEB37BD2732) (Version: 02/19/2013 6.0.1.6844 - Realtek Semiconductor Corp.)
 
==================== Custom CLSID (selected items): ==========================
 
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
 
CustomCLSID: HKU\S-1-5-21-1346962788-3022881501-2052787113-1000_Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\localserver32 -> rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf>ktds (the data entry has 247 more characters). <==== Poweliks?
 
==================== Restore Points  =========================
 
05-12-2014 15:35:17 Windows Modules Installer
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 21:34 - 2009-06-10 16:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
 
Task: {335DF3FB-0233-4682-9E9F-78E8AD712275} - System32\Tasks\CLMLSvc => C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [2013-03-06] (CyberLink)
Task: {34B40E58-A810-4D68-9787-4701B944C405} - System32\Tasks\TVT\TVSUUpdateTask => C:\Program Files (x86)\Lenovo\System Update\tvsuShim.exe [2013-02-04] ()
Task: {5ED22B53-CA00-49FF-A56A-DFDC01F0C5CF} - System32\Tasks\Lenovo\Message Center Plus Launcher => C:\Program Files (x86)\Lenovo\message center plus\mcplaunch.exe [2012-05-15] (Lenovo)
Task: {628EDF36-DA6D-4382-9ABC-CB59D865C593} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-27] (Adobe Systems Incorporated)
Task: {6608B510-2305-49A2-8D6C-42808935E13A} - System32\Tasks\PMTask => C:\Program Files (x86)\Lenovo\PowerMgr\PwmIdTsv.exe [2013-02-26] (Lenovo Group Limited)
Task: {76304FC9-0A66-432A-85AA-50EFD824D198} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2013-02-19] (Realtek Semiconductor)
Task: {7F92B5F1-E4D3-43B6-B519-C1F6902746FA} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-09-20] (Google Inc.)
Task: {D8BFA84C-57A1-4FCC-828C-8BBB5FA83ED2} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-11-11] (AVAST Software)
Task: {D99855FD-549C-44E8-92FF-57440921A533} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-09-20] (Google Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (whitelisted) =============
 
2014-12-05 08:38 - 2014-12-05 08:38 - 02905088 _____ () C:\Program Files\AVAST Software\Avast\defs\14120501\algo.dll
2014-04-26 12:32 - 2013-07-02 17:33 - 00033520 _____ () C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBServiceps.dll
2013-03-06 23:49 - 2013-03-06 23:49 - 00626240 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
2013-03-06 23:52 - 2013-03-06 23:52 - 00015424 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
2014-11-11 09:09 - 2014-11-11 09:09 - 38562088 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2014-04-26 12:23 - 2013-03-12 16:20 - 01199576 _____ () C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\ACE.dll
2014-11-27 12:13 - 2014-11-25 01:39 - 01077064 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\libglesv2.dll
2014-11-27 12:13 - 2014-11-25 01:39 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\libegl.dll
2014-11-27 12:13 - 2014-11-25 01:39 - 09009480 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\pdf.dll
2014-11-27 12:13 - 2014-11-25 01:39 - 01677128 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\ffmpegsumo.dll
2014-11-27 12:13 - 2014-11-25 01:39 - 14910280 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\PepperFlash\pepflashplayer.dll
 
==================== Alternate Data Streams (whitelisted) =========
 
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
 
AlternateDataStreams: C:\Windows:nlsPreferences
 
==================== Safe Mode (whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== EXE Association (whitelisted) =============
 
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
 
 
==================== MSCONFIG/TASK MANAGER disabled items =========
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\Services: Sks8821 => 2
MSCONFIG\Services: SUService => 3
MSCONFIG\startupreg: Power Manager Startup Utility => C:\Program Files (x86)\Lenovo\PowerMgr\DPMHost.exe
 
========================= Accounts: ==========================
 
Administrator (S-1-5-21-1346962788-3022881501-2052787113-500 - Administrator - Disabled)
Guest (S-1-5-21-1346962788-3022881501-2052787113-501 - Limited - Disabled)
Kris (S-1-5-21-1346962788-3022881501-2052787113-1001 - Limited - Enabled) => C:\Users\Kris
Kristen (S-1-5-21-1346962788-3022881501-2052787113-1000 - Administrator - Enabled) => C:\Users\Kristen
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (12/05/2014 10:22:57 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (12/04/2014 11:59:45 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: iexplore.exe, version: 11.0.9600.17420, time stamp: 0x4a5bc637
Faulting module name: MSHTML.dll, version: 11.0.9600.17420, time stamp: 0x545ae63c
Exception code: 0xc00000fd
Fault offset: 0x0033e915
Faulting process id: 0xd88
Faulting application start time: 0xiexplore.exe0
Faulting application path: iexplore.exe1
Faulting module path: iexplore.exe2
Report Id: iexplore.exe3
 
Error: (12/04/2014 11:20:41 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: iexplore.exe, version: 11.0.9600.17420, time stamp: 0x4a5bcd6e
Faulting module name: ntdll.dll, version: 6.1.7601.18247, time stamp: 0x521ea8e7
Exception code: 0xc00000fd
Fault offset: 0x0002defe
Faulting process id: 0x1868
Faulting application start time: 0xiexplore.exe0
Faulting application path: iexplore.exe1
Faulting module path: iexplore.exe2
Report Id: iexplore.exe3
 
Error: (12/04/2014 09:51:49 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: iexplore.exe, version: 11.0.9600.17420, time stamp: 0x4a5bc5e1
Faulting module name: MSHTML.dll, version: 11.0.9600.17420, time stamp: 0x545ae63c
Exception code: 0xc00000fd
Fault offset: 0x00448a62
Faulting process id: 0x1f14
Faulting application start time: 0xiexplore.exe0
Faulting application path: iexplore.exe1
Faulting module path: iexplore.exe2
Report Id: iexplore.exe3
 
Error: (12/04/2014 09:45:01 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: iexplore.exe, version: 11.0.9600.17420, time stamp: 0x4a5bcb52
Faulting module name: MSHTML.dll, version: 11.0.9600.17420, time stamp: 0x545ae63c
Exception code: 0xc00000fd
Fault offset: 0x0014d2bc
Faulting process id: 0x36e0
Faulting application start time: 0xiexplore.exe0
Faulting application path: iexplore.exe1
Faulting module path: iexplore.exe2
Report Id: iexplore.exe3
 
Error: (12/04/2014 09:43:29 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: iexplore.exe, version: 11.0.9600.17420, time stamp: 0x4a5bce11
Faulting module name: MSHTML.dll, version: 11.0.9600.17420, time stamp: 0x545ae63c
Exception code: 0xc00000fd
Fault offset: 0x0014ddbf
Faulting process id: 0x163c
Faulting application start time: 0xiexplore.exe0
Faulting application path: iexplore.exe1
Faulting module path: iexplore.exe2
Report Id: iexplore.exe3
 
Error: (12/04/2014 09:41:32 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: iexplore.exe, version: 11.0.9600.17420, time stamp: 0x4a5bce11
Faulting module name: MSHTML.dll, version: 11.0.9600.17420, time stamp: 0x545ae63c
Exception code: 0xc00000fd
Fault offset: 0x0014ddbf
Faulting process id: 0x3258
Faulting application start time: 0xiexplore.exe0
Faulting application path: iexplore.exe1
Faulting module path: iexplore.exe2
Report Id: iexplore.exe3
 
Error: (12/04/2014 08:55:31 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: iexplore.exe, version: 11.0.9600.17420, time stamp: 0x4a5bc637
Faulting module name: MSHTML.dll, version: 11.0.9600.17420, time stamp: 0x545ae63c
Exception code: 0xc0000005
Fault offset: 0x000b2d80
Faulting process id: 0xc70
Faulting application start time: 0xiexplore.exe0
Faulting application path: iexplore.exe1
Faulting module path: iexplore.exe2
Report Id: iexplore.exe3
 
Error: (12/04/2014 08:44:18 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: iexplore.exe, version: 11.0.9600.17420, time stamp: 0x4ce7a46b
Faulting module name: MSHTML.dll, version: 11.0.9600.17420, time stamp: 0x545ae63c
Exception code: 0xc00000fd
Fault offset: 0x0014ddbf
Faulting process id: 0x574
Faulting application start time: 0xiexplore.exe0
Faulting application path: iexplore.exe1
Faulting module path: iexplore.exe2
Report Id: iexplore.exe3
 
Error: (12/04/2014 08:14:35 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: iexplore.exe, version: 11.0.9600.17420, time stamp: 0x4a5bc6b7
Faulting module name: MSHTML.dll, version: 11.0.9600.17420, time stamp: 0x545ae63c
Exception code: 0xc00000fd
Fault offset: 0x00093729
Faulting process id: 0x51c
Faulting application start time: 0xiexplore.exe0
Faulting application path: iexplore.exe1
Faulting module path: iexplore.exe2
Report Id: iexplore.exe3
 
 
System errors:
=============
Error: (12/05/2014 10:24:34 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
 
Error: (12/05/2014 10:23:46 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)
 
Error: (12/05/2014 10:11:24 AM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 40.
 
Error: (12/05/2014 10:11:24 AM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 70.
 
Error: (12/05/2014 10:08:56 AM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 40.
 
Error: (12/05/2014 10:08:56 AM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 70.
 
Error: (12/05/2014 09:11:28 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 70. The internal error state is 11.
 
Error: (12/05/2014 07:37:24 AM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 40.
 
Error: (12/05/2014 07:35:36 AM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 40.
 
Error: (12/05/2014 06:48:57 AM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 40.
 
 
Microsoft Office Sessions:
=========================
Error: (12/05/2014 10:22:57 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (12/04/2014 11:59:45 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: iexplore.exe11.0.9600.174204a5bc637MSHTML.dll11.0.9600.17420545ae63cc00000fd0033e915d8801d0104839a48143C:\Program Files\Internet Explorer\iexplore.exeC:\Windows\system32\MSHTML.dll87ab726f-7c3b-11e4-9162-448a5ba8d92d
 
Error: (12/04/2014 11:20:41 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: iexplore.exe11.0.9600.174204a5bcd6entdll.dll6.1.7601.18247521ea8e7c00000fd0002defe186801d0104265d41264C:\Program Files\Internet Explorer\iexplore.exeC:\Windows\SysWOW64\ntdll.dll12384ad3-7c36-11e4-9162-448a5ba8d92d
 
Error: (12/04/2014 09:51:49 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: iexplore.exe11.0.9600.174204a5bc5e1MSHTML.dll11.0.9600.17420545ae63cc00000fd00448a621f1401d0103661fd2b0dC:\Program Files\Internet Explorer\iexplore.exeC:\Windows\system32\MSHTML.dlla8567700-7c29-11e4-9162-448a5ba8d92d
 
Error: (12/04/2014 09:45:01 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: iexplore.exe11.0.9600.174204a5bcb52MSHTML.dll11.0.9600.17420545ae63cc00000fd0014d2bc36e001d010347a1f39f2C:\Program Files\Internet Explorer\iexplore.exeC:\Windows\system32\MSHTML.dllb4b18102-7c28-11e4-9162-448a5ba8d92d
 
Error: (12/04/2014 09:43:29 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: iexplore.exe11.0.9600.174204a5bce11MSHTML.dll11.0.9600.17420545ae63cc00000fd0014ddbf163c01d0103527fd4925C:\Program Files\Internet Explorer\iexplore.exeC:\Windows\system32\MSHTML.dll7e1dfa05-7c28-11e4-9162-448a5ba8d92d
 
