Jump to content

hockey5

Members
  • Posts

    17
  • Joined

  • Last visited

Reputation

0 Neutral
  1. I am happy and you can mark this as solved. Thanks again for your help.
  2. Adam, The second link for delfix.exe worked and I think everything is working great. The only problem I am having now is getting the Pay Pal to accept my donation. The button link you have above takes me to a paypal site that assumes I am in Great Britain. I am in the United States. Even when I change the location to United States it still won't let me proceed unless I pick a county. The drop down menu for counties are all in GB. Any ideas?
  3. Adam, First, Thank you so much. Your help/work is much appreciated. I will absolutely donate, once I lookup the conversion of GBP to USD. haha. Seriously, many beers coming your way. Second, the link in the post above, for delfix.exe did not work for me. Is there another website I should use to find this file. Thank you again. Todd
  4. The contents of the checkup.txt log are below. I don't notice any other issues with the computer. However this is a laptop computer and I have it at work right now. I usually have this computer at home. It is not connected to my home printer. I guess I should try out the printer when I get home. It appeared that one of the folders infected was a "Hewlett Packard" folder, which I assume is for my printer. I also noted that there was a Fitbit folder infected. Which is my wife's fitness bracelet. She hasn't tried to "connect" the braclet to the computer since the computer was infected. I guess we'll try tonight. If it doesn't work should I uninstall that software and reinstall? The same with other issues I run into in the future? Results of screen317's Security Check version 0.99.89 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 10 Out of date! ``````````````Antivirus/Firewall Check:`````````````` Windows Firewall Enabled! Microsoft Security Essentials Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Adobe Reader XI Mozilla Firefox (33.1) ````````Process Check: objlist.exe by Laurent```````` Microsoft Security Essentials MSMpEng.exe Microsoft Security Essentials msseces.exe Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbam.exe Malwarebytes Anti-Malware mbamscheduler.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: 0% ````````````````````End of Log``````````````````````
  5. Adam, I find the below list of folders with the "Win32/Filecoder.CR trojan" flag. To be honest, none of those folders contain personal photos or documents so I am not sure what file I should be trying to restore. I would guess these folders are "important" as there names seem to indicate that they are used for our printer (Hewlett Packard) or my wife's fitness bracelet (fitbit) or Adobe among other things. I just don't know what file is encrypted or how the virus is effecting the operation of these. I guess it is good that photos and such aren't encrypted? Sorry if I'm not doing something correct. If you want me to try something else please let me know C:\FRST\Quarantine\C\Users\Laura\AppData\Local\Apps\DECRYPT_INSTRUCTION.TXT.xBAD Win32/Filecoder.CR trojan C:\ProgramData\FitbitConnect\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\ProgramData\Hewlett-Packard\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\ProgramData\Hewlett-Packard\HP Advisor\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\ProgramData\Hewlett-Packard\HP Advisor\basefeeds\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\ProgramData\Hewlett-Packard\HP Advisor\basefeeds\hq\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\ProgramData\Hewlett-Packard\HP Advisor\basefeeds\hq\101\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\ProgramData\Hewlett-Packard\HP Advisor\basefeeds\hq\101\ec-base\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\ProgramData\Hewlett-Packard\HP Advisor\basefeeds\hq\101\ec-base\attach\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\ProgramData\Hewlett-Packard\HP Advisor\basefeeds\hq\101\ec-base\attach\media\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\ProgramData\Hewlett-Packard\HP Advisor\basefeeds\hq\101\ec-base\attach\media\acceller\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\ProgramData\Hewlett-Packard\HP Advisor\basefeeds\hq\101\ec-base\attach\media\aol\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\ProgramData\Hewlett-Packard\HP Advisor\basefeeds\hq\101\ec-base\attach\media\attach\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\ProgramData\Hewlett-Packard\HP Advisor\basefeeds\hq\101\ec-base\attach\media\symantec\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\ProgramData\Hewlett-Packard\HP Advisor\basefeeds\hq\101\ec-base\attach\media\vongo\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\ProgramData\Hewlett-Packard\HP Advisor\LangRes\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\ProgramData\Hewlett-Packard\HP Advisor\LangRes\xx_xx\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\ProgramData\Hewlett-Packard\HP Advisor\LangRes\xx_xx\Resources\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\ProgramData\Hewlett-Packard\HPSAUpgrade3\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\ProgramData\Real\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\ProgramData\Real\RealPlayer\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\ProgramData\Real\RealPlayer\Database\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\ProgramData\Real\RealShare\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\ProgramData\Real\RealShare\Flash\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\ProgramData\RealNetworks\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\ProgramData\RealNetworks\RealDownloader\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\ProgramData\RealNetworks\RealDownloader\Flash\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\ProgramData\WildTangent\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\ProgramData\WildTangent\Zuma\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\ProgramData\WildTangent\Zuma\cached\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\ProgramData\WildTangent\Zuma\cached\sounds\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\All