Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Hit with Cryptowall, must disinfect computer


  • This topic is locked This topic is locked
14 replies to this topic

#1 quatermass

quatermass

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:02:37 AM

Posted 12 April 2015 - 05:30 PM

I run Windows XP Home with SP3 and Outlook Express. I have Windows Defender and run a 1.5 hour scan each day at 2 am.
 
On April 2, I received email on my primary address which was redirected from our little theatre website (as it is set up to do) with the subject "(some normal name) - resume". The body of the message said "please give the attached resume your consideration". As artistic director, it is my responsibility to bring new talent into the group. The attachment was shown to be a .pdf, but changed to a .zip when clicked. I'm not sure if I opened the .zip, probably did. Nothing came of it. Or so I thought...
 
At some point after this, I noticed the red "hard drive busy" light was constantly on. Later on April 2, thinking that I had acquired a virus, I tried to run a Windows Defender scan, but I could not update the latest virus profiles. I then ran Malwarebytes, which found five trojans, including one referring to "ransom.ed". These were quarantined, at which point the hard drive light returned to normal and I could update Windows Defender.
 
On April 5, I tried to access a contact list file in the theatre folder, only to find gibberish, in that and all other theatre files. I ran another Malwarebytes scan in safe mode and it found only PUPs. In safe mode with networking, I ran ESET, which hung up at 98% and had to be stopped manually. It found all the "help_decrypt" files in the affected folders. I have operated in safe mode ever since, except to run the FRST program for the necessary attachments.
 
I never got the screen saying "your files are encrypted, pay $500".
 
I ran listcwall to determine the extent of the damage. The log showed all encrypted files and it appears that the encryption operates alphabetically, because only folders up to D were listed in the log. Other folders in My Documents such as My Music seem to have survived. It looks like the Malwarebytes scan on April 3 stopped the encryption process well before it affected all my files. This is some consolation.
 
I am aware that the affected files are irretrievably lost, including 14 years of theatre archives. I did not have a recent backup (2009 was the last), shadow copy was not available and, because the encryption was interrupted, it never got to the final ransom message, so I probably can't even pay the $500.
 
Please give this post your consideration. My wish is to confirm that my computer is completely free of Cryptowall, and anything else for that matter. I could just use the instructions for removal on your website, but because the encryption did not fully complete, there may be other procedures necessary. I don't know.
 
Thanks.
 
quatermass
 
FRST.txt follows, Addition.txt attached.
 
 
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 12-04-2015
Ran by Ron (administrator) on ALPHA1 on 12-04-2015 17:39:50
Running from C:\Documents and Settings\Ron\Desktop
Loaded Profiles: Ron (Available profiles: Ron & Administrator)
Platform: Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: English (United States)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Microsoft Corporation) C:\WINDOWS\system32\savedump.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.26.9\GoogleCrashHandler.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(HP) C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
(LogMeIn Inc.) C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE
(APN LLC.) C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
(SiSoftware) C:\Program Files\SiSoftware\SiSoftware Sandra Lite XII.SP2c\RpcAgentSrv.exe
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(APN) C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
(InterVideo Inc.) C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
(Microsoft® Corporation) C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.bin
(Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [866584 2006-11-03] (Microsoft Corporation)
HKLM\...\Run: [ULiRaid] => C:\Program Files\ULiRaid\ULiRaid.exe [409600 2005-10-18] ()
HKLM\...\Run: [NeroFilterCheck] => C:\WINDOWS\system32\NeroCheck.exe [155648 2006-01-12] (Nero AG)
HKLM\...\Run: [HPDJ Taskbar Utility] => C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe [196608 2001-11-06] (HP)
HKLM\...\Run: [High Definition Audio Property Page Shortcut] => C:\WINDOWS\system32\HDAShCut.exe [61952 2004-10-27] (Windows ® Server 2003 DDK provider)
HKLM\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe [1910152 2010-12-06] (LogMeIn Inc.)
HKLM\...\Run: [RTHDCPL] => C:\WINDOWS\RTHDCPL.EXE [20053608 2011-04-14] (Realtek Semiconductor Corp.)
HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2011-06-27] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [ROC_ROC_NT] => "C:\Program Files\AVG Secure Search\ROC_ROC_NT.exe" / /PROMPT /CMPID=ROC_NT
HKLM\...\Run: [KernelFaultCheck] => %systemroot%\system32\dumprep 0 -k
HKLM\...\Run: [BrowserSafeguard] => "C:\Program Files\Browsersafeguard\BrowserSafeguard.exe"
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\qttask.exe [421888 2014-01-17] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKLM\...\Run: [ApnTBMon] => C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1949592 2015-02-14] (APN)
Winlogon\Notify\AtiExtEvent: C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
HKLM\...\Policies\Explorer: [NoCDBurning] 0
HKU\S-1-5-21-1645522239-1708537768-725345543-1004\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [204288 2006-10-18] (Microsoft Corporation)
HKU\S-1-5-21-1645522239-1708537768-725345543-1004\...\Run: [Microsoft Works Update Detection] => \WkDetect.exe
HKU\S-1-5-21-1645522239-1708537768-725345543-1004\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2010-08-13] (Google Inc.)
HKU\S-1-5-21-1645522239-1708537768-725345543-1004\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\ssstars.scr [14336 2008-04-13] (Microsoft Corporation)
HKU\S-1-5-18\...\Run: [DWQueuedReporting] => c:\Program Files\Common Files\Microsoft Shared\DW\DWTRIG20.EXE [39264 2007-03-13] (Microsoft Corporation)
HKU\S-1-5-18\...\RunOnce: [tscuninstall] => C:\WINDOWS\system32\tscupgrd.exe [44544 2004-08-04] (Microsoft Corporation)
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
ShortcutTarget: Adobe Reader Speed Launch.lnk -> C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk
ShortcutTarget: InterVideo WinCinema Manager.lnk -> C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe (InterVideo Inc.)
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk
ShortcutTarget: Microsoft Works Calendar Reminders.lnk -> C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe (Microsoft® Corporation)
Startup: C:\Documents and Settings\Ron\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
ShortcutTarget: OpenOffice.org 3.2.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
ShellIconOverlayIdentifiers: [GDriveBlacklistedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google)
ShellIconOverlayIdentifiers: [GDriveSharedEditOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google)
ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google)
ShellIconOverlayIdentifiers: [GDriveSharedViewOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google)
ShellIconOverlayIdentifiers: [GDriveSyncedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google)
ShellIconOverlayIdentifiers: [GDriveSyncingOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKU\S-1-5-21-1645522239-1708537768-725345543-1004\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-1645522239-1708537768-725345543-1004\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
HKU\S-1-5-21-1645522239-1708537768-725345543-1004\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ca.msn.com/?lang=en-ca&OCID=iehp
URLSearchHook: [S-1-5-21-1645522239-1708537768-725345543-1004] ATTENTION ==> Default URLSearchHook is missing.
URLSearchHook: HKU\S-1-5-21-1645522239-1708537768-725345543-1004 - SearchHook Class - {D8278076-BC68-4484-9233-6E7F1628B56C} - C:\Program Files\AskPartnerNetwork\Toolbar\searchhook.dll (APN LLC.)
URLSearchHook: HKU\S-1-5-21-1645522239-1708537768-725345543-1004 - (No Name) - {6c97a91e-4524-4019-86af-2aa2d567bf5c} -  No File
SearchScopes: HKLM -> DefaultScope {B44B85B3-A282-4318-BE19-6A64A806F7E1} URL = 
SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD21} URL = http://search.imesh.com//web?src=ieb&appid=580&systemid=1&sr=0&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1645522239-1708537768-725345543-1004 -> {568353DE-8421-479B-B350-EA143ACA8BF5} URL = http://ca.search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=chr-yie8
SearchScopes: HKU\S-1-5-21-1645522239-1708537768-725345543-1004 -> {62A36902-34A8-41E7-9D0F-825678386D92} URL = http://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKU\S-1-5-21-1645522239-1708537768-725345543-1004 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD21} URL = 
SearchScopes: HKU\S-1-5-21-1645522239-1708537768-725345543-1004 -> {b0441a0e-a49a-4e16-afc1-74ecced1921f} URL = 
BHO: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} ->  No File
BHO: Adobe PDF Reader Link Helper -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-12-18] (Adobe Systems Incorporated)
BHO: AVG Safe Search -> {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -> C:\Program Files\AVG\AVG2012\avgssie.dll No File
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2014-09-26] (Oracle Corporation)
BHO: No Name -> {95B7759C-8C7F-4BF1-B163-73684A933233} ->  No File
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-02] (Google Inc.)
BHO: Google Toolbar Notifier BHO -> {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -> C:\Program Files\Google\GoogleToolbarNotifier\5.10.11023.1534\swg.dll [2015-03-02] (Google Inc.)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-09-26] (Oracle Corporation)
Toolbar: HKLM - No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} -  No File
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-02] (Google Inc.)
Toolbar: HKU\S-1-5-21-1645522239-1708537768-725345543-1004 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-02] (Google Inc.)
Toolbar: HKU\S-1-5-21-1645522239-1708537768-725345543-1004 -> No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} -  No File
Toolbar: HKU\S-1-5-21-1645522239-1708537768-725345543-1004 -> No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} -  No File
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} http://www.driveragent.com/files/driveragent.cab
Handler: intu-qt2007 - {026BF40D-BA05-467b-9F1F-AD0D7A3F5F11} - C:\Program Files\QuickTax 2007\ic2007pp.dll No File []
Handler: intu-qt2008 - {05E53CE9-66C8-4a9e-A99F-FDB7A8E7B596} - C:\Program Files\QuickTax 2008\ic2008pp.dll No File []
Handler: intu-qt2009 - {03947252-2355-4e9b-B446-8CCC75C43370} - C:\Program Files\QuickTax 2009\ic2009pp.dll [2010-03-02] (Intuit Canada, a general partnership/une société en nom collectif.)
Handler: intu-tt2010 - {97A0575E-2309-4e75-8509-B1F9390C4DE7} - C:\Program Files\TurboTax 2010\ic2010pp.dll [2010-12-01] (Intuit Canada, a general partnership/une société en nom collectif.)
Handler: intu-tt2011 - {B3B5DAD9-E96D-45b4-B636-B6CF2F773DE1} - C:\Program Files\TurboTax 2011\ic2011pp.dll [2012-03-16] (Intuit Canada, a general partnership/une société en nom collectif.)
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll No File []
ShellExecuteHooks: Microsoft AntiMalware ShellExecuteHook - {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll [83224 2006-11-03] (Microsoft Corporation)
 
FireFox:
========
FF ProfilePath: C:\Documents and Settings\Ron\Application Data\Mozilla\Firefox\Profiles\odiqqo40.default
FF SearchEngineOrder.1: Ask.com
FF SelectedSearchEngine: Google
FF Homepage: google.ca
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-04-02] ()
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 -> C:\Program Files\DivX\DivX Web Player\npdivx32.dll [2008-03-21] (DivX,Inc.)
FF Plugin: @divx.com/DivX Player Plugin,version=1.0.0 -> C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll [2008-03-21] (DivX, Inc)
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-09-26] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2014-09-26] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll [2014-02-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @pack.google.com/Google Updater;version=14 -> C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll [2011-09-05] (Google)
FF Plugin: @real.com/nppl3260;version=6.0.12.69 -> C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll [2008-10-10] (RealNetworks, Inc.)
FF Plugin: @real.com/nprjplug;version=1.0.3.69 -> C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll [2008-10-10] (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=6.0.12.69 -> C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll [2008-10-10] (RealNetworks, Inc.)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.)
FF Plugin HKU\S-1-5-21-1645522239-1708537768-725345543-1004: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll No File
FF Plugin HKU\S-1-5-21-1645522239-1708537768-725345543-1004: @unity3d.com/UnityPlayer,version=1.0 -> C:\Documents and Settings\Ron\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll [2013-01-10] (Unity Technologies ApS)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\cgpcfg.dll [2008-02-07] (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\CgpCore.dll [2008-02-07] (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\confmgr.dll [2008-02-07] ()
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\ctxlogging.dll [2008-02-07] ()
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\ctxmui.dll [2008-02-07] (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\icafile.dll [2008-02-07] (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\icalogon.dll [2008-02-07] (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\msvcm80.dll [2007-03-16] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\msvcp80.dll [2007-03-16] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\msvcr80.dll [2007-03-16] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npdivx32.dll [2008-03-21] (DivX,Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npDivxPlayerPlugin.dll [2008-03-21] (DivX, Inc)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npicaN.dll [2008-02-07] ()
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2006-12-18] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppl3260.dll [2008-10-10] (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprjplug.dll [2008-10-10] (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprpjplug.dll [2008-10-10] (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPSFDMGR.dll [2007-12-04] (SpiralFrog Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\sslsdk_b.dll [2007-07-20] (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\TcpPServ.dll [2008-02-07] (Citrix Systems, Inc.)
FF SearchPlugin: C:\Documents and Settings\Ron\Application Data\Mozilla\Firefox\Profiles\odiqqo40.default\searchplugins\SearchResults.xml [2011-09-13]
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\avg-secure-search.xml [2013-03-30]
FF Extension: Microsoft .NET Framework Assistant - C:\Documents and Settings\Ron\Application Data\Mozilla\Firefox\Profiles\odiqqo40.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010-05-01]
FF Extension: Google Toolbar for Firefox - C:\Documents and Settings\Ron\Application Data\Mozilla\Firefox\Profiles\odiqqo40.default\Extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2011-11-23]
FF Extension: Google Toolbar for Firefox - C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2015-04-02]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-08-22]
 
Chrome: 
=======
CHR HomePage: Default -> 
CHR StartupUrls: Default -> "hxxp://google.ca/", "hxxp://google.ca/"
CHR Profile: C:\Documents and Settings\Ron\Local Settings\Application Data\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Documents and Settings\Ron\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-04-20]
CHR Extension: (Google Drive) - C:\Documents and Settings\Ron\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-04-20]
CHR Extension: (YouTube) - C:\Documents and Settings\Ron\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-09-28]
CHR Extension: (Google Search) - C:\Documents and Settings\Ron\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-09-28]
CHR Extension: (Universe) - C:\Documents and Settings\Ron\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ebkhmhnhknbjjggjfagcaaoimilkogcn [2014-04-21]
CHR Extension: (Click&Clean) - C:\Documents and Settings\Ron\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ghgabhipcejejjmhhchfonmamedcbeod [2014-04-21]
CHR Extension: (Chrome Hotword Shared Module) - C:\Documents and Settings\Ron\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-12]
CHR Extension: (Solitaire) - C:\Documents and Settings\Ron\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lkbhppfbabandkdmgjmifahoabeodiep [2014-11-14]
CHR Extension: (Google Wallet) - C:\Documents and Settings\Ron\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-20]
CHR Extension: (Click&Clean App) - C:\Documents and Settings\Ron\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp [2014-06-03]
CHR Extension: (Gmail) - C:\Documents and Settings\Ron\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-09-28]
 