Error: (12/04/2014 09:41:32 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: iexplore.exe11.0.9600.174204a5bce11MSHTML.dll11.0.9600.17420545ae63cc00000fd0014ddbf325801d01034a38d2e1eC:\Program Files\Internet Explorer\iexplore.exeC:\Windows\system32\MSHTML.dll386124e1-7c28-11e4-9162-448a5ba8d92d
 
Error: (12/04/2014 08:55:31 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: iexplore.exe11.0.9600.174204a5bc637MSHTML.dll11.0.9600.17420545ae63cc0000005000b2d80c7001d0102da1500a09C:\Program Files\Internet Explorer\iexplore.exeC:\Windows\system32\MSHTML.dllcae345e0-7c21-11e4-9162-448a5ba8d92d
 
Error: (12/04/2014 08:44:18 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: iexplore.exe11.0.9600.174204ce7a46bMSHTML.dll11.0.9600.17420545ae63cc00000fd0014ddbf57401d0102cd6cab3c6C:\Program Files\Internet Explorer\iexplore.exeC:\Windows\system32\MSHTML.dll39d9785f-7c20-11e4-9162-448a5ba8d92d
 
Error: (12/04/2014 08:14:35 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: iexplore.exe11.0.9600.174204a5bc6b7MSHTML.dll11.0.9600.17420545ae63cc00000fd0009372951c01d01028c8e4a488C:\Program Files\Internet Explorer\iexplore.exeC:\Windows\system32\MSHTML.dll12f10758-7c1c-11e4-9162-448a5ba8d92d
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i3-4130 CPU @ 3.40GHz
Percentage of memory in use: 33%
Total physical RAM: 3913.41 MB
Available physical RAM: 2608.65 MB
Total Pagefile: 7824.99 MB
Available Pagefile: 5859.95 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB
 
==================== Drives ================================
 
Drive c: (Windows7_OS) (Fixed) (Total:450.62 GB) (Free:375.12 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive e: (HBCD 15.2) (CDROM) (Total:0.58 GB) (Free:0 GB) CDFS
Drive q: (Lenovo_Recovery) (Fixed) (Total:13.67 GB) (Free:3.35 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: F96A4DE5)
Partition 1: (Active) - (Size=1.5 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=450.6 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=13.7 GB) - (Type=07 NTFS)
 
==================== End Of Log ============================


#5 B-boy/StyLe/

B-boy/StyLe/

    Bleepin' Freestyler


  • Malware Response Team
  • 8,307 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bulgaria
  • Local time:02:36 AM

Posted 08 December 2014 - 11:35 AM

Hi,

 

 
Please download the following file => [attachment=158991:fixlist.txt] and save it to the Desktop.
NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

Run FRST and press the Fix button just once and wait.
The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.

 

 

 

Regards,

Georgi


cXfZ4wS.png


#6 Laserrick

Laserrick
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:06:36 PM

Posted 09 December 2014 - 08:37 AM

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 07-12-2014 02
Ran by Kristen at 2014-12-08 13:16:42 Run:1
Running from C:\Users\Kristen\Downloads
Loaded Profiles: Kristen & Kris (Available profiles: Kristen & Kris)
Boot Mode: Normal
==============================================
 
Content of fixlist:
*****************
start
CloseProcesses:
HKU\S-1-5-21-1346962788-3022881501-2052787113-1000\...\Run: [146cfa0] => C:\Users\Kristen\AppData\Roaming\146cfa0.exe
C:\Users\Kristen\AppData\Roaming\146cfa0.exe
HKU\S-1-5-21-1346962788-3022881501-2052787113-1000\...\Run: [GoogleUpdate] => C:\Users\Kristen\AppData\Roaming\FrameworkUpdate7\GoogleUpdate.exe    
HKU\S-1-5-21-1346962788-3022881501-2052787113-1000\...A8F59079A8D5}\localserver32: rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf>ktds (the data entry has 239 more characters). <==== Poweliks!
SearchScopes: HKU\S-1-5-21-1346962788-3022881501-2052787113-1000 -> {229DA86E-0353-40CE-8D8A-B4C253884DC6} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3291325&CUI=UN13422851613163739&UM=2
SearchScopes: HKU\S-1-5-21-1346962788-3022881501-2052787113-1000 -> {C9F13383-82EB-45B1-AED5-387BB9FB6B2D} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3279415&CUI=UN39082197322256974&UM=2
CMD: del /F /Q /S "C:\DECRYPT_INSTRUCTION.HTML"
CMD: del /F /Q /S "C:\DECRYPT_INSTRUCTION.TXT"
2014-11-09 11:33 - 2014-11-16 08:43 - 00000000 ____D () C:\ProgramData\ZozatJeqeb
2014-11-09 11:33 - 2014-11-16 08:43 - 00000000 ____D () C:\ProgramData\FamuSehi
2014-11-09 11:32 - 2014-11-10 14:53 - 00000160 ____H () C:\ProgramData\@system3.att
2014-11-09 11:31 - 2014-11-11 09:21 - 00000000 ____D () C:\Users\Kristen\AppData\Roaming\FrameworkUpdate7
2014-11-09 11:31 - 2014-11-10 14:53 - 00000424 _____ () C:\ProgramData\@system.temp
2014-11-09 11:31 - 2014-11-09 11:31 - 00000448 ____H () C:\Users\Kristen\AppData\Roaming\麽鎒駓覜
2014-11-09 11:30 - 2014-11-21 14:47 - 00000000 ___HD () C:\146cfa0
2014-11-21 14:47 - 2013-08-03 09:05 - 00000000 ____D () C:\Users\Kristen\AppData\Local\Conduit
2014-11-09 11:33 - 2006-04-22 10:30 - 00000000 ____D () C:\ProgramData\Windows Genuine Advantage
emptytemp:
end
*****************
 
Processes closed successfully.
HKU\S-1-5-21-1346962788-3022881501-2052787113-1000\Software\Microsoft\Windows\CurrentVersion\Run\\146cfa0 => Value not found.
"C:\Users\Kristen\AppData\Roaming\146cfa0.exe" => File/Directory not found.
HKU\S-1-5-21-1346962788-3022881501-2052787113-1000\Software\Microsoft\Windows\CurrentVersion\Run\\GoogleUpdate => value deleted successfully.
"HKU\S-1-5-21-1346962788-3022881501-2052787113-1000\Software\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\localserver32" => Key not found.
"HKU\S-1-5-21-1346962788-3022881501-2052787113-1000\Software\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{09971cee-01b8-42bc-9d91-456b1faad6be}" => Key not found.
"HKCR\CLSID\{09971cee-01b8-42bc-9d91-456b1faad6be}" => Key not found.
"HKU\S-1-5-21-1346962788-3022881501-2052787113-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{09971cee-01b8-42bc-9d91-456b1faad6be}" => Key not found.
"HKCR\CLSID\{09971cee-01b8-42bc-9d91-456b1faad6be}" => Key not found.
"HKU\S-1-5-21-1346962788-3022881501-2052787113-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{229DA86E-0353-40CE-8D8A-B4C253884DC6}" => Key not found.
"HKCR\CLSID\{229DA86E-0353-40CE-8D8A-B4C253884DC6}" => Key not found.
"HKU\S-1-5-21-1346962788-3022881501-2052787113-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{C9F13383-82EB-45B1-AED5-387BB9FB6B2D}" => Key not found.
"HKCR\CLSID\{C9F13383-82EB-45B1-AED5-387BB9FB6B2D}" => Key not found.
 
