This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

malware infection...please help

24 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer is infected with malware…avg keeps showing trojan virus infection in system 32 files but can't access them to heal. Desktop is white, gambling program has appeared and fake spyware detectors etc. HJT log below. Any comments would be much appreciated. (Have uninstalled Norton so not sure why so many symantec entries). (Have also uninstalled kill and clean using control panel)

Thanks
Stillwill


Logfile of HijackThis v1.99.0
Scan saved at 21:18:11, on 02/08/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\ssoftsrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\ishost.exe
C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\System32\ismon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Real\RealPlayer\trueplay.exe
C:\Documents and Settings\Omni\My Documents\My Deliveries\SPYWARE TOOLS\hijackthisnew\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BTopenworld
R3 - URLSearchHook: (no name) - {500F5A07-1175-6909-99D3-F001C5911E1E} - iehelper.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [TotalRecorderScheduler] C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [pizda] killall.exe
O4 - HKLM\..\Run: [zxc] SpyElim.exe
O4 - HKLM\..\Run: [sqkpm.exe] C:\WINDOWS\System32\sqkpm.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
O4 - HKCU\..\Run: [KillAndClean] "C:\Program Files\KillAndClean\KillAndClean.exe"
O4 - HKCU\..\Run: [typeconf] teqq32.exe
O4 - HKCU\..\Run: [___] FLKPT.exe
O4 - HKCU\..\Run: [ERTYDF] Brong32.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.btinternet.com/
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {F04F4F32-6457-401A-8169-D2773DDFF930} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/…ropper1_6uk.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9310FF1F-C13E-4A01-BFB8-90840CC4AAF3}: NameServer = 85.255.115.27,85.255.112.181
O17 - HKLM\System\CCS\Services\Tcpip\..\{ABA1FB6B-231E-443B-AB8D-3FAAA0DA3187}: NameServer = 85.255.115.27,85.255.112.181
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.27 85.255.112.181
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.115.27 85.255.112.181
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.115.27 85.255.112.181
O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: EPSON Printer Status Agent2 - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sony SPTI Service - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: Cryptainer service - Unknown - ssoftsrv.exe (file missing)
O23 - Service: TrueVector Internet Monitor - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Welcome to the forum :wavey:

Only for Windows XP and Windows 2000

Download SmitfraudFix (by S!Ri) to your Desktop.
http://siri.urz.free.fr/Fix/SmitfraudFix.zip
Extract all the files to your Destop. A folder named SmitfraudFix will be created on your Desktop.

[external image: Posted Image]

______________________________
Next:

Download ewido anti-spyware from HERE and save that file to your
desktop.
This is a 30 day trial of the program
  • Once you have downloaded ewido anti-spyware, locate the icon on the desktop
    and double-click it to launch the set up program.
  • Once the setup is complete you will need run ewido and update the definition
    files.
  • On the main screen select the icon "Update" then select the "
    Update now
    " link.
    • Next select the "Start Update" button, the update will start and a
      progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of
    the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then
    select "Quarantine".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close ewido anti-spyware, Do Not run a scan just yet, we will shortly.
    ______________________________

    Open the SmitfraudFix folder and double-click smitfraudfix.cmd
    Select option #1 - Search by typing 1 and press Enter

    [external image: Posted Image]

    This program will scan large amounts of files on your computer for known patterns so please be patient while it works. It will create a file named:

    c:\rapport.txt

    Open that file with Notepad, and "copy/paste" the ENTIRE CONTENTS of it into this thread.
thanks for helping. this is a struggle as computer has limited functionality. avg now accessing and healing generic xks, xfv and clicker fr but regularly freezing up as i try to do anything. anyway have downloaded smitfraud and ewido….see rapport.txt log below. regards stillwill SmitFraudFix v2.81 Scan done at 22:51:40.73, 06/08/2006 Run from C:\Documents and Settings\Omni\Desktop\SmitfraudFix\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT Fix ran in normal mode »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 C:\WINDOWS\system32\ishost.exe FOUND ! C:\WINDOWS\system32\ismon.exe FOUND ! C:\WINDOWS\system32\1024\ FOUND ! C:\WINDOWS\system32\components\flx?.dll FOUND ! C:\WINDOWS\system32\components\flx??.dll FOUND ! C:\WINDOWS\system32\components\flx???.dll FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Omni\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Omni\FAVORI~1 »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys HKLM\SOFTWARE\SHUDDERLTD FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="C:\\WINDOWS\\desktop.html" "SubscribedURL"="C:\\WINDOWS\\desktop.html" "FriendlyName"="Security" »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End
Running the Clean

Warning: running option #2 on a non infected computer will remove your Desktop background.


Please print out or copy these instructions/tutorial to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
______________________________

Open the SmitfraudFix Folder, then double-click smitfraudfix.cmd file to start the tool.
Select option #2 - Clean by typing 2 and press Enter.
Wait for the tool to complete and disk cleanup to finish.
You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.

[external image: Posted Image]


The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. Reboot in Safe Mode.

The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.
______________________________

Clean out your Temporary Internet files. Proceed like this:
  • Quit Internet Explorer and quit any instances of Windows Explorer.
  • Click Start, click Control Panel, and then double-click Internet Options.
  • On the General tab, click Delete Files under Temporary Internet Files.
  • In the Delete Files dialog box, tick the Delete all offline content check box , and then click OK.
  • On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
  • Click on the Programs tab then click the Reset Web Settings button. Click Apply then OK.
  • Click OK.
Next Click Start, click Control Panel and then double-click Display. Click on the Desktop tab, then click the Customize Desktop button. Click on the Web tab. Under Web Pages you should see a checked entry called Security info or something similar. If it is there, select that entry and click the Delete button. Click Ok then Apply and Ok.

Empty the Recycle Bin by right-clicking the Recycle Bin icon on your Desktop, and then clicking Empty Recycle Bin.
______________________________

Close ALL open Windows / Programs / Folders. Please start Ewido, and run a full scan.
  • IMPORTANT: Do not open any other windows or
    programs while ewido is scanning, it may interfere with the scanning proccess:
  • Lauch ewido-anti-spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab
    then click on "Complete System Scan".
  • ewido will now begin the scanning process, be patient this may take a little
    time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all
    actions
    "
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the
    screen and save it as a text file on your Desktop (make sure to remember where you saved that file, this is important).
Close Ewido and Reboot in Normal Mode.

______________________________

Please post:
  • c:\rapport.txt
  • Ewido log
  • A new HijackThis log
Your may need several replies to post the requested logs, otherwise they might get cut off.

You also have a "Wareout" infection that may take another post or two to remove.
:)
Hi Again, thanks for help…it will be a great relief when I can feel confident that the computer will make it through to the next stage before seizing up!!! Thought it was going ok…have completed smitfraud operation and am posting the rapport log. However Ewido scan showed 23 entries!!! with 103 infected objects (a bit shocking..does this mean adaware isn't really keeping on top of things now?) but unfortunately has got stuck. Scanned for two hours up to system32\vkaa.dll then continued to scan that file for a further one and a half hours. Task manager shows ewido running but there was no movement of the scan on from that file for over ninety minutes. Is that correct…am I too impatient or is that the scan getting stuck? I'll try again anyway but have posted the rapport file in the meantime. Regards Stillwill SmitFraudFix v2.81 Scan done at 19:19:40.37, 07/08/2006 Run from C:\Documents and Settings\Omni\Desktop\SmitfraudFix\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT Fix ran in safe mode »»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» Killing process »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix GenericRenosFix by S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files C:\WINDOWS\system32\ishost.exe Deleted C:\WINDOWS\system32\ismon.exe Deleted C:\WINDOWS\system32\1024\ Deleted C:\WINDOWS\system32\components\flx?.dll Deleted C:\WINDOWS\system32\components\flx??.dll Deleted »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning HKLM\SOFTWARE\SHUDDERLTD Deleted Registry Cleaning done. »»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» End
Maybe if you pause here and post a new HijackThis! log, we might be able to kill a few items to help Ewido run faster. You had a "Wareout" infection also present in your first post. :)
Here is the current hijack this log. I did run another ewido scan last night but it got stuck on the same file again so am not able to provide a report at this stage.

have just done some quick research on wareout…is it that which causes the scan to stop?? Do we need to deal with that first? Anyway, looking forward to your reply.

thanks
stillwill

Logfile of HijackThis v1.99.0
Scan saved at 18:18:36, on 08/08/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\ssoftsrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Real\RealPlayer\trueplay.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Omni\My Documents\My Deliveries\SPYWARE TOOLS\hijackthisnew\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.btinternet.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BTopenworld
R3 - URLSearchHook: (no name) - {500F5A07-1175-6909-99D3-F001C5911E1E} - iehelper.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [TotalRecorderScheduler] C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [pizda] killall.exe
O4 - HKLM\..\Run: [zxc] SpyElim.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [rntvf.exe] C:\WINDOWS\System32\rntvf.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
O4 - HKCU\..\Run: [KillAndClean] "C:\Program Files\KillAndClean\KillAndClean.exe"
O4 - HKCU\..\Run: [typeconf] teqq32.exe
O4 - HKCU\..\Run: [___] FLKPT.exe
O4 - HKCU\..\Run: [ERTYDF] Brong32.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.btinternet.com/
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {F04F4F32-6457-401A-8169-D2773DDFF930} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/…ropper1_6uk.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9310FF1F-C13E-4A01-BFB8-90840CC4AAF3}: NameServer = 85.255.115.27,85.255.112.181
O17 - HKLM\System\CCS\Services\Tcpip\..\{ABA1FB6B-231E-443B-AB8D-3FAAA0DA3187}: NameServer = 85.255.115.27,85.255.112.181
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.27 85.255.112.181
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.115.27 85.255.112.181
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.115.27 85.255.112.181
O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: EPSON Printer Status Agent2 - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sony SPTI Service - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: Cryptainer service - Unknown - ssoftsrv.exe (file missing)
O23 - Service: TrueVector Internet Monitor - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
And I'll bet a pickled Buffalo tongue you have the new "Wareout" infection that is a bit more tricky to remove.

I'll know for sure after your next post.

Please download FixWareout from one of these links:
Fixwareout.exe
Fixwareout.exe

Save it to your Desktop.

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

O4 - HKLM\..\Run: [pizda] killall.exe

O4 - HKLM\..\Run: [zxc] SpyElim.exe

O4 - HKLM\..\Run: [rntvf.exe] C:\WINDOWS\System32\rntvf.exe

O4 - HKCU\..\Run: [KillAndClean] "C:\Program Files\KillAndClean\KillAndClean.exe"

O4 - HKCU\..\Run: [typeconf] teqq32.exe

O4 - HKCU\..\Run: [___] FLKPT.exe

O4 - HKCU\..\Run: [ERTYDF] Brong32.exe

O17 - HKLM\System\CCS\Services\Tcpip\..\{9310FF1F-C13E-4A01-BFB8-90840CC4AAF3}: NameServer = 85.255.115.27,85.255.112.181

O17 - HKLM\System\CCS\Services\Tcpip\..\{ABA1FB6B-231E-443B-AB8D-3FAAA0DA3187}: NameServer = 85.255.115.27,85.255.112.181

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.27 85.255.112.181

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.115.27 85.255.112.181

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.115.27 85.255.112.181


Then click "Fix checked" and close Hijack This!.

* Run fixwareout on the desktop.
* Click Next, then Install, make sure "Run fixit" is checked and click Finish.
* The fix will begin; follow the prompts.
* You will be asked to reboot your computer; please do so.
* Your system may take longer than usual to load; this is normal.
* Once the desktop loads a text will open (report.txt). We'll need that in a bit.

"Copy/paste" a new HijackThis! log file into this thread.

Also open this file with Notepad:

C:\fixwareout\report.txt

And paste it's contents into your next post.

:)
phew!!!! its running again!!!
here are the two logs
thanks!

