Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Cryptowall 3.0 infection


  • Please log in to reply
9 replies to this topic

#1 cyndi2966

cyndi2966

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:03:08 AM

Posted 02 September 2015 - 04:22 PM

Hi all, 

 

A computer at work got infected today with the Cryptowall 3.0 virus.  All her data files are encrypted.  We have a backup of data files.  Would like to clean the system and go from there before (if at all) reformatting and restoring.  As far as I know, no financial transactions occur on the system but the accounting software is on the computer but they don't have it linked to any bank accounts or anything financial.  

 

Waiting for my next step.  I will download the files needed - I saw them in another cryptowall post.- and be ready to run when you get back to me.

 

Thanks so much,

Cyndi



BC AdBot (Login to Remove)

 


m

#2 nasdaq

nasdaq

  • Malware Response Team
  • 38,256 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:02:08 AM

Posted 03 September 2015 - 07:47 AM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

This is the infection - CryptoWall and HELP_DECRYPT Ransomware Information Guide
http://www.bleepingcomputer.com/virus-removal/cryptowall-ransomware-information

Other than paying the ransom if it's not too late there is nothing we can do to restore your files.
I know one thing I would not trust them, your call.

If you want us to clean what has been left over the the infections please run these tools and submit the logs for my review.

Please download AdwCleaner by Xplode onto your Desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Click the Report button and the report will open in Notepad.
IMPORTANT
  • If you click the Clean button all items listed in the report will be removed.
If you find some false positive items or programs that you wish to keep, Close the AdwCleaner windows.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Check off the element(s) you wish to keep.
  • Click on the Clean button follow the prompts.
  • A log file will automatically open after the scan has finished.
  • Please post the content of that log file with your next answer.
  • You can find the log file at C:\AdwCleaner[Sn].txt (n is a number).
===

Download the version of this tool for your operating system.
Farbar Recovery Scan Tool (64 bit)
Farbar Recovery Scan Tool (32 bit)
and save it to a folder on your computer's Desktop.
Double-click to run it. When the tool opens click Yes to disclaimer.
Press Scan button.
It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
===

Please paste the logs in your next reply DO NOT ATTACH THEM unless specified.
To attach a file select the "More Reply Option" and follow the instructions.

Wait for further instructions.

#3 cyndi2966

cyndi2966
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:03:08 AM

Posted 03 September 2015 - 06:56 PM

Hi,

 

I have run the two scans and below are the contents of the reports/logs.

 

# AdwCleaner v5.005 - Logfile created 03/09/2015 at 19:45:48
# Updated 31/08/2015 by Xplode
# Database : 2015-08-31.2 [Local]
# Operating system : Windows 7 Professional Service Pack 1 (x64)
# Username : EileenCCI - EILEENCCI-PC
# Running from : C:\Users\EileenCCI\Desktop\AdwCleaner (1).exe
# Option : Cleaning
 
***** [ Services ] *****
 
 
***** [ Folders ] *****
 
 
***** [ Files ] *****
 
[-] File Deleted : C:\Users\Public\Desktop\eBay.lnk
 
***** [ Shortcuts ] *****
 
 
***** [ Scheduled tasks ] *****
 
 
***** [ Registry ] *****
 
 
***** [ Web browsers ] *****
 
 
*************************
 
:: Winsock settings cleared
 
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [689 bytes] ##########
 
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:31-08-2015
Ran by EileenCCI (administrator) on EILEENCCI-PC (03-09-2015 19:53:06)
Running from C:\Users\EileenCCI\Desktop
Loaded Profiles: EileenCCI (Available Profiles: EileenCCI)
Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Carbonite, Inc. (www.carbonite.com)) C:\Program Files\Carbonite\Carbonite Backup\CarboniteService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(Intuit) C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
(Intuit Inc.) C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe
(Dell Inc.) C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Atheros) C:\Program Files (x86)\Dell Wireless\Ath_WlanAgent.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intuit Inc.) C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
(Intuit Inc.) C:\Program Files (x86)\Intuit\QuickBooks 2014\QBW32.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Carbonite, Inc.) C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe
(McAfee, Inc.) C:\Program Files\mcafee\MSC\McAPExe.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(McAfee, Inc.) C:\Program Files\mcafee\VirusScan\McVsShld.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\Core\mchost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PrivacyIconClient.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
(Dell Inc.) C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe
(Dell Products, LP.) C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe
(Dell Inc.) C:\Program Files (x86)\Dell Update\DellUpService.exe
(Dell Inc.) C:\Program Files (x86)\Dell Update\DellUpTray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\CSP\1.6.1008.0\McCSPServiceHost.exe
(SoftThinks SAS) C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe
(Dell Inc.) C:\Program Files\Dell\DellDataVault\DellDataVault.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\Core\mchost.exe
(Farbar) C:\Users\EileenCCI\Desktop\FRST64 (1).exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6463080 2012-01-16] (Realtek Semiconductor)
HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PIconStartup.exe [133400 2011-12-16] (Intel Corporation)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-27] (Intel Corporation)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-01] (Intel Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Intuit SyncManager] => C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe [3775800 2014-02-27] (Intuit Inc. All rights reserved.)
HKLM-x32\...\Run: [Carbonite Backup] => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe [1066192 2015-07-14] (Carbonite, Inc.)
HKLM-x32\...\Run: [vsadmin] => C
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-517160071-1547752724-213923089-1000\...\Run: [vsadmin] => C:\Users\EileenCCI\AppData\Roaming\vcwllo.exe
HKU\S-1-5-21-517160071-1547752724-213923089-1000\...\RunOnce: [Uninstall C:\Users\EileenCCI\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\EileenCCI\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64"
ShellIconOverlayIdentifiers: [ Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-07-14] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [ Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-07-14] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [ Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-07-14] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-07-14] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-07-14] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-07-14] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [DBARFileBackuped] -> {831cebdd-6baf-4432-be76-9e0989c14aef} => C:\Windows\system32\mscoree.dll [2010-11-20] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [DBARFileNotBackuped] -> {275e4fd7-21ef-45cf-a836-832e5d2cc1b3} => C:\Windows\system32\mscoree.dll [2010-11-20] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-07-14] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [ Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-07-14] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [ Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-07-14] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-07-14] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-07-14] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-07-14] (Carbonite, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Intuit Data Protect.lnk [2014-02-25]
ShortcutTarget: Intuit Data Protect.lnk -> C:\Program Files (x86)\Common Files\Intuit\DataProtect\IntuitDataProtect.exe (Intuit Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk [2014-02-25]
ShortcutTarget: QuickBooks Update Agent.lnk -> C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\QuickBooks_Standard_21.lnk [2014-02-25]
ShortcutTarget: QuickBooks_Standard_21.lnk -> C:\Program Files (x86)\Intuit\QuickBooks 2014\QBW32.EXE (Intuit Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\restore_files_sqkjs.html [2015-09-02] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\restore_files_sqkjs.txt [2015-09-02] ()
Startup: C:\Users\EileenCCI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\restore_files_sqkjs.html [2015-09-02] ()
Startup: C:\Users\EileenCCI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\restore_files_sqkjs.txt [2015-09-02] ()
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{5FCE3D3D-AF14-43EE-A06F-CE492B7256C1}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{E8A0AE41-3ABF-45CD-9CC5-60F4E40B4FE4}: [DhcpNameServer] 192.168.1.1
 
Internet Explorer:
==================
HKU\S-1-5-21-517160071-1547752724-213923089-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell13.msn.com/?pc=DCJB
HKU\S-1-5-21-517160071-1547752724-213923089-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-517160071-1547752724-213923089-1000 -> DefaultScope {E32CDABE-3662-4E60-9623-57CDCBFADAF3} URL = hxxps://search.yahoo.com/search?fr=mcafee&type=C011US105D20140715&p={searchTerms}
SearchScopes: HKU\S-1-5-21-517160071-1547752724-213923089-1000 -> {2A15D47E-C65C-4DFE-9AAB-3732165C1AFE} URL = 
SearchScopes: HKU\S-1-5-21-517160071-1547752724-213923089-1000 -> {DECA3892-BA8F-44b8-A993-A466AD694AE4} URL = hxxp://search.yahoo.com/search?fr=mcafee&p={searchTerms}
SearchScopes: HKU\S-1-5-21-517160071-1547752724-213923089-1000 -> {E32CDABE-3662-4E60-9623-57CDCBFADAF3} URL = hxxps://search.yahoo.com/search?fr=mcafee&type=C011US105D20140715&p={searchTerms}
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-07-14] (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2015-07-14] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-07-14] (Microsoft Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2015-07-14] (Microsoft Corporation)
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mcieplg.dll [2015-08-04] (McAfee, Inc.)
Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\mcieplg.dll [2015-08-04] (McAfee, Inc.)
Handler-x32: intu-help-qb7 - {5A03BD9D-766D-47A6-8E87-CD90F60BE245} - C:\Program Files (x86)\Intuit\QuickBooks 2014\HelpAsyncPluggableProtocol.dll [2014-12-10] (Intuit, Inc.)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-02-03] (Microsoft Corporation)
Handler-x32: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - C:\Windows\SysWOW64\mscoree.dll [2010-11-20] (Microsoft Corporation)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mcieplg.dll [2015-08-04] (McAfee, Inc.)
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\mcieplg.dll [2015-08-04] (McAfee, Inc.)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\MSC\McSnIePl64.dll [2015-08-21] (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll [2015-08-21] (McAfee, Inc.)
 
FireFox:
========
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2015-08-21] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2015-08-21] ()
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2014-03-20] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor
FF Extension: McAfee WebAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor [2014-02-25]
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2014-02-25]
 