Users\FitbitConnect\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\All Users\Hewlett-Packard\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\All Users\Hewlett-Packard\HP Advisor\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\All Users\Hewlett-Packard\HP Advisor\basefeeds\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\All Users\Hewlett-Packard\HP Advisor\basefeeds\hq\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\All Users\Hewlett-Packard\HP Advisor\basefeeds\hq\101\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\All Users\Hewlett-Packard\HP Advisor\basefeeds\hq\101\ec-base\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\All Users\Hewlett-Packard\HP Advisor\basefeeds\hq\101\ec-base\attach\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\All Users\Hewlett-Packard\HP Advisor\basefeeds\hq\101\ec-base\attach\media\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\All Users\Hewlett-Packard\HP Advisor\basefeeds\hq\101\ec-base\attach\media\acceller\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\All Users\Hewlett-Packard\HP Advisor\basefeeds\hq\101\ec-base\attach\media\aol\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\All Users\Hewlett-Packard\HP Advisor\basefeeds\hq\101\ec-base\attach\media\attach\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\All Users\Hewlett-Packard\HP Advisor\basefeeds\hq\101\ec-base\attach\media\symantec\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\All Users\Hewlett-Packard\HP Advisor\basefeeds\hq\101\ec-base\attach\media\vongo\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\All Users\Hewlett-Packard\HP Advisor\LangRes\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\All Users\Hewlett-Packard\HP Advisor\LangRes\xx_xx\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\All Users\Hewlett-Packard\HP Advisor\LangRes\xx_xx\Resources\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\All Users\Hewlett-Packard\HPSAUpgrade3\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\All Users\Real\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\All Users\Real\RealPlayer\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\All Users\Real\RealPlayer\Database\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\All Users\Real\RealShare\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\All Users\Real\RealShare\Flash\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\All Users\RealNetworks\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\All Users\RealNetworks\RealDownloader\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\All Users\RealNetworks\RealDownloader\Flash\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\All Users\WildTangent\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\All Users\WildTangent\Zuma\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\All Users\WildTangent\Zuma\cached\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\All Users\WildTangent\Zuma\cached\sounds\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Adobe\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Adobe\Updater6\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Adobe\Updater6\Data\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Apple Computer\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Apple Computer\iTunes\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Apple Computer\iTunes\iAd\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Apps\2.0\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Apps\2.0\Data\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Apps\2.0\Data\GBZ19DNH.31D\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Apps\2.0\Data\GBZ19DNH.31D\YEVYKDRB.VOH\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Apps\2.0\Data\GBZ19DNH.31D\YEVYKDRB.VOH\onli..tion_751ffe0e5ce5d2e7_0001.0001_c972d513e1621f14\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Apps\2.0\Data\GBZ19DNH.31D\YEVYKDRB.VOH\onli..tion_751ffe0e5ce5d2e7_0001.0001_c972d513e1621f14\Data\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Apps\2.0\RGLHOHN1.LLA\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Apps\2.0\RGLHOHN1.LLA\TVNJGV9H.NK8\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Apps\2.0\RGLHOHN1.LLA\TVNJGV9H.NK8\onli...exe_751ffe0e5ce5d2e7_0001.0001_none_74bdab4cdb5192d3\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Atheros\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\00f472BE936eCDedF2ea37d5ed9a05D1\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\0139bfB97Ca081deA62b0fa2bd2e8B16\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\019847807983118fBB31c0f4fe0398C3\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\01e20c02966d5E0b9F5af6c9a0e48418\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\03227bAAA3ddBC7055460cab8ce02EF0\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\034a0209AF9aE1d74226a82821bc43AD\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\035aed6EBC9eDE66F4047ef87ef3B514\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\0504c5BA33a21285FF95be348c701D81\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\05fa4936B4091Bcf2D39a0f32515B983\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\06ca4777CF48DCe8FAf97e8ab192D8A0\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\06f307167613542600225b88cc7aF0EE\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\06fef4197Ff81A52179fd4cc2dc1D122\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\0708e040B01bE26fE2a0c9c4967588B8\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\08d2838020f481a60Ce36a5c23aeB568\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