Logfile of HijackThis v1.99.0
Scan saved at 20:33:00, on 08/08/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ssoftsrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\System32\rundll32.exe
C:\Documents and Settings\Omni\My Documents\My Deliveries\SPYWARE TOOLS\hijackthisnew\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BTopenworld
R3 - URLSearchHook: (no name) - {500F5A07-1175-6909-99D3-F001C5911E1E} - iehelper.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [TotalRecorderScheduler] C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.btinternet.com/
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {F04F4F32-6457-401A-8169-D2773DDFF930} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/…ropper1_6uk.cab
O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: EPSON Printer Status Agent2 - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sony SPTI Service - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: Cryptainer service - Unknown - ssoftsrv.exe (file missing)
O23 - Service: TrueVector Internet Monitor - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Fixwareout ver 1.003 Last edited 07/1/2006 Post this report in the forums please Reg Entries that were deleted HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7E4263DD0D82-74C9-53B4-3B68-31FC4D22{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2ADDB5F3BFE6-BBFA-EC44-946C-614B966B{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}769181910852-485A-C824-7FD4-029811D9{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}BEA75F227587-B3D9-3DB4-9D28-CE59EABD{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E9DF7450B1C9-5878-BAD4-BEF8-2D7CC992{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}58DFE0EFF700-A9F9-8804-025F-7FEED5BB{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}72B43398D322-A50B-2444-8878-5967D1C0{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}EAF35CA45125-A4CB-0B84-DDB5-B6C7B7CA{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}31E560AA96CB-5EF9-7B84-4841-98CD81CE{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C953453F5A92-87DB-7C94-D867-29FE5D2E{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9B68FDEF6203-51EA-3F84-6AE6-431C892B{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2DF0537CB425-31B9-2F94-E6CE-9CCCFA1E{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}97AD7D4DCD94-D52A-B8A4-5344-EA5908F3{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}56BBC84E2E94-7AD8-2044-DBF1-6A5F47EB{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2A5D028ADB44-5C59-F264-AEAE-488A82B9{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1FBFA30F1AF7-37C9-4F44-E45C-E786BD64{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}15761DD80451-EB5B-5EE4-1875-7D2115A0{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}DC7752439D43-514B-35F4-BCB0-95B7B9DE{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B5214049CF16-92C8-1104-142A-3050F2D1{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}503D1B82BD05-4E2A-1244-B7B4-C8F70B0C{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}28ADD0193539-957B-45B4-2F6F-896C45EF{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0F2425D3F464-E999-89A4-C086-07DA4DFC{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F64FDACD22CD-E5E9-A944-31A0-DCD6C45B{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D2D8741B9084-A29A-5624-BD02-3A440784{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}86A569F1136B-3F48-F044-74BD-089CA0A2{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}20679C338B65-F76B-64B4-ADE2-BA856E8D{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}27AA6CD0E6E5-80AB-37B4-7D20-2FC7FEE7{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}03847FBF2721-5F3A-1464-CCB2-28E4CA50{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}26836C7540B6-22A9-3024-F83E-F282B38D{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}671E42EED190-C11B-D184-FFB8-96E219A4{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}EDDA1071EB73-360A-8FC4-6F27-EA616E21{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}87F368624565-96EB-8E54-8BEB-67A213E4{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3C066355E338-BEE8-7B44-4183-1E365A95{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3024A184001D-6549-4C84-DF30-907E500C{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}EC1E21B70A4C-509B-EAE4-B54C-FA621C16{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7D96EE6D54A0-D309-8524-BFE9-9A92182A{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}515028574405-8558-5CB4-C30E-AB1FCF9A{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0E1B16F788B4-A42A-7034-0316-55F94735{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B160FE2C86E8-C86A-3B74-9FB2-02C02EA6{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}629E5810516C-60BA-4E94-BF7E-9A5E78C0{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}20677AD1D1C3-A239-57A4-C785-8723655F{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7345B5C592F2-CEEA-74C4-AEFC-A77A5FB0{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}41DA5E3DC494-E92A-7E74-B89E-BB8AAE20{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F8672A589732-477A-DDF4-A991-3D63F586{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FC9DB96A0561-84E8-F244-6B72-8A6FB465{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}68450FDC1314-2009-ADC4-2B8A-64B89F74{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}133FA69C0BB5-67E9-5184-F68E-6A3A45AC{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AD6C2E6D5542-74F9-B414-86B0-F4DADC8B{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A29064191C73-B29B-2854-3DE8-880A1F30{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1D10012B6F3A-29CB-6E24-4FD6-EFE269B7{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}30224C212BC4-A7C9-84B4-03C3-CA7043AE{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}60F939709A86-50CB-2AC4-BF4B-8AAC4771{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}62DD01B184FE-D7B8-2D64-29C8-A62C602F{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CDA7FC20F71C-3FEA-AC94-1FF8-8081CEEC{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2F2DC88E378E-8F59-C4E4-7761-19B83BD2{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3D3D05AC0085-3D1A-D164-812C-8DFF61F8{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}958700BAAD2F-D968-F2E4-F742-D6CD76C4{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A8E5DBD2FE70-21AB-0594-4405-73176662{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AAD843DA9F24-E629-1754-F458-F8C5704F{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1949530C111D-F4A9-0BA4-9220-224DCBE9{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}596AC041893E-0F39-AE94-4921-BB045D18{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5E10C56F0C5D-E0FB-98F4-6FA6-E1659592{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4B06871D4C84-C3DA-2214-8A9B-9ACAA985{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}236B7E286921-ED49-C1E4-7592-984967D6{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E74B270E4229-2419-ACC4-3031-D6202E47{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7CA551181643-495B-6B74-5BC6-D702EA94{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9AFFDCBC4827-A2D9-8F24-EBCD-D61AC24F{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1D37743D8C62-C109-58B4-A26B-212383ED{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F888C3E0A368-484A-B644-D648-FE0425F4{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}26B42D6775FD-331B-3FB4-904C-5A49DDD4{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}808D47989C41-4D1B-37B4-755A-90448528{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6D420621AC2B-E5A8-34C4-526C-2A081644{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D64D65267843-0368-8F74-A1B3-7942A85A{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6ADBAC6C1B03-C06A-D804-0337-36E1114F{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E34C12A514F1-1A3B-9DA4-F70F-EE0596C4{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}980853A3D356-88EA-A8D4-5B1D-BD5CDC92{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}060D5FFB8690-81BA-9054-AB4E-859E5FB0{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}DF278668935E-649A-A534-D69B-2A17418E{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6044A158CE64-F848-2914-201B-154A3ED8{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8E45A1F886B5-585B-3804-BD56-0B29908A{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3D6AA5234515-1448-8964-8DB1-346393E9{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2AB54A92AD0C-62E8-92B4-D674-97F65AC9{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E101B22A7D4E-806B-77E4-9B79-395FEB51{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}56B731BDA6E6-77DA-82C4-68FB-A53F058E{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5411C1CE083A-46FB-1484-0664-9C84AD7A{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}EA4E9B9DBC9B-811B-A514-D78D-8B45F079{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9627DB8068C6-9F7B-9784-B3F5-F94CFFF5{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}EAC411B50F5D-B1EA-46E4-21C1-544C70BF{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B367B024343F-21D8-68B4-4171-8580F4CB{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CF92DD5BF87F-A379-ADF4-4A89-53C40E51{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}70012292299E-264B-5D54-DEC1-A8C74182{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0C005336C3E4-EE69-D774-2B3D-ED7E1E3B{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AD93F899FECC-83CA-8974-DE5B-20D01106{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}BB0E0BDE8E0C-E4FA-F7E4-C0C7-A8A9A83C{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}11964B451515-374B-8034-A553-61217F29{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}191C5920A343-9E18-F6B4-C6BB-E8CF0A57{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}04AE619B6103-9338-34B4-C04F-0F50BEF2{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}95674AF2A128-1CBB-A2F4-2C5E-9D0C06CB{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}76E9CA3934B6-363B-E514-3E87-94EB658E{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2AE2F924B9E4-8919-0254-D17C-D761328E{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1724A55AB424-19FB-3CE4-B1F0-5A9D9462{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}873A35BDCCA3-D629-7624-0751-4D24ED7F{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B564AF444A2B-F5D8-2CE4-8E17-31F76060{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}EC399A75767A-0578-CF64-6147-89B6B644{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F25DC657869A-7A2A-28F4-7346-9EA47BCD{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D6D8B22FEE9C-EBDA-BCA4-4ED5-92B4E1FE{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3E05E973686B-A859-C754-02C1-121749FD{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}695F442B1756-4CA9-5994-56C3-E3259EE3{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6C91E51DBFA9-25B8-5234-CA31-7E7D3821{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}51CF2CC6B527-E819-72D4-CD4E-B36465E6{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CF851B71D6D8-7439-3DB4-62B4-75128545{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AA43835FE73C-179A-0984-CF28-B7B9C839{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}562D0DF807F6-723A-3B94-177E-A4FD653C{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}62073F5A586A-1008-0AD4-CE92-39A901CA{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CB5DF2CD60F2-E7BB-AD44-5AB7-9D3C46F6{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5AB136B56384-8318-3F74-D5FE-B3F7BA85{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}00BDB6DA9D31-8A7B-4F04-B185-9A1B6CD8{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F697EB3B19E2-02A8-46F4-7593-2134E7BD{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3B8EFC576DB3-B409-7BC4-6C21-440BAB2B{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4FDC65D00818-5578-5344-9151-936EFED4{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F475E16EDE07-96DA-64E4-3FFD-F9BFAEEF{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F50C96D65ACA-A29B-AE14-44BD-9CC6CEB5{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3AC4C2149A80-F818-CF94-D1DC-28C3124F{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}800784C1903D-48D8-8464-2A18-CCD43FEA{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}46846EBAA4E5-56DB-4D04-3A5C-D8185B46{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C737FD46779D-2CFB-92D4-82CE-21CD6A05{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}820E95628F86-131A-8314-FE2A-418E5B6A{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CFA34DA9C404-F59B-E354-8DCD-C7A8B88F{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B09B47DD292E-3F2B-AFD4-0DA0-7D9E78BC{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CADD99DA2DD5-24BA-7324-6C7E-AC407E2E{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D4AF2D1FB3FA-E6CA-5514-D5BD-7A4FFF60{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AA47F988AA47-D278-F9B4-65BF-E72056C0{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C14D6EA53691-371A-6544-C44C-02329B40{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AC9299358300-D94B-4B34-3983-A98B9153{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}BCB1FB0FF2D8-9429-6F84-6FCF-CA4E7219{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8185B9D2A60A-9EE8-D8F4-9AA7-5F6352B9{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D8842A665081-FC3B-C534-7832-D89E0447{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B78BA234B824-ACE8-A9E4-36DA-D1D6EFB9{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}36E4EEA431D5-7CEA-DC34-0828-4ECA54E1{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}249A4C57A099-2D1B-3764-ADE1-6CC5E68C{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C4BD08EBD858-5FCA-EBC4-0BD2-1E111A7A{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}73D56850584F-920B-C154-85F4-6987C7A1{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}67ED65BF2039-AB9B-DA14-5E96-224240BC{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1B8D845D6D5C-D67B-BA34-A5FA-07123E1D{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A4E04213EB72-5159-A8D4-F1BD-53C85794{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A2243747BA43-67DB-EDE4-53EE-2A468863{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4D4D675947E4-41CA-F184-9357-135AB69B{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}44DD8EE0A427-2F88-4F24-1D50-6A7652FE{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E0C7081288BE-ED3A-2B94-8EDD-1662D22E{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0546578974B0-956A-E754-D053-D318366D{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FA2EFA303BB2-B9DA-53C4-7A80-E51F5C56{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A834F16F2DFF-64E8-7964-9166-4AA1DD88{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6A62DCB35085-BF4B-0F44-A87D-3371E91C{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}90457D0935B5-70FA-5014-BDFF-984CC104{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0E387FD3F7E1-A09B-BB74-11CA-1E8EAEA2{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E9845FA86C20-135B-9DE4-F86C-DF1B50AD{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}266CE239586D-F579-66F4-297E-53199A2B{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}214A536ACC4E-AB8A-2004-BAFF-D7C4E19B{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9436047BD3E8-8DC8-2DA4-3A33-1F0B85B8{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B7D0D69020BC-E9BA-7F24-7A18-A9BBF44D{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3F96ACABB459-70DA-BEE4-0657-40FBA884{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AC0B56176B33-B459-4254-7465-B6250A9B{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4BE09454657B-0088-7BD4-8692-80194089{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}18B1B8B7D531-73EA-B994-2E54-9ABBCF92{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D8266FE4D093-98CB-FA24-B6EE-B07DDC90{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C5827BE3B20B-52BA-CF44-DAD5-BC442E27{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C77AF1721902-6768-EB84-53DA-4EF706DC{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AF6306B158EB-D69A-F9E4-81B1-735187D8{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4D36445BDD0B-1A3B-8494-4E91-8CF2C210{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1DCF703DD801-BCAB-3464-19C2-93980800{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CCA7CB585950-ACF9-1384-E867-B91BB82F{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6663371363D5-749A-25A4-E15B-43785004{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6AF67EB6E2A8-3F88-23C4-83C1-42724C56{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6BCE0ED074A3-BC89-0564-8FDE-DAD728D6{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D54DA645FC48-55CA-E174-3570-46CF1C24{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4ED58B504F63-B28B-F654-F1C4-86264FEF{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4092239A140D-3AD8-D824-6032-B771836C{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5F2E11BFFAB4-2B3A-AD64-1966-AC381340{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5F41037ED60E-A32A-3134-10F2-00DF26E8{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AEEBC8DFF2FB-BF7B-3D24-68B4-133BFB46{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}15762668C4B0-980A-B4F4-864F-D684EC23{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8AF59E764A46-EF59-CB94-AF68-5B65BD0A{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}78F55B43EC0A-085A-A404-A49E-98A95A72{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}047A43A92EEE-C619-C794-6F2C-5538786C{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C7DDCC0C7BB2-F058-9544-BF92-9C1427A2{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FB79E272F5D3-5C78-3DF4-D1FC-8749AA64{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2D961367F320-EA89-D894-FA3F-B0382ABC{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6A2F695A780C-04D9-5F84-0E36-3439835D{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C0D23FD6FF20-B4DB-0914-2942-730726C2{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E145B9CA2600-AA4A-F364-FB22-EB9D81D3{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}99BC347284F6-9DD9-3DE4-C39E-3546DD04{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CD8FFA811266-EB89-E7D4-3113-66075751{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7BBF36BACE50-582A-E054-CDD7-1485BABB{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D847A4910627-E779-67E4-AA76-FA44FBC6{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A8779D7C5C99-635A-6B54-482F-33BEAB38{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F42FAF28F92F-7CA8-1344-2361-DDA85102{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1F4142DA4913-580B-BE74-361B-523C6CDB{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FD6D4C0EEAEF-F3E9-79D4-C612-736B303F{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}386E2E643800-874B-3E14-C88A-C9ED4157{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}12FB46AC94DF-E9E8-6DF4-E965-D2C1A4EB{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B2F6FDECC795-864B-0584-7E02-DEB64EF5{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7E0F7D1CDF38-9668-5DE4-7D97-20929D09{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C2A756FC89CB-F9C8-A0C4-2FAA-D63D110B{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}53553956201E-71DA-5C74-8078-2512BA2A{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E7B76C21AC16-8BB9-9624-9A13-A7C1F9F5{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}55F147BC9824-3508-4B24-172B-4DC7144A{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C8D282037AC0-840A-9224-CDEC-742FCC16{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8BF77B209EEA-56EA-4D34-ABFD-5C7D9457{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FE85D00E09A0-3298-DFD4-7778-AB7F2CEE{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}254E08E69A84-A69A-69D4-BF9B-C1403288{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4A4F2927F998-65C9-C354-4301-2BE781E7{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D809D0B0A9CC-20B9-E884-54DF-4494164E{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7DC1087EFA14-3A08-D814-A264-09518099{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}85D2DE10CF1B-2469-A604-40CF-6E5E27A3{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}546ED91FA961-EB69-6004-414E-DD75765A{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}63760A58C930-1F8B-FCD4-E983-9937669E{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5330BDB10E6C-C1CB-1BF4-0BD9-2325