=========  del /F /Q /S "C:\DECRYPT_INSTRUCTION.HTML" =========
 
 
Deleted file - C:\ProgramData\Lenovo\Themes\Wallpaper_think\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Lenovo\Themes\Wallpaper_touch\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Microsoft\OFFICE\DATA\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\Microsoft\RAC\PublishedData\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\RICOH_DRV\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\RICOH_DRV\RICOH MP C4503 PCL 6\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\ProgramData\RICOH_DRV\RICOH MP C4503 PCL 6\_common\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Apple Computer\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Apple Computer\iTunes\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Google\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Extensions\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\audio\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Storage\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\chrome-signin\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\chrome-signin\def\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\databases\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\audio\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fdkednngfjmpnljkolbapdednncafhen\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fdkednngfjmpnljkolbapdednncafhen\10.31.4.510_0\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fdkednngfjmpnljkolbapdednncafhen\10.31.4.510_0\Search\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fdkednngfjmpnljkolbapdednncafhen\10.31.4.510_0\Search\NewTabPages\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fdkednngfjmpnljkolbapdednncafhen\10.31.4.510_0\Search\NewTabPages\img\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fdkednngfjmpnljkolbapdednncafhen\10.31.4.510_0\tb\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\IndexedDB\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\IndexedDB\https_docs.google.com_0.indexeddb.leveldb\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Pepper Data\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Pepper Data\Shockwave Flash\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache\VQY2JJ85\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Storage\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Storage\ext\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Storage\ext\chrome-signin\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Storage\ext\chrome-signin\def\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Storage\ext\chrome-signin\def\databases\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Data\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Internet Explorer\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Media Player\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Media Player\Art Cache\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Media Player\Art Cache\LocalMLS\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Outlook\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Silverlight\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Silverlight\is\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Silverlight\is\pe4frbif.rhp\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Silverlight\is\pe4frbif.rhp\aqoch2k5.dd3\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Silverlight\is\pe4frbif.rhp\aqoch2k5.dd3\1\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Silverlight\is\pe4frbif.rhp\aqoch2k5.dd3\1\s\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Silverlight\is\pe4frbif.rhp\aqoch2k5.dd3\1\s\gx2dtgu0jwm3behddpeqaxumfnjfj0aese4jbh5v112dfe1kacaaaafa\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Silverlight\is\pe4frbif.rhp\aqoch2k5.dd3\1\s\gx2dtgu0jwm3behddpeqaxumfnjfj0aese4jbh5v112dfe1kacaaaafa\f\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Silverlight\is\pe4frbif.rhp\aqoch2k5.dd3\1\s\psld1rq2evnjg2ki2ziatkouhebg2l4klzm3vvurqxwtu41pinaaahda\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Silverlight\is\pe4frbif.rhp\aqoch2k5.dd3\1\s\psld1rq2evnjg2ki2ziatkouhebg2l4klzm3vvurqxwtu41pinaaahda\f\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Silverlight\is\pe4frbif.rhp\aqoch2k5.dd3\1\s\rwezhocofrlgs5fkm5xdwrzg2mxy4sck314tmtygqsjutqph0daaagga\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Silverlight\is\pe4frbif.rhp\aqoch2k5.dd3\1\s\rwezhocofrlgs5fkm5xdwrzg2mxy4sck314tmtygqsjutqph0daaagga\f\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Windows Live Photo Gallery\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Windows Mail\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Windows Mail\Backup\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Windows Mail\Backup\new\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Windows Mail\Stationery\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Windows Media\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Windows Media\11.0\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Windows Media\12.0\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Local\Move Networks\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Adobe\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Adobe\Acrobat\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Adobe\Acrobat\10.0\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Adobe\Acrobat\7.0\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Adobe\Acrobat\7.0\Messages\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Adobe\Acrobat\7.0\Messages\ENU\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Adobe\Acrobat\7.0\Updater\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Adobe\Flash Player\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Adobe\Flash Player\AssetCache\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Adobe\Flash Player\AssetCache\QGG6VAEX\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Adobe\Photoshop Album\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Adobe\Photoshop Album\3.0\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\AdobeAUM\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-09-26_134812.212521BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-09-26_134812.212521BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-09-26_140803.211833BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-09-26_140803.211833BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-09-26_141650.212427BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-09-26_141650.212427BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-09-26_144614.212369BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-09-26_144614.212369BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-09-27_101612.212534BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-09-27_101612.212534BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-09-27_184207.212658BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-09-27_184207.212658BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_134138.212524BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_134138.212524BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_141428.212649BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_141428.212649BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_143620.212223BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_143620.212223BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_144235.212276BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_144235.212276BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_151119.208146BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_151119.208146BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_151727.212713BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_151727.212713BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_171241.212584BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_171241.212584BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_172513.211435BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_172513.211435BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_175414.208640BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_175414.208640BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_182818.212672BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_182818.212672BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_184155.212467BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_184155.212467BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-03_101658.212525BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-03_101658.212525BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-03_102526.212531BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-03_102526.212531BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-03_103149.209347BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-03_103149.209347BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_171136.212503BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_171136.212503BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_184048.211973BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_184048.211973BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_184540.212654BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_184540.212654BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_193613.211906BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_193613.211906BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_194131.212821BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_194131.212821BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_195411.212579BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_195411.212579BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_200915.212485BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_200915.212485BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_202350.208426BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_202350.208426BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_203713.212220BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_203713.212220BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_215519.210723BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_215519.210723BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_220108.210688BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_220108.210688BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_221321.212260BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_221321.212260BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_221925.211961BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_221925.211961BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-05_090727.212611BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-05_090727.212611BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-07_102226.212623BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-07_102226.212623BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-07_123355.212607BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-07_123355.212607BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-07_124625.213807BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-07_124625.213807BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-07_152734.212745BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-07_152734.212745BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-07_153540.213570BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-07_153540.213570BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-07_161317.212012BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-07_161317.212012BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-07_165331.210873BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-07_165331.210873BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-07_215520.212352BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-07_215520.212352BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-07_231215.212428BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-07_231215.212428BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-07_233957.212769BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-07_233957.212769BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-08_122054.211615BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-08_122054.211615BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-08_125534.213038BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-08_125534.213038BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-08_132108.212681BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-08_132108.212681BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-08_132627.212677BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-08_132627.212677BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-08_134830.212619BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-08_134830.212619BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-08_135443.212494BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-08_135443.212494BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-08_143420.211970BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-08_143420.211970BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-08_153118.210911BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-08_153118.210911BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-08_212853.212119BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-08_212853.212119BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_092608.212734BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_092608.212734BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_102354.212643BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_102354.212643BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_140620.212611BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_140620.212611BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_141858.212501BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_141858.212501BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_143512.209364BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_143512.209364BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_145213.212453BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_145213.212453BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_151722.211540BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_151722.211540BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_153656.209772BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_153656.209772BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_155819.211412BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_155819.211412BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_170806.212294BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_170806.212294BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_174758.212301BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_174758.212301BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_175450.211089BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_175450.211089BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-15_162344.212557BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-15_162344.212557BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-15_164007.211765BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-15_164007.211765BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-15_202826.211885BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-15_202826.211885BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-16_103049.210161BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-16_103049.210161BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-16_125818.212983BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-16_125818.212983BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-16_131251.213087BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-16_131251.213087BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-16_133428.211558BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-16_133428.211558BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-16_172245.212526BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-16_172245.212526BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-16_173928.209174BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-16_173928.209174BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-16_184015.212399BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-16_184015.212399BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-16_193023.212067BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-16_193023.212067BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-16_212448.211437BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-16_212448.211437BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-17_170127.212514BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-17_170127.212514BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-17_191106.212444BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-17_191106.212444BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-17_201926.212557BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-17_201926.212557BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-17_210731.213372BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-17_210731.213372BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-17_215432.211300BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-17_215432.211300BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-17_220754.212779BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-17_220754.212779BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-18_134626.212874BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-18_134626.212874BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-19_155814.213050BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-19_155814.213050BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-19_160651.212517BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-19_160651.212517BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-19_232338.212263BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-19_232338.212263BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-19_233042.208167BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-19_233042.208167BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-19_234255.213007BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-19_234255.213007BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-20_142406.212543BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-20_142406.212543BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-20_145513.212781BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-20_145513.212781BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-20_151008.213217BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-20_151008.213217BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-20_152003.211831BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-20_152003.211831BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-20_155730.212611BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-20_155730.212611BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-20_164025.209353BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-20_164025.209353BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-20_165925.212810BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-20_165925.212810BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-20_171839.209925BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-20_171839.209925BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-21_231905.209588BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-21_231905.209588BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-22_120416.213342BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-22_120416.213342BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-22_151843.211853BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-22_151843.211853BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-22_153156.212317BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-22_153156.212317BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-22_154202.213198BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-22_154202.213198BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-22_174255.212690BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-22_174255.212690BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-22_191449.212958BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-22_191449.212958BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-22_192653.212886BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-22_192653.212886BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-23_134548.213950BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-23_134548.213950BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-23_135914.211417BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-23_135914.211417BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-23_141624.212475BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-23_141624.212475BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-24_103101.213068BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-24_103101.213068BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-24_160246.212699BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-24_160246.212699BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-24_165059.212821BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-24_165059.212821BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-25_092810.213163BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-25_092810.213163BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-25_114935.212185BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-25_114935.212185BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-25_181819.211909BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-25_181819.211909BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-25_183505.213256BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-25_183505.213256BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-26_134613.212397BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-26_134613.212397BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-26_140620.212597BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-26_140620.212597BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-26_144908.212320BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-26_144908.212320BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-27_143708.213173BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-27_143708.213173BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-27_182231.212885BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-27_182231.212885BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-27_183134.212891BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-27_183134.212891BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-27_190220.212590BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-27_190220.212590BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-27_231612.212342BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-27_231612.212342BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-28_101844.208813BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-28_101844.208813BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-28_122730.212798BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-28_122730.212798BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-28_130347.212438BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-28_130347.212438BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-28_132246.212562BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-28_132246.212562BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-28_133046.208756BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-28_133046.208756BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-28_194055.212681BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-28_194055.212681BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-28_201908.212783BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-28_201908.212783BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-28_203556.213008BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-28_203556.213008BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-28_204219.211936BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-28_204219.211936BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-29_122143.212852BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-29_122143.212852BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\FileOpen\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\IObit\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\IObit\Advanced SystemCare V6\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\IObit\Advanced SystemCare V6\Log\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Malwarebytes\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Logs\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Microsoft\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Microsoft\Templates\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\MIMS\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Move Networks\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Nitro\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Nitro\Pro\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Nitro\Pro\8.0\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Nitro\Pro\8.0\Stamps\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Nitro PDF\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Nitro PDF\Professional\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Real\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Real\RealMediaSDK\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Real\RealPlayer\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Real\RealPlayer\db\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Real\Update\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Real\Update\setup\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Real\Update\setup\data\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Real\Update\setup\data\pages\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Real\Update\setup\data\pages\superpass\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Real\Update\setup\data\pages\update\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Real\Update\setup\data\pages\weather\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\Java\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\Java\Deployment\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\Java\Deployment\SystemCache\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\Java\Deployment\SystemCache\6.0\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\Java\Deployment\SystemCache\6.0\11\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\Java\Deployment\SystemCache\6.0\17\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\Java\Deployment\SystemCache\6.0\23\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\Java\Deployment\SystemCache\6.0\24\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\Java\Deployment\SystemCache\6.0\25\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\Java\Deployment\SystemCache\6.0\26\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\Java\Deployment\SystemCache\6.0\29\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\Java\Deployment\SystemCache\6.0\3\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\Java\Deployment\SystemCache\6.0\32\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\Java\Deployment\SystemCache\6.0\4\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\Java\Deployment\SystemCache\6.0\42\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\Java\Deployment\SystemCache\6.0\46\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\Java\Deployment\SystemCache\6.0\50\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\Java\Deployment\SystemCache\6.0\54\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\Java\jre1.6.0_20\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\Java\jre1.6.0_22\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Talkback\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Talkback\MozillaOrg\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Talkback\MozillaOrg\Firefox2\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Talkback\MozillaOrg\Firefox2\Win32\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Talkback\MozillaOrg\Firefox2\Win32\2007072518\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\Talkback\MozillaOrg\Firefox2\Win32\2007111504\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\U3\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\AppData\Roaming\U3\0000051016073468\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\Desktop\Copy of Jared's Photos\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\Desktop\Funeral home\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\Desktop\Jared's Photos\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\Desktop\MMFH Docs\My Documents\Directions\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\Desktop\MMFH Docs\My Documents\Labels\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\Desktop\MMFH Docs\My Documents\MSWORKS\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\Desktop\MMFH Docs\My Documents\MSWORKS\Documents\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\Desktop\MMFH Docs\My Documents\MSWORKS\MANCHEST\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\Desktop\MMFH Docs\My Documents\MSWORKS\WKSTMPL\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\Desktop\MMFH Docs\My Documents\My Pictures\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\Desktop\MMFH Docs\My Documents\obit-net\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\Desktop\MMFH Docs\My Documents\Price Lists\DECRYPT_INSTRUCTION.HTML
Deleted file - C:\Users\Kristen\Desktop\MMFH Docs\My Documents\Roy - NJ Forms\DECRYPT_INSTRUCTION.HTML
 
