Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Crypto Malware got me. I think I am clean, what now?


  • This topic is locked This topic is locked
7 replies to this topic

#1 frigitar

frigitar

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:09:28 AM

Posted 22 April 2015 - 08:33 AM

Hello helpful folk,

 

I think I have cleaned out my computer with various tools before I found you. Still have all my data that is encrypted and I have HTML and .txt and .bmp files everywhere tell me how to pay. I am not going to pay. i just want a fresh start, without my data but without reformatting or reinstalling my computer.

 

Thanks

 

Frig

 

 

 

FRST log

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 20-04-2015
Ran by Red 1 - Admin (administrator) on Red1-PC on 22-04-2015 12:16:04
Running from C:\Users\Red 1 - Admin\Downloads
Loaded Profiles: Red 1 - Admin (Available profiles: Red 1 & Red 1 - Admin)
Platform: Microsoft Windows 7 Professional  Service Pack 1 (X86) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(AMD) C:\Windows\System32\atiesrxx.exe
(Hewlett-Packard) C:\Windows\System32\hpservice.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Andrea Electronics Corporation) C:\Windows\System32\AEADISRV.EXE
(Juniper Networks, Inc.) C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
(Fortinet Inc.) C:\Windows\System32\FortiSSLVPNdaemon.exe
() C:\Program Files\ShrewSoft\VPN Client\iked.exe
() C:\Program Files\ShrewSoft\VPN Client\ipsecd.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(McAfee, Inc.) C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(Nitro PDF Software) C:\Program Files\Nitro\Pro 8\NitroPDFDriverService8.exe
(Nitro PDF Software) C:\Program Files\Nitro\Pro 9\NitroPDFDriverService9.exe
(Nitro PDF Software) C:\Program Files\Nitro\Reader 3\NitroPDFReaderDriverService3.exe
() C:\Program Files\Nitro\Pro 9\Nitro_UpdateService.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(Nalpeiron Ltd.) C:\Windows\System32\NLSSRV32.EXE
(pdfforge GmbH) C:\Program Files\PDF Architect\HelperService.exe
(pdfforge GmbH) C:\Program Files\PDF Architect\ConversionService.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
(PDF Complete Inc) C:\Program Files\PDF Complete\pdfsvc.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(McAfee, Inc.) C:\Program Files\McAfee\MSC\McAPExe.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
() C:\Program Files\QNAP\Qfinder\iSCSIAgent.exe
( Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Analog Devices, Inc.) C:\Program Files\Analog Devices\Core\smax4pnp.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe
(Adobe Systems Inc.) C:\Program Files\Adobe\Acrobat 11.0\Acrobat\acrotray.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
( Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
() C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\CSP\1.3.336.0\McCSPServiceHost.exe
(McAfee, Inc.) C:\Program Files\McAfee\MAT\McPvTray.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [QlbCtrl.exe] => C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [288312 2009-07-28] ( Hewlett-Packard Development Company, L.P.)
HKLM\...\Run: [IAAnotif] => C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-08-25] (Intel Corporation)
HKLM\...\Run: [PDF Complete] => C:\Program Files\PDF Complete\pdfsty.exe [563736 2009-06-18] (PDF Complete Inc)
HKLM\...\Run: [WirelessAssistant] => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [498744 2009-07-23] (Hewlett-Packard)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1721640 2014-12-08] (Synaptics Incorporated)
HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-08-04] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [SoundMAXPnP] => C:\Program Files\Analog Devices\Core\smax4pnp.exe [1314816 2009-05-18] (Analog Devices, Inc.)
HKLM\...\Run: [SoundMAX] => C:\Program Files\Analog Devices\SoundMAX\soundmax.exe [3866624 2009-05-18] (Analog Devices, Inc.)
HKLM\...\Run: [mcpltui_exe] => C:\Program Files\Common Files\McAfee\Platform\mcuicnt.exe [562688 2015-02-11] (McAfee, Inc.)
HKLM\...\Run: [HP Software Update] => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM\...\Run: [] => [X]
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKLM\...\Run: [Acrobat Assistant 8.0] => C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe [3477640 2012-09-23] (Adobe Systems Inc.)
HKLM\...\RunOnce: [NCPluginUpdater] => C:\Program Files\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe [21720 2014-12-03] (Hewlett-
 
Packard)
HKLM\...\runonceex: [ContentMerger] => c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\ContentMerger10.exe [19952 2009-06-13] (Sonic Solutions)
HKU\S-1-5-21-1872118813-3924231162-3133279225-1002\...\Run: [HPADVISOR] => C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [1668664 2009-07-16] (Hewlett-
 
Packard)
HKU\S-1-5-21-1872118813-3924231162-3133279225-1002\...\Run: [LightScribe Control Panel] => C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe 
 
[2363392 2009-06-17] (Hewlett-Packard Company)
HKU\S-1-5-21-1872118813-3924231162-3133279225-1002\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\windows\System32\scrnsave.scr [10240 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\windows\System32\SPReview\SPReview.exe [280576 2014-01-09] (Microsoft Corporation)
HKU\S-1-5-18\...\RunOnce: [{91120000-0031-0000-0000-0000000FF1CE}] => C:\windows\system32\cmd.exe /C del "C:\ProgramData\Microsoft Help\Rgstrtn.lck" /Q /A:H
Startup: C:\Users\Red 1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HELP_RESTORE_FILES.txt [2015-04-21] ()
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
ShellIconOverlayIdentifiers: [GDriveBlacklistedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-02-19] 
 
(Google)
ShellIconOverlayIdentifiers: [GDriveSharedEditOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-02-19] 
 
(Google)
ShellIconOverlayIdentifiers: [GDriveSharedViewOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-02-19] 
 
(Google)
ShellIconOverlayIdentifiers: [GDriveSyncedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-02-19] 
 
(Google)
ShellIconOverlayIdentifiers: [GDriveSyncingOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-02-19] 
 
(Google)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-1872118813-3924231162-3133279225-1002\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-1872118813-3924231162-3133279225-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?
 
TYPE=3&tp=iehome&locale=en_DE&c=92&bd=all&pf=cmnb
SearchScopes: HKU\S-1-5-21-1872118813-3924231162-3133279225-1002 -> DefaultScope {FAE36ACB-390B-4919-A1ED-48A03FC94607} URL = https://duckduckgo.com/?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1872118813-3924231162-3133279225-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-1872118813-3924231162-3133279225-1002 -> {FAE36ACB-390B-4919-A1ED-48A03FC94607} URL = https://duckduckgo.com/?q={searchTerms}
BHO: PDF Architect Helper -> {3A2D5EBA-F86D-4BD3-A177-019765996711} -> C:\Program Files\PDF Architect\PDFIEHelper.dll [2013-04-08] (pdfforge GmbH)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-04-21] (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll 
 
[2012-07-17] (Microsoft Corp.)
BHO: Adobe Acrobat Create PDF Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll 
 
[2012-09-23] (Adobe Systems Incorporated)
BHO: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll [2015-03-11] (McAfee, Inc.)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-21] (Oracle Corporation)
BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll 
 
[2012-09-23] (Adobe Systems Incorporated)
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll [2015-03-11] (McAfee, Inc.)
Toolbar: HKLM - PDF Architect Toolbar - {25A3A431-30BB-47C8-AD6A-E1063801134F} - C:\Program Files\PDF Architect\PDFIEPlugin.dll [2013-04-08] (pdfforge GmbH)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll 
 
[2012-09-23] (Adobe Systems Incorporated)
DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://juniper.net/dana-cached/sc/JuniperSetupClient.cab
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll [2015-03-11] (McAfee, Inc.)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll [2015-03-11] (McAfee, Inc.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl.dll [2015-03-03] (McAfee, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
 
FireFox:
========
FF ProfilePath: C:\Users\Red 1 - Admin\AppData\Roaming\Mozilla\Firefox\Profiles\23bsldxh.default
FF Plugin: @FortinetCacheClean -> C:\Program Files\Fortinet\SslvpnClient\npccplugin.dll [2014-04-09] (Fortinet Inc.)
FF Plugin: @FortinetCacheCleanEx -> C:\Program Files\Fortinet\SslvpnClient\npccpluginex.dll [2014-04-09] (Fortinet Inc.)
FF Plugin: @FortinetTunnelControl -> C:\Program Files\Fortinet\SslvpnClient\nptcplugin.dll [2014-04-09] (Fortinet Inc.)
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-04-21] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-04-21] (Oracle Corporation)
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2015-03-03] ()
FF Plugin: @mcafee.com/MVT -> C:\Program Files\McAfee\Supportability\MVT\NPMVTPlugin.dll [2014-12-08] (McAfee, Inc.)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @microsoft.com/WLPG,version=16.4.3522.0110 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2014-01-10] (Microsoft Corporation)
FF Plugin: @nitropdf.com/NitroPDF -> C:\Program Files\Nitro\Pro 9\npnitromozilla.dll [2014-07-16] (Nitro PDF)
FF Plugin: @nitropdf.com/NitroPDF.PrevVerNPR -> C:\Program Files\Nitro\Pro 8\npnitromozilla.dll [2013-11-14] (Nitro PDF)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-12] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-12] (Google Inc.)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll [2012-09-23] (Adobe Systems Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2012-09-20] (Adobe Systems)
FF Plugin ProgramFiles/Appdata: C:\Users\Red 1 - Admin\AppData\Roaming\mozilla\plugins\npatgpc.dll [2014-12-11] (Cisco WebEx LLC)
FF Extension: Adblock Plus - C:\Users\Red 1 - Admin\AppData\Roaming\Mozilla\Firefox\Profiles\23bsldxh.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi 
 
[2015-04-22]
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\SiteAdvisor
FF Extension: McAfee SiteAdvisor - C:\Program Files\McAfee\SiteAdvisor [2014-01-05]
FF HKLM\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files\PDF Architect\FFPDFArchitectExt
FF Extension: PDF Architect Converter For Firefox - C:\Program Files\PDF Architect\FFPDFArchitectExt [2014-03-18]
FF HKLM\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn [2014-05-03]
FF HKLM\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2014-01-05]
 
Chrome: 
=======
CHR DefaultSearchKeyword: Default -> google
CHR DefaultSearchURL: Default -> http://google.com/search?q={searchTerms}
CHR DefaultSuggestURL: Default -> 
CHR Profile: C:\Users\Red 1 - Admin\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Red 1 - Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-05]
CHR Extension: (Google Drive) - C:\Users\Red 1 - Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-05]
CHR Extension: (YouTube) - C:\Users\Red 1 - Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-05]
CHR Extension: (Adblock Plus) - C:\Users\Red 1 - Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-01-07]
CHR Extension: (Google Search) - C:\Users\Red 1 - Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-05]
CHR Extension: (Adobe Acrobat - Create PDF) - C:\Users\Red 1 - Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2014-
 
05-05]
CHR Extension: (No Name) - C:\Users\Red 1 - Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2014-12-05]
CHR Extension: (Bookmark Manager) - C:\Users\Red 1 - Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-17]
CHR Extension: (Zoho Assist - FREE Remote Support Tool) - C:\Users\Red 1 - Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions
 
\ieinjhnflpkoheailbgaickpoaehjoal [2015-01-20]
CHR Extension: (Cisco WebEx Extension) - C:\Users\Red 1 - Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlhmfgmfgeifomenelglieieghnjghma [2014-12-11]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Red 1 - Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015
 
-03-13]
CHR Extension: (Google Wallet) - C:\Users\Red 1 - Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-05]
CHR Extension: (Gmail) - C:\Users\Red 1 - Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-05]
CHR Extension: (Streak for Gmail) - C:\Users\Red 1 - Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnnfemgpilpdaojpnkjdgfgbnnjojfik [2015-02-18]
CHR Profile: C:\Users\Red 1 - Admin\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Google Slides) - C:\Users\Red 1 - Admin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-12-09]
CHR Extension: (Google Docs) - C:\Users\Red 1 - Admin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2014-12-09]
CHR Extension: (Google Drive) - C:\Users\Red 1 - Admin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-12-09]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Red 1 - Admin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions
 
\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-12-10]
CHR Extension: (YouTube) - C:\Users\Red 1 - Admin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-12-09]
CHR Extension: (Google Search) - C:\Users\Red 1 - Admin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-12-09]
CHR Extension: (Adobe Acrobat - Create PDF) - C:\Users\Red 1 - Admin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2014
 
-12-09]
CHR Extension: (Google Sheets) - C:\Users\Red 1 - Admin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-12-09]
CHR Extension: (SiteAdvisor) - C:\Users\Red 1 - Admin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2014-12-09]
CHR Extension: (Google Wallet) - C:\Users\Red 1 - Admin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-09]
CHR Extension: (Gmail) - C:\Users\Red 1 - Admin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-12-09]
CHR HKLM\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx [2012-09-23]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files\McAfee\SiteAdvisor\McChPlg.crx [2015-04-14]
 