FBC8{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3AF761738674-E46B-7D44-0E29-7F7F0D42{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6AAF172D5087-A8F9-6B64-5863-7F48ADE0{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0642EAEFC9F5-DDFA-DBE4-7818-E3B11E15{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}54282DCF1240-56F9-5194-F2F4-7859DA10{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2D46AFFF128D-7238-26F4-FADB-FB0387A7{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}DAEBBB01477E-282B-E594-7E0C-FD969A54{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5188986DC757-A30A-3E54-72F0-8406B4EF{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E60312DA3440-E61A-B8E4-59AF-1E9E2804{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}26A55C0F1C3E-D198-0444-619C-3D499383{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9A5BCBA43818-0F29-C394-803B-7A322525{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8963F2446B08-A288-0BF4-D939-55FEF765{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9A5305DFC253-EB09-DF74-5909-F98DCB5F{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0DDCB28DE224-ED88-78C4-0352-8511AB30{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}74008235662E-7E5A-0BF4-ABE2-40DE1ACA{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AE3DAAA90D1B-423B-95C4-90FC-00F257AB{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F36E1D58E03D-DC4A-CEF4-DB50-D957CFFC{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F1B38A27C08C-054B-AF74-9668-61357A99{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}193D8548FA84-5089-4384-133A-CB3A499D{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B8044D2759A9-C789-0D54-1F77-AAE4C036{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5F16312F4F39-F70B-F824-B9D1-CA52E8B4{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CBBCE61E3750-738B-AAB4-3DB1-32EF0BF1{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}748920B488CC-BC8B-01B4-0765-09D27606{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D4C2FE6D87D1-4A09-4EA4-D8DE-4D6C02F7{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B510BE4ABACC-D08A-6D64-DB06-EA806345{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9026CAB993B4-037A-A444-D1D3-140901FD{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F7557EF78EA3-E6EB-99F4-1D6C-45D3EAA5{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}876B60AC0A5F-9059-CD74-F218-9AA1818F{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2E2C32F925A5-86A9-DC44-131C-F78F9C00{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FF4876B9A7F6-E48A-8354-366A-5C2C3BBA{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}26FB592B151C-209A-E4B4-6208-ACD625E8{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6747CE777610-3A3A-4714-D61F-E9548914{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}912A042779A5-F43B-7284-9380-D533FCDC{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}026F5F06DC2D-10D8-3B34-1ED9-87338B45{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E1C7EC79A346-6A49-F374-585D-4D2FFE5A{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A6E35A855C04-7FCB-5744-6230-EAD79EBA{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E8EB16B7B9B1-CC99-B5C4-389A-18EF7954{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B5C0591DAAD9-2A9B-8874-35F8-C04C592C{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D74344A3B259-8E0A-3E84-3EE5-ABB2813D{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0333FDB2D8E9-725A-26F4-076F-130A5BA8{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}37AC3FFEF134-C3FA-9284-7815-38C3372B{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D9AD5A3D6788-591B-4F84-B3C4-E46B36F4{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}81223E494599-8C3A-35B4-D440-DDD3A803{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0DFB70F9B48D-F32B-4AE4-5B26-0E23FF28{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}BAB57E34D2CC-70C8-A4D4-9125-0FB2F8BC{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}53C5498848A7-919A-A314-1AA0-46E68271{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}17536E74F782-CCA8-27C4-ED1C-D040D4FE{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7A2651456471-4618-6B04-B471-6D31071D{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}161040C999A2-254A-75A4-C4AA-D990A445{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5503F8AB5C45-432B-CA04-268C-F074D743{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3535F2BF6BEC-67C9-4E44-033C-A07FA9E4{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7DE22F3BF481-1639-4B84-6787-E8D3DA38{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3B50F7FF17C4-E3AB-EB54-4EFD-1D117B2D{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C81C16B518EB-499B-0C14-B9CF-8B76F379{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}798CC0EBFB12-6CFA-D814-2D0E-9FBD16B7{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}76C1280A3551-D109-2684-C82B-F91765AD{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}26F7042A1D0B-DCBA-B034-81D3-3FA05A76{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D025E9AC4007-0A48-7654-122C-2F1401FB{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5185085A7ABD-0468-8E74-CFEB-912C3E32{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8711A1A0F573-CE29-9EC4-A585-70328286{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F73AC5E0B7D7-4659-4F94-7E71-E01E090B{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FF0C447989C8-FCF8-E694-92C8-F2166D7F{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}23148507F5A9-08F8-0C24-89FA-69E21A40{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FEF0EA2CD727-2F18-C2C4-9B69-23585866{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9D687F362E07-F1F8-8164-8F1F-19DC0DF6{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}837FAD674362-E799-9314-A0D4-59DBE973{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AB3BDA915671-8308-9E84-73D3-6CEFDBBB{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}07ED524F25D0-E508-E534-C57D-37BA8A60{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F347FF4AB444-1C9B-F9E4-6561-8CD837F2{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B85497975358-498A-BB94-1130-E0C8EC80{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}EFAB48F082EB-A82B-19F4-9FA2-9454CF26{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8D731E840783-1869-3404-758C-2246FDE1{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B7D72A15ECFF-4C38-C854-E023-0C22DE1E{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A34CA045D34E-E0DA-5734-2E73-FB4AB7FD{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}168A4C5E36AE-7889-8654-D64A-980077AF{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9FC77D5EE46A-2039-9F54-CBC2-E56249BE{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}687954C6BD21-87F9-8CA4-34FE-982D5C26{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7CE04EEA2AD5-A26A-E494-4993-0B94C86E{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2B8DA059D672-7B3A-3054-9C27-712A2FBC{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}57B86CBB97E1-C7C9-BE24-ABE2-49A74BFF{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}12F21F7BCE3D-1BA8-0B44-A0A5-4CEF6268{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3A91CCD0EE5E-A0A8-74F4-F64D-ABD04061{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D746606C19EB-7B6B-8E04-D258-48FD5049{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}792BA7ACEACD-551B-0224-A401-BC580888{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}441914B7626B-98AA-5034-2F2A-297FB682{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C06A419A79E6-0ADA-A924-8762-9D97A3D0{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E3C01D1638B5-4BAA-5F84-095A-2761CFAB{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}EBBF5F596B92-0B4B-DEC4-48E5-C524F434{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}942B7CD28335-4D8A-9FE4-9523-D45AEDD7{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CFAC0E0CFE57-A5AA-8104-EEDA-06036A09{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D7B3331EA151-D3A9-CCD4-BA92-11206E7F{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}445C54D0EF0F-E7DB-5C24-E9E4-2A372CA8{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}408523C4FDE4-A4EA-1784-5994-C4D4FEA7{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}89A6B89C59D3-CA7A-2F54-D14D-6D10219E{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CCD506B00AF6-A248-A324-74D3-C9FFDCE3{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1A510125E588-2C7A-B1E4-A999-378F0B6E{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8E67778504D2-2E4B-7204-2392-8670876C{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}32460FA47B9B-8619-49D4-A93B-019A8073{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}ED53D55D0DF4-865B-4C74-6AE7-5EB5EE1B{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E7F5F9C0F27A-9D18-9D54-F6C3-8B649D9D{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C2C8C96C3CC6-3EE8-6FC4-35AA-E2033E1A{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3BC1AADDDF10-E91A-7D84-DF87-6D18503B{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4367CB54133C-8FA8-5F14-0C17-39531941{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}72A0490E2239-2D58-59F4-5F3F-8988D439{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}165B452723B4-00B9-DD94-FB38-29A0332A{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B5D5F4B0D369-99B9-FF74-59CC-10047B25{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5B8B45424768-3078-12F4-3C58-EA4E8870{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AAE063E8AACC-C48A-6EA4-3364-2F4CCC90{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}75A4D99C37D0-2FCA-D284-A738-7F6FE5F9{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}59C2A5AFD14E-9F89-3D94-DD4E-428AAD97{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}13B64FF4443E-423B-5E94-797D-DC8E1E5F{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B127FCA48E7C-785A-E5D4-175B-7C4F3104{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3EDFA8A253E9-396A-6554-FEED-06FFC7AB{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}83CED9963CBD-9909-FCC4-3574-5353A079{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B069386B8559-B1DB-FB34-3F75-84E60971{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4486F2B6B255-B22A-A324-66D4-AAE3CE7F{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CADF8F4A7B69-6F68-9944-75DC-F6D32EDD{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}00F29DDBAB7F-526A-FE24-595B-A1F15610{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}92400113D731-0E59-FF64-FF2C-692D7F6D{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}32568AA00687-CFEA-A474-9876-CBDD91E5{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5D7247B96AC5-B048-8584-B4B3-BB3E5585{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CCBA5D620E15-B679-A784-4833-9B66AA12{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}08EE2654AC81-1588-74E4-16F6-A5454849{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C4DD46E3C252-9F58-6834-58D9-E926D86F{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FA319C442BBC-4FD9-EB54-3ABC-DB2CCD14{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D8F0F4FF0519-50E8-4F84-08FA-F009998C{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1C2F31C2A9BC-6868-EB44-2C60-D4B2CABE{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}87C98C2EA0B5-02E8-B594-B3C0-630ED02F{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6D8DA3E06DC1-7BBB-6ED4-986E-ED221B42{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0CCF33262C70-6E98-0854-2122-EE0B163D{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4D34FC5EDF70-25D8-3F24-2AE5-7304B7C1{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}031DB5071CF1-5538-C384-1D96-CC4050C3{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}665FADB3725B-8239-C8F4-E1F7-E922708E{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}74F36F78EE96-DDD8-D2D4-CDBE-A99CFEA2{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C93C14114CE9-758A-8FB4-460C-15B8F1D4{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4A14173457FF-0C98-1DB4-FD25-0E7B15F8{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B6075FC7900A-55B9-4134-A562-D22F783A{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}ED5C16221CBC-92E8-5AE4-80B1-D455BDAB{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}ADC7EEF123FE-E2C8-03C4-A93B-1D5628E2{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E1D6468D7688-990B-4364-4449-7721CA03{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6B6E40AB14C2-4F3A-33E4-2692-07254673{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}DCA4CFCC0CBF-350B-08F4-AE3C-9C8DC26C{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}85990F4BE45A-5B18-5004-6BCA-C90028F4{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1DC034C3BD08-06D8-F2A4-EB44-99E6E4AA{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0142B3FDC436-42CB-F924-B243-1A42F63C{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B7B8369D9622-7B5A-F1F4-B602-65C2A130{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9AD9856C612B-A3D9-B064-E47D-B37290CB{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}164DE0F8C37F-E4BB-3254-5312-59FCF296{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8D2572432661-635A-B024-9464-0680728F{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8E30EA337351-4CC9-8194-31B7-DD2782D6{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FE23339DD0E8-A48B-7BD4-EB1A-36731D2E{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}292E4A6A44FC-8A6A-C934-D867-57B50349{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D2517206282D-687B-9CC4-A936-0EFD5BD0{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}882EBD8F74C4-132B-1C14-CE05-DCF11109{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}15EA63D8E537-7DBB-B2D4-1BDF-E9DA9435{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A7D34FD872C7-A4CA-FBF4-7ACA-1BE36F84{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}585F43FAF743-FEAA-4F84-5689-7C3131AB{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AFF1CEF8E835-D0C8-16B4-D1A4-6DD28ACE{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5DE43DC7309E-5FD9-0B64-F6E2-924062F3{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B03E52ABFD54-CC5B-BB54-F965-97C82EFB{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}15074A555CA3-A7DA-C1E4-97B0-67AC969F{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7D2BD4BE6C7E-7168-8DE4-BA6A-884E50F9{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}93750BC50149-493A-E574-C579-DACF820D{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}03FEC0B2A6C5-A1E8-E944-34B7-64292EA3{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}02CE37596676-8CF9-5704-62B4-86779B0F{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}DEBB01F15068-8518-5424-3E71-41A0B593{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6FBB58D026F0-E7B8-46C4-A9A8-F11F9F50{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}119B8E1B42D6-5A48-1A64-B044-9B8ECE93{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B17B89AFC14B-2319-CDD4-5C6A-0ADAADCF{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}BB35B30BE18A-354A-FCF4-0928-E08D8B4C{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7639A6F9B74A-022B-B9A4-4360-FADBBCEF{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AFC2E3093A07-BB9B-47C4-8114-6BD82CE3{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CDB0ED23FC9B-6959-15C4-5FA9-894EC8CB{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2A9D4B5AD5A5-1009-6814-2057-F8FE33DF{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2D1E2E4C5D35-619A-FF44-A022-0E51E41B{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}89ACC84702E4-D5CB-2584-1B97-A47B514F{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E61C15080E0D-0C89-3794-A0B3-339135EB{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B697291C835E-F208-9BE4-8EF7-6E8D57DC{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C2C0C25E1322-44B9-6C54-1760-8043CC72{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C5AB2A337E88-624B-03F4-296E-99494B05{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}BE3675E1A449-86DA-FBD4-08C1-A2551DBB{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}46B0E0801EB0-15BA-CCB4-CE07-F415BDC1{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A78518A2668D-DFA9-DAA4-FACA-855D8BD9{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}18C55F06CC79-94CA-82B4-ABD5-E539A5B1{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FFB5755F6F8E-DEBB-4594-6563-33111F28{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5B69FC86BC63-A22A-6F34-4D79-6F5C9DC3{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}99777C91ED29-505A-9384-4CFC-44D488C5{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8C5B4EF4384E-2419-9D74-F1AF-4A8DDA7E{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1B00275E0BB0-2EEB-00E4-2572-1BA2D339{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5CBA6239E46E-7B4A-6114-E0D9-FF50B396{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}53DB547670CA-F209-25D4-B5DD-D96BF52F{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7B555F4F7795-CA59-F804-03C2-73303D8B{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}451166ED30DA-A3A8-6504-95A3-16A770CB{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7733E5D53433-E998-33C4-D308-7EB15357{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2DE4B7DE7F70-CAAB-2ED4-75CC-7368D920{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AD65A7147A5B-AAC8-31F4-111B-68B35F32{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2EAB80BFAC78-1A48-C0B4-F7FA-F147F445{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}60CBE751E659-1C5B-7164-F105-C57379D8{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3EFDFA42A3DC-1CAA-0664-BDB2-F4EA5BAE{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C7536715D03F-A278-92E4-2E41-C2FDF0F3{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B15E1A33BE06-D189-8FB4-67EE-F815BB7F{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}809FBB1E32A6-C8C8-40E4-4D59-F7F6F782{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}72924BED308E-BEDB-DAA4-2FE7-52F13A9E{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9A5C763FBA4B-953A-5E24-B944-914E3CA1{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6F56ED579002-A4D8-7F14-8104-E755705C{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4B30E64087EE-55DA-A714-8E1B-E5658B0E{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E237A0E87287-5429-8CB4-D644-746DA494{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9F62FDAB2999-5029-65E4-61F8-08FF00C9{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}54A789588D89-1ECB-1524-9A91-FBE2E029{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}041161357D45-7E0A-F774-FEA5-61113948{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7B8F389875E5-EC0B-3EE4-5081-666398D7{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E3BBD397290E-5E78-C904-74E5-C0771B4D{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}32211A73E62D-85CA-74F4-4482-A3113967{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}805A356B9B20-B5E9-C9D4-3AFC-2D078FCE{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}97944C125273-D5BA-3474-609C-73A2150E{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FFF1AB0807F3-C8AB-1034-5FA4-52DF9EFA{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}656B33C38E60-D5B9-ED74-389E-15368177{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}EEAD4C97C077-647A-A4A4-9E48-0D413C9C{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4B1ACA695F7E-6C08-DBB4-83CC-6C9C5E65{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3757D1F8D445-A7AA-6304-2880-7969EA5A{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F5C7A4C9B6C1-AC4B-E724-2AB4-8FFA57FC{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F9B978777031-9319-E7E4-2EE6-5A833E13{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C7FEFED99526-4B78-E534-2822-3E549EC5{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}631585E640C1-1B9B-DB24-B09C-865E4BF9{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5E8BB1253D0F-0129-22B4-CBE0-E7DBC525{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FE386212162C-A60B-6C34-8249-107345EC{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2C564C90C823-5749-F784-3CB4-CC435D4C{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6C7F1C667FCF-53F8-3E24-2F06-D4A9CE7C{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}387DD5C30B3E-A878-9B74-05FE-EE76949E{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3F00B2C83E85-E37A-F624-191B-4DAB411F{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B248BCC2431C-E449-9104-1966-1FE235CC{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}619571ADC0B4-D10B-5514-2D02-426305B8{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}727ABCE7EF2D-198B-58E4-DB1B-3F67FAAA{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CA5B10070D92-A3CB-8B14-C86E-6A19B392{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6056B44547BA-A6C9-A964-85F6-13A44CAF{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A3B8974DC3B4-1DFA-9C14-30B0-4266768D{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}45FCED12ADD0-61A8-C244-8D1D-11C145A7{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5FF45A4A9618-2899-CC04-F9EF-159C78E8{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2A45DF5179BE-3078-E6A4-A2CC-88F775A6{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F241CCAE9315-99BB-2384-7696-6013F2A1{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}112F92363787-C7A9-9914-ACE7-EB452EF0{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}BA9FEDED74DE-D12A-91F4-BA32-67D40617{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5C719562D9E1-74E8-62E4-7AFF-1D7C4362{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F11937B75C60-B899-AA24-6BB2-ECF0B168{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}65E00D67D9C4-AD58-0694-95B8-727DEFDD{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1ED31140F5FC-A01A-4574-D624-7B49908D{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}DAE668D74B5B-B60A-CC34-386B-9C9B2993{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}442A97A9
KEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}DAE668D74B5B-B60A-CC34-386B-9C9B2993{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}442A97A93CB1-0ABA-B624-DE6D-84B2F37A{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}ED0D07A86FFB-3A2A-BDD4-E153-220657F0{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}BC1CDE6733F3-A73B-D854-9CF9-F39DCE11{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B146B0AB279F-BEC9-AD04-A5FF-E3CA677B{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A6A5D6AD4694-3309-F2B4-C71A-AD229068{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}24524BC7FF43-668B-6254-4533-21D23355{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6F799F84025F-6C88-35E4-95FB-E3F2BDC6{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9E7AD822D8A6-9CF8-75B4-F35A-676A7ED8{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2418EDC5F470-9319-7B74-AA8A-7DA56DD4{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6BDBFA0076C5-C0DA-EB54-A85A-EE0F8845{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7C6E6859357A-4BBA-3CB4-159C-F67160C6{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}801D6ADAD57C-EE39-ECE4-E235-A7DF036D{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}887C8BD07951-4329-9A14-7941-2E6AD69F{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}DB9D9C2BC03A-9149-CCB4-E882-B6F03B96{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FAA304BCC448-CB4A-2884-DB50-7D824573{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}30E1EC8847C4-3C2A-89F4-5ED1-4C8A8C6F{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FC36DDE0454A-E8D8-16F4-98AC-FB2B93A5{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E8B0C1491401-33D8-5574-8165-4A98E009{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}05D1C443EC89-010A-4424-FE35-B3372520{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F3F3B1683A18-7A98-9B34-7F50-F6D2B00D{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}775EEF287AE1-D859-C974-F9DD-A92B7B75{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}49E3CAFAD3B1-A23B-99B4-3817-474E3083{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9FC834E94A34-9FC9-3724-3D14-1E7ADD9D{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E446359D0556-015B-5F24-6154-2A72559A{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}623944040D89-6C48-29D4-B2E9-8E78384C{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E96F61CA5CA3-8BD8-7C74-30D7-9361437B{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6CC5D95062F5-814A-9354-D401-60B56C57{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\kaimd HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}89BA9B0B234D-D0AB-EA24-6D5D-F6A1FC0E{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7E09DFB8FA97-6AE9-11E4-316B-2C3A32CC{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C2147D04E385-D5BA-0DD4-396C-A5423F49{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CEBB276A9908-CDEA-F344-2346-4DC2D5C8{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4A3EE4D13B72-A73A-0C04-C6AB-1055A134{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}74596FB2A29E-5E79-9D74-D1F0-93A47EE7{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E9D3E7E92D62-18F9-7B34-99FC-5CCD725E{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9CCD1841E92C-4AE8-33A4-0FFF-8981D9C7{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}970402C4C64C-5F39-1994-75EE-40698384{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E792EC87DAD8-1FF8-2614-2B70-F8278736{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3A95E90BC22B-E94A-B7B4-4930-DE9775FA{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}05C1B82DF7C1-DC48-3DE4-086B-2E0DDC8F{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F519E01DBBC0-4DA8-7264-F10F-EF30B4EA{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}869CD863DB16-8FF8-BA34-EC73-168927FA{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3BD44AEF4116-E2F8-6D34-9E34-5F56F175{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4D335078403E-B159-CA54-B93D-9F0A3EBA{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}24D92F0EA389-7E4B-3B44-A303-F5143C4E{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}531A5E9D1FAE-1318-4914-3809-CE8029AB{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9992E73C1FB8-40AA-DA24-67A4-7ADAB37F{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CC69B8DA291B-5A48-95E4-171D-28FAB179{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D2C1283F89E1-C78A-1A84-C578-016FB340{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}EDF9D7EEB9AF-B728-B614-777D-22F18642{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0103E4232532-B3B8-7E74-73E6-2F6C7876{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}909E6306A3FB-8F38-71D4-8E2E-5DFF888A{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E72A81D9F304-AB69-E024-6FC3-4DD91C74{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6AF430CDCF6C-4769-A354-A816-4B88F0F3{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C7727C77963C-1149-3074-16BE-C219F9B8{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D46599339A67-E7DA-23E4-207D-F091A1C8{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0D339A34E468-8C5A-6F64-36CD-6C1E977B{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A8473FCFDB5F-C3F8-8304-FE97-9934DBFA{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}BB02BE18AEE4-55AA-1E34-A48A-1774FDF5{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}94E0844C4CEF-963B-E7E4-C17B-6B8FB94B{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}72FF70226E81-D248-E604-C3D7-DF1BA41B{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2DD9BE08A868-C2EB-C6D4-070C-2AC243F5{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B26AA8145A2C-448A-D384-A517-A693396C{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CDEF0204D2ED-2148-AFE4-BB7E-14030C84{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7EFB0BE33034-B318-A614-6373-AB55C94E{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}67674DC8AFA4-E46B-43C4-17B1-B6A456D6{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AC069B89A82E-413A-DC44-3C8F-DC038192{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}02A8E45E5D02-EDBA-8C84-72F3-2E778F7E{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9097A9CF501C-BAEB-11A4-7D55-AB0E6A6F{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}796E269FD800-94D8-C754-6722-BAEEA8EB{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B370215FA242-07FA-FAB4-0EEA-3C8C7242{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}04031148C746-E999-B544-1B3F-E943706C{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3EE2CB796F1E-146B-2364-72B4-514C2DB6{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6D29A940CC09-20FA-FB74-243E-F3E65C44{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}41B4FEEB0A8B-CB08-E314-CE6E-5A167D4A{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}62870C37FE0C-E0DB-2E94-5270-F70C4113{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0B58FB9F46EB-FBCA-2FC4-55AE-CBFCD9A0{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}26F74BD0C257-BA6B-5614-D7B9-68F47967{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B19C1318E597-0EDA-3AC4-AB5C-F766D122{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4342F4E4826F-6219-6DF4-FEAA-996BD917{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1FBB06A60422-6A88-7EE4-B586-CC0CA73D{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}05E9A5DBF9C6-8BBB-1EA4-4F73-23839A8F{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}02108B244F09-C6CB-CF34-6C06-C21E6C4A{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D3ED9BDE6466-A689-99A4-0BC7-2BE8CC87{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}65775B1BAE1A-3C5A-9ED4-D719-779E8176{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3975894B5B1A-35EA-0A54-401C-008F7834{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1E386BD2BEF5-3D19-FD24-E3B8-2E63293A{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}ECD1D8318DC5-2968-AFF4-B872-7D5FCE1A{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B34C1F5AA688-672A-FC34-A257-505921DC{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8DB6A0EB9FB9-D1FB-2FF4-450E-5C923C56{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5F833B38C535-48F8-1184-70A0-C32527FD{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}DC2C383B37E9-EADB-EA24-6F17-2B8B3063{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}92F68C17167C-7609-D144-7860-2CC9B147{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}930BD5E51E58-D8CB-05D4-B241-A6B15F95{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}34A6ADF0A1D5-3CA9-A474-9B78-890AD165{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1177E168FFDE-06A9-1264-2A5F-9E33E3A3{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4FF45667BCEE-429B-12C4-BA04-82FC618F{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7EB516C9B88F-14DB-CFA4-528D-223D7322{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F95D04FE4497-4509-B434-4E5C-C878CBF2{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}71508F098CB2-F458-A484-9500-9A2FE495{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C22015A3C816-2278-0354-BAD1-47D74A10{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F880BA27E52D-2148-E0B4-FB89-8F7B01C4{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4B783EDD8AC0-055B-9DB4-99E6-B92CAC91{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FBD6BF1D5CF4-6F19-6354-3F91-E4BCD405{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}619B62361BAD-46CB-14D4-3824-EB356540{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}503502E53DAD-0629-A094-19E3-52D9186B{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}610E640A5830-DAA8-9674-C640-2D150AA0{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}83C44EDF153D-03EB-1DF4-1C61-FB6D3591{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}37C99A5DF5E1-3139-8E84-7C00-4F60E859{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}32F0B057A9FB-07EB-9A84-7146-E6394CFE{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}56A6464BA2C7-8D08-F9B4-343B-F46662AD{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1831FE83A5D9-9168-5C04-547F-DCD7CCE2{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}385B2D079FA1-B499-FC14-1A16-070DDA83{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8F4C8D3323A7-4D38-5F04-B3D4-73AAAC9D{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1D6CE406F079-59EA-9564-0212-5B73E390{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B64949146DD1-9D6B-0394-7EB4-2A58FA53{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0A739EB854AD-1718-2204-545E-07919BFB{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9D043A57D66B-5739-30E4-AE58-1E16429C{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9A6ACB5A75B9-2EB9-D264-B4A3-63DE5D6C{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1AFDF0734683-6DCA-6A64-A18B-9D4582CE{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D98AFD05A427-5278-C194-05FD-58BDDD95{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}485EAB6529B1-5AB9-8734-C3C3-8B029B9B{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\swen HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\ogol HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\llun HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\eerht HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\evif HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\ypszr HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\putesprpgd HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\onisacputes … Microsoft ® Windows Script Host Version 5.6 Random Runs removed from HKLM "dmiak.exe"=- … PLEASE NOTE, There WILL be LEGIT FILES LISTED. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE. Example ipsec6.exe is legitimate »»»»» Search by size and names… * csr.exe C:\WINDOWS\System32\CSBDY.EXE »»»»» Misc files »»»»» Checking for older varients covered by the Rem3 tool »»»»» Search five digit cs, dm and jb files This WILL/CAN also list Legit Files, Submit them at Virustotal C:\WINDOWS\SYSTEM32\CSBDY.EXE 51,276 2006-08-01 Other suspects Directory of C:\WINDOWS\system32 {BFB91970-E545-4022-8171-DA458BE937A0}.exe {35AF85A2-4BE7-4930-B6D9-1DD64194946B}.exe {093E37B5-2120-4659-AE95-970F604EC6D1}.exe {D9CAAA37-4D3B-40F5-83D4-7A3233D8C4F8}.exe {2FBC878C-C5E4-434B-9054-7944EF40D59F}.exe {0A9DCFBC-EA55-4CF2-ACBF-BE64F9BF85B0}.exe {6BD2C415-4B27-4632-B641-E1F697BC2EE3}.exe {2427C8C3-AEE0-4BAF-AF70-242AF512073B}.exe {BE8AEEAB-2276-457C-8D49-008DF962E697}.exe {F6A6E0BA-55D7-4A11-BEAB-C105FC9A7909}.exe {291830CD-F8C3-44CD-A314-E28A98B960CA}.exe {AFBD4399-79EF-4038-8F3C-F5BDFCF3748A}.exe {48389604-EE57-4991-93F5-C46C4C204079}.exe {9DC338A2-127F-4632-A149-DB11907FC3AD}.exe {8C5D2CD4-6432-443F-AEDC-8099A672BBEC}.exe {CC23A3C2-B613-4E11-9EA6-79AF8BFD90E7}.exe {B7341639-7D03-47C7-8DB8-3AC5AC16F69E}.exe {C48387E8-9E2B-4D92-84C6-98D040449326}.exe {A95527A2-4516-42F5-B510-6550D953644E}.exe {8DE7A676-A53F-4B57-8FC9-6A8D228DA7E9}.exe {0F756022-351E-4DDB-A2A3-BFF68A70D0DE}.exe {693B05FF-9D0E-4116-A4B7-E64E9326ABC5}.exe {533F8BF9-1C69-4E75-A3FD-B0D751B0AE8B}.exe {9DB8D558-ACAF-4AAD-9AFD-D8662A81587A}.exe {BBD1552A-1C80-4DBF-AD68-944A1E5763EB}.exe {50B49499-E692-4F30-B426-88E733A2BA5C}.exe {27CC3408-0671-45C6-9B44-2231E52C0C2C}.exe {FECBBDAF-0634-4A9B-B220-A47B9F6A9367}.exe {F0B97768-4B26-4075-9FC8-67669573EC20}.exe {30AC1277-9444-4634-B099-8867D8646D1E}.exe {2E8265D1-B39A-4C30-8C2E-EF321FEE7CDA}.exe {BADB554D-1B08-4EA5-8E29-CBC12261C5DE}.exe {A387F22D-265A-4314-9B55-A0097CF5706B}.exe {8F51B7E0-52DF-4BD1-89C0-FF75437141A4}.exe {4D1F8B51-C064-4BF8-A857-9EC41141C39C}.exe {E807229E-7F1E-4F8C-9328-B5273BDAF566}.exe {79DAA824-E4DD-49D3-98F9-E41DFA5A2C95}.exe {9F5EF6F7-837A-482D-ACF2-0D73C99D4A57}.exe {09CCC4F2-4633-4AE6-A84C-CCAA8E360EAA}.exe {0788E4AE-85C3-4F21-8703-86742454B8B5}.exe {52B74001-CC95-47FF-9B99-963D0B4F5D5B}.exe {A2330A92-83BF-49DD-9B00-4B327254B561}.exe {934D8898-F3F5-4F95-85D2-9322E0940A27}.exe {14913593-71C0-41F5-8AF8-C33145BC7634}.exe {B30581D6-78FD-48D7-A19E-01FDDDAA1CB3}.exe {A1E3302E-AA53-4CF6-8EE3-6CC3C69C8C2C}.exe {D9D946B8-3C6F-45D9-81D9-A72F0C9F5F7E}.exe {B1EE5BE5-7EA6-47C4-B568-4FD0D55D35DE}.exe {3708A910-B39A-4D94-9168-B9B74AF06423}.exe {C6780768-2932-4027-B4E2-2D40587776E8}.exe {E6B0F873-999A-4E1B-A7C2-885E521015A1}.exe {3ECDFF9C-3D47-423A-842A-6FA00B605DCC}.exe {E91201D6-D41D-45F2-A7AC-3D95C98B6A98}.exe {7AEF4D4C-4995-4871-AE4A-4EDF4C325804}.exe {8AC273A2-4E9E-42C5-BD7E-F0FE0D45C544}.exe {F7E60211-29AB-4DCC-9A3D-151AE1333B7D}.exe {90A63060-ADEE-4018-AA5A-75EFC0E0CAFC}.exe {7DDEA54D-3259-4EF9-A8D4-53382DC7B249}.exe {434F425C-5E84-4CED-B4B0-29B695F5FBBE}.exe {BAFC1672-A590-48F5-AAB4-5B8361D10C3E}.exe {0D3A79D9-2678-429A-ADA0-6E97A914A60C}.exe {286BF792-A2F2-4305-AA89-B6267B419144}.exe {888085CB-104A-4220-B155-DCAECA7AB297}.exe {FFB47A94-2EBA-42EB-9C7C-1E79BBC68B75}.exe {ABE97DAE-0326-4475-BCF7-40C558A53E6A}.exe {DF109041-3D1D-444A-A730-4B399BAC6209}.exe {543608AE-60BD-46D6-A80D-CCABA4EB015B}.exe {8CBF5232-9DB0-4FB1-BC1C-C6E01BDB0335}.exe {E9667399-389E-4DCF-B8F1-039C85A06736}.exe {A56757DD-E414-4006-96BE-169AF19DE645}.exe {CBA2830B-F3AF-498D-98AE-023F763169D2}.exe {46AA9478-CF1D-4FD3-87C5-3D5F272E97BF}.exe {2A7241C9-29FB-4459-850F-2BB7C0CCDD7C}.exe {29FCBBA9-45E2-499B-AE37-135D7B8B1B81}.exe {B2A99135-E792-4F66-975F-D685932EC662}.exe {C19E1733-D78A-44F0-B4FB-58053BCD26A6}.exe {88DD1AA4-6619-4697-8E46-FFD2F61F438A}.exe {65C5F15E-08A7-4C35-AD9B-2BB303AFE2AF}.exe {D663813D-350D-457E-A659-0B4798756450}.exe {E22D2661-DDE8-49B2-A3DE-EB8821807C0E}.exe {EF2567A6-05D1-42F4-88F2-724A0EE8DD44}.exe {B96BA531-7539-481F-AC14-4E749576D4D4}.exe {368864A2-EE35-4EDE-BD76-34AB7473422A}.exe {49758C35-DB1F-4D8A-9515-27BE31240E4A}.exe {D1E32170-AF5A-43AB-B76D-C5D6D548D8B1}.exe {CB042422-69E5-41AD-B9BA-9302FB56DE76}.exe {1A7C7896-4F58-451C-B029-F48505865D37}.exe {A7A111E1-2DB0-4CBE-ACF5-858DBE80DB4C}.exe {C86E5CC6-1EDA-4673-B1D2-990A75C4A942}.exe {1E45ACE4-8280-43CD-AEC7-5D134AEE4E63}.exe {DCB74AE9-6437-4F82-A2A7-A968756CD52F}.exe {BC60C0D9-E5C2-4F2A-BBC1-821A2FA47659}.exe {2FEB05F0-F40C-4B43-8339-3016B916EA40}.exe {75A0FC8E-BB6C-4B6F-81E9-343A0295C191}.exe {BC4F0858-1714-4B86-8D12-F343420B763B}.exe {970F54B8-D87D-415A-B118-B9CBD9B9E4AE}.exe {15BEF593-97B9-4E77-B608-E4D7A22B101E}.exe {9CA56F79-476D-4B29-8E26-C0DA29A45BA2}.exe {A80992B0-65DB-4083-B585-5B688F1A54E8}.exe {8DE3A451-B102-4192-848F-46EC851A4406}.exe {0BF5E958-E4BA-4509-AB18-0968BFF5D060}.exe {29CDC5DB-D1B5-4D8A-AE88-653D3A358089}.exe {4C6950EE-F07F-4AD9-B3A1-1F415A21C43E}.exe {F4111E63-7330-408D-A60C-30B1C6CABDA6}.exe {4DDD94A5-C409-4BF3-B133-DF5776D24B62}.exe {4F5240EF-846D-446B-A484-863A0E3C888F}.exe {DE383212-B62A-4B85-901C-26C8D34773D1}.exe {49AE207D-6CB5-47B6-B594-346181155AC7}.exe {74E2026D-1303-4CCA-9142-9224E072B47E}.exe {589AACA9-B9A8-4122-AD3C-48C4D17860B4}.exe {2959561E-6AF6-4F89-BF0E-D5C0F65C01E5}.exe {9EBCD422-0229-4AB0-9A4F-D111C0359491}.exe {F4075C8F-854F-4571-926E-42F9AD348DAA}.exe {4C67DC6D-247F-4E2F-869D-F2DAAB007859}.exe {8F16FFD8-C218-461D-A1D3-5800CA50D3D3}.exe {CEEC1808-8FF1-49CA-AEF3-C17F02CF7ADC}.exe {F206C26A-8C92-46D2-8B7D-EF481B10DD26}.exe {EA3407AC-3C30-4B48-9C7A-4CB212C42203}.exe {7B962EFE-6DF4-42E6-BC92-A3F6B21001D1}.exe {B8CDAD4F-0B68-414B-9F47-2455D6E2C6DA}.exe {CA54A3A6-E86F-4815-9E76-5BB0C96AF331}.exe {47F98B46-A8B2-4CDA-9002-4131CDF05486}.exe {564BF6A8-27B6-442F-8E48-1650A69BD9CF}.exe {685F36D3-199A-4FDD-A774-237985A2768F}.exe {02EAA8BB-E98B-47E7-A29E-494CD3E5AD14}.exe {0BF5A77A-CFEA-4C47-AEEC-2F295C5B5437}.exe {F5563278-587C-4A75-932A-3C1D1DA77602}.exe {0C87E5A9-E7FB-49E4-AB06-C6150185E926}.exe {6AE20C20-2BF9-47B3-A68C-8E68C2EF061B}.exe {53749F55-6130-4307-A24A-4B887F61B1E0}.exe {A9FCF1BA-E03C-4BC5-8558-504475820515}.exe {A28129A9-9EFB-4258-903D-0A45D6EE69D7}.exe {61C126AF-C45B-4EAE-B905-C4A07B12E1CE}.exe {C005E709-03FD-48C4-9456-D100481A4203}.exe {59A563E1-3814-44B7-8EEB-833E553660C3}.exe {4E312A76-BEB8-45E8-BE69-565426863F78}.exe {12E616AE-72F6-4CF8-A063-37BE1701ADDE}.exe {4A912E69-8BFF-481D-B11C-091DEE24E176}.exe {D83B282F-E38F-4203-9A22-6B0457C63862}.exe {05AC4E82-2BCC-4641-A3F5-1272FBF74830}.exe {7EEF7CF2-02D7-4B73-BA08-5E6E0DC6AA72}.exe {D8E658AB-2EDA-4B46-B67F-56B833C97602}.exe {2A0AC980-DB47-440F-84F3-B6311F965A68}.exe {487044A3-20DB-4265-A92A-4809B1478D2D}.exe {B54C6DCD-0A13-449A-9E5E-DC22DCADF46F}.exe {CFD4AD70-680C-4A98-999E-464F3D5242F0}.exe {FE54C698-F6F2-4B54-B759-9353910DDA82}.exe {C0B07F8C-4B7B-4421-A2E4-50DB28B1D305}.exe {1D2F0503-A241-4011-8C29-61FC9404125B}.exe {ED9B7B59-0BCB-4F53-B415-34D9342577CD}.exe {596D586F-4722-418D-A075-622BE10C550B}.exe {9D4B2060-2C19-4C6D-A656-1CC4430D9F04}.exe {361CBE81-1B89-4E3B-8ABD-B03CA0E56D3C}.exe {0A5112D7-5781-4EE5-B5BE-15408DD16751}.exe {9B28A884-EAEA-462F-95C5-44BDA820D5A2}.exe {3F8095AE-4435-4A8B-A25D-49DCD4D7DA79}.exe {E1AFCCC9-EC6E-49F2-9B13-524BC7350FD2}.exe {B298C134-6EA6-48F3-AE15-3026FEDF86B9}.exe {E2D5EF92-768D-49C7-BD78-29A5F354359C}.exe {EC18DC89-1484-48B7-9FE5-BC69AA065E13}.exe {AC7B7C6B-5BDD-48B0-BC4A-52154AC53FAE}.exe {BB5DEEF7-F520-4088-9F9A-007FFE0EFD85}.exe {299CC7D2-8FEB-4DAB-8785-9C1B0547FD9E}.exe {DBAE95EC-82D9-4BD3-9D3B-785722F57AEB}.exe {9D118920-4DF7-428C-A584-258019181967}.exe {B669B416-C649-44CE-AFBB-6EFB3F5BDDA2}.exe
Looks like I owe you some Buffalo tongue…..
:oops:

Buffalo Tongue

Pick your favorite.
;)

That's right up there for the "Longest Fixwareout Log" trophy….
:o

Copy the text in the following quote box into Notepad:

attrib -r -s -h c:\WINDOWS\SYSTEM32\CSBDY.EXE
attrib -r -s -h c:\WINDOWS\system32\{BFB91970-E545-4022-8171-DA458BE937A0}.exe
attrib -r -s -h c:\WINDOWS\system32\{35AF85A2-4BE7-4930-B6D9-1DD64194946B}.exe
attrib -r -s -h c:\WINDOWS\system32\{093E37B5-2120-4659-AE95-970F604EC6D1}.exe
attrib -r -s -h c:\WINDOWS\system32\{D9CAAA37-4D3B-40F5-83D4-7A3233D8C4F8}.exe
attrib -r -s -h c:\WINDOWS\system32\{2FBC878C-C5E4-434B-9054-7944EF40D59F}.exe
attrib -r -s -h c:\WINDOWS\system32\{0A9DCFBC-EA55-4CF2-ACBF-BE64F9BF85B0}.exe
attrib -r -s -h c:\WINDOWS\system32\{6BD2C415-4B27-4632-B641-E1F697BC2EE3}.exe
attrib -r -s -h c:\WINDOWS\system32\{2427C8C3-AEE0-4BAF-AF70-242AF512073B}.exe
attrib -r -s -h c:\WINDOWS\system32\{BE8AEEAB-2276-457C-8D49-008DF962E697}.exe
attrib -r -s -h c:\WINDOWS\system32\{F6A6E0BA-55D7-4A11-BEAB-C105FC9A7909}.exe
attrib -r -s -h c:\WINDOWS\system32\{291830CD-F8C3-44CD-A314-E28A98B960CA}.exe
attrib -r -s -h c:\WINDOWS\system32\{AFBD4399-79EF-4038-8F3C-F5BDFCF3748A}.exe
attrib -r -s -h c:\WINDOWS\system32\{48389604-EE57-4991-93F5-C46C4C204079}.exe
attrib -r -s -h c:\WINDOWS\system32\{9DC338A2-127F-4632-A149-DB11907FC3AD}.exe
attrib -r -s -h c:\WINDOWS\system32\{8C5D2CD4-6432-443F-AEDC-8099A672BBEC}.exe
attrib -r -s -h c:\WINDOWS\system32\{CC23A3C2-B613-4E11-9EA6-79AF8BFD90E7}.exe
attrib -r -s -h c:\WINDOWS\system32\{B7341639-7D03-47C7-8DB8-3AC5AC16F69E}.exe
attrib -r -s -h c:\WINDOWS\system32\{C48387E8-9E2B-4D92-84C6-98D040449326}.exe
attrib -r -s -h c:\WINDOWS\system32\{A95527A2-4516-42F5-B510-6550D953644E}.exe
attrib -r -s -h c:\WINDOWS\system32\{8DE7A676-A53F-4B57-8FC9-6A8D228DA7E9}.exe
attrib -r -s -h c:\WINDOWS\system32\{0F756022-351E-4DDB-A2A3-BFF68A70D0DE}.exe
attrib -r -s -h c:\WINDOWS\system32\{693B05FF-9D0E-4116-A4B7-E64E9326ABC5}.exe
attrib -r -s -h c:\WINDOWS\system32\{533F8BF9-1C69-4E75-A3FD-B0D751B0AE8B}.exe
attrib -r -s -h c:\WINDOWS\system32\{9DB8D558-ACAF-4AAD-9AFD-D8662A81587A}.exe
attrib -r -s -h c:\WINDOWS\system32\{BBD1552A-1C80-4DBF-AD68-944A1E5763EB}.exe
attrib -r -s -h c:\WINDOWS\system32\{50B49499-E692-4F30-B426-88E733A2BA5C}.exe
attrib -r -s -h c:\WINDOWS\system32\{27CC3408-0671-45C6-9B44-2231E52C0C2C}.exe
attrib -r -s -h c:\WINDOWS\system32\{FECBBDAF-0634-4A9B-B220-A47B9F6A9367}.exe
attrib -r -s -h c:\WINDOWS\system32\{F0B97768-4B26-4075-9FC8-67669573EC20}.exe
attrib -r -s -h c:\WINDOWS\system32\{30AC1277-9444-4634-B099-8867D8646D1E}.exe
attrib -r -s -h c:\WINDOWS\system32\{2E8265D1-B39A-4C30-8C2E-EF321FEE7CDA}.exe
attrib -r -s -h c:\WINDOWS\system32\{BADB554D-1B08-4EA5-8E29-CBC12261C5DE}.exe
attrib -r -s -h c:\WINDOWS\system32\{A387F22D-265A-4314-9B55-A0097CF5706B}.exe
attrib -r -s -h c:\WINDOWS\system32\{8F51B7E0-52DF-4BD1-89C0-FF75437141A4}.exe
attrib -r -s -h c:\WINDOWS\system32\{4D1F8B51-C064-4BF8-A857-9EC41141C39C}.exe
attrib -r -s -h c:\WINDOWS\system32\{E807229E-7F1E-4F8C-9328-B5273BDAF566}.exe
attrib -r -s -h c:\WINDOWS\system32\{79DAA824-E4DD-49D3-98F9-E41DFA5A2C95}.exe
attrib -r -s -h c:\WINDOWS\system32\{9F5EF6F7-837A-482D-ACF2-0D73C99D4A57}.exe
attrib -r -s -h c:\WINDOWS\system32\{09CCC4F2-4633-4AE6-A84C-CCAA8E360EAA}.exe
attrib -r -s -h c:\WINDOWS\system32\{0788E4AE-85C3-4F21-8703-86742454B8B5}.exe
attrib -r -s -h c:\WINDOWS\system32\{52B74001-CC95-47FF-9B99-963D0B4F5D5B}.exe
attrib -r -s -h c:\WINDOWS\system32\{A2330A92-83BF-49DD-9B00-4B327254B561}.exe
attrib -r -s -h c:\WINDOWS\system32\{934D8898-F3F5-4F95-85D2-9322E0940A27}.exe
attrib -r -s -h c:\WINDOWS\system32\{14913593-71C0-41F5-8AF8-C33145BC7634}.exe
attrib -r -s -h c:\WINDOWS\system32\{B30581D6-78FD-48D7-A19E-01FDDDAA1CB3}.exe
attrib -r -s -h c:\WINDOWS\system32\{A1E3302E-AA53-4CF6-8EE3-6CC3C69C8C2C}.exe
attrib -r -s -h c:\WINDOWS\system32\{D9D946B8-3C6F-45D9-81D9-A72F0C9F5F7E}.exe
attrib -r -s -h c:\WINDOWS\system32\{B1EE5BE5-7EA6-47C4-B568-4FD0D55D35DE}.exe
attrib -r -s -h c:\WINDOWS\system32\{3708A910-B39A-4D94-9168-B9B74AF06423}.exe
attrib -r -s -h c:\WINDOWS\system32\{C6780768-2932-4027-B4E2-2D40587776E8}.exe
attrib -r -s -h c:\WINDOWS\system32\{E6B0F873-999A-4E1B-A7C2-885E521015A1}.exe
attrib -r -s -h c:\WINDOWS\system32\{3ECDFF9C-3D47-423A-842A-6FA00B605DCC}.exe
attrib -r -s -h c:\WINDOWS\system32\{E91201D6-D41D-45F2-A7AC-3D95C98B6A98}.exe
attrib -r -s -h c:\WINDOWS\system32\{7AEF4D4C-4995-4871-AE4A-4EDF4C325804}.exe
attrib -r -s -h c:\WINDOWS\system32\{8AC273A2-4E9E-42C5-BD7E-F0FE0D45C544}.exe
attrib -r -s -h c:\WINDOWS\system32\{F7E60211-29AB-4DCC-9A3D-151AE1333B7D}.exe
attrib -r -s -h c:\WINDOWS\system32\{90A63060-ADEE-4018-AA5A-75EFC0E0CAFC}.exe
attrib -r -s -h c:\WINDOWS\system32\{7DDEA54D-3259-4EF9-A8D4-53382DC7B249}.exe
attrib -r -s -h c:\WINDOWS\system32\{434F425C-5E84-4CED-B4B0-29B695F5FBBE}.exe
attrib -r -s -h c:\WINDOWS\system32\{BAFC1672-A590-48F5-AAB4-5B8361D10C3E}.exe
attrib -r -s -h c:\WINDOWS\system32\{0D3A79D9-2678-429A-ADA0-6E97A914A60C}.exe
attrib -r -s -h c:\WINDOWS\system32\{286BF792-A2F2-4305-AA89-B6267B419144}.exe
attrib -r -s -h c:\WINDOWS\system32\{888085CB-104A-4220-B155-DCAECA7AB297}.exe
attrib -r -s -h c:\WINDOWS\system32\{FFB47A94-2EBA-42EB-9C7C-1E79BBC68B75}.exe
attrib -r -s -h c:\WINDOWS\system32\{ABE97DAE-0326-4475-BCF7-40C558A53E6A}.exe
attrib -r -s -h c:\WINDOWS\system32\{DF109041-3D1D-444A-A730-4B399BAC6209}.exe
attrib -r -s -h c:\WINDOWS\system32\{543608AE-60BD-46D6-A80D-CCABA4EB015B}.exe
attrib -r -s -h c:\WINDOWS\system32\{8CBF5232-9DB0-4FB1-BC1C-C6E01BDB0335}.exe
attrib -r -s -h c:\WINDOWS\system32\{E9667399-389E-4DCF-B8F1-039C85A06736}.exe
attrib -r -s -h c:\WINDOWS\system32\{A56757DD-E414-4006-96BE-169AF19DE645}.exe
attrib -r -s -h c:\WINDOWS\system32\{CBA2830B-F3AF-498D-98AE-023F763169D2}.exe
attrib -r -s -h c:\WINDOWS\system32\{46AA9478-CF1D-4FD3-87C5-3D5F272E97BF}.exe
attrib -r -s -h c:\WINDOWS\system32\{2A7241C9-29FB-4459-850F-2BB7C0CCDD7C}.exe
attrib -r -s -h c:\WINDOWS\system32\{29FCBBA9-45E2-499B-AE37-135D7B8B1B81}.exe
attrib -r -s -h c:\WINDOWS\system32\{B2A99135-E792-4F66-975F-D685932EC662}.exe
attrib -r -s -h c:\WINDOWS\system32\{C19E1733-D78A-44F0-B4FB-58053BCD26A6}.exe
attrib -r -s -h c:\WINDOWS\system32\{88DD1AA4-6619-4697-8E46-FFD2F61F438A}.exe
attrib -r -s -h c:\WINDOWS\system32\{65C5F15E-08A7-4C35-AD9B-2BB303AFE2AF}.exe
attrib -r -s -h c:\WINDOWS\system32\{D663813D-350D-457E-A659-0B4798756450}.exe
attrib -r -s -h c:\WINDOWS\system32\{E22D2661-DDE8-49B2-A3DE-EB8821807C0E}.exe
attrib -r -s -h c:\WINDOWS\system32\{EF2567A6-05D1-42F4-88F2-724A0EE8DD44}.exe
attrib -r -s -h c:\WINDOWS\system32\{B96BA531-7539-481F-AC14-4E749576D4D4}.exe
attrib -r -s -h c:\WINDOWS\system32\{368864A2-EE35-4EDE-BD76-34AB7473422A}.exe
attrib -r -s -h c:\WINDOWS\system32\{49758C35-DB1F-4D8A-9515-27BE31240E4A}.exe
attrib -r -s -h c:\WINDOWS\system32\{D1E32170-AF5A-43AB-B76D-C5D6D548D8B1}.exe
attrib -r -s -h c:\WINDOWS\system32\{CB042422-69E5-41AD-B9BA-9302FB56DE76}.exe
attrib -r -s -h c:\WINDOWS\system32\{1A7C7896-4F58-451C-B029-F48505865D37}.exe
attrib -r -s -h c:\WINDOWS\system32\{A7A111E1-2DB0-4CBE-ACF5-858DBE80DB4C}.exe
attrib -r -s -h c:\WINDOWS\system32\{C86E5CC6-1EDA-4673-B1D2-990A75C4A942}.exe
attrib -r -s -h c:\WINDOWS\system32\{1E45ACE4-8280-43CD-AEC7-5D134AEE4E63}.exe
attrib -r -s -h c:\WINDOWS\system32\{DCB74AE9-6437-4F82-A2A7-A968756CD52F}.exe
attrib -r -s -h c:\WINDOWS\system32\{BC60C0D9-E5C2-4F2A-BBC1-821A2FA47659}.exe
attrib -r -s -h c:\WINDOWS\system32\{2FEB05F0-F40C-4B43-8339-3016B916EA40}.exe
attrib -r -s -h c:\WINDOWS\system32\{75A0FC8E-BB6C-4B6F-81E9-343A0295C191}.exe
attrib -r -s -h c:\WINDOWS\system32\{BC4F0858-1714-4B86-8D12-F343420B763B}.exe
attrib -r -s -h c:\WINDOWS\system32\{970F54B8-D87D-415A-B118-B9CBD9B9E4AE}.exe
attrib -r -s -h c:\WINDOWS\system32\{15BEF593-97B9-4E77-B608-E4D7A22B101E}.exe
attrib -r -s -h c:\WINDOWS\system32\{9CA56F79-476D-4B29-8E26-C0DA29A45BA2}.exe
attrib -r -s -h c:\WINDOWS\system32\{A80992B0-65DB-4083-B585-5B688F1A54E8}.exe
attrib -r -s -h c:\WINDOWS\system32\{8DE3A451-B102-4192-848F-46EC851A4406}.exe
attrib -r -s -h c:\WINDOWS\system32\{0BF5E958-E4BA-4509-AB18-0968BFF5D060}.exe