========================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [177560 2015-01-30] (APN LLC.)
S3 AppleChargerSrv; C:\WINDOWS\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
S2 Hamachi2Svc; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [1238408 2010-12-06] (LogMeIn Inc.)
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2014-09-26] (Oracle Corporation)
S3 Macromedia Licensing Service; C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe [68096 2009-06-05] () [File not signed]
R2 SandraAgentSrv; C:\Program Files\SiSoftware\SiSoftware Sandra Lite XII.SP2c\RpcAgentSrv.exe [98488 2008-04-23] (SiSoftware)
S3 usprserv; C:\WINDOWS\System32\svchost.exe [14336 2008-04-13] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [13592 2006-11-03] (Microsoft Corporation)
S2 ADExchange; C:\Program Files\Common Files\ArcSoft\esinter\Bin\eservutil.exe [X]
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 61883; C:\WINDOWS\System32\DRIVERS\61883.sys [48128 2008-04-13] (Microsoft Corporation)
S3 Ambfilt; C:\WINDOWS\System32\drivers\Ambfilt.sys [1691480 2009-11-17] (Creative)
R3 amdhub30; C:\WINDOWS\System32\DRIVERS\amdhub30.sys [70272 2011-03-17] (Advanced Micro Devices, INC.)
R3 amdxhc; C:\WINDOWS\System32\DRIVERS\amdxhc.sys [149632 2011-03-17] (Advanced Micro Devices, INC.)
R1 AppleCharger; C:\WINDOWS\System32\DRIVERS\AppleCharger.sys [18544 2011-01-10] ()
R1 AsIO; C:\WINDOWS\System32\drivers\AsIO.sys [4962 2004-10-14] () [File not signed]
R3 ati2mtag; C:\WINDOWS\System32\DRIVERS\ati2mtag.sys [7022080 2011-06-27] (ATI Technologies Inc.) [File not signed]
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation)
S3 ENTECH; C:\WINDOWS\system32\DRIVERS\ENTECH.sys [27672 2007-09-07] (EnTech Taiwan)
S3 ENUM1394; C:\WINDOWS\System32\DRIVERS\enum1394.sys [6400 2001-08-17] (Microsoft Corporation)
S3 EtronHub3; C:\WINDOWS\System32\Drivers\EtronHub3.sys [45056 2011-08-17] (Etron Technology Inc)
S3 gameenum; C:\WINDOWS\System32\DRIVERS\gameenum.sys [10624 2008-04-13] (Microsoft Corporation)
R3 hamachi; C:\WINDOWS\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
S3 HdAudAddService; C:\WINDOWS\System32\drivers\HdAudio.sys [145920 2004-10-27] (Windows ® Server 2003 DDK provider)
R3 Iviaspi; C:\WINDOWS\System32\drivers\iviaspi.sys [21060 2003-09-10] (InterVideo, Inc.) [File not signed]
S3 libusb0; C:\WINDOWS\System32\drivers\libusb0.sys [21504 2011-11-23] (http://libusb-win32.sourceforge.net) [File not signed]
R0 m5288; C:\WINDOWS\System32\drivers\m5288.sys [102528 2005-10-18] (ULi Electronics Inc.)
S3 Monfilt; C:\WINDOWS\System32\drivers\Monfilt.sys [1395800 2009-11-17] (Creative Technology Ltd.)
S3 ms_mpu401; C:\WINDOWS\System32\drivers\msmpu401.sys [2944 2001-08-17] (Microsoft Corporation)
S3 MTsensor; C:\WINDOWS\System32\DRIVERS\ASACPI.sys [5810 2004-08-12] ()
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
S3 RT25USBAP; C:\WINDOWS\System32\DRIVERS\rt25usbap.sys [162816 2006-04-10] (Ralink Technology Inc.) [File not signed]
R3 RTHDMIAzAudService; C:\WINDOWS\System32\drivers\RtKHDMI.sys [4104488 2011-04-25] (Realtek Semiconductor Corp.)
S3 SANDRA; C:\Program Files\SiSoftware\SiSoftware Sandra Lite XII.SP2c\WNt500x86\Sandra.sys [21408 2008-03-10] (SiSoftware)
S3 TVICHW32; C:\WINDOWS\system32\DRIVERS\TVICHW32.SYS [23600 2008-01-17] (EnTech Taiwan) [File not signed]
S3 yukonwxp; C:\WINDOWS\System32\DRIVERS\yk51x86.sys [299008 2009-12-11] (Marvell)
S3 ADIHdAudAddService; system32\drivers\ADIHdAud.sys [X]
S3 AEAudioService; system32\drivers\AEAudio.sys [X]
S3 ALSysIO; \??\C:\DOCUME~1\Ron\LOCALS~1\Temp\ALSysIO.sys [X]
S2 ASInsHelp; \??\C:\WINDOWS\system32\drivers\AsInsHelp32.sys [X]
S2 Aspi32; System32\drivers\aspi32.sys [X]
S3 catchme; \??\C:\DOCUME~1\Ron\LOCALS~1\Temp\catchme.sys [X]
S3 cpuz135; \??\C:\DOCUME~1\Ron\LOCALS~1\Temp\cpuz135\cpuz135_x32.sys [X]
S3 EtronXHCI; System32\Drivers\EtronXHCI.sys [X]
S3 gdrv; \??\C:\WINDOWS\gdrv.sys [X]
S4 IntelIde; No ImagePath
S1 SBRE; \??\C:\WINDOWS\system32\drivers\SBREdrv.sys [X]
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
S3 SenFiltService; system32\drivers\Senfilt.sys [X]
U1 WS2IFSL; No ImagePath
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-04-12 17:39 - 2015-04-12 17:40 - 00028408 _____ () C:\Documents and Settings\Ron\Desktop\FRST.txt
2015-04-12 17:39 - 2015-04-12 17:39 - 00000000 ____D () C:\FRST
2015-04-12 17:31 - 2015-04-12 17:31 - 01135616 _____ (Farbar) C:\Documents and Settings\Ron\Desktop\FRST.exe
2015-04-06 09:33 - 2015-04-06 09:38 - 02823330 _____ () C:\Documents and Settings\Ron\Desktop\ListCWall.txt
2015-04-06 09:33 - 2015-04-06 09:33 - 00452424 _____ (Bleeping Computer, LLC) C:\Documents and Settings\Ron\Desktop\ListCWall.exe
2015-04-06 09:28 - 2015-04-06 09:28 - 00350242 _____ () C:\Documents and Settings\Ron\Desktop\ESET Results Text 1.txt
2015-04-05 18:32 - 2015-04-05 18:32 - 00000664 _____ () C:\WINDOWS\system32\d3d9caps.dat
2015-04-05 17:49 - 2015-04-05 17:49 - 00005120 ___SH () C:\Documents and Settings\Ron\Local Settings\Thumbs.db
2015-04-05 17:49 - 2015-04-05 17:49 - 00005120 ___SH () C:\Documents and Settings\Ron\Application Data\Thumbs.db
2015-04-03 18:34 - 2015-04-04 00:31 - 00000000 ____D () C:\Documents and Settings\Ron\My Documents\CompleteNatGeo
2015-04-03 18:34 - 2015-04-03 18:34 - 00000000 ____D () C:\Documents and Settings\Ron\Application Data\com.nationalgeographic.products.cng120.68B1CC4249876152EBE333BD4B7514ADB4D94062.1
2015-04-03 18:34 - 2015-04-03 18:34 - 00000000 ____D () C:\Documents and Settings\Ron\Application Data\com.nationalgeographic.products.cng120
2015-04-03 18:32 - 2015-04-03 18:32 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\The Complete National Geographic
2015-04-03 18:31 - 2015-04-03 18:31 - 00001016 _____ () C:\Documents and Settings\All Users\Desktop\The Complete National Geographic.lnk
2015-04-03 18:31 - 2015-04-03 18:31 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\National Geographic
2015-04-03 18:30 - 2015-04-03 18:30 - 00000000 _____ () C:\Documents and Settings\Ron\.airappinstall.log
2015-04-03 18:27 - 2015-04-03 18:34 - 00000000 ____D () C:\Program Files\National Geographic
2015-04-03 18:27 - 2015-04-03 18:32 - 00000000 ____D () C:\Documents and Settings\Ron\natgeo_temp
2015-04-03 14:15 - 2015-04-03 14:15 - 00000000 _____ () C:\Documents and Settings\All Users\Application Data\xml57.tmp
2015-04-02 16:23 - 2015-04-02 16:23 - 00002588 _____ () C:\WINDOWS\bitssetup.log
2015-04-02 16:21 - 2015-04-02 19:03 - 00065536 _____ () C:\WINDOWS\system32\config\WindowsPowerShell.evt
2015-04-02 16:21 - 2015-04-02 16:21 - 00033035 _____ () C:\WINDOWS\KB926139-v2.log
2015-04-02 16:21 - 2015-04-02 16:21 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB926139-v2$
2015-04-02 16:21 - 2015-04-02 16:21 - 00000000 ____D () C:\WINDOWS\system32\windowspowershell
2015-04-02 16:21 - 2015-04-02 16:21 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Windows PowerShell 1.0
2015-04-02 16:07 - 2015-04-02 16:09 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-04-02 15:21 - 2015-04-02 15:21 - 00008598 _____ () C:\Documents and Settings\Ron\Local Settings\HELP_DECRYPT.HTML
2015-04-02 15:21 - 2015-04-02 15:21 - 00008598 _____ () C:\Documents and Settings\Ron\Local Settings\Application Data\HELP_DECRYPT.HTML
2015-04-02 15:21 - 2015-04-02 15:21 - 00004242 _____ () C:\Documents and Settings\Ron\Local Settings\HELP_DECRYPT.TXT
2015-04-02 15:21 - 2015-04-02 15:21 - 00004242 _____ () C:\Documents and Settings\Ron\Local Settings\Application Data\HELP_DECRYPT.TXT
2015-04-02 15:21 - 2015-04-02 15:21 - 00000280 _____ () C:\Documents and Settings\Ron\Local Settings\HELP_DECRYPT.URL
2015-04-02 15:21 - 2015-04-02 15:21 - 00000280 _____ () C:\Documents and Settings\Ron\Local Settings\Application Data\HELP_DECRYPT.URL
2015-04-02 14:46 - 2015-04-02 14:46 - 00008598 _____ () C:\Documents and Settings\Ron\Application Data\HELP_DECRYPT.HTML
2015-04-02 14:46 - 2015-04-02 14:46 - 00004242 _____ () C:\Documents and Settings\Ron\Application Data\HELP_DECRYPT.TXT
2015-04-02 14:46 - 2015-04-02 14:46 - 00000280 _____ () C:\Documents and Settings\Ron\Application Data\HELP_DECRYPT.URL
2015-04-02 14:44 - 2015-04-02 14:44 - 00008598 _____ () C:\Documents and Settings\NetworkService\Local Settings\HELP_DECRYPT.HTML
2015-04-02 14:44 - 2015-04-02 14:44 - 00008598 _____ () C:\Documents and Settings\NetworkService\Local Settings\Application Data\HELP_DECRYPT.HTML
2015-04-02 14:44 - 2015-04-02 14:44 - 00008598 _____ () C:\Documents and Settings\NetworkService\HELP_DECRYPT.HTML
2015-04-02 14:44 - 2015-04-02 14:44 - 00008598 _____ () C:\Documents and Settings\LocalService\Local Settings\HELP_DECRYPT.HTML
2015-04-02 14:44 - 2015-04-02 14:44 - 00008598 _____ () C:\Documents and Settings\LocalService\Local Settings\Application Data\HELP_DECRYPT.HTML
2015-04-02 14:44 - 2015-04-02 14:44 - 00008598 _____ () C:\Documents and Settings\LocalService\HELP_DECRYPT.HTML
2015-04-02 14:44 - 2015-04-02 14:44 - 00008598 _____ () C:\Documents and Settings\LocalService\Application Data\HELP_DECRYPT.HTML
2015-04-02 14:44 - 2015-04-02 14:44 - 00008598 _____ () C:\Documents and Settings\Default User\Local Settings\HELP_DECRYPT.HTML
2015-04-02 14:44 - 2015-04-02 14:44 - 00008598 _____ () C:\Documents and Settings\Default User\Local Settings\Application Data\HELP_DECRYPT.HTML
2015-04-02 14:44 - 2015-04-02 14:44 - 00008598 _____ () C:\Documents and Settings\Default User\HELP_DECRYPT.HTML
2015-04-02 14:44 - 2015-04-02 14:44 - 00008598 _____ () C:\Documents and Settings\Default User\Application Data\HELP_DECRYPT.HTML
2015-04-02 14:44 - 2015-04-02 14:44 - 00008598 _____ () C:\Documents and Settings\All Users\HELP_DECRYPT.HTML
2015-04-02 14:44 - 2015-04-02 14:44 - 00004242 _____ () C:\Documents and Settings\NetworkService\Local Settings\HELP_DECRYPT.TXT
2015-04-02 14:44 - 2015-04-02 14:44 - 00004242 _____ () C:\Documents and Settings\NetworkService\Local Settings\Application Data\HELP_DECRYPT.TXT
2015-04-02 14:44 - 2015-04-02 14:44 - 00004242 _____ () C:\Documents and Settings\NetworkService\HELP_DECRYPT.TXT
2015-04-02 14:44 - 2015-04-02 14:44 - 00004242 _____ () C:\Documents and Settings\LocalService\Local Settings\HELP_DECRYPT.TXT
2015-04-02 14:44 - 2015-04-02 14:44 - 00004242 _____ () C:\Documents and Settings\LocalService\Local Settings\Application Data\HELP_DECRYPT.TXT
2015-04-02 14:44 - 2015-04-02 14:44 - 00004242 _____ () C:\Documents and Settings\LocalService\HELP_DECRYPT.TXT
2015-04-02 14:44 - 2015-04-02 14:44 - 00004242 _____ () C:\Documents and Settings\LocalService\Application Data\HELP_DECRYPT.TXT
2015-04-02 14:44 - 2015-04-02 14:44 - 00004242 _____ () C:\Documents and Settings\Default User\Local Settings\HELP_DECRYPT.TXT
2015-04-02 14:44 - 2015-04-02 14:44 - 00004242 _____ () C:\Documents and Settings\Default User\Local Settings\Application Data\HELP_DECRYPT.TXT
2015-04-02 14:44 - 2015-04-02 14:44 - 00004242 _____ () C:\Documents and Settings\Default User\HELP_DECRYPT.TXT
2015-04-02 14:44 - 2015-04-02 14:44 - 00004242 _____ () C:\Documents and Settings\Default User\Application Data\HELP_DECRYPT.TXT
2015-04-02 14:44 - 2015-04-02 14:44 - 00004242 _____ () C:\Documents and Settings\All Users\HELP_DECRYPT.TXT
2015-04-02 14:44 - 2015-04-02 14:44 - 00000280 _____ () C:\Documents and Settings\NetworkService\Local Settings\HELP_DECRYPT.URL
2015-04-02 14:44 - 2015-04-02 14:44 - 00000280 _____ () C:\Documents and Settings\NetworkService\Local Settings\Application Data\HELP_DECRYPT.URL
2015-04-02 14:44 - 2015-04-02 14:44 - 00000280 _____ () C:\Documents and Settings\NetworkService\HELP_DECRYPT.URL
2015-04-02 14:44 - 2015-04-02 14:44 - 00000280 _____ () C:\Documents and Settings\LocalService\Local Settings\HELP_DECRYPT.URL
2015-04-02 14:44 - 2015-04-02 14:44 - 00000280 _____ () C:\Documents and Settings\LocalService\Local Settings\Application Data\HELP_DECRYPT.URL
2015-04-02 14:44 - 2015-04-02 14:44 - 00000280 _____ () C:\Documents and Settings\LocalService\HELP_DECRYPT.URL
2015-04-02 14:44 - 2015-04-02 14:44 - 00000280 _____ () C:\Documents and Settings\LocalService\Application Data\HELP_DECRYPT.URL
2015-04-02 14:44 - 2015-04-02 14:44 - 00000280 _____ () C:\Documents and Settings\Default User\Local Settings\HELP_DECRYPT.URL
2015-04-02 14:44 - 2015-04-02 14:44 - 00000280 _____ () C:\Documents and Settings\Default User\Local Settings\Application Data\HELP_DECRYPT.URL
2015-04-02 14:44 - 2015-04-02 14:44 - 00000280 _____ () C:\Documents and Settings\Default User\HELP_DECRYPT.URL
2015-04-02 14:44 - 2015-04-02 14:44 - 00000280 _____ () C:\Documents and Settings\Default User\Application Data\HELP_DECRYPT.URL
2015-04-02 14:44 - 2015-04-02 14:44 - 00000280 _____ () C:\Documents and Settings\All Users\HELP_DECRYPT.URL
2015-04-02 11:35 - 2015-04-02 11:35 - 00008598 _____ () C:\Documents and Settings\All Users\Application Data\HELP_DECRYPT.HTML
2015-04-02 11:35 - 2015-04-02 11:35 - 00008598 _____ () C:\Documents and Settings\Administrator\Local Settings\HELP_DECRYPT.HTML
2015-04-02 11:35 - 2015-04-02 11:35 - 00008598 _____ () C:\Documents and Settings\Administrator\Local Settings\Application Data\HELP_DECRYPT.HTML
2015-04-02 11:35 - 2015-04-02 11:35 - 00008598 _____ () C:\Documents and Settings\Administrator\HELP_DECRYPT.HTML
2015-04-02 11:35 - 2015-04-02 11:35 - 00008598 _____ () C:\Documents and Settings\Administrator\Application Data\HELP_DECRYPT.HTML
2015-04-02 11:35 - 2015-04-02 11:35 - 00004242 _____ () C:\Documents and Settings\All Users\Application Data\HELP_DECRYPT.TXT
2015-04-02 11:35 - 2015-04-02 11:35 - 00004242 _____ () C:\Documents and Settings\Administrator\Local Settings\HELP_DECRYPT.TXT
2015-04-02 11:35 - 2015-04-02 11:35 - 00004242 _____ () C:\Documents and Settings\Administrator\Local Settings\Application Data\HELP_DECRYPT.TXT
2015-04-02 11:35 - 2015-04-02 11:35 - 00004242 _____ () C:\Documents and Settings\Administrator\HELP_DECRYPT.TXT
2015-04-02 11:35 - 2015-04-02 11:35 - 00004242 _____ () C:\Documents and Settings\Administrator\Application Data\HELP_DECRYPT.TXT
2015-04-02 11:35 - 2015-04-02 11:35 - 00000280 _____ () C:\Documents and Settings\All Users\Application Data\HELP_DECRYPT.URL
2015-04-02 11:35 - 2015-04-02 11:35 - 00000280 _____ () C:\Documents and Settings\Administrator\Local Settings\HELP_DECRYPT.URL
2015-04-02 11:35 - 2015-04-02 11:35 - 00000280 _____ () C:\Documents and Settings\Administrator\Local Settings\Application Data\HELP_DECRYPT.URL
2015-04-02 11:35 - 2015-04-02 11:35 - 00000280 _____ () C:\Documents and Settings\Administrator\HELP_DECRYPT.URL
2015-04-02 11:35 - 2015-04-02 11:35 - 00000280 _____ () C:\Documents and Settings\Administrator\Application Data\HELP_DECRYPT.URL
2015-04-02 11:34 - 2015-04-02 19:03 - 00000000 ___HD () C:\4bab80d9
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-04-12 17:40 - 2010-02-11 21:03 - 00000000 ____D () C:\Documents and Settings\Ron\Local Settings\temp
2015-04-12 17:39 - 2006-05-26 07:35 - 01585565 _____ () C:\WINDOWS\WindowsUpdate.log
2015-04-12 17:38 - 2004-08-04 08:00 - 00012598 _____ () C:\WINDOWS\system32\wpa.dbl
2015-04-12 17:37 - 2014-03-27 04:13 - 00000218 _____ () C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job
2015-04-12 17:37 - 2012-06-21 18:57 - 00000330 ____H () C:\WINDOWS\Tasks\MP Scheduled Scan.job
2015-04-12 17:37 - 2009-12-20 01:12 - 00000882 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-04-12 17:37 - 2006-05-26 07:39 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-04-12 17:37 - 2006-05-26 03:30 - 00000159 _____ () C:\WINDOWS\wiadebug.log
2015-04-12 17:37 - 2006-05-26 03:30 - 00000049 _____ () C:\WINDOWS\wiaservc.log
2015-04-12 17:33 - 2006-05-26 14:40 - 00000000 ____D () C:\Installation Files
2015-04-12 17:33 - 2006-05-26 07:39 - 00000178 ___SH () C:\Documents and Settings\Ron\ntuser.ini
2015-04-06 09:37 - 2014-07-07 18:40 - 00114904 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-04-06 00:39 - 2011-07-24 00:07 - 00338791 _____ () C:\WINDOWS\setupapi.log
2015-04-06 00:35 - 2013-11-13 04:04 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2900986$
2015-04-05 19:36 - 2011-10-05 19:22 - 00000000 ____D () C:\Program Files\FrostWire 5
2015-04-05 17:49 - 2011-10-05 19:22 - 00000000 ____D () C:\Documents and Settings\Ron\.frostwire5
2015-04-05 17:49 - 2008-08-11 16:42 - 00000000 ____D () C:\Documents and Settings\Ron\jemu2
2015-04-05 17:48 - 2013-05-05 12:40 - 00000178 ___SH () C:\Documents and Settings\Administrator\ntuser.ini
2015-04-05 15:28 - 2006-05-26 08:42 - 00524288 _____ () C:\WINDOWS\system32\config\ACEEvent.evt
2015-04-05 15:28 - 2006-05-26 07:39 - 00032534 _____ () C:\WINDOWS\SchedLgU.Txt
2015-04-05 15:26 - 2009-12-20 01:12 - 00000886 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-04-05 15:18 - 2013-04-23 00:35 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-04-05 11:44 - 2006-05-26 16:53 - 00000000 ____D () C:\Documents and Settings\Ron\Application Data\1st Free Solitaire
2015-04-05 04:00 - 2012-06-04 21:42 - 00000940 _____ () C:\WINDOWS\Tasks\Ad-Aware Antivirus Scheduled Scan.job
2015-04-05 01:34 - 2010-02-11 21:03 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\temp
2015-04-03 18:30 - 2006-05-26 07:39 - 00000000 ____D () C:\Documents and Settings\Ron
2015-04-03 18:23 - 2009-07-15 19:53 - 00000000 ____D () C:\Program Files\Common Files\Adobe AIR
2015-04-03 18:23 - 2006-05-26 12:25 - 00000000 ____D () C:\Documents and Settings\Ron\Local Settings\Application Data\Adobe
2015-04-03 18:23 - 2006-05-26 08:49 - 00000000 ____D () C:\Program Files\Adobe
2015-04-03 14:16 - 2006-05-26 03:28 - 00299718 _____ () C:\WINDOWS\setupact.log
2015-04-03 14:15 - 2014-07-06 21:30 - 00000000 _____ () C:\Documents and Settings\All Users\Application Data\xml21EE.tmp
2015-04-03 14:15 - 2008-08-12 17:50 - 00015439 _____ () C:\Documents and Settings\All Users\Application Data\xmlB7.tmp
2015-04-02 19:08 - 2010-12-23 18:52 - 00000000 ____D () C:\Documents and Settings\Ron\Local Settings\Application Data\LogMeIn Hamachi
2015-04-02 19:05 - 2006-05-26 09:35 - 00173797 ____C () C:\WINDOWS\spupdsvc.log
2015-04-02 19:04 - 2015-01-04 06:36 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-04-02 19:04 - 2011-07-26 03:03 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB979559$
2015-04-02 18:46 - 2007-01-12 19:07 - 00000000 ____D () C:\Documents and Settings\Ron\My Documents\MoviePlus
2015-04-02 17:07 - 2006-05-26 07:34 - 00000000 ____D () C:\WINDOWS\Registration
2015-04-02 16:36 - 2014-06-15 16:37 - 00000000 ____D () C:\Documents and Settings\Ron\My Documents\Manuals
2015-04-02 16:36 - 2010-11-12 17:52 - 00000000 ____D () C:\Documents and Settings\Ron\My Documents\FrostWire
2015-04-02 16:36 - 2006-05-26 13:21 - 00000000 ____D () C:\Documents and Settings\Ron\My Documents\HHGTTG
2015-04-02 16:34 - 2006-05-26 08:36 - 00000000 ____D () C:\WINDOWS\Microsoft.NET
2015-04-02 16:28 - 2014-04-20 18:20 - 00001813 _____ () C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
2015-04-02 16:28 - 2012-06-04 21:29 - 00000000 ____D () C:\Documents and Settings\Ron\My Documents\ecu
2015-04-02 16:26 - 2006-05-26 13:19 - 00000000 ____D () C:\Documents and Settings\Ron\My Documents\Digital Photos
2015-04-02 16:21 - 2006-05-26 03:29 - 03880362 _____ () C:\WINDOWS\FaxSetup.log
2015-04-02 16:21 - 2006-05-26 03:29 - 01866432 _____ () C:\WINDOWS\ocgen.log
2015-04-02 16:21 - 2006-05-26 03:29 - 01487121 _____ () C:\WINDOWS\tsoc.log
2015-04-02 16:21 - 2006-05-26 03:29 - 00772056 _____ () C:\WINDOWS\ntdtcsetup.log
2015-04-02 16:21 - 2006-05-26 03:29 - 00606986 _____ () C:\WINDOWS\iis6.log
2015-04-02 16:21 - 2006-05-26 03:29 - 00225225 _____ () C:\WINDOWS\comsetup.log
2015-04-02 16:21 - 2006-05-26 03:29 - 00210685 _____ () C:\WINDOWS\ocmsn.log
2015-04-02 16:21 - 2006-05-26 03:29 - 00194633 _____ () C:\WINDOWS\msgsocm.log
2015-04-02 16:21 - 2006-05-26 03:29 - 00001355 _____ () C:\WINDOWS\imsins.log
2015-04-02 16:17 - 2006-12-05 22:19 - 00000955 _____ () C:\Documents and Settings\All Users\Start Menu\Programs\Windows Defender.lnk
2015-04-02 16:16 - 2007-04-05 17:10 - 00000000 ____D () C:\Documents and Settings\Ron\My Documents\Astro Photos
2015-04-02 16:16 - 2006-05-26 13:19 - 00000000 ____D () C:\Documents and Settings\Ron\My Documents\Corel User Files
2015-04-02 16:16 - 2006-05-26 12:34 - 00000000 ____D () C:\Documents and Settings\Ron\My Documents\Act-1 Forms
2015-04-02 16:13 - 2006-05-26 12:35 - 00000000 ____D () C:\Documents and Settings\Ron\My Documents\ACT Show Files
2015-04-02 16:11 - 2012-05-30 18:20 - 00778928 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2015-04-02 16:10 - 2011-07-23 18:53 - 00142512 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2015-04-02 16:09 - 2010-12-23 00:29 - 00000000 ____D () C:\Documents and Settings\Ron\Desktop\Minecraft server
2015-04-02 16:02 - 2010-12-23 18:48 - 00000000 ____D () C:\Documents and Settings\LocalService\Local Settings\Application Data\LogMeIn Hamachi
2015-04-02 15:57 - 2014-04-27 03:10 - 00001137 _____ () C:\Documents and Settings\Ron\Desktop\CoreTemp.ini
2015-04-02 15:21 - 2013-07-10 23:50 - 00000000 ____D () C:\Documents and Settings\Ron\Local Settings\Application Data\Sun
2015-04-02 15:21 - 2008-12-12 23:23 - 00000000 ____D () C:\Documents and Settings\Ron\Local Settings\Application Data\Opera
2015-04-02 15:21 - 2007-01-04 23:43 - 00000000 ____D () C:\Documents and Settings\Ron\Local Settings\Application Data\Mozilla
2015-04-02 15:17 - 2009-06-05 22:03 - 00000000 ____D () C:\Documents and Settings\Ron\Local Settings\Application Data\Macromedia
2015-04-02 15:14 - 2011-12-10 12:31 - 00000000 ____D () C:\Documents and Settings\Ron\Local Settings\Application Data\Kobo
2015-04-02 15:14 - 2011-09-13 18:04 - 00000000 ____D () C:\Documents and Settings\Ron\Local Settings\Application Data\iMesh
2015-04-02 15:13 - 2006-05-26 17:19 - 00000000 ____D () C:\Documents and Settings\Ron\Local Settings\Application Data\Google
2015-04-02 15:12 - 2014-06-06 17:20 - 00000000 ____D () C:\Documents and Settings\Ron\Desktop\vlc-2.1.3
2015-04-02 15:12 - 2013-05-05 11:08 - 00000000 ____D () C:\Documents and Settings\Ron\Local Settings\Application Data\Conduit
2015-04-02 15:12 - 2012-06-03 00:43 - 00000000 ____D () C:\Documents and Settings\Ron\Local Settings\Application Data\adawarebp
2015-04-02 15:11 - 2013-08-13 11:47 - 00000000 ____D () C:\Documents and Settings\Ron\Desktop\syobon-action
2015-04-02 15:11 - 2013-08-13 00:27 - 00000000 ____D () C:\Documents and Settings\Ron\Desktop\PSP CFW
2015-04-02 15:10 - 2011-07-23 18:55 - 00000000 ____D () C:\Documents and Settings\Ron\Desktop\New Computer Stuff
2015-04-02 15:09 - 2013-08-14 23:16 - 00000000 ____D () C:\Documents and Settings\Ron\Desktop\M7788v1.0
2015-04-02 14:46 - 2010-08-11 21:20 - 00000000 ____D () C:\Documents and Settings\Ron\Application Data\OpenOffice.org
2015-04-02 14:46 - 2008-12-12 23:23 - 00000000 ____D () C:\Documents and Settings\Ron\Application Data\Opera
2015-04-02 14:46 - 2008-08-10 17:32 - 00000000 __RHD () C:\Documents and Settings\Ron\Application Data\SecuROM
2015-04-02 14:46 - 2006-07-02 16:56 - 00000000 ____D () C:\Documents and Settings\Ron\Application Data\Real
2015-04-02 14:46 - 2006-05-31 15:44 - 00000000 ____D () C:\Documents and Settings\Ron\Application Data\Sun
2015-04-02 14:46 - 2006-05-27 12:22 - 00000000 ____D () C:\Documents and Settings\Ron\Application Data\Serif
2015-04-02 14:46 - 2006-05-26 17:03 - 00000000 ____D () C:\Documents and Settings\Ron\Application Data\OpenOffice.org2
2015-04-02 14:45 - 2011-09-13 18:04 - 00000000 ____D () C:\Documents and Settings\Ron\Application Data\mediabarim
2015-04-02 14:45 - 2011-08-04 13:56 - 00000000 ____D () C:\Documents and Settings\Ron\Application Data\.minecraft
2015-04-02 14:45 - 2010-11-12 17:52 - 00000000 ____D () C:\Documents and Settings\Ron\Application Data\FrostWire
2015-04-02 14:45 - 2010-10-27 18:12 - 00000000 ____D () C:\Documents and Settings\Ron\Application Data\BitTorrent
2015-04-02 14:45 - 2008-02-16 16:45 - 00000000 ____D () C:\Documents and Settings\Ron\Application Data\Aim
2015-04-02 14:45 - 2007-01-04 23:43 - 00000000 ____D () C:\Documents and Settings\Ron\Application Data\Mozilla
2015-04-02 14:45 - 2006-05-31 15:48 - 00000000 ____D () C:\Documents and Settings\Ron\Application Data\Macromedia
2015-04-02 14:45 - 2006-05-26 08:48 - 00000000 ____D () C:\Documents and Settings\Ron\Application Data\Adobe
2015-04-02 14:44 - 2013-11-22 08:47 - 00000000 ____D () C:\Documents and Settings\LocalService\Application Data\McAfee
2015-04-02 14:44 - 2013-05-01 07:25 - 00000000 ____D () C:\Documents and Settings\Default User\Local Settings\Application Data\Google
2015-04-02 14:44 - 2007-11-17 02:50 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Application Data\PCHealth
2015-04-02 14:44 - 2006-05-26 07:39 - 00000000 __SHD () C:\Documents and Settings\NetworkService
2015-04-02 14:44 - 2006-05-26 07:39 - 00000000 __SHD () C:\Documents and Settings\LocalService
2015-04-02 14:44 - 2006-05-26 07:36 - 00000000 __SHD () C:\Documents and Settings\All Users\DRM
2015-04-02 11:35 - 2014-12-02 21:28 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Canon_Inc_IC
2015-04-02 11:35 - 2014-04-23 07:56 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Freemake
2015-04-02 11:35 - 2013-05-05 12:40 - 00000000 ____D () C:\Documents and Settings\Administrator
2015-04-02 11:35 - 2012-06-21 18:54 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\GFI Software
2015-04-02 11:35 - 2011-09-13 18:04 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\14A4
2015-04-02 11:35 - 2011-07-23 19:08 - 00000000 ____D () C:\AMD
2015-04-02 11:35 - 2010-10-18 00:03 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\MFAData
2015-04-02 11:35 - 2009-11-18 00:52 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\avg9
2015-04-02 11:35 - 2006-07-18 17:40 - 00000000 ____D () C:\dj920
2015-04-02 11:35 - 2006-05-27 14:02 - 00000000 ____D () C:\CanoScan
2015-04-01 21:23 - 2010-10-22 15:08 - 00000486 _____ () C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
2015-03-27 20:15 - 2012-04-16 22:42 - 00014624 _____ () C:\Documents and Settings\Ron\Desktop\Shopping List.xls
2015-03-27 12:31 - 2006-05-26 14:39 - 00010016 _____ () C:\Documents and Settings\Ron\My Documents\Menus.xls
2015-03-21 03:20 - 2006-05-26 03:29 - 00573444 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2015-03-21 03:16 - 2011-07-23 19:59 - 2145386496 _____ () C:\WINDOWS\MEMORY.DMP
 