========= End of CMD: =========
 
 
=========  del /F /Q /S "C:\DECRYPT_INSTRUCTION.TXT" =========
 
 
Deleted file - C:\MIMS.Net\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Lenovo\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Lenovo\MessageCenterPlus\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Lenovo\MessageCenterPlus\ServerRepository\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Lenovo\Themes\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Lenovo\Themes\Wallpaper_think\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Lenovo\Themes\Wallpaper_touch\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Microsoft\OFFICE\DATA\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\Microsoft\RAC\PublishedData\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\RICOH_DRV\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\RICOH_DRV\RICOH MP C4503 PCL 6\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\ProgramData\RICOH_DRV\RICOH MP C4503 PCL 6\_common\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Apple Computer\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Apple Computer\iTunes\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Google\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Extensions\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\audio\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Storage\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\chrome-signin\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\chrome-signin\def\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\databases\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\audio\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fdkednngfjmpnljkolbapdednncafhen\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fdkednngfjmpnljkolbapdednncafhen\10.31.4.510_0\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fdkednngfjmpnljkolbapdednncafhen\10.31.4.510_0\Search\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fdkednngfjmpnljkolbapdednncafhen\10.31.4.510_0\Search\NewTabPages\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fdkednngfjmpnljkolbapdednncafhen\10.31.4.510_0\Search\NewTabPages\img\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fdkednngfjmpnljkolbapdednncafhen\10.31.4.510_0\tb\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\IndexedDB\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\IndexedDB\https_docs.google.com_0.indexeddb.leveldb\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Pepper Data\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Pepper Data\Shockwave Flash\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache\VQY2JJ85\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Storage\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Storage\ext\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Storage\ext\chrome-signin\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Storage\ext\chrome-signin\def\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Storage\ext\chrome-signin\def\databases\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Data\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Internet Explorer\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Media Player\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Media Player\Art Cache\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Media Player\Art Cache\LocalMLS\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Outlook\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Silverlight\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Silverlight\is\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Silverlight\is\pe4frbif.rhp\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Silverlight\is\pe4frbif.rhp\aqoch2k5.dd3\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Silverlight\is\pe4frbif.rhp\aqoch2k5.dd3\1\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Silverlight\is\pe4frbif.rhp\aqoch2k5.dd3\1\s\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Silverlight\is\pe4frbif.rhp\aqoch2k5.dd3\1\s\gx2dtgu0jwm3behddpeqaxumfnjfj0aese4jbh5v112dfe1kacaaaafa\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Silverlight\is\pe4frbif.rhp\aqoch2k5.dd3\1\s\gx2dtgu0jwm3behddpeqaxumfnjfj0aese4jbh5v112dfe1kacaaaafa\f\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Silverlight\is\pe4frbif.rhp\aqoch2k5.dd3\1\s\psld1rq2evnjg2ki2ziatkouhebg2l4klzm3vvurqxwtu41pinaaahda\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Silverlight\is\pe4frbif.rhp\aqoch2k5.dd3\1\s\psld1rq2evnjg2ki2ziatkouhebg2l4klzm3vvurqxwtu41pinaaahda\f\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Silverlight\is\pe4frbif.rhp\aqoch2k5.dd3\1\s\rwezhocofrlgs5fkm5xdwrzg2mxy4sck314tmtygqsjutqph0daaagga\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Silverlight\is\pe4frbif.rhp\aqoch2k5.dd3\1\s\rwezhocofrlgs5fkm5xdwrzg2mxy4sck314tmtygqsjutqph0daaagga\f\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Windows Live Photo Gallery\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Windows Mail\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Windows Mail\Backup\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Windows Mail\Backup\new\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Windows Mail\Stationery\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Windows Media\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Windows Media\11.0\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Microsoft\Windows Media\12.0\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Local\Move Networks\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Adobe\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Adobe\Acrobat\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Adobe\Acrobat\10.0\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Adobe\Acrobat\7.0\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Adobe\Acrobat\7.0\Messages\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Adobe\Acrobat\7.0\Messages\ENU\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Adobe\Acrobat\7.0\Updater\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Adobe\Flash Player\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Adobe\Flash Player\AssetCache\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Adobe\Flash Player\AssetCache\QGG6VAEX\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Adobe\Photoshop Album\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Adobe\Photoshop Album\3.0\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\AdobeAUM\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-09-26_134812.212521BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-09-26_134812.212521BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-09-26_140803.211833BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-09-26_140803.211833BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-09-26_141650.212427BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-09-26_141650.212427BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-09-26_144614.212369BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-09-26_144614.212369BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-09-27_101612.212534BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-09-27_101612.212534BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-09-27_184207.212658BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-09-27_184207.212658BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_134138.212524BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_134138.212524BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_141428.212649BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_141428.212649BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_143620.212223BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_143620.212223BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_144235.212276BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_144235.212276BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_151119.208146BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_151119.208146BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_151727.212713BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_151727.212713BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_171241.212584BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_171241.212584BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_172513.211435BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_172513.211435BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_175414.208640BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_175414.208640BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_182818.212672BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_182818.212672BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_184155.212467BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-01_184155.212467BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-03_101658.212525BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-03_101658.212525BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-03_102526.212531BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-03_102526.212531BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-03_103149.209347BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-03_103149.209347BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_171136.212503BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_171136.212503BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_184048.211973BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_184048.211973BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_184540.212654BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_184540.212654BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_193613.211906BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_193613.211906BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_194131.212821BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_194131.212821BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_195411.212579BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_195411.212579BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_200915.212485BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_200915.212485BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_202350.208426BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_202350.208426BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_203713.212220BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_203713.212220BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_215519.210723BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_215519.210723BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_220108.210688BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_220108.210688BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_221321.212260BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_221321.212260BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_221925.211961BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-04_221925.211961BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-05_090727.212611BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-05_090727.212611BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-07_102226.212623BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-07_102226.212623BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-07_123355.212607BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-07_123355.212607BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-07_124625.213807BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-07_124625.213807BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-07_152734.212745BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-07_152734.212745BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-07_153540.213570BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-07_153540.213570BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-07_161317.212012BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-07_161317.212012BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-07_165331.210873BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-07_165331.210873BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-07_215520.212352BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-07_215520.212352BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-07_231215.212428BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-07_231215.212428BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-07_233957.212769BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-07_233957.212769BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-08_122054.211615BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-08_122054.211615BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-08_125534.213038BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-08_125534.213038BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-08_132108.212681BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-08_132108.212681BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-08_132627.212677BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-08_132627.212677BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-08_134830.212619BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-08_134830.212619BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-08_135443.212494BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-08_135443.212494BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-08_143420.211970BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-08_143420.211970BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-08_153118.210911BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-08_153118.210911BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-08_212853.212119BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-08_212853.212119BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_092608.212734BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_092608.212734BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_102354.212643BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_102354.212643BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_140620.212611BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_140620.212611BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_141858.212501BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_141858.212501BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_143512.209364BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_143512.209364BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_145213.212453BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_145213.212453BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_151722.211540BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_151722.211540BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_153656.209772BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_153656.209772BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_155819.211412BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_155819.211412BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_170806.212294BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_170806.212294BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_174758.212301BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_174758.212301BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_175450.211089BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-09_175450.211089BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-15_162344.212557BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-15_162344.212557BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-15_164007.211765BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-15_164007.211765BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-15_202826.211885BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-15_202826.211885BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-16_103049.210161BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-16_103049.210161BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-16_125818.212983BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-16_125818.212983BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-16_131251.213087BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-16_131251.213087BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-16_133428.211558BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-16_133428.211558BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-16_172245.212526BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-16_172245.212526BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-16_173928.209174BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-16_173928.209174BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-16_184015.212399BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-16_184015.212399BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-16_193023.212067BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-16_193023.212067BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-16_212448.211437BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-16_212448.211437BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-17_170127.212514BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-17_170127.212514BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-17_191106.212444BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-17_191106.212444BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-17_201926.212557BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-17_201926.212557BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-17_210731.213372BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-17_210731.213372BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-17_215432.211300BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-17_215432.211300BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-17_220754.212779BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-17_220754.212779BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-18_134626.212874BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-18_134626.212874BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-19_155814.213050BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-19_155814.213050BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-19_160651.212517BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-19_160651.212517BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-19_232338.212263BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-19_232338.212263BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-19_233042.208167BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-19_233042.208167BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-19_234255.213007BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-19_234255.213007BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-20_142406.212543BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-20_142406.212543BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-20_145513.212781BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-20_145513.212781BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-20_151008.213217BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-20_151008.213217BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-20_152003.211831BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-20_152003.211831BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-20_155730.212611BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-20_155730.212611BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-20_164025.209353BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-20_164025.209353BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-20_165925.212810BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-20_165925.212810BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-20_171839.209925BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-20_171839.209925BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-21_231905.209588BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-21_231905.209588BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-22_120416.213342BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-22_120416.213342BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-22_151843.211853BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-22_151843.211853BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-22_153156.212317BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-22_153156.212317BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-22_154202.213198BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-22_154202.213198BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-22_174255.212690BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-22_174255.212690BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-22_191449.212958BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-22_191449.212958BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-22_192653.212886BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-22_192653.212886BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-23_134548.213950BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-23_134548.213950BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-23_135914.211417BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-23_135914.211417BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-23_141624.212475BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-23_141624.212475BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-24_103101.213068BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-24_103101.213068BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-24_160246.212699BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-24_160246.212699BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-24_165059.212821BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-24_165059.212821BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-25_092810.213163BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-25_092810.213163BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-25_114935.212185BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-25_114935.212185BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-25_181819.211909BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-25_181819.211909BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-25_183505.213256BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-25_183505.213256BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-26_134613.212397BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-26_134613.212397BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-26_140620.212597BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-26_140620.212597BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-26_144908.212320BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-26_144908.212320BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-27_143708.213173BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-27_143708.213173BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-27_182231.212885BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-27_182231.212885BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-27_183134.212891BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-27_183134.212891BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-27_190220.212590BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-27_190220.212590BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-27_231612.212342BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-27_231612.212342BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-28_101844.208813BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-28_101844.208813BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-28_122730.212798BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-28_122730.212798BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-28_130347.212438BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-28_130347.212438BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-28_132246.212562BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-28_132246.212562BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-28_133046.208756BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-28_133046.208756BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-28_194055.212681BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-28_194055.212681BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-28_201908.212783BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-28_201908.212783BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-28_203556.213008BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-28_203556.213008BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-28_204219.211936BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-28_204219.211936BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-29_122143.212852BCMWLAN Core Power Alert\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Apple Computer\Logs\CrashReporter\MobileDevice\Tommys iPhone\com.apple.driver.AppleBCMWLANCore\2013-10-29_122143.212852BCMWLAN Core Power Alert\StateSnapshots\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\FileOpen\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\IObit\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\IObit\Advanced SystemCare V6\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\IObit\Advanced SystemCare V6\Log\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Malwarebytes\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Logs\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Microsoft\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Microsoft\Templates\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\MIMS\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Move Networks\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Nitro\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Nitro\Pro\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Nitro\Pro\8.0\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Nitro\Pro\8.0\Stamps\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Nitro PDF\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Nitro PDF\Professional\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Real\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Real\RealMediaSDK\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Real\RealPlayer\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Real\RealPlayer\db\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Real\Update\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Real\Update\setup\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Real\Update\setup\data\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Real\Update\setup\data\pages\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Real\Update\setup\data\pages\superpass\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Real\Update\setup\data\pages\update\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Real\Update\setup\data\pages\weather\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\Java\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\Java\Deployment\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\Java\Deployment\SystemCache\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\Java\Deployment\SystemCache\6.0\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\Java\Deployment\SystemCache\6.0\11\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\Java\Deployment\SystemCache\6.0\17\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\Java\Deployment\SystemCache\6.0\23\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\Java\Deployment\SystemCache\6.0\24\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\Java\Deployment\SystemCache\6.0\25\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\Java\Deployment\SystemCache\6.0\26\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\Java\Deployment\SystemCache\6.0\29\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\Java\Deployment\SystemCache\6.0\3\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\Java\Deployment\SystemCache\6.0\32\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\Java\Deployment\SystemCache\6.0\4\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\Java\Deployment\SystemCache\6.0\42\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\Java\Deployment\SystemCache\6.0\46\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\Java\Deployment\SystemCache\6.0\50\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\Java\Deployment\SystemCache\6.0\54\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\Java\jre1.6.0_20\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Sun\Java\jre1.6.0_22\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Talkback\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Talkback\MozillaOrg\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Talkback\MozillaOrg\Firefox2\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Talkback\MozillaOrg\Firefox2\Win32\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Talkback\MozillaOrg\Firefox2\Win32\2007072518\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\Talkback\MozillaOrg\Firefox2\Win32\2007111504\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\U3\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\AppData\Roaming\U3\0000051016073468\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\Desktop\Copy of Jared's Photos\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\Desktop\Funeral home\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\Desktop\Jared's Photos\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\Desktop\MMFH Docs\My Documents\Directions\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\Desktop\MMFH Docs\My Documents\Labels\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\Desktop\MMFH Docs\My Documents\MSWORKS\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\Desktop\MMFH Docs\My Documents\MSWORKS\Documents\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\Desktop\MMFH Docs\My Documents\MSWORKS\MANCHEST\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\Desktop\MMFH Docs\My Documents\MSWORKS\WKSTMPL\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\Desktop\MMFH Docs\My Documents\My Pictures\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\Desktop\MMFH Docs\My Documents\obit-net\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\Desktop\MMFH Docs\My Documents\Price Lists\DECRYPT_INSTRUCTION.TXT
Deleted file - C:\Users\Kristen\Desktop\MMFH Docs\My Documents\Roy - NJ Forms\DECRYPT_INSTRUCTION.TXT
 
========= End of CMD: =========
 
C:\ProgramData\ZozatJeqeb => Moved successfully.
C:\ProgramData\FamuSehi => Moved successfully.
C:\ProgramData\@system3.att => Moved successfully.
C:\Users\Kristen\AppData\Roaming\FrameworkUpdate7 => Moved successfully.
C:\ProgramData\@system.temp => Moved successfully.
C:\Users\Kristen\AppData\Roaming\麽鎒駓覜 => Moved successfully.
C:\146cfa0 => Moved successfully.
"C:\Users\Kristen\AppData\Local\Conduit" => File/Directory not found.
C:\ProgramData\Windows Genuine Advantage => Moved successfully.
EmptyTemp: => Removed 28.9 GB temporary data.
 