attrib -r -s -h c:\WINDOWS\system32\{29CDC5DB-D1B5-4D8A-AE88-653D3A358089}.exe
attrib -r -s -h c:\WINDOWS\system32\{4C6950EE-F07F-4AD9-B3A1-1F415A21C43E}.exe
attrib -r -s -h c:\WINDOWS\system32\{F4111E63-7330-408D-A60C-30B1C6CABDA6}.exe
attrib -r -s -h c:\WINDOWS\system32\{4DDD94A5-C409-4BF3-B133-DF5776D24B62}.exe
attrib -r -s -h c:\WINDOWS\system32\{4F5240EF-846D-446B-A484-863A0E3C888F}.exe
attrib -r -s -h c:\WINDOWS\system32\{DE383212-B62A-4B85-901C-26C8D34773D1}.exe
attrib -r -s -h c:\WINDOWS\system32\{49AE207D-6CB5-47B6-B594-346181155AC7}.exe
attrib -r -s -h c:\WINDOWS\system32\{74E2026D-1303-4CCA-9142-9224E072B47E}.exe
attrib -r -s -h c:\WINDOWS\system32\{589AACA9-B9A8-4122-AD3C-48C4D17860B4}.exe
attrib -r -s -h c:\WINDOWS\system32\{2959561E-6AF6-4F89-BF0E-D5C0F65C01E5}.exe
attrib -r -s -h c:\WINDOWS\system32\{9EBCD422-0229-4AB0-9A4F-D111C0359491}.exe
attrib -r -s -h c:\WINDOWS\system32\{F4075C8F-854F-4571-926E-42F9AD348DAA}.exe
attrib -r -s -h c:\WINDOWS\system32\{4C67DC6D-247F-4E2F-869D-F2DAAB007859}.exe
attrib -r -s -h c:\WINDOWS\system32\{8F16FFD8-C218-461D-A1D3-5800CA50D3D3}.exe
attrib -r -s -h c:\WINDOWS\system32\{CEEC1808-8FF1-49CA-AEF3-C17F02CF7ADC}.exe
attrib -r -s -h c:\WINDOWS\system32\{F206C26A-8C92-46D2-8B7D-EF481B10DD26}.exe
attrib -r -s -h c:\WINDOWS\system32\{EA3407AC-3C30-4B48-9C7A-4CB212C42203}.exe
attrib -r -s -h c:\WINDOWS\system32\{7B962EFE-6DF4-42E6-BC92-A3F6B21001D1}.exe
attrib -r -s -h c:\WINDOWS\system32\{B8CDAD4F-0B68-414B-9F47-2455D6E2C6DA}.exe
attrib -r -s -h c:\WINDOWS\system32\{CA54A3A6-E86F-4815-9E76-5BB0C96AF331}.exe
attrib -r -s -h c:\WINDOWS\system32\{47F98B46-A8B2-4CDA-9002-4131CDF05486}.exe
attrib -r -s -h c:\WINDOWS\system32\{564BF6A8-27B6-442F-8E48-1650A69BD9CF}.exe
attrib -r -s -h c:\WINDOWS\system32\{685F36D3-199A-4FDD-A774-237985A2768F}.exe
attrib -r -s -h c:\WINDOWS\system32\{02EAA8BB-E98B-47E7-A29E-494CD3E5AD14}.exe
attrib -r -s -h c:\WINDOWS\system32\{0BF5A77A-CFEA-4C47-AEEC-2F295C5B5437}.exe
attrib -r -s -h c:\WINDOWS\system32\{F5563278-587C-4A75-932A-3C1D1DA77602}.exe
attrib -r -s -h c:\WINDOWS\system32\{0C87E5A9-E7FB-49E4-AB06-C6150185E926}.exe
attrib -r -s -h c:\WINDOWS\system32\{6AE20C20-2BF9-47B3-A68C-8E68C2EF061B}.exe
attrib -r -s -h c:\WINDOWS\system32\{53749F55-6130-4307-A24A-4B887F61B1E0}.exe
attrib -r -s -h c:\WINDOWS\system32\{A9FCF1BA-E03C-4BC5-8558-504475820515}.exe
attrib -r -s -h c:\WINDOWS\system32\{A28129A9-9EFB-4258-903D-0A45D6EE69D7}.exe
attrib -r -s -h c:\WINDOWS\system32\{61C126AF-C45B-4EAE-B905-C4A07B12E1CE}.exe
attrib -r -s -h c:\WINDOWS\system32\{C005E709-03FD-48C4-9456-D100481A4203}.exe
attrib -r -s -h c:\WINDOWS\system32\{59A563E1-3814-44B7-8EEB-833E553660C3}.exe
attrib -r -s -h c:\WINDOWS\system32\{4E312A76-BEB8-45E8-BE69-565426863F78}.exe
attrib -r -s -h c:\WINDOWS\system32\{12E616AE-72F6-4CF8-A063-37BE1701ADDE}.exe
attrib -r -s -h c:\WINDOWS\system32\{4A912E69-8BFF-481D-B11C-091DEE24E176}.exe
attrib -r -s -h c:\WINDOWS\system32\{D83B282F-E38F-4203-9A22-6B0457C63862}.exe
attrib -r -s -h c:\WINDOWS\system32\{05AC4E82-2BCC-4641-A3F5-1272FBF74830}.exe
attrib -r -s -h c:\WINDOWS\system32\{7EEF7CF2-02D7-4B73-BA08-5E6E0DC6AA72}.exe
attrib -r -s -h c:\WINDOWS\system32\{D8E658AB-2EDA-4B46-B67F-56B833C97602}.exe
attrib -r -s -h c:\WINDOWS\system32\{2A0AC980-DB47-440F-84F3-B6311F965A68}.exe
attrib -r -s -h c:\WINDOWS\system32\{487044A3-20DB-4265-A92A-4809B1478D2D}.exe
attrib -r -s -h c:\WINDOWS\system32\{B54C6DCD-0A13-449A-9E5E-DC22DCADF46F}.exe
attrib -r -s -h c:\WINDOWS\system32\{CFD4AD70-680C-4A98-999E-464F3D5242F0}.exe
attrib -r -s -h c:\WINDOWS\system32\{FE54C698-F6F2-4B54-B759-9353910DDA82}.exe
attrib -r -s -h c:\WINDOWS\system32\{C0B07F8C-4B7B-4421-A2E4-50DB28B1D305}.exe
attrib -r -s -h c:\WINDOWS\system32\{1D2F0503-A241-4011-8C29-61FC9404125B}.exe
attrib -r -s -h c:\WINDOWS\system32\{ED9B7B59-0BCB-4F53-B415-34D9342577CD}.exe
attrib -r -s -h c:\WINDOWS\system32\{596D586F-4722-418D-A075-622BE10C550B}.exe
attrib -r -s -h c:\WINDOWS\system32\{9D4B2060-2C19-4C6D-A656-1CC4430D9F04}.exe
attrib -r -s -h c:\WINDOWS\system32\{361CBE81-1B89-4E3B-8ABD-B03CA0E56D3C}.exe
attrib -r -s -h c:\WINDOWS\system32\{0A5112D7-5781-4EE5-B5BE-15408DD16751}.exe
attrib -r -s -h c:\WINDOWS\system32\{9B28A884-EAEA-462F-95C5-44BDA820D5A2}.exe
attrib -r -s -h c:\WINDOWS\system32\{3F8095AE-4435-4A8B-A25D-49DCD4D7DA79}.exe
attrib -r -s -h c:\WINDOWS\system32\{E1AFCCC9-EC6E-49F2-9B13-524BC7350FD2}.exe
attrib -r -s -h c:\WINDOWS\system32\{B298C134-6EA6-48F3-AE15-3026FEDF86B9}.exe
attrib -r -s -h c:\WINDOWS\system32\{E2D5EF92-768D-49C7-BD78-29A5F354359C}.exe
attrib -r -s -h c:\WINDOWS\system32\{EC18DC89-1484-48B7-9FE5-BC69AA065E13}.exe
attrib -r -s -h c:\WINDOWS\system32\{AC7B7C6B-5BDD-48B0-BC4A-52154AC53FAE}.exe
attrib -r -s -h c:\WINDOWS\system32\{BB5DEEF7-F520-4088-9F9A-007FFE0EFD85}.exe
attrib -r -s -h c:\WINDOWS\system32\{299CC7D2-8FEB-4DAB-8785-9C1B0547FD9E}.exe
attrib -r -s -h c:\WINDOWS\system32\{DBAE95EC-82D9-4BD3-9D3B-785722F57AEB}.exe
attrib -r -s -h c:\WINDOWS\system32\{9D118920-4DF7-428C-A584-258019181967}.exe
attrib -r -s -h c:\WINDOWS\system32\{B669B416-C649-44CE-AFBB-6EFB3F5BDDA2}.exe
del c:\WINDOWS\SYSTEM32\CSBDY.EXE
del c:\WINDOWS\system32\{BFB91970-E545-4022-8171-DA458BE937A0}.exe
del c:\WINDOWS\system32\{35AF85A2-4BE7-4930-B6D9-1DD64194946B}.exe
del c:\WINDOWS\system32\{093E37B5-2120-4659-AE95-970F604EC6D1}.exe
del c:\WINDOWS\system32\{D9CAAA37-4D3B-40F5-83D4-7A3233D8C4F8}.exe
del c:\WINDOWS\system32\{2FBC878C-C5E4-434B-9054-7944EF40D59F}.exe
del c:\WINDOWS\system32\{0A9DCFBC-EA55-4CF2-ACBF-BE64F9BF85B0}.exe
del c:\WINDOWS\system32\{6BD2C415-4B27-4632-B641-E1F697BC2EE3}.exe
del c:\WINDOWS\system32\{2427C8C3-AEE0-4BAF-AF70-242AF512073B}.exe
del c:\WINDOWS\system32\{BE8AEEAB-2276-457C-8D49-008DF962E697}.exe
del c:\WINDOWS\system32\{F6A6E0BA-55D7-4A11-BEAB-C105FC9A7909}.exe
del c:\WINDOWS\system32\{291830CD-F8C3-44CD-A314-E28A98B960CA}.exe
del c:\WINDOWS\system32\{AFBD4399-79EF-4038-8F3C-F5BDFCF3748A}.exe
del c:\WINDOWS\system32\{48389604-EE57-4991-93F5-C46C4C204079}.exe
del c:\WINDOWS\system32\{9DC338A2-127F-4632-A149-DB11907FC3AD}.exe
del c:\WINDOWS\system32\{8C5D2CD4-6432-443F-AEDC-8099A672BBEC}.exe
del c:\WINDOWS\system32\{CC23A3C2-B613-4E11-9EA6-79AF8BFD90E7}.exe
del c:\WINDOWS\system32\{B7341639-7D03-47C7-8DB8-3AC5AC16F69E}.exe
del c:\WINDOWS\system32\{C48387E8-9E2B-4D92-84C6-98D040449326}.exe
del c:\WINDOWS\system32\{A95527A2-4516-42F5-B510-6550D953644E}.exe
del c:\WINDOWS\system32\{8DE7A676-A53F-4B57-8FC9-6A8D228DA7E9}.exe
del c:\WINDOWS\system32\{0F756022-351E-4DDB-A2A3-BFF68A70D0DE}.exe
del c:\WINDOWS\system32\{693B05FF-9D0E-4116-A4B7-E64E9326ABC5}.exe
del c:\WINDOWS\system32\{533F8BF9-1C69-4E75-A3FD-B0D751B0AE8B}.exe
del c:\WINDOWS\system32\{9DB8D558-ACAF-4AAD-9AFD-D8662A81587A}.exe
del c:\WINDOWS\system32\{BBD1552A-1C80-4DBF-AD68-944A1E5763EB}.exe
del c:\WINDOWS\system32\{50B49499-E692-4F30-B426-88E733A2BA5C}.exe
del c:\WINDOWS\system32\{27CC3408-0671-45C6-9B44-2231E52C0C2C}.exe
del c:\WINDOWS\system32\{FECBBDAF-0634-4A9B-B220-A47B9F6A9367}.exe
del c:\WINDOWS\system32\{F0B97768-4B26-4075-9FC8-67669573EC20}.exe
del c:\WINDOWS\system32\{30AC1277-9444-4634-B099-8867D8646D1E}.exe
del c:\WINDOWS\system32\{2E8265D1-B39A-4C30-8C2E-EF321FEE7CDA}.exe
del c:\WINDOWS\system32\{BADB554D-1B08-4EA5-8E29-CBC12261C5DE}.exe
del c:\WINDOWS\system32\{A387F22D-265A-4314-9B55-A0097CF5706B}.exe
del c:\WINDOWS\system32\{8F51B7E0-52DF-4BD1-89C0-FF75437141A4}.exe
del c:\WINDOWS\system32\{4D1F8B51-C064-4BF8-A857-9EC41141C39C}.exe
del c:\WINDOWS\system32\{E807229E-7F1E-4F8C-9328-B5273BDAF566}.exe
del c:\WINDOWS\system32\{79DAA824-E4DD-49D3-98F9-E41DFA5A2C95}.exe
del c:\WINDOWS\system32\{9F5EF6F7-837A-482D-ACF2-0D73C99D4A57}.exe
del c:\WINDOWS\system32\{09CCC4F2-4633-4AE6-A84C-CCAA8E360EAA}.exe
del c:\WINDOWS\system32\{0788E4AE-85C3-4F21-8703-86742454B8B5}.exe
del c:\WINDOWS\system32\{52B74001-CC95-47FF-9B99-963D0B4F5D5B}.exe
del c:\WINDOWS\system32\{A2330A92-83BF-49DD-9B00-4B327254B561}.exe
del c:\WINDOWS\system32\{934D8898-F3F5-4F95-85D2-9322E0940A27}.exe
del c:\WINDOWS\system32\{14913593-71C0-41F5-8AF8-C33145BC7634}.exe