==================== Files in the root of some directories =======
 
2011-12-17 17:29 - 2011-12-17 17:29 - 63308193 _____ (Apogee Development, Ltd                                     ) C:\Program Files\A-OK! WoM Windows Installer.exe
2014-06-15 16:49 - 2014-06-15 16:49 - 0536104 _____ (Microsoft Corporation) C:\Program Files\WindowsXP-KB934428-v3-x86-ENU.exe
2014-06-15 16:52 - 2014-06-15 16:52 - 3403304 _____ (Microsoft Corporation) C:\Program Files\WindowsXP-KB955704-x86-ENU.exe
2009-05-20 20:03 - 2012-06-01 18:00 - 0002542 _____ () C:\Documents and Settings\Ron\Application Data\A-OK! WoM.ini
2015-04-02 14:46 - 2015-04-02 14:46 - 0008598 _____ () C:\Documents and Settings\Ron\Application Data\HELP_DECRYPT.HTML
2015-04-02 14:46 - 2015-04-02 14:46 - 0045457 _____ () C:\Documents and Settings\Ron\Application Data\HELP_DECRYPT.PNG
2015-04-02 14:46 - 2015-04-02 14:46 - 0004242 _____ () C:\Documents and Settings\Ron\Application Data\HELP_DECRYPT.TXT
2015-04-02 14:46 - 2015-04-02 14:46 - 0000280 _____ () C:\Documents and Settings\Ron\Application Data\HELP_DECRYPT.URL
2015-04-05 17:49 - 2015-04-05 17:49 - 0005120 ___SH () C:\Documents and Settings\Ron\Application Data\Thumbs.db
2008-09-08 17:57 - 2009-01-22 23:10 - 0000054 _____ () C:\Documents and Settings\Ron\Application Data\turing_files.ini
2006-05-27 15:24 - 2014-11-14 21:59 - 0168960 _____ () C:\Documents and Settings\Ron\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-08-10 11:00 - 2012-08-10 11:00 - 0027520 _____ () C:\Documents and Settings\Ron\Local Settings\Application Data\dt.dat
2006-05-26 08:42 - 2006-05-26 08:42 - 0000126 _____ () C:\Documents and Settings\Ron\Local Settings\Application Data\fusioncache.dat
2015-04-02 15:21 - 2015-04-02 15:21 - 0008598 _____ () C:\Documents and Settings\Ron\Local Settings\Application Data\HELP_DECRYPT.HTML
2015-04-02 15:21 - 2015-04-02 15:21 - 0045457 _____ () C:\Documents and Settings\Ron\Local Settings\Application Data\HELP_DECRYPT.PNG
2015-04-02 15:21 - 2015-04-02 15:21 - 0004242 _____ () C:\Documents and Settings\Ron\Local Settings\Application Data\HELP_DECRYPT.TXT
2015-04-02 15:21 - 2015-04-02 15:21 - 0000280 _____ () C:\Documents and Settings\Ron\Local Settings\Application Data\HELP_DECRYPT.URL
2015-04-02 14:44 - 2015-04-02 14:44 - 0008598 _____ () C:\Documents and Settings\All Users\HELP_DECRYPT.HTML
2015-04-02 14:44 - 2015-04-02 14:44 - 0045457 _____ () C:\Documents and Settings\All Users\HELP_DECRYPT.PNG
2015-04-02 14:44 - 2015-04-02 14:44 - 0004242 _____ () C:\Documents and Settings\All Users\HELP_DECRYPT.TXT
2015-04-02 14:44 - 2015-04-02 14:44 - 0000280 _____ () C:\Documents and Settings\All Users\HELP_DECRYPT.URL
 