Chrome: 
=======
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2015-08-10]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2015-08-10]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2765496 2015-07-14] (Microsoft Corporation)
R2 DellDataVault; C:\Program Files\Dell\DellDataVault\DellDataVault.exe [2573520 2015-05-22] (Dell Inc.)
R2 DellDataVaultWiz; C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe [201936 2015-05-22] (Dell Inc.)
R2 DellUpdate; C:\Program Files (x86)\Dell Update\DellUpService.exe [237272 2015-08-27] (Dell Inc.)
R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [368048 2015-07-21] (McAfee, Inc.)
R2 McAfee SiteAdvisor Service; C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe [155368 2015-08-04] (McAfee, Inc.)
R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [782608 2015-08-21] (McAfee, Inc.)
R2 mcbootdelaystartsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [368048 2015-07-21] (McAfee, Inc.)
R2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\1.6.1008.0\McCSPServiceHost.exe [1694152 2015-07-23] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [368048 2015-07-21] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [368048 2015-07-21] (McAfee, Inc.)
S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [639456 2015-07-17] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [368048 2015-07-21] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [368048 2015-07-21] (McAfee, Inc.)
R3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [232656 2015-06-29] (McAfee, Inc.)
R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe [373704 2015-07-06] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [254792 2015-06-29] (McAfee, Inc.)
R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [368048 2015-07-21] (McAfee, Inc.)
R2 QBCFMonitorService; C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe [45056 2014-12-10] (Intuit) [File not signed]
S3 QBFCService; C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe [65536 2013-10-10] (Intuit Inc.) [File not signed]
R2 QBVSS; C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe [1248256 2013-10-10] (Intuit Inc.) [File not signed]
R2 SftService; C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe [1911312 2013-08-30] (SoftThinks SAS)
R2 SupportAssistAgent; C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [20648 2015-06-11] (Dell Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-12-02] (Microsoft Corporation)
R2 ZAtheros Wlan Agent; C:\Program Files (x86)\Dell Wireless\Ath_WlanAgent.exe [73728 2012-02-08] (Atheros) [File not signed]
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [77536 2015-07-02] (McAfee, Inc.)
R3 DDDriver; C:\Windows\System32\drivers\DDDriver64Dcsa.sys [23760 2015-02-26] (Dell Computer Corporation)
R3 DellProf; C:\Windows\System32\drivers\DellProf.sys [24240 2015-05-22] (Dell Computer Corporation)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [207208 2015-05-19] (McAfee, Inc.)
R3 mfeaack; C:\Windows\System32\drivers\mfeaack.sys [412440 2015-07-02] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [347800 2015-07-02] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [496888 2015-07-02] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [875928 2015-07-02] (McAfee, Inc.)
R3 mfencbdc; C:\Windows\System32\DRIVERS\mfencbdc.sys [529080 2015-06-28] (McAfee, Inc.)
S3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [109728 2015-06-28] (McAfee, Inc.)
R3 mfesapsn; C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys [37960 2015-08-04] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [344704 2015-07-02] (McAfee, Inc.)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-09-03 19:53 - 2015-09-03 19:53 - 00020682 _____ C:\Users\EileenCCI\Desktop\FRST.txt
2015-09-03 19:52 - 2015-09-03 19:53 - 00000000 ____D C:\FRST
2015-09-03 19:52 - 2015-09-03 19:51 - 02188800 _____ (Farbar) C:\Users\EileenCCI\Desktop\FRST64 (1).exe
2015-09-03 19:43 - 2013-09-04 12:47 - 00000117 ____H C:\DBAR_Ver.txt
2015-09-03 19:39 - 2015-09-02 17:25 - 05635829 _____ (Swearware) C:\Users\EileenCCI\Desktop\ComboFix.exe
2015-09-03 19:39 - 2015-09-02 17:25 - 02019656 _____ (Bleeping Computer, LLC) C:\Users\EileenCCI\Desktop\rkill.exe
2015-09-03 19:39 - 2015-09-02 17:24 - 04404952 _____ (Kaspersky Lab ZAO) C:\Users\EileenCCI\Desktop\tdsskiller.exe
2015-09-03 19:39 - 2015-09-02 17:24 - 01799392 _____ (Malwarebytes Corporation) C:\Users\EileenCCI\Desktop\JRT (2).exe
2015-09-03 19:39 - 2015-09-02 17:24 - 01654272 _____ C:\Users\EileenCCI\Desktop\AdwCleaner (1).exe
2015-09-03 19:31 - 2015-09-03 19:45 - 00000000 ____D C:\AdwCleaner
2015-09-02 11:47 - 2015-09-02 11:47 - 00005100 _____ C:\Users\Public\restore_files_sqkjs.html
2015-09-02 11:47 - 2015-09-02 11:47 - 00005100 _____ C:\Users\EileenCCI\Desktop\RESTORE_FILES.HTML
2015-09-02 11:47 - 2015-09-02 11:47 - 00002261 _____ C:\Users\Public\restore_files_sqkjs.txt
2015-09-02 11:47 - 2015-09-02 11:47 - 00002261 _____ C:\Users\EileenCCI\Desktop\RESTORE_FILES.TXT
2015-09-02 11:46 - 2015-09-02 11:46 - 00005100 _____ C:\Users\Public\Downloads\restore_files_sqkjs.html
2015-09-02 11:46 - 2015-09-02 11:46 - 00005100 _____ C:\Users\EileenCCI\restore_files_sqkjs.html
2015-09-02 11:46 - 2015-09-02 11:46 - 00002261 _____ C:\Users\Public\Downloads\restore_files_sqkjs.txt
2015-09-02 11:46 - 2015-09-02 11:46 - 00002261 _____ C:\Users\EileenCCI\restore_files_sqkjs.txt
2015-09-02 11:43 - 2015-09-02 11:43 - 00005100 _____ C:\Users\EileenCCI\Downloads\restore_files_sqkjs.html
2015-09-02 11:43 - 2015-09-02 11:43 - 00005100 _____ C:\Users\EileenCCI\Documents\restore_files_sqkjs.html
2015-09-02 11:43 - 2015-09-02 11:43 - 00002261 _____ C:\Users\EileenCCI\Downloads\restore_files_sqkjs.txt
2015-09-02 11:43 - 2015-09-02 11:43 - 00002261 _____ C:\Users\EileenCCI\Documents\restore_files_sqkjs.txt
2015-09-02 11:36 - 2015-09-02 11:46 - 00005100 _____ C:\Users\EileenCCI\AppData\Roaming\Microsoft\Windows\Start Menu\restore_files_sqkjs.html
2015-09-02 11:36 - 2015-09-02 11:46 - 00002261 _____ C:\Users\EileenCCI\AppData\Roaming\Microsoft\Windows\Start Menu\restore_files_sqkjs.txt
2015-09-02 11:36 - 2015-09-02 11:36 - 00005100 _____ C:\Users\EileenCCI\AppData\Roaming\restore_files_sqkjs.html
2015-09-02 11:36 - 2015-09-02 11:36 - 00005100 _____ C:\Users\EileenCCI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\restore_files_sqkjs.html
2015-09-02 11:36 - 2015-09-02 11:36 - 00005100 _____ C:\Users\EileenCCI\AppData\restore_files_sqkjs.html
2015-09-02 11:36 - 2015-09-02 11:36 - 00002261 _____ C:\Users\EileenCCI\AppData\Roaming\restore_files_sqkjs.txt
2015-09-02 11:36 - 2015-09-02 11:36 - 00002261 _____ C:\Users\EileenCCI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\restore_files_sqkjs.txt
2015-09-02 11:36 - 2015-09-02 11:36 - 00002261 _____ C:\Users\EileenCCI\AppData\restore_files_sqkjs.txt
2015-09-02 11:25 - 2015-09-02 11:46 - 00005100 _____ C:\Users\Public\Documents\restore_files_sqkjs.html
2015-09-02 11:25 - 2015-09-02 11:46 - 00002261 _____ C:\Users\Public\Documents\restore_files_sqkjs.txt
2015-09-02 11:25 - 2015-09-02 11:43 - 00005100 _____ C:\Users\EileenCCI\AppData\Local\restore_files_sqkjs.html
2015-09-02 11:25 - 2015-09-02 11:43 - 00002261 _____ C:\Users\EileenCCI\AppData\Local\restore_files_sqkjs.txt
2015-09-02 11:25 - 2015-09-02 11:25 - 00005100 _____ C:\Users\Public\Desktop\restore_files_sqkjs.html
2015-09-02 11:25 - 2015-09-02 11:25 - 00005100 _____ C:\Users\Default\restore_files_sqkjs.html
2015-09-02 11:25 - 2015-09-02 11:25 - 00005100 _____ C:\Users\Default\Downloads\restore_files_sqkjs.html
2015-09-02 11:25 - 2015-09-02 11:25 - 00005100 _____ C:\Users\Default\Documents\restore_files_sqkjs.html
2015-09-02 11:25 - 2015-09-02 11:25 - 00005100 _____ C:\Users\Default\Desktop\restore_files_sqkjs.html
2015-09-02 11:25 - 2015-09-02 11:25 - 00005100 _____ C:\Users\Default\AppData\Roaming\restore_files_sqkjs.html
2015-09-02 11:25 - 2015-09-02 11:25 - 00005100 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\restore_files_sqkjs.html
2015-09-02 11:25 - 2015-09-02 11:25 - 00005100 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\restore_files_sqkjs.html
2015-09-02 11:25 - 2015-09-02 11:25 - 00005100 _____ C:\Users\Default\AppData\restore_files_sqkjs.html
2015-09-02 11:25 - 2015-09-02 11:25 - 00005100 _____ C:\Users\Default\AppData\Local\restore_files_sqkjs.html
2015-09-02 11:25 - 2015-09-02 11:25 - 00005100 _____ C:\Users\Default User\Downloads\restore_files_sqkjs.html
2015-09-02 11:25 - 2015-09-02 11:25 - 00005100 _____ C:\Users\Default User\Documents\restore_files_sqkjs.html
2015-09-02 11:25 - 2015-09-02 11:25 - 00005100 _____ C:\Users\Default User\Desktop\restore_files_sqkjs.html
2015-09-02 11:25 - 2015-09-02 11:25 - 00005100 _____ C:\Users\Default User\AppData\Roaming\restore_files_sqkjs.html
2015-09-02 11:25 - 2015-09-02 11:25 - 00005100 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\restore_files_sqkjs.html
2015-09-02 11:25 - 2015-09-02 11:25 - 00005100 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\restore_files_sqkjs.html
2015-09-02 11:25 - 2015-09-02 11:25 - 00005100 _____ C:\Users\Default User\AppData\restore_files_sqkjs.html
2015-09-02 11:25 - 2015-09-02 11:25 - 00005100 _____ C:\Users\Default User\AppData\Local\restore_files_sqkjs.html
2015-09-02 11:25 - 2015-09-02 11:25 - 00005100 _____ C:\ProgramData\Microsoft\Windows\Start Menu\restore_files_sqkjs.html
2015-09-02 11:25 - 2015-09-02 11:25 - 00005100 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\restore_files_sqkjs.html
2015-09-02 11:25 - 2015-09-02 11:25 - 00002261 _____ C:\Users\Public\Desktop\restore_files_sqkjs.txt
2015-09-02 11:25 - 2015-09-02 11:25 - 00002261 _____ C:\Users\Default\restore_files_sqkjs.txt
2015-09-02 11:25 - 2015-09-02 11:25 - 00002261 _____ C:\Users\Default\Downloads\restore_files_sqkjs.txt
2015-09-02 11:25 - 2015-09-02 11:25 - 00002261 _____ C:\Users\Default\Documents\restore_files_sqkjs.txt
2015-09-02 11:25 - 2015-09-02 11:25 - 00002261 _____ C:\Users\Default\Desktop\restore_files_sqkjs.txt
2015-09-02 11:25 - 2015-09-02 11:25 - 00002261 _____ C:\Users\Default\AppData\Roaming\restore_files_sqkjs.txt
2015-09-02 11:25 - 2015-09-02 11:25 - 00002261 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\restore_files_sqkjs.txt
2015-09-02 11:25 - 2015-09-02 11:25 - 00002261 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\restore_files_sqkjs.txt
2015-09-02 11:25 - 2015-09-02 11:25 - 00002261 _____ C:\Users\Default\AppData\restore_files_sqkjs.txt
2015-09-02 11:25 - 2015-09-02 11:25 - 00002261 _____ C:\Users\Default\AppData\Local\restore_files_sqkjs.txt
2015-09-02 11:25 - 2015-09-02 11:25 - 00002261 _____ C:\Users\Default User\Downloads\restore_files_sqkjs.txt
2015-09-02 11:25 - 2015-09-02 11:25 - 00002261 _____ C:\Users\Default User\Documents\restore_files_sqkjs.txt
2015-09-02 11:25 - 2015-09-02 11:25 - 00002261 _____ C:\Users\Default User\Desktop\restore_files_sqkjs.txt
2015-09-02 11:25 - 2015-09-02 11:25 - 00002261 _____ C:\Users\Default User\AppData\Roaming\restore_files_sqkjs.txt
2015-09-02 11:25 - 2015-09-02 11:25 - 00002261 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\restore_files_sqkjs.txt
2015-09-02 11:25 - 2015-09-02 11:25 - 00002261 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\restore_files_sqkjs.txt
2015-09-02 11:25 - 2015-09-02 11:25 - 00002261 _____ C:\Users\Default User\AppData\restore_files_sqkjs.txt
2015-09-02 11:25 - 2015-09-02 11:25 - 00002261 _____ C:\Users\Default User\AppData\Local\restore_files_sqkjs.txt
2015-09-02 11:25 - 2015-09-02 11:25 - 00002261 _____ C:\ProgramData\Microsoft\Windows\Start Menu\restore_files_sqkjs.txt
2015-09-02 11:25 - 2015-09-02 11:25 - 00002261 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\restore_files_sqkjs.txt
2015-09-02 11:24 - 2015-09-02 11:25 - 00005100 _____ C:\ProgramData\restore_files_sqkjs.html
2015-09-02 11:24 - 2015-09-02 11:25 - 00002261 _____ C:\ProgramData\restore_files_sqkjs.txt
2015-09-02 11:24 - 2015-09-02 11:24 - 00005100 _____ C:\Program Files\restore_files_sqkjs.html
2015-09-02 11:24 - 2015-09-02 11:24 - 00002261 _____ C:\Program Files\restore_files_sqkjs.txt
2015-09-02 11:22 - 2015-09-02 11:22 - 00005100 _____ C:\Program Files\Common Files\restore_files_sqkjs.html
2015-09-02 11:22 - 2015-09-02 11:22 - 00002261 _____ C:\Program Files\Common Files\restore_files_sqkjs.txt
2015-09-02 11:21 - 2015-09-02 11:47 - 00005100 _____ C:\Users\restore_files_sqkjs.html
2015-09-02 11:21 - 2015-09-02 11:47 - 00002261 _____ C:\Users\restore_files_sqkjs.txt
2015-09-02 11:19 - 2015-09-02 11:19 - 00000250 _____ C:\Users\EileenCCI\Documents\Recovery_File_xgietrehj.txt
2015-08-31 12:54 - 2015-09-02 11:36 - 00037294 _____ C:\Users\EileenCCI\Documents\3630 NEW CLIENT CHECKLIST.doc.abc
2015-08-31 11:23 - 2015-09-02 11:37 - 00059838 _____ C:\Users\EileenCCI\Documents\DIRECT DEPOSIT FORM.pdf.abc
2015-08-31 11:02 - 2015-09-02 11:37 - 00492974 _____ C:\Users\EileenCCI\Documents\I-9.pdf.abc
2015-08-31 10:59 - 2015-09-02 11:43 - 00027582 _____ C:\Users\EileenCCI\Documents\RI FORM W-4 2015.pdf.abc
2015-08-31 10:57 - 2015-09-02 11:37 - 00127790 _____ C:\Users\EileenCCI\Documents\FEDERAL FORM W-4 2015.pdf.abc
2015-08-31 07:14 - 2015-08-31 07:14 - 00000000 ____D C:\Program Files (x86)\Dell Update
2015-08-24 13:05 - 2015-08-10 21:20 - 25191936 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-08-24 13:05 - 2015-08-10 21:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-08-24 13:05 - 2015-08-10 20:33 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-08-24 13:05 - 2015-08-10 20:20 - 19871232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-08-24 12:40 - 2015-09-02 11:36 - 00649422 _____ C:\Users\EileenCCI\Documents\BCBS Renewal.pdf.abc
2015-08-24 11:26 - 2015-09-02 11:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Carbonite
2015-08-24 11:26 - 2015-08-24 11:26 - 00002134 _____ C:\Users\Public\Desktop\Carbonite InfoCenter.lnk