========================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 dsNcService; C:\Program Files\Juniper Networks\Common Files\dsNcService.exe [684144 2014-12-24] (Juniper Networks, Inc.)
R2 FortiSslvpnDaemon; C:\windows\system32\FortiSSLVPNdaemon.exe [954080 2014-04-09] (Fortinet Inc.)
R2 HomeNetSvc; C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe [291816 2015-02-11] (McAfee, Inc.)
R2 HP Health Check Service; C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [124928 2009-07-10] (Hewlett-Packard) [File not signed]
R2 iked; C:\Program Files\ShrewSoft\VPN Client\iked.exe [772408 2013-07-01] ()
R2 ipsecd; C:\Program Files\ShrewSoft\VPN Client\ipsecd.exe [544400 2013-07-01] ()
R2 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [73728 2009-06-17] (Hewlett-Packard Company) [File not signed]
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-03-17] (Malwarebytes Corporation)
R2 McAfee SiteAdvisor Service; C:\Program Files\McAfee\SiteAdvisor\McSACore.exe [132160 2015-04-10] (McAfee, Inc.)
R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [690408 2015-03-03] (McAfee, Inc.)
R2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\1.3.336.0\McCSPServiceHost.exe [338160 2014-11-21] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe [291816 2015-02-11] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [291816 2015-02-11] (McAfee, Inc.)
S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [476680 2015-02-27] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [291816 2015-02-11] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [291816 2015-02-11] (McAfee, Inc.)
R3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [196600 2015-02-17] (McAfee, Inc.)
R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe [334576 2015-03-01] (McAfee, Inc.)
R2 mfevtp; C:\windows\system32\mfevtps.exe [238288 2015-02-17] (McAfee, Inc.)
R2 MSK80Service; C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe [291816 2015-02-11] (McAfee, Inc.)
R2 NitroDriverReadSpool8; C:\Program Files\Nitro\Pro 8\NitroPDFDriverService8.exe [197128 2013-11-14] (Nitro PDF Software)
R2 NitroDriverReadSpool9; C:\Program Files\Nitro\Pro 9\NitroPDFDriverService9.exe [197128 2014-07-16] (Nitro PDF Software)
R2 NitroReaderDriverReadSpool3; C:\Program Files\Nitro\Reader 3\NitroPDFReaderDriverService3.exe [196624 2013-07-26] (Nitro PDF Software)
R2 NitroUpdateService; C:\Program Files\Nitro\Pro 9\Nitro_UpdateService.exe [392712 2014-07-16] ()
S3 OpenVPNService; C:\Program Files\OpenVPN\bin\openvpnserv.exe [25088 2015-01-16] (The OpenVPN Project) [File not signed]
R2 PDF Architect Helper Service; C:\Program Files\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH)
R2 PDF Architect Service; C:\Program Files\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH)
R2 pdfcDispatcher; C:\Program Files\PDF Complete\pdfsvc.exe [635416 2009-06-18] (PDF Complete Inc)
R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [5436176 2015-02-17] (TeamViewer GmbH)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
R2 yksvc; C:\windows\System32\yk62x86.dll [282624 2009-07-20] (Marvell)
S3 Zoho Assist-Remote Support; C:\Program Files\ZohoMeeting\ZohoMeeting.exe [480288 2015-01-21] ()
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 cfwids; C:\windows\System32\drivers\cfwids.sys [61848 2015-02-17] (McAfee, Inc.)
R3 dsNcAdpt; C:\windows\System32\DRIVERS\dsNcAdpt.sys [27648 2014-12-24] (Juniper Networks)
S3 HipShieldK; C:\windows\System32\drivers\HipShieldK.sys [147912 2013-09-23] (McAfee, Inc.)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [23256 2015-03-17] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [51928 2015-03-17] (Malwarebytes Corporation)
R2 McPvDrv; C:\windows\system32\drivers\McPvDrv.sys [67800 2015-02-28] (McAfee, Inc.)
R3 mfeaack; C:\windows\System32\drivers\mfeaack.sys [304928 2015-02-17] (McAfee, Inc.)
R3 mfeavfk; C:\windows\System32\drivers\mfeavfk.sys [260248 2015-02-17] (McAfee, Inc.)
R0 mfedisk; C:\windows\System32\DRIVERS\mfedisk.sys [82800 2015-02-17] (McAfee, Inc.)
R3 mfefirek; C:\windows\System32\drivers\mfefirek.sys [371648 2015-02-17] (McAfee, Inc.)
R0 mfehidk; C:\windows\System32\drivers\mfehidk.sys [648552 2015-02-17] (McAfee, Inc.)
R3 mfencbdc; C:\windows\System32\DRIVERS\mfencbdc.sys [380496 2015-01-16] (McAfee, Inc.)
S3 mfencrk; C:\windows\System32\DRIVERS\mfencrk.sys [80760 2015-01-16] (McAfee, Inc.)
S3 MfeRKDK; C:\windows\System32\drivers\MfeRKDK.sys [34248 2009-05-16] (McAfee, Inc.)
R1 mfetdik; C:\windows\System32\drivers\mfetdik.sys [55336 2009-05-16] (McAfee, Inc.)
R0 mfewfpk; C:\windows\System32\drivers\mfewfpk.sys [217584 2015-02-17] (McAfee, Inc.)
R1 NEOFLTR_808_33771; C:\windows\system32\Drivers\NEOFLTR_808_33771.SYS [92984 2014-12-24] (Juniper Networks, Inc.)
S3 NETw1v32; C:\windows\System32\DRIVERS\NETw1v32.sys [5958656 2009-07-21] (Intel Corporation)
R3 pppop; C:\windows\System32\DRIVERS\pppop.sys [36384 2009-07-21] (Fortinet Inc.)
S3 Ser2plx86; C:\windows\System32\DRIVERS\ser2pl.sys [140800 2014-09-03] (Prolific Technology Inc.)
R3 tap0901; C:\windows\System32\DRIVERS\tap0901.sys [23040 2014-04-08] (The OpenVPN Project)
R1 vflt; C:\windows\System32\DRIVERS\vfilter.sys [18944 2013-07-01] (Shrew Soft Inc)
S3 vnet; C:\windows\System32\DRIVERS\virtualnet.sys [13824 2013-07-01] (Shrew Soft Inc)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-04-22 12:16 - 2015-04-22 12:17 - 00028213 _____ () C:\Users\Red 1 - Admin\Downloads\FRST.txt
2015-04-22 12:15 - 2015-04-22 12:16 - 00000000 ____D () C:\FRST
2015-04-22 12:15 - 2015-04-22 12:15 - 01139200 _____ (Farbar) C:\Users\Red 1 - Admin\Downloads\FRST.exe
2015-04-22 11:04 - 2015-04-22 11:04 - 00000000 ____D () C:\Users\Red 1 - Admin\Desktop\All desktop encrypted data
2015-04-22 10:42 - 2015-04-22 10:42 - 00000000 ____D () C:\Users\Red 1 - Admin\AppData\Roaming\McAfee
2015-04-22 10:40 - 2015-04-22 10:40 - 00586096 _____ (McAfee, Inc.) C:\Users\Red 1 - Admin\Downloads\MVTInstaller.exe
2015-04-22 10:40 - 2015-04-22 10:40 - 00586096 _____ (McAfee, Inc.) C:\Users\Red 1 - Admin\Downloads\MVTInstaller (1).exe
2015-04-22 10:30 - 2015-04-22 10:30 - 00243304 _____ () C:\Users\Red 1 - Admin\Downloads\Firefox Setup Stub 37.0.2.exe
2015-04-22 10:30 - 2015-04-22 10:30 - 00001121 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-04-22 10:30 - 2015-04-22 10:30 - 00000000 ____D () C:\Users\Red 1 - Admin\AppData\Local\Mozilla
2015-04-22 10:30 - 2015-04-22 10:30 - 00000000 ____D () C:\ProgramData\Mozilla
2015-04-22 10:30 - 2015-04-22 10:30 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-04-22 10:30 - 2015-04-22 10:30 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-04-21 20:15 - 2015-04-21 20:41 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2015-04-21 20:15 - 2015-04-21 20:15 - 00001220 _____ () C:\Users\Red 1 - Admin\Desktop\Spybot - Search & Destroy.lnk
2015-04-21 20:15 - 2015-04-21 20:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
2015-04-21 20:15 - 2015-04-21 20:15 - 00000000 ____D () C:\Program Files\Spybot - Search & Destroy
2015-04-21 19:42 - 2015-04-21 19:42 - 16409960 _____ (Safer Networking Limited ) C:\Users\Red 1 - Admin\Downloads\spybotsd162.exe
2015-04-21 19:42 - 2015-04-21 19:42 - 00388608 _____ (Trend Micro Inc.) C:\Users\Red 1 - Admin\Downloads\HijackThis.exe
2015-04-21 19:32 - 2015-04-21 20:03 - 00119512 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2015-04-21 19:31 - 2015-04-21 19:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-04-21 19:31 - 2015-04-21 19:31 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-04-21 19:31 - 2015-04-21 19:31 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2015-04-21 19:31 - 2015-03-17 06:15 - 00092888 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2015-04-21 19:31 - 2015-03-17 06:15 - 00051928 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2015-04-21 19:31 - 2015-03-17 06:15 - 00023256 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2015-04-21 19:30 - 2015-04-21 19:30 - 21540440 _____ (Malwarebytes Corporation ) C:\Users\Red 1 - Admin\Downloads\mbam-setup-2.1.4.1018.exe
2015-04-21 19:16 - 2015-04-21 19:25 - 00000000 ____D () C:\Safe Files
2015-04-21 18:39 - 2015-04-21 18:39 - 02304678 _____ () C:\Users\Red 1 - Admin\Desktop\HeLP_ReSTORe_FILeS.bmp
2015-04-21 18:39 - 2015-04-21 18:39 - 00001644 _____ () C:\Users\Red 1 - Admin\Desktop\CryptoLocker.lnk
2015-04-21 18:36 - 2015-04-21 18:36 - 00002678 _____ () C:\windows\Tasks\HELP_RESTORE_FILES.txt
2015-04-21 18:34 - 2015-04-21 18:34 - 00002678 _____ () C:\Users\Red 1 - Admin\HELP_RESTORE_FILES.txt
2015-04-21 18:34 - 2015-04-21 18:34 - 00002678 _____ () C:\Users\Red 1 - Admin\Downloads\HELP_RESTORE_FILES.txt
2015-04-21 18:34 - 2015-04-21 18:34 - 00002678 _____ () C:\Users\Red 1 - Admin\AppData\Roaming\Microsoft\Windows\Start Menu\HELP_RESTORE_FILES.txt
2015-04-21 18:34 - 2015-04-21 18:34 - 00002678 _____ () C:\Users\Red 1 - Admin\AppData\Local\HELP_RESTORE_FILES.txt
2015-04-21 18:33 - 2015-04-21 18:39 - 00001364 _____ () C:\Users\Red 1 - Admin\Desktop\HELP_RESTORE_FILES.txt
2015-04-21 18:33 - 2015-04-21 18:34 - 00002678 _____ () C:\Users\Red 1 - Admin\Documents\HELP_RESTORE_FILES.txt
2015-04-21 18:29 - 2015-04-21 18:34 - 00050148 _____ () C:\Users\Red 1 - Admin\Downloads\HELP_DECRYPT.PNG.ecc
2015-04-21 18:29 - 2015-04-21 18:34 - 00004868 _____ () C:\Users\Red 1 - Admin\Downloads\HELP_DECRYPT.TXT.ecc
2015-04-21 18:29 - 2015-04-21 18:29 - 00009042 _____ () C:\Users\Red 1 - Admin\HELP_DECRYPT.HTML
2015-04-21 18:29 - 2015-04-21 18:29 - 00009042 _____ () C:\Users\Red 1 - Admin\Downloads\HELP_DECRYPT.HTML
2015-04-21 18:29 - 2015-04-21 18:29 - 00009042 _____ () C:\HELP_DECRYPT.HTML
2015-04-21 18:29 - 2015-04-21 18:29 - 00004844 _____ () C:\Users\Red 1 - Admin\HELP_DECRYPT.TXT
2015-04-21 18:29 - 2015-04-21 18:29 - 00004844 _____ () C:\HELP_DECRYPT.TXT
2015-04-21 18:29 - 2015-04-21 18:29 - 00000292 _____ () C:\Users\Red 1 - Admin\HELP_DECRYPT.URL
2015-04-21 18:29 - 2015-04-21 18:29 - 00000292 _____ () C:\Users\Red 1 - Admin\Downloads\HELP_DECRYPT.URL
2015-04-21 18:29 - 2015-04-21 18:29 - 00000292 _____ () C:\HELP_DECRYPT.URL
2015-04-21 18:26 - 2015-04-21 18:33 - 00050148 _____ () C:\Users\Red 1 - Admin\Documents\HELP_DECRYPT.PNG.ecc
2015-04-21 18:26 - 2015-04-21 18:33 - 00004868 _____ () C:\Users\Red 1 - Admin\Documents\HELP_DECRYPT.TXT.ecc
2015-04-21 18:26 - 2015-04-21 18:26 - 00009042 _____ () C:\Users\Red 1 - Admin\Documents\HELP_DECRYPT.HTML
2015-04-21 18:26 - 2015-04-21 18:26 - 00000292 _____ () C:\Users\Red 1 - Admin\Documents\HELP_DECRYPT.URL
2015-04-21 18:00 - 2015-04-21 18:00 - 00002678 _____ () C:\Users\Red 1\HELP_RESTORE_FILES.txt
2015-04-21 18:00 - 2015-04-21 18:00 - 00002678 _____ () C:\Users\Red 1 - Admin\AppData\Roaming\HELP_RESTORE_FILES.txt
2015-04-21 18:00 - 2015-04-21 18:00 - 00002678 _____ () C:\Users\Red 1 - Admin\AppData\HELP_RESTORE_FILES.txt
2015-04-21 17:54 - 2015-04-21 17:54 - 00002678 _____ () C:\Users\Red 1\Downloads\HELP_RESTORE_FILES.txt
2015-04-21 17:54 - 2015-04-21 17:54 - 00002678 _____ () C:\Users\Red 1\Documents\HELP_RESTORE_FILES.txt
2015-04-21 17:53 - 2015-04-21 18:00 - 00002678 _____ () C:\Users\Red 1\AppData\Roaming\Microsoft\Windows\Start Menu\HELP_RESTORE_FILES.txt
2015-04-21 17:53 - 2015-04-21 17:53 - 00002678 _____ () C:\Users\Red 1\Desktop\HELP_RESTORE_FILES.txt
2015-04-21 17:53 - 2015-04-21 17:53 - 00002678 _____ () C:\Users\Red 1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HELP_RESTORE_FILES.txt
2015-04-21 17:53 - 2015-04-21 17:53 - 00002678 _____ () C:\Users\Red 1\AppData\Roaming\HELP_RESTORE_FILES.txt
2015-04-21 17:53 - 2015-04-21 17:53 - 00002678 _____ () C:\Users\Red 1\AppData\HELP_RESTORE_FILES.txt
2015-04-21 17:42 - 2015-02-28 01:10 - 00067800 _____ (McAfee, Inc.) C:\windows\system32\Drivers\McPvDrv.sys
2015-04-21 17:41 - 2013-09-23 13:48 - 00147912 _____ (McAfee, Inc.) C:\windows\system32\Drivers\HipShieldK.sys
2015-04-21 16:47 - 2015-04-21 16:55 - 00050148 _____ () C:\Users\Public\HELP_DECRYPT.PNG.ecc
2015-04-21 16:47 - 2015-04-21 16:55 - 00050148 _____ () C:\Users\Public\Downloads\HELP_DECRYPT.PNG.ecc
2015-04-21 16:47 - 2015-04-21 16:55 - 00050148 _____ () C:\Users\Public\Documents\HELP_DECRYPT.PNG.ecc
2015-04-21 16:47 - 2015-04-21 16:55 - 00004868 _____ () C:\Users\Public\HELP_DECRYPT.TXT.ecc
2015-04-21 16:47 - 2015-04-21 16:55 - 00004868 _____ () C:\Users\Public\Downloads\HELP_DECRYPT.TXT.ecc
2015-04-21 16:47 - 2015-04-21 16:55 - 00004868 _____ () C:\Users\Public\Documents\HELP_DECRYPT.TXT.ecc
2015-04-21 16:47 - 2015-04-21 16:47 - 00009042 _____ () C:\Users\Public\HELP_DECRYPT.HTML
2015-04-21 16:47 - 2015-04-21 16:47 - 00009042 _____ () C:\Users\Public\Downloads\HELP_DECRYPT.HTML
2015-04-21 16:47 - 2015-04-21 16:47 - 00009042 _____ () C:\Users\Public\Documents\HELP_DECRYPT.HTML
2015-04-21 16:47 - 2015-04-21 16:47 - 00000292 _____ () C:\Users\Public\HELP_DECRYPT.URL
2015-04-21 16:47 - 2015-04-21 16:47 - 00000292 _____ () C:\Users\Public\Downloads\HELP_DECRYPT.URL
2015-04-21 16:47 - 2015-04-21 16:47 - 00000292 _____ () C:\Users\Public\Documents\HELP_DECRYPT.URL
2015-04-21 16:24 - 2015-04-21 18:00 - 00050228 _____ () C:\Users\Red 1 - Admin\AppData\HELP_DECRYPT.PNG.ecc
2015-04-21 16:24 - 2015-04-21 18:00 - 00004868 _____ () C:\Users\Red 1 - Admin\AppData\HELP_DECRYPT.TXT.ecc
2015-04-21 16:24 - 2015-04-21 16:24 - 00009042 _____ () C:\Users\Red 1 - Admin\AppData\Roaming\HELP_DECRYPT.HTML
2015-04-21 16:24 - 2015-04-21 16:24 - 00009042 _____ () C:\Users\Red 1 - Admin\AppData\Local\HELP_DECRYPT.HTML
2015-04-21 16:24 - 2015-04-21 16:24 - 00009042 _____ () C:\Users\Red 1 - Admin\AppData\HELP_DECRYPT.HTML
2015-04-21 16:24 - 2015-04-21 16:24 - 00004844 _____ () C:\Users\Red 1 - Admin\AppData\Roaming\HELP_DECRYPT.TXT
2015-04-21 16:24 - 2015-04-21 16:24 - 00004844 _____ () C:\Users\Red 1 - Admin\AppData\Local\HELP_DECRYPT.TXT
2015-04-21 16:24 - 2015-04-21 16:24 - 00000292 _____ () C:\Users\Red 1 - Admin\AppData\Roaming\HELP_DECRYPT.URL
2015-04-21 16:24 - 2015-04-21 16:24 - 00000292 _____ () C:\Users\Red 1 - Admin\AppData\Local\HELP_DECRYPT.URL
2015-04-21 16:24 - 2015-04-21 16:24 - 00000292 _____ () C:\Users\Red 1 - Admin\AppData\HELP_DECRYPT.URL
2015-04-21 16:22 - 2015-04-21 17:54 - 00050228 _____ () C:\Users\Red 1\HELP_DECRYPT.PNG.ecc
2015-04-21 16:22 - 2015-04-21 17:54 - 00004868 _____ () C:\Users\Red 1\HELP_DECRYPT.TXT.ecc
2015-04-21 16:22 - 2015-04-21 16:22 - 00009042 _____ () C:\Users\Red 1\HELP_DECRYPT.HTML
2015-04-21 16:22 - 2015-04-21 16:22 - 00000292 _____ () C:\Users\Red 1\HELP_DECRYPT.URL
2015-04-21 16:21 - 2015-04-21 17:54 - 00002678 _____ () C:\Users\Red 1\AppData\Local\HELP_RESTORE_FILES.txt
2015-04-21 16:21 - 2015-04-21 16:56 - 00002678 _____ () C:\Users\Red 1\AppData\Local\Apps\HELP_RESTORE_FILES.txt
2015-04-21 16:21 - 2015-04-21 16:55 - 00002960 _____ () C:\Users\Public\HELP_RESTORE_FILES.txt
2015-04-21 16:21 - 2015-04-21 16:55 - 00002960 _____ () C:\Users\Public\Downloads\HELP_RESTORE_FILES.txt
2015-04-21 16:18 - 2015-04-21 16:55 - 00002960 _____ () C:\Users\Public\Documents\HELP_RESTORE_FILES.txt
2015-04-21 16:18 - 2015-04-21 16:55 - 00002960 _____ () C:\ProgramData\HELP_RESTORE_FILES.txt
2015-04-21 16:14 - 2015-04-21 16:14 - 00000000 ____D () C:\Program Files\Common Files\Java
2015-04-21 15:58 - 2015-04-21 17:54 - 00050228 _____ () C:\Users\Red 1\Downloads\HELP_DECRYPT.PNG.ecc
2015-04-21 15:58 - 2015-04-21 17:54 - 00004868 _____ () C:\Users\Red 1\Downloads\HELP_DECRYPT.TXT.ecc
2015-04-21 15:58 - 2015-04-21 15:58 - 00009042 _____ () C:\Users\Red 1\Downloads\HELP_DECRYPT.HTML
2015-04-21 15:58 - 2015-04-21 15:58 - 00000292 _____ () C:\Users\Red 1\Downloads\HELP_DECRYPT.URL
2015-04-21 15:57 - 2015-04-21 18:39 - 05679498 _____ () C:\Users\Red 1 - Admin\AppData\Roaming\log.html
2015-04-21 15:57 - 2015-04-21 18:39 - 00000752 _____ () C:\Users\Red 1 - Admin\AppData\Roaming\key.dat
2015-04-21 15:57 - 2015-04-21 16:44 - 00000512 _____ () C:\Users\Red 1 - Admin\Documents\RECOVERY_KEY.TXT
2015-04-21 15:56 - 2015-04-21 17:53 - 00050228 _____ () C:\Users\Red 1\Documents\HELP_DECRYPT.PNG.ecc
2015-04-21 15:56 - 2015-04-21 17:53 - 00050228 _____ () C:\Users\Red 1\AppData\Roaming\HELP_DECRYPT.PNG.ecc
2015-04-21 15:56 - 2015-04-21 17:53 - 00004868 _____ () C:\Users\Red 1\Documents\HELP_DECRYPT.TXT.ecc
2015-04-21 15:56 - 2015-04-21 17:53 - 00004868 _____ () C:\Users\Red 1\AppData\Roaming\HELP_DECRYPT.TXT.ecc
2015-04-21 15:56 - 2015-04-21 16:21 - 00050228 _____ () C:\Users\Red 1\AppData\HELP_DECRYPT.PNG.ecc
2015-04-21 15:56 - 2015-04-21 16:21 - 00004868 _____ () C:\Users\Red 1\AppData\HELP_DECRYPT.TXT.ecc
2015-04-21 15:56 - 2015-04-21 15:56 - 00009042 _____ () C:\Users\Red 1\Documents\HELP_DECRYPT.HTML
2015-04-21 15:56 - 2015-04-21 15:56 - 00009042 _____ () C:\Users\Red 1\AppData\Roaming\HELP_DECRYPT.HTML
2015-04-21 15:56 - 2015-04-21 15:56 - 00009042 _____ () C:\Users\Red 1\AppData\HELP_DECRYPT.HTML
2015-04-21 15:56 - 2015-04-21 15:56 - 00000292 _____ () C:\Users\Red 1\Documents\HELP_DECRYPT.URL
2015-04-21 15:56 - 2015-04-21 15:56 - 00000292 _____ () C:\Users\Red 1\AppData\Roaming\HELP_DECRYPT.URL
2015-04-21 15:56 - 2015-04-21 15:56 - 00000292 _____ () C:\Users\Red 1\AppData\HELP_DECRYPT.URL
2015-04-21 15:55 - 2015-04-21 16:25 - 00050228 _____ () C:\Users\Red 1\AppData\Local\HELP_DECRYPT.PNG.ecc
2015-04-21 15:55 - 2015-04-21 16:25 - 00004868 _____ () C:\Users\Red 1\AppData\Local\HELP_DECRYPT.TXT.ecc
2015-04-21 15:55 - 2015-04-21 15:55 - 00009042 _____ () C:\Users\Red 1\AppData\Local\HELP_DECRYPT.HTML
2015-04-21 15:55 - 2015-04-21 15:55 - 00000292 _____ () C:\Users\Red 1\AppData\Local\HELP_DECRYPT.URL
2015-04-21 15:54 - 2015-04-21 16:50 - 00050148 _____ () C:\ProgramData\HELP_DECRYPT.PNG.ecc
2015-04-21 15:54 - 2015-04-21 16:50 - 00004868 _____ () C:\ProgramData\HELP_DECRYPT.TXT.ecc
2015-04-21 15:54 - 2015-04-21 16:45 - 00009042 _____ () C:\ProgramData\HELP_DECRYPT.HTML
2015-04-21 15:54 - 2015-04-21 16:45 - 00000292 _____ () C:\ProgramData\HELP_DECRYPT.URL
2015-04-21 15:49 - 2015-04-21 18:31 - 00000000 ___HD () C:\81f935d2
2015-04-21 15:46 - 2015-04-21 20:00 - 00000000 ___HD () C:\ProgramData\{D9E629DC-CB1C-4A97-9900-81922B4EFFD4}
2015-04-16 16:27 - 2015-04-21 18:34 - 00494564 _____ () C:\Users\Red 1 - Admin\Downloads\Sample load data.xlsx.ecc
2015-04-15 18:13 - 2015-04-02 01:49 - 00342704 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2015-04-15 18:13 - 2015-03-23 05:06 - 00860160 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2015-04-15 18:13 - 2015-03-23 05:06 - 00630784 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2015-04-15 18:13 - 2015-03-23 05:06 - 00576000 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2015-04-15 18:13 - 2015-03-23 05:06 - 00331264 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2015-04-15 18:13 - 2015-03-23 05:06 - 00202752 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2015-04-15 18:13 - 2015-03-23 05:06 - 00159744 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll
2015-04-15 18:13 - 2015-03-23 05:06 - 00026112 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
2015-04-15 18:13 - 2015-03-23 04:59 - 00896000 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2015-04-15 18:13 - 2015-03-17 07:01 - 03976632 _____ (Microsoft Corporation) C:\windows\system32\ntkrnlpa.exe
2015-04-15 18:13 - 2015-03-17 07:01 - 03920824 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2015-04-15 18:13 - 2015-03-17 07:01 - 00137656 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2015-04-15 18:13 - 2015-03-17 07:01 - 00067512 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2015-04-15 18:13 - 2015-03-17 06:59 - 01306112 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2015-04-15 18:13 - 2015-03-17 06:57 - 01061376 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2015-04-15 18:13 - 2015-03-17 06:57 - 00550912 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2015-04-15 18:13 - 2015-03-17 06:57 - 00400896 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2015-04-15 18:13 - 2015-03-17 06:57 - 00259584 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2015-04-15 18:13 - 2015-03-17 06:57 - 00248832 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2015-04-15 18:13 - 2015-03-17 06:57 - 00221184 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2015-04-15 18:13 - 2015-03-17 06:57 - 00172032 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2015-04-15 18:13 - 2015-03-17 06:57 - 00100352 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2015-04-15 18:13 - 2015-03-17 06:57 - 00065536 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2015-04-15 18:13 - 2015-03-17 06:57 - 00043008 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2015-04-15 18:13 - 2015-03-17 06:57 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2015-04-15 18:13 - 2015-03-17 06:57 - 00015872 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2015-04-15 18:13 - 2015-03-17 06:56 - 00262656 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2015-04-15 18:13 - 2015-03-17 06:56 - 00069632 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2015-04-15 18:13 - 2015-03-17 06:56 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2015-04-15 18:13 - 2015-03-17 06:56 - 00038912 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2015-04-15 18:13 - 2015-03-17 06:56 - 00022528 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2015-04-15 18:13 - 2015-03-17 06:56 - 00017408 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2015-04-15 18:13 - 2015-03-17 06:53 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2015-04-15 18:13 - 2015-03-17 06:53 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2015-04-15 18:13 - 2015-03-17 06:50 - 00686080 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2015-04-15 18:13 - 2015-03-17 06:50 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2015-04-15 18:13 - 2015-03-13 05:42 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2015-04-15 18:13 - 2015-03-13 05:42 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2015-04-15 18:13 - 2015-03-13 05:28 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2015-04-15 18:13 - 2015-03-13 05:27 - 00047616 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2015-04-15 18:13 - 2015-03-13 05:20 - 00047104 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2015-04-15 18:13 - 2015-03-13 05:20 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2015-04-15 18:13 - 2015-03-13 05:17 - 00478208 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2015-04-15 18:13 - 2015-03-13 05:16 - 00115712 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2015-04-15 18:13 - 2015-03-13 05:16 - 00102912 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2015-04-15 18:13 - 2015-03-13 05:15 - 00620032 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2015-04-15 18:13 - 2015-03-13 05:09 - 00667648 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2015-04-15 18:13 - 2015-03-13 05:06 - 00418304 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2015-04-15 18:13 - 2015-03-13 05:01 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2015-04-15 18:13 - 2015-03-13 04:57 - 00168960 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2015-04-15 18:13 - 2015-03-13 04:54 - 00285696 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2015-04-15 18:13 - 2015-03-13 04:44 - 00689152 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2015-04-15 18:13 - 2015-03-13 04:43 - 02052608 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2015-04-15 18:13 - 2015-03-13 04:43 - 00685568 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2015-04-15 18:13 - 2015-03-13 04:20 - 01888256 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2015-04-15 18:13 - 2015-03-13 04:16 - 01311232 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2015-04-15 18:13 - 2015-03-13 04:14 - 00710144 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2015-04-15 18:13 - 2015-03-05 06:06 - 00305152 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
2015-04-15 18:13 - 2015-03-04 06:16 - 00249784 _____ (Microsoft Corporation) C:\windows\system32\clfs.sys
2015-04-15 18:13 - 2015-03-04 06:10 - 00058880 _____ (Microsoft Corporation) C:\windows\system32\clfsw32.dll
2015-04-15 18:12 - 2015-03-13 05:42 - 19695616 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2015-04-15 18:12 - 2015-03-13 05:28 - 00503296 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2015-04-15 18:12 - 2015-03-13 05:27 - 00340992 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2015-04-15 18:12 - 2015-03-13 05:26 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2015-04-15 18:12 - 2015-03-13 05:22 - 02278400 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2015-04-15 18:12 - 2015-03-13 04:56 - 00076288 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2015-04-15 18:12 - 2015-03-13 04:49 - 04305408 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2015-04-15 18:12 - 2015-03-13 04:42 - 01155072 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2015-04-15 18:12 - 2015-03-13 04:34 - 12825600 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2015-04-15 18:10 - 2015-03-25 05:00 - 03088384 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2015-04-15 18:10 - 2015-03-25 05:00 - 02020864 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2015-04-15 18:10 - 2015-03-25 05:00 - 00566784 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2015-04-15 18:10 - 2015-03-25 05:00 - 00173056 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2015-04-15 18:10 - 2015-03-25 05:00 - 00131584 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2015-04-15 18:10 - 2015-03-25 05:00 - 00092672 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2015-04-15 18:10 - 2015-03-25 05:00 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\WinSetupUI.dll
2015-04-15 18:10 - 2015-03-25 05:00 - 00035328 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2015-04-15 18:10 - 2015-03-25 05:00 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2015-04-15 18:10 - 2015-03-25 05:00 - 00029696 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2015-04-15 18:10 - 2015-03-25 05:00 - 00011776 _____ (Microsoft Corporation) C:\windows\system32\wu.upgrade.ps.dll
2015-04-15 18:09 - 2015-03-10 05:08 - 01237504 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll
2015-04-15 18:09 - 2015-03-10 05:05 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml3r.dll
2015-04-15 18:09 - 2015-02-25 05:03 - 00514560 _____ (Microsoft Corporation) C:\windows\system32\Drivers\http.sys
2015-04-15 17:52 - 2015-04-21 18:34 - 00012740 _____ () C:\Users\Red 1 - Admin\Downloads\Red - Laptops.xlsx.ecc
2015-04-10 18:50 - 2015-04-21 16:18 - 00000000 ____D () C:\ProgramData\Applications
2015-04-10 18:50 - 2015-04-10 18:50 - 06745792 _____ (Microsoft Corporation) C:\Users\Red 1 - Admin\Downloads\WindowsPhone.exe
2015-04-10 18:50 - 2015-04-10 18:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Phone
2015-04-10 18:50 - 2015-04-10 18:50 - 00000000 ____D () C:\Program Files\Windows Phone
2015-04-10 18:46 - 2015-04-21 18:34 - 00000000 ___RD () C:\Users\Red 1 - Admin\Podcasts
2015-04-10 18:38 - 2015-04-10 18:38 - 105664248 _____ (Microsoft Corporation) C:\Users\Red 1 - Admin\Downloads\ZuneSetupPkg.exe
2015-04-10 18:15 - 2015-04-10 18:15 - 00000000 ____H () C:\windows\system32\Drivers\Msft_User_PCCSWpdDriver_01_09_00.Wdf
2015-04-10 18:15 - 2015-04-10 18:15 - 00000000 ____H () C:\windows\system32\Drivers\Msft_Kernel_ccdcmb_01009.Wdf
2015-04-10 18:13 - 2015-04-21 16:24 - 00000000 ____D () C:\Users\Red 1 - Admin\AppData\Roaming\PC Suite
2015-04-10 18:13 - 2015-04-21 16:21 - 00000000 ____D () C:\ProgramData\PC Suite
2015-04-10 18:13 - 2015-04-10 18:15 - 00000000 ____D () C:\Users\Red 1 - Admin\AppData\Roaming\Nokia
2015-04-10 18:12 - 2015-04-10 18:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nokia PC Suite
2015-04-10 18:12 - 2015-04-10 18:12 - 00000000 ____D () C:\Program Files\Common Files\PCSuite
2015-04-10 18:12 - 2015-04-10 18:12 - 00000000 ____D () C:\Program Files\Common Files\Nokia
2015-04-10 18:11 - 2015-04-10 18:12 - 00000000 ____D () C:\Program Files\Nokia
2015-04-10 18:11 - 2015-04-10 18:11 - 00000000 ____D () C:\Program Files\PC Connectivity Solution
2015-04-10 18:11 - 2012-06-11 11:33 - 00019072 _____ (Nokia) C:\windows\system32\Drivers\pccsmcfd.sys
2015-04-10 18:11 - 2012-01-09 17:28 - 00075264 _____ (Nokia) C:\windows\system32\nmwcdcls.dll
2015-04-10 18:10 - 2015-04-21 16:20 - 00000000 ____D () C:\ProgramData\Installations
2015-04-10 18:09 - 2015-04-10 18:09 - 67963216 _____ () C:\Users\Red 1 - Admin\Downloads\Nokia_PC_Suite_ALL.exe
2015-04-10 12:56 - 2015-04-21 18:33 - 00182068 _____ () C:\Users\Red 1 - Admin\Downloads\20150131_AA Laptop Purchase Jan 2015 - CHECK IF TO PAY (3).pdf.ecc
2015-04-10 12:55 - 2015-04-21 18:33 - 00182068 _____ () C:\Users\Red 1 - Admin\Downloads\20150131_AA Laptop Purchase Jan 2015 - CHECK IF TO PAY.pdf.ecc
2015-04-10 12:55 - 2015-04-21 18:33 - 00182068 _____ () C:\Users\Red 1 - Admin\Downloads\20150131_AA Laptop Purchase Jan 2015 - CHECK IF TO PAY (2).pdf.ecc
2015-04-10 12:55 - 2015-04-21 18:33 - 00182068 _____ () C:\Users\Red 1 - Admin\Downloads\20150131_AA Laptop Purchase Jan 2015 - CHECK IF TO PAY (1).pdf.ecc
2015-04-09 17:10 - 2015-04-09 17:10 - 00002026 _____ () C:\Users\Red 1 - Admin\Desktop\PV Logging.sut
2015-04-09 11:47 - 2015-04-09 11:47 - 14737142 _____ () C:\Users\Red 1 - Admin\Downloads\Sunny-WebBox-Assistant-2.0.12.R.exe
2015-04-08 13:06 - 2015-04-21 18:33 - 00358628 _____ () C:\Users\Red 1 - Admin\Downloads\20141127_Shanta_Marvin_2020 (2).xlsx.ecc
2015-04-08 13:03 - 2015-04-21 18:34 - 00119780 _____ () C:\Users\Red 1 - Admin\Downloads\Sample_Yearly_Load_Profile_SHA002.xlsx.ecc
2015-04-08 12:52 - 2015-04-21 18:34 - 00287204 _____ () C:\Users\Red 1 - Admin\Downloads\Siemens_Checklist SGS 1st analysis- EXTERNAL - 2013 06 18.xlsx.ecc
2015-04-08 11:36 - 2015-04-17 16:19 - 00000000 ____D () C:\Program Files\OpenVPN
2015-04-08 11:36 - 2015-04-08 11:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenVPN
2015-04-08 11:36 - 2015-04-08 11:38 - 00000000 ____D () C:\Program Files\TAP-Windows
2015-04-08 11:36 - 2015-04-08 11:36 - 01789449 _____ () C:\Users\Red 1 - Admin\Downloads\WindowsOpenVPN_mdex_fixed.IP_i686.exe
2015-04-08 11:36 - 2015-04-08 11:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TAP-Windows
2015-04-07 12:41 - 2015-04-21 18:33 - 00019908 _____ () C:\Users\Red 1 - Admin\Downloads\20150320_Rockfound_Village_Sizing_Questions (6).docx.ecc
2015-04-07 12:41 - 2015-04-21 18:33 - 00012852 _____ () C:\Users\Red 1 - Admin\Downloads\20150320_Rockfound_Village_Sizing_Questions (5).docx.ecc
2015-04-07 12:40 - 2015-04-21 18:34 - 00028692 _____ () C:\Users\Red 1 - Admin\Downloads\Load Pattern Summary_Prospective GENCO Sites_30 VP_Araria (4).xlsx.ecc
2015-04-07 12:40 - 2015-04-21 18:33 - 00012852 _____ () C:\Users\Red 1 - Admin\Downloads\20150320_Rockfound_Village_Sizing_Questions (4).docx.ecc
2015-04-06 16:21 - 2015-04-21 18:34 - 03471668 _____ () C:\Users\Red 1 - Admin\Downloads\SMA_Red_NDA_Liability_Modbus.pdf.ecc
2015-04-06 14:28 - 2015-04-21 18:33 - 00019908 _____ () C:\Users\Red 1 - Admin\Downloads\20150320_Rockfound_Village_Sizing_Questions (3).docx.ecc
2015-04-06 14:04 - 2015-04-21 18:34 - 00211732 _____ () C:\Users\Red 1 - Admin\Downloads\nicta_publication_full_3587.pdf.ecc
2015-04-06 11:23 - 2015-04-21 18:33 - 00630436 _____ () C:\Users\Red 1 - Admin\Downloads\03-23 Graph Set rev1.docx.ecc
2015-04-06 10:19 - 2015-04-06 10:19 - 00000000 ___SD () C:\windows\system32\GWX
2015-04-03 11:11 - 2015-04-03 11:11 - 00037186 _____ () C:\Users\Red 1 - Admin\Downloads\CAM02_2015-04-03_11-11.cfg
2015-04-02 12:59 - 2015-04-21 18:34 - 00050068 _____ () C:\Users\Red 1 - Admin\Downloads\PV Data logging (2).jpg.ecc
2015-04-02 12:57 - 2015-04-21 18:34 - 00050068 _____ () C:\Users\Red 1 - Admin\Downloads\PV Data logging (1).jpg.ecc
2015-04-02 12:52 - 2015-04-21 18:34 - 00050068 _____ () C:\Users\Red 1 - Admin\Downloads\PV Data logging.jpg.ecc
2015-04-02 10:51 - 2015-04-21 18:33 - 01126116 _____ () C:\Users\Red 1 - Admin\Downloads\app_note_elitepro_port_forwarding-1.pdf.ecc
2015-04-01 16:58 - 2015-04-21 18:33 - 00021460 _____ () C:\Users\Red 1 - Admin\Downloads\2015-03-25 Schedule Update  (3).xlsx.ecc
2015-03-31 12:53 - 2015-04-21 18:34 - 00013780 _____ () C:\Users\Red 1 - Admin\Downloads\master_internship (1).xlsx.ecc
2015-03-27 11:59 - 2015-04-21 18:34 - 00013972 _____ () C:\Users\Red 1 - Admin\Downloads\Microgrid Controller Documentation Outline.docx.ecc
2015-03-27 11:41 - 2015-04-21 18:33 - 00021924 _____ () C:\Users\Red 1 - Admin\Downloads\2015-03-25 Schedule Update  (2).xlsx.ecc
2015-03-26 18:48 - 2015-04-21 18:33 - 00021924 _____ () C:\Users\Red 1 - Admin\Downloads\2015-03-25 Schedule Update  (1).xlsx.ecc
2015-03-26 15:13 - 2015-04-21 18:33 - 00107876 _____ () C:\Users\Red 1 - Admin\Downloads\150326_AA_Feedback on plot results.docx.ecc
2015-03-26 11:27 - 2015-04-21 18:33 - 00021332 _____ () C:\Users\Red 1 - Admin\Downloads\2015-03-25 Schedule Update .xlsx.ecc
2015-03-25 11:59 - 2015-04-21 18:34 - 04298996 _____ () C:\Users\Red 1 - Admin\Downloads\KippZonen_Manual_Datalogger_LOGBOX_SD_1012.pdf.ecc
2015-03-24 19:28 - 2015-04-21 18:33 - 00012852 _____ () C:\Users\Red 1 - Admin\Downloads\20150320_Rockfound_Village_Sizing_Questions (2).docx.ecc
2015-03-24 19:27 - 2015-04-21 18:33 - 00012500 _____ () C:\Users\Red 1 - Admin\Downloads\20150320_Rockfound_Village_Sizing_Questions (1).docx.ecc
2015-03-24 19:07 - 2015-04-21 18:33 - 00012500 _____ () C:\Users\Red 1 - Admin\Downloads\20150320_Rockfound_Village_Sizing_Questions.docx.ecc
2015-03-24 16:25 - 2015-04-21 18:33 - 00016420 _____ () C:\Users\Red 1 - Admin\Downloads\2015-01 Schedule Update v3 and QA and Testing considerations.xlsx.xlsx.ecc
2015-03-24 16:13 - 2015-04-21 18:34 - 00418452 _____ () C:\Users\Red 1 - Admin\Downloads\PV Penetration Results v2 (1).docx.ecc
2015-03-24 16:13 - 2015-04-21 18:33 - 00227876 _____ () C:\Users\Red 1 - Admin\Downloads\150115_Dan_PVPenetrationResults.docx (2).docx.ecc
 