 
The system needed a reboot. 
 
==== End of Fixlog ====


#7 B-boy/StyLe/

B-boy/StyLe/

    Bleepin' Freestyler


  • Malware Response Team
  • 8,307 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bulgaria
  • Local time:02:36 AM

Posted 09 December 2014 - 08:52 AM

Hi,

 

Good work. It seems that you were hit by Cryptowall. See here fore more information

 

CryptoWall and DECRYPT_INSTRUCTION Ransomware Information Guide and FAQ

 

but unfortunately probably your files are lost forever. Check post 713 fore more information.

 

 

  • Now please download Combofix from here.
     
  • Save it to your Desktop.
     
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Please refer to this link for instructions.
     
  • Double click it & follow the prompts.
     
  • If you receive a UAC prompt asking if you want to continue running the program, you should press the Continue button.
     
  • Click on Yes, to continue scanning for malware.
     
  • When finished, it will produce a log for you.
     
  • Please include the C:\ComboFix.txt in your next reply.
     
  • Note: After running Combofix, you may receive an error about "illegal operation on a registry key that has been marked for deletion." If you receive this error, please reboot and it should disappear.

 

Do not touch your mouse/keyboard until the ComboFix scan has completed, as this may cause the process to stall or the computer to lock.

 

 

Regards,

Georgi


cXfZ4wS.png


#8 Laserrick

Laserrick
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:06:36 PM

Posted 09 December 2014 - 02:09 PM

ComboFix 14-12-08.01 - Kristen 12/09/2014  12:24:40.1.4 - x64
Microsoft Windows 7 Professional   6.1.7601.1.1252.1.1033.18.3913.2633 [GMT -5:00]
Running from: c:\users\Kristen\Downloads\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
ADS - Windows: deleted 192 bytes in 1 streams.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Kristen\AppData\Local\Temp\_MEI37722\_ctypes.pyd
c:\users\Kristen\AppData\Local\Temp\_MEI37722\_elementtree.pyd
c:\users\Kristen\AppData\Local\Temp\_MEI37722\_hashlib.pyd
c:\users\Kristen\AppData\Local\Temp\_MEI37722\_multiprocessing.pyd
c:\users\Kristen\AppData\Local\Temp\_MEI37722\_socket.pyd
c:\users\Kristen\AppData\Local\Temp\_MEI37722\_ssl.pyd
c:\users\Kristen\AppData\Local\Temp\_MEI37722\hashobjs_ext.pyd
c:\users\Kristen\AppData\Local\Temp\_MEI37722\pyexpat.pyd
c:\users\Kristen\AppData\Local\Temp\_MEI37722\pysqlite2._sqlite.pyd
c:\users\Kristen\AppData\Local\Temp\_MEI37722\python27.dll
c:\users\Kristen\AppData\Local\Temp\_MEI37722\pythoncom27.dll
c:\users\Kristen\AppData\Local\Temp\_MEI37722\PyWinTypes27.dll
c:\users\Kristen\AppData\Local\Temp\_MEI37722\select.pyd
c:\users\Kristen\AppData\Local\Temp\_MEI37722\unicodedata.pyd
c:\users\Kristen\AppData\Local\Temp\_MEI37722\win32api.pyd
c:\users\Kristen\AppData\Local\Temp\_MEI37722\win32com.shell.shell.pyd
c:\users\Kristen\AppData\Local\Temp\_MEI37722\win32crypt.pyd
c:\users\Kristen\AppData\Local\Temp\_MEI37722\win32event.pyd
c:\users\Kristen\AppData\Local\Temp\_MEI37722\win32file.pyd
c:\users\Kristen\AppData\Local\Temp\_MEI37722\win32gui.pyd
c:\users\Kristen\AppData\Local\Temp\_MEI37722\win32inet.pyd
c:\users\Kristen\AppData\Local\Temp\_MEI37722\win32pdh.pyd
c:\users\Kristen\AppData\Local\Temp\_MEI37722\win32pipe.pyd
c:\users\Kristen\AppData\Local\Temp\_MEI37722\win32process.pyd
c:\users\Kristen\AppData\Local\Temp\_MEI37722\win32profile.pyd
c:\users\Kristen\AppData\Local\Temp\_MEI37722\win32security.pyd
c:\users\Kristen\AppData\Local\Temp\_MEI37722\win32ts.pyd
c:\users\Kristen\AppData\Local\Temp\_MEI37722\windows._lib_cacheinvalidation.pyd
c:\users\Kristen\AppData\Local\Temp\_MEI37722\wx._animate.pyd
c:\users\Kristen\AppData\Local\Temp\_MEI37722\wx._controls_.pyd
c:\users\Kristen\AppData\Local\Temp\_MEI37722\wx._core_.pyd
c:\users\Kristen\AppData\Local\Temp\_MEI37722\wx._gdi_.pyd
c:\users\Kristen\AppData\Local\Temp\_MEI37722\wx._html2.pyd
c:\users\Kristen\AppData\Local\Temp\_MEI37722\wx._misc_.pyd
c:\users\Kristen\AppData\Local\Temp\_MEI37722\wx._windows_.pyd
c:\users\Kristen\AppData\Local\Temp\_MEI37722\wx._wizard.pyd
c:\users\Kristen\AppData\Local\Temp\_MEI37722\wxbase294u_net_vc90.dll
c:\users\Kristen\AppData\Local\Temp\_MEI37722\wxbase294u_vc90.dll
c:\users\Kristen\AppData\Local\Temp\_MEI37722\wxmsw294u_adv_vc90.dll
c:\users\Kristen\AppData\Local\Temp\_MEI37722\wxmsw294u_core_vc90.dll
c:\users\Kristen\AppData\Local\Temp\_MEI37722\wxmsw294u_html_vc90.dll
c:\users\Kristen\AppData\Local\Temp\_MEI37722\wxmsw294u_webview_vc90.dll
c:\users\Kristen\Documents\~WRL1257.tmp
c:\users\Kristen\WINDOWS
Q:\AUTORUN.INF
.
.
(((((((((((((((((((((((((   Files Created from 2014-11-09 to 2014-12-09  )))))))))))))))))))))))))))))))
.
.
2014-12-09 10:56 . 2014-11-02 04:20 11632448 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{17F4E65A-EBAC-49B5-8B3B-668CC11D2DB2}\mpengine.dll
2014-12-05 17:59 . 2014-12-05 17:59 -------- d-----w- c:\users\Kristen\AppData\Roaming\DesktopPwrMgr
2014-12-05 17:53 . 2014-12-05 17:53 34808 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2014-12-05 17:53 . 2014-12-05 17:53 -------- d-----w- c:\programdata\RogueKiller
2014-12-05 17:17 . 2014-12-05 17:32 -------- d-----w- C:\AdwCleaner
2014-12-05 16:40 . 2014-12-05 16:40 -------- d-----w- c:\windows\ERUNT
2014-12-05 16:10 . 2014-12-08 20:58 -------- d-----w- C:\FRST
2014-12-05 13:58 . 2014-12-05 13:58 -------- d-----w- c:\program files (x86)\Glary Utilities 5
2014-11-21 15:17 . 2014-11-11 03:08 241152 ----a-w- c:\windows\system32\pku2u.dll
2014-11-21 15:17 . 2014-11-11 03:08 728064 ----a-w- c:\windows\system32\kerberos.dll
2014-11-21 15:17 . 2014-11-11 02:44 186880 ----a-w- c:\windows\SysWow64\pku2u.dll
2014-11-21 15:17 . 2014-11-11 02:44 550912 ----a-w- c:\windows\SysWow64\kerberos.dll
2014-11-14 13:29 . 2014-11-14 13:29 -------- d-sh--w- c:\users\Kristen\AppData\Local\EmieBrowserModeList
2014-11-12 13:49 . 2014-10-14 01:50 22016 ----a-w- c:\windows\SysWow64\secur32.dll
2014-11-12 13:49 . 2014-10-14 01:49 96768 ----a-w- c:\windows\SysWow64\sspicli.dll
2014-11-12 13:43 . 2014-10-25 01:57 77824 ----a-w- c:\windows\system32\packager.dll
2014-11-12 13:43 . 2014-10-25 01:32 67584 ----a-w- c:\windows\SysWow64\packager.dll
2014-11-12 13:43 . 2014-10-10 00:57 3198976 ----a-w- c:\windows\system32\win32k.sys
2014-11-12 13:43 . 2014-10-14 02:13 3241984 ----a-w- c:\windows\system32\msi.dll
2014-11-12 13:43 . 2014-10-14 01:50 2363904 ----a-w- c:\windows\SysWow64\msi.dll
2014-11-12 13:43 . 2014-10-18 02:05 861696 ----a-w- c:\windows\system32\oleaut32.dll
2014-11-12 13:43 . 2014-10-18 01:33 571904 ----a-w- c:\windows\SysWow64\oleaut32.dll
2014-11-11 14:22 . 2014-11-11 14:22 -------- d-----w- c:\users\Kristen\AppData\Roaming\Dropbox
2014-11-11 14:09 . 2014-11-11 14:09 267632 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-11-11 14:09 . 2014-11-11 14:09 116728 ----a-w- c:\windows\system32\drivers\aswStm.sys
2014-11-11 14:09 . 2014-11-11 14:09 83280 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-11-11 14:09 . 2014-11-11 14:09 65776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-11-11 14:09 . 2014-11-11 14:09 436624 ----a-w- c:\windows\system32\drivers\aswSP.sys
2014-11-11 14:09 . 2014-11-11 14:09 93568 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2014-11-11 14:09 . 2014-11-11 14:09 29208 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2014-11-11 14:09 . 2014-11-22 02:15 1050432 ----a-w- c:\windows\system32\drivers\aswsnx.sys
2014-11-11 14:09 . 2014-11-11 14:09 364512 ----a-w- c:\windows\system32\aswBoot.exe
2014-11-11 14:09 . 2014-11-11 14:09 43152 ----a-w- c:\windows\avastSS.scr
2014-11-11 14:08 . 2014-11-11 14:08 -------- d-----w- c:\program files\AVAST Software
2014-11-11 13:28 . 2014-11-11 13:28 -------- d-----w- c:\users\Kristen\AppData\Roaming\TeamViewer
2014-11-11 13:28 . 2014-12-09 12:44 -------- d-----w- c:\program files (x86)\TeamViewer
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-11-27 16:42 . 2014-09-24 13:52 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-11-27 16:42 . 2014-09-24 13:52 701104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-11-13 08:10 . 2014-09-20 15:02 103374192 ----a-w- c:\windows\system32\MRT.exe
2014-11-04 19:30 . 2010-11-21 03:27 275080 ------w- c:\windows\system32\MpSigStub.exe
2014-09-25 02:08 . 2014-10-01 13:06 371712 ----a-w- c:\windows\system32\qdvd.dll
2014-09-25 01:40 . 2014-10-01 13:06 519680 ----a-w- c:\windows\SysWow64\qdvd.dll
2014-09-20 15:23 . 2014-09-20 15:23 194048 ----a-w- c:\windows\SysWow64\elshyph.dll
2014-09-20 15:23 . 2014-09-20 15:23 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll
2014-09-20 15:23 . 2014-09-20 15:23 235008 ----a-w- c:\windows\system32\elshyph.dll
2014-09-20 15:23 . 2014-09-20 15:23 182272 ----a-w- c:\windows\SysWow64\msls31.dll
2014-09-20 15:23 . 2014-09-20 15:23 62464 ----a-w- c:\windows\SysWow64\tdc.ocx
2014-09-20 15:23 . 2014-09-20 15:23 337408 ----a-w- c:\windows\SysWow64\html.iec
2014-09-20 15:23 . 2014-09-20 15:23 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll
2014-09-20 15:23 . 2014-09-20 15:23 151552 ----a-w- c:\windows\SysWow64\iexpress.exe
2014-09-20 15:23 . 2014-09-20 15:23 139264 ----a-w- c:\windows\SysWow64\wextract.exe
2014-09-20 15:23 . 2014-09-20 15:23 942592 ----a-w- c:\windows\system32\jsIntl.dll
2014-09-20 15:23 . 2014-09-20 15:23 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll
2014-09-20 15:23 . 2014-09-20 15:23 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2014-09-20 15:23 . 2014-09-20 15:23 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2014-09-20 15:23 . 2014-09-20 15:23 36352 ----a-w- c:\windows\SysWow64\imgutil.dll
2014-09-20 15:23 . 2014-09-20 15:23 247808 ----a-w- c:\windows\system32\msls31.dll
2014-09-20 15:23 . 2014-09-20 15:23 13312 ----a-w- c:\windows\SysWow64\mshta.exe
2014-09-20 15:23 . 2014-09-20 15:23 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2014-09-20 15:23 . 2014-09-20 15:23 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2014-09-20 15:23 . 2014-09-20 15:23 81408 ----a-w- c:\windows\system32\icardie.dll
2014-09-20 15:23 . 2014-09-20 15:23 77312 ----a-w- c:\windows\system32\tdc.ocx
2014-09-20 15:23 . 2014-09-20 15:23 616104 ----a-w- c:\windows\system32\ieapfltr.dat
2014-09-20 15:23 . 2014-09-20 15:23 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2014-09-20 15:23 . 2014-09-20 15:23 48640 ----a-w- c:\windows\system32\mshtmler.dll
2014-09-20 15:23 . 2014-09-20 15:23 413696 ----a-w- c:\windows\system32\html.iec
2014-09-20 15:23 . 2014-09-20 15:23 235520 ----a-w- c:\windows\system32\url.dll
2014-09-20 15:23 . 2014-09-20 15:23 13312 ----a-w- c:\windows\system32\msfeedssync.exe
2014-09-20 15:23 . 2014-09-20 15:23 131072 ----a-w- c:\windows\system32\IEAdvpack.dll
2014-09-20 15:23 . 2014-09-20 15:23 105984 ----a-w- c:\windows\system32\iesysprep.dll
2014-09-20 15:23 . 2014-09-20 15:23 774144 ----a-w- c:\windows\system32\jscript.dll
2014-09-20 15:23 . 2014-09-20 15:23 62464 ----a-w- c:\windows\system32\pngfilt.dll
2014-09-20 15:23 . 2014-09-20 15:23 48128 ----a-w- c:\windows\system32\imgutil.dll
2014-09-20 15:23 . 2014-09-20 15:23 30208 ----a-w- c:\windows\system32\licmgr10.dll
2014-09-20 15:23 . 2014-09-20 15:23 243200 ----a-w- c:\windows\system32\webcheck.dll
2014-09-20 15:23 . 2014-09-20 15:23 167424 ----a-w- c:\windows\system32\iexpress.exe
2014-09-20 15:23 . 2014-09-20 15:23 147968 ----a-w- c:\windows\system32\occache.dll
2014-09-20 15:23 . 2014-09-20 15:23 143872 ----a-w- c:\windows\system32\wextract.exe
2014-09-20 15:23 . 2014-09-20 15:23 13824 ----a-w- c:\windows\system32\mshta.exe
2014-09-20 15:23 . 2014-09-20 15:23 135680 ----a-w- c:\windows\system32\iepeers.dll
2014-09-20 15:23 . 2014-09-20 15:23 101376 ----a-w- c:\windows\system32\inseng.dll
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GoogleDriveSync"="c:\program files (x86)\Google\Drive\googledrivesync.exe" [2014-10-21 22869088]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"USB3MON"="c:\program files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2013-04-26 292848]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2014-08-21 959176]
"Lenovo Registration"="c:\program files (x86)\Lenovo Registration\LenovoReg.exe" [2011-06-01 4315872]
"Fastboot"="c:\program files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe" [2013-07-02 733936]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-11-21 5226600]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
desktop (1).ini [2006-1-12 84]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 Intel® Capability Licensing Service TCP IP Interface;Intel® Capability Licensing Service TCP IP Interface;c:\program files\Intel\iCLS Client\SocketHeciServer.exe;c:\program files\Intel\iCLS Client\SocketHeciServer.exe [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
R3 Power Manager DBC Service;Power Manager DBC Service;c:\program files (x86)\Lenovo\PowerMgr\PWMDBSVC.EXE;c:\program files (x86)\Lenovo\PowerMgr\PWMDBSVC.EXE [x]
R3 PwmEWSvc;Cisco EnergyWise Enabler;c:\program files (x86)\Lenovo\PowerMgr\PWMEWSVC.EXE;c:\program files (x86)\Lenovo\PowerMgr\PWMEWSVC.EXE [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 Sks8821;Skdaemon Service;c:\program files\Lenovo\Lenovo Slim USB Keyboard\Sks8821.exe;c:\program files\Lenovo\Lenovo Slim USB Keyboard\Sks8821.exe [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S0 Fastboot;Fastboot;c:\windows\System32\DRIVERS\fastboot.sys;c:\windows\SYSNATIVE\DRIVERS\fastboot.sys [x]
S0 iaStorA;iaStorA;c:\windows\system32\drivers\iaStorA.sys;c:\windows\SYSNATIVE\drivers\iaStorA.sys [x]
S0 iaStorF;iaStorF;c:\windows\system32\drivers\iaStorF.sys;c:\windows\SYSNATIVE\drivers\iaStorF.sys [x]
S0 iusb3hcs;Intel® USB 3.0 Host Controller Switch Driver;c:\windows\system32\drivers\iusb3hcs.sys;c:\windows\SYSNATIVE\drivers\iusb3hcs.sys [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
S2 FastbootService;FastbootService;c:\program files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe;c:\program files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe [x]
S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 Intel® Capability Licensing Service Interface;Intel® Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 jhi_service;Intel® Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [x]
S2 LENOVO.CAMMUTE;Lenovo Camera Mute;c:\program files\Lenovo\Communications Utility\CAMMUTE.exe;c:\program files\Lenovo\Communications Utility\CAMMUTE.exe [x]
S2 LENOVO.TPKNRSVC;Lenovo Keyboard Noise Reduction;c:\program files\Lenovo\Communications Utility\TPKNRSVC.exe;c:\program files\Lenovo\Communications Utility\TPKNRSVC.exe [x]
S2 NitroDriverReadSpool8;NitroPDFDriverCreatorReadSpool8;c:\program files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe;c:\program files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe [x]
S2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\SysWOW64\NLSSRV32.EXE;c:\windows\SysWOW64\NLSSRV32.EXE [x]
S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 iusb3hub;Intel® USB 3.0 Hub Driver;c:\windows\system32\drivers\iusb3hub.sys;c:\windows\SYSNATIVE\drivers\iusb3hub.sys [x]
S3 iusb3xhc;Intel® USB 3.0 eXtensible Host Controller Driver;c:\windows\system32\drivers\iusb3xhc.sys;c:\windows\SYSNATIVE\drivers\iusb3xhc.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 WSDScan;WSD Scan Support via UMB;c:\windows\system32\DRIVERS\WSDScan.sys;c:\windows\SYSNATIVE\DRIVERS\WSDScan.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-11-27 16:03 1087304 ----a-w- c:\program files (x86)\Google\Chrome\Application\39.0.2171.71\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2014-12-09 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-24 16:42]
.
2014-12-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-09-20 16:17]
.
2014-12-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-09-20 16:17]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-11-11 14:09 860984 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2014-10-21 22:52 777032 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2014-10-21 22:52 777032 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2014-10-21 22:52 777032 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2014-10-21 22:52 777032 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2014-10-21 22:52 777032 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2013-07-03 165872]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2013-07-03 407536]
"Persistence"="c:\windows\system32\igfxpers.exe" [2013-07-03 444400]
"Skd8821"="c:\program files\Lenovo\Lenovo Slim USB Keyboard\Skd8821.exe" [2011-03-23 384512]
"LENOVO.TPKNRRES"="c:\program files\Lenovo\Communications Utility\TPKNRRES.exe" [2013-01-28 293672]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mDefault_Page_URL = hxxp://www.google.com
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
Toolbar-Locked - (no file)
ShellIconOverlayIdentifiers-{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} - c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
ShellIconOverlayIdentifiers-{62CCD8E3-9C21-41E1-B55E-1E26DFC68511} - c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
ShellIconOverlayIdentifiers-{A759AFF6-5851-457D-A540-F4ECED148351} - c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
ShellIconOverlayIdentifiers-{1574C9EF-7D58-488F-B358-8B78C1538F51} - c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_15_0_0_239_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_15_0_0_239_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_15_0_0_239_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_15_0_0_239_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_239.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.15"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_239.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_239.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_239.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\TeamViewer\TeamViewer_Service.exe
c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
c:\program files (x86)\TeamViewer\TeamViewer.exe
c:\program files (x86)\TeamViewer\tv_w32.exe
c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe
c:\program files (x86)\Lenovo\message center plus\mcplaunch.exe
.
**************************************************************************
.
Completion time: 2014-12-09  14:04:54 - machine was rebooted
ComboFix-quarantined-files.txt  2014-12-09 19:04
.
Pre-Run: 431,064,887,296 bytes free
Post-Run: 430,675,197,952 bytes free
.
- - End Of File - - DF7484ED7EE9E925E9B3F59FC0BE94E5
13B96B893E779CA56840A3A6ED81DB9E


#9 B-boy/StyLe/

B-boy/StyLe/

    Bleepin' Freestyler


  • Malware Response Team
  • 8,307 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bulgaria
  • Local time:02:36 AM

Posted 09 December 2014 - 07:08 PM

Hi,

 

Nice work. The Combofix log is clean.