2015-08-18 12:25 - 2015-07-30 09:13 - 00124624 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-18 12:25 - 2015-07-30 09:13 - 00103120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-08-18 11:54 - 2015-07-20 20:39 - 00389840 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-08-18 11:54 - 2015-07-20 20:12 - 00342736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-08-18 11:54 - 2015-07-16 16:54 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-08-18 11:54 - 2015-07-16 16:37 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-08-18 11:54 - 2015-07-16 16:36 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-08-18 11:54 - 2015-07-16 16:36 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-08-18 11:54 - 2015-07-16 16:36 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-08-18 11:54 - 2015-07-16 16:35 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-08-18 11:54 - 2015-07-16 16:35 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-08-18 11:54 - 2015-07-16 16:27 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-08-18 11:54 - 2015-07-16 16:26 - 05923328 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-08-18 11:54 - 2015-07-16 16:26 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-08-18 11:54 - 2015-07-16 16:23 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-08-18 11:54 - 2015-07-16 16:21 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-08-18 11:54 - 2015-07-16 16:21 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-08-18 11:54 - 2015-07-16 16:21 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-08-18 11:54 - 2015-07-16 16:21 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-08-18 11:54 - 2015-07-16 16:12 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-08-18 11:54 - 2015-07-16 16:08 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-08-18 11:54 - 2015-07-16 16:00 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-08-18 11:54 - 2015-07-16 15:55 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-08-18 11:54 - 2015-07-16 15:54 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-08-18 11:54 - 2015-07-16 15:51 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-08-18 11:54 - 2015-07-16 15:51 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-08-18 11:54 - 2015-07-16 15:51 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-08-18 11:54 - 2015-07-16 15:50 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-08-18 11:54 - 2015-07-16 15:50 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-08-18 11:54 - 2015-07-16 15:49 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-08-18 11:54 - 2015-07-16 15:45 - 02279424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-08-18 11:54 - 2015-07-16 15:43 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-08-18 11:54 - 2015-07-16 15:43 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-08-18 11:54 - 2015-07-16 15:41 - 00479232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-08-18 11:54 - 2015-07-16 15:39 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-08-18 11:54 - 2015-07-16 15:39 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-08-18 11:54 - 2015-07-16 15:38 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-08-18 11:54 - 2015-07-16 15:36 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-08-18 11:54 - 2015-07-16 15:35 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-08-18 11:54 - 2015-07-16 15:34 - 14451200 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-08-18 11:54 - 2015-07-16 15:33 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-08-18 11:54 - 2015-07-16 15:32 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-08-18 11:54 - 2015-07-16 15:29 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-08-18 11:54 - 2015-07-16 15:24 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-08-18 11:54 - 2015-07-16 15:20 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-08-18 11:54 - 2015-07-16 15:19 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-08-18 11:54 - 2015-07-16 15:17 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-08-18 11:54 - 2015-07-16 15:12 - 04520448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-08-18 11:54 - 2015-07-16 15:12 - 02427904 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-08-18 11:54 - 2015-07-16 15:10 - 12856832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-08-18 11:54 - 2015-07-16 15:06 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-08-18 11:54 - 2015-07-16 15:06 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-08-18 11:54 - 2015-07-16 15:05 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-08-18 11:54 - 2015-07-16 15:01 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-08-18 11:54 - 2015-07-16 14:49 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-08-18 11:54 - 2015-07-16 14:42 - 01951232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-08-18 11:54 - 2015-07-16 14:38 - 01310720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-08-18 11:54 - 2015-07-16 14:37 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-08-18 11:06 - 2015-07-14 23:19 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\basesrv.dll
2015-08-18 10:59 - 2015-07-28 16:09 - 00017344 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2015-08-18 10:59 - 2015-07-28 16:05 - 01116672 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-08-18 10:59 - 2015-07-28 16:05 - 00774656 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-08-18 10:59 - 2015-07-28 16:05 - 00743424 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-08-18 10:59 - 2015-07-28 16:05 - 00437760 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-08-18 10:59 - 2015-07-28 16:05 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-08-18 10:59 - 2015-07-28 16:05 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-08-18 10:59 - 2015-07-28 15:55 - 01148416 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-08-18 10:55 - 2015-07-16 15:12 - 06131200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2015-08-18 10:55 - 2015-07-16 15:12 - 00856064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2015-08-18 10:55 - 2015-07-16 15:12 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2015-08-18 10:55 - 2015-07-16 15:11 - 07077376 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-08-18 10:55 - 2015-07-16 15:11 - 01057792 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2015-08-18 10:55 - 2015-07-16 15:11 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2015-08-18 10:55 - 2015-07-11 09:15 - 00429568 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2015-08-18 10:54 - 2015-07-15 14:15 - 05568960 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-08-18 10:54 - 2015-07-15 14:15 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-08-18 10:54 - 2015-07-15 14:15 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-08-18 10:54 - 2015-07-15 14:15 - 00094656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2015-08-18 10:54 - 2015-07-15 14:12 - 01730496 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-08-18 10:54 - 2015-07-15 14:11 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2015-08-18 10:54 - 2015-07-15 14:11 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2015-08-18 10:54 - 2015-07-15 14:11 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2015-08-18 10:54 - 2015-07-15 14:11 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-08-18 10:54 - 2015-07-15 14:11 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2015-08-18 10:54 - 2015-07-15 14:10 - 01743360 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll
2015-08-18 10:54 - 2015-07-15 14:10 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-08-18 10:54 - 2015-07-15 14:10 - 01216512 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-08-18 10:54 - 2015-07-15 14:10 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-08-18 10:54 - 2015-07-15 14:10 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-08-18 10:54 - 2015-07-15 14:10 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-08-18 10:54 - 2015-07-15 14:10 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-08-18 10:54 - 2015-07-15 14:10 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-08-18 10:54 - 2015-07-15 14:10 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-08-18 10:54 - 2015-07-15 14:10 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-08-18 10:54 - 2015-07-15 14:10 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-08-18 10:54 - 2015-07-15 14:10 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-08-18 10:54 - 2015-07-15 14:10 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-08-18 10:54 - 2015-07-15 14:10 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-08-18 10:54 - 2015-07-15 14:10 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-08-18 10:54 - 2015-07-15 14:10 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2015-08-18 10:54 - 2015-07-15 14:10 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-08-18 10:54 - 2015-07-15 14:10 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-08-18 10:54 - 2015-07-15 14:10 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-08-18 10:54 - 2015-07-15 14:10 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-08-18 10:54 - 2015-07-15 14:10 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-08-18 10:54 - 2015-07-15 14:10 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2015-08-18 10:54 - 2015-07-15 14:10 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2015-08-18 10:54 - 2015-07-15 14:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-08-18 10:54 - 2015-07-15 14:09 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-08-18 10:54 - 2015-07-15 14:05 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-08-18 10:54 - 2015-07-15 14:05 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-08-18 10:54 - 2015-07-15 14:00 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-08-18 10:54 - 2015-07-15 14:00 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-08-18 10:54 - 2015-07-15 14:00 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 14:00 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 14:00 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 14:00 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 14:00 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 14:00 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 14:00 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 14:00 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 14:00 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 14:00 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 14:00 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 14:00 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 14:00 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 14:00 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 14:00 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 14:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 14:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 14:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 14:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 14:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 14:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 14:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 14:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 14:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 14:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 14:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 14:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 14:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 13:59 - 03989952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-08-18 10:54 - 2015-07-15 13:59 - 03934656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-08-18 10:54 - 2015-07-15 13:56 - 01311768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-08-18 10:54 - 2015-07-15 13:55 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-08-18 10:54 - 2015-07-15 13:55 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-08-18 10:54 - 2015-07-15 13:55 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-08-18 10:54 - 2015-07-15 13:55 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-08-18 10:54 - 2015-07-15 13:55 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-08-18 10:54 - 2015-07-15 13:54 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-08-18 10:54 - 2015-07-15 13:54 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-08-18 10:54 - 2015-07-15 13:54 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-08-18 10:54 - 2015-07-15 13:54 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2015-08-18 10:54 - 2015-07-15 13:54 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2015-08-18 10:54 - 2015-07-15 13:54 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-08-18 10:54 - 2015-07-15 13:54 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2015-08-18 10:54 - 2015-07-15 13:53 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2015-08-18 10:54 - 2015-07-15 13:53 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2015-08-18 10:54 - 2015-07-15 13:53 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2015-08-18 10:54 - 2015-07-15 13:53 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-08-18 10:54 - 2015-07-15 13:53 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-08-18 10:54 - 2015-07-15 13:53 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2015-08-18 10:54 - 2015-07-15 13:49 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-08-18 10:54 - 2015-07-15 13:48 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-08-18 10:54 - 2015-07-15 13:44 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-08-18 10:54 - 2015-07-15 13:44 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-08-18 10:54 - 2015-07-15 13:44 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 13:44 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 13:44 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 13:44 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 13:44 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 13:44 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 13:44 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 13:44 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 13:44 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 13:44 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 13:44 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 13:44 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 13:44 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 13:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 13:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 13:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 13:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 13:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 13:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 13:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 13:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 13:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 13:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 13:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 12:46 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-08-18 10:54 - 2015-07-15 12:46 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-08-18 10:54 - 2015-07-15 12:46 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-08-18 10:54 - 2015-07-15 12:37 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2015-08-18 10:54 - 2015-07-15 12:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2015-08-18 10:54 - 2015-07-15 12:34 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 12:34 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 12:34 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-08-18 10:54 - 2015-07-15 12:34 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-08-18 10:41 - 2015-07-01 16:49 - 00260096 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2015-08-18 10:41 - 2015-07-01 16:48 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2015-08-18 10:41 - 2015-07-01 16:30 - 00206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2015-08-18 10:41 - 2015-07-01 16:30 - 00082432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2015-08-18 10:40 - 2015-07-14 23:19 - 02004992 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2015-08-18 10:40 - 2015-07-14 23:19 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-08-18 10:40 - 2015-07-14 23:14 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2015-08-18 10:40 - 2015-07-14 23:13 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2015-08-18 10:40 - 2015-07-14 22:55 - 01390592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2015-08-18 10:40 - 2015-07-14 22:55 - 01241088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2015-08-18 10:40 - 2015-07-14 22:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2015-08-18 10:40 - 2015-07-14 22:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2015-08-18 10:36 - 2015-07-30 14:06 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2015-08-18 10:36 - 2015-07-30 14:06 - 01648128 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-08-18 10:36 - 2015-07-30 14:06 - 01180160 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-08-18 10:36 - 2015-07-30 14:06 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-08-18 10:36 - 2015-07-30 14:06 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-08-18 10:36 - 2015-07-30 14:06 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-08-18 10:36 - 2015-07-30 14:06 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-08-18 10:36 - 2015-07-30 13:57 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2015-08-18 10:36 - 2015-07-30 13:57 - 01251328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2015-08-18 10:36 - 2015-07-30 13:57 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2015-08-18 10:36 - 2015-07-30 13:57 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2015-08-18 10:36 - 2015-07-30 13:57 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2015-08-18 10:36 - 2015-07-30 13:55 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2015-08-18 10:36 - 2015-07-30 12:56 - 03208192 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-08-18 10:36 - 2015-07-30 12:52 - 00372736 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-08-18 10:36 - 2015-07-30 12:49 - 00299520 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2015-08-18 10:33 - 2015-07-10 13:51 - 14177280 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-08-18 10:33 - 2015-07-10 13:34 - 12875776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2015-08-11 15:28 - 2015-07-09 13:57 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\notepad.exe