2015-03-24 15:42 - 2015-04-21 18:33 - 00041588 _____ () C:\Users\Red 1 - Admin\Downloads\1LEBENSLAUF_nitinn (1).docx.ecc
2015-03-24 15:36 - 2015-04-21 18:33 - 00012932 _____ () C:\Users\Red 1 - Admin\Downloads\20150218_Interns_Checklist.xlsx.ecc
2015-03-24 15:35 - 2015-04-21 18:34 - 00013780 _____ () C:\Users\Red 1 - Admin\Downloads\master_internship.xlsx.ecc
2015-03-24 15:33 - 2015-03-24 15:33 - 30431616 _____ (Microsoft Corporation) C:\Users\Red 1 - Admin\Downloads\AnyMeetingInstaller_v3.1.0 (1).exe
2015-03-24 15:32 - 2015-03-24 15:33 - 30431616 _____ (Microsoft Corporation) C:\Users\Red 1 - Admin\Downloads\AnyMeetingInstaller_v3.1.0.exe
2015-03-24 12:31 - 2015-04-21 18:33 - 00541060 _____ () C:\Users\Red 1 - Admin\Downloads\03-23 Graph Set.docx.ecc
2015-03-24 12:23 - 2015-03-24 12:23 - 07824680 _____ (TeamViewer GmbH) C:\Users\Red 1 - Admin\Downloads\TeamViewer_Setup_de.exe
2015-03-24 11:37 - 2015-03-24 11:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kst-2.0.8
2015-03-24 11:37 - 2015-03-24 11:37 - 00000000 ____D () C:\Program Files\Kst-2.0.8
2015-03-23 19:31 - 2015-04-21 18:34 - 00019476 _____ () C:\Users\Red 1 - Admin\Downloads\Intervention capacity improvement (4).xlsx.ecc
2015-03-23 16:06 - 2015-04-21 18:34 - 00028692 _____ () C:\Users\Red 1 - Admin\Downloads\Load Pattern Summary_Prospective GENCO Sites_30 VP_Araria (3).xlsx.ecc
2015-03-23 16:03 - 2015-04-21 18:34 - 00019476 _____ () C:\Users\Red 1 - Admin\Downloads\Intervention capacity improvement (3).xlsx.ecc
2015-03-23 13:00 - 2015-04-21 18:34 - 00018548 _____ () C:\Users\Red 1 - Admin\Downloads\Intervention capacity improvement (2).xlsx.ecc
2015-03-23 11:27 - 2015-03-23 11:27 - 00170723 _____ () C:\Users\Red 1 - Admin\Downloads\20150202 XC1410004-01 T1 OR G1 MCCB.elog
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-04-22 12:07 - 2014-07-14 10:02 - 00000830 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2015-04-22 11:43 - 2014-02-17 10:44 - 00001098 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA1cf2bbc7987060f.job
2015-04-22 11:01 - 2009-07-14 06:34 - 00025648 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-22 11:01 - 2009-07-14 06:34 - 00025648 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-22 10:59 - 2014-07-14 10:03 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2015-04-22 10:58 - 2014-01-05 20:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2015-04-22 10:57 - 2009-09-17 05:52 - 00785794 _____ () C:\windows\system32\PerfStringBackup.INI
2015-04-22 10:56 - 2014-01-27 21:25 - 00000000 __RSD () C:\Users\Red 1 - Admin\Documents\McAfee Vaults
2015-04-22 10:56 - 2014-01-05 15:23 - 01190505 _____ () C:\windows\WindowsUpdate.log
2015-04-22 10:53 - 2014-01-05 21:03 - 00001094 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-04-22 10:53 - 2014-01-05 20:39 - 00000000 ____D () C:\Program Files\McAfee
2015-04-22 10:53 - 2009-07-14 06:53 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2015-04-22 10:53 - 2009-07-14 06:39 - 00106642 _____ () C:\windows\setupact.log
2015-04-22 10:52 - 2014-01-05 15:59 - 00100602 _____ () C:\windows\PFRO.log
2015-04-22 10:47 - 2014-01-05 20:23 - 00000000 ____D () C:\Program Files\Common Files\McAfee
2015-04-22 10:41 - 2009-09-17 06:11 - 00000000 ____D () C:\ProgramData\McAfee
2015-04-22 10:30 - 2014-12-11 18:00 - 00000000 ____D () C:\Users\Red 1 - Admin\AppData\Roaming\Mozilla
2015-04-21 20:11 - 2014-01-05 20:40 - 00000000 __RSD () C:\Users\Red 1\Documents\McAfee Vaults
2015-04-21 18:36 - 2009-07-14 06:52 - 00000000 ____D () C:\windows\system32\FxsTmp
2015-04-21 18:36 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\tracing
2015-04-21 18:34 - 2015-03-20 12:49 - 04193668 _____ () C:\Users\Red 1 - Admin\Downloads\download_2015-03-20_11-48-54.zip.ecc
2015-04-21 18:34 - 2015-03-20 12:44 - 01597524 _____ () C:\Users\Red 1 - Admin\Downloads\download_2015-03-20_11-44-09.zip.ecc
2015-04-21 18:34 - 2015-03-18 19:56 - 08741604 _____ () C:\Users\Red 1 - Admin\Downloads\mx_ML_MxEasy_en_20140310.pdf.ecc
2015-04-21 18:34 - 2015-03-18 16:46 - 00405092 _____ () C:\Users\Red 1 - Admin\Downloads\MG Controller 140709.pdf.ecc
2015-04-21 18:34 - 2015-03-18 16:43 - 00120132 _____ () C:\Users\Red 1 - Admin\Downloads\cdc_up_product_design_template.doc.ecc
2015-04-21 18:34 - 2015-03-18 13:27 - 00013172 _____ () C:\Users\Red 1 - Admin\Downloads\starnberg monitoring install.xlsx.ecc
2015-04-21 18:34 - 2015-03-17 19:14 - 01326612 _____ () C:\Users\Red 1 - Admin\Downloads\Moxa_White_Paper---Critical_Elements_of_Industrial-
 