\0Aaee1C80F8823f36F010b7a560852CE\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\0Ca71dD971c6D2e41A133b7dfca494FC\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\0De93446734d9Ad404f71e3f711c469E\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\0Fbda54B69ba2F8aFE3c7c529ca471D1\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\13843bA6201aDEcf86818ab0f09aEFCD\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\1384dd88EF6a82cfB51425a7ece968D5\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\1478a3FC2202B01561e4b5912ea74691\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\14a393A0A63c725eF21c0f8fed6123B0\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\157796863888480eECcb55d2b850F49E\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\166487BB15c597c76Ca10480467d9CD2\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\168d1b7D91e38B44B8916204399f5C39\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\16f75a1D6A2f285b3074b823e0b0E12B\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\18d9d6F8E4ab421d736064ae533d9D91\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\1917acCD93f6A5441661bb9633ffDFA3\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\1Ac17d5843d3C860DE6b6e31f725D8C1\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\1Ba997844D532C62F12b7d284e857257\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\1Ec901288Ac4BD56A829c53ffe964D1D\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\1Ede0eFE7AdeA3fc777f886da6f4B7B1\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\1F08d23E32fdB3104Ec578dd39d062C5\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\219b134865bfE0cdFF698e6187ce9F83\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\21f6a24BDE41AF8d2Ce7810d9972807B\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\2317f30D0Dc609fdF897a1812d688CC2\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\239ae2B1A349D234830a3fbab8d192D2\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\24a9e6DD4A98F1843A9c6135cdba69FB\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\26777dB4B98d325a657b38ef29756118\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\26a20b7856e945e2AD9764aca08822F7\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\296c6e37FF67C158885ae6886b7e7B92\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\29d092AF3Eac5C473Bbdb805b4731A02\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\2Cbba291D56fCCd607498d2482c29C5D\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\2E403fCFDA39AD4600b817b0569cEC47\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\306065B56661B7a353ecee546a279A17\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\30b6491F8600021f37068ded8e8f470D\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\30e9041B933c593068a68568e7471696\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\319d2cECF3d646d25Dc4e8076a58E4C0\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\3200f213DBec8EbaE2d3033399ff1D3C\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\3542c6A1E3d7B972A6b792fe84c47DA8\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\369f6f288B2f28a491c620a97baeC810\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\377c69D7DD74E015C5091b3919d421A0\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\38869e70177635a8B091e351f6c43178\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\393bd831079eE98f82ae4070f3f18DF3\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\39685d1664fbCF06AEb1117571c0853B\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\3D52d970A4be1Bcb9A43828380699D8B\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\3Ead4dFD5Ce7D7515377086c919727C2\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\3F1066FC7953097aD5c22956c6c2C5BF\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\3F71f711B1329B74875360c0b7843B87\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\40e30b6357de5E5eFD475fa1b41a3D70\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\415cc33CD255972f606027c1ff5aB3F6\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\434041340Ad1ACe5C77e94e0878e1745\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\45e13b26AE15AC7e6E1545fb90a2E91A\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\461d9dC96Fed7Ace6715150257c1E583\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\46a1f5075430EDb59212d9d7979c9FB9\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\4798700CEB6c96764201b9600d9f6F51\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\4923dfBBAAd7643b88513394709cBE02\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\498dbc621884AE29E4a32f3baac03ACB\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\4A7ff4AC26f565e031e368a5bd264473\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\4B57ee66568bD0e8187fba8d3cd15BDD\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\4Bac5543C2580De1172e224e46424B87\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\4Bc2dd60BA088E95A826c51c15b766CD\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\4D2b59BB6A8fFCf1E2f5746d344aFDA5\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\4Dbed925B6e7664eBE3f8d8f2ed7446D\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\4F0f8b72864eC55f94b670fd64201580\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\5217bc3756dfE123ABe97e4e3fe26A41\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\526d6cDB5Cd55Cdd5A4178c0b769EF98\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\5585f34CF6308D39D7b53519091c53FB\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\57b3b3541Efd2781A67f10d453068471\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\584ee7D1CE6b0Ac0CEe40f837b647EFE\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\5950ae36097f7Fc9073d3d780221BB4D\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\5975cfC6E9d06Bbc34e25b41bc8b9350\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\5A6ee034C08fC9e4EB0911940