 

The Poweliks trojan was taken care of. :)

 

However if you don't mind, I want to make sure there is nothing lurking on the system so just in case I want you to go through these steps:

 

 

STEP 1

 

Please download Malwarebytes Anti-Rootkit MBAM_Logo.png and save it to your desktop.

  • Be sure to print out and follow these instructions for performing a scan.
  • Caution: This is a beta version so also read the disclaimer and back up all your data before using.
  • When the scan completes, click on the Cleanup button to remove any threats found and reboot the computer if prompted to do so.
  • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
  • Two files (mbar-log-YYYY-MM-DD, system-log.txt) will be created and saved within that same folder.
  • Copy and paste the contents of these two log files in your next reply.

 

 

STEP 2

 

 

 

  • Please download RogueKillerX64.exe and save to the desktop.
  • Close all windows and browsers
  • Right-click the program and select 'Run as Administrator'
  • Press the scan button.
  • A report opens on the desktop named - RKreport.txt
  • Please post it in your next reply.

 

 

STEP 3
 

 

Please download the latest version of TDSSKiller from here and save it to your Desktop.

  • Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters.
     
  • Put a checkmark beside loaded modules.
    Sbf88.png
  • A reboot will be needed to apply the changes. Do it.
  • TDSSKiller will launch automatically after the reboot. Also your computer may seem very slow and unusable. This is normal. Give it enough time to load your background programs.
  • Then click on Change parameters in TDSSKiller.
  • Check all boxes then click OK.
     
  • Click the Start Scan button.
     
  • The scan should take no longer than 2 minutes.
  • If a suspicious object is detected, the default action will be Skip, click on Continue.
     
  • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
    Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.

    Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.
  • A report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and past the results at pastebin.com and post the link to the log in your next reply.

 

 

 

STEP 4

 

 

 

1.Please download HitmanPro.

  • For 32-bit Operating System - dEMD6.gif.
  • This is the mirror - dEMD6.gif
  • For 64-bit Operating System - dEMD6.gif
  • This is the mirror - dEMD6.gif

2.Launch the program by double clicking on the 5vo5F.jpg icon. (Windows Vista/7 users right click on the HitmanPro icon and select run as administrator).

Note: If the program won't run please then open the program while holding down the left CTRL key until the program is loaded.

3.Click on the next button. You must agree with the terms of EULA. (if asked)

4.Check the box beside "No, I only want to perform a one-time scan to check this computer".

5.Click on the next button.

6.The program will start to scan the computer. The scan will typically take no more than 2-3 minutes.

7.When the scan is done click on drop-down menu of the found entries (if any) and choose - Apply to all => Ignore <= IMPORTANT!!!

 

6-scanfin-choose.jpg
 
8.Click on the next button.

9.Click on the "Save Log" button.

10.Save that file to your desktop and post the content of that file in your next reply.
 
Note: if there isn't a dropdown menu when the scan is done then please don't delete anything and close HitmanPro

Navigate to C:\ProgramData\HitmanPro\Logs open the report and copy and paste it to your next reply.

 

Note: Programdata is hidden by default. Please make sure that you can view all hidden files. Instructions on how to do this can be found here:
How to see hidden files in Windows

 

 

 

Regards,

Georgi


cXfZ4wS.png


#10 Laserrick

Laserrick
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:06:36 PM

Posted 10 December 2014 - 07:50 AM

Malwarebytes Anti-Rootkit BETA 1.08.2.1001
 
© Malwarebytes Corporation 2011-2012
 
OS version: 6.1.7601 Windows 7 Service Pack 1 x64
 
Account is Administrative
 
Internet Explorer version: 11.0.9600.17420
 
File system is: NTFS
Disk drives: C:\ DRIVE_FIXED, Q:\ DRIVE_FIXED
CPU speed: 3.392000 GHz
Memory total: 4103503872, free: 2154573824
 
=======================================
Initializing...
------------ Kernel report ------------
     12/09/2014 22:35:35
------------ Loaded modules -----------
\SystemRoot\system32\ntoskrnl.exe
\SystemRoot\system32\hal.dll
\SystemRoot\system32\kdcom.dll
\SystemRoot\system32\mcupdate_GenuineIntel.dll
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\CLFS.SYS
\SystemRoot\system32\CI.dll
\SystemRoot\system32\drivers\Wdf01000.sys
\SystemRoot\system32\drivers\WDFLDR.SYS
\SystemRoot\system32\drivers\ACPI.sys
\SystemRoot\system32\drivers\WMILIB.SYS
\SystemRoot\system32\drivers\msisadrv.sys
\SystemRoot\system32\drivers\pci.sys
\SystemRoot\system32\drivers\vdrvroot.sys
\SystemRoot\system32\drivers\iusb3hcs.sys
\SystemRoot\System32\drivers\partmgr.sys
\SystemRoot\system32\drivers\compbatt.sys
\SystemRoot\system32\drivers\BATTC.SYS
\SystemRoot\system32\drivers\volmgr.sys
\SystemRoot\System32\drivers\volmgrx.sys
\SystemRoot\System32\drivers\mountmgr.sys
\SystemRoot\system32\drivers\iaStorA.sys
\SystemRoot\system32\drivers\storport.sys
\SystemRoot\system32\drivers\amdxata.sys
\SystemRoot\system32\drivers\fltmgr.sys
\SystemRoot\system32\drivers\fileinfo.sys
\SystemRoot\System32\DRIVERS\fastboot.sys
\SystemRoot\System32\Drivers\Ntfs.sys
\SystemRoot\System32\Drivers\msrpc.sys
\SystemRoot\System32\Drivers\ksecdd.sys
\SystemRoot\System32\Drivers\cng.sys
\SystemRoot\System32\drivers\pcw.sys
\SystemRoot\System32\Drivers\Fs_Rec.sys
\SystemRoot\system32\drivers\ndis.sys
\SystemRoot\system32\drivers\NETIO.SYS
\SystemRoot\System32\Drivers\ksecpkg.sys
\SystemRoot\System32\drivers\tcpip.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\system32\drivers\vmstorfl.sys
\SystemRoot\system32\drivers\volsnap.sys
\SystemRoot\System32\Drivers\spldr.sys
\SystemRoot\System32\drivers\rdyboost.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\system32\drivers\iaStorF.sys
\SystemRoot\System32\drivers\hwpolicy.sys
\SystemRoot\System32\DRIVERS\fvevol.sys
\SystemRoot\system32\drivers\disk.sys
\SystemRoot\system32\drivers\CLASSPNP.SYS
\SystemRoot\System32\Drivers\aswVmm.sys
\SystemRoot\System32\Drivers\aswRvrt.sys
\SystemRoot\system32\DRIVERS\cdrom.sys
\SystemRoot\system32\drivers\aswSnx.sys
\SystemRoot\system32\drivers\aswSP.sys
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\drivers\VIDEOPRT.SYS
\SystemRoot\System32\drivers\watchdog.sys
\SystemRoot\System32\DRIVERS\RDPCDD.sys
\SystemRoot\system32\drivers\rdpencdd.sys
\SystemRoot\system32\drivers\rdprefmp.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\system32\DRIVERS\tdx.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\system32\drivers\afd.sys
\SystemRoot\system32\drivers\aswRdr2.sys
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\system32\drivers\ws2ifsl.sys
\SystemRoot\system32\DRIVERS\wfplwf.sys
\SystemRoot\system32\DRIVERS\pacer.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\drivers\serial.sys
\SystemRoot\system32\DRIVERS\wanarp.sys
\SystemRoot\system32\drivers\termdd.sys
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\drivers\nsiproxy.sys
\SystemRoot\system32\drivers\mssmbios.sys
\SystemRoot\System32\drivers\discache.sys
\SystemRoot\system32\drivers\csc.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\system32\drivers\blbdrive.sys
\SystemRoot\system32\DRIVERS\tunnel.sys
\SystemRoot\system32\DRIVERS\igdkmd64.sys
\SystemRoot\System32\drivers\dxgkrnl.sys
\SystemRoot\System32\drivers\dxgmms1.sys
\SystemRoot\system32\drivers\HDAudBus.sys
\SystemRoot\system32\drivers\iusb3xhc.sys
\SystemRoot\system32\drivers\USBD.SYS
\SystemRoot\system32\drivers\HECIx64.sys
\SystemRoot\system32\drivers\usbehci.sys
\SystemRoot\system32\drivers\USBPORT.SYS
\SystemRoot\system32\DRIVERS\Rt64win7.sys
\SystemRoot\system32\drivers\serenum.sys
\SystemRoot\system32\drivers\parport.sys
\SystemRoot\system32\drivers\intelppm.sys
\SystemRoot\system32\drivers\wmiacpi.sys
\SystemRoot\system32\drivers\CompositeBus.sys
\SystemRoot\system32\DRIVERS\AgileVpn.sys
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\rassstp.sys
\SystemRoot\system32\drivers\rdpbus.sys
\SystemRoot\system32\DRIVERS\kbdclass.sys
\SystemRoot\system32\DRIVERS\mouclass.sys
\SystemRoot\system32\DRIVERS\psadd.sys
\SystemRoot\system32\drivers\swenum.sys
\SystemRoot\system32\drivers\ks.sys
\SystemRoot\system32\DRIVERS\umbus.sys
\SystemRoot\system32\drivers\usbhub.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\system32\DRIVERS\IntcDAud.sys
\SystemRoot\system32\DRIVERS\portcls.sys
\SystemRoot\system32\DRIVERS\drmk.sys
\SystemRoot\system32\drivers\ksthunk.sys
\SystemRoot\system32\drivers\iusb3hub.sys
\SystemRoot\system32\drivers\RTKVHD64.sys
\SystemRoot\system32\DRIVERS\cdfs.sys
\SystemRoot\System32\Drivers\crashdmp.sys
\SystemRoot\System32\Drivers\dump_diskdump.sys
\SystemRoot\System32\Drivers\dump_iaStorA.sys
\SystemRoot\System32\Drivers\dump_dumpfve.sys
\SystemRoot\system32\DRIVERS\usbccgp.sys
\SystemRoot\system32\DRIVERS\hidusb.sys
\SystemRoot\system32\DRIVERS\HIDCLASS.SYS
\SystemRoot\system32\DRIVERS\HIDPARSE.SYS
\SystemRoot\system32\DRIVERS\mouhid.sys
\SystemRoot\system32\DRIVERS\kbdhid.sys
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\system32\DRIVERS\monitor.sys
\SystemRoot\System32\TSDDD.dll
\SystemRoot\System32\cdd.dll
\SystemRoot\System32\ATMFD.DLL
\SystemRoot\system32\drivers\luafv.sys
\SystemRoot\system32\drivers\aswMonFlt.sys
\SystemRoot\system32\drivers\aswStm.sys
\SystemRoot\system32\DRIVERS\lltdio.sys
\SystemRoot\system32\DRIVERS\rspndr.sys
\SystemRoot\system32\drivers\HTTP.sys
\SystemRoot\system32\DRIVERS\bowser.sys
\SystemRoot\System32\drivers\mpsdrv.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\system32\DRIVERS\mrxsmb10.sys
\SystemRoot\system32\DRIVERS\mrxsmb20.sys
\SystemRoot\system32\drivers\aswHwid.sys
\SystemRoot\system32\drivers\peauth.sys
\SystemRoot\System32\Drivers\secdrv.SYS
\SystemRoot\System32\DRIVERS\srvnet.sys
\SystemRoot\System32\drivers\tcpipreg.sys
\SystemRoot\System32\DRIVERS\srv2.sys
\SystemRoot\System32\DRIVERS\srv.sys
\SystemRoot\system32\DRIVERS\WSDPrint.sys
\SystemRoot\system32\DRIVERS\WSDScan.sys
\??\C:\Windows\system32\drivers\mbamchameleon.sys
\??\C:\Windows\system32\drivers\MBAMSwissArmy.sys
\Windows\System32\ntdll.dll
\Windows\System32\smss.exe
\Windows\System32\apisetschema.dll
\Windows\System32\autochk.exe
\Windows\System32\msvcrt.dll
\Windows\System32\urlmon.dll
\Windows\System32\comdlg32.dll
\Windows\System32\ws2_32.dll
\Windows\System32\advapi32.dll
\Windows\System32\normaliz.dll
\Windows\System32\imagehlp.dll
\Windows\System32\difxapi.dll
\Windows\System32\oleaut32.dll
\Windows\System32\wininet.dll
\Windows\System32\ole32.dll
\Windows\System32\msctf.dll
\Windows\System32\gdi32.dll
\Windows\System32\kernel32.dll
\Windows\System32\clbcatq.dll
\Windows\System32\shell32.dll
\Windows\System32\shlwapi.dll
\Windows\System32\lpk.dll
\Windows\System32\rpcrt4.dll
\Windows\System32\psapi.dll
\Windows\System32\imm32.dll
\Windows\System32\nsi.dll
\Windows\System32\user32.dll
\Windows\System32\setupapi.dll
\Windows\System32\usp10.dll
\Windows\System32\iertutil.dll
\Windows\System32\Wldap32.dll
\Windows\System32\sechost.dll
\Windows\System32\crypt32.dll
\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
\Windows\System32\cfgmgr32.dll
\Windows\System32\wintrust.dll
\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
\Windows\System32\userenv.dll
\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
\Windows\System32\comctl32.dll
\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
\Windows\System32\devobj.dll
\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
\Windows\System32\KernelBase.dll
\Windows\System32\msasn1.dll
----------- End -----------
Done!
<<<1>>>
Upper Device Name: \Device\Harddisk0\DR0
Upper Device Object: 0xfffffa8004429060
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\00000067\
Lower Device Object: 0xfffffa80036637e0
Lower Device Driver Name: \Driver\iaStorA\
<<<2>>>
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xfffffa8004429060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa8004429b90, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa80042df9a0, DeviceName: Unknown, DriverName: \Driver\Fastboot\
DevicePointer: 0xfffffa8004429060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa80042dfc50, DeviceName: Unknown, DriverName: \Driver\iaStorF\
DevicePointer: 0xfffffa80036637e0, DeviceName: \Device\00000067\, DriverName: \Driver\iaStorA\
------------ End ----------
Alternate DeviceName: Unknown, DriverName: \Driver\Fastboot\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
Done!
Drive 0
This is a System drive
Scanning MBR on drive 0...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: F96A4DE5
 