Grade_Wireless_Devices.pdf.ecc
2015-04-21 18:34 - 2015-03-17 14:43 - 00133540 _____ () C:\Users\Red 1 - Admin\Downloads\G_IK10_EN_30225J.jpg.ecc
2015-04-21 18:34 - 2015-03-17 14:43 - 00047316 _____ () C:\Users\Red 1 - Admin\Downloads\G_IK10_XX_30225I.jpg.ecc
2015-04-21 18:34 - 2015-03-17 14:33 - 03068068 _____ () C:\Users\Red 1 - Admin\Downloads\Industrial_Wireless_Guidebook_2009 (1).pdf.ecc
2015-04-21 18:34 - 2015-03-17 12:56 - 02910580 _____ () C:\Users\Red 1 - Admin\Downloads\HOMER268Beta.zip.ecc
2015-04-21 18:34 - 2015-03-17 11:29 - 00032516 _____ () C:\Users\Red 1 - Admin\Downloads\SMA5PctComplete_2015-03-11 (1).png.ecc
2015-04-21 18:34 - 2015-03-16 18:57 - 00222436 _____ () C:\Users\Red 1 - Admin\Downloads\documents-export-2015-03-16.zip.ecc
2015-04-21 18:34 - 2015-03-16 18:31 - 00185140 _____ () C:\Users\Red 1 - Admin\Downloads\Step 3.jpg.ecc
2015-04-21 18:34 - 2015-03-16 18:31 - 00178628 _____ () C:\Users\Red 1 - Admin\Downloads\Step 5.jpg.ecc
2015-04-21 18:34 - 2015-03-16 18:31 - 00163892 _____ () C:\Users\Red 1 - Admin\Downloads\Step 4.jpg.ecc
2015-04-21 18:34 - 2015-03-16 18:31 - 00116500 _____ () C:\Users\Red 1 - Admin\Downloads\Step 2.jpg.ecc
2015-04-21 18:34 - 2015-03-16 18:30 - 00194548 _____ () C:\Users\Red 1 - Admin\Downloads\Step 1.jpg.ecc
2015-04-21 18:34 - 2015-03-16 17:50 - 00001956 _____ () C:\Users\Red 1 - Admin\Downloads\dust_measuring_(daily)_Diagram_1 (2).csv.ecc
2015-04-21 18:34 - 2015-03-16 17:47 - 00001828 _____ () C:\Users\Red 1 - Admin\Downloads\dust_measuring_(daily)_Diagram_1 (1).csv.ecc
2015-04-21 18:34 - 2015-03-16 17:43 - 00001828 _____ () C:\Users\Red 1 - Admin\Downloads\dust_measuring_(daily)_Diagram_1.csv.ecc
2015-04-21 18:34 - 2015-03-16 17:42 - 00000708 _____ () C:\Users\Red 1 - Admin\Downloads\Sensor_Sensorbox_724_Diagram_1.csv.ecc
2015-04-21 18:34 - 2015-03-16 11:57 - 00032516 _____ () C:\Users\Red 1 - Admin\Downloads\SMA5PctComplete_2015-03-11.png.ecc
2015-04-21 18:34 - 2015-03-16 11:26 - 00000000 ____D () C:\Users\Red 1 - Admin\Tracing
2015-04-21 18:34 - 2015-03-16 11:14 - 00028692 _____ () C:\Users\Red 1 - Admin\Downloads\Load Pattern Summary_Prospective GENCO Sites_30 VP_Araria.xlsx.ecc
2015-04-21 18:34 - 2015-03-13 16:18 - 00000000 ____D () C:\Users\Red 1 - Admin\Downloads\Kst-plot-kst-build-1874ae9
2015-04-21 18:34 - 2015-03-13 16:16 - 13429428 _____ () C:\Users\Red 1 - Admin\Downloads\Kst-plot-kst-build-1874ae9.zip.ecc
2015-04-21 18:34 - 2015-03-13 15:21 - 00018548 _____ () C:\Users\Red 1 - Admin\Downloads\Intervention capacity improvement (1).xlsx.ecc
2015-04-21 18:34 - 2015-03-12 19:18 - 00058020 _____ () C:\Users\Red 1 - Admin\Downloads\troj (1).png.ecc
2015-04-21 18:34 - 2015-03-12 19:14 - 00049460 _____ () C:\Users\Red 1 - Admin\Downloads\troj.png.ecc
2015-04-21 18:34 - 2015-03-12 19:01 - 00400820 _____ () C:\Users\Red 1 - Admin\Downloads\Getting Started with Red Microgrid Controller Server.docx.ecc
2015-04-21 18:34 - 2015-03-12 18:47 - 00127252 _____ () C:\Users\Red 1 - Admin\Downloads\Main Distribution Substation.jpg.ecc
2015-04-21 18:34 - 2015-03-12 18:38 - 02662132 _____ () C:\Users\Red 1 - Admin\Downloads\IMG_1052 (2).JPG.ecc
2015-04-21 18:34 - 2015-03-10 18:48 - 00395412 _____ () C:\Users\Red 1 - Admin\Downloads\MODBUS-NSM-eng-TUS113513(INTERNAL)_MODBUS Plant Contorl.pdf.ecc
2015-04-21 18:34 - 2015-03-10 15:57 - 00017668 _____ () C:\Users\Red 1 - Admin\Downloads\Intervention capacity improvement.xlsx.ecc
2015-04-21 18:34 - 2015-03-10 12:44 - 00000628 _____ () C:\Users\Red 1 - Admin\Downloads\easylog.txt.ecc
2015-04-21 18:34 - 2015-03-10 11:53 - 03068068 _____ () C:\Users\Red 1 - Admin\Downloads\Industrial_Wireless_Guidebook_2009.pdf.ecc
2015-04-21 18:34 - 2015-03-10 11:52 - 01895140 _____ () C:\Users\Red 1 - Admin\Downloads\Industrial_Wireless_Guidebook_2009_v1.2 (1).zip.ecc
2015-04-21 18:34 - 2015-03-10 11:51 - 01895140 _____ () C:\Users\Red 1 - Admin\Downloads\Industrial_Wireless_Guidebook_2009_v1.2.zip.ecc
2015-04-21 18:34 - 2015-03-09 13:17 - 01626900 _____ () C:\Users\Red 1 - Admin\Downloads\SAV Innovations-SMA NDA (final-012815).pdf.ecc
2015-04-21 18:34 - 2015-03-06 14:14 - 00243636 _____ () C:\Users\Red 1 - Admin\Downloads\CVE-30360_CE_DoC (1).zip.ecc
2015-04-21 18:34 - 2015-03-06 14:12 - 00243636 _____ () C:\Users\Red 1 - Admin\Downloads\CVE-30360_CE_DoC.zip.ecc
2015-04-21 18:34 - 2015-03-04 17:55 - 00000000 ____D () C:\Users\Red 1 - Admin\Downloads\yasdi-1.8.1build9-bin-win32
2015-04-21 18:34 - 2015-03-04 17:54 - 00115764 _____ () C:\Users\Red 1 - Admin\Downloads\yasdi-1.8.1build9-bin-win32.zip.ecc
2015-04-21 18:34 - 2015-03-04 16:55 - 00000000 ____D () C:\Users\Red 1 - Admin\Downloads\wgbitte
2015-04-21 18:34 - 2015-03-04 16:34 - 06509620 _____ () C:\Users\Red 1 - Admin\Downloads\FINAL Solar intermittency Australias clean energy challenge (3).pdf.ecc
2015-04-21 18:34 - 2015-03-04 16:22 - 00221828 _____ () C:\Users\Red 1 - Admin\Downloads\wgbitteumfeedbackzuvdeanwendungsregelpvhybridsyste.zip.ecc
2015-04-21 18:34 - 2015-03-04 11:44 - 00036644 _____ () C:\Users\Red 1 - Admin\Downloads\SMA_2015-03-02.xlsx.ecc
2015-04-21 18:34 - 2015-03-02 12:37 - 00441892 _____ () C:\Users\Red 1 - Admin\Downloads\log4jOutput.zip.ecc
 
2015-04-21 18:34 - 2015-02-27 13:46 - 00147444 _____ () C:\Users\Red 1 - Admin\Downloads\ddi-documentation-english-87.pdf.ecc
2015-04-21 18:34 - 2015-02-27 12:17 - 02662132 _____ () C:\Users\Red 1 - Admin\Downloads\IMG_1052 (1).JPG.ecc
2015-04-21 18:34 - 2015-02-26 15:54 - 02662132 _____ () C:\Users\Red 1 - Admin\Downloads\IMG_1052.JPG.ecc
2015-04-21 18:34 - 2015-02-26 15:51 - 02669924 _____ () C:\Users\Red 1 - Admin\Downloads\IMG_1053.JPG.ecc
2015-04-21 18:34 - 2015-02-25 18:03 - 00742212 _____ () C:\Users\Red 1 - Admin\Downloads\KippZonen_Brochure_Data_Loggers_English_V1206.pdf.ecc
 
2015-04-21 18:34 - 2015-02-18 13:33 - 00049892 _____ () C:\Users\Red 1 - Admin\Downloads\Cover letter.pdf.ecc
2015-04-21 18:34 - 2015-02-18 13:32 - 00016804 _____ () C:\Users\Red 1 - Admin\Downloads\Resume2014.pdf.ecc
2015-04-21 18:34 - 2015-02-18 13:29 - 00179572 _____ () C:\Users\Red 1 - Admin\Downloads\CV-Resume(English).pdf.ecc
2015-04-21 18:34 - 2015-02-18 13:17 - 00097604 _____ () C:\Users\Red 1 - Admin\Downloads\Resume-2015.docx.ecc
2015-04-21 18:34 - 2015-02-18 12:09 - 03033828 _____ () C:\Users\Red 1 - Admin\Downloads\awproduktmwprojektinfo.zip.ecc
2015-04-21 18:34 - 2015-02-17 17:45 - 00024420 _____ () C:\Users\Red 1 - Admin\Downloads\Mustervorlage_Prepaid_Kuendigung_mit_Rufnummernmitnahme (1).DOCX.ecc
2015-04-21 18:34 - 2015-02-17 14:07 - 01279428 _____ () C:\Users\Red 1 - Admin\Downloads\IEA-PVPS_Task_9_-_Innovative_PV_Business_Models_for_Emerging_Regions.pdf.ecc
2015-04-21 18:34 - 2015-02-12 15:48 - 00057284 _____ () C:\Users\Red 1 - Admin\Downloads\CSU_Affiliate_Registration_Form_Signed.pdf.ecc
2015-04-21 18:34 - 2015-02-12 12:09 - 00165652 _____ () C:\Users\Red 1 - Admin\Downloads\SKMBT_C36015021016220.pdf.ecc
2015-04-21 18:34 - 2015-01-26 13:17 - 00476116 _____ () C:\Users\Red 1 - Admin\Downloads\QSK50-DM-1216kW.pdf.ecc
2015-04-21 18:34 - 2015-01-23 13:18 - 00025412 _____ () C:\Users\Red 1 - Admin\Downloads\Lieferschein 351045.pdf.ecc
2015-04-21 18:34 - 2015-01-23 13:17 - 00094804 _____ () C:\Users\Red 1 - Admin\Downloads\Auftragsbestaetigung 3500290-2.pdf.ecc
2015-04-21 18:34 - 2015-01-23 01:38 - 00028132 _____ () C:\Users\Red 1 - Admin\Downloads\Terra yield estimate1 (1).xlsx.ecc
2015-04-21 18:34 - 2015-01-22 17:11 - 00028132 _____ () C:\Users\Red 1 - Admin\Downloads\Terra yield estimate1.xlsx.ecc
2015-04-21 18:34 - 2015-01-22 13:42 - 00081988 _____ () C:\Users\Red 1 - Admin\Downloads\Microgrid Controller.pptx.ecc
2015-04-21 18:34 - 2015-01-21 13:37 - 73049508 _____ () C:\Users\Red 1 - Admin\Downloads\Cluster_Controller_FW_v1_01_16_R.zip.ecc
2015-04-21 18:34 - 2015-01-20 19:27 - 01613396 _____ () C:\Users\Red 1 - Admin\Downloads\KippZonen_InstructionSheet_Pyranometer_SP_Lite2_V1402.pdf.ecc
2015-04-21 18:34 - 2015-01-20 19:08 - 00008180 _____ () C:\Users\Red 1 - Admin\Downloads\Interntasklistandrequirementsjobdescription.docx.ecc
2015-04-21 18:34 - 2015-01-20 19:08 - 00008180 _____ () C:\Users\Red 1 - Admin\Downloads\Interntasklistandrequirementsjobdescription (1).docx.ecc
2015-04-21 18:34 - 2015-01-19 13:02 - 00623652 _____ () C:\Users\Red 1 - Admin\Downloads\SGS Contract Engineering.docx.ecc
2015-04-21 18:34 - 2015-01-15 14:47 - 03768244 _____ () C:\Users\Red 1 - Admin\Downloads\DispatcherLog_Strategy300.7z.ecc
2015-04-21 18:34 - 2015-01-14 12:15 - 00006516 _____ () C:\Users\Red 1 - Admin\Downloads\Inverter_2_(I_and_V)_Diagram_1.csv.ecc
2015-04-21 18:34 - 2015-01-10 12:07 - 00063524 _____ () C:\Users\Red 1 - Admin\Downloads\Konto_1823095-Auszug_2015_002.PDF.ecc
2015-04-21 18:34 - 2015-01-09 14:28 - 00012500 _____ () C:\Users\Red 1 - Admin\Downloads\project plan timelines.xlsx.ecc
2015-04-21 18:34 - 2015-01-09 12:34 - 00018548 _____ () C:\Users\Red 1 - Admin\Downloads\goals 2015.xlsx.ecc
2015-04-21 18:34 - 2015-01-09 11:42 - 00632916 _____ () C:\Users\Red 1 - Admin\Downloads\Simulation Examples (2).docx.ecc
2015-04-21 18:34 - 2015-01-08 12:05 - 00316916 _____ () C:\Users\Red 1 - Admin\Downloads\PV-Hybrid_Simulation and Financials_SHA002_Red GmbH 1 MW.pdf.ecc
2015-04-21 18:34 - 2015-01-06 15:05 - 00019044 _____ () C:\Users\Red 1 - Admin\Downloads\predicted yield.xlsx.ecc
2015-04-21 18:34 - 2015-01-05 15:54 - 00007028 _____ () C:\Users\Red 1 - Admin\Downloads\Inverter_1_(I_and_V)_Diagramm_1.csv.ecc
2015-04-21 18:34 - 2015-01-02 17:34 - 00012612 _____ () C:\Users\Red 1 - Admin\Downloads\Capex Information.specs.xlsx.ecc
2015-04-21 18:34 - 2015-01-02 17:34 - 00012612 _____ () C:\Users\Red 1 - Admin\Downloads\Capex Information.specs (1).xlsx.ecc
2015-04-21 18:34 - 2014-12-31 14:47 - 00632916 _____ () C:\Users\Red 1 - Admin\Downloads\Simulation Examples (1).docx.ecc
2015-04-21 18:34 - 2014-12-31 12:50 - 00495316 _____ () C:\Users\Red 1 - Admin\Downloads\C88UPV.pdf.ecc
2015-04-21 18:34 - 2014-12-31 12:19 - 05186676 _____ () C:\Users\Red 1 - Admin\Downloads\Rechnungen-2014-12-31.zip.ecc
2015-04-21 18:34 - 2014-12-30 17:31 - 00024420 _____ () C:\Users\Red 1 - Admin\Downloads\Mustervorlage_Prepaid_Kuendigung_mit_Rufnummernmitnahme.DOCX.ecc
2015-04-21 18:34 - 2014-12-30 17:31 - 00015924 _____ () C:\Users\Red 1 - Admin\Downloads
 
\Mustervorlage_Mobilfunkvertrag_Kuendigung_und_sofortige_Rufnummernmitnahme.docx.ecc
2015-04-21 18:34 - 2014-12-29 18:55 - 00005172 _____ () C:\Users\Red 1 - Admin\Downloads\SampleRun (1).zip.ecc
2015-04-21 18:34 - 2014-12-29 15:45 - 00168372 _____ () C:\Users\Red 1 - Admin\Downloads\US_Visa.jpg.ecc
2015-04-21 18:34 - 2014-12-29 15:45 - 00138836 _____ () C:\Users\Red 1 - Admin\Downloads\eu_passbild.jpg.ecc
2015-04-21 18:34 - 2014-12-29 13:57 - 00005172 _____ () C:\Users\Red 1 - Admin\Downloads\SampleRun.zip.ecc
2015-04-21 18:34 - 2014-12-26 14:50 - 00053108 _____ () C:\Users\Red 1 - Admin\Downloads\DEUMI0312214.pdf.ecc
2015-04-21 18:34 - 2014-12-25 19:48 - 02312372 _____ () C:\Users\Red 1 - Admin\Downloads\vg-newswire-july-aug-21102014.pdf.ecc
2015-04-21 18:34 - 2014-12-25 19:42 - 06979028 _____ () C:\Users\Red 1 - Admin\Downloads\Cold Storage.pptx.ecc
2015-04-21 18:34 - 2014-12-22 14:15 - 04268500 _____ () C:\Users\Red 1 - Admin\Downloads\IEA-PVPS_T13-D2_3_Analytical_Monitoring_of_PV_Systems_Final.pdf.ecc
2015-04-21 18:34 - 2014-12-22 11:48 - 00632916 _____ () C:\Users\Red 1 - Admin\Downloads\Simulation Examples.docx.ecc
2015-04-21 18:34 - 2014-12-18 16:27 - 00008788 _____ () C:\Users\Red 1 - Admin\Downloads\BluePoint Comments (2).xlsx.ecc
2015-04-21 18:34 - 2014-12-18 16:22 - 00002724 _____ () C:\Users\Red 1 - Admin\Downloads\Serial_Numbers.csv.ecc
2015-04-21 18:34 - 2014-12-18 16:10 - 00022932 _____ () C:\Users\Red 1 - Admin\Downloads\Red Flash Data & serial numbers (1).xlsx.ecc
2015-04-21 18:34 - 2014-12-17 18:21 - 00098196 _____ () C:\Users\Red 1 - Admin\Downloads\OF_9005574_Red_FSC 1.pdf.ecc
2015-04-21 18:34 - 2014-12-17 13:16 - 00232276 _____ () C:\Users\Red 1 - Admin\Downloads\office work.mp4.ecc
2015-04-21 18:34 - 2014-12-16 13:18 - 00011076 _____ () C:\Users\Red 1 - Admin\Downloads\Systems Comparision.xlsx.ecc
2015-04-21 18:34 - 2014-12-15 18:08 - 00064164 _____ () C:\Users\Red 1 - Admin\Downloads\MW Layout Plant (1).dwg.ecc
2015-04-21 18:34 - 2014-12-15 17:51 - 00064164 _____ () C:\Users\Red 1 - Admin\Downloads\MW Layout Plant.dwg.ecc
2015-04-21 18:34 - 2014-12-12 12:01 - 00010756 _____ () C:\Users\Red 1 - Admin\Downloads\BluePoint Comments.xlsx (2).xlsx.ecc
2015-04-21 18:34 - 2014-12-12 12:00 - 00010244 _____ () C:\Users\Red 1 - Admin\Downloads\BluePoint Comments (1).xlsx.ecc
2015-04-21 18:34 - 2014-12-11 17:53 - 00464932 _____ () C:\Users\Red 1 - Admin\Downloads\Load Modeling for Red Mine Project (2).docx.ecc
2015-04-21 18:34 - 2014-12-11 13:40 - 01420932 _____ () C:\Users\Red 1 - Admin\Downloads\ECO40_4pole.pdf.ecc
2015-04-21 18:34 - 2014-12-11 11:41 - 01534292 _____ () C:\Users\Red 1 - Admin\Downloads\IMG_0373.JPG.ecc
2015-04-21 18:34 - 2014-12-11 11:39 - 02018500 _____ () C:\Users\Red 1 - Admin\Downloads\IMG_0371.JPG.ecc
2015-04-21 18:34 - 2014-12-10 18:57 - 00067604 _____ () C:\Users\Red 1 - Admin\Downloads\Diesel_Hybrid_Questionnaire_V_0 20_2007-2014 (1).xlsx.ecc
2015-04-21 18:34 - 2014-12-10 18:44 - 00066276 _____ () C:\Users\Red 1 - Admin\Downloads\Diesel_Hybrid_Questionnaire_V_0 20_2007-2014.xlsx.ecc
2015-04-21 18:34 - 2014-12-10 18:24 - 00015796 _____ () C:\Users\Red 1 - Admin\Downloads\New Luika Serial Numbers.xlsx.ecc
2015-04-21 18:34 - 2014-12-10 16:15 - 00457732 _____ () C:\Users\Red 1 - Admin\Downloads\Load Modeling for Red Mine Project.docx.ecc
2015-04-21 18:34 - 2014-12-10 13:22 - 00022932 _____ () C:\Users\Red 1 - Admin\Downloads\Red Flash Data & serial numbers.xlsx.ecc
2015-04-21 18:34 - 2014-12-09 17:33 - 00007956 _____ () C:\Users\Red 1 - Admin\Downloads\BluePoint Comments.xlsx (1) (1).xlsx.ecc
2015-04-21 18:34 - 2014-12-09 17:30 - 00007956 _____ () C:\Users\Red 1 - Admin\Downloads\BluePoint Comments.xlsx (1).xlsx.ecc
2015-04-21 18:34 - 2014-12-09 16:21 - 00008708 _____ () C:\Users\Red 1 - Admin\Downloads\Book1.xlsx.ecc
2015-04-21 18:34 - 2014-12-09 16:21 - 00008708 _____ () C:\Users\Red 1 - Admin\Downloads\Book1 (1).xlsx.ecc
2015-04-21 18:34 - 2014-12-09 16:03 - 00010244 _____ () C:\Users\Red 1 - Admin\Downloads\BluePoint Comments.xlsx.ecc
2015-04-21 18:34 - 2014-12-09 16:03 - 00007748 _____ () C:\Users\Red 1 - Admin\Downloads\BluePoint Comments.xlsx.xlsx.ecc
2015-04-21 18:34 - 2014-12-08 19:50 - 00105684 _____ () C:\Users\Red 1 - Admin\Downloads\IMG_0608.JPG.ecc
2015-04-21 18:34 - 2014-01-27 21:23 - 00000000 ____D () C:\Users\Red 1 - Admin
2015-04-21 18:33 - 2015-03-18 19:45 - 00018260 _____ () C:\Users\Red 1 - Admin\Downloads\150318_2015-01 Schedule Update  (1).xlsx.ecc
2015-04-21 18:33 - 2015-03-18 19:42 - 00018276 _____ () C:\Users\Red 1 - Admin\Downloads\150318_2015-01 Schedule Update .xlsx.ecc
2015-04-21 18:33 - 2015-03-18 14:37 - 00227892 _____ () C:\Users\Red 1 - Admin\Downloads\150115_Dan_PVPenetrationResults.docx (1).docx.ecc
2015-04-21 18:33 - 2015-03-18 14:23 - 00012788 _____ () C:\Users\Red 1 - Admin\Downloads\2015-01 Schedule Update v3 and QA and Testing considerations (2).xlsx.ecc
2015-04-21 18:33 - 2015-03-18 14:17 - 00227892 _____ () C:\Users\Red 1 - Admin\Downloads\150115_Dan_PVPenetrationResults.docx.docx.ecc
2015-04-21 18:33 - 2015-03-17 14:03 - 00599348 _____ () C:\Users\Red 1 - Admin\Downloads\ASC Plant Management data sheet 4921240459 UK_2014.10.21 (1).pdf.ecc
2015-04-21 18:33 - 2015-03-17 14:00 - 00200228 _____ () C:\Users\Red 1 - Admin\Downloads\ASC Plant Management handout (UK) (1).pdf.ecc
2015-04-21 18:33 - 2015-03-16 18:38 - 01932724 _____ () C:\Users\Red 1 - Admin\Downloads\121016_P11_1046_RU01 (1).pdf.ecc
2015-04-21 18:33 - 2015-03-16 16:08 - 00016452 _____ () C:\Users\Red 1 - Admin\Downloads\2015-01 Schedule Update v3 and QA and Testing considerations (1).xlsx.ecc
2015-04-21 18:33 - 2015-03-16 16:03 - 00012788 _____ () C:\Users\Red 1 - Admin\Downloads\2015-01 Schedule Update v3 and QA and Testing considerations.xlsx.ecc
2015-04-21 18:33 - 2015-03-16 11:09 - 01932724 _____ () C:\Users\Red 1 - Admin\Downloads\121016_P11_1046_RU01.pdf.ecc
2015-04-21 18:33 - 2015-03-13 17:30 - 00011556 _____ () C:\Users\Red 1 - Admin\Documents\130315_Ping_NLGM8logger.txt.ecc
2015-04-21 18:33 - 2015-03-04 18:34 - 00011156 _____ () C:\Users\Red 1 - Admin\Downloads\2015-01 Schedule Update v1 (1).xlsx.ecc
2015-04-21 18:33 - 2015-03-04 15:02 - 00290100 _____ () C:\Users\Red 1 - Admin\Downloads\20150304_Otti_640811 (1).pdf.ecc
2015-04-21 18:33 - 2015-03-04 15:02 - 00284404 _____ () C:\Users\Red 1 - Admin\Downloads\20150304_Otti_640811_2 (1).pdf.ecc
2015-04-21 18:33 - 2015-03-04 14:53 - 00290100 _____ () C:\Users\Red 1 - Admin\Downloads\20150304_Otti_640811.pdf.ecc
2015-04-21 18:33 - 2015-03-04 14:53 - 00284404 _____ () C:\Users\Red 1 - Admin\Downloads\20150304_Otti_640811_2.pdf.ecc
2015-04-21 18:33 - 2015-02-25 17:25 - 00177812 _____ () C:\Users\Red 1 - Admin\Documents\2014-01-07 - cloud projection.png.ecc
2015-04-21 18:33 - 2015-02-25 16:48 - 00703892 _____ () C:\Users\Red 1 - Admin\Downloads\2015FEB_Study_Renewables_as_Leverage_in_Negotiations.pdf.ecc
2015-04-21 18:33 - 2015-02-25 16:26 - 01404820 _____ () C:\Users\Red 1 - Admin\Downloads\150219_Solar_Eclipse_Impact_Analysis_Final.pdf.ecc
2015-04-21 18:33 - 2015-02-24 19:47 - 00355764 _____ () C:\Users\Red 1 - Admin\Downloads\antragaufenthaltstitel.pdf.ecc
2015-04-21 18:33 - 2015-02-23 19:53 - 00599348 _____ () C:\Users\Red 1 - Admin\Downloads\ASC Plant Management data sheet 4921240459 UK_2014.10.21.pdf.ecc
2015-04-21 18:33 - 2015-02-23 19:51 - 00200228 _____ () C:\Users\Red 1 - Admin\Downloads\ASC Plant Management handout (UK).pdf.ecc
2015-04-21 18:33 - 2015-02-23 19:47 - 00727732 _____ () C:\Users\Red 1 - Admin\Downloads\ASC PM data sheet.pdf.ecc
2015-04-21 18:33 - 2015-02-23 19:47 - 00541972 _____ () C:\Users\Red 1 - Admin\Downloads\4352880101e_Project_application.pdf.ecc
 