2015-08-11 15:28 - 2015-07-09 13:57 - 00193536 _____ (Microsoft Corporation) C:\Windows\notepad.exe
2015-08-11 15:28 - 2015-07-09 13:42 - 00179712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
2015-08-11 15:21 - 2015-07-20 14:12 - 03154944 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-08-11 15:21 - 2015-07-20 14:12 - 02606080 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-08-11 15:21 - 2015-07-20 14:12 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-08-11 15:21 - 2015-07-20 14:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-08-11 15:21 - 2015-07-20 14:12 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-08-11 15:21 - 2015-07-20 14:12 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-08-11 15:21 - 2015-07-20 14:12 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-08-11 15:21 - 2015-07-20 14:12 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-08-11 15:21 - 2015-07-20 14:12 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-08-11 15:21 - 2015-07-20 14:12 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-08-11 15:21 - 2015-07-20 14:12 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-08-11 15:21 - 2015-07-20 13:56 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-08-11 15:21 - 2015-07-20 13:56 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-08-11 15:21 - 2015-07-20 13:56 - 00093184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-08-11 15:21 - 2015-07-20 13:56 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-08-11 15:21 - 2015-07-20 13:56 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-08-11 15:20 - 2015-05-09 14:26 - 00493504 _____ (Microsoft Corporation) C:\Windows\system32\mcupdate_GenuineIntel.dll
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-09-03 19:51 - 2009-07-14 01:13 - 00781790 _____ C:\Windows\system32\PerfStringBackup.INI
2015-09-03 19:50 - 2013-12-02 11:42 - 01309529 _____ C:\Windows\WindowsUpdate.log
2015-09-03 19:49 - 2013-12-02 11:55 - 00000000 ____D C:\Program Files (x86)\Dell Backup and Recovery
2015-09-03 19:46 - 2009-07-14 01:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-09-03 19:46 - 2009-07-14 00:51 - 00051391 _____ C:\Windows\setupact.log
2015-09-03 19:43 - 2009-07-14 00:45 - 00021312 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-09-03 19:43 - 2009-07-14 00:45 - 00021312 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-09-02 11:59 - 2010-11-20 23:47 - 00313908 _____ C:\Windows\PFRO.log
2015-09-02 11:47 - 2010-11-21 03:16 - 00000000 ___RD C:\Users\Public\Recorded TV
2015-09-02 11:47 - 2009-07-13 23:20 - 00000000 __RHD C:\Users\Public\Libraries
2015-09-02 11:46 - 2014-02-25 12:17 - 00000000 ____D C:\Users\Public\Documents\Intuit
2015-09-02 11:46 - 2014-02-25 12:08 - 00000000 ___RD C:\Users\EileenCCI\SkyDrive
2015-09-02 11:46 - 2014-02-25 11:44 - 00000000 ___RD C:\Users\EileenCCI\Virtual Machines
2015-09-02 11:46 - 2014-02-25 11:41 - 00000000 ____D C:\Users\EileenCCI
2015-09-02 11:46 - 2008-08-05 10:45 - 00000000 ____D C:\Users\Public\Documents\Adobe PDF
2015-09-02 11:46 - 2008-04-25 14:18 - 00000000 ____D C:\Users\EileenCCI\WINDOWS
2015-09-02 11:43 - 2015-06-24 11:39 - 00160014 _____ C:\Users\EileenCCI\Documents\outstanding invoices.xlsx.abc
2015-09-02 11:43 - 2015-06-09 12:01 - 00000000 ____D C:\Users\EileenCCI\Documents\Restored_Cambridge 06092015_Files
2015-09-02 11:43 - 2015-03-24 15:21 - 00161678 _____ C:\Users\EileenCCI\Documents\update GE unpaid.xlsx.abc
2015-09-02 11:43 - 2015-03-12 09:45 - 02195022 _____ C:\Users\EileenCCI\Documents\Switzerland attendee list.zip.abc
2015-09-02 11:43 - 2015-03-12 09:43 - 02195662 _____ C:\Users\EileenCCI\Documents\Switzerland attendee list.jpg.abc
2015-09-02 11:43 - 2015-01-15 14:10 - 00112654 _____ C:\Users\EileenCCI\Documents\W-9   12-15-14.pdf.abc
2015-09-02 11:43 - 2015-01-08 10:23 - 00109454 _____ C:\Users\EileenCCI\Documents\No Permanent establishment India Disclosure Declaration.pdf.abc
2015-09-02 11:43 - 2015-01-06 11:47 - 00042414 _____ C:\Users\EileenCCI\Documents\No Permanent establishment India Disclosure Declaration.doc.abc
2015-09-02 11:43 - 2015-01-02 12:49 - 00012798 _____ C:\Users\EileenCCI\Documents\No permanent Establishment.docx.abc
2015-09-02 11:43 - 2014-12-23 14:43 - 00273934 _____ C:\Users\EileenCCI\Documents\Vendor Setup Policy - New Vendors - (vendor documents)1.pdf.abc
2015-09-02 11:43 - 2014-12-23 12:47 - 00232462 _____ C:\Users\EileenCCI\Documents\Vendor Setup Policy - New Vendors - (vendor documents) (1).pdf.abc
2015-09-02 11:43 - 2014-11-24 15:28 - 00013102 _____ C:\Users\EileenCCI\Documents\Peter Gilli.docx.abc
2015-09-02 11:43 - 2014-11-24 13:42 - 00012830 _____ C:\Users\EileenCCI\Documents\NYC Expenses.docx.abc
2015-09-02 11:43 - 2014-11-11 12:49 - 00000000 ____D C:\Users\EileenCCI\Documents\New folder
2015-09-02 11:43 - 2014-10-28 13:01 - 00012878 _____ C:\Users\EileenCCI\Documents\Vietnam bank info.docx.abc
2015-09-02 11:43 - 2014-10-09 14:56 - 00097710 _____ C:\Users\EileenCCI\Documents\SB Recertification form - Medimmune (2).doc.abc
2015-09-02 11:43 - 2014-06-11 10:27 - 00000000 ____D C:\Users\EileenCCI\Documents\Restored_Cambridge 060614_Files
2015-09-02 11:43 - 2014-06-11 10:27 - 00000000 ____D C:\Users\EileenCCI\Documents\QuickBooksAutoDataRecovery
2015-09-02 11:43 - 2013-12-13 10:51 - 00020398 _____ C:\Users\EileenCCI\Documents\T Rowe letter #2.doc.abc
2015-09-02 11:43 - 2013-12-12 11:20 - 00020910 _____ C:\Users\EileenCCI\Documents\Type of Insurance               Insurance requirements           What we have at this point.doc.abc
2015-09-02 11:43 - 2013-12-12 10:42 - 00020398 _____ C:\Users\EileenCCI\Documents\T Rowe letter.doc.abc
2015-09-02 11:43 - 2013-12-06 13:11 - 00020398 _____ C:\Users\EileenCCI\Documents\trowe letter.doc.abc
2015-09-02 11:43 - 2013-11-21 11:54 - 00018670 _____ C:\Users\EileenCCI\Documents\NHS Community Service Verfication Sheet.docx.abc
2015-09-02 11:43 - 2013-10-15 11:48 - 00000590 ____H C:\Users\EileenCCI\Documents\~$&08 &09-2013 Monthly Financial Summary-August and September.doc.abc
2015-09-02 11:43 - 2013-09-26 11:06 - 00098734 _____ C:\Users\EileenCCI\Documents\SB Recertification form - August 2013.doc.abc
2015-09-02 11:43 - 2013-07-30 10:59 - 00020398 _____ C:\Users\EileenCCI\Documents\T Rowe Price 2013 letter.doc.abc
2015-09-02 11:43 - 2013-06-24 11:00 - 00080814 _____ C:\Users\EileenCCI\Documents\VENDOR INFORMATION FORM_HUGE.doc.abc
2015-09-02 11:43 - 2013-04-02 10:54 - 00011054 _____ C:\Users\EileenCCI\Documents\TRowe 2012.pdf.abc
2015-09-02 11:43 - 2011-03-29 10:54 - 00000000 ____D C:\Users\EileenCCI\Documents\travel expenses
2015-09-02 11:43 - 2010-12-14 11:41 - 00342958 _____ C:\Users\EileenCCI\Documents\State of IL Ui50a.pdf.abc
2015-09-02 11:43 - 2010-04-29 09:56 - 00020910 _____ C:\Users\EileenCCI\Documents\We start our kids at the tender age of 5 playing Tball.doc.abc
2015-09-02 11:43 - 2010-04-27 11:08 - 00021422 _____ C:\Users\EileenCCI\Documents\Questions for DrRizzo.doc.abc
2015-09-02 11:43 - 2010-03-18 09:53 - 00478862 _____ C:\Users\EileenCCI\Documents\W-9 signed 12-10-07.pdf.abc
2015-09-02 11:43 - 2010-03-16 11:02 - 00085934 _____ C:\Users\EileenCCI\Documents\Supplier questionaire.doc.abc
2015-09-02 11:43 - 2010-03-16 11:02 - 00074286 _____ C:\Users\EileenCCI\Documents\SUPPLIER_fw9.pdf.abc
2015-09-02 11:43 - 2010-01-26 11:49 - 00020910 _____ C:\Users\EileenCCI\Documents\Page Five Self Evaluation.doc.abc
2015-09-02 11:43 - 2008-04-25 14:17 - 00000000 ____D C:\Users\EileenCCI\Documents\Wes Docs
2015-09-02 11:43 - 2008-04-25 14:17 - 00000000 ____D C:\Users\EileenCCI\Documents\My Scans
2015-09-02 11:43 - 2008-04-25 14:16 - 00373902 _____ C:\Users\EileenCCI\Documents\Professional Services Agreement.pdf.abc
2015-09-02 11:43 - 2008-04-25 14:16 - 00269742 _____ C:\Users\EileenCCI\Documents\WooMart Network Diagram.doc.abc
2015-09-02 11:43 - 2008-04-25 14:16 - 00032942 _____ C:\Users\EileenCCI\Documents\P9020016.jpg.abc
2015-09-02 11:43 - 2008-04-25 14:16 - 00027326 _____ C:\Users\EileenCCI\Documents\P9020015.jpg.abc
2015-09-02 11:43 - 2008-04-25 14:16 - 00026270 _____ C:\Users\EileenCCI\Documents\PICT3717.jpg.abc
2015-09-02 11:43 - 2008-04-25 14:16 - 00020398 _____ C:\Users\EileenCCI\Documents\workers comp letter.doc.abc
2015-09-02 11:43 - 2008-04-25 14:16 - 00018462 _____ C:\Users\EileenCCI\Documents\P9030056.jpg.abc
2015-09-02 11:43 - 2008-04-25 14:16 - 00017902 _____ C:\Users\EileenCCI\Documents\WooMart Network Diagram.pdf.abc
2015-09-02 11:42 - 2015-04-02 09:40 - 00012206 _____ C:\Users\EileenCCI\Documents\Misc. tax 2014.docx.abc
2015-09-02 11:42 - 2014-07-17 10:38 - 00058798 _____ C:\Users\EileenCCI\Documents\MOCK Invoice for GE.doc.abc
2015-09-02 11:42 - 2012-07-31 13:45 - 00021422 _____ C:\Users\EileenCCI\Documents\Monthly expenses fixed.doc.abc
2015-09-02 11:42 - 2009-06-16 09:27 - 00000000 ____D C:\Users\EileenCCI\Documents\My Albums
2015-09-02 11:42 - 2008-04-25 14:18 - 00000000 ____D C:\Users\EileenCCI\Documents\invoices
2015-09-02 11:42 - 2008-04-25 14:17 - 00000000 ____D C:\Users\EileenCCI\Documents\msproject
2015-09-02 11:42 - 2008-04-25 14:16 - 00056750 _____ C:\Users\EileenCCI\Documents\Monthly Financial Summary-Jan-Sept2007revised.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00055726 _____ C:\Users\EileenCCI\Documents\Monthly Financial SummaryJan-December2006.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00055214 _____ C:\Users\EileenCCI\Documents\Monthly Financial SummaryJan-November2006.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00055214 _____ C:\Users\EileenCCI\Documents\Monthly Financial Summary-Jan-August 2007revised.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00054702 _____ C:\Users\EileenCCI\Documents\Monthly Financial SummaryJan-September2006.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00054702 _____ C:\Users\EileenCCI\Documents\Monthly Financial SummaryJan-October2006.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00054190 _____ C:\Users\EileenCCI\Documents\Monthly Financial Summary-Jan-August 2007.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00053678 _____ C:\Users\EileenCCI\Documents\Monthly Financial SummaryJan-Julyl2006.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00053678 _____ C:\Users\EileenCCI\Documents\Monthly Financial SummaryJan-Augustl2006.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00053166 _____ C:\Users\EileenCCI\Documents\Monthly Financial SummaryJan-Mayl2006.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00053166 _____ C:\Users\EileenCCI\Documents\Monthly Financial SummaryJan-Junel2006.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00053166 _____ C:\Users\EileenCCI\Documents\Monthly Financial Summary-Jan-July 2007.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00052654 _____ C:\Users\EileenCCI\Documents\Monthly Financial Summary-Jan-June 2007.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00052654 _____ C:\Users\EileenCCI\Documents\Monthly Financial SummaryJan-April2006.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00052142 _____ C:\Users\EileenCCI\Documents\Monthly Financial Summary-Jan-May 2007.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00052142 _____ C:\Users\EileenCCI\Documents\Monthly Financial Summary-Jan-April 2007.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00051630 _____ C:\Users\EileenCCI\Documents\Monthly Financial Summary-Jan-Mar 2007.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00051630 _____ C:\Users\EileenCCI\Documents\Monthly Financial SummaryJan-2006.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00051630 _____ C:\Users\EileenCCI\Documents\Monthly Financial SummaryJan- March2006.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00051630 _____ C:\Users\EileenCCI\Documents\Monthly Financial SummaryJan- Feb2006.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00050606 _____ C:\Users\EileenCCI\Documents\Monthly Financial Summary-Jan-Feb 2007.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00050606 _____ C:\Users\EileenCCI\Documents\Monthly Financial Summary-February 2007.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00050094 _____ C:\Users\EileenCCI\Documents\Monthly Financial Summary-January 2007.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00050094 _____ C:\Users\EileenCCI\Documents\Monthly Financial Summary-January 2006.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00044974 _____ C:\Users\EileenCCI\Documents\Monthly Financial SummaryJan-August2005.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00044462 _____ C:\Users\EileenCCI\Documents\Monthly Financial SummaryJan-May.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00038318 _____ C:\Users\EileenCCI\Documents\Monthly Financial Summary.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00034222 _____ C:\Users\EileenCCI\Documents\Monthly Financial SummaryJan-October.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00034222 _____ C:\Users\EileenCCI\Documents\Monthly Financial SummaryJan-November2005.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00034222 _____ C:\Users\EileenCCI\Documents\Monthly Financial SummaryJan-November.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00034222 _____ C:\Users\EileenCCI\Documents\Monthly Financial SummaryJan-December2005.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00034222 _____ C:\Users\EileenCCI\Documents\Monthly Financial SummaryJan-December2004.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00033710 _____ C:\Users\EileenCCI\Documents\Monthly Financial SummaryJan-September2005.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00033710 _____ C:\Users\EileenCCI\Documents\Monthly Financial SummaryJan-September.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00033710 _____ C:\Users\EileenCCI\Documents\Monthly Financial SummaryJan-October2005.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00033710 _____ C:\Users\EileenCCI\Documents\Monthly Financial SummaryJan-August.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00033198 _____ C:\Users\EileenCCI\Documents\Monthly Financial SummaryJan-Mayl2005.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00033198 _____ C:\Users\EileenCCI\Documents\Monthly Financial SummaryJan-Junel2005.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00033198 _____ C:\Users\EileenCCI\Documents\Monthly Financial SummaryJan-June.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00033198 _____ C:\Users\EileenCCI\Documents\Monthly Financial SummaryJan-Julyl2005.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00033198 _____ C:\Users\EileenCCI\Documents\Monthly Financial SummaryJan-July.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00033198 _____ C:\Users\EileenCCI\Documents\Monthly Financial SummaryJan-April2005.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00032686 _____ C:\Users\EileenCCI\Documents\Monthly Financial SummaryJan-March2005.doc.abc
2015-09-02 11:42 - 2008-04-25 14:16 - 00019886 _____ C:\Users\EileenCCI\Documents\Ms Loretta McCarthy.doc.abc
2015-09-02 11:37 - 2015-06-17 10:27 - 00050606 _____ C:\Users\EileenCCI\Documents\INV1727 Bangkok, Thailand PO#.doc.abc
2015-09-02 11:37 - 2015-06-09 12:02 - 00000000 ____D C:\Users\EileenCCI\Documents\Cambridge 06092015.QBW.SearchIndex
2015-09-02 11:37 - 2015-06-03 12:30 - 02439214 _____ C:\Users\EileenCCI\Documents\DSC00621.jpg.abc
2015-09-02 11:37 - 2015-06-03 12:30 - 00604302 _____ C:\Users\EileenCCI\Documents\DSC00691.jpg.abc
2015-09-02 11:37 - 2015-05-26 10:40 - 00050606 _____ C:\Users\EileenCCI\Documents\INV1751 PO#304285 Bangalore PMF.DOC.abc
2015-09-02 11:37 - 2015-05-19 13:00 - 01169598 _____ C:\Users\EileenCCI\Documents\INV1792Exp rects 5-12-15 CAS Stamford.pdf.abc
2015-09-02 11:37 - 2015-04-10 11:14 - 00166462 _____ C:\Users\EileenCCI\Documents\doc00796320150410094302.pdf.abc
2015-09-02 11:37 - 2015-03-19 10:36 - 00050606 _____ C:\Users\EileenCCI\Documents\INV1775 PO#305534 Bangalore PMF.DOC.abc