Partition information:
 
    Partition 0 type is Primary (0x7)
    Partition is ACTIVE.
    Partition starts at LBA: 2048  Numsec = 3072000
    Partition file system is NTFS
    Partition is bootable
 
    Partition 1 type is Primary (0x7)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 3074048  Numsec = 945025024
 
    Partition 2 type is Primary (0x7)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 948099072  Numsec = 28672000
 
    Partition 3 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
 
Disk Size: 500107862016 bytes
Sector size: 512 bytes
 
Done!
Scan finished
=======================================
 
 
Removal queue found; removal started
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\VBR-0-0-2048-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-r.mbam...
Removal finished


#11 Laserrick

Laserrick
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:06:36 PM

Posted 10 December 2014 - 08:21 AM

RogueKiller V10.0.8.0 [Nov 20 2014] by Adlice Software
 
Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : Kristen [Administrator]
Mode : Scan -- Date : 12/10/2014  06:56:39
 
¤¤¤ Processes : 0 ¤¤¤
 
¤¤¤ Registry : 21 ¤¤¤
[PUM.HomePage] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.yahoo.com/?fr=befhp&type=iehp-3.13-1406  -> Found
[PUM.HomePage] (X64) HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome  -> Found
[PUM.HomePage] (X86) HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome  -> Found
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-1346962788-3022881501-2052787113-1001\Software\Microsoft\Internet Explorer\Main | Start Page : www.google.com  -> Found
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-1346962788-3022881501-2052787113-1001\Software\Microsoft\Internet Explorer\Main | Start Page : www.google.com  -> Found
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome  -> Found
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome  -> Found
[PUM.SearchPage] (X64) HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch  -> Found
[PUM.SearchPage] (X86) HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch  -> Found
[PUM.SearchPage] (X64) HKEY_USERS\S-1-5-21-1346962788-3022881501-2052787113-1000\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch  -> Found
[PUM.SearchPage] (X86) HKEY_USERS\S-1-5-21-1346962788-3022881501-2052787113-1000\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch  -> Found
[PUM.SearchPage] (X64) HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch  -> Found
[PUM.SearchPage] (X86) HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch  -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-1346962788-3022881501-2052787113-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0  -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-1346962788-3022881501-2052787113-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowRecentDocs : 2  -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-1346962788-3022881501-2052787113-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0  -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-1346962788-3022881501-2052787113-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowRecentDocs : 2  -> Found
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1  -> Found
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1  -> Found
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1  -> Found
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1  -> Found
 
¤¤¤ Tasks : 0 ¤¤¤
 
¤¤¤ Files : 0 ¤¤¤
 
¤¤¤ Hosts File : 1 ¤¤¤
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1       localhost
 
¤¤¤ Antirootkit : 0 (Driver: Not loaded [0xc000036b]) ¤¤¤
 
¤¤¤ Web browsers : 0 ¤¤¤
 
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: ST500DM0 02-1BD142 SCSI Disk Device +++++
--- User ---
[MBR] ad5c544aa3da22a8ffa73d89078c29d1
[BSP] 7e0e0d79bbbede5f1811a30184e3a05d : Lenovo MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 1500 MB
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 3074048 | Size: 461438 MB
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 948099072 | Size: 14000 MB
User = LL1 ... OK
User = LL2 ... OK
 
 
============================================
RKreport_DEL_12052014_125730.log - RKreport_SCN_12052014_125606.log


#12 B-boy/StyLe/

B-boy/StyLe/

    Bleepin' Freestyler


  • Malware Response Team
  • 8,307 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bulgaria
  • Local time:02:36 AM

Posted 10 December 2014 - 12:17 PM

Hi,

 

You forgot to post the other log from Malwarebytes Anti-Rootkit.

 

Please post that log too.

 

Thank you! :)

 

 

Regards,

Georgi


cXfZ4wS.png


#13 Laserrick

Laserrick
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:06:36 PM

Posted 10 December 2014 - 11:54 PM

HitmanPro 3.7.9.232
www.hitmanpro.com
 
   Computer name . . . . : KRISTEN-THINK
   Windows . . . . . . . : 6.1.1.7601.X64/4
   User name . . . . . . : Kristen-THINK\Kristen
   UAC . . . . . . . . . : Enabled
   License . . . . . . . : Free
 
   Scan date . . . . . . : 2014-12-10 23:02:00
   Scan mode . . . . . . : Normal
   Scan duration . . . . : 3m 29s
   Disk access mode  . . : Direct disk access (SRB)
   Cloud . . . . . . . . : Internet
   Reboot  . . . . . . . : No
 
   Threats . . . . . . . : 0
   Traces  . . . . . . . : 40
 
   Objects scanned . . . : 4,510,273
   Files scanned . . . . : 55,690
   Remnants scanned  . . : 3,315,875 files / 1,138,708 keys
 
Suspicious files ____________________________________________________________
 
   C:\Users\Kristen\Downloads\FRST-OlderVersion\FRST64.exe
      Size . . . . . . . : 2,117,632 bytes
      Age  . . . . . . . : 5.5 days (2014-12-05 11:05:09)
      Entropy  . . . . . : 7.5
      SHA-256  . . . . . : BC4085201F2E3D94A95791B6995DA8BACFFBABFC710B87C8A33624C1BBE14E8B
      Needs elevation  . : Yes
      Fuzzy  . . . . . . : 24.0
         Program has no publisher information but prompts the user for permission elevation.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Time indicates that the file appeared recently on this computer.
 
   C:\Users\Kristen\Downloads\FRST64.exe
      Size . . . . . . . : 2,119,680 bytes
      Age  . . . . . . . : 2.4 days (2014-12-08 13:16:08)
      Entropy  . . . . . : 7.5
      SHA-256  . . . . . : 742FC4359E8B6EDBD04FDB2101C7745E73E1A7DF1AB335A65BF9570EB7468128
      Needs elevation  . : Yes
      Fuzzy  . . . . . . : 24.0
         Program has no publisher information but prompts the user for permission elevation.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Time indicates that the file appeared recently on this computer.
 
 
Potential Unwanted Programs _________________________________________________
 
   ask.com
   C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Web Data
 
   HKU\S-1-5-21-1346962788-3022881501-2052787113-1001\Software\Microsoft\Internet Explorer\SearchScopes\{E0E6A689-D9DC-410D-B9F9-748B9CC78FEB}\ (Conduit)
 
Cookies _____________________________________________________________________
 
   C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.360yield.com
   C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.mlnadvertising.com
   C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.bridgetrack.com
   C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.mediade.sk
   C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.p161.net
   C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.pointroll.com
   C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.pubmatic.com
   C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.undertone.com
   C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Cookies:adtechus.com
   C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Cookies:advertising.com
   C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Cookies:at.atwola.com
   C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Cookies:atdmt.com
   C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Cookies:bs.serving-sys.com
   C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Cookies:burstnet.com
   C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Cookies:casalemedia.com
   C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Cookies:collective-media.net
   C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Cookies:doubleclick.net
   C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Cookies:fastclick.net
   C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Cookies:interclick.com
   C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Cookies:media6degrees.com
   C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Cookies:mediaplex.com
   C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Cookies:oasc18.247realmedia.com
   C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Cookies:pointroll.com
   C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Cookies:questionmarket.com
   C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Cookies:realmedia.com
   C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Cookies:revsci.net
   C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Cookies:ru4.com
   C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Cookies:serving-sys.com
   C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Cookies:smartadserver.com
   C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Cookies:survey.g.doubleclick.net
   C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Cookies:tacoda.at.atwola.com
   C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Cookies:track.adform.net
   C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Cookies:track.punkaddicts.com
   C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Cookies:tribalfusion.com
   C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Cookies:www.burstnet.com
   C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Cookies:zedo.com
 
 


#14 Laserrick

Laserrick
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:06:36 PM

Posted 11 December 2014 - 08:47 AM

Malwarebytes was posed before Rougekiller  TDSS Killer found nothing. I followed you instructions in order.Thank you so much for your help!



#15 B-boy/StyLe/

B-boy/StyLe/

    Bleepin' Freestyler


  • Malware Response Team
  • 8,307 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bulgaria
  • Local time:02:36 AM

Posted 11 December 2014 - 03:08 PM

Hi,

 

Yeah, I noticed the MBAR log but there should be another one from MBAR:

 

 

  • Two files (mbar-log-YYYY-MM-DD, system-log.txt) will be created and saved within that same folder.
  • Copy and paste the contents of these two log files in your next reply.

 

 

 

Regards,

Georgi


cXfZ4wS.png





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users