2015-04-21 18:33 - 2015-02-16 17:54 - 00013876 _____ () C:\Users\Red 1 - Admin\Downloads\2015-01 Schedule Update v3.xlsx.ecc
2015-04-21 18:33 - 2015-02-13 14:42 - 11565988 _____ () C:\Users\Red 1 - Admin\Downloads\2014-01-03- cloud projection.csv.ecc
2015-04-21 18:33 - 2015-01-23 13:19 - 00094804 _____ () C:\Users\Red 1 - Admin\Downloads\Auftragsbestaetigung 3500290-2 (1).pdf.ecc
2015-04-21 18:33 - 2015-01-23 12:42 - 00011156 _____ () C:\Users\Red 1 - Admin\Downloads\2015-01 Schedule Update v1.xlsx.ecc
2015-04-21 18:33 - 2015-01-23 01:21 - 00133732 _____ () C:\Users\Red 1 - Admin\Downloads\ActivePowerModbusControl.jpg.ecc
2015-04-21 18:33 - 2015-01-21 19:58 - 00095092 _____ () C:\Users\Red 1 - Admin\Downloads\2 cluster controller status.png.ecc
2015-04-21 18:33 - 2015-01-21 18:56 - 00024820 _____ () C:\Users\Red 1 - Admin\Downloads\Abrechnung_4917828510165150_20150107.PDF.ecc
2015-04-21 18:33 - 2015-01-19 13:58 - 00099364 _____ () C:\Users\Red 1 - Admin\Downloads\Analysis of Simulation Results.docx.ecc
2015-04-21 18:33 - 2015-01-15 17:56 - 00028500 _____ () C:\Users\Red 1 - Admin\Documents\Datalogging Caution Labels.docx.ecc
2015-04-21 18:33 - 2015-01-13 18:02 - 03872548 _____ () C:\Users\Red 1 - Admin\Downloads\07_UMFO-U4-002_Kontoeröffnungsantrag_SDRS_Version_0015.pdf.ecc
2015-04-21 18:33 - 2015-01-13 17:29 - 00010964 _____ () C:\Users\Red 1 - Admin\Downloads\20150113_RFQ_Sonepar.xlsx.ecc
2015-04-21 18:33 - 2015-01-12 11:36 - 00000000 ____D () C:\Users\Red 1 - Admin\Documents\DENT
2015-04-21 18:33 - 2015-01-07 11:51 - 10347556 _____ () C:\Users\Red 1 - Admin\Downloads\20141002_Minute Load Calculator.xlsx.ecc
2015-04-21 18:33 - 2015-01-07 11:45 - 08369796 _____ () C:\Users\Red 1 - Admin\Downloads\20141002_Hourly Load Calculator.xlsx.ecc
2015-04-21 18:33 - 2015-01-07 11:45 - 00024964 _____ () C:\Users\Red 1 - Admin\Downloads\20141008_Hourly simulation handbook.docx.ecc
 
2015-04-21 18:33 - 2014-12-22 18:35 - 00928276 _____ () C:\Users\Red 1 - Admin\Downloads\3E_White_Paper_Beyond_Standard_Monitoring_Practice.pdf.ecc
2015-04-21 18:33 - 2014-12-22 15:59 - 04085332 _____ () C:\Users\Red 1 - Admin\Downloads\20120427_Silverlake load profile v5.xlsx.ecc
2015-04-21 18:33 - 2014-12-22 12:40 - 00137028 _____ () C:\Users\Red 1 - Admin\Downloads\2014-07-11_ARE_Membership_Form_FINAL.docx.ecc
2015-04-21 18:33 - 2014-12-18 14:04 - 00108356 _____ () C:\Users\Red 1 - Admin\Downloads\140704 Asset Database (2).xls.ecc
2015-04-21 18:33 - 2014-12-16 18:09 - 00078148 _____ () C:\Users\Red 1 - Admin\Downloads\140704 Asset Database (1).xls.ecc
2015-04-21 18:33 - 2014-12-15 17:48 - 00106772 _____ () C:\Users\Red 1 - Admin\Downloads\140404_Single_Container_Plant_Layout.pdf.ecc
2015-04-21 18:33 - 2014-12-15 16:20 - 02352948 _____ () C:\Users\Red 1 - Admin\Downloads\141211 Precontract Visit TERRA (1).pdf.ecc
2015-04-21 18:33 - 2014-12-15 16:17 - 01043748 _____ () C:\Users\Red 1 - Admin\Downloads\141209 Precontract Visit SGS (1).pdf.ecc
2015-04-21 18:33 - 2014-12-15 16:07 - 01043748 _____ () C:\Users\Red 1 - Admin\Downloads\141209 Precontract Visit SGS.pdf.ecc
2015-04-21 18:33 - 2014-12-15 11:23 - 00012852 _____ () C:\Users\Red 1 - Admin\Downloads\20141212_travel and sales force mngt automation.xlsx.ecc
2015-04-21 18:33 - 2014-12-12 17:19 - 02352948 _____ () C:\Users\Red 1 - Admin\Downloads\141211 Precontract Visit TERRA.pdf.ecc
 
2015-04-21 18:33 - 2014-12-11 19:41 - 00011732 _____ () C:\Users\Red 1 - Admin\Downloads\20141023_Digitising Data.xlsx.ecc
2015-04-21 18:33 - 2014-12-11 18:01 - 00000000 __SHD () C:\Users\Red 1 - Admin\Documents\cache
2015-04-21 18:33 - 2014-12-10 15:00 - 00078148 _____ () C:\Users\Red 1 - Admin\Downloads\140704 Asset Database.xls.ecc
2015-04-21 18:33 - 2014-12-09 18:52 - 00000000 ____D () C:\Users\Red 1 - Admin\Documents\KEW
2015-04-21 18:33 - 2014-12-09 15:59 - 00086068 _____ () C:\Users\Red 1 - Admin\Downloads\20140404_Framework Commercial Management Agreement - SV1.pdf.ecc
2015-04-21 18:33 - 2014-12-09 15:50 - 00161748 _____ () C:\Users\Red 1 - Admin\Downloads\20140404_Framework Operational Management Agreement - SV1.pdf.ecc
 