2015-09-02 11:37 - 2015-03-12 12:57 - 00143726 _____ C:\Users\EileenCCI\Documents\INV1782 Switzerland attendee list - Copy.jpg.abc
2015-09-02 11:37 - 2015-03-03 12:44 - 00012734 _____ C:\Users\EileenCCI\Documents\Hi Kevin.docx.abc
2015-09-02 11:37 - 2015-01-20 11:05 - 00025006 _____ C:\Users\EileenCCI\Documents\France ACKNOWLEDGMENT_RECEIPT_ACCEPTANCE_INTEGRITYGUIDE.doc.abc
2015-09-02 11:37 - 2015-01-20 11:04 - 00026542 _____ C:\Users\EileenCCI\Documents\France CONSENT FOR PROCESSING AND TRANSFERRING.doc.abc
2015-09-02 11:37 - 2015-01-15 13:19 - 00020030 _____ C:\Users\EileenCCI\Documents\GE Team Invoice record 2014.xlsx.abc
2015-09-02 11:37 - 2015-01-15 13:19 - 00013086 _____ C:\Users\EileenCCI\Documents\GE Team Invoice record 2015.xlsx.abc
2015-09-02 11:37 - 2015-01-14 15:19 - 00051630 _____ C:\Users\EileenCCI\Documents\INV1721a Buc France GE 10 2-3 PO# 331020011597-POFR013743.doc.abc
2015-09-02 11:37 - 2015-01-06 11:45 - 00042414 _____ C:\Users\EileenCCI\Documents\India Disclosure Declaration.doc.abc
2015-09-02 11:37 - 2014-12-26 12:44 - 00076590 _____ C:\Users\EileenCCI\Documents\Confidentiality Agreement for Vendors.pdf.abc
2015-09-02 11:37 - 2014-12-18 15:03 - 00042414 _____ C:\Users\EileenCCI\Documents\Confidentiality Agreement for Vendors Mini Mobile.doc.abc
2015-09-02 11:37 - 2014-10-23 12:30 - 00052654 _____ C:\Users\EileenCCI\Documents\INV1730 Turkey october 16-17GE PO#12612.doc.abc
2015-09-02 11:37 - 2014-10-21 11:44 - 00031870 _____ C:\Users\EileenCCI\Documents\Corp bank info.docx.abc
2015-09-02 11:37 - 2014-10-09 12:00 - 00012142 _____ C:\Users\EileenCCI\Documents\General Electric Deutschland Holding Gmb2.docx.abc
2015-09-02 11:37 - 2014-09-25 11:46 - 00012126 _____ C:\Users\EileenCCI\Documents\General Electric Deutschland Holding Gmb1.docx.abc
2015-09-02 11:37 - 2014-09-18 15:02 - 00012174 _____ C:\Users\EileenCCI\Documents\General Electric Deutschland Holding GmbH.docx.abc
2015-09-02 11:37 - 2014-09-11 13:25 - 00056238 _____ C:\Users\EileenCCI\Documents\France bank infoSupplier Form_QPBFT.doc.abc
2015-09-02 11:37 - 2014-09-04 15:26 - 00054702 _____ C:\Users\EileenCCI\Documents\INV1700a GA TX PMF Invoice for GE.doc.abc
2015-09-02 11:37 - 2014-08-28 09:55 - 00053166 _____ C:\Users\EileenCCI\Documents\INV1700 GA TX PMF Invoice for GE.doc.abc
2015-09-02 11:37 - 2014-07-25 11:08 - 00300510 _____ C:\Users\EileenCCI\Documents\INV1693 PO CTS PM 7-2014 Crotonville.pdf.abc
2015-09-02 11:37 - 2014-07-17 10:29 - 00315598 _____ C:\Users\EileenCCI\Documents\Document1 [Compatibility Mode].docx.abc
2015-09-02 11:37 - 2014-07-01 10:21 - 00013982 _____ C:\Users\EileenCCI\Documents\INV1685Expense 2014 - 15 - E 03 - CCI - GE PMF Bangalore - June 10-13, 2014.docx.abc
2015-09-02 11:37 - 2014-07-01 10:03 - 00052654 _____ C:\Users\EileenCCI\Documents\INV1685  Bangalore  Regional PMF- 2 sessions.doc.abc
2015-09-02 11:37 - 2014-06-24 11:36 - 00310158 _____ C:\Users\EileenCCI\Documents\INV1685Taxi Invoice - Jun 9.pdf.abc
2015-09-02 11:37 - 2014-06-11 10:27 - 00000000 ____D C:\Users\EileenCCI\Documents\Cambridge 060614.QBW.SearchIndex
2015-09-02 11:37 - 2014-03-28 10:41 - 00046718 _____ C:\Users\EileenCCI\Documents\INV1672SOW_Cambridge[1].pdf.abc
2015-09-02 11:37 - 2014-03-25 11:00 - 00577790 _____ C:\Users\EileenCCI\Documents\INV1672Expense Receipts  BM- 0307 - GE Oakville - Receipts 2.pdf.abc
2015-09-02 11:37 - 2014-03-25 11:00 - 00048782 _____ C:\Users\EileenCCI\Documents\INV1672Expense Summary BM  - 0307.pdf.abc
2015-09-02 11:37 - 2014-03-06 12:05 - 00020046 _____ C:\Users\EileenCCI\Documents\GE Team Invoice record.xlsx.abc
2015-09-02 11:37 - 2014-01-16 11:12 - 00037294 _____ C:\Users\EileenCCI\Documents\Fax Southern California Ins. Cert.doc.abc
2015-09-02 11:37 - 2014-01-14 10:57 - 00021422 _____ C:\Users\EileenCCI\Documents\Consulate of India Visa from CC.doc.abc
2015-09-02 11:37 - 2014-01-07 12:29 - 00172974 _____ C:\Users\EileenCCI\Documents\GE Invite Letter from India GE Business.doc.abc
2015-09-02 11:37 - 2014-01-07 12:21 - 00267182 _____ C:\Users\EileenCCI\Documents\GE Visa Invitation Letter for non-GE ees India.doc.abc
2015-09-02 11:37 - 2013-12-10 11:33 - 00022958 _____ C:\Users\EileenCCI\Documents\GE Hilton Garden Inn info.doc.abc
2015-09-02 11:37 - 2013-11-21 12:19 - 00031662 _____ C:\Users\EileenCCI\Documents\GE INSURANCE REQMTS.doc.abc
2015-09-02 11:37 - 2013-11-14 14:28 - 00449678 _____ C:\Users\EileenCCI\Documents\Cambridge W-9 GE.pdf.abc
2015-09-02 11:37 - 2013-11-14 14:28 - 00151518 _____ C:\Users\EileenCCI\Documents\Cambridge EFT Info GE.pdf.abc
2015-09-02 11:37 - 2013-11-14 14:10 - 01897726 _____ C:\Users\EileenCCI\Documents\GE Cambridge Consulting - W-9.JPG.abc
2015-09-02 11:37 - 2013-11-14 14:09 - 00688654 _____ C:\Users\EileenCCI\Documents\Cambridge Consulting - W-9.jpg.abc
2015-09-02 11:37 - 2013-11-14 13:46 - 00127678 _____ C:\Users\EileenCCI\Documents\GE W-9.pdf.abc
2015-09-02 11:37 - 2013-11-14 10:43 - 00026542 _____ C:\Users\EileenCCI\Documents\GE EFT FORM 2012.doc.abc
2015-09-02 11:37 - 2013-04-30 11:26 - 00076718 _____ C:\Users\EileenCCI\Documents\INV1632MITRE 4-24-13 Travel Expense Summary.doc.abc
2015-09-02 11:37 - 2013-03-22 11:42 - 00085422 _____ C:\Users\EileenCCI\Documents\INV1624Medi Expense Summary 3-20-13.doc.abc
2015-09-02 11:37 - 2012-11-06 10:58 - 00036270 _____ C:\Users\EileenCCI\Documents\fax workers comp.doc.abc
2015-09-02 11:37 - 2012-09-13 08:54 - 00025006 _____ C:\Users\EileenCCI\Documents\HSA Termination.doc.abc
2015-09-02 11:37 - 2012-03-13 10:55 - 00086446 _____ C:\Users\EileenCCI\Documents\Inv1587MRMTravel.doc.abc
2015-09-02 11:37 - 2011-02-22 11:44 - 00094894 _____ C:\Users\EileenCCI\Documents\Dyson receipts 2-16-18-11.pdf.abc
2015-09-02 11:37 - 2011-02-22 11:44 - 00085422 _____ C:\Users\EileenCCI\Documents\Dyson PM -2-2011 Travel Expense Summary.doc.abc
2015-09-02 11:37 - 2011-02-22 11:44 - 00041390 _____ C:\Users\EileenCCI\Documents\Dyson PM invoice 2-2011.doc.abc
2015-09-02 11:37 - 2010-03-16 12:02 - 00000000 ____D C:\Users\EileenCCI\Documents\Cardinal Health
2015-09-02 11:37 - 2010-01-12 11:40 - 00020910 _____ C:\Users\EileenCCI\Documents\EasyPassviolation.doc.abc
2015-09-02 11:37 - 2009-05-12 12:57 - 00000000 __SHD C:\Users\EileenCCI\Documents\cache
2015-09-02 11:37 - 2009-01-06 11:42 - 00022446 _____ C:\Users\EileenCCI\Documents\Dear Liam.doc.abc
2015-09-02 11:37 - 2008-04-28 12:21 - 00000000 ____D C:\Users\EileenCCI\Documents\C C I
2015-09-02 11:37 - 2008-04-28 12:20 - 00000000 ____D C:\Users\EileenCCI\Documents\Brochures
2015-09-02 11:37 - 2008-04-25 14:18 - 00000000 ____D C:\Users\EileenCCI\Documents\eileencci
2015-09-02 11:37 - 2008-04-25 14:16 - 00042414 _____ C:\Users\EileenCCI\Documents\INV1431Wyeth 4-24-08.doc.abc
2015-09-02 11:37 - 2008-04-25 14:16 - 00041390 _____ C:\Users\EileenCCI\Documents\INV1390 LINTV 6-1-07.doc.abc
2015-09-02 11:37 - 2008-04-25 14:16 - 00037294 _____ C:\Users\EileenCCI\Documents\fax.doc.abc
2015-09-02 11:37 - 2008-04-25 14:16 - 00019886 _____ C:\Users\EileenCCI\Documents\cover letter.doc.abc
2015-09-02 11:36 - 2015-07-29 13:20 - 00036782 _____ C:\Users\EileenCCI\Documents\01-6 2015 Monthly Financial Summary-Jan thru June 2015.doc.abc
2015-09-02 11:36 - 2015-06-18 13:01 - 00036782 _____ C:\Users\EileenCCI\Documents\01-5 2015 Monthly Financial Summary-Jan thru May 2015.doc.abc
2015-09-02 11:36 - 2015-04-15 11:51 - 00035758 _____ C:\Users\EileenCCI\Documents\01-3 2015 Monthly Financial Summary-Jan thru March 2015.doc.abc
2015-09-02 11:36 - 2015-04-15 11:38 - 00035246 _____ C:\Users\EileenCCI\Documents\01-2015 Monthly Financial Summary-Jan 2015.doc.abc
2015-09-02 11:36 - 2015-02-09 14:57 - 00038318 _____ C:\Users\EileenCCI\Desktop\Bill 2015.xlsx.abc
2015-09-02 11:36 - 2015-01-13 12:26 - 00038318 _____ C:\Users\EileenCCI\Documents\01-11&12 2014 Monthly Financial Summary-Jan-Dec 2014.doc.abc
2015-09-02 11:36 - 2014-11-21 12:04 - 00011694 _____ C:\Users\EileenCCI\Desktop\Rate Conv. Worksheet.xlsx.abc
2015-09-02 11:36 - 2014-11-18 17:31 - 00038318 _____ C:\Users\EileenCCI\Documents\01-10 2014 Monthly Financial Summary-Jan-Oct 2014.doc.abc
2015-09-02 11:36 - 2014-10-09 09:37 - 00038318 _____ C:\Users\EileenCCI\Documents\01-09 2014 Monthly Financial Summary-Jan-sept 2014.doc.abc
2015-09-02 11:36 - 2014-09-08 13:43 - 00037806 _____ C:\Users\EileenCCI\Documents\01-08 2014 Monthly Financial Summary-Jan-August 2014.doc.abc
2015-09-02 11:36 - 2014-08-15 10:55 - 02360446 _____ C:\Users\EileenCCI\Documents\August Mock Invoice 8-14-14 travel receipts DP ATL.pdf.abc
2015-09-02 11:36 - 2014-08-15 10:54 - 00058798 _____ C:\Users\EileenCCI\Documents\August MOCK Invoice for GE.doc.abc
2015-09-02 11:36 - 2014-08-14 12:11 - 00037294 _____ C:\Users\EileenCCI\Documents\01-07 2014 Monthly Financial Summary-Jan-July 2014.doc.abc
2015-09-02 11:36 - 2014-08-12 11:33 - 00035758 _____ C:\Users\EileenCCI\Documents\01-2014 Monthly Financial Summary-Jan 2014.doc.abc
2015-09-02 11:36 - 2014-02-26 13:07 - 00000000 ____D C:\Users\EileenCCI\AppData\Roaming\Stamps.com Internet Postage
2015-09-02 11:36 - 2014-02-26 11:50 - 00000000 ____D C:\Users\EileenCCI\AppData\Roaming\PCDr
2015-09-02 11:36 - 2014-02-25 11:52 - 00000000 ____D C:\Users\EileenCCI\AppData\Roaming\Windows Live Writer
2015-09-02 11:36 - 2014-02-25 11:41 - 00000000 ___RD C:\Users\EileenCCI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-09-02 11:36 - 2014-02-25 11:41 - 00000000 ___RD C:\Users\EileenCCI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-09-02 11:36 - 2014-02-11 14:41 - 00012110 _____ C:\Users\EileenCCI\Desktop\GE Team Record- invoices.xlsx.abc
2015-09-02 11:36 - 2014-02-11 14:41 - 00010158 _____ C:\Users\EileenCCI\Desktop\GE Invoices.xlsx.abc
2015-09-02 11:36 - 2014-02-11 13:48 - 00097710 _____ C:\Users\EileenCCI\Desktop\Bill 2014.xls.abc
2015-09-02 11:36 - 2014-02-04 12:57 - 00039854 _____ C:\Users\EileenCCI\Documents\12-2013 Monthly Financial Summary.doc.abc
2015-09-02 11:36 - 2014-01-09 13:46 - 00557230 _____ C:\Users\EileenCCI\Documents\Application - Express Reneal Questionnaire MP.pdf.abc
2015-09-02 11:36 - 2013-12-17 13:38 - 00039854 _____ C:\Users\EileenCCI\Documents\10&11-2013 Monthly Financial Summary.doc.abc
2015-09-02 11:36 - 2013-10-15 12:20 - 00039854 _____ C:\Users\EileenCCI\Documents\08 &09-2013 Monthly Financial Summary-August and September.doc.abc
2015-09-02 11:36 - 2013-10-15 11:48 - 00039854 _____ C:\Users\EileenCCI\Documents\05&08 &09-2013 Monthly Financial Summary-August and September.doc.abc
2015-09-02 11:36 - 2013-08-13 13:24 - 00039342 _____ C:\Users\EileenCCI\Documents\05&6&7-2013 Monthly Financial Summary-May June July 2013.doc.abc
2015-09-02 11:36 - 2013-05-07 11:39 - 00038318 _____ C:\Users\EileenCCI\Documents\04-2013 Monthly Financial Summary-April 2013.doc.abc
2015-09-02 11:36 - 2013-04-25 10:44 - 00038318 _____ C:\Users\EileenCCI\Documents\03-2013 Monthly Financial Summary-March 2013.doc.abc
2015-09-02 11:36 - 2013-04-25 10:36 - 00037806 _____ C:\Users\EileenCCI\Documents\02-2013 Monthly Financial Summary-Feb 2013.doc.abc
2015-09-02 11:36 - 2013-02-05 12:04 - 00035246 _____ C:\Users\EileenCCI\Documents\01-2013 Monthly Financial Summary-Jan 2013.doc.abc
2015-09-02 11:36 - 2013-01-31 12:25 - 00073134 _____ C:\Users\EileenCCI\Desktop\Bill 2013.xls.abc
2015-09-02 11:36 - 2013-01-10 11:50 - 00040878 _____ C:\Users\EileenCCI\Documents\12-2012 Monthly Financial Summary-December 2012.doc.abc
2015-09-02 11:36 - 2013-01-03 12:29 - 00040878 _____ C:\Users\EileenCCI\Documents\11-2012 Monthly Financial Summary-November 2012.doc.abc
2015-09-02 11:36 - 2013-01-03 12:08 - 00040878 _____ C:\Users\EileenCCI\Documents\10-2012 Monthly Financial Summary-October 2012.doc.abc
2015-09-02 11:36 - 2013-01-03 12:01 - 00040366 _____ C:\Users\EileenCCI\Documents\09-2012 Monthly Financial Summary-September 2012.doc.abc
2015-09-02 11:36 - 2013-01-03 11:58 - 00039854 _____ C:\Users\EileenCCI\Documents\08-2012 Monthly Financial Summary-August 2012.doc.abc
2015-09-02 11:36 - 2013-01-03 11:56 - 00039854 _____ C:\Users\EileenCCI\Documents\07-2012 Monthly Financial Summary-July 2012.doc.abc
2015-09-02 11:36 - 2012-07-17 09:53 - 00039854 _____ C:\Users\EileenCCI\Documents\06-2012 Monthly Financial Summary-June 2012.doc.abc
2015-09-02 11:36 - 2012-06-28 12:19 - 00039342 _____ C:\Users\EileenCCI\Documents\05-2012 Monthly Financial Summary-May 2012.doc.abc
2015-09-02 11:36 - 2012-06-28 12:16 - 00039342 _____ C:\Users\EileenCCI\Documents\05-2012 Monthly Financial Summary-Mayl 2012.doc.abc
2015-09-02 11:36 - 2012-06-28 11:41 - 00038318 _____ C:\Users\EileenCCI\Documents\04-2012 Monthly Financial Summary-April 2012.doc.abc
2015-09-02 11:36 - 2012-05-01 11:37 - 00037806 _____ C:\Users\EileenCCI\Documents\03-2012 Monthly Financial Summary-March 2012.doc.abc
2015-09-02 11:36 - 2012-03-20 11:46 - 00037806 _____ C:\Users\EileenCCI\Documents\02-2012 Monthly Financial Summary-Feb 2012.doc.abc
2015-09-02 11:36 - 2012-02-28 12:56 - 00037806 _____ C:\Users\EileenCCI\Documents\01-2012 Monthly Financial Summary-Jan 2012.doc.abc
2015-09-02 11:36 - 2012-01-24 12:44 - 00073646 _____ C:\Users\EileenCCI\Desktop\Bill 2012.xls.abc
2015-09-02 11:36 - 2012-01-10 12:56 - 00040366 _____ C:\Users\EileenCCI\Documents\12-2011 Monthly Financial Summary-December 2011.doc.abc
2015-09-02 11:36 - 2011-12-15 11:45 - 00040366 _____ C:\Users\EileenCCI\Documents\11-2011 Monthly Financial Summary-November 2011.doc.abc
2015-09-02 11:36 - 2011-11-08 12:53 - 00040366 _____ C:\Users\EileenCCI\Documents\10-2011 Monthly Financial Summary-October 2011.doc.abc
2015-09-02 11:36 - 2011-10-13 12:05 - 00039854 _____ C:\Users\EileenCCI\Documents\09-2011 Monthly Financial Summary-September 2011.doc.abc
2015-09-02 11:36 - 2011-09-22 10:57 - 00039854 _____ C:\Users\EileenCCI\Documents\08-2011 Monthly Financial Summary-August 2011.doc.abc
2015-09-02 11:36 - 2011-08-23 10:16 - 00039854 _____ C:\Users\EileenCCI\Documents\07-2011 Monthly Financial Summary-July 2011.doc.abc
2015-09-02 11:36 - 2011-07-14 11:45 - 00039342 _____ C:\Users\EileenCCI\Documents\06-2011 Monthly Financial Summary-June 2011.doc.abc
2015-09-02 11:36 - 2011-06-09 09:31 - 00038830 _____ C:\Users\EileenCCI\Documents\05-2011 Monthly Financial Summary-May 2011.doc.abc
2015-09-02 11:36 - 2011-05-10 10:33 - 00038318 _____ C:\Users\EileenCCI\Documents\04-2011 Monthly Financial Summary-April 2011.doc.abc
2015-09-02 11:36 - 2011-04-12 11:45 - 00038318 _____ C:\Users\EileenCCI\Documents\03-2011 Monthly Financial Summary-March 2011.doc.abc
2015-09-02 11:36 - 2011-03-08 13:45 - 00037806 _____ C:\Users\EileenCCI\Documents\02-2011 Monthly Financial Summary-Feb 2011.doc.abc
2015-09-02 11:36 - 2011-02-08 11:48 - 00037806 _____ C:\Users\EileenCCI\Documents\01-2011 Monthly Financial Summary-Jan 2011.doc.abc
2015-09-02 11:36 - 2011-01-20 10:43 - 00071598 _____ C:\Users\EileenCCI\Desktop\Bill 2011.xls.abc
2015-09-02 11:36 - 2010-12-07 13:31 - 00040878 _____ C:\Users\EileenCCI\Documents\11-2010 Monthly Financial Summary-Nov 2010.doc.abc
2015-09-02 11:36 - 2010-11-11 12:22 - 00040366 _____ C:\Users\EileenCCI\Documents\10-2010 Monthly Financial Summary-Oct 2010.doc.abc
2015-09-02 11:36 - 2010-10-19 11:42 - 00039854 _____ C:\Users\EileenCCI\Documents\09-2010 Monthly Financial Summary-Sept 2010.doc.abc
2015-09-02 11:36 - 2010-09-21 12:08 - 00039854 _____ C:\Users\EileenCCI\Documents\08-2010 Monthly Financial Summary-Aug 2010.doc.abc
2015-09-02 11:36 - 2010-07-13 11:20 - 00039342 _____ C:\Users\EileenCCI\Documents\06-2010 Monthly Financial Summary-June 2010.doc.abc
2015-09-02 11:36 - 2010-06-10 12:06 - 00039342 _____ C:\Users\EileenCCI\Documents\05-2010 Monthly Financial Summary-May 2010.doc.abc
2015-09-02 11:36 - 2010-05-11 11:41 - 00038318 _____ C:\Users\EileenCCI\Documents\04-2010 Monthly Financial Summary-April 2010.doc.abc
2015-09-02 11:36 - 2010-04-13 12:11 - 00037806 _____ C:\Users\EileenCCI\Documents\03-2010 Monthly Financial Summary-March 2010.doc.abc
2015-09-02 11:36 - 2010-03-11 12:33 - 00037806 _____ C:\Users\EileenCCI\Documents\02-2010 Monthly Financial Summary-Feb 2010.doc.abc
2015-09-02 11:36 - 2010-03-04 11:37 - 00073134 _____ C:\Users\EileenCCI\Desktop\Bill 2010.xls.abc