e093901\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\5Ad689DF1E44F34c490c19d39555278E\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\5B4f329E603bDB4dDE9509fd7e291FC2\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\5Beae8DF330e199cC01c32555d1bA728\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\5E69a4B924e3040e2Bde2ef7e2e8F714\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\6181f00326adB36f6604317b33e4128C\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\62caf0EB9Baa4C52C745a75d63b25F10\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\630a0e97CD9a2E12BB9ce2e46c9214B1\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\64aa4e821614CAb5311ad5973857B538\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\64fed340AE1fED56FEec31e1bf705E89\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\65100019509614b090b64584649d7D57\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\661042E352685818CEa97a87890b3646\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\6720d2F46274CF24FB0949f5b12c4BA8\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\672b2766F5e54Dbe5B7299b51c7b4811\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\684344CDD325965859d096133db8C5D7\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\6926c317DAb368cb58c119b417ba3C2E\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\6B962f7C4Dcc36e4DE02f245f9ceA182\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\6CddacD73A7f1D378E9b336fe42193B4\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\6D45783E5EbdCB52F46b57b55db95DF8\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\6E263c0C6C76D852C6e7155bc915D001\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\6F3abf40F078D3f5C75aab7bf805B784\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\70a8b89491a28F229A53d3519c15DAFA\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\70bf186D6EfbEFbb073edcc77f746A12\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\7241f986B11622555E291194a9fc1E98\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\7329783224cc6A4d4Dbbf156de18B02A\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\7385c395AFa4EE9150b501ed94aaCAED\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\77cdb31C463d29fcF9d8677cc7a1830A\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\7801ea9A19acBF097D13c002fd01B1AD\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\791200B2911e018722e7993b2b381F3E\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\79cad186F6c8934dD22651c2a06436BE\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\7A3e1e971F4251a9AAc836b26bfc0163\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\7Ad9718B5774747e21d73d21a7a53FD0\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\7C84b3805Cc20997EB1605d6fa98447B\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\7D06f00E72abDD96397f7284de830D56\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\7E749a0F2Fdb2CdbBA14971c69ed3932\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\7Fb26d09D0c05F35EE8ed3c153a2F1B1\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\7Fca5364FAafC0cf43b2278f6d1b3B83\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\80c3bbE12Dd0BEecBD3f4358be2746E2\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\81a807A611c1EDb027eee964946806AC\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\81afadD31F2a1Cbe6Fdf10a056248DF6\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\827f38C6456b0982838baf5b42fa53B1\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\83d98bC75D3d18a0C0d99c2fb6fe0387\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\873062A66B7dC2c9EAd2a3bee153F406\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\8891f67BC45b0A0462a66bb00989AC3E\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\8B588444F31b60249Fac052b15865E2F\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\8C10954E53e24Dc0076df930d356962C\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\8C7f1b8B3D62C45d4495d43760030EA9\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\8F6815912D41855985ef7694d4a987AC\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\901c3f9D743b83e1D9dbda0ca90023C4\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\906fb11C3B4f8C1b195ebd1099c87AC8\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\914121F0B47b3E21A9492d1598d3966D\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\91e97e6BDEf5E38b9D972648c4039D5E\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\924ddf22F856AA3241d5cb790d72AACE\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\92cda0716070205d4D5e946238f76B6A\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\93840f277C7fD28bBF042d26a4dc57C9\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\943206603Df8778771ae384d05b23BB6\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\9461362C275aE115AEcb8fba343b1296\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\9539f373DB47254cB192b59d04c389E7\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\9597d073927cF3daC38418a3e20765DC\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\9684566B060609486271719a04e45CF3\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\96f43eA54683E6b2ADa55acaa446B1DE\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\9Baa8bD6C6ccB48c80f0fdac2590CE18\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\9C09973165c7D6f42C0d04272cca7F54\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\9Ce2a693B84eBD6e2D887068b1122936\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\9D4a57897590E6011Ed8ee38a44dE5B7\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\9E307e8F9768663eC306cbbdf5a63CBD\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\9E67b34690831FaaCF26430f1dcd8BFF\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\A07d33604De40F5077c5eb045c557779\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\A2345c16FE54C65bFF62698236402229\