2015-04-21 18:33 - 2014-03-18 18:07 - 00000000 ____D () C:\Users\Red 1 - Admin\Documents\PDF Architect Files
2015-04-21 18:28 - 2014-05-05 22:00 - 00000000 ____D () C:\Users\Red 1 - Admin\AppData\Roaming\Skype
2015-04-21 18:00 - 2014-07-17 16:57 - 00000000 ___RD () C:\Users\Red 1\New folder
2015-04-21 18:00 - 2014-03-26 11:48 - 00000000 ____D () C:\Users\Red 1\Tracing
2015-04-21 18:00 - 2014-03-26 11:40 - 00000000 ___RD () C:\Users\Red 1\OneDrive
2015-04-21 18:00 - 2014-02-21 15:59 - 00272196 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image2.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00111668 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image1.jpg.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000612 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image30.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000580 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image58.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000564 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image44.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000564 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image16.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000548 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image15.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000532 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image27.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000532 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image24.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000516 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image26.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000516 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image23.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000516 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image14.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000516 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image12.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000500 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image9.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000500 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image6.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000500 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image57.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000500 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image55.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000500 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image54.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000500 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image41.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000500 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image40.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000500 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image35.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000500 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image29.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000500 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image22.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000484 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image7.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000484 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image52.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000484 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image51.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000484 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image43.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000484 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image21.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000484 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image17.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000484 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image13.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000484 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image11.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000468 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image8.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000468 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image10.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000452 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image56.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000452 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image50.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000452 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image5.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000452 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image46.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000452 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image42.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000452 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image36.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000452 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image28.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000452 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image25.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000452 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image20.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000436 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image49.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000436 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image4.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000436 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image39.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000436 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image37.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000436 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image32.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000436 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image19.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000420 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image53.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000420 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image48.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000420 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image45.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000420 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image38.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000420 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image34.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000420 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image33.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000420 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image18.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000404 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image47.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000404 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image31.png.ecc
2015-04-21 18:00 - 2014-02-21 15:59 - 00000372 _____ () C:\Users\Red 1\TCO_WP_CRM Outsiders_DE_page16_image3.png.ecc
2015-04-21 18:00 - 2014-01-05 15:26 - 00000000 ____D () C:\Users\Red 1
2015-04-21 17:54 - 2014-10-31 15:25 - 00000868 _____ () C:\Users\Red 1\Downloads\Riso_Values_Diagram_3.csv.ecc
2015-04-21 17:54 - 2014-10-31 14:53 - 00017972 _____ () C:\Users\Red 1\Downloads\20141030_Storage Issue Tree.docx.ecc
2015-04-21 17:54 - 2014-10-31 11:51 - 00092484 _____ () C:\Users\Red 1\Downloads\SHA001 SLD.pdf.ecc
2015-04-21 17:54 - 2014-10-31 11:41 - 00272612 _____ () C:\Users\Red 1\Downloads\Red_Island_SLD.pdf.ecc
2015-04-21 17:54 - 2014-10-31 10:50 - 00189844 _____ () C:\Users\Red 1\Downloads\01-09-2014.csv.ecc
2015-04-21 17:54 - 2014-10-31 10:49 - 00190324 _____ () C:\Users\Red 1\Downloads\06-09-2014.csv.ecc
2015-04-21 17:54 - 2014-10-23 11:41 - 00262676 _____ () C:\Users\Red 1\Downloads\photo 2 (2).JPG.ecc
2015-04-21 17:54 - 2014-10-23 11:41 - 00240308 _____ () C:\Users\Red 1\Downloads\photo 1 (1).JPG.ecc
2015-04-21 17:54 - 2014-10-17 14:52 - 00262676 _____ () C:\Users\Red 1\Downloads\photo 2.JPG.ecc
2015-04-21 17:54 - 2014-10-17 14:52 - 00262676 _____ () C:\Users\Red 1\Downloads\photo 2 (1).JPG.ecc
2015-04-21 17:54 - 2014-10-17 14:52 - 00240308 _____ () C:\Users\Red 1\Downloads\photo 1.JPG.ecc
2015-04-21 17:54 - 2014-10-15 11:20 - 04678900 _____ () C:\Users\Red 1\Downloads\RZ.LOGO_CMYK.jpg.ecc
2015-04-21 17:54 - 2014-10-02 12:03 - 00699204 _____ () C:\Users\Red 1\Downloads\ercexam.ppt.ecc
2015-04-21 17:54 - 2014-09-19 15:35 - 00275092 _____ () C:\Users\Red 1\Downloads\MSNA20140304648196.pdf.ecc
2015-04-21 17:54 - 2014-09-16 14:17 - 00364836 _____ () C:\Users\Red 1\Downloads\140829_Exergeia_Fellowship_Post_EXT (2) (2).pdf.ecc
2015-04-21 17:54 - 2014-09-15 11:54 - 02778532 _____ () C:\Users\Red 1\Downloads\radwx_077450895.csv (2).tar.gz.ecc
2015-04-21 17:54 - 2014-09-15 09:37 - 02778532 _____ () C:\Users\Red 1\Downloads\radwx_077450895.csv (1).tar.gz.ecc
2015-04-21 17:54 - 2014-09-09 11:51 - 00273220 _____ () C:\Users\Red 1\Downloads\GTG_1595OEM_Wart_8R32D.doc.ecc
2015-04-21 17:54 - 2014-09-09 11:49 - 01529668 _____ () C:\Users\Red 1\Downloads\GTG_1628OEM_Wartsila18V32_60Hz.doc.ecc
2015-04-21 17:54 - 2014-09-09 11:49 - 00287556 _____ () C:\Users\Red 1\Downloads\GTG_1594OEM_Wart_8R32LN.doc.ecc
2015-04-21 17:54 - 2014-09-09 11:48 - 00237380 _____ () C:\Users\Red 1\Downloads\GTG_1592OEM_Wart_9L20 (1).doc.ecc
2015-04-21 17:54 - 2014-09-09 11:48 - 00217412 _____ () C:\Users\Red 1\Downloads\GTG_1593OEM_Wart_6R32.doc.ecc
2015-04-21 17:54 - 2014-09-09 11:46 - 00395076 _____ () C:\Users\Red 1\Downloads\GTG_1486OEM_ Wartsila_9R32.doc.ecc
2015-04-21 17:54 - 2014-09-09 11:29 - 00237380 _____ () C:\Users\Red 1\Downloads\GTG_1592OEM_Wart_9L20.doc.ecc
2015-04-21 17:54 - 2014-09-09 11:05 - 00720932 _____ () C:\Users\Red 1\Downloads\198423_24 MW HFO Plan (3).pdf.ecc
2015-04-21 17:54 - 2014-09-08 12:28 - 00635060 _____ () C:\Users\Red 1\Downloads\aggreko generator report shanta -140830.xlsx.ecc
2015-04-21 17:54 - 2014-09-08 09:41 - 00364836 _____ () C:\Users\Red 1\Downloads\140829_Exergeia_Fellowship_Post_EXT (2) (1).pdf.ecc
2015-04-21 17:54 - 2014-09-08 09:38 - 00364836 _____ () C:\Users\Red 1\Downloads\140829_Exergeia_Fellowship_Post_EXT (2).pdf.ecc
2015-04-21 17:54 - 2014-09-03 16:56 - 00053044 _____ () C:\Users\Red 1\Downloads\2014_EmergencyNumbers.pdf.ecc
2015-04-21 17:54 - 2014-09-02 15:53 - 00089412 _____ () C:\Users\Red 1\Downloads\Fuel consumption, CO2 and C calculator (1).xls.ecc
2015-04-21 17:54 - 2014-09-02 15:51 - 00089412 _____ () C:\Users\Red 1\Downloads\Fuel consumption, CO2 and C calculator.xls.ecc
2015-04-21 17:54 - 2014-09-01 13:18 - 05940772 _____ () C:\Users\Red 1\Downloads\joined_document_10.pdf.ecc
2015-04-21 17:54 - 2014-09-01 13:04 - 14239380 _____ () C:\Users\Red 1\Downloads\20140430_AssetCo+Capital+Increase+contract.1-38.pdf.ecc
2015-04-21 17:54 - 2014-08-27 16:11 - 01321204 _____ () C:\Users\Red 1\Downloads\20130321_NEW001+Rental+Agreement.1-3.pdf.ecc
2015-04-21 17:54 - 2014-08-26 15:21 - 00084212 _____ () C:\Users\Red 1\Downloads\20120415_Advisor Agreement Pluriomics BV - GMBH - NYCS.pdf.ecc
2015-04-21 17:54 - 2014-08-20 14:59 - 00000740 _____ () C:\Users\Red 1\Downloads\MonthlyRadiation085400S_332700E.txt.ecc
2015-04-21 17:54 - 2014-08-20 14:58 - 00003316 _____ () C:\Users\Red 1\Downloads\dailyrad085400S_332700E_20deg_0deg.txt.ecc
2015-04-21 17:54 - 2014-08-19 10:56 - 03353572 _____ () C:\Users\Red 1\Downloads\cdo-1.6.4-win32.zip.ecc
2015-04-21 17:54 - 2014-08-18 16:36 - 02778532 _____ () C:\Users\Red 1\Downloads\radwx_077450895.csv.tar.gz.ecc
2015-04-21 17:54 - 2014-08-18 16:04 - 01038628 _____ () C:\Users\Red 1\Downloads\tiruchchirapalli_433440.zip.ecc
2015-04-21 17:54 - 2014-08-18 15:57 - 09743700 _____ () C:\Users\Red 1\Downloads\Monthly_DNI.zip.ecc
2015-04-21 17:54 - 2014-08-18 15:13 - 00002708 _____ () C:\Users\Red 1\Downloads\dailyrad082938S_351319E_0deg_0deg.txt.ecc
2015-04-21 17:54 - 2014-08-18 14:02 - 00000000 ____D () C:\Users\Red 1\Documents\{5FC9B800-1F37-4ACE-B1B0-2438B740F98E}
2015-04-21 17:54 - 2014-08-18 13:56 - 01252116 _____ () C:\Users\Red 1\Downloads\463-1898-1-PB.pdf.ecc
2015-04-21 17:54 - 2014-08-18 09:40 - 00053060 _____ () C:\Users\Red 1\Downloads\Enclosure 2.xls.ecc
2015-04-21 17:54 - 2014-08-18 09:35 - 01563972 _____ () C:\Users\Red 1\Downloads\Oil-Power-Plants.pdf.ecc
2015-04-21 17:54 - 2014-08-18 09:35 - 01563972 _____ () C:\Users\Red 1\Downloads\Oil-Power-Plants (1).pdf.ecc
2015-04-21 17:54 - 2014-08-13 15:51 - 00720932 _____ () C:\Users\Red 1\Downloads\198423_24 MW HFO Plan (2).pdf.ecc
2015-04-21 17:54 - 2014-08-13 12:48 - 00320772 _____ () C:\Users\Red 1\Downloads\MA-thesis Charis_Chrysopoulos Sulphur directive.docx.ecc
2015-04-21 17:54 - 2014-08-12 17:19 - 00720932 _____ () C:\Users\Red 1\Downloads\198423_24 MW HFO Plan (1).pdf.ecc
2015-04-21 17:54 - 2014-08-12 12:03 - 00793700 _____ () C:\Users\Red 1\Downloads\wp-2-report-5-energy-demand-and-emissions-of-marine-engines.pdf.ecc
2015-04-21 17:54 - 2014-08-12 11:58 - 00720932 _____ () C:\Users\Red 1\Downloads\198423_24 MW HFO Plan.pdf.ecc
2015-04-21 17:54 - 2014-08-05 13:05 - 00680596 _____ () C:\Users\Red 1\Downloads\INPS0028.csv.ecc
2015-04-21 17:54 - 2014-07-29 14:52 - 00109460 _____ () C:\Users\Red 1\Downloads\CPG-Rental-Specs-and-Sizing-Chart.pdf.ecc
2015-04-21 17:54 - 2014-07-17 15:57 - 09007028 _____ () C:\Users\Red 1\Downloads\Load data 27 and 28.zip.ecc
2015-04-21 17:54 - 2014-07-17 15:53 - 00000000 ____D () C:\Users\Red 1\Documents\KEW
2015-04-21 17:54 - 2014-07-17 14:35 - 09045300 _____ () C:\Users\Red 1\Downloads\data group 1 thermal eng_v10.xlsx.ecc
2015-04-21 17:54 - 2014-07-15 14:52 - 04133492 _____ () C:\Users\Red 1\Downloads\joined_document.pdf.ecc
2015-04-21 17:54 - 2014-07-14 12:20 - 04622148 _____ () C:\Users\Red 1\Downloads\fellowship_programme_sids_2014_application_form_final.doc.ecc
2015-04-21 17:54 - 2014-07-10 16:47 - 00228436 _____ () C:\Users\Red 1\Downloads\T1017.pdf.ecc
2015-04-21 17:54 - 2014-07-10 13:03 - 05013316 _____ () C:\Users\Red 1\Downloads\index_html.doc.ecc
2015-04-21 17:54 - 2014-07-10 09:53 - 00906676 _____ () C:\Users\Red 1\Downloads\605-1821-1-SM.pdf.ecc
2015-04-21 17:54 - 2014-07-08 14:25 - 00022532 _____ () C:\Users\Red 1\Downloads\Patent Search.xlsx.ecc
2015-04-21 17:54 - 2014-07-08 14:24 - 00000484 _____ () C:\Users\Red 1\Downloads\~$Patent Search.xlsx.ecc
2015-04-21 17:54 - 2014-07-08 11:14 - 00178708 _____ () C:\Users\Red 1\Downloads\0910-0009 pdf.pdf.ecc
2015-04-21 17:54 - 2014-07-07 15:33 - 05169476 _____ () C:\Users\Red 1\Downloads\chpt11_2.ppt.ecc
2015-04-21 17:54 - 2014-07-07 14:21 - 00617652 _____ () C:\Users\Red 1\Downloads\career-flyer-web.pdf.ecc
2015-04-21 17:54 - 2014-05-13 12:13 - 00000484 ____H () C:\Users\Red 1\Downloads\~$rketing Manager National Geographic Channels (1).docx.ecc
2015-04-21 17:53 - 2014-09-21 20:47 - 00000484 ____H () C:\Users\Red 1\Desktop\~$20140908_Method II Minute Load Calculator .xlsx.ecc
2015-04-21 17:53 - 2014-09-12 14:58 - 00000000 ____D () C:\Users\Red 1\Desktop\KEW Software
2015-04-21 17:53 - 2014-08-25 09:31 - 00000000 ____D () C:\Users\Red 1\Desktop\Back up folder
2015-04-21 17:53 - 2014-08-18 14:06 - 00000000 ____D () C:\Users\Red 1\AppData\Roaming\Macrovision
2015-04-21 17:53 - 2014-07-24 14:27 - 00000000 ___RD () C:\Users\Red 1\Desktop\Desktop Icons
2015-04-21 17:53 - 2014-07-22 15:14 - 00967284 _____ () C:\Users\Red 1\Documents\Book1.xlsx.ecc
2015-04-21 17:53 - 2014-07-15 15:12 - 00000000 ____D () C:\Users\Red 1\Documents\15.7 Scan
2015-04-21 17:53 - 2014-07-15 13:33 - 00000000 ____D () C:\Users\Red 1\AppData\Roaming\inkscape
2015-04-21 17:53 - 2014-05-04 17:59 - 00000000 ____D () C:\Users\Red 1\AppData\Roaming\PDAppFlex
2015-04-21 17:53 - 2014-05-03 17:01 - 00000000 ____D () C:\Users\Red 1\AppData\Roaming\com.adobe.formscentral.FormsCentralForAcrobat
2015-04-21 17:53 - 2014-03-27 18:18 - 00000000 ____D () C:\Users\Red 1\AppData\Roaming\Notepad++
2015-04-21 17:53 - 2014-03-18 18:12 - 00000000 ____D () C:\Users\Red 1\AppData\Roaming\PDF Architect
2015-04-21 17:53 - 2014-03-18 12:56 - 00000000 ____D () C:\Users\Red 1\AppData\Roaming\HpUpdate
2015-04-21 17:53 - 2014-03-05 18:35 - 00000000 ____D () C:\Users\Red 1\AppData\Roaming\PDF Writer
2015-04-21 17:53 - 2014-01-27 21:28 - 00000000 ____D () C:\Users\Red 1\AppData\Roaming\WinRAR
2015-04-21 17:53 - 2014-01-27 21:26 - 00000000 ____D () C:\Users\Red 1\AppData\Roaming\Skype
2015-04-21 17:53 - 2014-01-08 13:17 - 00000000 ____D () C:\Users\Red 1\AppData\Roaming\Nitro PDF
2015-04-21 17:53 - 2014-01-05 21:31 - 00000000 ____D () C:\Users\Red 1\AppData\Roaming\Nitro
2015-04-21 17:53 - 2014-01-05 21:30 - 00000000 ____D () C:\Users\Red 1\AppData\Roaming\Downloaded Installations
2015-04-21 17:53 - 2014-01-05 20:51 - 00000000 ____D () C:\Users\Red 1\AppData\Roaming\Macromedia
2015-04-21 17:53 - 2014-01-05 15:38 - 00000000 ____D () C:\Users\Red 1\AppData\Roaming\Hewlett-Packard
2015-04-21 17:53 - 2014-01-05 15:36 - 00000000 ____D () C:\Users\Red 1\AppData\Roaming\HP TCS
2015-04-21 17:53 - 2014-01-05 15:28 - 00000000 ____D () C:\Users\Red 1\AppData\Roaming\InstallShield
2015-04-21 17:53 - 2014-01-05 15:26 - 00000000 ___RD () C:\Users\Red 1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-04-21 17:53 - 2014-01-05 15:26 - 00000000 ___RD () C:\Users\Red 1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-04-21 17:53 - 2014-01-05 15:26 - 00000000 ____D () C:\Users\Red 1\AppData\Roaming\hpqLog
2015-04-21 17:52 - 2014-05-03 16:43 - 00000000 ____D () C:\Users\Red 1\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
2015-04-21 17:52 - 2014-04-19 13:18 - 00000000 ____D () C:\Users\Red 1\AppData\Local\Windows Live
2015-04-21 17:52 - 2014-01-27 16:35 - 00000000 ____D () C:\Users\Red 1\AppData\Local\WinZip
2015-04-21 17:52 - 2014-01-05 15:47 - 00000000 ____D () C:\Users\Red 1\AppData\Roaming\Adobe
2015-04-21 17:52 - 2014-01-05 15:26 - 00000000 ____D () C:\Users\Red 1\AppData\Roaming\ATI
2015-04-21 17:52 - 2014-01-05 15:26 - 00000000 ____D () C:\Users\Red 1\AppData\Local\VirtualStore
2015-04-21 16:55 - 2015-03-13 12:16 - 00000000 ____D () C:\Users\Public\Juniper Networks
2015-04-21 16:55 - 2009-07-27 15:49 - 00000000 ___RD () C:\Users\Public\Recorded TV
2015-04-21 16:55 - 2009-07-14 04:37 - 00000000 __RHD () C:\Users\Public\Libraries
2015-04-21 16:55 - 2009-07-14 04:37 - 00000000 ___RD () C:\Users\Public
2015-04-21 16:27 - 2014-01-27 21:26 - 00000000 ____D () C:\Users\Red 1\AppData\Local\Skype
2015-04-21 16:26 - 2014-07-17 14:13 - 00000000 ____D () C:\Users\Red 1\AppData\Local\Microsoft Help
2015-04-21 16:26 - 2014-03-05 18:35 - 00000000 ____D () C:\Users\Red 1\AppData\Local\PDF Writer
2015-04-21 16:26 - 2014-01-05 15:38 - 00000000 ____D () C:\Users\Red 1\AppData\Local\PDFC
2015-04-21 16:25 - 2014-07-15 14:02 - 00000000 ____D () C:\Users\Red 1\AppData\Local\HP
2015-04-21 16:25 - 2014-01-05 21:03 - 00000000 ____D () C:\Users\Red 1\AppData\Local\Google
2015-04-21 16:25 - 2014-01-05 20:40 - 00000000 ____D () C:\Users\Red 1\AppData\Local\McAfee File Lock
2015-04-21 16:25 - 2014-01-05 15:28 - 00000000 ____D () C:\Users\Red 1\AppData\Local\Hewlett-Packard
2015-04-21 16:24 - 2015-03-18 19:57 - 00000000 ____D () C:\Users\Red 1 - Admin\AppData\Roaming\Mobotix
2015-04-21 16:24 - 2014-12-31 12:23 - 00000000 ____D () C:\Users\Red 1 - Admin\AppData\Roaming\Nitro
2015-04-21 16:24 - 2014-12-24 18:56 - 00000000 ____D () C:\Users\Red 1 - Admin\AppData\Roaming\Nitro PDF
2015-04-21 16:24 - 2014-12-11 18:01 - 00000000 ____D () C:\Users\Red 1 - Admin\AppData\Roaming\webex
2015-04-21 16:24 - 2014-12-05 16:00 - 00000000 ____D () C:\Users\Red 1 - Admin\AppData\Roaming\TeamViewer
2015-04-21 16:24 - 2014-05-05 22:01 - 00000000 ____D () C:\Users\Red 1 - Admin\AppData\Local\Skype
2015-04-21 16:24 - 2014-03-24 14:02 - 00000000 ____D () C:\Users\Red 1 - Admin\AppData\Roaming\Notepad++
2015-04-21 16:24 - 2014-01-27 21:23 - 00000000 ____D () C:\Users\Red 1 - Admin\AppData\Roaming\Adobe
2015-04-21 16:23 - 2014-03-11 11:35 - 00000000 ____D () C:\Users\Red 1 - Admin\AppData\Local\HP
2015-04-21 16:23 - 2014-01-27 21:23 - 00000000 ____D () C:\Users\Red 1 - Admin\AppData\Local\Google
2015-04-21 16:22 - 2014-05-03 16:43 - 00000000 ____D () C:\Users\Red 1 - Admin\AppData\Local\Adobe
2015-04-21 16:21 - 2015-03-13 12:08 - 00000000 ____D () C:\ProgramData\Sun
2015-04-21 16:21 - 2015-03-13 12:07 - 00000000 ____D () C:\ProgramData\Oracle
2015-04-21 16:21 - 2015-01-21 16:40 - 00000000 ____D () C:\ProgramData\ZohoMeeting
2015-04-21 16:21 - 2015-01-12 16:07 - 00000000 ____D () C:\ProgramData\Shrew Soft VPN
2015-04-21 16:21 - 2014-12-11 18:00 - 00000000 ____D () C:\ProgramData\WebEx
2015-04-21 16:21 - 2014-08-18 15:22 - 00000000 ____D () C:\ProgramData\PVsyst
2015-04-21 16:21 - 2014-06-22 21:11 - 00000000 __SHD () C:\Users\Red 1\AppData\Local\EmieUserList
2015-04-21 16:21 - 2014-06-22 21:11 - 00000000 __SHD () C:\Users\Red 1\AppData\Local\EmieSiteList
2015-04-21 16:21 - 2014-05-03 16:59 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe
2015-04-21 16:21 - 2014-05-03 16:42 - 00000000 ____D () C:\Users\Red 1\AppData\Local\Adobe
2015-04-21 16:21 - 2014-03-26 11:40 - 00000000 ____D () C:\ProgramData\Microsoft OneDrive
2015-04-21 16:21 - 2014-03-05 18:32 - 00000000 ____D () C:\ProgramData\PDF Writer
2015-04-21 16:21 - 2014-01-05 21:31 - 00000000 ____D () C:\ProgramData\Nitro
2015-04-21 16:21 - 2014-01-05 21:02 - 00000000 ____D () C:\Users\Red 1\AppData\Local\Deployment
2015-04-21 16:21 - 2014-01-05 21:02 - 00000000 ____D () C:\Users\Red 1\AppData\Local\Apps\2.0
2015-04-21 16:21 - 2014-01-05 15:34 - 00000000 ____D () C:\ProgramData\Skype
2015-04-21 16:21 - 2014-01-05 15:28 - 00000000 ____D () C:\ProgramData\WinZip
2015-04-21 16:21 - 2014-01-05 15:28 - 00000000 ____D () C:\ProgramData\SonicFocus
2015-04-21 16:21 - 2014-01-05 15:26 - 00000000 ____D () C:\Users\Red 1\AppData\Local\ATI
2015-04-21 16:21 - 2009-09-17 06:10 - 00000000 ____D () C:\ProgramData\Uninstall
2015-04-21 16:21 - 2009-09-17 06:08 - 00000000 ____D () C:\ProgramData\Sonic
2015-04-21 16:21 - 2009-09-17 06:08 - 00000000 ____D () C:\ProgramData\Roxio
2015-04-21 16:21 - 2009-09-17 05:53 - 00000000 ____D () C:\ProgramData\PDFC
2015-04-21 16:20 - 2014-08-18 14:04 - 00000000 ____D () C:\ProgramData\Macrovision
2015-04-21 16:20 - 2014-03-11 11:58 - 00000000 ____D () C:\ProgramData\HP
2015-04-21 16:20 - 2009-09-17 05:49 - 00000000 ____D () C:\ProgramData\Hewlett-Packard
2015-04-21 16:18 - 2015-03-13 12:07 - 00000000 ____D () C:\Program Files\Java
2015-04-21 16:18 - 2014-05-03 16:43 - 00000000 ____D () C:\ProgramData\Adobe
2015-04-21 16:18 - 2014-01-06 00:11 - 00000000 ____D () C:\ProgramData\ATI
2015-04-21 16:17 - 2009-07-27 18:12 - 00000000 ___HD () C:\SYSTEM.SAV
2015-04-21 16:14 - 2015-02-25 19:48 - 00000000 ____D () C:\PortQryUI
2015-04-21 16:14 - 2015-02-25 19:41 - 00000000 ____D () C:\PortQryV2
2015-04-21 16:14 - 2009-09-17 05:48 - 00000000 ___HD () C:\hp
2015-04-21 16:11 - 2015-03-13 12:08 - 00096680 _____ (Oracle Corporation) C:\windows\system32\WindowsAccessBridge.dll
2015-04-21 16:10 - 2009-07-27 21:48 - 00000000 ____D () C:\EFI
2015-04-16 14:32 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\AppCompat
2015-04-16 14:25 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\rescache
2015-04-16 13:49 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\Microsoft.NET
2015-04-16 11:22 - 2014-12-11 11:26 - 00000000 ____D () C:\windows\system32\appraiser
2015-04-16 11:22 - 2014-05-06 17:46 - 00000000 ___SD () C:\windows\system32\CompatTel
2015-04-15 20:46 - 2014-01-20 17:42 - 00000000 ____D () C:\windows\system32\MRT
2015-04-15 20:25 - 2014-01-20 17:42 - 125832184 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2015-04-15 20:24 - 2009-09-17 05:58 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-04-14 13:45 - 2014-12-05 11:22 - 00000000 ____D () C:\Users\Red 1 - Admin\AppData\Roaming\HP Support Assistant
2015-04-14 13:45 - 2014-03-11 11:58 - 00000000 ____D () C:\Users\Red 1 - Admin\AppData\Roaming\HpUpdate
2015-04-10 18:12 - 2015-01-12 11:36 - 00000000 ____D () C:\Program Files\DIFX
2015-04-10 18:12 - 2014-01-06 00:10 - 00054748 _____ () C:\windows\DPINST.LOG
2015-04-09 12:11 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\NDF
2015-04-06 12:40 - 2015-02-25 20:04 - 00000600 _____ () C:\Users\Red 1 - Admin\AppData\Roaming\winscp.rnd
2015-03-27 00:51 - 2009-07-14 06:53 - 00032620 _____ () C:\windows\Tasks\SCHEDLGU.TXT
2015-03-24 12:59 - 2014-12-05 16:58 - 00001005 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk
2015-03-24 12:59 - 2014-12-05 16:58 - 00000000 ____D () C:\Program Files\TeamViewer
 
==================== Files in the root of some directories =======
 
2015-04-21 16:24 - 2015-04-21 16:24 - 0009042 _____ () C:\Users\Red 1 - Admin\AppData\Roaming\HELP_DECRYPT.HTML
2015-04-21 16:24 - 2015-04-21 16:24 - 0050192 _____ () C:\Users\Red 1 - Admin\AppData\Roaming\HELP_DECRYPT.PNG
2015-04-21 16:24 - 2015-04-21 16:24 - 0004844 _____ () C:\Users\Red 1 - Admin\AppData\Roaming\HELP_DECRYPT.TXT
2015-04-21 16:24 - 2015-04-21 16:24 - 0000292 _____ () C:\Users\Red 1 - Admin\AppData\Roaming\HELP_DECRYPT.URL
2015-04-21 18:00 - 2015-04-21 18:00 - 0002678 _____ () C:\Users\Red 1 - Admin\AppData\Roaming\HELP_RESTORE_FILES.txt
2015-04-21 15:57 - 2015-04-21 18:39 - 0000752 _____ () C:\Users\Red 1 - Admin\AppData\Roaming\key.dat
2015-04-21 15:57 - 2015-04-21 18:39 - 5679498 _____ () C:\Users\Red 1 - Admin\AppData\Roaming\log.html
2015-02-25 20:04 - 2015-04-06 12:40 - 0000600 _____ () C:\Users\Red 1 - Admin\AppData\Roaming\winscp.rnd
2014-01-27 21:23 - 2014-01-27 21:23 - 0000000 _____ () C:\Users\Red 1 - Admin\AppData\Local\AtStart.txt
2014-01-27 21:23 - 2014-01-27 21:23 - 0000000 _____ () C:\Users\Red 1 - Admin\AppData\Local\DSwitch.txt
2015-04-21 16:24 - 2015-04-21 16:24 - 0009042 _____ () C:\Users\Red 1 - Admin\AppData\Local\HELP_DECRYPT.HTML
2015-04-21 16:24 - 2015-04-21 16:24 - 0050192 _____ () C:\Users\Red 1 - Admin\AppData\Local\HELP_DECRYPT.PNG
2015-04-21 16:24 - 2015-04-21 16:24 - 0004844 _____ () C:\Users\Red 1 - Admin\AppData\Local\HELP_DECRYPT.TXT
2015-04-21 16:24 - 2015-04-21 16:24 - 0000292 _____ () C:\Users\Red 1 - Admin\AppData\Local\HELP_DECRYPT.URL
2015-04-21 18:34 - 2015-04-21 18:34 - 0002678 _____ () C:\Users\Red 1 - Admin\AppData\Local\HELP_RESTORE_FILES.txt
2015-03-12 19:19 - 2015-03-16 20:16 - 0000600 _____ () C:\Users\Red 1 - Admin\AppData\Local\PUTTY.RND
2014-01-27 21:23 - 2014-01-27 21:23 - 0000000 _____ () C:\Users\Red 1 - Admin\AppData\Local\QSwitch.txt
2014-02-12 17:43 - 2014-02-12 17:43 - 0000218 _____ () C:\Users\Red 1 - Admin\AppData\Local\recently-used.xbel
2014-03-11 11:58 - 2014-03-11 11:58 - 0000057 _____ () C:\ProgramData\Ament.ini
2015-04-21 15:54 - 2015-04-21 16:45 - 0009042 _____ () C:\ProgramData\HELP_DECRYPT.HTML
2015-04-21 15:54 - 2015-04-21 16:50 - 0050148 _____ () C:\ProgramData\HELP_DECRYPT.PNG.ecc
2015-04-21 15:54 - 2015-04-21 16:50 - 0004868 _____ () C:\ProgramData\HELP_DECRYPT.TXT.ecc
2015-04-21 15:54 - 2015-04-21 16:45 - 0000292 _____ () C:\ProgramData\HELP_DECRYPT.URL
2015-04-21 16:18 - 2015-04-21 16:55 - 0002960 _____ () C:\ProgramData\HELP_RESTORE_FILES.txt
2009-09-17 06:17 - 2009-09-17 06:17 - 0000193 _____ () C:\ProgramData\HPWALog.txt
 