del c:\WINDOWS\system32\{B30581D6-78FD-48D7-A19E-01FDDDAA1CB3}.exe
del c:\WINDOWS\system32\{A1E3302E-AA53-4CF6-8EE3-6CC3C69C8C2C}.exe
del c:\WINDOWS\system32\{D9D946B8-3C6F-45D9-81D9-A72F0C9F5F7E}.exe
del c:\WINDOWS\system32\{B1EE5BE5-7EA6-47C4-B568-4FD0D55D35DE}.exe
del c:\WINDOWS\system32\{3708A910-B39A-4D94-9168-B9B74AF06423}.exe
del c:\WINDOWS\system32\{C6780768-2932-4027-B4E2-2D40587776E8}.exe
del c:\WINDOWS\system32\{E6B0F873-999A-4E1B-A7C2-885E521015A1}.exe
del c:\WINDOWS\system32\{3ECDFF9C-3D47-423A-842A-6FA00B605DCC}.exe
del c:\WINDOWS\system32\{E91201D6-D41D-45F2-A7AC-3D95C98B6A98}.exe
del c:\WINDOWS\system32\{7AEF4D4C-4995-4871-AE4A-4EDF4C325804}.exe
del c:\WINDOWS\system32\{8AC273A2-4E9E-42C5-BD7E-F0FE0D45C544}.exe
del c:\WINDOWS\system32\{F7E60211-29AB-4DCC-9A3D-151AE1333B7D}.exe
del c:\WINDOWS\system32\{90A63060-ADEE-4018-AA5A-75EFC0E0CAFC}.exe
del c:\WINDOWS\system32\{7DDEA54D-3259-4EF9-A8D4-53382DC7B249}.exe
del c:\WINDOWS\system32\{434F425C-5E84-4CED-B4B0-29B695F5FBBE}.exe
del c:\WINDOWS\system32\{BAFC1672-A590-48F5-AAB4-5B8361D10C3E}.exe
del c:\WINDOWS\system32\{0D3A79D9-2678-429A-ADA0-6E97A914A60C}.exe
del c:\WINDOWS\system32\{286BF792-A2F2-4305-AA89-B6267B419144}.exe
del c:\WINDOWS\system32\{888085CB-104A-4220-B155-DCAECA7AB297}.exe
del c:\WINDOWS\system32\{FFB47A94-2EBA-42EB-9C7C-1E79BBC68B75}.exe
del c:\WINDOWS\system32\{ABE97DAE-0326-4475-BCF7-40C558A53E6A}.exe
del c:\WINDOWS\system32\{DF109041-3D1D-444A-A730-4B399BAC6209}.exe
del c:\WINDOWS\system32\{543608AE-60BD-46D6-A80D-CCABA4EB015B}.exe
del c:\WINDOWS\system32\{8CBF5232-9DB0-4FB1-BC1C-C6E01BDB0335}.exe
del c:\WINDOWS\system32\{E9667399-389E-4DCF-B8F1-039C85A06736}.exe
del c:\WINDOWS\system32\{A56757DD-E414-4006-96BE-169AF19DE645}.exe
del c:\WINDOWS\system32\{CBA2830B-F3AF-498D-98AE-023F763169D2}.exe
del c:\WINDOWS\system32\{46AA9478-CF1D-4FD3-87C5-3D5F272E97BF}.exe
del c:\WINDOWS\system32\{2A7241C9-29FB-4459-850F-2BB7C0CCDD7C}.exe
del c:\WINDOWS\system32\{29FCBBA9-45E2-499B-AE37-135D7B8B1B81}.exe
del c:\WINDOWS\system32\{B2A99135-E792-4F66-975F-D685932EC662}.exe
del c:\WINDOWS\system32\{C19E1733-D78A-44F0-B4FB-58053BCD26A6}.exe
del c:\WINDOWS\system32\{88DD1AA4-6619-4697-8E46-FFD2F61F438A}.exe
del c:\WINDOWS\system32\{65C5F15E-08A7-4C35-AD9B-2BB303AFE2AF}.exe
del c:\WINDOWS\system32\{D663813D-350D-457E-A659-0B4798756450}.exe
del c:\WINDOWS\system32\{E22D2661-DDE8-49B2-A3DE-EB8821807C0E}.exe
del c:\WINDOWS\system32\{EF2567A6-05D1-42F4-88F2-724A0EE8DD44}.exe
del c:\WINDOWS\system32\{B96BA531-7539-481F-AC14-4E749576D4D4}.exe
del c:\WINDOWS\system32\{368864A2-EE35-4EDE-BD76-34AB7473422A}.exe
del c:\WINDOWS\system32\{49758C35-DB1F-4D8A-9515-27BE31240E4A}.exe
del c:\WINDOWS\system32\{D1E32170-AF5A-43AB-B76D-C5D6D548D8B1}.exe
del c:\WINDOWS\system32\{CB042422-69E5-41AD-B9BA-9302FB56DE76}.exe
del c:\WINDOWS\system32\{1A7C7896-4F58-451C-B029-F48505865D37}.exe
del c:\WINDOWS\system32\{A7A111E1-2DB0-4CBE-ACF5-858DBE80DB4C}.exe
del c:\WINDOWS\system32\{C86E5CC6-1EDA-4673-B1D2-990A75C4A942}.exe
del c:\WINDOWS\system32\{1E45ACE4-8280-43CD-AEC7-5D134AEE4E63}.exe
del c:\WINDOWS\system32\{DCB74AE9-6437-4F82-A2A7-A968756CD52F}.exe
del c:\WINDOWS\system32\{BC60C0D9-E5C2-4F2A-BBC1-821A2FA47659}.exe
del c:\WINDOWS\system32\{2FEB05F0-F40C-4B43-8339-3016B916EA40}.exe
del c:\WINDOWS\system32\{75A0FC8E-BB6C-4B6F-81E9-343A0295C191}.exe
del c:\WINDOWS\system32\{BC4F0858-1714-4B86-8D12-F343420B763B}.exe
del c:\WINDOWS\system32\{970F54B8-D87D-415A-B118-B9CBD9B9E4AE}.exe
del c:\WINDOWS\system32\{15BEF593-97B9-4E77-B608-E4D7A22B101E}.exe
del c:\WINDOWS\system32\{9CA56F79-476D-4B29-8E26-C0DA29A45BA2}.exe
del c:\WINDOWS\system32\{A80992B0-65DB-4083-B585-5B688F1A54E8}.exe
del c:\WINDOWS\system32\{8DE3A451-B102-4192-848F-46EC851A4406}.exe
del c:\WINDOWS\system32\{0BF5E958-E4BA-4509-AB18-0968BFF5D060}.exe
del c:\WINDOWS\system32\{29CDC5DB-D1B5-4D8A-AE88-653D3A358089}.exe
del c:\WINDOWS\system32\{4C6950EE-F07F-4AD9-B3A1-1F415A21C43E}.exe
del c:\WINDOWS\system32\{F4111E63-7330-408D-A60C-30B1C6CABDA6}.exe
del c:\WINDOWS\system32\{4DDD94A5-C409-4BF3-B133-DF5776D24B62}.exe
del c:\WINDOWS\system32\{4F5240EF-846D-446B-A484-863A0E3C888F}.exe
del c:\WINDOWS\system32\{DE383212-B62A-4B85-901C-26C8D34773D1}.exe
del c:\WINDOWS\system32\{49AE207D-6CB5-47B6-B594-346181155AC7}.exe
del c:\WINDOWS\system32\{74E2026D-1303-4CCA-9142-9224E072B47E}.exe
del c:\WINDOWS\system32\{589AACA9-B9A8-4122-AD3C-48C4D17860B4}.exe
del c:\WINDOWS\system32\{2959561E-6AF6-4F89-BF0E-D5C0F65C01E5}.exe
del c:\WINDOWS\system32\{9EBCD422-0229-4AB0-9A4F-D111C0359491}.exe
del c:\WINDOWS\system32\{F4075C8F-854F-4571-926E-42F9AD348DAA}.exe
del c:\WINDOWS\system32\{4C67DC6D-247F-4E2F-869D-F2DAAB007859}.exe
del c:\WINDOWS\system32\{8F16FFD8-C218-461D-A1D3-5800CA50D3D3}.exe
del c:\WINDOWS\system32\{CEEC1808-8FF1-49CA-AEF3-C17F02CF7ADC}.exe
del c:\WINDOWS\system32\{F206C26A-8C92-46D2-8B7D-EF481B10DD26}.exe
del c:\WINDOWS\system32\{EA3407AC-3C30-4B48-9C7A-4CB212C42203}.exe
del c:\WINDOWS\system32\{7B962EFE-6DF4-42E6-BC92-A3F6B21001D1}.exe
del c:\WINDOWS\system32\{B8CDAD4F-0B68-414B-9F47-2455D6E2C6DA}.exe
del c:\WINDOWS\system32\{CA54A3A6-E86F-4815-9E76-5BB0C96AF331}.exe
del c:\WINDOWS\system32\{47F98B46-A8B2-4CDA-9002-4131CDF05486}.exe
del c:\WINDOWS\system32\{564BF6A8-27B6-442F-8E48-1650A69BD9CF}.exe
del c:\WINDOWS\system32\{685F36D3-199A-4FDD-A774-237985A2768F}.exe
del c:\WINDOWS\system32\{02EAA8BB-E98B-47E7-A29E-494CD3E5AD14}.exe
del c:\WINDOWS\system32\{0BF5A77A-CFEA-4C47-AEEC-2F295C5B5437}.exe
del c:\WINDOWS\system32\{F5563278-587C-4A75-932A-3C1D1DA77602}.exe
del c:\WINDOWS\system32\{0C87E5A9-E7FB-49E4-AB06-C6150185E926}.exe
del c:\WINDOWS\system32\{6AE20C20-2BF9-47B3-A68C-8E68C2EF061B}.exe
del c:\WINDOWS\system32\{53749F55-6130-4307-A24A-4B887F61B1E0}.exe
del c:\WINDOWS\system32\{A9FCF1BA-E03C-4BC5-8558-504475820515}.exe
del c:\WINDOWS\system32\{A28129A9-9EFB-4258-903D-0A45D6EE69D7}.exe
del c:\WINDOWS\system32\{61C126AF-C45B-4EAE-B905-C4A07B12E1CE}.exe
del c:\WINDOWS\system32\{C005E709-03FD-48C4-9456-D100481A4203}.exe
del c:\WINDOWS\system32\{59A563E1-3814-44B7-8EEB-833E553660C3}.exe
del c:\WINDOWS\system32\{4E312A76-BEB8-45E8-BE69-565426863F78}.exe
del c:\WINDOWS\system32\{12E616AE-72F6-4CF8-A063-37BE1701ADDE}.exe
del c:\WINDOWS\system32\{4A912E69-8BFF-481D-B11C-091DEE24E176}.exe
del c:\WINDOWS\system32\{D83B282F-E38F-4203-9A22-6B0457C63862}.exe
del c:\WINDOWS\system32\{05AC4E82-2BCC-4641-A3F5-1272FBF74830}.exe
del c:\WINDOWS\system32\{7EEF7CF2-02D7-4B73-BA08-5E6E0DC6AA72}.exe
del c:\WINDOWS\system32\{D8E658AB-2EDA-4B46-B67F-56B833C97602}.exe
del c:\WINDOWS\system32\{2A0AC980-DB47-440F-84F3-B6311F965A68}.exe
del c:\WINDOWS\system32\{487044A3-20DB-4265-A92A-4809B1478D2D}.exe
del c:\WINDOWS\system32\{B54C6DCD-0A13-449A-9E5E-DC22DCADF46F}.exe
del c:\WINDOWS\system32\{CFD4AD70-680C-4A98-999E-464F3D5242F0}.exe
del c:\WINDOWS\system32\{FE54C698-F6F2-4B54-B759-9353910DDA82}.exe
del c:\WINDOWS\system32\{C0B07F8C-4B7B-4421-A2E4-50DB28B1D305}.exe
del c:\WINDOWS\system32\{1D2F0503-A241-4011-8C29-61FC9404125B}.exe
del c:\WINDOWS\system32\{ED9B7B59-0BCB-4F53-B415-34D9342577CD}.exe
del c:\WINDOWS\system32\{596D586F-4722-418D-A075-622BE10C550B}.exe
del c:\WINDOWS\system32\{9D4B2060-2C19-4C6D-A656-1CC4430D9F04}.exe
del c:\WINDOWS\system32\{361CBE81-1B89-4E3B-8ABD-B03CA0E56D3C}.exe
del c:\WINDOWS\system32\{0A5112D7-5781-4EE5-B5BE-15408DD16751}.exe
del c:\WINDOWS\system32\{9B28A884-EAEA-462F-95C5-44BDA820D5A2}.exe
del c:\WINDOWS\system32\{3F8095AE-4435-4A8B-A25D-49DCD4D7DA79}.exe
del c:\WINDOWS\system32\{E1AFCCC9-EC6E-49F2-9B13-524BC7350FD2}.exe
del c:\WINDOWS\system32\{B298C134-6EA6-48F3-AE15-3026FEDF86B9}.exe
del c:\WINDOWS\system32\{E2D5EF92-768D-49C7-BD78-29A5F354359C}.exe
del c:\WINDOWS\system32\{EC18DC89-1484-48B7-9FE5-BC69AA065E13}.exe
del c:\WINDOWS\system32\{AC7B7C6B-5BDD-48B0-BC4A-52154AC53FAE}.exe
del c:\WINDOWS\system32\{BB5DEEF7-F520-4088-9F9A-007FFE0EFD85}.exe
del c:\WINDOWS\system32\{299CC7D2-8FEB-4DAB-8785-9C1B0547FD9E}.exe
del c:\WINDOWS\system32\{DBAE95EC-82D9-4BD3-9D3B-785722F57AEB}.exe
del c:\WINDOWS\system32\{9D118920-4DF7-428C-A584-258019181967}.exe
del c:\WINDOWS\system32\{B669B416-C649-44CE-AFBB-6EFB3F5BDDA2}.exe