2015-09-02 11:36 - 2010-02-11 13:56 - 00037806 _____ C:\Users\EileenCCI\Documents\01-2010 Monthly Financial Summary-Jan 2010.doc.abc
2015-09-02 11:36 - 2010-01-12 12:31 - 00040878 _____ C:\Users\EileenCCI\Documents\12-2009 Monthly Financial Summary-Dec 2009.doc.abc
2015-09-02 11:36 - 2009-12-10 11:39 - 00040878 _____ C:\Users\EileenCCI\Documents\11-2009 Monthly Financial Summary-Nov 2009.doc.abc
2015-09-02 11:36 - 2009-11-12 10:33 - 00040366 _____ C:\Users\EileenCCI\Documents\10-2009 Monthly Financial Summary-Oct 2009.doc.abc
2015-09-02 11:36 - 2009-10-06 11:38 - 00039854 _____ C:\Users\EileenCCI\Documents\09-2009 Monthly Financial Summary-Sept 2009.doc.abc
2015-09-02 11:36 - 2009-10-06 11:30 - 00039854 _____ C:\Users\EileenCCI\Documents\08-2009 Monthly Financial Summary-August 2009.doc.abc
2015-09-02 11:36 - 2009-08-11 10:10 - 00039854 _____ C:\Users\EileenCCI\Documents\07-2009 Monthly Financial Summary-July 2009.doc.abc
2015-09-02 11:36 - 2009-07-16 12:24 - 00039342 _____ C:\Users\EileenCCI\Documents\06-2009 Monthly Financial Summary-June 2009.doc.abc
2015-09-02 11:36 - 2009-06-09 10:06 - 00039342 _____ C:\Users\EileenCCI\Documents\05-2009 Monthly Financial Summary-May 2009.doc.abc
2015-09-02 11:36 - 2009-05-07 11:17 - 00038318 _____ C:\Users\EileenCCI\Documents\04-2009 Monthly Financial Summary-April 2009.doc.abc
2015-09-02 11:36 - 2009-04-09 11:33 - 00037806 _____ C:\Users\EileenCCI\Documents\03-2009 Monthly Financial Summary-March 2009.doc.abc
2015-09-02 11:36 - 2009-03-17 10:41 - 00037806 _____ C:\Users\EileenCCI\Documents\02-2009 Monthly Financial Summary-Feb 2009.doc.abc
2015-09-02 11:36 - 2009-03-17 10:35 - 00037806 _____ C:\Users\EileenCCI\Documents\01-2009 Monthly Financial Summary-Feb 2009.doc.abc
2015-09-02 11:36 - 2009-02-10 11:16 - 00037294 _____ C:\Users\EileenCCI\Documents\01-2009 Monthly Financial Summary-Jan 2009.doc.abc
2015-09-02 11:36 - 2009-01-22 10:50 - 00040878 _____ C:\Users\EileenCCI\Documents\12-2008 Monthly Financial Summary-Jan-Dec2008.doc.abc
2015-09-02 11:36 - 2009-01-13 12:40 - 00072622 _____ C:\Users\EileenCCI\Desktop\Bill 2009.xls.abc
2015-09-02 11:36 - 2008-12-11 11:18 - 00040366 _____ C:\Users\EileenCCI\Documents\11-2008 Monthly Financial Summary-Jan-Nov2008.doc.abc
2015-09-02 11:36 - 2008-11-20 10:26 - 00040366 _____ C:\Users\EileenCCI\Documents\10-2008 Monthly Financial Summary-Jan-Oct2008.doc.abc
2015-09-02 11:36 - 2008-10-07 11:55 - 00039854 _____ C:\Users\EileenCCI\Documents\09-2008 Monthly Financial Summary-Jan-Sept2008.doc.abc
2015-09-02 11:36 - 2008-09-16 10:02 - 00039854 _____ C:\Users\EileenCCI\Documents\08-2008 Monthly Financial Summary-Jan-August2008.doc.abc
2015-09-02 11:36 - 2008-08-12 11:53 - 00039342 _____ C:\Users\EileenCCI\Documents\07-2008 Monthly Financial Summary-Jan-July2008.doc.abc
2015-09-02 11:36 - 2008-08-12 10:57 - 00039342 _____ C:\Users\EileenCCI\Documents\06-2008 Monthly Financial Summary-Jan-July2008.doc.abc
2015-09-02 11:36 - 2008-07-29 11:20 - 00039342 _____ C:\Users\EileenCCI\Documents\06-2008 Monthly Financial Summary-Jan-June2008.doc.abc
2015-09-02 11:36 - 2008-06-11 12:14 - 00039342 _____ C:\Users\EileenCCI\Documents\05-2008 Monthly Financial Summary-Jan-May 2008.doc.abc
2015-09-02 11:36 - 2008-05-20 09:39 - 00038318 _____ C:\Users\EileenCCI\Documents\03-2008 Monthly Financial Summary-Jan-April 2008.doc.abc
2015-09-02 11:36 - 2008-04-29 11:35 - 00000846 _____ C:\Users\EileenCCI\Documents\address.csv.abc
2015-09-02 11:36 - 2008-04-28 12:20 - 00000000 ____D C:\Users\EileenCCI\Documents\Bill Summary
2015-09-02 11:36 - 2008-04-25 14:16 - 00141230 _____ C:\Users\EileenCCI\Documents\5-07 Consulting Services Summary.doc.abc
2015-09-02 11:36 - 2008-04-25 14:16 - 00081838 _____ C:\Users\EileenCCI\Desktop\Bill 2006.xls.abc
2015-09-02 11:36 - 2008-04-25 14:16 - 00076718 _____ C:\Users\EileenCCI\Desktop\Bill 2008.xls.abc
2015-09-02 11:36 - 2008-04-25 14:16 - 00070574 _____ C:\Users\EileenCCI\Desktop\Bill 2007.xls.abc
2015-09-02 11:36 - 2008-04-25 14:16 - 00065454 _____ C:\Users\EileenCCI\Desktop\Bill 2005.xls.abc
2015-09-02 11:36 - 2008-04-25 14:16 - 00063406 _____ C:\Users\EileenCCI\Desktop\Bill 2004.xls.abc
2015-09-02 11:36 - 2008-04-25 14:16 - 00042414 _____ C:\Users\EileenCCI\Desktop\Fin Sum Jan-December2004.doc.abc
2015-09-02 11:36 - 2008-04-25 14:16 - 00038318 _____ C:\Users\EileenCCI\Documents\12-2007 Monthly Financial Summary-Jan-Dec 2007.doc.abc
2015-09-02 11:36 - 2008-04-25 14:16 - 00038318 _____ C:\Users\EileenCCI\Documents\11-2007 Monthly Financial Summary-Jan-Nov 2007.doc.abc
2015-09-02 11:36 - 2008-04-25 14:16 - 00038318 _____ C:\Users\EileenCCI\Documents\10-2007 Monthly Financial Summary-Jan-Nov 2007.doc.abc
2015-09-02 11:36 - 2008-04-25 14:16 - 00038318 _____ C:\Users\EileenCCI\Documents\03-2008 Monthly Financial Summary-Jan-Mar 2008.doc.abc
2015-09-02 11:36 - 2008-04-25 14:16 - 00037806 _____ C:\Users\EileenCCI\Documents\10-2007 Monthly Financial Summary-Jan-Oct 2007.doc.abc
2015-09-02 11:36 - 2008-04-25 14:16 - 00037806 _____ C:\Users\EileenCCI\Documents\02-2008 Monthly Financial Summary-Jan-Feb 2008.doc.abc
2015-09-02 11:36 - 2008-04-25 14:16 - 00037294 _____ C:\Users\EileenCCI\Documents\12-2008 Monthly Financial Summary-Jan 2008.doc.abc
2015-09-02 11:36 - 2008-04-25 14:16 - 00037294 _____ C:\Users\EileenCCI\Documents\01-2008 Monthly Financial Summary-Jan 2008.doc.abc
2015-09-02 11:36 - 2008-04-25 14:16 - 00032686 _____ C:\Users\EileenCCI\Documents\7-04 Monthly Fin Summary.doc.abc
2015-09-02 11:35 - 2014-02-26 12:51 - 00000000 ____D C:\Users\EileenCCI\AppData\Roaming\Malwarebytes
2015-09-02 11:35 - 2014-02-25 14:01 - 00000000 ____D C:\Users\EileenCCI\AppData\Local\Windows Live
2015-09-02 11:35 - 2014-02-25 11:52 - 00000000 ____D C:\Users\EileenCCI\AppData\Local\Windows Live Writer
2015-09-02 11:35 - 2014-02-25 11:49 - 00000000 ____D C:\Users\EileenCCI\AppData\Roaming\Dell
2015-09-02 11:35 - 2014-02-25 11:46 - 00000000 ____D C:\Users\EileenCCI\AppData\Roaming\Macromedia
2015-09-02 11:35 - 2014-02-25 11:45 - 00000000 ____D C:\Users\EileenCCI\AppData\Roaming\Intel Corporation
2015-09-02 11:35 - 2014-02-25 11:44 - 00000000 ____D C:\Users\EileenCCI\AppData\Roaming\Adobe
2015-09-02 11:35 - 2014-02-25 11:44 - 00000000 ____D C:\Users\EileenCCI\AppData\Local\VirtualStore
2015-09-02 11:34 - 2014-04-01 10:49 - 00000000 ____D C:\Users\EileenCCI\AppData\Local\Microsoft Help
2015-09-02 11:34 - 2014-02-26 13:04 - 00000000 ____D C:\Users\EileenCCI\AppData\Local\Seven Zip
2015-09-02 11:34 - 2014-02-26 10:40 - 00000000 ___DC C:\Users\EileenCCI\AppData\Local\MigWiz
2015-09-02 11:34 - 2014-02-25 11:47 - 00000000 ____D C:\Users\EileenCCI\AppData\Local\softthinks
2015-09-02 11:25 - 2015-06-30 09:47 - 00000000 ____D C:\ProgramData\PC-Doctor for Windows
2015-09-02 11:25 - 2015-06-24 08:50 - 00000000 __HDC C:\ProgramData\{8AF32939-989B-460A-8726-CA2C776032A1}
2015-09-02 11:25 - 2015-06-11 08:31 - 00000000 ____D C:\Users\EileenCCI\AppData\Local\GWX
2015-09-02 11:25 - 2015-04-01 11:40 - 00000000 ____D C:\ProgramData\SupportAssistAgent
2015-09-02 11:25 - 2015-03-03 09:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2015-09-02 11:25 - 2014-11-18 10:54 - 00000000 __SHD C:\Users\EileenCCI\AppData\Local\EmieBrowserModeList
2015-09-02 11:25 - 2014-04-24 10:05 - 00000000 __SHD C:\Users\EileenCCI\AppData\Local\EmieUserList
2015-09-02 11:25 - 2014-04-24 10:05 - 00000000 __SHD C:\Users\EileenCCI\AppData\Local\EmieSiteList
2015-09-02 11:25 - 2014-02-27 12:11 - 00000000 ____D C:\Users\EileenCCI\AppData\Local\Adobe
2015-09-02 11:25 - 2014-02-26 13:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Stamps.com
2015-09-02 11:25 - 2014-02-26 13:06 - 00000000 ____D C:\ProgramData\{B26C223F-75F7-4201-923E-111C38B71D5C}
2015-09-02 11:25 - 2014-02-26 12:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
2015-09-02 11:25 - 2014-02-26 12:51 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-09-02 11:25 - 2014-02-25 14:05 - 00000000 ____D C:\ProgramData\Carbonite
2015-09-02 11:25 - 2014-02-25 12:23 - 00000000 ____D C:\Users\EileenCCI\AppData\Local\Intuit
2015-09-02 11:25 - 2014-02-25 12:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickBooks
2015-09-02 11:25 - 2014-02-25 12:17 - 00000000 ____D C:\ProgramData\SQL Anywhere 11
2015-09-02 11:25 - 2014-02-25 12:17 - 00000000 ____D C:\ProgramData\Nuance
2015-09-02 11:25 - 2014-02-25 12:17 - 00000000 ____D C:\ProgramData\Intuit
2015-09-02 11:25 - 2014-02-25 12:08 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
2015-09-02 11:25 - 2014-02-25 12:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-09-02 11:25 - 2014-02-25 11:47 - 00000000 ____D C:\ProgramData\softthinks
2015-09-02 11:25 - 2013-12-02 13:30 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Virtual PC
2015-09-02 11:25 - 2013-12-02 11:54 - 00000000 ____D C:\ProgramData\McAfee
2015-09-02 11:25 - 2013-12-02 11:53 - 00000000 ____D C:\ProgramData\PCDr
2015-09-02 11:25 - 2013-12-02 11:52 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
2015-09-02 11:25 - 2013-12-02 11:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell
2015-09-02 11:25 - 2013-12-02 11:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HotSpot
2015-09-02 11:25 - 2013-12-02 11:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Atheros Smart Net
2015-09-02 11:25 - 2013-12-02 11:47 - 00000000 ____D C:\ProgramData\Dell
2015-09-02 11:25 - 2013-12-02 11:46 - 00000000 ____D C:\ProgramData\Intel
2015-09-02 11:25 - 2013-12-02 11:45 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2015-09-02 11:25 - 2010-11-21 03:16 - 00000000 __RHD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
2015-09-02 11:25 - 2009-07-14 01:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-09-02 11:25 - 2009-07-13 23:20 - 00000000 __RHD C:\Users\Default
2015-09-02 11:25 - 2009-07-13 23:20 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-09-02 11:25 - 2009-07-13 23:20 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-09-02 11:25 - 2009-07-13 23:20 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-09-02 11:25 - 2009-07-13 23:20 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-09-02 11:25 - 2009-07-13 23:20 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-09-02 11:25 - 2009-07-13 23:20 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-09-02 11:25 - 2008-04-25 14:16 - 00000000 ____D C:\Users\EileenCCI\.jpi_cache
2015-09-02 11:25 - 2008-04-25 14:16 - 00000000 ____D C:\Users\EileenCCI\.java
2015-09-02 11:24 - 2014-02-25 12:04 - 00000000 ____D C:\Program Files\Microsoft Office 15
2015-09-02 11:24 - 2013-12-02 13:38 - 00000000 ____D C:\Program Files\Realtek
2015-09-02 11:24 - 2013-12-02 11:56 - 00000000 ____D C:\Temp
2015-09-02 11:24 - 2013-12-02 11:55 - 00000000 ____D C:\ProgramData\Adobe
2015-09-02 11:24 - 2013-12-02 11:52 - 00000000 ____D C:\Program Files\Windows Live
2015-09-02 11:24 - 2013-12-02 11:45 - 00000000 ____D C:\Program Files\Windows XP Mode
2015-09-02 11:24 - 2010-11-21 03:17 - 00000000 ____D C:\Program Files\Windows Journal
2015-09-02 11:24 - 2009-07-14 01:32 - 00000000 ____D C:\Program Files\Windows Sidebar
2015-09-02 11:24 - 2009-07-14 01:32 - 00000000 ____D C:\Program Files\Windows Portable Devices
2015-09-02 11:24 - 2009-07-14 01:32 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2015-09-02 11:24 - 2009-07-14 01:32 - 00000000 ____D C:\Program Files\Windows Defender
2015-09-02 11:24 - 2009-07-14 01:32 - 00000000 ____D C:\Program Files\Reference Assemblies
2015-09-02 11:24 - 2009-07-14 01:32 - 00000000 ____D C:\Program Files\MSBuild
2015-09-02 11:24 - 2009-07-13 23:20 - 00000000 ____D C:\Program Files\Windows NT
2015-09-02 11:24 - 2009-06-16 09:28 - 00000878 _____ C:\propertiesTable.dbf.abc
2015-09-02 11:24 - 2009-06-16 09:28 - 00000814 _____ C:\ROFTable.dbf.abc
2015-09-02 11:24 - 2009-06-16 09:28 - 00000782 _____ C:\ROFImagesTable.dbf.abc
2015-09-02 11:23 - 2015-06-30 09:47 - 00000000 ____D C:\Program Files\Dell Support Center
2015-09-02 11:23 - 2015-02-16 13:09 - 00000000 ____D C:\Program Files\Dell
2015-09-02 11:23 - 2014-02-25 13:10 - 00000000 ____D C:\Program Files\McAfee.com
2015-09-02 11:23 - 2013-12-02 11:54 - 00000000 ____D C:\Program Files\mcafee
2015-09-02 11:23 - 2013-12-02 11:45 - 00000000 ____D C:\Program Files\Intel
2015-09-02 11:23 - 2013-12-02 11:42 - 00000000 ____D C:\Program Files\Dell Inc
2015-09-02 11:23 - 2009-07-14 01:32 - 00000000 ____D C:\Program Files\DVD Maker
2015-09-02 11:22 - 2015-07-22 13:37 - 00000000 ____D C:\Program Files\Common Files\AV
2015-09-02 11:22 - 2014-02-25 14:06 - 00000000 ____D C:\Program Files\Carbonite
2015-09-02 11:22 - 2014-02-25 12:26 - 00000000 ____D C:\Program Files\Common Files\McAfee
2015-09-02 11:22 - 2013-12-02 13:38 - 00000000 ____D C:\Program Files\Common Files\Intel
2015-09-02 11:22 - 2013-12-02 13:38 - 00000000 ____D C:\Intel
2015-09-02 11:22 - 2012-10-05 12:08 - 00000000 ____D C:\e4a103b98c28c769461667e605
2015-09-02 11:22 - 2009-07-13 23:20 - 00000000 ____D C:\Program Files\Common Files\System
2015-09-02 11:22 - 2009-07-13 23:20 - 00000000 ____D C:\Program Files\Common Files\SpeechEngines
2015-09-02 11:22 - 2009-07-13 23:20 - 00000000 ____D C:\Program Files\Common Files\Services
2015-09-02 11:22 - 2009-07-13 23:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2015-09-02 11:22 - 2009-06-16 09:28 - 00001358 _____ C:\imageTable.dbf.abc
2015-09-02 11:22 - 2009-06-16 09:28 - 00000942 _____ C:\imageTable.fpk.abc
2015-09-02 11:22 - 2009-06-16 09:28 - 00000910 _____ C:\EXIFTable.dbf.abc
2015-09-02 11:22 - 2009-06-16 09:28 - 00000878 _____ C:\keywordTable.dbf.abc
2015-09-02 11:22 - 2009-06-16 09:28 - 00000846 _____ C:\pathnameTable.dbf.abc
2015-09-02 11:22 - 2009-06-16 09:28 - 00000782 _____ C:\managedFolderTable.dbf.abc
2015-09-02 11:22 - 2009-06-16 09:28 - 00000782 _____ C:\keywordImagesTable.dbf.abc
2015-09-02 11:21 - 2015-07-10 09:39 - 00000000 ___HD C:\$Windows.~BT
2015-09-02 11:21 - 2014-02-25 11:47 - 00000542 ____H C:\DBAR_Ver.txt.abc
2015-09-02 11:21 - 2014-02-14 12:50 - 00000000 ____D C:\a705a975c661185d889f616d3f3b9b1d
2015-09-02 11:21 - 2014-01-16 11:24 - 00000000 ____D C:\0ff12466b1c8f14a2d2bbcf37b0846d0
2015-09-02 11:21 - 2013-12-12 14:54 - 00000000 ____D C:\d3fe568bbae173732b31d8bb
2015-09-02 11:21 - 2013-11-14 14:40 - 00000000 ____D C:\4dd98a0f09f41566811826f810da
2015-09-02 11:21 - 2013-10-10 12:01 - 00000000 ____D C:\d051e9c51ffa498524
2015-09-02 11:21 - 2013-09-19 12:00 - 00000000 ____D C:\b4abf1e682ff1cc3b8d6865549
2015-09-02 11:21 - 2013-08-16 03:30 - 00000000 ____D C:\a57641c8b8ae732d6a10c7a3827b
2015-09-02 11:21 - 2011-02-10 10:25 - 00000000 ____D C:\dell
2015-09-02 11:21 - 2009-06-16 09:28 - 00001214 _____ C:\administrativeInfo.dbf.abc
2015-09-02 11:21 - 2009-06-16 09:28 - 00001006 _____ C:\albumTable.dbf.abc
2015-09-02 11:21 - 2009-06-16 09:28 - 00000846 _____ C:\albumImagesTable.dbf.abc
2015-09-02 11:21 - 2008-04-25 16:10 - 00000000 ____D C:\bin
2015-09-02 09:49 - 2015-06-30 09:47 - 00003484 _____ C:\Windows\System32\Tasks\PCDEventLauncherTask
2015-09-02 09:10 - 2015-07-02 09:20 - 00003064 _____ C:\Windows\System32\Tasks\McAfeeLogon
2015-09-02 09:09 - 2014-02-25 13:10 - 00000000 ____D C:\Program Files (x86)\McAfee
2015-09-01 14:16 - 2015-06-09 12:01 - 43151360 ____R C:\Users\EileenCCI\Documents\Cambridge 06092015.QBW
2015-09-01 14:16 - 2015-06-09 12:01 - 04521984 ____R C:\Users\EileenCCI\Documents\Cambridge 06092015.QBW.TLG
2015-09-01 14:16 - 2015-06-09 12:01 - 00000353 _____ C:\Users\EileenCCI\Documents\Cambridge 06092015.QBW.ND
2015-08-31 09:28 - 2011-02-10 10:25 - 00000000 ____D C:\Windows\panther
2015-08-24 11:26 - 2014-02-25 14:06 - 00004160 _____ C:\Windows\System32\Tasks\{5F6010C8-60E5-41f3-BF5B-C3AF5DBE12D4}
2015-08-24 11:26 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\rescache
2015-08-24 09:24 - 2009-07-14 00:45 - 00336184 _____ C:\Windows\system32\FNTCACHE.DAT
2015-08-24 09:23 - 2015-04-20 08:34 - 00000000 ____D C:\Windows\system32\appraiser
2015-08-24 09:23 - 2014-05-06 12:01 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-08-11 15:29 - 2014-03-07 11:39 - 00000000 ____D C:\Windows\system32\MRT
2015-08-11 15:27 - 2014-03-07 11:39 - 132483416 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-08-05 10:18 - 2015-07-22 13:37 - 00003348 _____ C:\Windows\System32\Tasks\McAfee Remediation (Prepare)
 