Files to move or delete:
====================
C:\Documents and Settings\Ron\lametritonus_en.dll
C:\Documents and Settings\Ron\lame_enc_en.dll
 
 
Some content of TEMP:
====================
C:\Documents and Settings\Ron\Local Settings\temp\33ae7955-c2b4-4184-af8f-7de57bcb1d7e.exe
C:\Documents and Settings\Ron\Local Settings\temp\APNSetup.exe
C:\Documents and Settings\Ron\Local Settings\temp\avguidx.dll
C:\Documents and Settings\Ron\Local Settings\temp\bitool.dll
C:\Documents and Settings\Ron\Local Settings\temp\Cloud_Backup_Setup.exe
C:\Documents and Settings\Ron\Local Settings\temp\CommonInstaller.exe
C:\Documents and Settings\Ron\Local Settings\temp\contentDATs.exe
C:\Documents and Settings\Ron\Local Settings\temp\f5bbf16d-98b1-41be-ac9f-726492befcaa.exe
C:\Documents and Settings\Ron\Local Settings\temp\FreemakeAudioConverter_1.1.0.53.exe
C:\Documents and Settings\Ron\Local Settings\temp\GoogleDriveSync_1_8_4357_4863.exe
C:\Documents and Settings\Ron\Local Settings\temp\iMesh_setup.exe
C:\Documents and Settings\Ron\Local Settings\temp\InfraRecorder.exe
C:\Documents and Settings\Ron\Local Settings\temp\Installhelper.dll
C:\Documents and Settings\Ron\Local Settings\temp\jre-6u23-windows-i586-iftw-rv.exe
C:\Documents and Settings\Ron\Local Settings\temp\jre-6u24-windows-i586-iftw-rv.exe
C:\Documents and Settings\Ron\Local Settings\temp\jre-6u26-windows-i586-iftw-rv.exe
C:\Documents and Settings\Ron\Local Settings\temp\jre-6u31-windows-i586-iftw-rv.exe
C:\Documents and Settings\Ron\Local Settings\temp\jre-6u37-windows-i586-iftw.exe
C:\Documents and Settings\Ron\Local Settings\temp\jre-6u39-windows-i586-iftw.exe
C:\Documents and Settings\Ron\Local Settings\temp\jre-7u15-windows-i586-iftw.exe
C:\Documents and Settings\Ron\Local Settings\temp\jre-7u25-windows-i586-iftw.exe
C:\Documents and Settings\Ron\Local Settings\temp\jre-7u55-windows-i586-iftw.exe
C:\Documents and Settings\Ron\Local Settings\temp\jre-7u60-windows-i586-iftw.exe
C:\Documents and Settings\Ron\Local Settings\temp\jre-7u71-windows-i586-iftw.exe
C:\Documents and Settings\Ron\Local Settings\temp\jre-8u40-windows-au.exe
C:\Documents and Settings\Ron\Local Settings\temp\MachineIdCreator.exe
C:\Documents and Settings\Ron\Local Settings\temp\MOVIEPLUS1033_5.1.3_Patch-Setup.exe
C:\Documents and Settings\Ron\Local Settings\temp\mssinstaller.exe
C:\Documents and Settings\Ron\Local Settings\temp\oi_{7B31003E-09A4-4128-A86F-63CC5AE52838}.exe
C:\Documents and Settings\Ron\Local Settings\temp\oi_{DBD1C1E2-7D29-4B30-97A0-24A47C991BE7}.exe
C:\Documents and Settings\Ron\Local Settings\temp\SCC.dll
C:\Documents and Settings\Ron\Local Settings\temp\SecurityScan_Release.exe
C:\Documents and Settings\Ron\Local Settings\temp\setup_wm.exe
C:\Documents and Settings\Ron\Local Settings\temp\SRAssetsHelper.dll
C:\Documents and Settings\Ron\Local Settings\temp\System.Data.SQLite.dll
C:\Documents and Settings\Ron\Local Settings\temp\System.Data.SQLite13979.dll
C:\Documents and Settings\Ron\Local Settings\temp\System.Data.SQLite72239.dll
C:\Documents and Settings\Ron\Local Settings\temp\tbWhi0.dll
C:\Documents and Settings\Ron\Local Settings\temp\ToolbarInstaller.exe
C:\Documents and Settings\Ron\Local Settings\temp\UNINSTALL.EXE
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 
==================== End Of Log ============================

 

Attached Files



BC AdBot (Login to Remove)

 


#2 nasdaq

nasdaq

  • Malware Response Team
  • 38,770 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:02:37 AM

Posted 15 April 2015 - 09:25 AM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===


ATTENTION: System Restore is disabled.

Navigate to this Microsfoft page.
https://support.microsoft.com/en-us/kb/948247

Read the instructions to Restore you System point.
===

Using the Add/Remove programs applet delele this program in bold.
Search App by Ask (HKLM\...\{4F524A2D-5350-4500-76A7-A758B70C1902}) (Version: 12.25.2.60 - APN, LLC) <==== ATTENTION

===

Open notepad (Start =>All Programs => Accessories => Notepad). Please copy the entire contents of the code box below.
 
start

CloseProcesses:
EmptyTemp:

(APN LLC.) C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe
(APN) C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
HKLM\...\Run: [KernelFaultCheck] => %systemroot%\system32\dumprep 0 -k
HKLM\...\Run: [BrowserSafeguard] => "C:\Program Files\Browsersafeguard\BrowserSafeguard.exe"
HKLM\...\Run: [ApnTBMon] => C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1949592 2015-02-14] (APN)
HKU\S-1-5-21-1645522239-1708537768-725345543-1004\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-1645522239-1708537768-725345543-1004\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.search.ask.com/?tpid=ORJ-SPE&o=APN11406&pf=V7&trgb=IE&p2=^BBE^OSJ000^YY^CA&gct=hp&apn_ptnrs=BBE&apn_dtid=^OSJ000^YY^CA&apn_dbr=ie&apn_uid=19FF623B-F0F0-4188-8DFC-417CB587616A&itbv=12.21.0.114&doi=2015-01-01&psv=&pt=tb
URLSearchHook: [S-1-5-21-1645522239-1708537768-725345543-1004] ATTENTION ==> Default URLSearchHook is missing.
URLSearchHook: HKU\S-1-5-21-1645522239-1708537768-725345543-1004 - SearchHook Class - {D8278076-BC68-4484-9233-6E7F1628B56C} - C:\Program Files\AskPartnerNetwork\Toolbar\searchhook.dll (APN LLC.)
URLSearchHook: HKU\S-1-5-21-1645522239-1708537768-725345543-1004 - (No Name) - {6c97a91e-4524-4019-86af-2aa2d567bf5c} -  No File
SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD21} URL = http://search.imesh.com//web?src=ieb&appid=580&systemid=1&sr=0&q={searchTerms}
SearchScopes: HKLM -> {b0441a0e-a49a-4e16-afc1-74ecced1921f} URL = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?p2=^UX^xdm005^S04000^ca&si=CLfg_f_IqrQCFYs7MgodOnwA0Q&ptb=DF6CF306-59DC-44ED-BD3A-857EFF27D9B2&ind=2012122022&n=77ee8ba6&psa=&st=sb&searchfor={searchTerms}
SearchScopes: HKU\S-1-5-21-1645522239-1708537768-725345543-1004 -> {CB19A329-38E4-4C51-AF88-92A348A31A03} URL = http://www.search.ask.com/web?tpid=ORJ-SPE&o=APN11406&pf=V7&p2=^BBE^OSJ000^YY^CA&gct=sb&itbv=12.21.0.114&apn_uid=19FF623B-F0F0-4188-8DFC-417CB587616A&apn_ptnrs=BBE&apn_dtid=^OSJ000^YY^CA&apn_dbr=ie&doi=2015-01-01&trgb=IE&q={searchTerms}&psv=&pt=tb
BHO: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} ->  No File
BHO: AVG Safe Search -> {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -> C:\Program Files\AVG\AVG2012\avgssie.dll No File
BHO: No Name -> {95B7759C-8C7F-4BF1-B163-73684A933233} ->  No File
Toolbar: HKLM - No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} -  No File
Toolbar: HKU\S-1-5-21-1645522239-1708537768-725345543-1004 -> No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} -  No File
Toolbar: HKU\S-1-5-21-1645522239-1708537768-725345543-1004 -> No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} -  No File
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
Handler: intu-qt2007 - {026BF40D-BA05-467b-9F1F-AD0D7A3F5F11} - C:\Program Files\QuickTax 2007\ic2007pp.dll No File []
Handler: intu-qt2008 - {05E53CE9-66C8-4a9e-A99F-FDB7A8E7B596} - C:\Program Files\QuickTax 2008\ic2008pp.dll No File []
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll No File []
FF SearchEngineOrder.1: Ask.com
FF Plugin HKU\S-1-5-21-1645522239-1708537768-725345543-1004: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll No File
FF SearchPlugin: C:\Documents and Settings\Ron\Application Data\Mozilla\Firefox\Profiles\odiqqo40.default\searchplugins\SearchResults.xml [2011-09-13]
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\avg-secure-search.xml [2013-03-30]
R2 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [177560 2015-01-30] (APN LLC.)
S3 AppleChargerSrv; C:\WINDOWS\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
S2 ADExchange; C:\Program Files\Common Files\ArcSoft\esinter\Bin\eservutil.exe [X]
S3 ADIHdAudAddService; system32\drivers\ADIHdAud.sys [X]
S3 AEAudioService; system32\drivers\AEAudio.sys [X]
S3 ALSysIO; \??\C:\DOCUME~1\Ron\LOCALS~1\Temp\ALSysIO.sys [X]
S2 ASInsHelp; \??\C:\WINDOWS\system32\drivers\AsInsHelp32.sys [X]
S2 Aspi32; System32\drivers\aspi32.sys [X]
S3 catchme; \??\C:\DOCUME~1\Ron\LOCALS~1\Temp\catchme.sys [X]
S3 cpuz135; \??\C:\DOCUME~1\Ron\LOCALS~1\Temp\cpuz135\cpuz135_x32.sys [X]
S3 EtronXHCI; System32\Drivers\EtronXHCI.sys [X]
S3 gdrv; \??\C:\WINDOWS\gdrv.sys [X]
S4 IntelIde; No ImagePath
S1 SBRE; \??\C:\WINDOWS\system32\drivers\SBREdrv.sys [X]
S3 SenFiltService; system32\drivers\Senfilt.sys [X]
U1 WS2IFSL; No ImagePath
C:\Documents and Settings\Ron\Local Settings\HELP_DECRYPT.HTML
C:\Documents and Settings\Ron\Local Settings\Application Data\HELP_DECRYPT.HTML
C:\Documents and Settings\Ron\Local Settings\HELP_DECRYPT.TXT
C:\Documents and Settings\Ron\Local Settings\Application Data\HELP_DECRYPT.TXT
C:\Documents and Settings\Ron\Local Settings\HELP_DECRYPT.URL
C:\Documents and Settings\Ron\Local Settings\Application Data\HELP_DECRYPT.URL
C:\Documents and Settings\Ron\Application Data\HELP_DECRYPT.HTML
C:\Documents and Settings\Ron\Application Data\HELP_DECRYPT.TXT
C:\Documents and Settings\Ron\Application Data\HELP_DECRYPT.URL
C:\Documents and Settings\NetworkService\Local Settings\HELP_DECRYPT.HTML
C:\Documents and Settings\NetworkService\Local Settings\Application Data\HELP_DECRYPT.HTML
C:\Documents and Settings\NetworkService\HELP_DECRYPT.HTML
C:\Documents and Settings\LocalService\Local Settings\HELP_DECRYPT.HTML
C:\Documents and Settings\LocalService\Local Settings\Application Data\HELP_DECRYPT.HTML
C:\Documents and Settings\LocalService\HELP_DECRYPT.HTML
C:\Documents and Settings\LocalService\Application Data\HELP_DECRYPT.HTML
C:\Documents and Settings\Default User\Local Settings\HELP_DECRYPT.HTML
C:\Documents and Settings\Default User\Local Settings\Application Data\HELP_DECRYPT.HTML
C:\Documents and Settings\Default User\HELP_DECRYPT.HTML
C:\Documents and Settings\Default User\Application Data\HELP_DECRYPT.HTML
C:\Documents and Settings\All Users\HELP_DECRYPT.HTML
C:\Documents and Settings\NetworkService\Local Settings\HELP_DECRYPT.TXT
C:\Documents and Settings\NetworkService\Local Settings\Application Data\HELP_DECRYPT.TXT
C:\Documents and Settings\NetworkService\HELP_DECRYPT.TXT
C:\Documents and Settings\LocalService\Local Settings\HELP_DECRYPT.TXT
C:\Documents and Settings\LocalService\Local Settings\Application Data\HELP_DECRYPT.TXT
C:\Documents and Settings\LocalService\HELP_DECRYPT.TXT
C:\Documents and Settings\LocalService\Application Data\HELP_DECRYPT.TXT
C:\Documents and Settings\Default User\Local Settings\HELP_DECRYPT.TXT
C:\Documents and Settings\Default User\Local Settings\Application Data\HELP_DECRYPT.TXT
C:\Documents and Settings\Default User\HELP_DECRYPT.TXT
C:\Documents and Settings\Default User\Application Data\HELP_DECRYPT.TXT
C:\Documents and Settings\All Users\HELP_DECRYPT.TXT
C:\Documents and Settings\NetworkService\Local Settings\HELP_DECRYPT.URL
C:\Documents and Settings\NetworkService\Local Settings\Application Data\HELP_DECRYPT.URL
C:\Documents and Settings\NetworkService\HELP_DECRYPT.URL
C:\Documents and Settings\LocalService\Local Settings\HELP_DECRYPT.URL
C:\Documents and Settings\LocalService\Local Settings\Application Data\HELP_DECRYPT.URL
C:\Documents and Settings\LocalService\HELP_DECRYPT.URL
C:\Documents and Settings\LocalService\Application Data\HELP_DECRYPT.URL
C:\Documents and Settings\Default User\Local Settings\HELP_DECRYPT.URL
C:\Documents and Settings\Default User\Local Settings\Application Data\HELP_DECRYPT.URL
C:\Documents and Settings\Default User\HELP_DECRYPT.URL
C:\Documents and Settings\Default User\Application Data\HELP_DECRYPT.URL
C:\Documents and Settings\All Users\HELP_DECRYPT.URL
C:\Documents and Settings\All Users\Application Data\HELP_DECRYPT.HTML
C:\Documents and Settings\Administrator\Local Settings\HELP_DECRYPT.HTML
C:\Documents and Settings\Administrator\Local Settings\Application Data\HELP_DECRYPT.HTML
C:\Documents and Settings\Administrator\HELP_DECRYPT.HTML
C:\Documents and Settings\Administrator\Application Data\HELP_DECRYPT.HTML
C:\Documents and Settings\All Users\Application Data\HELP_DECRYPT.TXT
C:\Documents and Settings\Administrator\Local Settings\HELP_DECRYPT.TXT
C:\Documents and Settings\Administrator\Local Settings\Application Data\HELP_DECRYPT.TXT
C:\Documents and Settings\Administrator\HELP_DECRYPT.TXT
C:\Documents and Settings\Administrator\Application Data\HELP_DECRYPT.TXT
C:\Documents and Settings\All Users\Application Data\HELP_DECRYPT.URL
C:\Documents and Settings\Administrator\Local Settings\HELP_DECRYPT.URL
C:\Documents and Settings\Administrator\Local Settings\Application Data\HELP_DECRYPT.URL
C:\Documents and Settings\Administrator\HELP_DECRYPT.URL
C:\Documents and Settings\Administrator\Application Data\HELP_DECRYPT.URL
C:\4bab80d9
AlternateDataStreams: C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
C:\Program Files\Browsersafeguard

End
Save the files as fixlist.txt in the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the Farbar log you have submitted.

Run FRST and click Fix only once and wait.

Restart the computer normally to reset the registry.

The tool will create a log (Fixlog.txt) please post it to your reply.
===

Please download AdwCleaner by Xplode onto your Desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Click the Report button and the report will open in Notepad.
IMPORTANT
  • If you click the Clean button all items listed in the report will be removed.
If you find some false positive items or programs that you wish to keep, Close the AdwCleaner windows.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Check off the element(s) you wish to keep.
  • Click on the Clean button follow the prompts.
  • A log file will automatically open after the scan has finished.
  • Please post the content of that log file with your next answer.
  • You can find the log file at C:\AdwCleaner[Sn].txt (n is a number).
===

How is your computer running now?

#3 quatermass

quatermass
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:02:37 AM

Posted 15 April 2015 - 08:12 PM

Hi, nasdaq.

 

Computer seems to be working fine. Went through all your instructions as closely as possible and have embedded the two log files in this message. All I need is your blessing that my machine is spanking clean and ready to greet the world once again.

 

Thanks.

 

quatermass

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 15-04-2015 04
Ran by Ron at 2015-04-15 20:42:03 Run:1
Running from C:\Documents and Settings\Ron\Desktop
Loaded Profiles: Ron (Available profiles: Ron & Administrator)
Boot Mode: Normal
 
==============================================
 
Content of fixlist:
*****************
start
 
CloseProcesses:
EmptyTemp:
 
(APN LLC.) C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe
(APN) C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
HKLM\...\Run: [KernelFaultCheck] => %systemroot%\system32\dumprep 0 -k
HKLM\...\Run: [BrowserSafeguard] => "C:\Program Files\Browsersafeguard\BrowserSafeguard.exe"
HKLM\...\Run: [ApnTBMon] => C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1949592 2015-02-14] (APN)
HKU\S-1-5-21-1645522239-1708537768-725345543-1004\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
URLSearchHook: [S-1-5-21-1645522239-1708537768-725345543-1004] ATTENTION ==> Default URLSearchHook is missing.
URLSearchHook: HKU\S-1-5-21-1645522239-1708537768-725345543-1004 - SearchHook Class - {D8278076-BC68-4484-9233-6E7F1628B56C} - C:\Program Files\AskPartnerNetwork\Toolbar\searchhook.dll (APN LLC.)
URLSearchHook: HKU\S-1-5-21-1645522239-1708537768-725345543-1004 - (No Name) - {6c97a91e-4524-4019-86af-2aa2d567bf5c} -  No File
SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD21} URL = http://search.imesh.com//web?src=ieb&appid=580&systemid=1&sr=0&q={searchTerms}
BHO: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} ->  No File
BHO: AVG Safe Search -> {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -> C:\Program Files\AVG\AVG2012\avgssie.dll No File
BHO: No Name -> {95B7759C-8C7F-4BF1-B163-73684A933233} ->  No File
Toolbar: HKLM - No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} -  No File
Toolbar: HKU\S-1-5-21-1645522239-1708537768-725345543-1004 -> No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} -  No File
Toolbar: HKU\S-1-5-21-1645522239-1708537768-725345543-1004 -> No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} -  No File
Handler: intu-qt2007 - {026BF40D-BA05-467b-9F1F-AD0D7A3F5F11} - C:\Program Files\QuickTax 2007\ic2007pp.dll No File []
Handler: intu-qt2008 - {05E53CE9-66C8-4a9e-A99F-FDB7A8E7B596} - C:\Program Files\QuickTax 2008\ic2008pp.dll No File []
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll No File []
FF SearchEngineOrder.1: Ask.com
FF Plugin HKU\S-1-5-21-1645522239-1708537768-725345543-1004: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll No File
FF SearchPlugin: C:\Documents and Settings\Ron\Application Data\Mozilla\Firefox\Profiles\odiqqo40.default\searchplugins\SearchResults.xml [2011-09-13]
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\avg-secure-search.xml [2013-03-30]
R2 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [177560 2015-01-30] (APN LLC.)
S3 AppleChargerSrv; C:\WINDOWS\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
S2 ADExchange; C:\Program Files\Common Files\ArcSoft\esinter\Bin\eservutil.exe [X]
S3 ADIHdAudAddService; system32\drivers\ADIHdAud.sys [X]
S3 AEAudioService; system32\drivers\AEAudio.sys [X]
S3 ALSysIO; \??\C:\DOCUME~1\Ron\LOCALS~1\Temp\ALSysIO.sys [X]
S2 ASInsHelp; \??\C:\WINDOWS\system32\drivers\AsInsHelp32.sys [X]
S2 Aspi32; System32\drivers\aspi32.sys [X]
S3 catchme; \??\C:\DOCUME~1\Ron\LOCALS~1\Temp\catchme.sys [X]
S3 cpuz135; \??\C:\DOCUME~1\Ron\LOCALS~1\Temp\cpuz135\cpuz135_x32.sys [X]
S3 EtronXHCI; System32\Drivers\EtronXHCI.sys [X]
S3 gdrv; \??\C:\WINDOWS\gdrv.sys [X]
S4 IntelIde; No ImagePath
S1 SBRE; \??\C:\WINDOWS\system32\drivers\SBREdrv.sys [X]
S3 SenFiltService; system32\drivers\Senfilt.sys [X]
U1 WS2IFSL; No ImagePath
C:\Documents and Settings\Ron\Local Settings\HELP_DECRYPT.HTML
C:\Documents and Settings\Ron\Local Settings\Application Data\HELP_DECRYPT.HTML
C:\Documents and Settings\Ron\Local Settings\HELP_DECRYPT.TXT
C:\Documents and Settings\Ron\Local Settings\Application Data\HELP_DECRYPT.TXT
C:\Documents and Settings\Ron\Local Settings\HELP_DECRYPT.URL
C:\Documents and Settings\Ron\Local Settings\Application Data\HELP_DECRYPT.URL
C:\Documents and Settings\Ron\Application Data\HELP_DECRYPT.HTML
C:\Documents and Settings\Ron\Application Data\HELP_DECRYPT.TXT
C:\Documents and Settings\Ron\Application Data\HELP_DECRYPT.URL
C:\Documents and Settings\NetworkService\Local Settings\HELP_DECRYPT.HTML
C:\Documents and Settings\NetworkService\Local Settings\Application Data\HELP_DECRYPT.HTML
C:\Documents and Settings\NetworkService\HELP_DECRYPT.HTML
C:\Documents and Settings\LocalService\Local Settings\HELP_DECRYPT.HTML
C:\Documents and Settings\LocalService\Local Settings\Application Data\HELP_DECRYPT.HTML
C:\Documents and Settings\LocalService\HELP_DECRYPT.HTML
C:\Documents and Settings\LocalService\Application Data\HELP_DECRYPT.HTML
C:\Documents and Settings\Default User\Local Settings\HELP_DECRYPT.HTML
C:\Documents and Settings\Default User\Local Settings\Application Data\HELP_DECRYPT.HTML
C:\Documents and Settings\Default User\HELP_DECRYPT.HTML
C:\Documents and Settings\Default User\Application Data\HELP_DECRYPT.HTML
C:\Documents and Settings\All Users\HELP_DECRYPT.HTML
C:\Documents and Settings\NetworkService\Local Settings\HELP_DECRYPT.TXT
C:\Documents and Settings\NetworkService\Local Settings\Application Data\HELP_DECRYPT.TXT
C:\Documents and Settings\NetworkService\HELP_DECRYPT.TXT
C:\Documents and Settings\LocalService\Local Settings\HELP_DECRYPT.TXT
C:\Documents and Settings\LocalService\Local Settings\Application Data\HELP_DECRYPT.TXT
C:\Documents and Settings\LocalService\HELP_DECRYPT.TXT
C:\Documents and Settings\LocalService\Application Data\HELP_DECRYPT.TXT
C:\Documents and Settings\Default User\Local Settings\HELP_DECRYPT.TXT
C:\Documents and Settings\Default User\Local Settings\Application Data\HELP_DECRYPT.TXT
C:\Documents and Settings\Default User\HELP_DECRYPT.TXT
C:\Documents and Settings\Default User\Application Data\HELP_DECRYPT.TXT
C:\Documents and Settings\All Users\HELP_DECRYPT.TXT
C:\Documents and Settings\NetworkService\Local Settings\HELP_DECRYPT.URL
C:\Documents and Settings\NetworkService\Local Settings\Application Data\HELP_DECRYPT.URL
C:\Documents and Settings\NetworkService\HELP_DECRYPT.URL
C:\Documents and Settings\LocalService\Local Settings\HELP_DECRYPT.URL
C:\Documents and Settings\LocalService\Local Settings\Application Data\HELP_DECRYPT.URL
C:\Documents and Settings\LocalService\HELP_DECRYPT.URL
C:\Documents and Settings\LocalService\Application Data\HELP_DECRYPT.URL
C:\Documents and Settings\Default User\Local Settings\HELP_DECRYPT.URL
C:\Documents and Settings\Default User\Local Settings\Application Data\HELP_DECRYPT.URL
C:\Documents and Settings\Default User\HELP_DECRYPT.URL
C:\Documents and Settings\Default User\Application Data\HELP_DECRYPT.URL
C:\Documents and Settings\All Users\HELP_DECRYPT.URL
C:\Documents and Settings\All Users\Application Data\HELP_DECRYPT.HTML
C:\Documents and Settings\Administrator\Local Settings\HELP_DECRYPT.HTML
C:\Documents and Settings\Administrator\Local Settings\Application Data\HELP_DECRYPT.HTML
C:\Documents and Settings\Administrator\HELP_DECRYPT.HTML
C:\Documents and Settings\Administrator\Application Data\HELP_DECRYPT.HTML
C:\Documents and Settings\All Users\Application Data\HELP_DECRYPT.TXT
C:\Documents and Settings\Administrator\Local Settings\HELP_DECRYPT.TXT
C:\Documents and Settings\Administrator\Local Settings\Application Data\HELP_DECRYPT.TXT
C:\Documents and Settings\Administrator\HELP_DECRYPT.TXT
C:\Documents and Settings\Administrator\Application Data\HELP_DECRYPT.TXT
C:\Documents and Settings\All Users\Application Data\HELP_DECRYPT.URL
C:\Documents and Settings\Administrator\Local Settings\HELP_DECRYPT.URL
C:\Documents and Settings\Administrator\Local Settings\Application Data\HELP_DECRYPT.URL
C:\Documents and Settings\Administrator\HELP_DECRYPT.URL
C:\Documents and Settings\Administrator\Application Data\HELP_DECRYPT.URL
C:\4bab80d9
AlternateDataStreams: C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
C:\Program Files\Browsersafeguard
 
End
*****************
 
Processes closed successfully.
C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe => No running process found
C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe => No running process found
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\KernelFaultCheck => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\BrowserSafeguard => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ApnTBMon => Value not found.
"HKU\S-1-5-21-1645522239-1708537768-725345543-1004\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
HKU\S-1-5-21-1645522239-1708537768-725345543-1004\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
Error setting Default URLSearchHook.
HKU\S-1-5-21-1645522239-1708537768-725345543-1004\Software\Microsoft\Internet Explorer\URLSearchHooks\\{D8278076-BC68-4484-9233-6E7F1628B56C} => value deleted successfully.
HKU\S-1-5-21-1645522239-1708537768-725345543-1004\Software\Microsoft\Internet Explorer\URLSearchHooks\\{6c97a91e-4524-4019-86af-2aa2d567bf5c} => value deleted successfully.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}" => Key deleted successfully.
HKCR\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21} => Key not found. 
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{b0441a0e-a49a-4e16-afc1-74ecced1921f}" => Key deleted successfully.
HKCR\CLSID\{b0441a0e-a49a-4e16-afc1-74ecced1921f} => Key not found. 
"HKU\S-1-5-21-1645522239-1708537768-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CB19A329-38E4-4C51-AF88-92A348A31A03}" => Key deleted successfully.
HKCR\CLSID\{CB19A329-38E4-4C51-AF88-92A348A31A03} => Key not found. 
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}" => Key deleted successfully.
HKCR\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670} => Key not found. 
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}" => Key deleted successfully.
"HKCR\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}" => Key deleted successfully.
HKCR\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} => Key not found. 
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} => value deleted successfully.
HKCR\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} => Key not found. 
HKU\S-1-5-21-1645522239-1708537768-725345543-1004\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} => value deleted successfully.
HKCR\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} => Key not found. 
HKU\S-1-5-21-1645522239-1708537768-725345543-1004\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} => value deleted successfully.
"HKCR\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}" => Key deleted successfully.
"HKCR\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}" => Key deleted successfully.
"HKCR\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}" => Key deleted successfully.
"HKCR\PROTOCOLS\Handler\intu-qt2007" => Key deleted successfully.
"HKCR\CLSID\{026BF40D-BA05-467b-9F1F-AD0D7A3F5F11}" => Key deleted successfully.
"HKCR\PROTOCOLS\Handler\intu-qt2008" => Key deleted successfully.
"HKCR\CLSID\{05E53CE9-66C8-4a9e-A99F-FDB7A8E7B596}" => Key deleted successfully.
"HKCR\PROTOCOLS\Handler\linkscanner" => Key deleted successfully.
"HKCR\CLSID\{F274614C-63F8-47D5-A4D1-FBDDE494F8D1}" => Key deleted successfully.
Firefox SearchEngineOrder.1 deleted successfully.
"HKU\S-1-5-21-1645522239-1708537768-725345543-1004\Software\MozillaPlugins\@adobe.com/FlashPlayer" => Key deleted successfully.
C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll not found.
C:\Documents and Settings\Ron\Application Data\Mozilla\Firefox\Profiles\odiqqo40.default\searchplugins\SearchResults.xml => Moved successfully.
C:\Program Files\mozilla firefox\browser\searchplugins\avg-secure-search.xml => Moved successfully.
APNMCP => Service not found.
AppleChargerSrv => Service deleted successfully.
ADExchange => Service deleted successfully.
ADIHdAudAddService => Service deleted successfully.
AEAudioService => Service deleted successfully.
ALSysIO => Service deleted successfully.
ASInsHelp => Service deleted successfully.
Aspi32 => Service deleted successfully.
catchme => Service deleted successfully.
cpuz135 => Service deleted successfully.
EtronXHCI => Service deleted successfully.
gdrv => Service deleted successfully.
IntelIde => Service deleted successfully.
SBRE => Service deleted successfully.
SenFiltService => Service deleted successfully.
WS2IFSL => Service deleted successfully.
C:\Documents and Settings\Ron\Local Settings\HELP_DECRYPT.HTML => Moved successfully.
C:\Documents and Settings\Ron\Local Settings\Application Data\HELP_DECRYPT.HTML => Moved successfully.
C:\Documents and Settings\Ron\Local Settings\HELP_DECRYPT.TXT => Moved successfully.
C:\Documents and Settings\Ron\Local Settings\Application Data\HELP_DECRYPT.TXT => Moved successfully.
C:\Documents and Settings\Ron\Local Settings\HELP_DECRYPT.URL => Moved successfully.
C:\Documents and Settings\Ron\Local Settings\Application Data\HELP_DECRYPT.URL => Moved successfully.
C:\Documents and Settings\Ron\Application Data\HELP_DECRYPT.HTML => Moved successfully.
C:\Documents and Settings\Ron\Application Data\HELP_DECRYPT.TXT => Moved successfully.
C:\Documents and Settings\Ron\Application Data\HELP_DECRYPT.URL => Moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\HELP_DECRYPT.HTML => Moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\HELP_DECRYPT.HTML => Moved successfully.
C:\Documents and Settings\NetworkService\HELP_DECRYPT.HTML => Moved successfully.
C:\Documents and Settings\LocalService\Local Settings\HELP_DECRYPT.HTML => Moved successfully.
C:\Documents and Settings\LocalService\Local Settings\Application Data\HELP_DECRYPT.HTML => Moved successfully.
C:\Documents and Settings\LocalService\HELP_DECRYPT.HTML => Moved successfully.
C:\Documents and Settings\LocalService\Application Data\HELP_DECRYPT.HTML => Moved successfully.
C:\Documents and Settings\Default User\Local Settings\HELP_DECRYPT.HTML => Moved successfully.
C:\Documents and Settings\Default User\Local Settings\Application Data\HELP_DECRYPT.HTML => Moved successfully.
C:\Documents and Settings\Default User\HELP_DECRYPT.HTML => Moved successfully.
C:\Documents and Settings\Default User\Application Data\HELP_DECRYPT.HTML => Moved successfully.
C:\Documents and Settings\All Users\HELP_DECRYPT.HTML => Moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\HELP_DECRYPT.TXT => Moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\HELP_DECRYPT.TXT => Moved successfully.
C:\Documents and Settings\NetworkService\HELP_DECRYPT.TXT => Moved successfully.
C:\Documents and Settings\LocalService\Local Settings\HELP_DECRYPT.TXT => Moved successfully.
C:\Documents and Settings\LocalService\Local Settings\Application Data\HELP_DECRYPT.TXT => Moved successfully.
C:\Documents and Settings\LocalService\HELP_DECRYPT.TXT => Moved successfully.
C:\Documents and Settings\LocalService\Application Data\HELP_DECRYPT.TXT => Moved successfully.
C:\Documents and Settings\Default User\Local Settings\HELP_DECRYPT.TXT => Moved successfully.
C:\Documents and Settings\Default User\Local Settings\Application Data\HELP_DECRYPT.TXT => Moved successfully.
C:\Documents and Settings\Default User\HELP_DECRYPT.TXT => Moved successfully.
C:\Documents and Settings\Default User\Application Data\HELP_DECRYPT.TXT => Moved successfully.
C:\Documents and Settings\All Users\HELP_DECRYPT.TXT => Moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\HELP_DECRYPT.URL => Moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\HELP_DECRYPT.URL => Moved successfully.
C:\Documents and Settings\NetworkService\HELP_DECRYPT.URL => Moved successfully.
C:\Documents and Settings\LocalService\Local Settings\HELP_DECRYPT.URL => Moved successfully.
C:\Documents and Settings\LocalService\Local Settings\Application Data\HELP_DECRYPT.URL => Moved successfully.
C:\Documents and Settings\LocalService\HELP_DECRYPT.URL => Moved successfully.
C:\Documents and Settings\LocalService\Application Data\HELP_DECRYPT.URL => Moved successfully.
C:\Documents and Settings\Default User\Local Settings\HELP_DECRYPT.URL => Moved successfully.
C:\Documents and Settings\Default User\Local Settings\Application Data\HELP_DECRYPT.URL => Moved successfully.
C:\Documents and Settings\Default User\HELP_DECRYPT.URL => Moved successfully.
C:\Documents and Settings\Default User\Application Data\HELP_DECRYPT.URL => Moved successfully.
C:\Documents and Settings\All Users\HELP_DECRYPT.URL => Moved successfully.
C:\Documents and Settings\All Users\Application Data\HELP_DECRYPT.HTML => Moved successfully.
C:\Documents and Settings\Administrator\Local Settings\HELP_DECRYPT.HTML => Moved successfully.
C:\Documents and Settings\Administrator\Local Settings\Application Data\HELP_DECRYPT.HTML => Moved successfully.
C:\Documents and Settings\Administrator\HELP_DECRYPT.HTML => Moved successfully.
C:\Documents and Settings\Administrator\Application Data\HELP_DECRYPT.HTML => Moved successfully.
C:\Documents and Settings\All Users\Application Data\HELP_DECRYPT.TXT => Moved successfully.
C:\Documents and Settings\Administrator\Local Settings\HELP_DECRYPT.TXT => Moved successfully.
C:\Documents and Settings\Administrator\Local Settings\Application Data\HELP_DECRYPT.TXT => Moved successfully.
C:\Documents and Settings\Administrator\HELP_DECRYPT.TXT => Moved successfully.
C:\Documents and Settings\Administrator\Application Data\HELP_DECRYPT.TXT => Moved successfully.
C:\Documents and Settings\All Users\Application Data\HELP_DECRYPT.URL => Moved successfully.
C:\Documents and Settings\Administrator\Local Settings\HELP_DECRYPT.URL => Moved successfully.
C:\Documents and Settings\Administrator\Local Settings\Application Data\HELP_DECRYPT.URL => Moved successfully.
C:\Documents and Settings\Administrator\HELP_DECRYPT.URL => Moved successfully.
C:\Documents and Settings\Administrator\Application Data\HELP_DECRYPT.URL => Moved successfully.
C:\4bab80d9 => Moved successfully.
C:\Documents and Settings\All Users\Application Data\TEMP => ":0B4227B4" ADS removed successfully.
"C:\Program Files\Browsersafeguard" => File/Directory not found.
EmptyTemp: => Removed 20.7 GB temporary data.
 
 
The system needed a reboot. 
 
==== End of Fixlog 20:48:18 ====
 
 
# AdwCleaner v4.201 - Logfile created 15/04/2015 at 21:01:53
# Updated 08/04/2015 by Xplode
# Database : 2015-04-08.1 [Local]
# Operating system : Microsoft Windows XP Service Pack 3 (x86)
# Username : Ron - ALPHA1
# Running from : C:\Documents and Settings\Ron\Desktop\adwcleaner_4.201.exe
# Option : Cleaning
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
Folder Deleted : C:\Documents and Settings\All Users\Application Data\apn
Folder Deleted : C:\Program Files\Conduit
Folder Deleted : C:\Program Files\iMesh Applications
Folder Deleted : C:\Program Files\MyPC Backup
Folder Deleted : C:\Documents and Settings\Ron\Local Settings\Application Data\Conduit
Folder Deleted : C:\Documents and Settings\Ron\Local Settings\Application Data\iMesh
Folder Deleted : C:\Documents and Settings\Ron\Local Settings\Application Data\PackageAware
Folder Deleted : C:\Documents and Settings\Ron\Application Data\blekko
Folder Deleted : C:\Documents and Settings\Ron\Application Data\imeshbandmltbpi
Folder Deleted : C:\Documents and Settings\Ron\Application Data\mediabarim
File Deleted : C:\END
 
***** [ Scheduled tasks ] *****
 
 
***** [ Shortcuts ] *****
 
Shortcut Disinfected : C:\Documents and Settings\All Users\Start Menu\Programs\Video Converter Bundle\Video Converter Bundle.lnk
 
***** [ Registry ] *****
 
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\MyPC Backup
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Key Deleted : HKLM\SOFTWARE\Classes\Applications\ilividsetup.exe
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\ask.com
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3289847
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{44CBC005-6243-4502-8A02-3A096A282664}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{F297534D-7B06-459D-BC19-2DD8EF69297B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{44CBC005-6243-4502-8A02-3A096A282664}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{950F80EF-32C2-47DD-9C35-9576E21EE66E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A057A204-BACC-4D26-9990-79A187E2698F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F297534D-7B06-459D-BC19-2DD8EF69297B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A057A204-BACC-4D26-9990-79A187E26990}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{474597C5-AB09-49D6-A4D5-2E8D7341384E}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8F0B76E1-4E46-427B-B55B-B90593468AC6}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{474597C5-AB09-49D6-A4D5-2E8D7341384E}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F0B76E1-4E46-427B-B55B-B90593468AC6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\BI
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\ilivid
Key Deleted : HKCU\Software\IM
Key Deleted : HKCU\Software\mediabarim
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKLM\SOFTWARE\BrowserSafeGuard
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\PIP
Key Deleted : HKLM\SOFTWARE\Video Converter
Key Deleted : HKU\.DEFAULT\Software\AskPartnerNetwork
Key Deleted : HKU\.DEFAULT\Software\AVG Security Toolbar
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MyPC Backup
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Optimizer Pro_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Video Converter
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\VOPackage
 
***** [ Web browsers ] *****
 
-\\ Internet Explorer v8.0.6001.18702
 
 
-\\ Mozilla Firefox v36.0.4 (x86 en-US)
 
[odiqqo40.default\prefs.js] - Line Deleted : user_pref("CT3289847.smartbar.homepage", "true");
[odiqqo40.default\prefs.js] - Line Deleted : user_pref("Smartbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT3289847&octid=CT3289847&SearchSource=61&CUI=UN56145756118442825&UM=2&UP=SPA569AAA5-AB25-4781-9BE4-42C886737FB8");
[odiqqo40.default\prefs.js] - Line Deleted : user_pref("Smartbar.SearchFromAddressBarSavedUrl", "hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=");
[odiqqo40.default\prefs.js] - Line Deleted : user_pref("avg.toolbar.buttons_icon", ",,chrome://avg/skin/safesurf.png,chrome://avg/skin/safesurf.png,chrome://avg/skin/safesearch.png,chrome://avg/skin/avglinks.png,chrome://avg/skin/avglinks.png,")[...]
[odiqqo40.default\prefs.js] - Line Deleted : user_pref("browser.search.defaultengine", "Ask.com");
[odiqqo40.default\prefs.js] - Line Deleted : user_pref("browser.search.defaultthis.engineName", "WhiteSmoke New Customized Web Search");
[odiqqo40.default\prefs.js] - Line Deleted : user_pref("smartbar.conduitHomepageList", "hxxp://search.conduit.com/?ctid=CT3289847&CUI=UN56145756118442825&UM=2&SearchSource=13,hxxp://search.conduit.com/?ctid=CT3289847&octid=CT3289847&SearchSource[...]
[odiqqo40.default\prefs.js] - Line Deleted : user_pref("smartbar.conduitSearchAddressUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289847&SearchSource=2&CUI=UN56145756118442825&UM=2&q=");
[odiqqo40.default\prefs.js] - Line Deleted : user_pref("smartbar.originalHomepage", "yahoo.ca");
[odiqqo40.default\prefs.js] - Line Deleted : user_pref("smartbar.originalSearchAddressUrl", "hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=");
[odiqqo40.default\prefs.js] - Line Deleted : user_pref("smartbar.originalSearchEngine", "AVG Secure Search");
 
-\\ Google Chrome v41.0.2272.118
 
[C:\Documents and Settings\Ron\Local Settings\Application Data\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
[C:\Documents and Settings\Ron\Local Settings\Application Data\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
[C:\Documents and Settings\Ron\Local Settings\Application Data\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3319733&octid=EB_ORIGINAL_CTID&ISID=M74DE5FFC-882C-47E6-9C12-8B96D3BE7527&SearchSource=58&CUI=&UM=5&UP=SP82DD7FDD-969B-4AA6-A5AD-20E0119E4AC7&q={searchTerms}&SSPV=
[C:\Documents and Settings\Ron\Local Settings\Application Data\Google\Chrome\User Data\Default\Secure Preferences] - Deleted [Extension] : booedmolknjekdopkepjjeckmjkdpfgl
[C:\Documents and Settings\Ron\Local Settings\Application Data\Google\Chrome\User Data\Default\Secure Preferences] - Deleted [Extension] : flpcjncodpafbgdpnkljologafpionhb
[C:\Documents and Settings\Ron\Local Settings\Application Data\Google\Chrome\User Data\Default\Secure Preferences] - Deleted [Extension] : nglnnifljabmkcecofpnlokcgnmbecia
 
*************************
 
AdwCleaner[R0].txt - [9280 bytes] - [15/04/2015 20:55:24]
AdwCleaner[S0].txt - [9477 bytes] - [15/04/2015 21:01:53]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [9536  bytes] ##########
 
 


#4 nasdaq

nasdaq

  • Malware Response Team
  • 38,770 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:02:37 AM

Posted 16 April 2015 - 07:22 AM


There could be some remnant items.
Run this online scan.
It may take some time. Do it when you know you will not need the computer for a few hours.

Please downloadesetlogo.pngOnline Scanner and save it to your Desktop.
  • Disable the realtime-protection of your antivirus and anti-malware programs because they might interfere with the scan.
  • Start installer.pngwith administartor privileges.
  • Select the option Yes, I accept the Terms of Use and click on Start.
  • Choose the following settings:
settings.png
  • Click on Start. The virus signature database will begin to download. This may take some time.
  • When completed the Online Scan will begin automatically.
    Note: This scan might take a long time! Please be patient.
  • When completed select Uninstall application on close if you so wish, but make sure you copy the logfile first!
  • Now click on Finish
  • A log filelog.pngis created at logpath.png
    Copy and paste the content of this log file in your next reply.
Note: Do not forget to re-enable your antivirus application after running the above scan!
eset.gif

lesestoff.png

If all is well after this scan the your computer is as clean as we can get it.

#5 quatermass

quatermass
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:02:37 AM

Posted 16 April 2015 - 07:30 PM

Hi, nasdaq.

 

The ESET log is below. There were 2408 threats, but I did not quarantine anything. The log was too long to include in the post, so the first half is below and the second half is attached as a text file.

 

Thanks.

 

quatermass

 

 

 

ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=261608b2da70454b9b3e3b65596b5ed4
# engine=23417
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2015-04-16 11:39:21
# local_time=2015-04-16 07:39:21 (-0500, Eastern Daylight Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode_1=''
# compatibility_mode=5889 16768445 100 100 262934387 273800229 0 373161
# scanned=444220
# found=2408
# cleaned=0
# scan_time=18515
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\AdwCleaner\Quarantine\C\Documents and Settings\Ron\Application Data\mediabarim\HELP_DECRYPT.HTML.vir"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\AdwCleaner\Quarantine\C\Documents and Settings\Ron\Application Data\mediabarim\HELP_DECRYPT.TXT.vir"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\AdwCleaner\Quarantine\C\Documents and Settings\Ron\Local Settings\Application Data\Conduit\HELP_DECRYPT.HTML.vir"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\AdwCleaner\Quarantine\C\Documents and Settings\Ron\Local Settings\Application Data\Conduit\HELP_DECRYPT.TXT.vir"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\AdwCleaner\Quarantine\C\Documents and Settings\Ron\Local Settings\Application Data\Conduit\Community Alerts\HELP_DECRYPT.HTML.vir"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\AdwCleaner\Quarantine\C\Documents and Settings\Ron\Local Settings\Application Data\Conduit\Community Alerts\HELP_DECRYPT.TXT.vir"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\AdwCleaner\Quarantine\C\Documents and Settings\Ron\Local Settings\Application Data\Conduit\Community Alerts\Dialogs\HELP_DECRYPT.HTML.vir"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\AdwCleaner\Quarantine\C\Documents and Settings\Ron\Local Settings\Application Data\Conduit\Community Alerts\Dialogs\HELP_DECRYPT.TXT.vir"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\AdwCleaner\Quarantine\C\Documents and Settings\Ron\Local Settings\Application Data\iMesh\HELP_DECRYPT.HTML.vir"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\AdwCleaner\Quarantine\C\Documents and Settings\Ron\Local Settings\Application Data\iMesh\HELP_DECRYPT.TXT.vir"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\AdwCleaner\Quarantine\C\Documents and Settings\Ron\Local Settings\Application Data\iMesh\Data\HELP_DECRYPT.HTML.vir"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\AdwCleaner\Quarantine\C\Documents and Settings\Ron\Local Settings\Application Data\iMesh\Data\HELP_DECRYPT.TXT.vir"
sh=97BCCD25561F44E9B13F05F6EEF083C9CE9BA529 ft=1 fh=641f1fb3d2e699c4 vn="Win32/Toolbar.Conduit.Y potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\Conduit\Community Alerts\Alert.dll.vir"
sh=CF1B9A59077DFE7C896CC8A98A1A1FE8957763B9 ft=1 fh=8594cd2c843c1bb9 vn="a variant of Win32/MyPCBackup.D potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MyPC Backup\DEL_MPCBClient.dll.vir"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\dj920\win2k_xp\enu\nt4\Disk1\nt4\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\dj920\win2k_xp\enu\nt4\Disk1\nt4\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Administrator\Application Data\Microsoft\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Administrator\Application Data\Microsoft\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows Media\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows Media\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows Media\9.0\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows Media\9.0\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Administrator\Templates\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Administrator\Templates\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Application Data\14A4\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Application Data\14A4\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Application Data\avg9\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Application Data\avg9\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Application Data\avg9\scanlogs\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Application Data\avg9\scanlogs\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Application Data\Canon_Inc_IC\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Application Data\Canon_Inc_IC\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Application Data\Canon_Inc_IC\UniversalInstaller\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Application Data\Canon_Inc_IC\UniversalInstaller\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Application Data\Canon_Inc_IC\UniversalInstaller\ServiceLog\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Application Data\Canon_Inc_IC\UniversalInstaller\ServiceLog\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Application Data\Freemake\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Application Data\Freemake\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Application Data\Freemake\FreemakeAudioConverter\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Application Data\Freemake\FreemakeAudioConverter\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Application Data\GFI Software\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Application Data\GFI Software\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Application Data\GFI Software\AntiMalware\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Application Data\GFI Software\AntiMalware\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Application Data\GFI Software\AntiMalware\Logs\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Application Data\GFI Software\AntiMalware\Logs\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Application Data\MFAData\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Application Data\MFAData\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Application Data\MFAData\SelfUpd\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Application Data\MFAData\SelfUpd\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Application Data\Microsoft\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Application Data\Microsoft\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Application Data\Microsoft\FSXDemo\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Application Data\Microsoft\FSXDemo\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Application Data\Microsoft\FSXDemo\Facilities\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Application Data\Microsoft\FSXDemo\Facilities\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\Ariel Junk\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\Ariel Junk\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\Ariel Junk\My Documents\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\Ariel Junk\My Documents\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\Ariel Junk\My Documents\My Music\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\Ariel Junk\My Documents\My Music\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\Ariel Junk\My Documents\My Music\Ariel's music\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\Ariel Junk\My Documents\My Music\Ariel's music\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\Ariel Junk\My Documents\My Videos\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\Ariel Junk\My Documents\My Videos\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\Ariel Junk\roms\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\Ariel Junk\roms\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\Cameos\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\Cameos\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\chap06\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\chap06\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\Fandub1\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\Fandub1\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\LCDs\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\LCDs\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\miranda stuff\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\miranda stuff\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\My Music\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\My Music\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\My Videos\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\My Videos\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\New Folder\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\New Folder\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\New Folder\ePSXe\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\New Folder\ePSXe\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\New Folder\ePSXe\docs\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\New Folder\ePSXe\docs\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\New Folder\ePSXe\plugins\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\New Folder\ePSXe\plugins\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\Orange Range - Ist Contact\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\Orange Range - Ist Contact\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\Orange Range - MusiQ\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\Orange Range - MusiQ\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\Photoshop 7\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\Photoshop 7\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\Rat pictures\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\Rat pictures\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\Rat pictures\Rat Shots\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\Rat pictures\Rat Shots\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\Screens from Nar\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\Screens from Nar\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\Transfer\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\Transfer\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\Transfer\AiM\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\Transfer\AiM\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\Transfer\Backup\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\Transfer\Backup\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\Transfer\Digimon Tamers Uta to Ongaku Shuu Ver. 2\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\Transfer\Digimon Tamers Uta to Ongaku Shuu Ver. 2\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\Transfer\Exile2\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\Transfer\Exile2\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\zoopics\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel Stuff\zoopics\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\CD Hourly\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\CD Hourly\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\CD K.K\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\CD K.K\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\CD K.K\K.K. Songs (disc 1)\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\CD K.K\K.K. Songs (disc 1)\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\CD lyrics\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\CD lyrics\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\FMA Anime\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\FMA Anime\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\Higurashi no Naku Koro ni\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\Higurashi no Naku Koro ni\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\Higurashi no Naku Koro ni\[Nipponsei] Higurashi no Naku Koro ni OP Single - Higurashi no Naku Koro ni [Shimamiya Eiko] (320 kbps)\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\Higurashi no Naku Koro ni\[Nipponsei] Higurashi no Naku Koro ni OP Single - Higurashi no Naku Koro ni [Shimamiya Eiko] (320 kbps)\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\Higurashi no Naku Koro ni\[Nipponsei] Higurashi no Naku Koro ni OP Single - Higurashi no Naku Koro ni [Shimamiya Eiko] (320 kbps)\Scans\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\Higurashi no Naku Koro ni\[Nipponsei] Higurashi no Naku Koro ni OP Single - Higurashi no Naku Koro ni [Shimamiya Eiko] (320 kbps)\Scans\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\Janne Da Arc - Another Story\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\Janne Da Arc - Another Story\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\Mushishi OST\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\Mushishi OST\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\New Daigasso songs\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\New Daigasso songs\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\Nobodyknows\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\Nobodyknows\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\Nobodyknows\nobodyknows+ - Do You Know?\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\Nobodyknows\nobodyknows+ - Do You Know?\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\Orange Range - 1st Contact\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\Orange Range - 1st Contact\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\Orange Range - Asterisk\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\Orange Range - Asterisk\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\Orange Range - Kirikirimai\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\Orange Range - Kirikirimai\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\Orange Range - MusiQ\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\Orange Range - MusiQ\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\Orange Range - Orange Ball\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\Orange Range - Orange Ball\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\Orange Range - Squeezed\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\Orange Range - Squeezed\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\Orange Range - Squeezed\ORANGE RANGE RIMIX ALBUM?Squeezed?\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\Orange Range - Squeezed\ORANGE RANGE RIMIX ALBUM?Squeezed?\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\Orange Range - Squeezed\ORANGE RANGE RIMIX ALBUM?Squeezed?\JPEG+TXT\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\Orange Range - Squeezed\ORANGE RANGE RIMIX ALBUM?Squeezed?\JPEG+TXT\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\Orange Range - ?ATURAL\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\Orange Range - ?ATURAL\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\Orange Range other stuff\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\Orange Range other stuff\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\Porno Graffitti - Best Blue's\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\Porno Graffitti - Best Blue's\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\Porno Graffitti - Best Red's\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\Porno Graffitti - Best Red's\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\Porno Graffitti - THUMPx\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\media\Porno Graffitti - THUMPx\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\Zelda Music\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\Zelda Music\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\Zelda Music\not-so-good\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\Zelda Music\not-so-good\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\Zelda Music\NS playlist\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\Zelda Music\NS playlist\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\[TW] Naruto\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\Anime\[TW] Naruto\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\Busou Renkin\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\Busou Renkin\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\Mushishi\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\Mushishi\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\Mushishi\Mushishi_v01_c01[MS_L-H]\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\Mushishi\Mushishi_v01_c01[MS_L-H]\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\Mushishi\Mushishi_v01_c02[MS_L-H]\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\Mushishi\Mushishi_v01_c02[MS_L-H]\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\Mushishi\Mushishi_v01_c03[MS_L-H]\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\Mushishi\Mushishi_v01_c03[MS_L-H]\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\Mushishi\Mushishi_v01_c04[MS_L-H]\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\Mushishi\Mushishi_v01_c04[MS_L-H]\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\Mushishi\Mushishi_v01_c05[MS_L-H]\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\Mushishi\Mushishi_v01_c05[MS_L-H]\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\RK\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\RK\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\RK\Volume 25\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\RK\Volume 25\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\RK\Volume 25\Chapter218\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\RK\Volume 25\Chapter218\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\RK\Volume 25\Chapter219\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\RK\Volume 25\Chapter219\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\RK\Volume 25\Chapter220\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\RK\Volume 25\Chapter220\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\RK\Volume 25\Chapter221\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\RK\Volume 25\Chapter221\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\RK\Volume 25\Chapter222\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\RK\Volume 25\Chapter222\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\RK\Volume 25\Chapter223\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\RK\Volume 25\Chapter223\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\RK\Volume 25\Chapter224\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\RK\Volume 25\Chapter224\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\RK\Volume 25\Chapter225\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\RK\Volume 25\Chapter225\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\RK\Volume 25\Chapter226\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\RK\Volume 25\Chapter226\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\RK\Volume 25\Chapter227\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\RK\Volume 25\Chapter227\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\Shaman King\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\Shaman King\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\Shaman King\Shaman King vol 09\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\Shaman King\Shaman King vol 09\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\Shaman King\Shaman King vol 09\Chapter 72\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\Shaman King\Shaman King vol 09\Chapter 72\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\Shaman King\Shaman King vol 09\Chapter 73\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\Shaman King\Shaman King vol 09\Chapter 73\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\Shaman King\Shaman King vol 09\Chapter 74\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\Shaman King\Shaman King vol 09\Chapter 74\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\Shaman King\Shaman King vol 09\Chapter 75\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\Shaman King\Shaman King vol 09\Chapter 75\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\Shaman King\Shaman King vol 09\Chapter 76\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\Shaman King\Shaman King vol 09\Chapter 76\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\Shaman King\Shaman King vol 09\Chapter 77\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\Shaman King\Shaman King vol 09\Chapter 77\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\Shaman King\Shaman King vol 09\Chapter 78\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\download\Shaman King\Shaman King vol 09\Chapter 78\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\from shared\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\from shared\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\MS screenshots\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\MS screenshots\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\roms\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\roms\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\roms\Akumajou Dracula X Chi no Rondo (J)\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\roms\Akumajou Dracula X Chi no Rondo (J)\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\roms\Copy of Akumajou Dracula X Chi no Rondo (J)\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\roms\Copy of Akumajou Dracula X Chi no Rondo (J)\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\sent files\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ariel's salvaged stuff\sent files\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Black And White 2 [PCDVD][MULTi7][www.newpct.com]\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Black And White 2 [PCDVD][MULTi7][www.newpct.com]\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\booma\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\booma\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Italy pics\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Italy pics\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ken\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Ken\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\My Music\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\My Music\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\My Pictures\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\My Pictures\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\My Pictures\house\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\My Pictures\house\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\My Videos\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\My Videos\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\My Videos\[AF-F][C1] Mushishi\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\My Videos\[AF-F][C1] Mushishi\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\My Videos\[KAA]_Kino’s_Travels.1-13.DVD(complete)\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\My Videos\[KAA]_Kino’s_Travels.1-13.DVD(complete)\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\My Videos\[Lunar] Ouran High School Host Club\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\My Videos\[Lunar] Ouran High School Host Club\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Stuff\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Stuff\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Stuff\Diablo 2 + Expansion\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Stuff\Diablo 2 + Expansion\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\The Sims\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\The Sims\HELP_DECRYPT.TXT"
sh=8EF2158744E92F0AC16C54D16A155F056901D28A ft=0 fh=0000000000000000 vn="Win32/Keygen.FC potentially unsafe application" ac=I fn="C:\Documents and Settings\All Users\Documents\The Sims\Converted\The Sims 2 Glamour Life Stuff.iso"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\The Sims\The Sims 2 Complete\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\The Sims\The Sims 2 Complete\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\The Sims\The Sims 2 Complete\The Sims 2\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\The Sims\The Sims 2 Complete\The Sims 2\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\The Sims\The Sims 2 Complete\[Readme] Instructions\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\The Sims\The Sims 2 Complete\[Readme] Instructions\HELP_DECRYPT.TXT"
sh=11DC62236452C988043E916454E8D39FF3E708DD ft=1 fh=9e1eb2cda31f39f4 vn="a variant of Win32/HackTool.Patcher.AF potentially unsafe application" ac=I fn="C:\Documents and Settings\All Users\Documents\The Sims\The Sims 2 Complete\[Readme] Instructions\MagicISO v5.4\crack\Magic.ISO.Maker.v5.4.b251_patch.exe"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Installation Files\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Installation Files\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Installation Files\virtualdub\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Installation Files\virtualdub\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Installation Files\virtualdub\aviproxy\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Installation Files\virtualdub\aviproxy\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Installation Files\virtualdub\plugins\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Installation Files\virtualdub\plugins\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Digimon Frontier Uta to Ongaku Shuu Ver. 1\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Digimon Frontier Uta to Ongaku Shuu Ver. 1\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Digimon Music\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Digimon Music\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Digimon Music\1 Digimon Adventure\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Digimon Music\1 Digimon Adventure\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Digimon Music\2 Digimon Adventure 02\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Digimon Music\2 Digimon Adventure 02\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Digimon Music\3 Digimon Tamers\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Digimon Music\3 Digimon Tamers\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Digimon Music\4 Digimon Frontier\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Digimon Music\4 Digimon Frontier\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Digimon Music\Digimon Tamers Uta to Ongaku Shuu Ver. 2\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Digimon Music\Digimon Tamers Uta to Ongaku Shuu Ver. 2\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Digimon Music\karaokes\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Digimon Music\karaokes\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Digimon Music\lyrics\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Digimon Music\lyrics\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\FMA Anime\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\FMA Anime\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Incoming Music\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Incoming Music\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Incoming Music\Curse of Darkness OST\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Incoming Music\Curse of Darkness OST\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Incoming Music\Curse of Darkness OST\Akumajo Dracula Curse of Darkness Original Soundtrack\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Incoming Music\Curse of Darkness OST\Akumajo Dracula Curse of Darkness Original Soundtrack\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Incoming Music\Curse of Darkness OST\Akumajo Dracula Curse of Darkness Original Soundtrack\Disc 1\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Incoming Music\Curse of Darkness OST\Akumajo Dracula Curse of Darkness Original Soundtrack\Disc 1\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Incoming Music\Curse of Darkness OST\Akumajo Dracula Curse of Darkness Original Soundtrack\Disc 2\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Incoming Music\Curse of Darkness OST\Akumajo Dracula Curse of Darkness Original Soundtrack\Disc 2\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Incoming Music\CV\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Incoming Music\CV\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Incoming Music\CV\The Best 1986-2004\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Incoming Music\CV\The Best 1986-2004\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Incoming Music\Phoenix Wright\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Incoming Music\Phoenix Wright\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Other Music\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Other Music\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Other Music\Daigasso! music\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Other Music\Daigasso! music\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Other Music\Drama Tracks\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Other Music\Drama Tracks\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Other Music\Gundum Wing & Inuyasha Music\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Other Music\Gundum Wing & Inuyasha Music\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Other Music\katamari songs\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Other Music\katamari songs\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Other Music\Kobukuro Music\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Other Music\Kobukuro Music\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Other Music\Naruto Midi\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Other Music\Naruto Midi\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Other Music\natural selection\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Other Music\natural selection\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Other Music\Pillows Music\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Other Music\Pillows Music\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Other Music\Porno Graffitti Music\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Other Music\Porno Graffitti Music\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Other Music\Sen to Chihiro no Kamikakushi Music\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Other Music\Sen to Chihiro no Kamikakushi Music\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Other Music\Silent Hill 2\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Other Music\Silent Hill 2\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Other Music\Zelda Music\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\Other Music\Zelda Music\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\SotN\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Music\SotN\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\My Games\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\My Games\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\My Games\Oblivion\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\My Games\Oblivion\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\My Games\Oblivion\Saves\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\My Games\Oblivion\Saves\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\My Received Files\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\My Received Files\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\CAT\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\CAT\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\CAT\sfx\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\CAT\sfx\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\Digimon Encyclopedia\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\Digimon Encyclopedia\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\Digimon Next\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\Digimon Next\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\DVD\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\DVD\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\DVD\Volume 1\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\DVD\Volume 1\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\DVD\Volume 1\VIDEO_TS\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\DVD\Volume 1\VIDEO_TS\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\DVD\Volume 2\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\DVD\Volume 2\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\DVD\Volume 2\VIDEO_TS\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\DVD\Volume 2\VIDEO_TS\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\CVRL\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\CVRL\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\CVRL\res\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\CVRL\res\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\CVRL\wav\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\CVRL\wav\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\Digimon\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\Digimon\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\gens\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\gens\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\NESSIE\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\NESSIE\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\new\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\new\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\new\Gens\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\new\Gens\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\new\Gens\isos\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\new\Gens\isos\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\new\Gens\isos\Sonic CD (J)\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\new\Gens\isos\Sonic CD (J)\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\New Folder\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\New Folder\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\New Folder\ePSXe\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\New Folder\ePSXe\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\New Folder\ePSXe\docs\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\New Folder\ePSXe\docs\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\New Folder\ePSXe\kaillera\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\New Folder\ePSXe\kaillera\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\New Folder\ePSXe\plugins\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\New Folder\ePSXe\plugins\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\New Folder\PSX - Bloody Roar 2 (SLPS_01842)\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\New Folder\PSX - Bloody Roar 2 (SLPS_01842)\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\New Folder (2)\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\New Folder (2)\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\New Folder (2)\docs\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\New Folder (2)\docs\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\VBA\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\VBA\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\[ANIMAPU] Naruto-psx [NTSC_JAP]\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\I hate this magic 8 ball\[ANIMAPU] Naruto-psx [NTSC_JAP]\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\Inner Space\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\Inner Space\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\MST3K Season 1\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\MST3K Season 1\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\MST3K Season 2\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\MST3K Season 2\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\Nar videos\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\Nar videos\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\Schoolgunk\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\Schoolgunk\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\sounds\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\sounds\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\Video and Other\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\Video and Other\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\website\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\website\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\website\images\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\website\images\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\website\stuff\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Transfer Backup\Video and Other\website\stuff\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Website\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Website\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Website\aylmertheatre.ca\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Website\aylmertheatre.ca\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Website\aylmertheatre.ca\New Folder\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Website\aylmertheatre.ca\New Folder\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Website\Dearly Departed\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Website\Dearly Departed\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Website\Website\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Documents\Website\Website\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\DRM\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\DRM\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Templates\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\All Users\Templates\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Default User\Application Data\Microsoft\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Default User\Application Data\Microsoft\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Default User\Local Settings\Application Data\Google\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Default User\Local Settings\Application Data\Google\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Default User\Local Settings\Application Data\Google\Drive\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Default User\Local Settings\Application Data\Google\Drive\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Windows Media\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Windows Media\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Windows Media\9.0\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Windows Media\9.0\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Default User\Templates\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Default User\Templates\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\LocalService\Application Data\McAfee\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\LocalService\Application Data\McAfee\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\LocalService\Application Data\McAfee\sacore\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\LocalService\Application Data\McAfee\sacore\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\LocalService\Local Settings\Application Data\LogMeIn Hamachi\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\LocalService\Local Settings\Application Data\LogMeIn Hamachi\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows Media\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows Media\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows Media\10.0\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows Media\10.0\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows Media\11.0\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows Media\11.0\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Player NSS\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Player NSS\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Player NSS\3.0\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Player NSS\3.0\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Player NSS\3.0\Icon Files\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Player NSS\3.0\Icon Files\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\NetworkService\Local Settings\Application Data\PCHealth\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\NetworkService\Local Settings\Application Data\PCHealth\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\NetworkService\Local Settings\Application Data\PCHealth\ErrorRep\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\NetworkService\Local Settings\Application Data\PCHealth\ErrorRep\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\NetworkService\Local Settings\Application Data\PCHealth\ErrorRep\QSignoff\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\NetworkService\Local Settings\Application Data\PCHealth\ErrorRep\QSignoff\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\azureus\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\azureus\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\azureus\active\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\azureus\active\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\dbs\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\dbs\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\dbs\sharefiles.1\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\dbs\sharefiles.1\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\image_cache\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\image_cache\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\image_cache\farm2.static.flickr.com\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\image_cache\farm2.static.flickr.com\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\image_cache\farm2.static.flickr.com\1207\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\image_cache\farm2.static.flickr.com\1207\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\image_cache\farm2.static.flickr.com\1218\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\image_cache\farm2.static.flickr.com\1218\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\image_cache\farm5.static.flickr.com\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\image_cache\farm5.static.flickr.com\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\image_cache\farm5.static.flickr.com\4028\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\image_cache\farm5.static.flickr.com\4028\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\image_cache\farm5.static.flickr.com\4047\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\image_cache\farm5.static.flickr.com\4047\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\image_cache\farm5.static.flickr.com\4055\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\image_cache\farm5.static.flickr.com\4055\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\image_cache\farm5.static.flickr.com\4084\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\image_cache\farm5.static.flickr.com\4084\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\image_cache\farm5.static.flickr.com\4089\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\image_cache\farm5.static.flickr.com\4089\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\image_cache\farm5.static.flickr.com\4147\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\image_cache\farm5.static.flickr.com\4147\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\image_cache\farm6.static.flickr.com\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\image_cache\farm6.static.flickr.com\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\image_cache\farm6.static.flickr.com\5047\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\image_cache\farm6.static.flickr.com\5047\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\image_cache\farm6.static.flickr.com\5128\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\image_cache\farm6.static.flickr.com\5128\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\image_cache\static.frostwire.com\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\image_cache\static.frostwire.com\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\image_cache\static.frostwire.com\images\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\image_cache\static.frostwire.com\images\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\image_cache\static.frostwire.com\images\overlays\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\image_cache\static.frostwire.com\images\overlays\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\image_cache\static.frostwire.com\images\overlays\shop\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\image_cache\static.frostwire.com\images\overlays\shop\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\image_cache\static.frostwire.com\images\promos\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\image_cache\static.frostwire.com\images\promos\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\library_db\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\library_db\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\search_db\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\search_db\HELP_DECRYPT.TXT"
sh=D187CD6570E3F9E4E27DB52E518D8311B192EC4E ft=1 fh=1ab6308968c3ad5b vn="Win32/OpenCandy potentially unsafe application" ac=I fn="C:\Documents and Settings\Ron\.frostwire5\updates\frostwire-5.5.6.windows.exe"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\.minecraft\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\.minecraft\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Adobe\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Adobe\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Adobe\Acrobat\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Adobe\Acrobat\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Adobe\Acrobat\7.0\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Adobe\Acrobat\7.0\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Adobe\Acrobat\7.0\Messages\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Adobe\Acrobat\7.0\Messages\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Adobe\Acrobat\7.0\Messages\ENU\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Adobe\Acrobat\7.0\Messages\ENU\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Adobe\Acrobat\7.0\Updater\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Adobe\Acrobat\7.0\Updater\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Adobe\Flash Player\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Adobe\Flash Player\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Adobe\Flash Player\AssetCache\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Adobe\Flash Player\AssetCache\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Adobe\Flash Player\AssetCache\C64SPKQ5\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Adobe\Flash Player\AssetCache\C64SPKQ5\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Aim\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Aim\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Aim\DKFlamey\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Aim\DKFlamey\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Aim\tehgr8fuishkek\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Aim\tehgr8fuishkek\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\BitTorrent\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\BitTorrent\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\FrostWire\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\FrostWire\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\FrostWire\.AppSpecialShare\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\FrostWire\.AppSpecialShare\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\FrostWire\azureus\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\FrostWire\azureus\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\FrostWire\azureus\active\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\FrostWire\azureus\active\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\FrostWire\image_cache\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\FrostWire\image_cache\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\FrostWire\image_cache\static.frostwire.com\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\FrostWire\image_cache\static.frostwire.com\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\FrostWire\image_cache\static.frostwire.com\images\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\FrostWire\image_cache\static.frostwire.com\images\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\FrostWire\image_cache\static.frostwire.com\images\banners\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\FrostWire\image_cache\static.frostwire.com\images\banners\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\FrostWire\overlays\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\FrostWire\overlays\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\FrostWire\themes\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\FrostWire\themes\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\FrostWire\themes\classic_theme\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\FrostWire\themes\classic_theme\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Macromedia\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Macromedia\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Macromedia\Flash MX 2004\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Macromedia\Flash MX 2004\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Microsoft\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Microsoft\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Microsoft\FS9\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Microsoft\FS9\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Microsoft\FS9\Facilities\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Microsoft\FS9\Facilities\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Microsoft\Internet Explorer\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Microsoft\Internet Explorer\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Mozilla\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Mozilla\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Mozilla\Firefox\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Mozilla\Firefox\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Mozilla\Firefox\Profiles\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Mozilla\Firefox\Profiles\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Mozilla\Firefox\Profiles\odiqqo40.default\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Mozilla\Firefox\Profiles\odiqqo40.default\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Mozilla\Firefox\Profiles\odiqqo40.default\extensions\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Mozilla\Firefox\Profiles\odiqqo40.default\extensions\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Mozilla\Firefox\Profiles\odiqqo40.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Mozilla\Firefox\Profiles\odiqqo40.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Mozilla\Firefox\Profiles\odiqqo40.default\GoogleToolbarData\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Mozilla\Firefox\Profiles\odiqqo40.default\GoogleToolbarData\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Mozilla\Firefox\Profiles\odiqqo40.default\storage\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Mozilla\Firefox\Profiles\odiqqo40.default\storage\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Mozilla\Firefox\Profiles\odiqqo40.default\storage\default\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Mozilla\Firefox\Profiles\odiqqo40.default\storage\default\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Mozilla\Firefox\Profiles\odiqqo40.default\storage\default\http+++www.walmart.ca\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Mozilla\Firefox\Profiles\odiqqo40.default\storage\default\http+++www.walmart.ca\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Mozilla\Firefox\Profiles\odiqqo40.default\storage\default\http+++www.walmart.ca\idb\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Mozilla\Firefox\Profiles\odiqqo40.default\storage\default\http+++www.walmart.ca\idb\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Mozilla\Firefox\Profiles\odiqqo40.default\storage\permanent\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Mozilla\Firefox\Profiles\odiqqo40.default\storage\permanent\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Mozilla\Firefox\Profiles\odiqqo40.default\storage\permanent\chrome\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Mozilla\Firefox\Profiles\odiqqo40.default\storage\permanent\chrome\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Mozilla\Firefox\Profiles\odiqqo40.default\storage\permanent\chrome\idb\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Mozilla\Firefox\Profiles\odiqqo40.default\storage\permanent\chrome\idb\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\OpenOffice.org\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\OpenOffice.org\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\OpenOffice.org\3\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\OpenOffice.org\3\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\OpenOffice.org\3\user\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\OpenOffice.org\3\user\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\OpenOffice.org\3\user\backup\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\OpenOffice.org\3\user\backup\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\OpenOffice.org\3\user\database\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\OpenOffice.org\3\user\database\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\OpenOffice.org\3\user\database\biblio\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\OpenOffice.org\3\user\database\biblio\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\OpenOffice.org\3\user\gallery\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\OpenOffice.org\3\user\gallery\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\OpenOffice.org2\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\OpenOffice.org2\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\OpenOffice.org2\user\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\OpenOffice.org2\user\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\OpenOffice.org2\user\database\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\OpenOffice.org2\user\database\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\OpenOffice.org2\user\database\biblio\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\OpenOffice.org2\user\database\biblio\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\OpenOffice.org2\user\gallery\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\OpenOffice.org2\user\gallery\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Opera\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Opera\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Opera\Opera\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Opera\Opera\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Opera\Opera\profile\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Opera\Opera\profile\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Opera\Opera\profile\sessions\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Opera\Opera\profile\sessions\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Opera\Opera\profile\skin\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Opera\Opera\profile\skin\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Real\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Real\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Real\RealMediaSDK\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Real\RealMediaSDK\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Real\RealPlayer\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Real\RealPlayer\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Real\RealPlayer\db\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Real\RealPlayer\db\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Real\Update\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Real\Update\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\SecuROM\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\SecuROM\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\SecuROM\UserData\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\SecuROM\UserData\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Serif\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Serif\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Serif\PagePlus\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Serif\PagePlus\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Serif\PagePlus\13.0\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Serif\PagePlus\13.0\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Serif\PagePlus\13.0\Data\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Serif\PagePlus\13.0\Data\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Serif\PagePlus\14.0\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Serif\PagePlus\14.0\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Serif\PagePlus\14.0\Data\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Serif\PagePlus\14.0\Data\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Serif\PhotoPlus\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Serif\PhotoPlus\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Serif\PhotoPlus\13\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Serif\PhotoPlus\13\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Serif\PhotoPlus\13\Patterns\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Serif\PhotoPlus\13\Patterns\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\Deployment\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\Deployment\HELP_DECRYPT.TXT"
sh=8F4B98B668C8BD0D1582A29269E490164C16B86C ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.CVE-2010-0840.NAN trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\Deployment\cache\6.0\1\4caa9001-432d0a55"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\Deployment\SystemCache\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\Deployment\SystemCache\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\Deployment\SystemCache\6.0\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\Deployment\SystemCache\6.0\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\Deployment\SystemCache\6.0\11\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\Deployment\SystemCache\6.0\11\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\Deployment\SystemCache\6.0\23\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\Deployment\SystemCache\6.0\23\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\Deployment\SystemCache\6.0\24\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\Deployment\SystemCache\6.0\24\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\Deployment\SystemCache\6.0\25\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\Deployment\SystemCache\6.0\25\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\Deployment\SystemCache\6.0\26\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\Deployment\SystemCache\6.0\26\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\Deployment\SystemCache\6.0\29\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\Deployment\SystemCache\6.0\29\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\Deployment\SystemCache\6.0\3\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\Deployment\SystemCache\6.0\3\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\Deployment\SystemCache\6.0\32\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\Deployment\SystemCache\6.0\32\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\jre1.6.0_20\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\jre1.6.0_20\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\jre1.6.0_23\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\jre1.6.0_23\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\jre1.6.0_24\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Application Data\Sun\Java\jre1.6.0_24\HELP_DECRYPT.TXT"
sh=3F936E57E4AB6E69F8B168B79C410E3C3514897B ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Desktop\M7788v1.0\HELP_DECRYPT.HTML"
sh=7513EB7C4C1CE914EA6325656B45CC65123449E6 ft=0 fh=0000000000000000 vn="Win32/Filecoder.CR trojan" ac=I fn="C:\Documents and Settings\Ron\Desktop\M7788v1.0\HELP_DECRYPT.TXT"

Attached Files

  • Attached File  log1.txt   372.16KB   0 downloads


#6 nasdaq

nasdaq

  • Malware Response Team
  • 38,770 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:02:37 AM

Posted 17 April 2015 - 08:36 AM

Trust the scan and remove everything that has been identified.


Just to be on the safe side create a restore point before proceeding.

#7 quatermass

quatermass
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:02:37 AM

Posted 18 April 2015 - 09:12 PM

Hi, nasdaq.

 

Well, when I ran ESET the first time, it hung up at 98% with 2408 threats found. Next time it hung at 98% with 2408 threats. Next time it hung at 95% with 2385 threats. Finally it hung at 95% with 2360 threats. Each time I let the scan run several hours after the hang up. On one occasion, the scan stopped at 95% after 5 hours, but I waited another 17 hours before stopping it manually. Because the scan did not finish, I take it this would explain why there are so many threats still there to be found. Is there another program available to do what ESET can't?

 

Thanks.

 

quatermass



#8 nasdaq

nasdaq

  • Malware Response Team
  • 38,770 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:02:37 AM

Posted 19 April 2015 - 07:21 AM

Try this tool.

Download to your Desktop the Junkware Removal Tool Download from this link.
http://www.bleepingcomputer.com/download/junkware-removal-tool/

Shutdown your antivirus to avoid any conflicts.
Right click the icon - disable for say 20 mins.
Right-mouse click JRT.exe and select Run as administrator (If using XP just double click on the icon to run it.)
The tool will open and start scanning your system.
Please be patient as this can take a while to complete.
On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
Post the contents of JRT.txt into your next message.
======

#9 quatermass

quatermass
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:02:37 AM

Posted 19 April 2015 - 02:08 PM

Hi, nasdaq.

 

I shutdown my antivirus, but disabling for 20 minutes never came up. I downloaded jrt.exe to the desktop and double-clicked. It opened, extracted, gave me a DOS-like screen that said shut down your browser, which I did, and press any key to start. It produced some lines about the creating registry backup, checking startup, then said "file not found" and disappeared. What am I doing wrong?

 

Thanks.

 

quatermass



#10 nasdaq

nasdaq

  • Malware Response Team
  • 38,770 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:02:37 AM

Posted 20 April 2015 - 06:37 AM

Delete your current version.

Download the latest version and run it. Keep me posted.

#11 quatermass

quatermass
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:02:37 AM

Posted 20 April 2015 - 08:10 PM

Hi, nasdaq.

 

I double clicked on jrt.exe and it said I was running an old version and asked if I wanted to upgrade. I said yes and jrt_new.exe appeared. I opened that, it extracted and gave me the DOS screen. After pressing the any key, it created registry backup, checked startup and, without a "file not found" message, it disappeared. I searched for the website and found an updated version. It was 6.5.9 updated today as opposed to the 2.1.4 version of the program from Bleeping. I downloaded that and got the same result. What now?

 

Thanks.

 

quatermass



#12 nasdaq

nasdaq

  • Malware Response Team
  • 38,770 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:02:37 AM

Posted 21 April 2015 - 07:16 AM

The E-Set scan found many bad entrie HELP_DECRYPT it could very well be that JRT is not able to cope with that many entries.

Please run the E-set scan one more time and delete everything.
==

When done restart the computer normally.
Run the JRT tool and let me know how is goes.

#13 quatermass

quatermass
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:02:37 AM

Posted 01 May 2015 - 01:41 PM

Hi, nasdaq.

 

Sorry it has taken this long, but I think I'm now pristine. I believe that our problem was that anything we ran found all of those pesky HELP_DECRYPT files and identified them, overloading the janitorial programs. I decide to use Search in safe mode to find every instance of that phrase and then tried to delete them. Over 1400 it found, oy. It took forever to send them to the recycle bin. It takes a while for the system to transfer them, so it looks like nothing is happening. I deleted them in small batches (a pain in the patoot, I may say), but soon there were a manageable number that ESET could handle. I ran ESET and got 10 threats, one of which ESET quarantined. That left me with 9 threats to delete manually. Though time-consuming, I eventually sent them to recycle and then oblivion.

My last ESET full scan showed NO threats! Malwarebytes showed NO threats! Windows Defender showed NO threats! Am I back in the world of the uninfected? If so, please give me you blessing and I will never open an attached resume again.

 

Yours, next to Godliness,

 

quatermass



#14 nasdaq

nasdaq

  • Malware Response Team
  • 38,770 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:02:37 AM

Posted 02 May 2015 - 06:38 AM

Looking good.

If all is well.

To learn more about how to protect yourself while on the internet read this little guide best security practices keep safe.
http://www.bleepingcomputer.com/forums/t/407147/answers-to-common-security-questions-best-practices/
===

#15 nasdaq

nasdaq

  • Malware Response Team
  • 38,770 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:02:37 AM

Posted 08 May 2015 - 07:07 AM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users