Some content of TEMP:
====================
C:\Users\Red 1\AppData\Local\Temp\HPQSi.exe
C:\Users\Red 1\AppData\Local\Temp\nitro_reader3.exe
C:\Users\Red 1\AppData\Local\Temp\SpotifyUninstall.exe
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\windows\explorer.exe => File is digitally signed
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-04-15 12:47
 
==================== End Of Log ============================
 
 
ADDITION log
 
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 20-04-2015
Ran by red 1 - Admin at 2015-04-22 12:18:15
Running from C:\Users\red 1 - Admin\Downloads
Boot Mode: Normal
==========================================================
 
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: McAfee Anti-Virus and Anti-Spyware (Enabled - Up to date) {DA9F8ED0-D0DE-39CC-F55A-51AB4CC1B556}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: McAfee Anti-Virus and Anti-Spyware (Enabled - Up to date) {61FE6F34-F6E4-3642-CFEA-6AD93746FFEB}
FW: McAfee Firewall (Enabled) {E2A40FF5-9AB1-3894-DE05-F89EB212F22D}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
2007 Microsoft Office system (HKLM\...\PROHYBRIDR) (Version: 12.0.6612.1000 - Microsoft Corporation)
ActiveCheck component for HP Active Support Library (Version: 3.0.0.2 - Hewlett-Packard) Hidden
Adobe Acrobat XI Pro (HKLM\...\{AC76BA86-1033-FFFF-7760-000000000006}) (Version: 11.0.00 - Adobe Systems)
Adobe AIR (HKLM\...\Adobe AIR) (Version: 13.0.0.83 - Adobe Systems Incorporated)
Adobe Download Assistant (HKLM\...\com.adobe.downloadassistant.AdobeDownloadAssistant) (Version: 1.2.6 - Adobe Systems Incorporated)
Adobe Flash Player 15 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 15.0.0.189 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
AmoK DateWizard 1.1b (HKLM\...\AmoK DateWizard) (Version: 1.1b - AmoK - The Art of Coding)
ATI Catalyst Install Manager (HKLM\...\{8F0EDF80-31C2-FA10-DEE8-BD435A5F7D61}) (Version: 3.0.732.0 - ATI Technologies, Inc.)
Bullzip PDF Printer 10.3.0.2191 (HKLM\...\Bullzip PDF Printer_is1) (Version: 10.3.0.2191 - Bullzip)
ccc-core-static (Version: 2009.0804.1118.18368 - ATI) Hidden
Cisco WebEx Meetings (HKLM\...\ActiveTouchMeetingClient) (Version:  - Cisco WebEx LLC)
D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden
DirectX 9 Runtime (Version: 1.00.0000 - Sonic Solutions) Hidden
ELOG 13 (HKLM\...\ELOG 13) (Version: v1.276 - DENT Instruments, Inc.)
ELOG 14 (HKLM\...\ELOG 14) (Version: v1.292 - DENT Instruments, Inc.)
FortiClient SSLVPN v4.0.2300 (HKLM\...\{A34DCE59-0004-0000-2300-3F8A9926B752}) (Version: 4.0.2300 - Fortinet Inc.)
Fotogalerie (Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
FRITZ!Box-Fernzugang einrichten (HKLM\...\{EFADD989-D9F2-49F6-A280-675951CC78D3}) (Version: 1.0.3 - AVM Berlin)
Google Chrome (HKLM\...\Google Chrome) (Version: 42.0.2311.90 - Google Inc.)
Google Drive (HKLM\...\{6C36881B-0E51-4231-9D02-BF2149664D34}) (Version: 1.20.8672.3137 - Google, Inc.)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.26.9 - Google Inc.) Hidden
HOMER 2.68 beta (HKLM\...\HOMER_is1) (Version:  - )
HP 3D DriveGuard (HKLM\...\{991A4895-3346-4980-990F-A1041B73C6F7}) (Version: 4.0.5.1 - Hewlett-Packard Company)
HP Advisor (HKLM\...\{B53E61D7-7C80-40DF-82D2-CF5390D6D20A}) (Version: 3.2.8946.3086 - Hewlett-Packard)
HP Common Access Service Library (HKLM\...\{87CA636B-85B8-4611-A81D-F97E71024AFD}) (Version: 3.0.28.1 - Hewlett-Packard)
HP Customer Experience Enhancements (HKLM\...\{5B295588-59C1-4386-9F85-BB4BEDCB0D22}) (Version: 5.7.0.3036 - Hewlett-Packard)
HP ESU for Microsoft Windows 7 (HKLM\...\{511376F5-7E5A-4EC9-B603-193B1D425BC3}) (Version: 1.0.1.1 - Hewlett-Packard)
HP Officejet 4620 series Basic Device Software (HKLM\...\{C4E2A2F2-2A53-42C7-920A-169713776631}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Officejet 4620 series Help (HKLM\...\{606C37AB-EB04-4270-A592-201A03C2DB36}) (Version: 6.0.0 - Hewlett Packard)
HP Officejet 4620 series Product Improvement Study (HKLM\...\{5696CE5E-FD09-4DFF-82CE-DB87229F03DD}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Quick Launch Buttons (HKLM\...\{34D2AB40-150D-475D-AE32-BD23FB5EE355}) (Version: 6.50.4.2 - Hewlett-Packard)
HP QuickLook (HKLM\...\{6B11BCAC-CE60-418E-A0BD-F773EC1194E5}) (Version: 3.0.0.17 - Hewlett-Packard)
HP Setup (HKLM\...\{D0BFE65D-C320-4FC9-88D2-B9C32FB95DA0}) (Version: 1.2.3215.3078 - Hewlett-Packard)
HP Software Setup (HKLM\...\{76AF1F61-BB44-4694-A0EA-C6830C8BEF41}) (Version: 1.0.0.15 - Hewlett-Packard)
HP Support Assistant (HKLM\...\{4F46FDB9-B906-47BF-B3D5-C62E01B3C5EE}) (Version: 4.1.11.3 - Hewlett-Packard)
HP Update (HKLM\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard)
HP User Guides 0136 (HKLM\...\{004739E9-9BBF-4A8B-9FAC-EB7CA5B7A9D9}) (Version: 1.03.0002 - Hewlett-Packard)
HP Wallpaper (HKLM\...\{F173C2B3-296F-458C-98FF-1676A42EBA02}) (Version: 1.0.1.11 - Hewlett-Packard)
HP Wireless Assistant (HKLM\...\{54CC7901-804D-4155-B353-21F0CC9112AB}) (Version: 3.50.9.1 - Hewlett-Packard)
HPAsset component for HP Active Support Library (Version: 3.0.2.2 - Hewlett-Packard) Hidden
I.R.I.S. OCR (HKLM\...\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP)
Inkscape 0.48.4 (HKLM\...\Inkscape) (Version: 0.48.4 - )
Intel® Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version:  - Intel Corporation)
Java 8 Update 45 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation)
Juniper Networks Network Connect 8.0 (HKLM\...\Juniper Network Connect 8.0) (Version: 8.0.8.33771 - Juniper Networks)
Juniper Networks Secure Application Manager (HKLM\...\Neoteris_Secure_Application_Manager) (Version: 8.0.8.33771 - Juniper Networks)
Juniper Networks Setup Client (HKU\S-1-5-21-1872118813-3924231162-3133279225-1002\...\Juniper_Setup_Client) (Version: 8.0.8.52215 - Juniper Networks)
Juniper Networks Setup Client Activex Control (HKLM\...\Juniper_Setup_Client Activex Control) (Version: 2.1.1.1 - Juniper Networks)
KEW Windows for KEW6315 (HKLM\...\{8F11CB3E-287C-4397-B8B5-CF9CC7A9D1DF}) (Version: 1.10.0000 - KYORITSU ELECTRICAL INSTRUMENTS WORKS,LTD.)
KEW WindowsV2 (HKLM\...\{145F7360-5BA1-454D-ABF3-840DFFC2AD27}) (Version: 1.06.0000 - KYORITSU ELECTRICAL INSTRUMENTS WORKS,LTD.)
Kst-2.0.8 (HKLM\...\Kst-2.0.8) (Version: 2.1.1 - The Kst Team)
LightScribe System Software (HKLM\...\{82EF29B1-9B60-4142-A155-0599216DD053}) (Version: 1.18.6.1 - LightScribe)
Malwarebytes Anti-Malware version 2.1.4.1018 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.4.1018 - Malwarebytes Corporation)
Marvell Miniport Driver (HKLM\...\Marvell Miniport Driver) (Version: 10.70.5.3 - Marvell)
McAfee Total Protection (HKLM\...\MSC) (Version: 14.0.339 - McAfee, Inc.)
McAfee Virtual Technician (HKLM\...\McAfee Virtual Technician) (Version: 7.6.0.202 - McAfee, Inc.)
METEONORM Version 6.1 (HKLM\...\{8545573F-42FB-4C0E-89EA-F2EE981057D8}) (Version: 6.10.0022 - METEOTEST)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office Excel 2007 Help - Aggiornamento (KB963678) (HKLM\...\{90120000-0016-0410-0000-0000000FF1CE}_PROHYBRIDR_{9F57BDED-B51B-4D2F-B360-5B4EFAAF0F1A}) (Version:  - Microsoft)
Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Outlook 2007 Help - Aggiornamento (KB963677) (HKLM\...\{90120000-001A-0410-0000-0000000FF1CE}_PROHYBRIDR_{2278E02A-AB15-4BF7-B2B4-5C0EEB4B7EEB}) (Version:  - Microsoft)
Microsoft Office Powerpoint 2007 Help - Aggiornamento (KB963669) (HKLM\...\{90120000-0018-0410-0000-0000000FF1CE}_PROHYBRIDR_{C76C02F1-B07F-4974-876A-A18DEC9887C8}) (Version:  - Microsoft)
Microsoft Office Suite Activation Assistant (HKLM\...\{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}) (Version: 2.7 - Microsoft Corporation)
Microsoft Office Word 2007 Help - Aggiornamento (KB963665) (HKLM\...\{90120000-001B-0410-0000-0000000FF1CE}_PROHYBRIDR_{E5B82DB3-DD7D-4C45-BC5E-09864B26F9BC}) (Version:  - Microsoft)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Mise à jour Microsoft Office Excel 2007 Help  (KB963678) (HKLM\...\{90120000-0016-040C-0000-0000000FF1CE}_PROHYBRIDR_{B761869A-B85C-40E2-994C-A1CE78AC8F2C}) (Version:  - Microsoft)
Mise à jour Microsoft Office Outlook 2007 Help  (KB963677) (HKLM\...\{90120000-001A-040C-0000-0000000FF1CE}_PROHYBRIDR_{51EFB347-1F3D-4BAC-8B79-F056B904FE21}) (Version:  - Microsoft)
Mise à jour Microsoft Office Powerpoint 2007 Help  (KB963669) (HKLM\...\{90120000-0018-040C-0000-0000000FF1CE}_PROHYBRIDR_{C3DCA38E-005E-41BA-A52A-7C3429F351C3}) (Version:  - Microsoft)
Mise à jour Microsoft Office Word 2007 Help  (KB963665) (HKLM\...\{90120000-001B-040C-0000-0000000FF1CE}_PROHYBRIDR_{81536A04-DBFB-4DB3-978F-0F284590C223}) (Version:  - Microsoft)
Movie Maker (Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Mozilla Firefox 37.0.2 (x86 en-US) (HKLM\...\Mozilla Firefox 37.0.2 (x86 en-US)) (Version: 37.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 37.0.2 - Mozilla)
MSVC90_x86 (Version: 1.0.1.2 - Nokia) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MxEasy 1.6.1 (HKLM\...\{15D6691B-73D3-41C7-87AF-CF685FE84D99}_is1) (Version:  - MOBOTIX AG)
Nitro Pro 8 (HKLM\...\{B01B9207-59ED-448A-BB83-D3D66244FFFE}) (Version: 8.5.7.3 - Nitro)
Nitro Pro 9 (HKLM\...\{30317C59-4525-4FEA-B7DD-DD3844A3C24B}) (Version: 9.5.2.29 - Nitro)
Nitro Reader 3 (HKLM\...\{DC6952D8-0FDB-4A72-A34E-70AE329CAFC7}) (Version: 3.5.6.5 - Nitro)
Nokia Connectivity Cable Driver (HKLM\...\{A57025CC-5F2E-4D01-B387-06DB10500D43}) (Version: 7.1.78.0 - Nokia)
Nokia PC Suite (HKLM\...\Nokia PC Suite) (Version: 7.1.180.94 - Nokia)
Nokia PC Suite (Version: 7.1.180.94 - Nokia) Hidden
Notepad++ (HKLM\...\Notepad++) (Version: 6.5.5 - Notepad++ Team)
OpenVPN 2.3.6 (HKLM\...\OpenVPN) (Version: 2.3.6 - )
PC Connectivity Solution (HKLM\...\{644F4910-E812-49AD-93EC-86828CB81A0D}) (Version: 12.0.27.0 - Nokia)
PDF Architect (HKLM\...\{064A929A-4DE8-40CF-A901-BD40C14E4D25}) (Version: 1.1.83.9982 - pdfforge GmbH)
PDF Complete Special Edition (HKLM\...\PDF Complete) (Version: 3.5.108 - PDF Complete, Inc)
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.7.2 - pdfforge)
PuTTY development snapshot 2015-03-08.2422b18 (HKLM\...\PuTTY_is1) (Version: 2015-03-08.2422b18 - Simon Tatham)
QLBCASL (Version: 6.40.17.2 - Hewlett-Packard) Hidden
QNAP Qfinder (HKLM\...\QNAP_FINDER) (Version: 4.2.5.0108 - QNAP Systems, Inc.)
Roxio Creator Business (HKLM\...\{537BF16E-7412-448C-95D8-846E85A1D817}) (Version: 10.3 - Roxio)
SCR3xxx Smart Card Reader (HKLM\...\{E045FAC9-0B70-4796-AD3A-7035E89CE536}) (Version: 8.35 - SCM Microsystems)
Shrew Soft VPN Client (HKLM\...\Shrew Soft VPN Client) (Version:  - )
SiteAdvisor (HKLM\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 3.7.206 - McAfee, Inc.)
Skype™ 7.3 (HKLM\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.3.101 - Skype Technologies S.A.)
Sonic CinePlayer Decoder Pack (Version: 4.3.0 - Sonic Solutions) Hidden
SoundMAX (HKLM\...\{F0A37341-D692-11D4-A984-009027EC0A9C}) (Version: 6.10.1.7255 - Analog Devices)
Spybot - Search & Destroy (HKLM\...\{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1) (Version: 1.6.2 - Safer Networking Limited)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.0.17.2 - Synaptics Incorporated)
TAP-Windows 9.21.0 (HKLM\...\TAP-Windows) (Version: 9.21.0 - )
TeamViewer 10 (HKLM\...\TeamViewer) (Version: 10.0.39052 - TeamViewer)
Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM\...\{90120000-0016-0407-0000-0000000FF1CE}_PROHYBRIDR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version:  - Microsoft)
Update für Microsoft Office Outlook 2007 Help (KB963677) (HKLM\...\{90120000-001A-0407-0000-0000000FF1CE}_PROHYBRIDR_{F6828576-6F79-470D-AB50-69D1BBADBD30}) (Version:  - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM\...\{90120000-0018-0407-0000-0000000FF1CE}_PROHYBRIDR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version:  - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (HKLM\...\{90120000-001B-0407-0000-0000000FF1CE}_PROHYBRIDR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version:  - Microsoft)
Update voor Microsoft Office Excel 2007 Help (KB963678) (HKLM\...\{90120000-0016-0413-0000-0000000FF1CE}_PROHYBRIDR_{5CF7002F-6F49-4482-9564-5614FBE560FA}) (Version:  - Microsoft)
Update voor Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM\...\{90120000-0018-0413-0000-0000000FF1CE}_PROHYBRIDR_{15D84E79-1ED7-42C5-B2FD-745C3FBDDDC5}) (Version:  - Microsoft)
Update voor Microsoft Office Word 2007 Help (KB963665) (HKLM\...\{90120000-001B-0413-0000-0000000FF1CE}_PROHYBRIDR_{A66AE6A1-8D8C-4102-BC18-38CBDE40F809}) (Version:  - Microsoft)
Windows 7 Default Setting (HKLM\...\{E70E6183-F6EC-45B4-AFA4-0C3C36D4B664}) (Version: 1.0.0.6 - Hewlett-Packard)
Windows Driver Package - DENT Instruments, Inc. (usbser) Ports  (02/20/2013 6.0.0.0) (HKLM\...\DA2FF47F7E13CC4DCB20A78B3484A15AD48EB782) (Version: 02/20/2013 6.0.0.0 - DENT Instruments, Inc.)
Windows Driver Package - Nokia Modem  (02/25/2011 4.7) (HKLM\...\E0AC723A3DE3A04256288CADBBB011B112AED454) (Version: 02/25/2011 4.7 - Nokia)
Windows Driver Package - Nokia Modem  (02/25/2011 7.01.0.9) (HKLM\...\72A50F48CC5601190B9C4E74D81161693133E7F7) (Version: 02/25/2011 7.01.0.9 - Nokia)
Windows Driver Package - Nokia pccsmcfd “LegacyDriver”  (05/31/2012 7.1.2.0) (HKLM\...\17D063A0A9F5D5A225B76B1D9BCB5ADBE85C8382) (Version: 05/31/2012 7.1.2.0 - Nokia)
Windows Live Essentials (HKLM\...\WinLiveSuite) (Version: 16.4.3522.0110 - Microsoft Corporation)
Windows Phone app for desktop (HKLM\...\{5F71448B-88EB-4357-9A98-8658D4C49C48}) (Version: 1.1.2726.0 - Microsoft Corporation)
WinRAR 5.11 (32-Bit) (HKLM\...\WinRAR archiver) (Version: 5.11.0 - win.rar GmbH)
WinSCP 5.7 (HKLM\...\winscp3_is1) (Version: 5.7 - Martin Prikryl)
WinZip 12.0 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240B7}) (Version: 12.0.8252 - WinZip Computing, S.L. )
Wireshark 1.12.4 (32-bit) (HKLM\...\Wireshark) (Version: 1.12.4 - The Wireshark developer community, http://www.wireshark.org)
ZohoAssist (HKLM\...\{FEBCC406-D823-4AF4-A7F5-9AB3487E28BB}) (Version: 1.1.62 - ZohoMeeting)
 
==================== Custom CLSID (selected items): ==========================
 
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
 
 
==================== Restore Points  =========================
 
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-14 04:04 - 2015-03-16 20:17 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
 
Task: {003F2C7A-839B-47BC-B822-A30046998D41} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-01-05] (Google Inc.)
Task: {09BB0669-3F5D-4390-8CAC-CBE2A220BC1E} - System32\Tasks\iSCSIAgentAutoStartup => C:\Program Files\QNAP\Qfinder\iSCSIAgent.exe [2015-01-27] ()
Task: {1DF0B5C4-E44E-467A-AE4E-E3DA28742F79} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {45B6C325-E89A-492A-927C-A19B2D2620DA} - System32\Tasks\HPCustPartic.exe_{3EBD05CA-29B4-40DB-9402-289A377AF413} => C:\Program Files\HP\HP Officejet 4620 series\Bin\HPCustPartic.exe [2012-10-17] (Hewlett-Packard Co.)
Task: {46DF6CE9-EA49-4224-9225-B6EA11A8C73C} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {52BCC9F4-AA2B-4B9A-A0E4-0D8B4B3D8FBE} - System32\Tasks\Adobe Flash Player Updater => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-10-23] (Adobe Systems Incorporated)
Task: {587A1B4E-CD0F-427D-9898-2DE6BAE75FC3} - System32\Tasks\ScanToPCActivationApp.exe_{2F20D3B5-DB60-4F79-AA6B-608DA17ECDEE} => C:\Program Files\HP\HP Officejet 4620 series\Bin\ScanToPCActivationApp.exe [2012-10-17] (Hewlett-Packard Co.)
Task: {72C3285E-0355-4F30-9D0D-9757231A8DAF} - System32\Tasks\HPCustParticipation HP Officejet 4620 series => C:\Program Files\HP\HP Officejet 4620 series\Bin\HPCustPartic.exe [2012-10-17] (Hewlett-Packard Co.)
Task: {7F80D29A-C47B-4164-9D1F-81A0D79EB850} - System32\Tasks\ScanToPCActivationApp.exe_{7686D4DA-A712-41A7-94BB-DE2AC52FBEC5} => C:\Program Files\HP\HP Officejet 4620 series\Bin\ScanToPCActivationApp.exe [2012-10-17] (Hewlett-Packard Co.)
Task: {81B9F66A-3883-43B2-AE98-FF40AC53AF73} - System32\Tasks\{828A4455-DB5B-400C-9456-B69D49997140} => pcalua.exe -a C:\ProgramData\Installations\{866C4563-ED53-43F3-A29D-8BEE2BD1BA3C}\Nokia_PC_Suite_ALL.exe
Task: {91BC7038-E776-4F77-93EE-4486BF0A318D} - System32\Tasks\Toolbox.exe_{207D6CFC-9EB1-412E-B73C-8DF8F5302672} => C:\Program Files\HP\HP Officejet 4620 series\Bin\Toolbox.exe [2012-10-17] (Hewlett-Packard Co.)
Task: {9C4B528A-9F0E-4773-AFCE-1576C5D21C81} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {B829B5FE-19C9-442F-B25E-DDB60701393E} - System32\Tasks\{A31859B5-95FE-4125-81F2-536025B6358D} => pcalua.exe -a "C:\Users\red 1 - Admin\Downloads\AmoK_Date_Wizard_v1.10b_(Setup).exe" -d "C:\Users\red 1 - Admin\Downloads"
Task: {C30C2BEC-9267-450D-B254-9E7E1C40BF1E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Ghost Resign Task => c:\program files\hewlett-packard\hp health check\activecheck\product_line\HPResignFileLoader.exe [2014-12-03] (Microsoft)
Task: {CC02AF1C-6D98-4716-BA92-7556C8B3603B} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HPSAObjUtilTask => C:\Program Files\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\UtilTask.exe [2014-12-03] (Microsoft)
Task: {CFF9BCF4-3DCA-46D3-BA59-F495CE1258ED} - System32\Tasks\HP Officejet 4620 series.exe_{3DB9A0CD-70F0-459D-8A62-4CC6BE3ABE2E} => C:\Program Files\HP\HP Officejet 4620 series\Bin\HP Officejet 4620 series.exe [2012-10-17] (Hewlett-Packard Co.)
Task: {DB25E284-FBB0-4F13-B5AF-1E38E6C1D812} - System32\Tasks\FaxApplications.exe_{C7CA38A6-0B08-41AE-BC39-48022FC3728A} => C:\Program Files\HP\HP Officejet 4620 series\Bin\FaxApplications.exe [2012-10-17] (Hewlett-Packard Co.)
Task: {E242147E-43C4-4630-954A-8E99B8F540B5} - System32\Tasks\GoogleUpdateTaskMachineUA1cf2bbc7987060f => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-01-05] (Google Inc.)
Task: {EE2055AD-A88A-4A4D-BFF1-A42AEA48F800} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\windows\system32\GWX\GWX.exe [2015-03-25] (Microsoft Corporation)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA1cf2bbc7987060f.job => C:\Program Files\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (whitelisted) ==============
 
2013-07-01 10:21 - 2013-07-01 10:21 - 00772408 _____ () C:\Program Files\ShrewSoft\VPN Client\iked.exe
2013-07-01 01:16 - 2013-07-01 01:16 - 00438272 _____ () C:\Program Files\ShrewSoft\VPN Client\libike.dll
2013-07-01 01:15 - 2013-07-01 01:15 - 00016384 _____ () C:\Program Files\ShrewSoft\VPN Client\libidb.dll
2013-07-01 01:15 - 2013-07-01 01:15 - 00014848 _____ () C:\Program Files\ShrewSoft\VPN Client\libith.dll
2013-07-01 01:17 - 2013-07-01 01:17 - 00030208 _____ () C:\Program Files\ShrewSoft\VPN Client\libvnet.dll
2013-07-01 01:16 - 2013-07-01 01:16 - 00010752 _____ () C:\Program Files\ShrewSoft\VPN Client\liblog.dll
2013-07-01 01:16 - 2013-07-01 01:16 - 00102400 _____ () C:\Program Files\ShrewSoft\VPN Client\libip.dll
2013-07-01 01:17 - 2013-07-01 01:17 - 00024576 _____ () C:\Program Files\ShrewSoft\VPN Client\libpfk.dll
2013-07-01 01:17 - 2013-07-01 01:17 - 00014848 _____ () C:\Program Files\ShrewSoft\VPN Client\libdtp.dll
2013-07-01 01:17 - 2013-07-01 01:17 - 00026624 _____ () C:\Program Files\ShrewSoft\VPN Client\libvflt.dll
2013-07-01 10:21 - 2013-07-01 10:21 - 00544400 _____ () C:\Program Files\ShrewSoft\VPN Client\ipsecd.exe
2014-07-16 16:07 - 2014-07-16 16:07 - 00392712 _____ () C:\Program Files\Nitro\Pro 9\Nitro_UpdateService.exe
2012-06-18 17:24 - 2012-06-18 17:24 - 00260096 _____ () C:\Program Files\Notepad++\NppShell_05.dll
2015-03-06 15:53 - 2015-01-27 09:16 - 01739952 _____ () C:\Program Files\QNAP\Qfinder\iSCSIAgent.exe
2009-07-16 02:51 - 2009-07-16 02:51 - 00061440 _____ () C:\Program Files\Hewlett-Packard\HP Advisor\Pillars\PCAlerts\PCAlertsPillar.dll
2009-07-16 02:51 - 2009-07-16 02:51 - 00131072 _____ () C:\Program Files\Hewlett-Packard\HP Advisor\Pillars\ECenter\ECLibrary.dll
2009-07-16 02:50 - 2009-07-16 02:50 - 00040960 _____ () C:\Program Files\Hewlett-Packard\HP Advisor\MessagingServer.dll
2009-07-16 02:50 - 2009-07-16 02:50 - 00005632 _____ () C:\Program Files\Hewlett-Packard\HP Advisor\MessagingInterface.dll
2009-07-16 02:50 - 2009-07-16 02:50 - 00018944 _____ () C:\Program Files\Hewlett-Packard\HP Advisor\MessagingMessages.dll
2009-07-16 02:50 - 2009-07-16 02:50 - 00036864 _____ () C:\Program Files\Hewlett-Packard\HP Advisor\MessagingClients.dll
2009-07-16 02:50 - 2009-07-16 02:50 - 00028672 _____ () C:\Program Files\Hewlett-Packard\HP Advisor\Microsoft.Practices.EnterpriseLibrary.ExceptionHandling.Logging.dll
2009-07-16 02:50 - 2009-07-16 02:50 - 00007680 _____ () C:\Program Files\Hewlett-Packard\HP Advisor\RemotingClient.dll
2009-06-17 20:40 - 2009-06-17 20:40 - 02121728 _____ () C:\Program Files\Common Files\LightScribe\QtCore4.dll
2009-06-17 20:40 - 2009-06-17 20:40 - 07745536 _____ () C:\Program Files\Common Files\LightScribe\QtGui4.dll
2009-06-17 20:40 - 2009-06-17 20:40 - 00135168 _____ () C:\Program Files\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll
2009-07-02 00:44 - 2009-07-02 00:44 - 00632888 _____ () C:\Program Files\Hewlett-Packard\Shared\hpqToaster.exe
2008-12-19 01:03 - 2008-12-19 01:03 - 00020480 ____R () C:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll
2014-01-06 00:11 - 2014-01-06 00:11 - 00270336 _____ () C:\windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2015-04-16 16:45 - 2015-04-13 23:55 - 01252680 _____ () C:\Program Files\Google\Chrome\Application\42.0.2311.90\libglesv2.dll
2015-04-16 16:45 - 2015-04-13 23:55 - 00080712 _____ () C:\Program Files\Google\Chrome\Application\42.0.2311.90\libegl.dll
 
==================== Alternate Data Streams (whitelisted) =========
 
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
 
AlternateDataStreams: C:\Windows:nlsPreferences
 
==================== Safe Mode (whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfemms => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
 
==================== EXE Association (whitelisted) ===============
 
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, the associated entry will be removed from the registry.)
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1872118813-3924231162-3133279225-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\red 1 - Admin\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.178.1
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1872118813-3924231162-3133279225-500 - Administrator - Disabled)
Guest (S-1-5-21-1872118813-3924231162-3133279225-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1872118813-3924231162-3133279225-1004 - Limited - Enabled)
red 1 (S-1-5-21-1872118813-3924231162-3133279225-1001 - Limited - Enabled) => C:\Users\red 1
red 1 - Admin (S-1-5-21-1872118813-3924231162-3133279225-1002 - Administrator - Enabled) => C:\Users\red 1 - Admin
 
==================== Faulty Device Manager Devices =============
 
Name: Shrew Soft Virtual Adapter
Description: Shrew Soft Virtual Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Shrew Soft
Service: vnet
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
Name: Bluetooth Peripheral Device
Description: Bluetooth Peripheral Device
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
Name: Marvell Yukon 88E8072 PCI-E Gigabit Ethernet Controller
Description: Marvell Yukon 88E8072 PCI-E Gigabit Ethernet Controller
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Marvell
Service: yukonw7
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
Name: Bluetooth Peripheral Device
Description: Bluetooth Peripheral Device
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (04/22/2015 00:04:36 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1".
Dependent Assembly Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (04/22/2015 00:02:50 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762"1".
Dependent Assembly Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (04/22/2015 00:02:34 AM) (Source: SideBySide) (EventID: 63) (User: )
Description: Activation context generation failed for "assemblyIdentity1".Error in manifest or policy file "assemblyIdentity2" on line assemblyIdentity3.
The value "*" of attribute "language" in element "assemblyIdentity" is invalid.
 
Error: (04/22/2015 00:02:26 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (04/21/2015 08:01:11 PM) (Source: AVLogEvent) (EventID: 5010) (User: NT AUTHORITY)
Description: McShield failed to start because it is not trusted.
Error Code:a7f40905
 
Error: (04/21/2015 08:01:11 PM) (Source: AVLogEvent) (EventID: 5007) (User: NT AUTHORITY)
Description: Failed to load a dependant module.
Error Code:a7f42003
 
Error: (04/21/2015 07:28:15 PM) (Source: AVLogEvent) (EventID: 5010) (User: NT AUTHORITY)
Description: McShield failed to start because it is not trusted.
Error Code:a7f40905
 
Error: (04/21/2015 07:28:15 PM) (Source: AVLogEvent) (EventID: 5007) (User: NT AUTHORITY)
Description: Failed to load a dependant module.
Error Code:a7f42003
 
Error: (04/21/2015 05:40:12 PM) (Source: AVLogEvent) (EventID: 5003) (User: NT AUTHORITY)
Description: McShield encountered error while stopping.
Error Code:a7f40610
 
Error: (04/21/2015 04:59:08 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: taskhost.exe, version: 6.1.7601.18010, time stamp: 0x50aee407
Faulting module name: ntdll.dll, version: 6.1.7601.18798, time stamp: 0x5507b3c6
Exception code: 0x80000003
Fault offset: 0x0006396e
Faulting process id: 0xcbc
Faulting application start time: 0xtaskhost.exe0
Faulting application path: taskhost.exe1
Faulting module path: taskhost.exe2
Report Id: taskhost.exe3
 
 
System errors:
=============
Error: (04/22/2015 10:53:01 AM) (Source: atikmdag) (EventID: 10261) (User: )
Description: Display is not active
 
Error: (04/22/2015 10:53:01 AM) (Source: atikmdag) (EventID: 19468) (User: )
Description: CPLIB :: General - Invalid Parameter
 
Error: (04/22/2015 10:47:10 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The McAfee Home Network service failed to start due to the following error: 
%%1053
 
Error: (04/22/2015 10:47:10 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the McAfee Home Network service to connect.
 
Error: (04/22/2015 10:47:08 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The McAfee Anti-Spam Service service failed to start due to the following error: 
%%1053
 
Error: (04/22/2015 10:47:08 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the McAfee Anti-Spam Service service to connect.
 
Error: (04/22/2015 10:47:07 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The McAfee Proxy Service service failed to start due to the following error: 
%%1053
 
Error: (04/22/2015 10:47:07 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the McAfee Proxy Service service to connect.
 
Error: (04/22/2015 10:47:02 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The McAfee Platform Services service failed to start due to the following error: 
%%1053
 
Error: (04/22/2015 10:47:02 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the McAfee Platform Services service to connect.
 
 
Microsoft Office Sessions:
=========================
Error: (07/31/2014 11:52:11 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6683.5002, Microsoft Office Version: 12.0.6612.1000. This session lasted 7349 seconds with 4920 seconds of active time.  This session ended with a crash.
 
Error: (03/17/2014 07:11:37 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6600.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 30027 seconds with 1680 seconds of active time.  This session ended with a crash.
 
Error: (02/17/2014 07:31:18 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6600.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 16970 seconds with 300 seconds of active time.  This session ended with a crash.
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™2 Duo CPU P7570 @ 2.26GHz
Percentage of memory in use: 73%
Total physical RAM: 3066.27 MB
Available physical RAM: 815.55 MB
Total Pagefile: 6130.83 MB
Available Pagefile: 2852.76 MB
Total Virtual: 2047.88 MB
Available Virtual: 1884.08 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:280.8 GB) (Free:216.16 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive e: (HP_TOOLS) (Fixed) (Total:1.99 GB) (Free:1.92 GB) FAT32
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: BA193EFF)
Partition 1: (Active) - (Size=300 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=280.8 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=15 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=2 GB) - (Type=0C)
 
==================== End Of Log ============================

Edited by frigitar, 22 April 2015 - 08:38 AM.


BC AdBot (Login to Remove)

 


m

#2 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 10,807 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:03:28 AM

Posted 22 April 2015 - 09:39 AM

Hi
 
:welcome:
 
Have you identified the ransom-ware that affected you? Use IDTool and post its results. Some of these have already be broken by experts.

 

Please download this attached  and save it in the same directory as FRST is saved.

  • Start FRST with Administrator privileges.
  • Press the Fix button.
  • When finished, a log file (Fixlog.txt) pops up and is saved to the same location the tool was run from.
    Please copy and paste its contents in your next reply.

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#3 frigitar

frigitar
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:09:28 AM

Posted 23 April 2015 - 04:35 AM

Hi, thanks

 

No I have not identified it yet but it seems to TorrentLocker or such. I tried running your IDTool but it is itself infected with a trojan Artemis!AA916670A0E3

So I am afraid I cannot do that.

 

What I can post is the recovery file that the Malware has posted all over my computer. Attached.

 

Also it created a link to begixcd.exe that it stored under C:\Users\Red 1 - Admin\AppData\Roaming\begixcd.exe .. this exe file has since been removed.

 

Do you think my computer is clean now? I can go about deleting the files myself .. looks like FRST has trouble with spaces in file paths due to CMD... There are also other .PNG.ecc/.TXT.ecc and .HTML files created by the Malware apart from the two you wrote so I can find and delete them using Windows. I will store all my encrypted data (.ecc files) for few weeks hoping for a decrypter to come out.

 

Thanks,

frig

 

Fixlog:

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 20-04-2015
Ran by Red 1 - Admin at 2015-04-23 11:36:56 Run:1
Running from C:\Users\Red 1 - Admin\Desktop
Loaded Profiles: Red 1 - Admin (Available profiles: Red 1 & Red 1 - Admin)
Boot Mode: Normal
 
==============================================
 
Content of fixlist:
*****************
Start
CMD: Type C:\Users\Red 1 - Admin\AppData\Roaming\HELP_DECRYPT.TXT
CMD: Type C:\Users\Red 1 - Admin\AppData\Roaming\HELP_RESTORE_FILES.txt
EmptyTemp:
End
*****************
 
 
=========  Type C:\Users\Red 1 - Admin\AppData\Roaming\HELP_DECRYPT.TXT =========
 
The system cannot find the file specified.
Error occurred while processing: C:\Users\Red.
The system cannot find the file specified.
Error occurred while processing: 1.
The system cannot find the file specified.
Error occurred while processing: -.
The system cannot find the path specified.
 
========= End of CMD: =========
 
 
=========  Type C:\Users\Red 1 - Admin\AppData\Roaming\HELP_RESTORE_FILES.txt =========
 
The system cannot find the file specified.
Error occurred while processing: C:\Users\Red.
The system cannot find the file specified.
Error occurred while processing: 1.
The system cannot find the file specified.
Error occurred while processing: -.
The system cannot find the path specified.
 
========= End of CMD: =========
 
EmptyTemp: => Removed 3.9 GB temporary data.
 
 
The system needed a reboot. 
 
==== End of Fixlog 11:40:56 ====

Attached Files


Edited by frigitar, 24 April 2015 - 03:56 AM.


#4 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 10,807 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:03:28 AM

Posted 23 April 2015 - 01:42 PM

I can remove all those files for you, but I wish to identify the infection, variants such as, Cryptolocker, do have a way to decrypt the files. Turn Off your security, then Disconnect fron the Internet and  run the IDTool.


No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#5 frigitar

frigitar
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:09:28 AM

Posted 28 April 2015 - 11:57 AM

Hi JSntgRvr,

 

sorry I was apprehensive because of the warning earlier. Ran the IDtool, here is the output:

 

Infection Detection Tool v1.6 - Nathan Scott
--------------------------------------------
Date/Time: 28.04.2015 18:49:48
Operating System: Windows 7
Service Pack: Service Pack 1
Version Number: 6.1
Product Type: Workstation
--------------------------------------------
[Detected Flags]
1.|  Possible CryptoWall Flag , HKCU\Software\3C8BCB27F28EE55BA24B27EB9AB9390A\022347999AAABBBE
 

Thanks,

frig

 

EDIT: Also, there are 2 types of files on my computer : HELP_RESTORE_FILES.txt (text in English) and HELP_DECRYPT.txt (text in German)



#6 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 10,807 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:03:28 AM

Posted 28 April 2015 - 08:20 PM

The computer has been infected with a Ransomware virus, Cryptowall. Unfortunately, we are still unable to reverse the damages done by this virus. All your files, in all drives are encrypted, and there is no easy way to decrypt these files. You can read about this virus here:

http://www.bleepingcomputer.com/virus-removal/cryptowall-ransomware-information#restore

BleepingComputer.com has created a small utility that will find the Registry key created by CryptoWall and then export its list of encrypted files to a text file for you. This tool will also allow you to backup the encrypted files to another location in the event that you want to archive the encrypted files and reformat the machine.If you wish to generate a list of files that have been encrypted, you can download the ListCWall tool, which will generate a ListCwall.txt report.

http://www.bleepingcomputer.com/download/listcwall/

There is an active CryptoWall support topic, which contains discussion and the experiences of a variety of IT consultants, end users, and companies who have been affected by CryptoWall. If you are interested in this infection or wish to ask questions about it, please visit the CryptoWall support topic. Once at the topic, and if you are a member, you can ask or answer questions and subscribe in order to get notifications when someone adds more information to the topic.

http://www.bleepingcomputer.com/forums/t/532879/cryptowall-new-variant-of-cryptodefense/

Please refer to the following article.

http://www.dslreports.com/faq/10063

We wont ask a member to reformat the computer, but you should have that in mind. If you still making financial transactions with your computer, I would suggest you contact all financial institutions you deal with and change your password using another computer.

It is dangerous and incorrect to assume that simply because the file that caused this issue has been removed, the computer is now secure.
 
Please download this attached and save it in the same directory as FRST.

  • Start FRST with Administrator privileges.
  • Press the Fix button.
  • When finished, a log file (Fixlog.txt) pops up and is saved to the same location the tool was run from.
    Please copy and paste its contents in your next reply.

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#7 frigitar

frigitar
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:09:28 AM

Posted 05 May 2015 - 03:50 AM

Thanks for your help and patience...  I'll inform myself about the best next steps from here on.

 

frig



#8 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 10,807 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:03:28 AM

Posted 05 May 2015 - 12:02 PM

Thanks for the feedback. Will now close the topic.


No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users