==================== Files in the root of some directories =======
 
2015-09-02 11:24 - 2015-09-02 11:24 - 0005100 _____ () C:\Program Files\restore_files_sqkjs.html
2015-09-02 11:24 - 2015-09-02 11:24 - 0002261 _____ () C:\Program Files\restore_files_sqkjs.txt
2015-09-02 11:22 - 2015-09-02 11:22 - 0005100 _____ () C:\Program Files\Common Files\restore_files_sqkjs.html
2015-09-02 11:22 - 2015-09-02 11:22 - 0002261 _____ () C:\Program Files\Common Files\restore_files_sqkjs.txt
2015-09-02 11:36 - 2015-09-02 11:36 - 0005100 _____ () C:\Users\EileenCCI\AppData\Roaming\restore_files_sqkjs.html
2015-09-02 11:36 - 2015-09-02 11:36 - 0002261 _____ () C:\Users\EileenCCI\AppData\Roaming\restore_files_sqkjs.txt
2015-09-02 11:25 - 2015-09-02 11:43 - 0005100 _____ () C:\Users\EileenCCI\AppData\Local\restore_files_sqkjs.html
2015-09-02 11:25 - 2015-09-02 11:43 - 0002261 _____ () C:\Users\EileenCCI\AppData\Local\restore_files_sqkjs.txt
2015-09-02 11:24 - 2015-09-02 11:25 - 0005100 _____ () C:\ProgramData\restore_files_sqkjs.html
2015-09-02 11:24 - 2015-09-02 11:25 - 0002261 _____ () C:\ProgramData\restore_files_sqkjs.txt
 
Files to move or delete:
====================
C:\Users\EileenCCI\atwbxdet.dll
 
 
Some files in TEMP:
====================
C:\Users\EileenCCI\AppData\Local\Temp\Abspdf.exe
C:\Users\EileenCCI\AppData\Local\Temp\acfpdfu.dll
C:\Users\EileenCCI\AppData\Local\Temp\acfpdfuamd64.dll
C:\Users\EileenCCI\AppData\Local\Temp\acfpdfui.dll
C:\Users\EileenCCI\AppData\Local\Temp\acfpdfuia64.dll
C:\Users\EileenCCI\AppData\Local\Temp\acfpdfuiamd64.dll
C:\Users\EileenCCI\AppData\Local\Temp\acfpdfuiia64.dll
C:\Users\EileenCCI\AppData\Local\Temp\cdintf.dll
C:\Users\EileenCCI\AppData\Local\Temp\OfficeSetup.exe
C:\Users\EileenCCI\AppData\Local\Temp\PDFPRT400.exe
C:\Users\EileenCCI\AppData\Local\Temp\sqlite3.dll
C:\Users\EileenCCI\AppData\Local\Temp\xmllite.dll
 
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-09-01 10:29
 
==================== End of FRST.txt ============================
 
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version:31-08-2015
Ran by EileenCCI (2015-09-03 19:54:01)
Running from C:\Users\EileenCCI\Desktop
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-517160071-1547752724-213923089-500 - Administrator - Disabled)
EileenCCI (S-1-5-21-517160071-1547752724-213923089-1000 - Administrator - Enabled) => C:\Users\EileenCCI
Guest (S-1-5-21-517160071-1547752724-213923089-501 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: McAfee Anti-Virus and Anti-Spyware (Enabled - Up to date) {DA9F8ED0-D0DE-39CC-F55A-51AB4CC1B556}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: McAfee Anti-Virus and Anti-Spyware (Enabled - Up to date) {61FE6F34-F6E4-3642-CFEA-6AD93746FFEB}
FW: McAfee Firewall (Enabled) {E2A40FF5-9AB1-3894-DE05-F89EB212F22D}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Accidental Damage Services Agreement (HKLM-x32\...\{EF85FEF4-EB92-4075-A6D2-5F519BB30A2C}) (Version: 2.0.0 - Dell Inc.)
Adobe Flash Player 17 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 17.0.0.188 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.08)  MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated)
Banctec Service Agreement (HKLM-x32\...\{42D68A86-DB1C-4256-B8C9-5D0D92919AF5}) (Version: 2.0.0 - Dell Inc.)
Carbonite (HKLM-x32\...\Carbonite Backup) (Version: 5.7.7 build 5155 (Jul-14-2015) - Carbonite)
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\...\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\...\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.)
Complete Care Business Service Agreement (HKLM-x32\...\{0ECFCB07-9BFE-4970-ACA1-D568D982760B}) (Version: 2.0.0 - Dell Inc.)
Consumer In-Home Service Agreement (HKLM-x32\...\{F47C37A4-7189-430A-B81D-739FF8A7A554}) (Version: 2.0.0 - Dell Inc.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Dell Backup and Recovery - Support Software (HKLM-x32\...\{A9668246-FB70-4103-A1E3-66C9BC2EFB49}) (Version: 1.6.0.3 - Dell Inc.)
Dell Backup and Recovery (HKLM-x32\...\{0ED7EE95-6A97-47AA-AD73-152C08A15B04}) (Version: 1.6.0.3 - Dell Inc.)
Dell Data Vault (Version: 4.3.4.0 - Dell Inc.) Hidden
Dell Digital Delivery (HKLM-x32\...\{693A23FB-F28B-4F7A-A720-4C1263F97F43}) (Version: 3.1.1002.0 - Dell Products, LP)
Dell Edoc Viewer (HKLM\...\{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}) (Version: 1.0.0 - Dell Inc)
Dell Home Systems Service Agreement (HKLM-x32\...\{AB2FDE4F-6BED-4E9E-B676-3DCCEBB1FBFE}) (Version: 2.0.0 - Dell Inc.)
Dell SupportAssist (HKLM\...\PC-Doctor for Windows) (Version: 1.1.6664.10 - Dell)
Dell SupportAssistAgent (HKLM-x32\...\{287348C8-8B47-4C36-AF28-441A3B7D8722}) (Version: 1.1.0.47 - Dell)
Dell Update (HKLM-x32\...\{DB82968B-57A4-4397-81A5-ECAB21B5DFCD}) (Version: 1.7.1015.0 - Dell Inc.)
Dell Wireless Driver Installation (HKLM-x32\...\{451517F1-7E41-400B-AA36-FB7E2563526D}) (Version: 9.0 - Dell)
eBay (HKLM-x32\...\{A8B88634-7F90-402F-B66A-86429755F6A5}) (Version: 1.4.0 - eBay Inc.)
Intel® Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.0.1351 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3412 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.1.0.1006 - Intel Corporation)
Intel® USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.4.220 - Intel Corporation)
Intel® Trusted Connect Service Client (HKLM\...\{6199B534-A1B6-46ED-873B-97B0ECF8F81E}) (Version: 1.23.216.0 - Intel Corporation)
Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Malwarebytes Anti-Malware version 1.75.0.1300 (HKLM-x32\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation)
McAfee SecurityCenter (HKLM-x32\...\MSC) (Version: 14.0.4121 - McAfee, Inc.)
McAfee WebAdvisor (HKLM-x32\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 4.0.124 - McAfee, Inc.)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office Home and Student 2013 - en-us (HKLM\...\HomeStudentRetail - en-us) (Version: 15.0.4745.1002 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-517160071-1547752724-213923089-1000\...\OneDriveSetup.exe) (Version: 17.0.4035.0328 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4745.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4745.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4745.1002 - Microsoft Corporation) Hidden
Premium Service Agreement (HKLM-x32\...\{C33AA6D6-F5EC-48F3-AFDC-8141345D473A}) (Version: 2.0.0 - Dell Inc.)
QualxServ Service Agreement (HKLM-x32\...\{903679E8-44C8-4C07-9600-05C92654FC50}) (Version: 2.0.0 - Dell Inc.)
QuickBooks (x32 Version: 24.0.4008.2403 - Intuit Inc.) Hidden
QuickBooks Pro 2014 (HKLM-x32\...\{4A21D17E-2FE8-42CD-88B7-ACF8E8860834}) (Version: 24.0.4003.2403 - Intuit Inc.)
QuickBooks Runtime Redistributable (HKLM\...\{F2A4F809-2DE6-4D27-888B-4D2BB8DAF20E}) (Version: 1.00.0000 - Intuit Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6554 - Realtek Semiconductor Corp.)
Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee)
Stamps.com (HKLM-x32\...\Stamps.com) (Version:  - Stamps.com, Inc.)
Stamps.com (x32 Version: 11.1.0.2691 - Stamps.com, Inc.) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-517160071-1547752724-213923089-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\EileenCCI\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-517160071-1547752724-213923089-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\EileenCCI\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-517160071-1547752724-213923089-1000_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\EileenCCI\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-517160071-1547752724-213923089-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\EileenCCI\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-517160071-1547752724-213923089-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\EileenCCI\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\FileSyncApi64.dll (Microsoft Corporation)
 
==================== Restore Points =========================
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 22:34 - 2009-06-10 17:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {0E3259BB-27CE-4311-A987-5D039A9D4C50} - System32\Tasks\{5F6010C8-60E5-41f3-BF5B-C3AF5DBE12D4} => C:\ProgramData\Carbonite\Carbonite Backup\CarboniteUpgrade.exe
Task: {2764E2E8-6FCF-43BF-8989-D26A224A1FBB} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-07-14] (Microsoft Corporation)
Task: {2AF2C20F-3F89-4FEE-822C-85DDBD8199ED} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\Dell\SupportAssist\uaclauncher.exe [2015-05-25] (PC-Doctor, Inc.)
Task: {2FC37EFD-26CE-4B97-9039-ADE72B4D43DD} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe invagent.dll,RunUpdate -noappraiser
Task: {40DB9C9E-AF2B-44F6-BFF5-2D242B956A8E} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe
Task: {4B2D25AE-D6FE-47AC-A009-75BCD4F82D99} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\Dell\SupportAssist\sessionchecker.exe [2015-05-25] (PC-Doctor, Inc.)
Task: {528E23D6-7AF4-4230-B778-55A4D66E622A} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-07-14] (Microsoft Corporation)
Task: {AB9EB9B3-D70C-4973-8674-BA89DA857AC2} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssist.exe [2015-06-11] (Dell Inc.)
Task: {D16D2273-AF6D-434A-8C9F-AA446626CB68} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee Anti-Virus And Anti-Spyware\upgrade.exe [2015-06-01] (McAfee, Inc.)
Task: {DCF507B8-5D28-482D-ACE3-031B64512EF4} - System32\Tasks\McAfeeLogon => C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe [2015-07-21] (McAfee, Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Loaded Modules (Whitelisted) ==============
 
2015-03-17 10:11 - 2015-01-27 11:29 - 08898720 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2013-12-02 11:56 - 2013-08-19 12:21 - 00020256 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBROverlayIcon.dll
2013-12-02 11:56 - 2013-08-19 12:21 - 00019232 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBROverlayNotBackuped.dll
2013-12-02 11:56 - 2013-08-19 12:21 - 00035104 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBRShellExtension.dll
2014-03-20 07:34 - 2014-05-20 09:19 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2013-12-02 13:11 - 2012-03-19 19:09 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2014-12-10 07:29 - 2014-12-10 07:29 - 00623432 _____ () C:\Program Files (x86)\Intuit\QuickBooks 2014\boost_regex-vc100-mt-1_47.dll
2014-12-10 07:30 - 2014-12-10 07:30 - 00021320 _____ () C:\Program Files (x86)\Intuit\QuickBooks 2014\QBCompressor.dll
2013-10-10 06:21 - 2013-10-10 06:21 - 00059904 _____ () C:\Program Files (x86)\Intuit\QuickBooks 2014\zlib1.dll
2014-12-10 07:30 - 2014-12-10 07:30 - 00149320 _____ () C:\Program Files (x86)\Intuit\QuickBooks 2014\QBMAPILibrary.dll
2014-12-10 07:29 - 2014-12-10 07:29 - 00247112 _____ () C:\Program Files (x86)\Intuit\QuickBooks 2014\boost_serialization-vc100-mt-1_47.dll
2014-12-10 07:29 - 2014-12-10 07:29 - 00623944 _____ () C:\Program Files (x86)\Intuit\QuickBooks 2014\FtuEngine.dll
2014-12-10 07:29 - 2014-12-10 07:29 - 00582472 _____ () C:\Program Files (x86)\Intuit\QuickBooks 2014\BackupLib.dll
2014-12-10 07:30 - 2014-12-10 07:30 - 00142664 _____ () C:\Program Files (x86)\Intuit\QuickBooks 2014\QBProActiveCore.dll
2014-12-10 07:29 - 2014-12-10 07:29 - 00791880 _____ () C:\Program Files (x86)\Intuit\QuickBooks 2014\FeaturesBridge.dll
2014-12-10 07:30 - 2014-12-10 07:30 - 00043848 _____ () C:\Program Files (x86)\Intuit\QuickBooks 2014\mbpopup.dll
2013-12-02 11:45 - 2011-12-16 14:39 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\ACE.dll
2015-03-16 11:28 - 2015-03-16 11:28 - 00155528 _____ () C:\Program Files (x86)\Dell Digital Delivery\ServiceTagPlusPlus.dll
2014-10-17 10:53 - 2014-10-17 10:53 - 00172544 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\1eeea3ab8d69ec722bdcb28b8eb8dd75\IsdiInterop.ni.dll
2013-12-02 11:48 - 2012-02-01 18:25 - 00059904 _____ () C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IsdiInterop.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\Users\EileenCCI\Documents\4 pictures for you.eml:OECustomProperty
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McNaiAnn => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfemms => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Service"
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-517160071-1547752724-213923089-1000\...\internet -> internet
IE trusted site: HKU\S-1-5-21-517160071-1547752724-213923089-1000\...\mcafee.com -> hxxp://mcafee.com
IE trusted site: HKU\S-1-5-21-517160071-1547752724-213923089-1000\...\mcafee.com -> hxxps://mcafee.com
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-517160071-1547752724-213923089-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\EileenCCI\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: Media is not connected to internet.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [VirtualPC-In-UDP-1] => (Allow) %SystemRoot%\System32\vpc.exe
FirewallRules: [VirtualPC-In-UDP-2] => (Allow) %SystemRoot%\System32\vpc.exe
FirewallRules: [VirtualPC-In-TCP-1] => (Allow) %SystemRoot%\System32\vpc.exe
FirewallRules: [{2DCC7924-6EBC-4C44-87BF-EC7F16290192}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{7C3820D5-419E-4848-8F04-005EF3C284F0}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{CAAB994B-41D5-418F-B905-7CD1CDDBD58F}] => (Allow) C:\Users\EileenCCI\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [{FB6696BC-08E3-4617-BF8F-FC7E68CCEAB9}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
FirewallRules: [{F6065AB7-6A45-4F91-9FF4-E2144FF12609}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
FirewallRules: [{C6BF95E7-FA27-4849-94E1-70F7A9921F2E}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{45F8107F-46ED-4837-9274-2FC6EE5E04A1}] => (Allow) LPort=2869
FirewallRules: [{BD609355-54CC-4731-9E12-8CBF19871AF0}] => (Allow) LPort=1900
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (09/03/2015 07:48:18 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (09/03/2015 07:38:21 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: recdisc.exe, version: 6.1.7601.17514, time stamp: 0x4ce7990e
Faulting module name: ole32.dll, version: 6.1.7601.18915, time stamp: 0x55981fd5
Exception code: 0xc0000005
Fault offset: 0x000000000001247b
Faulting process id: 0x10c4
Faulting application start time: 0xrecdisc.exe0
Faulting application path: recdisc.exe1
Faulting module path: recdisc.exe2
Report Id: recdisc.exe3
 
Error: (09/03/2015 07:38:19 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: recdisc.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: exception code c0000005, exception address 000007FEFD4A247B
Stack:
 
Error: (09/03/2015 07:36:24 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (09/03/2015 07:36:06 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: recdisc.exe, version: 6.1.7601.17514, time stamp: 0x4ce7990e
Faulting module name: ole32.dll, version: 6.1.7601.18915, time stamp: 0x55981fd5
Exception code: 0xc0000005
Fault offset: 0x000000000002850b
Faulting process id: 0x106c
Faulting application start time: 0xrecdisc.exe0
Faulting application path: recdisc.exe1
Faulting module path: recdisc.exe2
Report Id: recdisc.exe3
 
Error: (09/03/2015 07:36:06 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: recdisc.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: exception code c0000005, exception address 000007FEFD4B850B
Stack:
 
Error: (09/03/2015 07:27:16 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (09/02/2015 12:01:22 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (09/02/2015 08:39:26 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (09/01/2015 08:30:06 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
 
System errors:
=============
Error: (09/03/2015 07:46:02 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.
 
Module Path: C:\Windows\system32\athihvs.dll
 
Error: (09/03/2015 07:46:02 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.
 
Module Path: C:\Windows\system32\athihvs.dll
 
Error: (09/03/2015 07:45:58 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.
 
Module Path: C:\Windows\system32\athihvs.dll
 
Error: (09/03/2015 07:45:48 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Modules Installer service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 120000 milliseconds: Restart the service.
 
Error: (09/03/2015 07:45:48 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Presentation Foundation Font Cache 3.0.0.0 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 0 milliseconds: Restart the service.
 
Error: (09/03/2015 07:45:48 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The WMI Performance Adapter service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 120000 milliseconds: Restart the service.
 
Error: (09/03/2015 07:45:48 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Dell Data Vault service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (09/03/2015 07:45:48 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The SoftThinks Agent Service service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (09/03/2015 07:45:48 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Intel® Rapid Storage Technology service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (09/03/2015 07:45:47 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Dell Update Service service terminated unexpectedly.  It has done this 1 time(s).
 
 
Microsoft Office:
=========================
Error: (09/03/2015 07:48:18 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (09/03/2015 07:38:21 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: recdisc.exe6.1.7601.175144ce7990eole32.dll6.1.7601.1891555981fd5c0000005000000000001247b10c401d0e6a19c998c1dC:\Windows\system32\recdisc.exeC:\Windows\system32\ole32.dlldbf02d4e-5294-11e5-9c32-c81f661e844d
 
Error: (09/03/2015 07:38:19 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: recdisc.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: exception code c0000005, exception address 000007FEFD4A247B
Stack:
 
Error: (09/03/2015 07:36:24 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (09/03/2015 07:36:06 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: recdisc.exe6.1.7601.175144ce7990eole32.dll6.1.7601.1891555981fd5c0000005000000000002850b106c01d0e6a14d9c4265C:\Windows\system32\recdisc.exeC:\Windows\system32\ole32.dll8b7868cb-5294-11e5-9c32-c81f661e844d
 
Error: (09/03/2015 07:36:06 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: recdisc.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: exception code c0000005, exception address 000007FEFD4B850B
Stack:
 
Error: (09/03/2015 07:27:16 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (09/02/2015 12:01:22 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (09/02/2015 08:39:26 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (09/01/2015 08:30:06 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i3-3240 CPU @ 3.40GHz
Percentage of memory in use: 49%
Total physical RAM: 3970.04 MB
Available physical RAM: 2008.36 MB
Total Virtual: 7938.27 MB
Available Virtual: 5625.22 MB
 
==================== Drives ================================
 
Drive c: (OS) (Fixed) (Total:906.81 GB) (Free:849.39 GB) NTFS
Drive f: (OTLPE) (Removable) (Total:0.97 GB) (Free:0.59 GB) FAT
Drive y: (RECOVERY) (Fixed) (Total:24.67 GB) (Free:14.29 GB) NTFS ==>[system with boot components (obtained from reading drive)]
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 931.5 GB) (Disk ID: 882FD0A1)
Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
Partition 2: (Active) - (Size=24.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=906.8 GB) - (Type=07 NTFS)
 
========================================================
Disk: 2 (Size: 997.9 MB) (Disk ID: 0217934C)
Partition 1: (Active) - (Size=998 MB) - (Type=0E)
 
==================== End of Addition.txt ============================


#4 nasdaq

nasdaq

  • Malware Response Team
  • 38,256 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:02:08 AM

Posted 04 September 2015 - 07:46 AM

Press the windows key Windows_Logo_key.gif+ r on your keyboard at the same time. This will open the RUN BOX.
Type Notepad and and click the OK key.
Please copy the entire contents of the code box below to the a new file.
 
start

CreateRestorePoint:
EmptyTemp:
CloseProcesses:

HKLM-x32\...\Run: [vsadmin] => C
HKU\S-1-5-21-517160071-1547752724-213923089-1000\...\Run: [vsadmin] => C:\Users\EileenCCI\AppData\Roaming\vcwllo.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\restore_files_sqkjs.html [2015-09-02] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\restore_files_sqkjs.txt [2015-09-02] ()
Startup: C:\Users\EileenCCI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\restore_files_sqkjs.html [2015-09-02] ()
Startup: C:\Users\EileenCCI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\restore_files_sqkjs.txt [2015-09-02] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
C:\Users\EileenCCI\AppData\Roaming\vcwllo.exe

End
Save the file as fixlist.txt in the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the Farbar log you have submitted.

Run FRST and click Fix only once and wait.

Restart the computer normally to reset the registry.

The tool will create a log (Fixlog.txt) please post it to your reply.
===

Download to your Desktop the Junkware Removal Tool Download from this link.
http://www.bleepingcomputer.com/download/junkware-removal-tool/

Shutdown your antivirus to avoid any conflicts.
Right click the icon - disable for say 20 mins.
Right-mouse click JRT.exe and select Run as administrator (If using XP just double click on the icon to run it.)
The tool will open and start scanning your system.
Please be patient as this can take a while to complete.
On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
Post the contents of JRT.txt into your next message.
======

How is the computer running now?

#5 cyndi2966

cyndi2966
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:03:08 AM

Posted 04 September 2015 - 04:35 PM

Hello again and thank you for your support.  Below are the two log files you requested.

 

Overall it seems to be running fine.  I am not able to run the create a rescue disk program.  All data files are shot - but we knew that.  I have a backup and will deal with that.

 

The desktop still has four restore_files icons on it.

 

Thanks again,

Cyndi

 

Fix result of Farbar Recovery Scan Tool (x64) Version:31-08-2015
Ran by EileenCCI (2015-09-04 17:14:41) Run:1
Running from C:\Users\EileenCCI\Desktop
Loaded Profiles: EileenCCI (Available Profiles: EileenCCI)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
start
 
CreateRestorePoint:
EmptyTemp:
CloseProcesses:
 
HKLM-x32\...\Run: [vsadmin] => C
HKU\S-1-5-21-517160071-1547752724-213923089-1000\...\Run: [vsadmin] =>
C:\Users\EileenCCI\AppData\Roaming\vcwllo.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\restore_files_sqkjs.html [2015-09-02] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\restore_files_sqkjs.txt [2015-09-02] ()
Startup: C:\Users\EileenCCI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\restore_files_sqkjs.html [2015-09-02] ()
Startup: C:\Users\EileenCCI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\restore_files_sqkjs.txt [2015-09-02] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
C:\Users\EileenCCI\AppData\Roaming\vcwllo.exe
 
End
 
*****************
 
Restore point was successfully created.
Processes closed successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\vsadmin => value removed successfully
HKU\S-1-5-21-517160071-1547752724-213923089-1000\Software\Microsoft\Windows\CurrentVersion\Run\\vsadmin => value removed successfully
"C:\Users\EileenCCI\AppData\Roaming\vcwllo.exe" => File/Folder not found.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\restore_files_sqkjs.html => moved successfully
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\restore_files_sqkjs.txt => moved successfully
C:\Users\EileenCCI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\restore_files_sqkjs.html => moved successfully
C:\Users\EileenCCI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\restore_files_sqkjs.txt => moved successfully
"HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => key removed successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE" => key removed successfully
"C:\Users\EileenCCI\AppData\Roaming\vcwllo.exe" => File/Folder not found.
EmptyTemp: => 1.3 GB temporary data Removed.
 
 
The system needed a reboot.. 
 
==== End of Fixlog 17:16:38 ====
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.6.0 (08.31.2015:1)
OS: Windows 7 Professional x64
Ran by EileenCCI on Fri 09/04/2015 at 17:23:16.60
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
 
 
~~~ Tasks
 
 
 
~~~ Registry Values
 
 
 
~~~ Registry Keys
 
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{E32CDABE-3662-4E60-9623-57CDCBFADAF3}
 
 
 
~~~ Files
 
 
 
~~~ Folders
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Fri 09/04/2015 at 17:24:45.96
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 


#6 nasdaq

nasdaq

  • Malware Response Team
  • 38,256 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:02:08 AM

Posted 05 September 2015 - 07:49 AM


The desktop still has four restore_files icons on it.

Send them to the Recycle bin. You can flush them when all is well.
===


I am not able to run the create a rescue disk program


Hope this will help.

http://www.dell.com/support/article/us/en/19/SLN151701/EN

p.s.

Quoted from ths page.
NOTE: This is NOT the same as a Factory Backup, which allows you to return the system to factory settings after a Hard Drive failure.

===

If still having problems with this I suggest you contact DELL or possibly ask in the Windows 7 forum. This is not malware and not my forte.
http://www.bleepingcomputer.com/forums/f/167/windows-7/

===

To learn more about how to protect yourself while on the internet read this little guide best security practices keep safe.
http://www.bleepingcomputer.com/forums/t/407147/answers-to-common-security-questions-best-practices/
===

#7 cyndi2966

cyndi2966
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:03:08 AM

Posted 07 September 2015 - 02:15 PM

Hello again.  Thank you for your help.  How would you suggest I get rid of all the leftover restore_files files that are located in a million places.  And all the renamed encrypted files?

 

I attempted a search for the term "restore_files_sqjks" and it found like 600 instances....when I selected them all and told it to delete them all It seemed to do it.  But even upon a restart those files names are still showing in all the places they were before I "deleted" them.

 

Cyndi



#8 nasdaq

nasdaq

  • Malware Response Team
  • 38,256 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:02:08 AM

Posted 08 September 2015 - 07:02 AM

You may be able to delete them in Safe mode.

Before we try anything please post a complete and exact FileName you actually see when trying to delete it.

#9 cyndi2966

cyndi2966
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:03:08 AM

Posted 08 September 2015 - 08:55 AM

the files are either html or txt files and they are all named restore_files_sqkjs.  They are the ransom note from the virus.



#10 nasdaq

nasdaq

  • Malware Response Team
  • 38,256 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:02:08 AM

Posted 08 September 2015 - 01:34 PM


Let see if a can do something.

Please run the Farbar Recovery Scan Tool. Enter restore_files_sqkjs in the Search Box and hit the File Search button.
Post the content of the Search.txt in your next reply.

If the file is to large to paste please attach it.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users