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\A26d18183775B7dfDAa202ffe8f7B4F4\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\A3c39033CEe9105b170fc5b1f04a5376\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\A4e04bB28315286b8Ada323fb8546CD5\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\A88c520B3869ABf651cf629a09d98376\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\A8945123CCa25570D46250193007AD6D\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\A90d66312EfaE7930A3980425a10D7BD\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\A98bc4E661580B6e931ba253480d2366\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\A9f2f362BBa4431f1Ab7711b51181CEA\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\AB70fdBAD0990F362Bf9b6ef6c4eF192\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\ABaaa75C2145D5cb557d84a719777738\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\ADf898EC77de3F011Bc0a31b937b087B\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\AF6b8f852Db3E7e6CB3ea40578b5BA96\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\B0f0e92C440182f5F393298eb1ff5044\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\B4b926297Dc308b5EE6851bc69e7F077\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\B55fd9F6E4cc743095707b1a56c4801C\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\B5f6fcFC3CfcEE05E31189c1fbe56EFC\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\B9bef9C47140CDfaE9cdb0607d14F785\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\BA420d5AFE0d1D332Caa369655472BD4\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\BA7d67A56990B752E2a20b9c574dDA8C\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\BBe3723439f36672764604f7484bB0C3\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\BC450491BA211D50EA8074937acdDBC8\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\BCbaf5C7E50026aa558a9f45852fE21E\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\BDbf2bDE76265C3450e61390d4677C49\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\BE1ad722447086a8A6b0d3a889f5B181\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\BE823a3C6010E546F7b9baa810f231CB\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\BF8ec85736fd012d672e4efca5814B50\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\C09e7827B30148c1057c3a247c482FA3\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\C1c1eeF0E94b9771F509c8972bd63C0D\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\C34772181B0fE720B06a4c88ff96CBC1\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\C418a535FDf46FbaFC5a40f48ccbEA2B\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\C57c402E317eC379F5a6c4c4f752C50D\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\C608f65691d74D13179eb7c7ad044DB6\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\C64452B44E2fC9d932e4f32d24620CB0\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\C76f6654B3338Cfa7261c67a0e49E71F\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\C87f5c795C633Dd49Bcb7968e1ee1F9A\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\C88fd9DA5A9826e83170e925472c8EB4\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\C9ed27C73Fe382fdF21177e63d3a20DB\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\CAb1d880A070A2d0A808e769e957C6A1\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\CC7c13B06Ff60Aad4C714caa2b1e8369\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\CCe3a82F9E0b75fbCEfa2cc36a615DCA\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\CCfdba59D436A7ef3Fe3dbff261c5C5F\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\CD168377D7919A8d173572c25318F887\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\CD2c6aC89Abc8Fb0CDa9055cadb60B35\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\CD9a7e5910440Be8512b156e36a1C9EB\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\CE7abdD2D65c1Ac4B0229fc50842F72D\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\CF21d6A6CD34525995ab70b1d545467C\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\D00643625022223d4248cf4b1d7a6FE0\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\D0b1aa37715bB3f089d1cb9c5bb7E5C8\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\D12693972B2c0Ed7C2f141422eecFE70\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\D14ff2E283feE47899e72359b89e926C\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\D25ffaAB0739E76e08f0bc2f53f029B3\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\D27f66EBAC6b636a568f913c29dd19CD\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\D2826945DC34429f58a6da20932c67C8\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\D4b7413163043D5a8C25532fdb126450\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\D4e063F73Fd06Cb4EB0d73e4f7eaC252\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\D617021E5B2d1303D780baa1fcf4E122\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\D676534E0C7884b8449526fd0a79C469\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\D7a0941261e13B36376b6f9f258a3157\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\D910acDA1B786671CD28aa8fe37297BA\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\DC23e1AE94195Fa3DCbec6e6e6a5DA04\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\DD2a91EDB4769Aef2106a8b4564702AD\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\DE44a751B4efF78c52d9abd58818FF04\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\DF492b699EceCCd98Ba79e6e3928A210\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\E067b686D79119f367c88491386e5F78\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\E06f907DA19672c999798a9bbb7b8AA6\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\E14d228963f80079AD94356d5c5d4FBB\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\E1e153AE19b45Fc6E9a554904cdb143E\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\E2a197BD468e4667064a558c41ef721E\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\E30d4f6E088892ff2D47d25dcaabAEF4\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\E3bd31038A1b22cd6A35d346cc9c9CF8\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\E4884aA64B9dBAfd71b00c14f605D87D\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\E4fc65BAE4f94Aaa82bd73f2000a7540\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\E5ae6cD877c533a36015f05432620673\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\E61d36D03Bb579132C82e385f692E1CA\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\E642fdE4AF5846fdC1dad56cc2067942\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\E7042bFFC0740C0a126a7d002b965CE7\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\E8457607282d7F4e4469d71b42f928A2\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\AppData\Local\Corel\Thumbs\E97f801F0Afa1459C11d16e843d83F81\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan C:\Users\Laura\Downloads\cnet_full_video_converter_free_exe.exe a variant of Win32/InstallCore.D potentially unwanted application D:\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan E:\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR Trojan
  6. Adam, Thank you for the info on the warning boxes for internet explorer. I've check the "in the future..." boxes and all is good. I also figured out the sound issue on youtube. When I clicked on the volume icon in the system tray there was an option to click on "mixer", which I did. And a number of volume slides opened and for some reason the slide for Internet Explorer was muted. I unmuted and it worked. Regarding the infected files. Can you guide me in how to find an infected file? I've looked at a number of photos and videos and they all seem to work. I will keep looking but if there is a better way to locate please let me know. Todd
  7. Adam, Attached are the logs you requested. In general the computer is running much better. There are a couple of items that I noticed. First, when I use Internet Explorer, I consistently get two pop up windows. I get a "Security Alert" pop up window that states, "You are about to leave a secure Internet connection. It will be possible for others to view information you send. Do you want to continue? " Then when I click on yes a new window pops up that says, "You are about to view pages over a secure connection. Any information you exchange with this site cannot be viewed by anyone else on the web." Both times I have the option to check the "In the future, do not show this warning" box. I have never seen these before. Second, I went out to youtube and tried to play a couple of videos. I don't get any sound. I have turned up the volume on the computer and in the youtube window. But still no sound. I can hear the typical windows sounds such as a "bing" sound when I click on something incorrectly. So I don't think it is the speakers. Thanks so much for your help. Addition.txt Fixlog.txt FRST.txt
  8. Adam, Attached are the 4 logs you requested. AdwCleanerS0.txt Fixlog.txt JRT.txt MyEsetScan.txt
  9. Adam, Is it important for me to select Unicode in the Encoding: drop-down box when I save the fixlist.txt file. You mention that in one of your first posts, but no this time. So I wasn't sure. My notepad defaults to ANSI Encoding. Thank you, Todd
  10. Adam, Attached is the dirlook.txt file. Thank you. dirlook.txt
  11. Adam, I have completed the remainder of your instructions and attached the requested logs. Thanks for your help. I look forward to hearing from you again. Todd Addition.txt ComboFix.txt FRST.txt malwarebytes scan log.txt TDSSKiller.3.0.0.41_13.11.2014_09.34.44_log.txt TDSSKiller.3.0.0.41_13.11.2014_09.40.02_log.txt
  12. Adam, I have attached a txt file of the scan log. I know you stated you preferred that logs are posted directly as plain text, however I can't seem to get this to work. I have tried breaking the file up but I still can get it to paste. I apologize if I am making your work harder. I must be missing something. I can start Step 3 if you would like. Thank you. Todd malwarebytes scan log.txt
  13. Adam, I closed FRST, recreated Fixlist.txt and re-ran FRST. It again appears to be "fixing" for a long time. It is still running. However, I noticed a fixlog.txt on the desktop. I have attached the file. I tried to cut and paste the text into the body of this post, but I was having trouble. Sorry about that. Please let me know if I should do something else. Thank you. Fixlog.txt
  14. Adam, The FRST is still running. Since my last post, the program appears to have moved from "fixing" status to "scanning" status. It appears to be scanning all of the files on the computer. I do not find a Fixlog.txt on the desktop. I have NOT stopped the program, since it appears to still be scanning. Please let me know if you still want me to stop the program and restart the repair. Thank you
  15. Thank you for the help Adam. My first name is Todd. I was not aware that I had been infected with CryptoWall 2.0. I read the information you provided and I am obviously worried about what it has done to my computer and my files. I hadn't noticed that I couldn't open any documents or files, just that my computer was running very slow. However, I haven't checked the files so I guess I'll what happens. As I understand it, I would have to pay a ransom to open encrypted files? Is this something that can be decided later? Hopefully after you help me remove the infections and I have a chance to see what files were encrypted? I have started with STEP 1 of your instructions. I have copied the Script to a fixlist.txt file and placed it on the desktop (where the FRST64.exe files is) and ran the programme and clicked "fix". It has been "fixing" for over an hour. Is this normal and should I just let it keep running? One item to note, the infected computer is not connected to the internet. Is that a problem? Thank you for your help.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.