Save it to your desktop as ff.bat

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Now, the ff.bat file on the desktop. A DOS window will open as all those bad files are being removed.

Now, Browse to c:\fixwareout folder, Fixit.bat.

This will start Fixwareout again.

After the reboot, post:

1. The fixwareout report

2. A new HijackThis! log

Into this thread.
:)
this is the safemode ewido report I still have a white desktop with some info about restoring 'active desktop'. is this genuine? also there is a shortcut to a system 32 file for 'monaco gaming' which hasn't been removed at this stage. i've tried to reset my homepage to google uk but now it keeps reverting to msn. i'm not sure if i expressed my thanks enough in the last post (i guess i realise there's still a bit to go) but it is such a pleasure to have a working computer…so thanks!!!! regards stillwill ——————————————————— ewido anti-spyware - Scan Report ——————————————————— + Created at: 21:28:44 08/08/2006 + Scan result: HKU\S-1-5-21-2966927733-1723214923-4271176276-1004\Software\saap -> Adware.180Solutions : Cleaned with backup (quarantined). C:\Program Files\Kazaa\TopSearch.dll -> Adware.Altnet : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\CLSID\{538D316B-A3A2-1200-EE47-1BEF8BCDD755} -> Adware.CoolWebSearch : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\CLSID\{E47F2716-713A-7A1B-77DF-2FD30AEB8673} -> Adware.CoolWebSearch : Cleaned with backup (quarantined). C:\Program Files\WAV to MP3 Encoder\MthreeTopText_ezStub.exe -> Adware.EZula : Cleaned with backup (quarantined). C:\WINDOWS\system32\{093E37B5-2120-4659-AE95-970F604EC6D1}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{14913593-71C0-41F5-8AF8-C33145BC7634}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{1D2F0503-A241-4011-8C29-61FC9404125B}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{286BF792-A2F2-4305-AA89-B6267B419144}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{291830CD-F8C3-44CD-A314-E28A98B960CA}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{2959561E-6AF6-4F89-BF0E-D5C0F65C01E5}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{29CDC5DB-D1B5-4D8A-AE88-653D3A358089}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{2A0AC980-DB47-440F-84F3-B6311F965A68}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{2E8265D1-B39A-4C30-8C2E-EF321FEE7CDA}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{2FEB05F0-F40C-4B43-8339-3016B916EA40}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{368864A2-EE35-4EDE-BD76-34AB7473422A}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{434F425C-5E84-4CED-B4B0-29B695F5FBBE}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{46AA9478-CF1D-4FD3-87C5-3D5F272E97BF}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{48389604-EE57-4991-93F5-C46C4C204079}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{4E312A76-BEB8-45E8-BE69-565426863F78}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{52B74001-CC95-47FF-9B99-963D0B4F5D5B}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{53749F55-6130-4307-A24A-4B887F61B1E0}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{543608AE-60BD-46D6-A80D-CCABA4EB015B}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{61C126AF-C45B-4EAE-B905-C4A07B12E1CE}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{685F36D3-199A-4FDD-A774-237985A2768F}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{6BD2C415-4B27-4632-B641-E1F697BC2EE3}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{74E2026D-1303-4CCA-9142-9224E072B47E}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{7B962EFE-6DF4-42E6-BC92-A3F6B21001D1}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{88DD1AA4-6619-4697-8E46-FFD2F61F438A}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{8DE3A451-B102-4192-848F-46EC851A4406}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{8F16FFD8-C218-461D-A1D3-5800CA50D3D3}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{8F51B7E0-52DF-4BD1-89C0-FF75437141A4}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{9B28A884-EAEA-462F-95C5-44BDA820D5A2}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{9CA56F79-476D-4B29-8E26-C0DA29A45BA2}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{9D118920-4DF7-428C-A584-258019181967}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{9F5EF6F7-837A-482D-ACF2-0D73C99D4A57}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{AFBD4399-79EF-4038-8F3C-F5BDFCF3748A}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{BBD1552A-1C80-4DBF-AD68-944A1E5763EB}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{BE8AEEAB-2276-457C-8D49-008DF962E697}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{C48387E8-9E2B-4D92-84C6-98D040449326}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{C6780768-2932-4027-B4E2-2D40587776E8}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{C86E5CC6-1EDA-4673-B1D2-990A75C4A942}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{CA54A3A6-E86F-4815-9E76-5BB0C96AF331}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{CB042422-69E5-41AD-B9BA-9302FB56DE76}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{CC23A3C2-B613-4E11-9EA6-79AF8BFD90E7}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{CFD4AD70-680C-4A98-999E-464F3D5242F0}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{D83B282F-E38F-4203-9A22-6B0457C63862}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{D9D946B8-3C6F-45D9-81D9-A72F0C9F5F7E}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{DE383212-B62A-4B85-901C-26C8D34773D1}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{E1AFCCC9-EC6E-49F2-9B13-524BC7350FD2}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{E22D2661-DDE8-49B2-A3DE-EB8821807C0E}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{E807229E-7F1E-4F8C-9328-B5273BDAF566}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{E91201D6-D41D-45F2-A7AC-3D95C98B6A98}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{E9667399-389E-4DCF-B8F1-039C85A06736}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{EC18DC89-1484-48B7-9FE5-BC69AA065E13}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{F206C26A-8C92-46D2-8B7D-EF481B10DD26}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{F4075C8F-854F-4571-926E-42F9AD348DAA}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{F5563278-587C-4A75-932A-3C1D1DA77602}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{F7E60211-29AB-4DCC-9A3D-151AE1333B7D}.exe -> Adware.FindSpy : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\Media-Codec.Chl -> Adware.Generic : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\Media-Codec.Chl\CLSID -> Adware.Generic : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\AtlControl.AtlCtrl -> Adware.HotBar : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\AtlControl.AtlCtrl.1 -> Adware.HotBar : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\AtlControl.AtlCtrl\CLSID -> Adware.HotBar : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\AtlControl.AtlCtrl\CurVer -> Adware.HotBar : Cleaned with backup (quarantined). HKLM\SOFTWARE\PerfectNav -> Adware.KeenValue : Cleaned with backup (quarantined). HKLM\SOFTWARE\PerfectNav\BHO -> Adware.KeenValue : Cleaned with backup (quarantined). HKLM\SOFTWARE\PerfectNav\BHO\HomePage -> Adware.KeenValue : Cleaned with backup (quarantined). HKLM\SOFTWARE\PerfectNav\BHO\RedirectURLS -> Adware.KeenValue : Cleaned with backup (quarantined). C:\WINDOWS\system32\{DBAE95EC-82D9-4BD3-9D3B-785722F57AEB}.exe -> Adware.Msnagent : Cleaned with backup (quarantined). C:\WINDOWS\system32\{361CBE81-1B89-4E3B-8ABD-B03CA0E56D3C}.exe -> Adware.Raze : Cleaned with backup (quarantined). C:\WINDOWS\system32\70tovmto.ini -> Adware.Sahat : Cleaned with backup (quarantined). C:\Program Files\ClockSync -> Adware.WhenU : Cleaned with backup (quarantined). C:\Documents and Settings\Omni\My Documents\My Deliveries\SPYWARE TOOLS\hijackthisnew\backups\backup-20050402-232006-203.dll -> Adware.WinAD : Cleaned with backup (quarantined). C:\Program Files\BTopenworld\btwebcontrol.dll -> Dialer.BT.b : Cleaned with backup (quarantined). C:\WINDOWS\Downloaded Program Files\dba1865.exe -> Dialer.GBDialer.c : Cleaned with backup (quarantined). C:\WINDOWS\Greenstone.bmp:zxdkrh -> Downloader.Agent.pe : Cleaned with backup (quarantined). C:\WINDOWS\system32\csbdy.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\CLSID\{daa873d4-958c-453c-81ca-3fe6f3676a87} -> Downloader.Fugif : Cleaned with backup (quarantined). C:\Program Files\Kazaa\PerfectNavUninstall.exe -> Downloader.Keenval.e : Cleaned with backup (quarantined). C:\WINDOWS\system32:vkaa.dll -> Downloader.Small.azk : Cleaned with backup (quarantined). C:\WINDOWS\system32\{533F8BF9-1C69-4E75-A3FD-B0D751B0AE8B}.exe -> Downloader.Small.buy : Cleaned with backup (quarantined). C:\WINDOWS\system32\{9DC338A2-127F-4632-A149-DB11907FC3AD}.exe -> Downloader.Small.buy : Cleaned with backup (quarantined). C:\WINDOWS\Downloaded Program Files\gba1383.exe -> Heuristic.Win32.Dialer : Cleaned with backup (quarantined). C:\Documents and Settings\Omni\My Documents\My Deliveries\SPYWARE TOOLS\hijackthisnew\backups\backup-20050402-232005-745.dll -> Not-A-Virus.VirTool.Win32.Collector : Cleaned with backup (quarantined). C:\Documents and Settings\Omni\Cookies\omni@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). C:\WINDOWS\system32\{0A5112D7-5781-4EE5-B5BE-15408DD16751}.exe -> Trojan.Hoster : Cleaned with backup (quarantined). C:\WINDOWS\system32\{4DDD94A5-C409-4BF3-B133-DF5776D24B62}.exe -> Trojan.Hoster : Cleaned with backup (quarantined). C:\WINDOWS\system32\{7EEF7CF2-02D7-4B73-BA08-5E6E0DC6AA72}.exe -> Trojan.Hoster : Cleaned with backup (quarantined). C:\WINDOWS\system32\{8C5D2CD4-6432-443F-AEDC-8099A672BBEC}.exe -> Trojan.Hoster : Cleaned with backup (quarantined). C:\WINDOWS\system32\{8DE7A676-A53F-4B57-8FC9-6A8D228DA7E9}.exe -> Trojan.Hoster : Cleaned with backup (quarantined). C:\WINDOWS\system32\{9DB8D558-ACAF-4AAD-9AFD-D8662A81587A}.exe -> Trojan.Hoster : Cleaned with backup (quarantined). C:\WINDOWS\system32\{F4111E63-7330-408D-A60C-30B1C6CABDA6}.exe -> Trojan.Hoster : Cleaned with backup (quarantined). C:\WINDOWS\system32\{FFB47A94-2EBA-42EB-9C7C-1E79BBC68B75}.exe -> Trojan.Hoster : Cleaned with backup (quarantined). C:\WINDOWS\system32\{0788E4AE-85C3-4F21-8703-86742454B8B5}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{0A9DCFBC-EA55-4CF2-ACBF-BE64F9BF85B0}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{0BF5A77A-CFEA-4C47-AEEC-2F295C5B5437}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{0BF5E958-E4BA-4509-AB18-0968BFF5D060}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{0D3A79D9-2678-429A-ADA0-6E97A914A60C}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{15BEF593-97B9-4E77-B608-E4D7A22B101E}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{2427C8C3-AEE0-4BAF-AF70-242AF512073B}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{27CC3408-0671-45C6-9B44-2231E52C0C2C}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{299CC7D2-8FEB-4DAB-8785-9C1B0547FD9E}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{30AC1277-9444-4634-B099-8867D8646D1E}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{35AF85A2-4BE7-4930-B6D9-1DD64194946B}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{3708A910-B39A-4D94-9168-B9B74AF06423}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{3ECDFF9C-3D47-423A-842A-6FA00B605DCC}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{3F8095AE-4435-4A8B-A25D-49DCD4D7DA79}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{49AE207D-6CB5-47B6-B594-346181155AC7}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{4A912E69-8BFF-481D-B11C-091DEE24E176}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{4C67DC6D-247F-4E2F-869D-F2DAAB007859}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{4F5240EF-846D-446B-A484-863A0E3C888F}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{564BF6A8-27B6-442F-8E48-1650A69BD9CF}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{589AACA9-B9A8-4122-AD3C-48C4D17860B4}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{59A563E1-3814-44B7-8EEB-833E553660C3}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{6AE20C20-2BF9-47B3-A68C-8E68C2EF061B}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{79DAA824-E4DD-49D3-98F9-E41DFA5A2C95}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{7DDEA54D-3259-4EF9-A8D4-53382DC7B249}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{8AC273A2-4E9E-42C5-BD7E-F0FE0D45C544}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{8CBF5232-9DB0-4FB1-BC1C-C6E01BDB0335}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{934D8898-F3F5-4F95-85D2-9322E0940A27}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{970F54B8-D87D-415A-B118-B9CBD9B9E4AE}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{9EBCD422-0229-4AB0-9A4F-D111C0359491}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{A1E3302E-AA53-4CF6-8EE3-6CC3C69C8C2C}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{A28129A9-9EFB-4258-903D-0A45D6EE69D7}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{A387F22D-265A-4314-9B55-A0097CF5706B}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{A7A111E1-2DB0-4CBE-ACF5-858DBE80DB4C}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{A80992B0-65DB-4083-B585-5B688F1A54E8}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{B2A99135-E792-4F66-975F-D685932EC662}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{B54C6DCD-0A13-449A-9E5E-DC22DCADF46F}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{B7341639-7D03-47C7-8DB8-3AC5AC16F69E}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{B8CDAD4F-0B68-414B-9F47-2455D6E2C6DA}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{B96BA531-7539-481F-AC14-4E749576D4D4}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{BC4F0858-1714-4B86-8D12-F343420B763B}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{BC60C0D9-E5C2-4F2A-BBC1-821A2FA47659}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{C0B07F8C-4B7B-4421-A2E4-50DB28B1D305}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{C19E1733-D78A-44F0-B4FB-58053BCD26A6}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{CBA2830B-F3AF-498D-98AE-023F763169D2}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{CEEC1808-8FF1-49CA-AEF3-C17F02CF7ADC}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{D1E32170-AF5A-43AB-B76D-C5D6D548D8B1}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{D663813D-350D-457E-A659-0B4798756450}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{D8E658AB-2EDA-4B46-B67F-56B833C97602}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{DCB74AE9-6437-4F82-A2A7-A968756CD52F}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{DF109041-3D1D-444A-A730-4B399BAC6209}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{E2D5EF92-768D-49C7-BD78-29A5F354359C}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{EA3407AC-3C30-4B48-9C7A-4CB212C42203}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\WINDOWS\system32\{02EAA8BB-E98B-47E7-A29E-494CD3E5AD14}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{05AC4E82-2BCC-4641-A3F5-1272FBF74830}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{09CCC4F2-4633-4AE6-A84C-CCAA8E360EAA}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{0C87E5A9-E7FB-49E4-AB06-C6150185E926}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{0F756022-351E-4DDB-A2A3-BFF68A70D0DE}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{12E616AE-72F6-4CF8-A063-37BE1701ADDE}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{1A7C7896-4F58-451C-B029-F48505865D37}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{1E45ACE4-8280-43CD-AEC7-5D134AEE4E63}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{29FCBBA9-45E2-499B-AE37-135D7B8B1B81}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{2A7241C9-29FB-4459-850F-2BB7C0CCDD7C}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{2FBC878C-C5E4-434B-9054-7944EF40D59F}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{47F98B46-A8B2-4CDA-9002-4131CDF05486}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{487044A3-20DB-4265-A92A-4809B1478D2D}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{49758C35-DB1F-4D8A-9515-27BE31240E4A}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{4C6950EE-F07F-4AD9-B3A1-1F415A21C43E}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{4D1F8B51-C064-4BF8-A857-9EC41141C39C}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{50B49499-E692-4F30-B426-88E733A2BA5C}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{65C5F15E-08A7-4C35-AD9B-2BB303AFE2AF}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{693B05FF-9D0E-4116-A4B7-E64E9326ABC5}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{75A0FC8E-BB6C-4B6F-81E9-343A0295C191}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{7AEF4D4C-4995-4871-AE4A-4EDF4C325804}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{888085CB-104A-4220-B155-DCAECA7AB297}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{90A63060-ADEE-4018-AA5A-75EFC0E0CAFC}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{A2330A92-83BF-49DD-9B00-4B327254B561}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{A56757DD-E414-4006-96BE-169AF19DE645}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{A95527A2-4516-42F5-B510-6550D953644E}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{A9FCF1BA-E03C-4BC5-8558-504475820515}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{ABE97DAE-0326-4475-BCF7-40C558A53E6A}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{AC7B7C6B-5BDD-48B0-BC4A-52154AC53FAE}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{B1EE5BE5-7EA6-47C4-B568-4FD0D55D35DE}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{B298C134-6EA6-48F3-AE15-3026FEDF86B9}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{B30581D6-78FD-48D7-A19E-01FDDDAA1CB3}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{B669B416-C649-44CE-AFBB-6EFB3F5BDDA2}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{BADB554D-1B08-4EA5-8E29-CBC12261C5DE}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{BAFC1672-A590-48F5-AAB4-5B8361D10C3E}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{BFB91970-E545-4022-8171-DA458BE937A0}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{C005E709-03FD-48C4-9456-D100481A4203}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{D9CAAA37-4D3B-40F5-83D4-7A3233D8C4F8}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{E6B0F873-999A-4E1B-A7C2-885E521015A1}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{ED9B7B59-0BCB-4F53-B415-34D9342577CD}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{EF2567A6-05D1-42F4-88F2-724A0EE8DD44}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{F0B97768-4B26-4075-9FC8-67669573EC20}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{F6A6E0BA-55D7-4A11-BEAB-C105FC9A7909}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{FE54C698-F6F2-4B54-B759-9353910DDA82}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). C:\WINDOWS\system32\{FECBBDAF-0634-4A9B-B220-A47B9F6A9367}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). ::Report end
Ignore my last post.

Please do this:

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Browse to c:\fixwareout folder, Fixit.bat.

This will start Fixwareout again.

After the reboot, post:

1. The fixwareout report

2. A new HijackThis! log

Into this thread.
:)
Fixwareout ver 1.003
Last edited 07/1/2006
Post this report in the forums please

Reg Entries that were deleted
…

Microsoft ® Windows Script Host Version 5.6
Random Runs removed from HKLM
…

PLEASE NOTE, There WILL be LEGIT FILES LISTED. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
Example ipsec6.exe is legitimate

»»»»» Search by size and names…

»»»»» Misc files

»»»»» Checking for older varients covered by the Rem3 tool

»»»»»
Search five digit cs, dm and jb files
This WILL/CAN also list Legit Files, Submit them at Virustotal
Other suspects
Directory of C:\WINDOWS\system32
{596D586F-4722-418D-A075-622BE10C550B}.exe
{9D4B2060-2C19-4C6D-A656-1CC4430D9F04}.exe
{BB5DEEF7-F520-4088-9F9A-007FFE0EFD85}.exe


————————————————————



sorry, i obviously had a couple of windows open when i ran this …hope it hasn't made any difference.
stillwill


Logfile of HijackThis v1.99.0
Scan saved at 22:26:11, on 08/08/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\ssoftsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\System32\rundll32.exe
C:\Documents and Settings\Omni\My Documents\My Deliveries\SPYWARE TOOLS\hijackthisnew\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BTopenworld
R3 - URLSearchHook: (no name) - {500F5A07-1175-6909-99D3-F001C5911E1E} - iehelper.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [TotalRecorderScheduler] C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.btinternet.com/
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {F04F4F32-6457-401A-8169-D2773DDFF930} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/…ropper1_6uk.cab
O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: EPSON Printer Status Agent2 - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sony SPTI Service - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: Cryptainer service - Unknown - ssoftsrv.exe (file missing)
O23 - Service: TrueVector Internet Monitor - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI