Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 91701 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

Help needed to identify Trojans from logfile please


  • This topic is locked This topic is locked
26 replies to this topic

#1 trojanedbrian

trojanedbrian

    New Member

  • Authentic Member
  • Pip
  • 14 posts

Posted 26 February 2007 - 03:21 PM

PC runs slow, slow to boot up, browser 'grabbed' every other page.



Logfile of HijackThis v1.99.1
Scan saved at 23:40:50, on 25/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Dad\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.co.uk/0SEENGB/SAOS01
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bbc.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [hpppta] C:\Program Files\Hewlett-Packard\HP PrecisionScan\PrecisionScan\hpppta.exe /ICON
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Trend Micro Security Services - {D5E1CDC8-64B9-4f8c-8155-FC3B6D6749F7} - http://tmss.trendmic...CJBCJAFCCDJJGBD (file missing)
O9 - Extra 'Tools' menuitem: Trend Micro Security Services - {D5E1CDC8-64B9-4f8c-8155-FC3B6D6749F7} - http://tmss.trendmic...CJBCJAFCCDJJGBD (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.co.uk
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.h...staller_gmn.cab
O16 - DPF: {26CBF141-7D0F-46E1-AA06-718958B6E4D2} - http://download.ebay.../UK/install.cab
O16 - DPF: {410A8B3C-7CCB-40E8-8B11-28B099E5C488} (Trend Micro Security Services Control) - http://tmss.trendmic...TMSSReportW.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1093981054625
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1135023793578
O16 - DPF: {9B17FE0E-51F2-4692-8B32-8EFB805FC0E7} (HPObjectInstaller Class) - http://h30155.www3.h...edsolutions.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Windows Server Management Services (WSMSPSVC) - Unknown owner - C:\WINDOWS\navsvc.exe (file missing)

Edited by trojanedbrian, 26 February 2007 - 03:51 PM.

    Advertisements

Register to Remove


#2 Susan528

Susan528

    SuperMember

  • Authentic Member
  • PipPipPipPipPip
  • 3,194 posts

Posted 27 February 2007 - 06:14 AM

Hello trojanedbrian and Welcome to TomCoyote,

No Firewall Onboard

Also I do not see a firewall application installed. Perhaps you have a hardware firewall but a combination of both a software firewall and a hardware firewall is better. Just be sure there are no conflicts. Please do not rely solely on the Windows XP firewall. Using a software firewall other than the XP firewall will allow you to give/deny access for applications that want to go online. Select one of these, or another of your choice:Test your Firewall - Please test your firewall and make sure it is working properly.
Test Firewall

================

SDFix

Also download SDFix.zip
and save it to the Desktop.

Right click the SDFix.zip folder
Select: Extract All to extract it to its own folder on the Desktop.

====
Start the computer in Safe Mode :
-When the machine first starts again, tap the F8 key repeatedly until you are presented with a Windows XP Advanced Options menu.
-Select the option for Safe Mode using the arrow keys.
-Press Enter to boot into Safe Mode.

====
Open the SDFix folder on the Desktop, and double click RunThis.bat to start the script.
Type Y to begin the cleanup process.
The process removes any Trojan Services or Registry Entries found, and then prompts you to press any key to Reboot.

Press any key to restart the PC.
When the PC restarts the SDFix will run again and complete the removal process
It then displays Finished
Press any key to end the script and load the Desktop icons.

Once the Desktop icons load, the SDFix report opens on screen and saves itself in the SDFix folder as Report.txt.

===================
Please print out or copy these instructions/tutorial to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.

Please download AVG Anti-Spyware to your Desktop or to your usual Download Folder.
http://www.ewido.net/en/download/
  • Install AVG Anti-Spyware by double clicking the installer.
  • Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked.
  • On the main screen under Your Computer's security
    • Click on Change state next to Resident shield. It should now change to inactive.
    • Click on Change state next to Automatic updates. It should now change to inactive.
    • Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
    • Wait until you see the Update succesfull message.
  • Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit.
  • Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update AVG Anti-spyware.
AVG Anti-Spyware manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.
______________________________

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
______________________________

Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
    • Under How to act?
      • Click on Recommended Action and choose Quarantine from the popup menu.
    • Under How to scan?
      • All checkboxes should be ticked.
    • Under Possibly unwanted software:
      • All checkboxes should be ticked.
    • Under Reports:
      • Select Automatically generate report after every scan and uncheck Only if threats were found.
    • Under What to scan?
      • Select Scan every file.
  • Click on the Scan tab.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
  • When the scan has finished, follow the instructions below.
    IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
    • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
    • At the bottom of the window click on the Apply all Actions button. (3)
      Posted Image
  • When done, click the Save Scan Report button. (4)
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
Reboot in Normal Mode.
______________________________

Please post:
  • Report.txt.
  • AVG Anti-spyware log
  • A new HijackThis log
Your may need several replies to post the requested logs, otherwise they might get cut off.

Edited by Susan528, 27 February 2007 - 06:21 AM.

Posted Image

Proud member of ASAP since 2005

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Want to help others? Come join us in the Class Room and learn how.

#3 trojanedbrian

trojanedbrian

    New Member

  • Authentic Member
  • Pip
  • 14 posts

Posted 27 February 2007 - 06:20 PM

Thanks for your help - you've done this more than a few times!

I have an external Firewall / Router - tested as Secure.

I still appear to have the same problem.

Your instructions have been followed, data below:

SDFix: Version 1.68

Run by Dad - 27/02/2007 @ 20:59:52.57

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:

Name:
WSMSPSVC

Path:
"C:\WINDOWS\navsvc.exe"

WSMSPSVC Deleted

Restoring Windows Registry Entries
Restoring Default Hosts File


Rebooting...

Normal Mode:
Checking Files:

Below files will be copied to Backups folder then removed:

C:\WINDOWS\Temp\removalfile.bat - Deleted



ADS Check:

C:\WINDOWS\system32
No streams found.


Final Check:

Remaining Services:
------------------


Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\Maxis\\SimCity 3000 UK Edition\\Apps\\Updater\\UPDATER.EXE"="C:\\Program Files\\Maxis\\SimCity 3000 UK Edition\\Apps\\Updater\\UPDATER.EXE:*:Disabled:SC3UpdaterMFC"
"C:\\Program Files\\SpeedTouch\\Dr SpeedTouch\\drst.exe"="C:\\Program Files\\SpeedTouch\\Dr SpeedTouch\\drst.exe:*:Enabled:Dr SpeedTouch"
"C:\\WINDOWS\\system32\\sessmgr.exe"="C:\\WINDOWS\\system32\\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Disabled:Internet Explorer"
"C:\\Program Files\\BAMZOOKi Zook Kit\\Bonsai.exe"="C:\\Program Files\\BAMZOOKi Zook Kit\\Bonsai.exe:*:Disabled:Bonsai"
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"="C:\\Program Files\\Real\\RealPlayer\\realplay.exe:*:Disabled:RealPlayer"
"C:\\Documents and Settings\\Dad\\Local Settings\\Temp\\usmt\\migwiz.exe"="C:\\Documents and Settings\\Dad\\Local Settings\\Temp\\usmt\\migwiz.exe:*:Enabled:Files and Settings Transfer Wizard"
"C:\\WINDOWS\\system32\\usmt\\migwiz.exe"="C:\\WINDOWS\\system32\\usmt\\migwiz.exe:*:Enabled:Files and Settings Transfer Wizard"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG7\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe:*:Enabled:avgcc.exe"


[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"


Remaining Files:
---------------

Backups Folder: - C:\SDFix\backups\backups.zip


Checking For Files with Hidden Attributes :

C:\Documents and Settings\Dad\Local Settings\Temp\aglntdxt.dll
C:\Documents and Settings\Dad\Local Settings\Temp\ahoetuxa.dll
C:\Documents and Settings\Dad\Local Settings\Temp\awaxrnep.dll
C:\Documents and Settings\Dad\Local Settings\Temp\bpxvodvk.dll
C:\Documents and Settings\Dad\Local Settings\Temp\cagpohvq.dll
C:\Documents and Settings\Dad\Local Settings\Temp\cavkgwqu.dll
C:\Documents and Settings\Dad\Local Settings\Temp\cbxloxql.dll
C:\Documents and Settings\Dad\Local Settings\Temp\cnwxvcuf.dll
C:\Documents and Settings\Dad\Local Settings\Temp\ctnknkpk.dll
C:\Documents and Settings\Dad\Local Settings\Temp\ctsrrklv.dll
C:\Documents and Settings\Dad\Local Settings\Temp\dwdcehgm.dll
C:\Documents and Settings\Dad\Local Settings\Temp\egxciugh.dll
C:\Documents and Settings\Dad\Local Settings\Temp\eiolykau.dll
C:\Documents and Settings\Dad\Local Settings\Temp\fgpunuuk.dll
C:\Documents and Settings\Dad\Local Settings\Temp\fmmcgiql.dll
C:\Documents and Settings\Dad\Local Settings\Temp\fraiecdr.dll
C:\Documents and Settings\Dad\Local Settings\Temp\frxixmcw.dll
C:\Documents and Settings\Dad\Local Settings\Temp\gdaumlhc.dll
C:\Documents and Settings\Dad\Local Settings\Temp\glujofif.dll
C:\Documents and Settings\Dad\Local Settings\Temp\gnhsayir.dll
C:\Documents and Settings\Dad\Local Settings\Temp\gufdwyou.dll
C:\Documents and Settings\Dad\Local Settings\Temp\gvktnxlq.dll
C:\Documents and Settings\Dad\Local Settings\Temp\hbxrqfnc.dll
C:\Documents and Settings\Dad\Local Settings\Temp\hdhgdgda.dll
C:\Documents and Settings\Dad\Local Settings\Temp\hgcvyrjt.dll
C:\Documents and Settings\Dad\Local Settings\Temp\hukmmqqa.dll
C:\Documents and Settings\Dad\Local Settings\Temp\irjswkpp.dll
C:\Documents and Settings\Dad\Local Settings\Temp\jkqwgimc.dll
C:\Documents and Settings\Dad\Local Settings\Temp\jppkcskg.dll
C:\Documents and Settings\Dad\Local Settings\Temp\jqlxuyjr.dll
C:\Documents and Settings\Dad\Local Settings\Temp\juhfpncg.dll
C:\Documents and Settings\Dad\Local Settings\Temp\jyjeskis.dll
C:\Documents and Settings\Dad\Local Settings\Temp\kfcmvycq.dll
C:\Documents and Settings\Dad\Local Settings\Temp\kliymnns.dll
C:\Documents and Settings\Dad\Local Settings\Temp\ksplbqal.dll
C:\Documents and Settings\Dad\Local Settings\Temp\kvqwbtyx.dll
C:\Documents and Settings\Dad\Local Settings\Temp\lfthdvsn.dll
C:\Documents and Settings\Dad\Local Settings\Temp\lghahgob.dll
C:\Documents and Settings\Dad\Local Settings\Temp\ltcidftv.dll
C:\Documents and Settings\Dad\Local Settings\Temp\mghqffmm.dll
C:\Documents and Settings\Dad\Local Settings\Temp\mmjihvkm.dll
C:\Documents and Settings\Dad\Local Settings\Temp\mnlrrekq.dll
C:\Documents and Settings\Dad\Local Settings\Temp\moixerhl.dll
C:\Documents and Settings\Dad\Local Settings\Temp\obpurbfo.dll
C:\Documents and Settings\Dad\Local Settings\Temp\phpbngns.dll
C:\Documents and Settings\Dad\Local Settings\Temp\poweduda.dll
C:\Documents and Settings\Dad\Local Settings\Temp\pvglbugu.dll
C:\Documents and Settings\Dad\Local Settings\Temp\rcdprdjw.dll
C:\Documents and Settings\Dad\Local Settings\Temp\ruumuoct.dll
C:\Documents and Settings\Dad\Local Settings\Temp\rxsygqhx.dll
C:\Documents and Settings\Dad\Local Settings\Temp\uvqctbrg.dll
C:\Documents and Settings\Dad\Local Settings\Temp\vbgnjifo.dll
C:\Documents and Settings\Dad\Local Settings\Temp\vgfuoyca.dll
C:\Documents and Settings\Dad\Local Settings\Temp\vgnuxhxm.dll
C:\Documents and Settings\Dad\Local Settings\Temp\vnrmuxjh.dll
C:\Documents and Settings\Dad\Local Settings\Temp\vxwmkswp.dll
C:\Documents and Settings\Dad\Local Settings\Temp\wwbbfuxy.dll
C:\Documents and Settings\Dad\Local Settings\Temp\xcsgrqfx.dll
C:\Documents and Settings\Dad\Local Settings\Temp\xoqoriwe.dll
C:\Documents and Settings\Dad\Local Settings\Temp\xtbitsvl.dll
C:\Documents and Settings\Dad\Local Settings\Temp\yejdbywf.dll
C:\Documents and Settings\Dad\Local Settings\Temp\yypnmcav.dll
C:\Documents and Settings\Sarah\Local Settings\Temp\vguymyyy.dll
C:\WINDOWS\system32\awtqq.dll
C:\WINDOWS\system32\awtttuv.dll
C:\WINDOWS\system32\gebccax.dll
C:\WINDOWS\system32\jkhff.dll
C:\WINDOWS\system32\jkklljg.dll
C:\WINDOWS\system32\khfgffd.dll
C:\WINDOWS\system32\ljjifca.dll
C:\WINDOWS\system32\nnnnmno.dll
C:\WINDOWS\system32\qomljjg.dll
C:\WINDOWS\system32\qommlkl.dll
C:\WINDOWS\system32\ssqqoll.dll
C:\Documents and Settings\Dad\Local Settings\Temp\apqdvouo.exe
C:\Documents and Settings\Dad\Local Settings\Temp\clhrvxvl.exe
C:\Documents and Settings\Dad\Local Settings\Temp\dxxgotig.exe
C:\Documents and Settings\Dad\Local Settings\Temp\eslqsqiq.exe
C:\Documents and Settings\Dad\Local Settings\Temp\fgkrbjte.exe
C:\Documents and Settings\Dad\Local Settings\Temp\fglgnpwu.exe
C:\Documents and Settings\Dad\Local Settings\Temp\gbyfwqar.exe
C:\Documents and Settings\Dad\Local Settings\Temp\gptxmnwj.exe
C:\Documents and Settings\Dad\Local Settings\Temp\gxjrxddv.exe
C:\Documents and Settings\Dad\Local Settings\Temp\hhsfpiig.exe
C:\Documents and Settings\Dad\Local Settings\Temp\hynvrlsk.exe
C:\Documents and Settings\Dad\Local Settings\Temp\ieyenwxn.exe
C:\Documents and Settings\Dad\Local Settings\Temp\ijjloaeo.exe
C:\Documents and Settings\Dad\Local Settings\Temp\iqtympme.exe
C:\Documents and Settings\Dad\Local Settings\Temp\jbdqinmo.exe
C:\Documents and Settings\Dad\Local Settings\Temp\kibehqxx.exe
C:\Documents and Settings\Dad\Local Settings\Temp\mphxwnpl.exe
C:\Documents and Settings\Dad\Local Settings\Temp\nluplupn.exe
C:\Documents and Settings\Dad\Local Settings\Temp\nrqobfwe.exe
C:\Documents and Settings\Dad\Local Settings\Temp\ntmhgwml.exe
C:\Documents and Settings\Dad\Local Settings\Temp\ojijwxmj.exe
C:\Documents and Settings\Dad\Local Settings\Temp\qkhvjcgk.exe
C:\Documents and Settings\Dad\Local Settings\Temp\swbklmnx.exe
C:\Documents and Settings\Dad\Local Settings\Temp\tlyvfgdy.exe
C:\Documents and Settings\Dad\Local Settings\Temp\ulaufwec.exe
C:\Documents and Settings\Dad\Local Settings\Temp\vbijjglo.exe
C:\Documents and Settings\Dad\Local Settings\Temp\xcjdsyxp.exe
C:\Documents and Settings\Dad\Local Settings\Temp\xmrinjph.exe
C:\Documents and Settings\Sarah\Local Settings\Temp\vanlkfhh.exe
C:\Documents and Settings\All Users\DRM\Cache\Indiv03.tmp
C:\WINDOWS\system32\ffhkj.tmp

Add/Remove Programs List:

ECHO is off.
2004 Mahjongg
3D Chess Special Edition
Microsoft Office Access 2007
Ad-Aware SE Personal
Adobe Acrobat 7.0 Professional
Adobe Photoshop 7.0
ASUS Probe V2.21.08
AVG 7.5
AVG Anti-Rootkit Beta
Brain Power
Card & Board Deluxe 2
Cat & Mouse
Intel A/V Codecs V2.0
eGames Checkers
eGames GameButler
Microsoft Office Excel 2007
Frog Frenzy 2 - \"The Madness Continues\"
BAMZOOKi Zook Kit v1.0.91.1
HijackThis 1.99.1
HP PrecisionScan
Microsoft Internationalized Domain Names Mitigation APIs
Windows Internet Explorer 7
Canon Camera Window for ZoomBrowser EX
PowerQuest PartitionMagic 8.0
Canon Utilities File Viewer Utility 1.2
Turbo Lister
Canon Utilities RemoteCapture 2.7
Canon Internet Library for ZoomBrowser EX
Canon Utilities PhotoStitch 3.1
Intel® 537EP Modem
Living Scenes Jigsaw Puzzles 2.2
Memory Machine
Microsoft .NET Framework 1.1
Monkeys & Bananas Maze
MS Access 97 SP2
Microsoft Compression Client Pack 1.0 for Windows XP
MuVo Slim
Microsoft National Language Support Downlevel APIs
NVIDIA Drivers
Canon PhotoRecord
Microsoft Office Publisher 2007
Pyramid
QuickTime
RealPlayer
SereneScreen Aquarium Crystal
Macromedia Flash Player 8
SimCity 3000 UK Edition
Spybot - Search & Destroy 1.3
SpywareBlaster v3.5.1
Tomb Raider II
Tweak UI
Wanadoo Search Toolbar
Windows Genuine Advantage Validation Tool
Windows XP Service Pack 2
WinRAR archiver
Microsoft Office Word 2007
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Zoo Tycoon
The Sims Deluxe Edition
AutoUpdate
Image Resizer Powertoy for Windows XP
Microsoft Windows Journal Viewer
AutoCAD LT 2004
Camera Window
Windows Genuine Advantage v1.3.0254.0
PowerDVD
PartitionMagic
File Viewer Utility 1.2.2
DivX
DivX Player
Microsoft Office Professional Edition 2003
Microsoft Software Update for Web Folders (English) 12
Microsoft Office Access 2007
Microsoft Office Access MUI (English) 2007
Microsoft Office Excel 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Publisher 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Word 2007
Microsoft Office Word MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office FrontPage 2003
Microsoft Office Project Professional 2003
Microsoft Office Visio Professional 2003
Turbo Lister
Nero - Burning Rom
RemoteCapture 2.7.2
Adobe Acrobat 7.0 Professional
Adobe Reader 7.0.8
ArcSoft Camera Suite
DivX Converter
DivX Web Player
CIG
Logitech Gaming Software
Canon Utilities ZoomBrowser EX
Marvell Miniport Driver
Microsoft .NET Framework 1.1
NvMixer
Dorling Kindersley XP Update
Microsoft Plus! for Windows XP
PhotoStitch
HighMAT Extension to Microsoft Windows XP CD Writing Wizard

Finished


---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 23:42:59 27/02/2007

+ Scan result:



C:\WINDOWS\system32\awtttuv.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\WINDOWS\system32\gebccax.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\WINDOWS\system32\jkklljg.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\WINDOWS\system32\khfgffd.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ljjifca.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\WINDOWS\system32\nnnnmno.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\WINDOWS\system32\qomljjg.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\WINDOWS\system32\qommlkl.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ssqqoll.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0E024C5D-03DF-4DE5-AC56-9A1BE5B97F9C}\RP408\A0041245.dll -> Adware.WinAntiSpyware : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0E024C5D-03DF-4DE5-AC56-9A1BE5B97F9C}\RP408\A0041246.exe -> Adware.WinAntiSpyware : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0E024C5D-03DF-4DE5-AC56-9A1BE5B97F9C}\RP410\A0041977.exe -> Adware.WinFixer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0E024C5D-03DF-4DE5-AC56-9A1BE5B97F9C}\RP410\A0041978.exe -> Adware.WinFixer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0E024C5D-03DF-4DE5-AC56-9A1BE5B97F9C}\RP411\A0042432.exe -> Adware.WinFixer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0E024C5D-03DF-4DE5-AC56-9A1BE5B97F9C}\RP411\A0042433.exe -> Adware.WinFixer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0E024C5D-03DF-4DE5-AC56-9A1BE5B97F9C}\RP412\A0042888.exe -> Adware.WinFixer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0E024C5D-03DF-4DE5-AC56-9A1BE5B97F9C}\RP412\A0042889.exe -> Adware.WinFixer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0E024C5D-03DF-4DE5-AC56-9A1BE5B97F9C}\RP416\A0043199.exe -> Adware.WinFixer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0E024C5D-03DF-4DE5-AC56-9A1BE5B97F9C}\RP416\A0043200.exe -> Adware.WinFixer : Cleaned with backup (quarantined).
C:\Documents and Settings\Guest\Local Settings\Temporary Internet Files\Content.IE5\KRY32Z6J\google[1].htm -> Downloader.IstBar.z : Cleaned with backup (quarantined).
C:\Documents and Settings\Jan\Cookies\jan@217.73.66[2].txt -> TrackingCookie.217.73.66.16 : Cleaned.
C:\Documents and Settings\Sarah\Cookies\sarah@www.burstbeacon[2].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Sarah\Cookies\sarah@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Sarah\Cookies\sarah@www.burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Dad\Cookies\dad@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@com[2].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Dad\Cookies\dad@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\Sarah\Cookies\sarah@ehg-dig.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Sarah\Cookies\sarah@hypertracker[1].txt -> TrackingCookie.Hypertracker : Cleaned.
C:\Documents and Settings\Sarah\Cookies\sarah@image.masterstats[1].txt -> TrackingCookie.Masterstats : Cleaned.
C:\Documents and Settings\Sarah\Cookies\sarah@ads.realcastmedia[1].txt -> TrackingCookie.Realcastmedia : Cleaned.
C:\Documents and Settings\Dad\Cookies\dad@stats1.reliablestats[1].txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\Jan\Cookies\jan@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\Sarah\Cookies\sarah@ads1.revenue[1].txt -> TrackingCookie.Revenue : Cleaned.
C:\Documents and Settings\Jan\Cookies\jan@h.starware[1].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Jan\Cookies\jan@try.starware[1].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Sarah\Cookies\sarah@h.starware[1].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Sarah\Cookies\sarah@try.starware[1].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Sarah\Cookies\sarah@www.web-stat[1].txt -> TrackingCookie.Web-stat : Cleaned.
C:\Documents and Settings\Sarah\Cookies\sarah@yadro[1].txt -> TrackingCookie.Yadro : Cleaned.


::Report end



Logfile of HijackThis v1.99.1
Scan saved at 00:17:02, on 28/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Dad\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.co.uk/0SEENGB/SAOS01
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bbc.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [hpppta] C:\Program Files\Hewlett-Packard\HP PrecisionScan\PrecisionScan\hpppta.exe /ICON
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Trend Micro Security Services - {D5E1CDC8-64B9-4f8c-8155-FC3B6D6749F7} - http://tmss.trendmic...CJBCJAFCCDJJGBD (file missing)
O9 - Extra 'Tools' menuitem: Trend Micro Security Services - {D5E1CDC8-64B9-4f8c-8155-FC3B6D6749F7} - http://tmss.trendmic...CJBCJAFCCDJJGBD (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.co.uk
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.h...staller_gmn.cab
O16 - DPF: {26CBF141-7D0F-46E1-AA06-718958B6E4D2} - http://download.ebay.../UK/install.cab
O16 - DPF: {410A8B3C-7CCB-40E8-8B11-28B099E5C488} (Trend Micro Security Services Control) - http://tmss.trendmic...TMSSReportW.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1093981054625
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1135023793578
O16 - DPF: {9B17FE0E-51F2-4692-8B32-8EFB805FC0E7} (HPObjectInstaller Class) - http://h30155.www3.h...edsolutions.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

#4 Susan528

Susan528

    SuperMember

  • Authentic Member
  • PipPipPipPipPip
  • 3,194 posts

Posted 28 February 2007 - 06:42 AM

STEP 1.
======
Delete Files with Killbox

Download Pocket Killbox from http://www.downloads...org/KillBox.zip and unzip it; save it to your Desktop. DO NOT RUN IT YET.
==========
Double-click on KillBox.exe to launch the program. It is the red circle with a large white X in it
- Highlight the files in bold RED below and press the Ctrl key and the C key at the same time to copy them to the clipboard
C:\Documents and Settings\Dad\Local Settings\Temp\aglntdxt.dll
C:\Documents and Settings\Dad\Local Settings\Temp\ahoetuxa.dll
C:\Documents and Settings\Dad\Local Settings\Temp\awaxrnep.dll
C:\Documents and Settings\Dad\Local Settings\Temp\bpxvodvk.dll
C:\Documents and Settings\Dad\Local Settings\Temp\cagpohvq.dll
C:\Documents and Settings\Dad\Local Settings\Temp\cavkgwqu.dll
C:\Documents and Settings\Dad\Local Settings\Temp\cbxloxql.dll
C:\Documents and Settings\Dad\Local Settings\Temp\cnwxvcuf.dll
C:\Documents and Settings\Dad\Local Settings\Temp\ctnknkpk.dll
C:\Documents and Settings\Dad\Local Settings\Temp\ctsrrklv.dll
C:\Documents and Settings\Dad\Local Settings\Temp\dwdcehgm.dll
C:\Documents and Settings\Dad\Local Settings\Temp\egxciugh.dll
C:\Documents and Settings\Dad\Local Settings\Temp\eiolykau.dll
C:\Documents and Settings\Dad\Local Settings\Temp\fgpunuuk.dll
C:\Documents and Settings\Dad\Local Settings\Temp\fmmcgiql.dll
C:\Documents and Settings\Dad\Local Settings\Temp\fraiecdr.dll
C:\Documents and Settings\Dad\Local Settings\Temp\frxixmcw.dll
C:\Documents and Settings\Dad\Local Settings\Temp\gdaumlhc.dll
C:\Documents and Settings\Dad\Local Settings\Temp\glujofif.dll
C:\Documents and Settings\Dad\Local Settings\Temp\gnhsayir.dll
C:\Documents and Settings\Dad\Local Settings\Temp\gufdwyou.dll
C:\Documents and Settings\Dad\Local Settings\Temp\gvktnxlq.dll
C:\Documents and Settings\Dad\Local Settings\Temp\hbxrqfnc.dll
C:\Documents and Settings\Dad\Local Settings\Temp\hdhgdgda.dll
C:\Documents and Settings\Dad\Local Settings\Temp\hgcvyrjt.dll
C:\Documents and Settings\Dad\Local Settings\Temp\hukmmqqa.dll
C:\Documents and Settings\Dad\Local Settings\Temp\irjswkpp.dll
C:\Documents and Settings\Dad\Local Settings\Temp\jkqwgimc.dll
C:\Documents and Settings\Dad\Local Settings\Temp\jppkcskg.dll
C:\Documents and Settings\Dad\Local Settings\Temp\jqlxuyjr.dll
C:\Documents and Settings\Dad\Local Settings\Temp\juhfpncg.dll
C:\Documents and Settings\Dad\Local Settings\Temp\jyjeskis.dll
C:\Documents and Settings\Dad\Local Settings\Temp\kfcmvycq.dll
C:\Documents and Settings\Dad\Local Settings\Temp\kliymnns.dll
C:\Documents and Settings\Dad\Local Settings\Temp\ksplbqal.dll
C:\Documents and Settings\Dad\Local Settings\Temp\kvqwbtyx.dll
C:\Documents and Settings\Dad\Local Settings\Temp\lfthdvsn.dll
C:\Documents and Settings\Dad\Local Settings\Temp\lghahgob.dll
C:\Documents and Settings\Dad\Local Settings\Temp\ltcidftv.dll
C:\Documents and Settings\Dad\Local Settings\Temp\mghqffmm.dll
C:\Documents and Settings\Dad\Local Settings\Temp\mmjihvkm.dll
C:\Documents and Settings\Dad\Local Settings\Temp\mnlrrekq.dll
C:\Documents and Settings\Dad\Local Settings\Temp\moixerhl.dll
C:\Documents and Settings\Dad\Local Settings\Temp\obpurbfo.dll
C:\Documents and Settings\Dad\Local Settings\Temp\phpbngns.dll
C:\Documents and Settings\Dad\Local Settings\Temp\poweduda.dll
C:\Documents and Settings\Dad\Local Settings\Temp\pvglbugu.dll
C:\Documents and Settings\Dad\Local Settings\Temp\rcdprdjw.dll
C:\Documents and Settings\Dad\Local Settings\Temp\ruumuoct.dll
C:\Documents and Settings\Dad\Local Settings\Temp\rxsygqhx.dll
C:\Documents and Settings\Dad\Local Settings\Temp\uvqctbrg.dll
C:\Documents and Settings\Dad\Local Settings\Temp\vbgnjifo.dll
C:\Documents and Settings\Dad\Local Settings\Temp\vgfuoyca.dll
C:\Documents and Settings\Dad\Local Settings\Temp\vgnuxhxm.dll
C:\Documents and Settings\Dad\Local Settings\Temp\vnrmuxjh.dll
C:\Documents and Settings\Dad\Local Settings\Temp\vxwmkswp.dll
C:\Documents and Settings\Dad\Local Settings\Temp\wwbbfuxy.dll
C:\Documents and Settings\Dad\Local Settings\Temp\xcsgrqfx.dll
C:\Documents and Settings\Dad\Local Settings\Temp\xoqoriwe.dll
C:\Documents and Settings\Dad\Local Settings\Temp\xtbitsvl.dll
C:\Documents and Settings\Dad\Local Settings\Temp\yejdbywf.dll
C:\Documents and Settings\Dad\Local Settings\Temp\yypnmcav.dll
C:\Documents and Settings\Sarah\Local Settings\Temp\vguymyyy.dll
C:\Documents and Settings\Dad\Local Settings\Temp\apqdvouo.exe
C:\Documents and Settings\Dad\Local Settings\Temp\clhrvxvl.exe
C:\Documents and Settings\Dad\Local Settings\Temp\dxxgotig.exe
C:\Documents and Settings\Dad\Local Settings\Temp\eslqsqiq.exe
C:\Documents and Settings\Dad\Local Settings\Temp\fgkrbjte.exe
C:\Documents and Settings\Dad\Local Settings\Temp\fglgnpwu.exe
C:\Documents and Settings\Dad\Local Settings\Temp\gbyfwqar.exe
C:\Documents and Settings\Dad\Local Settings\Temp\gptxmnwj.exe
C:\Documents and Settings\Dad\Local Settings\Temp\gxjrxddv.exe
C:\Documents and Settings\Dad\Local Settings\Temp\hhsfpiig.exe
C:\Documents and Settings\Dad\Local Settings\Temp\hynvrlsk.exe
C:\Documents and Settings\Dad\Local Settings\Temp\ieyenwxn.exe
C:\Documents and Settings\Dad\Local Settings\Temp\ijjloaeo.exe
C:\Documents and Settings\Dad\Local Settings\Temp\iqtympme.exe
C:\Documents and Settings\Dad\Local Settings\Temp\jbdqinmo.exe
C:\Documents and Settings\Dad\Local Settings\Temp\kibehqxx.exe
C:\Documents and Settings\Dad\Local Settings\Temp\mphxwnpl.exe
C:\Documents and Settings\Dad\Local Settings\Temp\nluplupn.exe
C:\Documents and Settings\Dad\Local Settings\Temp\nrqobfwe.exe
C:\Documents and Settings\Dad\Local Settings\Temp\ntmhgwml.exe
C:\Documents and Settings\Dad\Local Settings\Temp\ojijwxmj.exe
C:\Documents and Settings\Dad\Local Settings\Temp\qkhvjcgk.exe
C:\Documents and Settings\Dad\Local Settings\Temp\swbklmnx.exe
C:\Documents and Settings\Dad\Local Settings\Temp\tlyvfgdy.exe
C:\Documents and Settings\Dad\Local Settings\Temp\ulaufwec.exe
C:\Documents and Settings\Dad\Local Settings\Temp\vbijjglo.exe
C:\Documents and Settings\Dad\Local Settings\Temp\xcjdsyxp.exe
C:\Documents and Settings\Dad\Local Settings\Temp\xmrinjph.exe
C:\Documents and Settings\Sarah\Local Settings\Temp\vanlkfhh.exe
C:\WINDOWS\system32\ffhkj.tmp


In Killbox click on the File menu and then the Paste from Clipboard item
in the Full Path of File to Delete field drop down the arrow and make sure that all of the files are listed
(Please note that the tool checks your computer for the presence of the files pasted into the box so if files are not present, it is possible that you might not see all files you pasted into the box.)
  • Click the option to Delete on Reboot
  • Click End Explorer Shell while Killing File
  • Click All Files right of the flashing green "Single files"
  • Click Yes when it asks "Files will be Removed on Reboot, Do you want to reboot now?"
(Note: If you get a "PendingFileRenameOperations Registry Data has been Removed by External Process!" message then just reboot manually)

If you have any issues with this method you can copy and paste the lines one at a time into the killbox top box. Then click the "Single File" button. Then click the Red X ...and for the confirmation message that will appear, you will need to click Yes. A second message will ask to Reboot now? you will need to click No until the last one at which time you click yes to allow the reboot.

STEP 2.
======
Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will shutdown your computer, click OK.
  • Turn your computer back on.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log.

Posted Image

Proud member of ASAP since 2005

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Want to help others? Come join us in the Class Room and learn how.

#5 trojanedbrian

trojanedbrian

    New Member

  • Authentic Member
  • Pip
  • 14 posts

Posted 28 February 2007 - 01:32 PM

Thanks again. Data Requested:

C:\WINDOWS\system32\akxmunae.exe
C:\WINDOWS\system32\ffhkj.bak1
C:\WINDOWS\system32\ffhkj.bak2
C:\WINDOWS\system32\ffhkj.ini
C:\WINDOWS\system32\ffhkj.ini2
C:\WINDOWS\system32\jkhff.dll
C:\WINDOWS\system32\qmekvkdy.ini
C:\WINDOWS\system32\ydkvkemq.dll


Logfile of HijackThis v1.99.1
Scan saved at 19:31:14, on 28/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Dad\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.co.uk/0SEENGB/SAOS01
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bbc.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {AC9D3DFE-2B52-4ACC-A034-FEF1F99C59C5} - C:\WINDOWS\system32\jkhff.dll (file missing)
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {B5E77A25-8054-4098-8E1C-487B59FE2D3C} - C:\WINDOWS\system32\gebccax.dll (file missing)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [hpppta] C:\Program Files\Hewlett-Packard\HP PrecisionScan\PrecisionScan\hpppta.exe /ICON
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Trend Micro Security Services - {D5E1CDC8-64B9-4f8c-8155-FC3B6D6749F7} - http://tmss.trendmic...CJBCJAFCCDJJGBD (file missing)
O9 - Extra 'Tools' menuitem: Trend Micro Security Services - {D5E1CDC8-64B9-4f8c-8155-FC3B6D6749F7} - http://tmss.trendmic...CJBCJAFCCDJJGBD (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.co.uk
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.h...staller_gmn.cab
O16 - DPF: {26CBF141-7D0F-46E1-AA06-718958B6E4D2} - http://download.ebay.../UK/install.cab
O16 - DPF: {410A8B3C-7CCB-40E8-8B11-28B099E5C488} (Trend Micro Security Services Control) - http://tmss.trendmic...TMSSReportW.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1093981054625
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1135023793578
O16 - DPF: {9B17FE0E-51F2-4692-8B32-8EFB805FC0E7} (HPObjectInstaller Class) - http://h30155.www3.h...edsolutions.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O20 - Winlogon Notify: gebccax - gebccax.dll (file missing)
O20 - Winlogon Notify: jkklljg - jkklljg.dll (file missing)
O20 - Winlogon Notify: qomljjg - qomljjg.dll (file missing)
O20 - Winlogon Notify: ssqqoll - ssqqoll.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

#6 Susan528

Susan528

    SuperMember

  • Authentic Member
  • PipPipPipPipPip
  • 3,194 posts

Posted 28 February 2007 - 02:23 PM

Scan with HijackThis. Place a check against each of the following:
O2 - BHO: (no name) - {AC9D3DFE-2B52-4ACC-A034-FEF1F99C59C5} - C:\WINDOWS\system32\jkhff.dll (file missing)
O2 - BHO: (no name) - {B5E77A25-8054-4098-8E1C-487B59FE2D3C} - C:\WINDOWS\system32\gebccax.dll (file missing)
O20 - Winlogon Notify: gebccax - gebccax.dll (file missing)
O20 - Winlogon Notify: jkklljg - jkklljg.dll (file missing)
O20 - Winlogon Notify: qomljjg - qomljjg.dll (file missing)
O20 - Winlogon Notify: ssqqoll - ssqqoll.dll (file missing)

Close all windows or browsers except for Hijackthis. Click on Fix Checked when finished and exit HijackThis.

======
Download L2mfix from one of these two locations:

http://www.atribune....oads/l2mfix.exe
http://www.downloads....org/l2mfix.exe

You may receive pop-up asking if you will allow script to run when you perform the following instructions. Please allow the script to run.

Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. Double click l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing enter. This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log. Save the contents of that log and copy and paste it into your next reply.

IMPORTANT: Do NOT run option #2 OR any other files in the l2mfix folder until you are asked to do so!

If you receive, while running option #1, an error similar like: ''C:\windows\system32\cmd.exe
C:\windows\system32\autoexec.nt the system file is not suitable for running ms-dos and microsoft windows applications. choose close to terminate the application.."...then please use option 5 or the web page link in the l2mfix folder to solve this error condition. do not run the fix portion without fixing this first.



Please post (reply) with a new hijackthis log and the log from the l2mfix.
Posted Image

Proud member of ASAP since 2005

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Want to help others? Come join us in the Class Room and learn how.

#7 trojanedbrian

trojanedbrian

    New Member

  • Authentic Member
  • Pip
  • 14 posts

Posted 28 February 2007 - 03:12 PM

Sorry, can't find L2mfix.exe on sites - is Look2Me-destroyer.exe a suitable equivalent?

#8 Susan528

Susan528

    SuperMember

  • Authentic Member
  • PipPipPipPipPip
  • 3,194 posts

Posted 28 February 2007 - 09:03 PM

Look2Me-destroyer.exe will not work. You have a Vundo infection and I like the report from the L2mfix.exe to study the files to determine if we got rid of them all. The report gives information that one could use to see files indicating a L2Me or Vundo infection.

You should be able to click one of the links that I gave you about and then the l2mfix.exe should download. Maybe something is preventing the download?

If you cannot get the l2mfix.exe then please do the following:

Download ComboScan to your Desktop.
  • Close all applications and windows.
  • Double-click on comboscan.exe to run it, and follow the prompts.
  • The scan may take a minute. When the scan is complete, a text file will open ComboScan.txt
Extra Note: When running Comboscan, some firewalls may warn that sigcheck.exe is trying to access the internet - please ensure that you allow sigcheck.exe permission to do so. Also, it may happen that your Antivirus flags Comboscan as suspicious. Please allow the Comboscan to run and don't let your Antivirus delete it. (In this case, it may be better to temporary disable your Antivirus)

Please post (Reply) with the Comboscan.txt from the Comboscan
Posted Image

Proud member of ASAP since 2005

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Want to help others? Come join us in the Class Room and learn how.

#9 trojanedbrian

trojanedbrian

    New Member

  • Authentic Member
  • Pip
  • 14 posts

Posted 01 March 2007 - 11:42 AM

Hi - eventually managed to get l2mfix file via another source.

Info as requested:

L2MFIX find log 051206
These are the registry keys present
**********************************************************************************
Winlogon/notify:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
"Logon"="WLEventLogon"
"Logoff"="WLEventLogoff"
"Startup"="WLEventStartup"
"Shutdown"="WLEventShutdown"
"StartScreenSaver"="WLEventStartScreenSaver"
"StopScreenSaver"="WLEventStopScreenSaver"
"Lock"="WLEventLock"
"Unlock"="WLEventUnlock"
"StartShell"="WLEventStartShell"
"PostShell"="WLEventPostShell"
"Disconnect"="WLEventDisconnect"
"Reconnect"="WLEventReconnect"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000000
"SafeMode"=dword:00000001
"MaxWait"=dword:ffffffff
"DllName"=hex(2):57,00,67,00,61,00,4c,00,6f,00,67,00,6f,00,6e,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Event"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon\Settings]
"Data"=hex:01,00,00,00,d0,8c,9d,df,01,15,d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,\
00,00,46,58,b6,ff,bb,46,94,45,ae,fa,06,76,b8,93,8b,52,04,00,00,00,04,00,00,\
00,53,00,00,00,03,66,00,00,a8,00,00,00,10,00,00,00,29,c4,85,71,ad,74,4b,5d,\
76,37,97,1e,d8,3c,97,9e,00,00,00,00,04,80,00,00,a0,00,00,00,10,00,00,00,26,\
2e,77,ac,5b,1f,f9,3f,f1,aa,d4,29,c0,7c,d3,4d,08,06,00,00,9f,ee,25,18,6a,5b,\
57,86,89,fe,83,e4,33,5f,74,14,77,fa,3e,ce,8f,e9,1b,e8,7b,2d,fb,51,c6,8a,75,\
4c,f3,db,6f,ac,dd,af,01,68,62,3b,4b,40,59,00,d6,e6,3f,7e,72,d9,8e,eb,67,e4,\
8e,d5,65,4c,82,9c,46,b0,68,77,94,ef,08,ba,a8,fa,45,a9,ba,d8,8c,88,99,36,d0,\
36,9b,df,81,fb,8c,bd,0a,16,e3,d2,9e,b4,e7,61,c8,a3,c3,53,9b,4b,b1,4e,c8,22,\
76,46,af,07,26,0b,fa,55,40,b6,65,8b,23,53,b7,8f,67,57,de,be,ff,62,9f,a6,74,\
d5,72,28,83,42,52,e7,1d,86,5d,48,89,97,7e,63,d8,22,e4,dc,b3,50,5b,a3,90,cb,\
f8,20,58,7e,a8,d7,76,5f,4c,74,27,ac,77,7e,b1,86,ea,f5,81,36,b8,87,12,b1,3e,\
15,c0,ab,fe,94,e1,50,55,b0,c4,43,0f,a8,75,5e,d4,db,41,86,58,1f,96,47,89,5b,\
64,ad,23,72,67,f0,e1,d9,55,7f,bc,60,f1,e7,51,52,8a,c2,34,28,3f,7f,b6,5d,9c,\
4d,e7,15,3b,4a,29,55,de,00,38,9d,33,4d,68,f9,c5,a8,f6,06,37,6d,9c,9f,af,67,\
4d,a7,f3,09,de,fc,06,73,70,2b,85,17,3f,3f,20,47,60,ff,c7,fa,9c,7e,99,83,89,\
45,2b,d7,69,1f,f4,5a,a9,8e,02,15,e1,0f,4b,df,81,5f,dd,ab,09,2f,e8,86,d8,cd,\
f4,2e,24,52,30,4e,ef,d4,2c,33,b2,56,4c,fb,f2,76,f8,81,d1,bd,6d,38,e7,62,f8,\
01,f9,55,9d,93,8a,9c,22,26,8d,49,3f,85,23,f8,ed,cf,02,4b,95,02,41,01,5a,a7,\
e7,db,55,14,1e,63,51,65,92,8d,4b,2b,23,bf,c1,78,36,1e,97,64,10,57,ab,45,1c,\
63,7b,a4,87,18,2f,cd,81,c4,e2,1e,3c,2f,ec,1a,ce,97,77,ff,a0,f4,48,67,c8,9d,\
48,be,28,5c,06,5a,80,0d,3f,dc,d6,74,dc,af,25,e0,06,e8,bf,d3,85,ae,00,c4,08,\
e5,d7,1a,80,45,f4,e0,8f,33,57,35,d0,5a,ae,06,bb,c2,03,55,8b,42,4c,aa,fe,76,\
a8,f0,49,4c,e9,50,1c,57,81,b1,a1,0a,cf,f0,ed,9d,d1,5d,82,1a,d7,8f,f0,4a,37,\
64,89,78,28,95,04,65,a3,f3,80,58,a2,6b,c7,ad,84,c0,20,6a,af,fc,44,aa,aa,f5,\
13,36,60,d9,15,54,25,52,5c,6a,18,f4,d3,57,e4,03,f9,d2,7e,be,c3,04,a1,98,94,\
c3,d7,34,71,14,52,3e,af,b4,ad,0d,e0,78,f9,3b,1c,f4,eb,64,40,ce,f5,06,51,1d,\
db,0c,8e,dd,74,6d,b3,86,19,97,7b,95,ab,3c,d1,64,2f,8c,dd,ae,b2,70,81,a2,06,\
6a,fc,d6,58,9c,5e,c9,88,fc,5a,ef,72,c7,07,ff,73,81,97,cd,40,5f,7d,24,06,0b,\
7a,cb,9c,01,f3,71,8a,6e,0d,25,08,38,ad,3e,19,99,2d,76,48,73,27,f3,94,b9,db,\
3d,73,98,92,fe,8a,e0,6b,23,83,d9,25,40,03,cf,1e,70,37,88,95,1a,e8,f7,12,06,\
e0,1e,68,37,41,8a,3e,42,c6,26,0c,4d,94,c9,ae,6a,11,97,68,72,0b,0e,a0,d2,f8,\
0c,dc,95,0e,09,ae,f5,22,e9,d5,d6,55,81,3c,a9,9b,ba,77,3b,99,ac,67,1c,7a,72,\
cb,7f,76,e4,82,12,2d,ea,ce,f5,28,15,c3,ab,6f,2b,56,c1,ce,0d,6f,e2,65,36,34,\
b4,fd,e6,79,ed,e2,1a,a0,81,3d,b7,f5,db,1c,5e,1d,35,9a,97,56,d0,14,de,d1,58,\
88,76,84,46,2d,c7,30,58,06,f1,85,49,a0,7c,e4,90,67,79,0f,9b,b6,ef,0d,ca,60,\
ac,bc,05,1a,f0,af,1c,b2,d8,1d,b6,a0,78,e9,0c,2b,0c,30,73,4a,6f,26,14,ec,5d,\
e9,9a,9f,6c,d4,72,cb,19,71,f0,1c,60,a5,c4,6f,7f,8b,c9,43,a0,e6,52,41,27,ac,\
34,9a,c1,b5,d9,2d,d1,7c,ff,b9,7a,6d,14,3b,ac,36,99,1f,f4,74,6d,df,93,c8,3f,\
c2,df,99,0a,6b,38,28,bb,2b,d1,87,c3,d5,d9,91,04,76,2f,5c,85,bf,43,b2,03,f6,\
93,11,79,b7,bc,73,f9,f3,9d,ad,13,84,fb,d6,12,4b,2d,e3,56,9f,bc,80,28,d2,3c,\
c1,ff,4b,62,b1,b6,d3,af,1d,3a,26,20,4c,ab,0a,dd,5b,5b,39,06,f4,83,e2,56,0e,\
90,a7,96,be,63,13,f9,ba,94,06,3c,88,5a,36,94,52,14,d9,b3,89,b8,a9,83,51,eb,\
4f,08,dd,a2,a5,29,0e,7d,cd,1f,ab,57,32,c1,da,e9,a6,a5,54,48,d4,04,65,6b,d8,\
f6,2b,cf,15,56,59,83,e1,5b,05,39,f0,7d,ab,fd,07,37,cc,fc,8b,f7,3e,b0,cc,cd,\
65,5b,41,84,26,5d,70,65,0b,8a,7e,25,bf,96,7f,21,21,50,42,f7,56,b9,c5,e2,65,\
4c,f9,aa,f9,1b,c0,73,06,dc,79,50,59,6e,97,61,7e,83,69,78,89,0b,0b,77,26,54,\
12,ce,ac,ac,0b,fb,68,cb,5f,5f,62,73,6d,ca,0c,9c,f3,2c,0e,06,76,66,d2,60,1f,\
8e,8a,c9,03,7b,20,82,ad,5f,8a,a5,54,2e,0e,b9,17,88,7b,21,28,3f,e9,35,9d,1a,\
1f,d0,91,c7,23,2c,1e,d6,71,c1,83,15,a8,af,d3,3d,98,01,35,a8,ff,dc,9c,0c,5c,\
6a,ac,5e,cd,22,8b,9f,37,56,1a,e5,27,b0,79,ce,12,02,0e,3f,ba,49,1c,d3,ad,3c,\
03,e5,7e,ff,48,33,9a,c8,8c,aa,07,73,50,c3,92,56,79,f9,11,f7,ea,13,3c,97,f7,\
8b,b1,c1,e4,79,ec,56,b4,03,cc,2a,5c,bb,e4,34,78,4c,54,6f,97,e1,a8,13,f5,b9,\
c8,16,a8,4e,be,dc,f4,73,af,a6,3e,59,72,f8,4a,f8,da,a1,19,12,56,36,65,2c,94,\
3d,60,b3,db,cb,b9,7f,f2,03,e4,98,9e,d3,69,4f,18,09,a7,12,8d,f3,b1,75,46,8d,\
1f,8b,eb,62,0d,ef,18,2e,00,c5,c6,a8,61,e0,63,6a,ad,2e,0b,63,5d,e5,89,dd,9b,\
49,16,8e,5d,4a,33,78,60,9d,3d,37,ee,1f,9c,58,4a,dc,d6,3c,88,94,6e,fd,50,29,\
cd,8a,60,b3,05,28,c2,63,66,00,d0,db,e2,ea,e5,d5,82,19,cf,d6,58,47,b1,17,e2,\
0f,1d,95,f3,5f,ff,24,39,73,da,63,d7,f8,96,7b,bb,b7,92,49,27,6f,0f,2e,7c,ad,\
78,ed,ee,2f,d3,e3,18,16,80,2b,a6,eb,80,9d,f9,54,4c,31,75,55,3d,ca,d9,96,8c,\
11,02,41,7f,92,51,15,b7,f1,95,60,25,3f,dc,a7,b6,e9,69,ad,49,70,e4,98,95,d9,\
a3,9b,c5,28,9a,b8,dc,a3,02,25,db,c9,54,d6,9b,79,34,59,45,af,d0,e9,2b,88,6b,\
c6,0f,81,58,e8,68,be,81,10,6c,10,5b,37,99,93,97,e2,26,68,77,55,27,af,d3,b0,\
2c,42,b1,13,c7,84,a2,0c,5f,4d,13,8b,33,38,3d,a2,f0,bb,4f,37,4c,a9,61,fe,a3,\
1f,52,9c,f9,12,85,e6,cc,d0,19,40,52,48,3d,ff,ad,a1,c0,a9,a7,1b,51,e6,93,79,\
84,8b,9f,70,e6,45,bb,a6,20,b4,26,16,b7,08,77,3a,2d,ee,cb,a2,1b,5c,bd,a9,c4,\
9f,e2,0e,1f,9f,64,a4,d7,bd,eb,ca,b7,02,14,00,00,00,e5,ff,c0,90,9d,8f,c7,87,\
e3,fc,3d,86,e5,a1,4f,5e,58,11,80,29

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

**********************************************************************************
useragent:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]

**********************************************************************************
Shell Extension key:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{00022613-0000-0000-C000-000000000046}"="Multimedia File Property Sheet"
"{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management"
"{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page"
"{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE Docfile Property Page"
"{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Shell extensions for sharing"
"{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
"{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Display Adapter CPL Extension"
"{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Display Monitor CPL Extension"
"{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL Extension"
"{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page"
"{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibility Page"
"{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler"
"{59099400-57FF-11CE-BD94-0020AF85B590}"="Disk Copy Extension"
"{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Shell extensions for Microsoft Windows Network objects"
"{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Monitor Management"
"{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management"
"{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Shell extensions for file compression"
"{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Shell Extension"
"{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
"{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption Context Menu"
"{85BBD920-42A0-1069-A2E4-08002B30309D}"="Briefcase"
"{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Ext"
"{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
"{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile"
"{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printers Security Page"
"{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Shell extensions for sharing"
"{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
"{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO Extension"
"{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign Extension"
"{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Network Connections"
"{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Network Connections"
"{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Scanners & Cameras"
"{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Scanners & Cameras"
"{905667aa-acd6-11d2-8080-00805f6596d2}"="Scanners & Cameras"
"{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Scanners & Cameras"
"{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Scanners & Cameras"
"{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
"{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
"{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Shell extensions for Windows Script Host"
"{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Link"
"{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
"{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
"{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Scheduled Tasks"
"{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Taskbar and Start Menu"
"{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Search"
"{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Run..."
"{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
"{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="E-mail"
"{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fonts"
"{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Administrative Tools"
"{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
"{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
"{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
"{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
"{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
"{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
"{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar"
"{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status"
"{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder"
"{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2"
"{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
"{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand"
"{30D02401-6A81-11d0-8274-00C04FD5AE38}"="IE Search Band"
"{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
"{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search"
"{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search"
"{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility"
"{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Address"
"{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox"
"{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete"
"{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
"{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List"
"{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List"
"{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
"{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar"
"{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Address Bar Parser"
"{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List"
"{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List"
"{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container"
"{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu"
"{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
"{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar"
"{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
"{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist"
"{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings"
"{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
"{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
"{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
"{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
"{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
"{FF393560-C2A7-11CF-BFF4-444553540000}"="History"
"{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
"{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen"
"{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
"{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
"{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
"{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="The Internet"
"{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
"{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
"{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder"
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
"{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
"{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder"
"{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
"{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
"{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
"{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
"{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
"{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
"{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
"{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Shell Application Manager"
"{0B124F8F-91F0-11D1-B8B5-006008059382}"="Installed Apps Enumerator"
"{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher"
"{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
"{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
"{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ file thumbnail extractor"
"{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Summary Info Thumbnail handler (DOCFILES)"
"{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML Thumbnail Extractor"
"{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
"{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Web Publishing Wizard"
"{add36aa8-751a-4579-a266-d66f5202ccbb}"="Print Ordering via the Web"
"{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object"
"{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Get a Passport Wizard"
"{7A9D77BD-5403-11d2-8785-2E0420524153}"="User Accounts"
"{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
"{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
"{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
"{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
"{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
"{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
"{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
"{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
"{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
"{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
"{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
"{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
"{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
"{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
"{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
"{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
"{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
"{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
"{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
"{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
"{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline Files Folder"
"{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
"{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
"{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
"{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
"{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
"{32714800-2E5F-11d0-8B85-00AA0044F941}"="For &People..."
"{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Burn Audio CD Context Menu Handler"
"{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Play as Playlist Context Menu Handler"
"{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
"{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults"
"{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Previous Versions Property Page"
"{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Previous Versions"
"{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder"
"{1D2680C9-0E2A-469d-B787-065558BC7D43}"="Fusion Cache"
"{1CDB2949-8F65-4355-8456-263E7C208A5D}"="Desktop Explorer"
"{1E9B04FB-F9E5-4718-997B-B8DA88302A47}"="Desktop Explorer Menu"
"{BDEADF00-C265-11D0-BCED-00A0C90AB50F}"="Web Folders"
"{42042206-2D85-11D3-8CFF-005004838597}"="Microsoft Office HTML Icon Handler"
"{506F4668-F13E-4AA1-BB04-B43203AB3CC0}"="{506F4668-F13E-4AA1-BB04-B43203AB3CC0}"
"{D66DC78C-4F61-447F-942B-3FB6980118CF}"="{D66DC78C-4F61-447F-942B-3FB6980118CF}"
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player"
"{1E2CDF40-419B-11D2-A5A1-002018648BA7}"="AVG Shell Extension"
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}"="WinRAR shell extension"
"{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802}"="Adobe.Acrobat.ContextMenu"
"{AC1DB655-4F9A-4c39-8AD2-A65324A4C446}"="Autodesk Drawing Preview"
"{36A21736-36C2-4C11-8ACB-D4136F2B57BD}"="AutoCAD Digital Signatures Icon Overlay Handler"
@=""
"{1530F7EE-5128-43BD-9977-84A4B0FAD7DF}"="PhotoToys"
"{BB7DF450-F119-11CD-8465-00AA00425D90}"="Microsoft Access Custom Icon Handler"
"{21569614-B795-46b1-85F4-E737A8DC09AD}"="Shell Search Band"
"{00E7B358-F65B-4dcf-83DF-CD026B94BFD4}"="Autoplay for SlideShow"
"{07C45BB1-4A8C-4642-A1F5-237E7215FF66}"="IE Microsoft BrowserBand"
"{1C1EDB47-CE22-4bbb-B608-77B48F83C823}"="IE Fade Task"
"{205D7A97-F16D-4691-86EF-F3075DCCA57D}"="IE Menu Desk Bar"
"{3028902F-6374-48b2-8DC6-9725E775B926}"="IE AutoComplete"
"{43886CD5-6529-41c4-A707-7B3C92C05E68}"="IE Navigation Bar"
"{44C76ECD-F7FA-411c-9929-1B77BA77F524}"="IE Menu Site"
"{4B78D326-D922-44f9-AF2A-07805C2A3560}"="IE Menu Band"
"{6038EF75-ABFC-4e59-AB6F-12D397F6568D}"="IE Microsoft History AutoComplete List"
"{6B4ECC4F-16D1-4474-94AB-5A763F2A54AE}"="IE Tracking Shell Menu"
"{6CF48EF8-44CD-45d2-8832-A16EA016311B}"="IE IShellFolderBand"
"{73CFD649-CD48-4fd8-A272-2070EA56526B}"="IE BandProxy"
"{98FF6D4B-6387-4b0a-8FBD-C5C4BB17B4F8}"="IE MRU AutoComplete List"
"{9A096BB5-9DC3-4D1C-8526-C3CBF991EA4E}"="IE RSS Feeder Folder"
"{9D958C62-3954-4b44-8FAB-C4670C1DB4C2}"="IE Microsoft Shell Folder AutoComplete List"
"{B31C5FAE-961F-415b-BAF0-E697A5178B94}"="IE Microsoft Multiple AutoComplete List Container"
"{BC476F4C-D9D7-4100-8D4E-E043F6DEC409}"="Microsoft Browser Architecture"
"{BFAD62EE-9D54-4b2a-BF3B-76F90697BD2A}"="IE Shell Rebar BandSite"
"{E6EE9AAC-F76B-4947-8260-A9F136138E11}"="IE Shell Band Site Menu"
"{F2CF5485-4E02-4f68-819C-B92DE9277049}"="&Links"
"{F83DAC1C-9BB9-4f2b-B619-09819DA81B0E}"="IE Registry Tree Options Utility"
"{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75}"="IE User Assist"
"{FDE7673D-2E19-4145-8376-BBD58C4BC7BA}"="IE Custom MRU AutoCompleted List"
"{993BE281-6695-4BA5-8A2A-7AACBFAAB69E}"="Microsoft Office Metadata Handler"
"{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97}"="Microsoft Office Thumbnail Handler"
"{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
"{35786D3C-B075-49b9-88DD-029876E11C01}"="Portable Devices"
"{D6791A63-E7E2-4fee-BF52-5DED8E86E9B8}"="Portable Devices Menu"
"{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}"="AVG7 Shell Extension"
"{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}"="AVG7 Find Extension"
"{00020D75-0000-0000-C000-000000000046}"="Microsoft Office Outlook Desktop Icon Handler"
"{0006F045-0000-0000-C000-000000000046}"="Microsoft Office Outlook Custom Icon Handler"

**********************************************************************************
HKEY ROOT CLASSIDS:
**********************************************************************************
Files Found are not all bad files:

C:\WINDOWS\SYSTEM32\
advpack.dll Mon 8 Jan 2007 19:00:48 A.... 124,928 122.00 K
awtqn.dll Wed 7 Feb 2007 21:00:16 A.... 7,186 7.02 K
awtqq.dll Mon 12 Feb 2007 19:28:38 ..SH. 277,592 271.09 K
awtsp.dll Thu 8 Feb 2007 1:02:58 A.... 7,186 7.02 K
awvtr.dll Thu 8 Feb 2007 1:30:16 A.... 7,186 7.02 K
awvvs.dll Fri 9 Feb 2007 19:14:02 A.... 7,186 7.02 K
awvvt.dll Thu 8 Feb 2007 20:05:38 A.... 7,186 7.02 K
awvvw.dll Fri 9 Feb 2007 19:04:16 A.... 7,120 6.95 K
corpol.dll Mon 8 Jan 2007 19:01:14 A.... 17,408 17.00 K
ddaba.dll Thu 8 Feb 2007 21:05:42 A.... 7,186 7.02 K
ddabc.dll Mon 12 Feb 2007 23:07:14 A.... 7,186 7.02 K
ddaya.dll Fri 9 Feb 2007 21:55:10 A.... 7,186 7.02 K
ddccb.dll Fri 9 Feb 2007 20:04:28 A.... 7,120 6.95 K
ddccd.dll Sun 11 Feb 2007 23:23:00 A.... 7,120 6.95 K
ddccy.dll Thu 8 Feb 2007 22:14:00 A.... 7,186 7.02 K
ddcya.dll Thu 8 Feb 2007 23:01:54 A.... 7,120 6.95 K
extmgr.dll Fri 12 Jan 2007 9:27:42 A.... 132,608 129.50 K
gebcd.dll Mon 12 Feb 2007 20:18:26 A.... 7,120 6.95 K
gebya.dll Mon 12 Feb 2007 20:10:52 A.... 7,186 7.02 K
gebyw.dll Sun 11 Feb 2007 23:24:08 A.... 7,186 7.02 K
gebyx.dll Thu 8 Feb 2007 21:55:26 A.... 7,186 7.02 K
geeba.dll Mon 12 Feb 2007 22:17:22 A.... 7,186 7.02 K
geeby.dll Thu 8 Feb 2007 22:05:46 A.... 7,186 7.02 K
ieakeng.dll Mon 8 Jan 2007 19:02:02 A.... 153,088 149.50 K
ieaksie.dll Mon 8 Jan 2007 19:02:02 A.... 230,400 225.00 K
ieakui.dll Mon 8 Jan 2007 19:02:02 A.... 161,792 158.00 K
ieapfltr.dll Mon 8 Jan 2007 19:02:02 ..... 383,488 374.50 K
iedkcs32.dll Mon 8 Jan 2007 19:02:02 A.... 384,000 375.00 K
ieframe.dll Fri 12 Jan 2007 9:27:42 ..... 6,054,400 5.77 M
iernonce.dll Mon 8 Jan 2007 19:02:04 A.... 44,544 43.50 K
iertutil.dll Mon 8 Jan 2007 19:02:04 A.... 266,752 260.50 K
jkhfc.dll Wed 7 Feb 2007 20:00:02 A.... 7,186 7.02 K
jkhhi.dll Wed 7 Feb 2007 19:32:28 A.... 7,186 7.02 K
jkkji.dll Sat 10 Feb 2007 1:03:44 A.... 7,120 6.95 K
jsproxy.dll Fri 12 Jan 2007 9:27:42 A.... 27,136 26.50 K
mljgh.dll Wed 7 Feb 2007 23:30:04 A.... 7,186 7.02 K
mljjg.dll Sun 11 Feb 2007 22:22:56 A.... 7,120 6.95 K
mljjk.dll Thu 8 Feb 2007 22:01:50 A.... 7,120 6.95 K
mlljh.dll Wed 7 Feb 2007 23:18:02 A.... 7,186 7.02 K
mlljk.dll Sat 10 Feb 2007 0:03:36 A.... 7,120 6.95 K
mllmn.dll Mon 12 Feb 2007 23:01:36 A.... 7,186 7.02 K
msfeeds.dll Fri 12 Jan 2007 9:27:42 ..... 458,752 448.00 K
msfeed~1.dll Fri 12 Jan 2007 9:27:42 ..... 51,712 50.50 K
mshtml.dll Fri 12 Jan 2007 9:27:42 A.... 3,580,416 3.41 M
mshtmled.dll Fri 12 Jan 2007 9:27:42 A.... 477,696 466.50 K
msrating.dll Mon 8 Jan 2007 19:03:02 A.... 193,024 188.50 K
mstime.dll Fri 12 Jan 2007 9:27:42 A.... 670,720 655.00 K
occache.dll Mon 8 Jan 2007 19:04:08 A.... 102,400 100.00 K
ogache~1.dll Tue 23 Jan 2007 15:15:22 A.... 676,224 660.38 K
pmkhf.dll Fri 9 Feb 2007 0:02:00 A.... 7,120 6.95 K
pmkhh.dll Fri 9 Feb 2007 23:55:28 A.... 7,186 7.02 K
pmnli.dll Tue 13 Feb 2007 0:07:20 A.... 7,186 7.02 K
pmnlj.dll Fri 9 Feb 2007 0:17:16 A.... 7,186 7.02 K
pmnlm.dll Thu 8 Feb 2007 21:17:00 A.... 7,186 7.02 K
pmnnk.dll Fri 9 Feb 2007 20:55:06 A.... 7,186 7.02 K
pmnnl.dll Sun 11 Feb 2007 21:23:58 A.... 7,186 7.02 K
pmnno.dll Mon 12 Feb 2007 21:17:24 A.... 7,186 7.02 K
shell32.dll Tue 19 Dec 2006 21:52:18 A.... 8,453,632 8.06 M
shsvcs.dll Tue 19 Dec 2006 21:52:18 A.... 134,656 131.50 K
ssqpm.dll Thu 8 Feb 2007 0:30:08 A.... 7,186 7.02 K
ssqrr.dll Mon 12 Feb 2007 0:23:04 A.... 7,120 6.95 K
ssqrs.dll Fri 9 Feb 2007 23:04:40 A.... 7,120 6.95 K
sstqo.dll Thu 8 Feb 2007 20:01:40 A.... 7,120 6.95 K
sstqp.dll Sat 10 Feb 2007 0:54:26 A.... 7,186 7.02 K
sstqr.dll Fri 9 Feb 2007 19:55:00 A.... 7,186 7.02 K
ssttq.dll Fri 9 Feb 2007 22:04:36 A.... 7,120 6.95 K
ssttr.dll Wed 7 Feb 2007 23:29:30 A.... 7,120 6.95 K
sstts.dll Thu 8 Feb 2007 0:29:36 A.... 7,120 6.95 K
url.dll Mon 8 Jan 2007 19:04:54 A.... 105,984 103.50 K
urlmon.dll Fri 12 Jan 2007 9:27:42 A.... 1,149,952 1.09 M
vtsqp.dll Fri 9 Feb 2007 0:14:12 A.... 7,186 7.02 K
vtsqq.dll Mon 12 Feb 2007 20:23:50 A.... 7,186 7.02 K
vtsqr.dll Fri 9 Feb 2007 22:55:14 A.... 7,186 7.02 K
vtstr.dll Fri 9 Feb 2007 21:04:32 A.... 7,120 6.95 K
vtsts.dll Sun 11 Feb 2007 22:24:04 A.... 7,186 7.02 K
vtstt.dll Thu 8 Feb 2007 1:29:42 A.... 7,120 6.95 K
vturp.dll Mon 12 Feb 2007 0:24:12 A.... 7,186 7.02 K
vtutq.dll Thu 8 Feb 2007 21:01:44 A.... 7,120 6.95 K
vtutu.dll Sun 11 Feb 2007 21:22:52 A.... 7,120 6.95 K
webcheck.dll Fri 12 Jan 2007 9:27:42 A.... 232,960 227.50 K
wiaservc.dll Tue 19 Dec 2006 18:16:48 A.... 333,824 326.00 K
wininet.dll Fri 12 Jan 2007 9:27:42 A.... 822,784 803.50 K

82 items found: 82 files (1 H/S), 0 directories.
Total of file sizes: 26,089,596 bytes 24.88 M
Locate .tmp files:

No matches found.
**********************************************************************************
Directory Listing of system files:
Volume in drive C has no label.
Volume Serial Number is E82F-ADEC

Directory of C:\WINDOWS\System32

14/02/2007 00:10 <DIR> dllcache
12/02/2007 19:28 277,592 awtqq.dll
31/08/2004 17:16 <DIR> Microsoft
1 File(s) 277,592 bytes
2 Dir(s) 21,175,865,344 bytes free




Logfile of HijackThis v1.99.1
Scan saved at 17:40:46, on 01/03/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Dad\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.co.uk/0SEENGB/SAOS01
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bbc.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [hpppta] C:\Program Files\Hewlett-Packard\HP PrecisionScan\PrecisionScan\hpppta.exe /ICON
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Trend Micro Security Services - {D5E1CDC8-64B9-4f8c-8155-FC3B6D6749F7} - http://tmss.trendmic...CJBCJAFCCDJJGBD (file missing)
O9 - Extra 'Tools' menuitem: Trend Micro Security Services - {D5E1CDC8-64B9-4f8c-8155-FC3B6D6749F7} - http://tmss.trendmic...CJBCJAFCCDJJGBD (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.co.uk
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.h...staller_gmn.cab
O16 - DPF: {26CBF141-7D0F-46E1-AA06-718958B6E4D2} - http://download.ebay.../UK/install.cab
O16 - DPF: {410A8B3C-7CCB-40E8-8B11-28B099E5C488} (Trend Micro Security Services Control) - http://tmss.trendmic...TMSSReportW.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1093981054625
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1135023793578
O16 - DPF: {9B17FE0E-51F2-4692-8B32-8EFB805FC0E7} (HPObjectInstaller Class) - http://h30155.www3.h...edsolutions.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

#10 Susan528

Susan528

    SuperMember

  • Authentic Member
  • PipPipPipPipPip
  • 3,194 posts

Posted 01 March 2007 - 02:26 PM

Your hijackthis log appears to be clean but there are many bad files in the system32 that we need to get rid of. I will need the report again to check.


======
Delete Files with Killbox

Skip the download if you still have Killbox.
Download Pocket Killbox from http://www.downloads...org/KillBox.zip and unzip it; save it to your Desktop. DO NOT RUN IT YET.
==========
Double-click on KillBox.exe to launch the program. It is the red circle with a large white X in it
- Highlight the files in bold RED below and press the Ctrl key and the C key at the same time to copy them to the clipboard

C:\WINDOWS\system32\awtqn.dll
C:\WINDOWS\system32\awtqq.dll
C:\WINDOWS\system32\awtsp.dll
C:\WINDOWS\system32\awvtr.dll
C:\WINDOWS\system32\awvvs.dll
C:\WINDOWS\system32\awvvt.dll
C:\WINDOWS\system32\awvvw.dll
C:\WINDOWS\system32\ddaba.dll
C:\WINDOWS\system32\ddabc.dll
C:\WINDOWS\system32\ddaya.dll
C:\WINDOWS\system32\ddccb.dll
C:\WINDOWS\system32\ddccd.dll
C:\WINDOWS\system32\ddccy.dll
C:\WINDOWS\system32\ddcya.dll
C:\WINDOWS\system32\gebcd.dll
C:\WINDOWS\system32\gebya.dll
C:\WINDOWS\system32\gebyw.dll
C:\WINDOWS\system32\gebyx.dll
C:\WINDOWS\system32\geeba.dll
C:\WINDOWS\system32\geeby.dll
C:\WINDOWS\system32\jkhfc.dll
C:\WINDOWS\system32\jkhhi.dll
C:\WINDOWS\system32\jkkji.dll
C:\WINDOWS\system32\mljgh.dll
C:\WINDOWS\system32\mljjg.dll
C:\WINDOWS\system32\mljjk.dll
C:\WINDOWS\system32\mlljh.dll
C:\WINDOWS\system32\mlljk.dll
C:\WINDOWS\system32\mllmn.dll
C:\WINDOWS\system32\pmkhf.dll
C:\WINDOWS\system32\pmkhh.dll
C:\WINDOWS\system32\pmnli.dll
C:\WINDOWS\system32\pmnlj.dll
C:\WINDOWS\system32\pmnlm.dll
C:\WINDOWS\system32\pmnnk.dll
C:\WINDOWS\system32\pmnnl.dll
C:\WINDOWS\system32\pmnno.dll
C:\WINDOWS\system32\ssqpm.dll
C:\WINDOWS\system32\ssqrr.dll
C:\WINDOWS\system32\ssqrs.dll
C:\WINDOWS\system32\sstqo.dll
C:\WINDOWS\system32\sstqp.dll
C:\WINDOWS\system32\sstqr.dll
C:\WINDOWS\system32\ssttq.dll
C:\WINDOWS\system32\ssttr.dll
C:\WINDOWS\system32\sstts.dll
C:\WINDOWS\system32\vtsqp.dll
C:\WINDOWS\system32\vtsqq.dll
C:\WINDOWS\system32\vtsqr.dll
C:\WINDOWS\system32\vtstr.dll
C:\WINDOWS\system32\vtsts.dll
C:\WINDOWS\system32\vtstt.dll
C:\WINDOWS\system32\vturp.dll
C:\WINDOWS\system32\vtutq.dll
C:\WINDOWS\system32\vtutu.dll


In Killbox click on the File menu and then the Paste from Clipboard item
in the Full Path of File to Delete field drop down the arrow and make sure that all of the files are listed
(Please note that the tool checks your computer for the presence of the files pasted into the box so if files are not present, it is possible that you might not see all files you pasted into the box.)
  • Click the option to Delete on Reboot
  • Click End Explorer Shell while Killing File
  • Click All Files right of the flashing green "Single files"
  • Click Yes when it asks "Files will be Removed on Reboot, Do you want to reboot now?"
(Note: If you get a "PendingFileRenameOperations Registry Data has been Removed by External Process!" message then just reboot manually)

If you have any issues with this method you can copy and paste the lines one at a time into the killbox top box. Then click the "Single File" button. Then click the Red X ...and for the confirmation message that will appear, you will need to click Yes. A second message will ask to Reboot now? you will need to click No until the last one at which time you click yes to allow the reboot.


Please run the l2mfix.exe (Option #1) again and reply with the log from the l2mfix.
Posted Image

Proud member of ASAP since 2005

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Want to help others? Come join us in the Class Room and learn how.

    Advertisements

Register to Remove


#11 trojanedbrian

trojanedbrian

    New Member

  • Authentic Member
  • Pip
  • 14 posts

Posted 01 March 2007 - 02:53 PM

Latest log as requested: L2MFIX find log 051206 These are the registry keys present ********************************************************************************** Winlogon/notify: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000000 "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\ 6c,00,00,00 "Logoff"="ChainWlxLogoffEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000000 "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "Logoff"="CryptnetWlxLogoffEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] "DLLName"="cscdll.dll" "Logon"="WinlogonLogonEvent" "Logoff"="WinlogonLogoffEvent" "ScreenSaver"="WinlogonScreenSaverEvent" "Startup"="WinlogonStartupEvent" "Shutdown"="WinlogonShutdownEvent" "StartShell"="WinlogonStartShellEvent" "Impersonate"=dword:00000000 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp] "DLLName"="wlnotify.dll" "Logon"="SCardStartCertProp" "Logoff"="SCardStopCertProp" "Lock"="SCardSuspendCertProp" "Unlock"="SCardResumeCertProp" "Enabled"=dword:00000001 "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule] "Asynchronous"=dword:00000000 "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "Impersonate"=dword:00000000 "StartShell"="SchedStartShell" "Logoff"="SchedEventLogOff" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy] "Logoff"="WLEventLogoff" "Impersonate"=dword:00000000 "Asynchronous"=dword:00000001 "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\ 6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn] "DLLName"="WlNotify.dll" "Lock"="SensLockEvent" "Logon"="SensLogonEvent" "Logoff"="SensLogoffEvent" "Safe"=dword:00000001 "MaxWait"=dword:00000258 "StartScreenSaver"="SensStartScreenSaverEvent" "StopScreenSaver"="SensStopScreenSaverEvent" "Startup"="SensStartupEvent" "Shutdown"="SensShutdownEvent" "StartShell"="SensStartShellEvent" "PostShell"="SensPostShellEvent" "Disconnect"="SensDisconnectEvent" "Reconnect"="SensReconnectEvent" "Unlock"="SensUnlockEvent" "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv] "Asynchronous"=dword:00000000 "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "Impersonate"=dword:00000000 "Logoff"="TSEventLogoff" "Logon"="TSEventLogon" "PostShell"="TSEventPostShell" "Shutdown"="TSEventShutdown" "StartShell"="TSEventStartShell" "Startup"="TSEventStartup" "MaxWait"=dword:00000258 "Reconnect"="TSEventReconnect" "Disconnect"="TSEventDisconnect" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon] "Logon"="WLEventLogon" "Logoff"="WLEventLogoff" "Startup"="WLEventStartup" "Shutdown"="WLEventShutdown" "StartScreenSaver"="WLEventStartScreenSaver" "StopScreenSaver"="WLEventStopScreenSaver" "Lock"="WLEventLock" "Unlock"="WLEventUnlock" "StartShell"="WLEventStartShell" "PostShell"="WLEventPostShell" "Disconnect"="WLEventDisconnect" "Reconnect"="WLEventReconnect" "Impersonate"=dword:00000001 "Asynchronous"=dword:00000000 "SafeMode"=dword:00000001 "MaxWait"=dword:ffffffff "DllName"=hex(2):57,00,67,00,61,00,4c,00,6f,00,67,00,6f,00,6e,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "Event"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon\Settings] "Data"=hex:01,00,00,00,d0,8c,9d,df,01,15,d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,\ 00,00,46,58,b6,ff,bb,46,94,45,ae,fa,06,76,b8,93,8b,52,04,00,00,00,04,00,00,\ 00,53,00,00,00,03,66,00,00,a8,00,00,00,10,00,00,00,0a,9e,7d,cb,66,6d,23,75,\ b9,ef,ad,6b,da,cd,bc,6c,00,00,00,00,04,80,00,00,a0,00,00,00,10,00,00,00,de,\ 79,46,2d,9a,af,17,d0,4c,59,04,2f,81,83,8b,1b,08,06,00,00,53,81,6b,4b,12,1e,\ 30,40,31,bb,c4,29,c6,c7,ba,d6,f5,e2,0f,a6,ed,f3,00,fd,3a,78,d2,8f,2d,4f,de,\ 99,e0,5c,48,37,6c,be,d6,2f,bc,cc,c1,75,0e,54,61,eb,7c,34,43,bf,50,16,1b,33,\ c3,62,fe,46,19,88,84,5c,ae,91,a7,c7,cc,f4,14,4a,d6,4f,73,e4,7c,47,21,7b,1e,\ ca,86,eb,d4,df,77,df,64,3d,47,3a,67,90,90,60,32,72,70,24,2d,dd,2f,71,42,99,\ ba,35,1a,46,13,e8,0d,2c,82,dd,77,49,0c,48,9a,2d,b4,fb,36,18,4d,32,63,3d,c1,\ 61,7f,d1,11,32,6e,66,76,84,af,db,ae,12,66,13,09,f0,d8,ec,38,1b,9d,5c,57,b1,\ f1,0d,e1,5d,21,7a,fb,98,9d,bb,fd,fd,af,8d,3d,70,24,bc,0d,94,df,e8,9f,71,3f,\ 78,5a,89,78,2e,6a,57,71,8b,5a,8a,54,d4,4c,06,21,92,a1,1d,7b,3c,a2,42,5f,3e,\ fb,b2,b7,77,ca,5e,cb,e3,e2,9a,7b,32,9a,37,ff,c5,6b,f0,12,f0,55,1d,8b,24,46,\ e7,6c,b3,f2,e5,ab,8d,b0,6d,8b,da,ad,86,56,c9,d2,fd,87,06,f4,5c,95,86,47,61,\ 0b,ff,f7,ec,a2,d3,d8,f8,bf,3a,6c,82,77,25,3e,42,96,f2,ed,3b,43,c0,24,29,da,\ a7,46,f0,7d,ed,f3,96,ba,0d,70,cb,c6,0d,87,0a,07,0a,cf,5b,a3,0e,08,50,07,e1,\ e5,1c,69,af,6b,91,6c,59,32,d2,a9,7b,8c,06,de,fd,81,8a,90,d3,6d,a5,b7,e3,82,\ ed,6c,44,8f,9c,cc,23,c4,6c,85,62,e3,dc,80,6f,75,00,9b,05,e4,43,83,16,59,54,\ 50,f9,3c,69,33,24,60,b5,cd,97,f0,91,9d,b3,3c,41,50,75,bb,9c,62,03,a8,f6,72,\ dc,7c,41,d2,34,c0,1d,8b,a2,4b,f7,d1,f9,c5,e6,8f,6e,02,e4,9e,1f,d3,d6,9c,ca,\ b3,59,25,63,92,42,02,d9,0a,4d,26,a9,e8,bc,b3,9c,9c,16,80,6d,32,87,7f,8e,25,\ eb,cb,65,f0,8a,e7,cd,42,29,a6,b7,7a,64,57,06,01,20,c3,a2,92,ae,b8,bb,2e,fd,\ 36,11,5e,21,33,95,03,10,a1,49,9e,88,dc,a9,48,98,5f,11,d0,f2,81,e2,d4,c8,7f,\ 67,75,2c,14,39,a8,01,70,5d,c2,a6,8c,f7,56,77,e8,fc,d4,fe,67,ad,a3,42,83,0a,\ 84,15,b8,81,22,21,49,a7,e9,c5,c8,d3,53,19,8f,98,a2,2a,c4,b4,ce,3a,f2,b8,48,\ c1,73,6c,a4,a9,17,bf,fd,01,94,92,47,bf,e4,51,00,d4,9a,89,8e,b7,91,4f,52,42,\ 48,41,a4,25,40,06,ca,fb,00,e8,ea,8d,f7,dd,1b,62,da,98,73,7d,54,7b,5a,eb,ff,\ 76,7c,4c,23,35,69,06,a3,46,4a,b4,86,61,6a,f1,06,91,b2,0b,c4,b1,57,4e,ef,b2,\ 33,79,55,6b,5a,ae,2f,e5,8c,40,e0,91,3e,39,29,57,b8,e9,5d,e8,e3,3e,4d,14,82,\ 51,87,66,98,ef,f6,3a,c9,20,4e,6a,93,bb,59,6c,a0,d6,47,9e,7f,44,c6,46,69,0f,\ 04,c8,51,4d,43,0d,d8,4e,1c,50,4d,30,af,56,0c,ea,be,75,4e,00,41,35,c0,c3,95,\ 04,34,48,83,2e,4f,cf,06,0c,38,32,1b,6c,df,28,92,61,34,18,07,7b,99,51,7f,af,\ 21,f4,f2,b6,c4,61,eb,e6,a8,e1,ce,40,e5,7b,a7,34,87,26,77,16,68,96,04,b3,58,\ 25,a7,46,92,aa,de,3b,d4,78,f6,8c,3b,78,c9,57,e1,13,62,5f,fd,53,44,a2,d8,9c,\ 8f,af,61,b4,28,0c,79,b5,7d,37,28,96,61,fe,68,60,a1,d4,05,d2,9d,1e,16,4d,2a,\ f6,db,d0,28,42,7e,1c,d6,a1,d1,5b,d6,38,9e,e6,e3,ec,09,7a,59,c6,4b,3b,1e,40,\ 66,d4,6b,52,b1,67,46,6e,cd,15,5f,8d,71,fb,50,48,19,a5,e1,0b,46,aa,1e,f7,92,\ 25,bf,d0,4f,54,df,89,86,1a,58,11,14,25,17,d4,e2,94,87,51,c7,53,38,94,8c,2b,\ 6b,97,73,a6,3c,61,bb,1f,44,36,aa,d1,21,73,d1,47,18,07,2a,84,8d,7c,4a,b8,db,\ a3,99,bd,41,48,ca,0a,0e,66,ea,45,57,9b,04,1b,02,32,dd,fc,9b,90,06,23,ba,55,\ 58,85,48,f1,f8,2a,32,1e,c8,87,2f,ba,c2,3e,65,7d,85,43,df,65,44,e2,bd,ef,9c,\ 48,ba,ac,d6,a5,11,4e,83,5e,b8,3d,73,28,e9,8a,a9,f7,08,86,89,02,75,4b,ec,6d,\ 15,3a,56,64,5f,2a,68,71,32,f6,7a,b6,13,4d,2b,a8,ac,de,f7,1b,db,68,9a,92,83,\ 60,dc,13,69,87,9e,58,79,24,92,cc,7b,4a,45,2a,ae,ca,7d,47,e6,07,a7,88,68,f3,\ 77,2e,1c,62,39,2c,8f,e7,ad,54,28,84,73,f2,63,88,4d,ca,93,9a,f3,e1,92,0e,14,\ 40,d2,37,60,5a,b0,b8,b4,66,31,ad,5d,19,04,c0,40,51,77,00,b1,9d,75,aa,1d,0e,\ 55,39,1e,44,55,b7,4a,77,a2,aa,74,23,dc,dc,26,c1,68,6d,1e,7c,4a,0b,69,5e,5b,\ 6b,18,07,68,41,34,59,53,02,f6,09,05,43,e4,18,49,1c,24,15,1d,f9,82,aa,15,a5,\ cd,fc,b1,3d,64,3a,9e,07,f1,af,50,1c,7b,0f,41,93,38,48,6b,fd,2c,89,18,d5,21,\ ad,0c,71,b1,ea,e0,55,9e,d9,4c,07,a4,56,55,d3,41,87,b1,b6,d7,f6,ac,95,ed,6c,\ 57,3c,e8,73,65,6b,a7,86,0b,bb,84,ae,63,ac,f2,84,8a,b2,60,dc,96,f5,47,7c,03,\ 04,05,27,40,e7,38,05,25,92,34,e7,d7,ee,97,bd,aa,79,69,75,4a,40,5e,72,2f,81,\ 10,67,34,f1,9d,fa,83,09,08,aa,d3,1f,fe,c6,3d,fd,fa,a5,ef,ee,33,0a,24,31,b4,\ 3b,c5,80,76,7a,6d,b2,33,15,41,fa,05,d5,a2,f2,2c,40,81,97,f1,85,9a,85,e3,b9,\ 71,5e,44,e2,10,04,c4,89,0d,42,1f,ec,ba,7d,5b,4b,4b,64,12,34,c9,b9,9d,af,8a,\ b1,bb,28,ee,57,06,73,4f,07,7c,65,89,b1,28,72,85,4c,56,d0,ef,cf,38,f5,e5,ed,\ 63,8c,6c,54,38,d1,35,8d,a0,af,6e,b7,58,7f,3f,10,5f,ba,b2,e7,92,fa,ba,ea,d2,\ 8f,1a,ca,4a,dc,74,c4,1f,50,d8,9f,29,6a,cd,bd,2b,6a,e8,8f,4b,f6,1d,db,11,8c,\ 09,19,db,f3,28,bf,7a,72,cb,62,25,cc,dc,ef,2c,e4,71,71,41,75,85,e4,7e,14,96,\ ef,04,9c,ce,89,3e,43,7e,9f,83,85,d3,b2,76,41,98,3c,a6,aa,93,c5,90,76,cf,4d,\ 11,36,36,48,1c,b9,1a,f8,d6,b7,04,6a,03,66,27,2f,c0,60,dd,06,22,38,ac,f8,df,\ 54,fe,43,8f,0f,b9,91,31,2f,fb,d0,56,a5,43,44,1f,62,b3,6c,41,f9,c7,da,04,53,\ de,33,c7,09,71,c6,10,fe,8e,cf,0b,be,d4,1e,13,a5,56,8b,06,23,42,b0,b1,34,2d,\ b7,cd,2d,1a,64,1e,fd,ec,2a,fb,0c,4b,11,28,1c,19,d2,b8,28,7c,42,96,49,37,0f,\ ec,88,30,04,85,ab,44,ed,7f,a7,b8,2f,27,e9,31,9d,c6,53,cd,db,49,6e,cb,09,36,\ 1d,28,bf,ad,b1,de,79,06,e3,fc,16,7c,f0,14,00,00,00,8f,c1,54,53,60,ae,53,fe,\ 3f,5d,95,36,0a,40,8c,cc,69,92,b7,a4 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon] "DLLName"="wlnotify.dll" "Logon"="RegisterTicketExpiredNotificationEvent" "Logoff"="UnregisterTicketExpiredNotificationEvent" "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 ********************************************************************************** useragent: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform] ********************************************************************************** Shell Extension key: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved] "{00022613-0000-0000-C000-000000000046}"="Multimedia File Property Sheet" "{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management" "{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page" "{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE Docfile Property Page" "{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Shell extensions for sharing" "{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension" "{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Display Adapter CPL Extension" "{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Display Monitor CPL Extension" "{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL Extension" "{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page" "{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibility Page" "{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler" "{59099400-57FF-11CE-BD94-0020AF85B590}"="Disk Copy Extension" "{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Shell extensions for Microsoft Windows Network objects" "{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Monitor Management" "{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management" "{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Shell extensions for file compression" "{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Shell Extension" "{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI" "{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption Context Menu" "{85BBD920-42A0-1069-A2E4-08002B30309D}"="Briefcase" "{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Ext" "{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts" "{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile" "{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printers Security Page" "{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Shell extensions for sharing" "{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension" "{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO Extension" "{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign Extension" "{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Network Connections" "{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Network Connections" "{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Scanners & Cameras" "{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Scanners & Cameras" "{905667aa-acd6-11d2-8080-00805f6596d2}"="Scanners & Cameras" "{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Scanners & Cameras" "{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Scanners & Cameras" "{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension" "{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension" "{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Shell extensions for Windows Script Host" "{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Link" "{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler" "{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension" "{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Scheduled Tasks" "{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Taskbar and Start Menu" "{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Search" "{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support" "{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support" "{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Run..." "{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet" "{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="E-mail" "{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fonts" "{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Administrative Tools" "{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler" "{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler" "{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler" "{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler" "{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler" "{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor" "{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar" "{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status" "{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder" "{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2" "{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy" "{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand" "{30D02401-6A81-11d0-8274-00C04FD5AE38}"="IE Search Band" "{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band" "{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search" "{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search" "{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility" "{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Address" "{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox" "{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete" "{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor" "{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List" "{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List" "{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible" "{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar" "{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Address Bar Parser" "{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List" "{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List" "{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container" "{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu" "{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp" "{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar" "{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite" "{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist" "{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings" "{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band" "{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service" "{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer" "{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture" "{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut" "{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service" "{FF393560-C2A7-11CF-BFF4-444553540000}"="History" "{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files" "{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files" "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook" "{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen" "{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook" "{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC" "{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC" "{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="The Internet" "{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space" "{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band" "{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service" "{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service" "{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder" "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck" "{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr" "{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder" "{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler" "{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent" "{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent" "{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent" "{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent" "{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent" "{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler" "{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Shell Application Manager" "{0B124F8F-91F0-11D1-B8B5-006008059382}"="Installed Apps Enumerator" "{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher" "{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs" "{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory" "{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ file thumbnail extractor" "{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Summary Info Thumbnail handler (DOCFILES)" "{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML Thumbnail Extractor" "{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler" "{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Web Publishing Wizard" "{add36aa8-751a-4579-a266-d66f5202ccbb}"="Print Ordering via the Web" "{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object" "{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Get a Passport Wizard" "{7A9D77BD-5403-11d2-8785-2E0420524153}"="User Accounts" "{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler" "{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target" "{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview" "{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext" "{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control" "{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control" "{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control" "{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control" "{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control" "{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI" "{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object" "{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find" "{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find" "{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI" "{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs" "{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook" "{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target" "{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties" "{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu" "{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options" "{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline Files Folder" "{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler" "{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell" "{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%" "{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler" "{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer" "{32714800-2E5F-11d0-8B85-00AA0044F941}"="For &People..." "{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Burn Audio CD Context Menu Handler" "{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Play as Playlist Context Menu Handler" "{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler" "{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults" "{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Previous Versions Property Page" "{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Previous Versions" "{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder" "{1D2680C9-0E2A-469d-B787-065558BC7D43}"="Fusion Cache" "{1CDB2949-8F65-4355-8456-263E7C208A5D}"="Desktop Explorer" "{1E9B04FB-F9E5-4718-997B-B8DA88302A47}"="Desktop Explorer Menu" "{BDEADF00-C265-11D0-BCED-00A0C90AB50F}"="Web Folders" "{42042206-2D85-11D3-8CFF-005004838597}"="Microsoft Office HTML Icon Handler" "{506F4668-F13E-4AA1-BB04-B43203AB3CC0}"="{506F4668-F13E-4AA1-BB04-B43203AB3CC0}" "{D66DC78C-4F61-447F-942B-3FB6980118CF}"="{D66DC78C-4F61-447F-942B-3FB6980118CF}" "{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player" "{1E2CDF40-419B-11D2-A5A1-002018648BA7}"="AVG Shell Extension" "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"="WinRAR shell extension" "{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802}"="Adobe.Acrobat.ContextMenu" "{AC1DB655-4F9A-4c39-8AD2-A65324A4C446}"="Autodesk Drawing Preview" "{36A21736-36C2-4C11-8ACB-D4136F2B57BD}"="AutoCAD Digital Signatures Icon Overlay Handler" @="" "{1530F7EE-5128-43BD-9977-84A4B0FAD7DF}"="PhotoToys" "{BB7DF450-F119-11CD-8465-00AA00425D90}"="Microsoft Access Custom Icon Handler" "{21569614-B795-46b1-85F4-E737A8DC09AD}"="Shell Search Band" "{00E7B358-F65B-4dcf-83DF-CD026B94BFD4}"="Autoplay for SlideShow" "{07C45BB1-4A8C-4642-A1F5-237E7215FF66}"="IE Microsoft BrowserBand" "{1C1EDB47-CE22-4bbb-B608-77B48F83C823}"="IE Fade Task" "{205D7A97-F16D-4691-86EF-F3075DCCA57D}"="IE Menu Desk Bar" "{3028902F-6374-48b2-8DC6-9725E775B926}"="IE AutoComplete" "{43886CD5-6529-41c4-A707-7B3C92C05E68}"="IE Navigation Bar" "{44C76ECD-F7FA-411c-9929-1B77BA77F524}"="IE Menu Site" "{4B78D326-D922-44f9-AF2A-07805C2A3560}"="IE Menu Band" "{6038EF75-ABFC-4e59-AB6F-12D397F6568D}"="IE Microsoft History AutoComplete List" "{6B4ECC4F-16D1-4474-94AB-5A763F2A54AE}"="IE Tracking Shell Menu" "{6CF48EF8-44CD-45d2-8832-A16EA016311B}"="IE IShellFolderBand" "{73CFD649-CD48-4fd8-A272-2070EA56526B}"="IE BandProxy" "{98FF6D4B-6387-4b0a-8FBD-C5C4BB17B4F8}"="IE MRU AutoComplete List" "{9A096BB5-9DC3-4D1C-8526-C3CBF991EA4E}"="IE RSS Feeder Folder" "{9D958C62-3954-4b44-8FAB-C4670C1DB4C2}"="IE Microsoft Shell Folder AutoComplete List" "{B31C5FAE-961F-415b-BAF0-E697A5178B94}"="IE Microsoft Multiple AutoComplete List Container" "{BC476F4C-D9D7-4100-8D4E-E043F6DEC409}"="Microsoft Browser Architecture" "{BFAD62EE-9D54-4b2a-BF3B-76F90697BD2A}"="IE Shell Rebar BandSite" "{E6EE9AAC-F76B-4947-8260-A9F136138E11}"="IE Shell Band Site Menu" "{F2CF5485-4E02-4f68-819C-B92DE9277049}"="&Links" "{F83DAC1C-9BB9-4f2b-B619-09819DA81B0E}"="IE Registry Tree Options Utility" "{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75}"="IE User Assist" "{FDE7673D-2E19-4145-8376-BBD58C4BC7BA}"="IE Custom MRU AutoCompleted List" "{993BE281-6695-4BA5-8A2A-7AACBFAAB69E}"="Microsoft Office Metadata Handler" "{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97}"="Microsoft Office Thumbnail Handler" "{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices" "{35786D3C-B075-49b9-88DD-029876E11C01}"="Portable Devices" "{D6791A63-E7E2-4fee-BF52-5DED8E86E9B8}"="Portable Devices Menu" "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}"="AVG7 Shell Extension" "{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}"="AVG7 Find Extension" "{00020D75-0000-0000-C000-000000000046}"="Microsoft Office Outlook Desktop Icon Handler" "{0006F045-0000-0000-C000-000000000046}"="Microsoft Office Outlook Custom Icon Handler" ********************************************************************************** HKEY ROOT CLASSIDS: ********************************************************************************** Files Found are not all bad files: C:\WINDOWS\SYSTEM32\ advpack.dll Mon 8 Jan 2007 19:00:48 A.... 124,928 122.00 K corpol.dll Mon 8 Jan 2007 19:01:14 A.... 17,408 17.00 K extmgr.dll Fri 12 Jan 2007 9:27:42 A.... 132,608 129.50 K ieakeng.dll Mon 8 Jan 2007 19:02:02 A.... 153,088 149.50 K ieaksie.dll Mon 8 Jan 2007 19:02:02 A.... 230,400 225.00 K ieakui.dll Mon 8 Jan 2007 19:02:02 A.... 161,792 158.00 K ieapfltr.dll Mon 8 Jan 2007 19:02:02 ..... 383,488 374.50 K iedkcs32.dll Mon 8 Jan 2007 19:02:02 A.... 384,000 375.00 K ieframe.dll Fri 12 Jan 2007 9:27:42 ..... 6,054,400 5.77 M iernonce.dll Mon 8 Jan 2007 19:02:04 A.... 44,544 43.50 K iertutil.dll Mon 8 Jan 2007 19:02:04 A.... 266,752 260.50 K jsproxy.dll Fri 12 Jan 2007 9:27:42 A.... 27,136 26.50 K msfeeds.dll Fri 12 Jan 2007 9:27:42 ..... 458,752 448.00 K msfeed~1.dll Fri 12 Jan 2007 9:27:42 ..... 51,712 50.50 K mshtml.dll Fri 12 Jan 2007 9:27:42 A.... 3,580,416 3.41 M mshtmled.dll Fri 12 Jan 2007 9:27:42 A.... 477,696 466.50 K msrating.dll Mon 8 Jan 2007 19:03:02 A.... 193,024 188.50 K mstime.dll Fri 12 Jan 2007 9:27:42 A.... 670,720 655.00 K occache.dll Mon 8 Jan 2007 19:04:08 A.... 102,400 100.00 K ogache~1.dll Tue 23 Jan 2007 15:15:22 A.... 676,224 660.38 K shell32.dll Tue 19 Dec 2006 21:52:18 A.... 8,453,632 8.06 M shsvcs.dll Tue 19 Dec 2006 21:52:18 A.... 134,656 131.50 K url.dll Mon 8 Jan 2007 19:04:54 A.... 105,984 103.50 K urlmon.dll Fri 12 Jan 2007 9:27:42 A.... 1,149,952 1.09 M webcheck.dll Fri 12 Jan 2007 9:27:42 A.... 232,960 227.50 K wiaservc.dll Tue 19 Dec 2006 18:16:48 A.... 333,824 326.00 K wininet.dll Fri 12 Jan 2007 9:27:42 A.... 822,784 803.50 K 27 items found: 27 files, 0 directories. Total of file sizes: 25,425,280 bytes 24.25 M Locate .tmp files: No matches found. ********************************************************************************** Directory Listing of system files: Volume in drive C has no label. Volume Serial Number is E82F-ADEC Directory of C:\WINDOWS\System32 14/02/2007 00:10 <DIR> dllcache 31/08/2004 17:16 <DIR> Microsoft 0 File(s) 0 bytes 2 Dir(s) 21,177,077,760 bytes free

#12 Susan528

Susan528

    SuperMember

  • Authentic Member
  • PipPipPipPipPip
  • 3,194 posts

Posted 01 March 2007 - 04:08 PM

Let's just run one more scan. If everything looks good, I will give the final instructions.

Now run this online scan using Internet Explorer:
Kaspersky Online Scanner from http://www.kaspersky.com/virusscanner

* Turn off the real time scanner of any existing antivirus program while performing the online scan
Next Click on Launch Kaspersky Online Scanner

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
  • Scan using the following Anti-Virus database:
  • Standard
  • Scan Options:
  • Scan Archives
  • Scan Mail Bases
  • Click OK
  • Now under select a target to scan:
  • Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button:
  • Save the file to your desktop.
Copy and paste that information from Kapersky in your next post.

**Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the license, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license is accepted, reset to 100%.

Please post(reply) with another hijackthis log and the log from Kapersky and let me know how your computer is running now..
Posted Image

Proud member of ASAP since 2005

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Want to help others? Come join us in the Class Room and learn how.

#13 trojanedbrian

trojanedbrian

    New Member

  • Authentic Member
  • Pip
  • 14 posts

Posted 02 March 2007 - 04:44 PM

Sorry for the delay. Scan results as requested - 1 virus found, but a lot of locked files. Friday, March 02, 2007 10:36:16 PM Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.83.0 Kaspersky Anti-Virus database last update: 2/03/2007 Kaspersky Anti-Virus database records: 259950 Scan Settings Scan using the following antivirus database standard Scan Archives true Scan Mail Bases true Scan Target My Computer A:\ C:\ D:\ E:\ F:\ G:\ H:\ Scan Statistics Total number of scanned objects 127154 Number of viruses found 1 Number of infected objects 1 / 0 Number of suspicious objects 0 Duration of the scan process 01:47:04 Infected Object Name Virus Name Last Action C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\006bd16e234bbb037bb23b1ce4e0b548_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0125a4856f39b26898fcab228388ad9f_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0165a5395ea5835273c9a69fc4b6ccef_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\026d8910aab8db2d7db3a9f3c4268f64_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\033072d698990b44940d935231841fbc_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\03c7480c1c1c271b966ee26b56954c94_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0476c3f7df809f5b11040b8c6b003af0_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0479f6f3aab25cdec619761835611f41_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\04e2710768903be329b52f869bb3f4dc_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\057d3dace93b03bcbc4fa63f2b26814c_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\05e837f80f855cf9911770800779f80f_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\05f6886108d181f72a0226ba039b9bd7_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\05f829446c194492fb030b4576eddaf9_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\06009c91bfdbf7a20872794080582925_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0655b8cb9e40283f865fa1212dd31346_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\067001605ade7c06ff4b526b2b5f8da9_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\08652075b3ad7232a8434ba93551786c_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\088f700b8c6f5b009314b38ef7f9f1b2_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\090ccffa48941c197dacd3128e5dce7e_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0954f20b24c272803f25242074d29aeb_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0980a276cf2f94bd0bec9c90231202bd_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\09cb4a3c15684515384d75c58720209f_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0a432ab8683ed49fc450a718b12eb4ef_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0a5dd920a7eb9ef03b0c9d5803652d90_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0b76223167de56742da7f77b6e31f5be_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0d798a2e709b32f27d575a8a4d0aff38_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0dc02bfa8d5e6029d1939674e12f6ecd_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0ec8e8f2a268bdbd81c7191b3b8744a8_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0f3800bc55bb585b6b61e5d1846b213d_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\10f515c495f3c9fe0aa70847b8d0da6c_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1102db040b571313d7c8b264d9d7a101_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\11ae715d5ee1bd7a4d7c9cf424a94e36_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\120e7d3e9d61de0e455dc4a4a5c56afb_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\129fe5c182afad313f09119b09d48b1b_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\140f6cb7d6c71329b600e557f4d51ddf_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\148a21ba47ab8335e275f106da184908_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\15b37bdef78beb19bbc22a9fcae9df54_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\168b86d1a706b9a61221d1eb462e6d58_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\16bac5866a4b7f15a3a42e3ca60dac24_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\16f7b93824be7dec50920b9c28db7186_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\16ffa969fda4584d73f0733e0324b226_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\178705e0a9c3137bbf9f53bd7fb113c3_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\178fa646deeb17d1163b556fc02cebf3_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1875ef3f0211768606ab5a83c660e232_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\18d5e95f0a487c4e92c3028ff2bb0c8f_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\19167968e1b3cf4b8056c10af7ad4390_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1afc540d679c959e98dd7992b31574b2_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1b2a6cfd53c3b6d57da68593a2ea88e8_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1b705d0044107c95bf3298981a6bea50_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1c9c0450460df6e7c9aa733a24cedc16_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1cdd2e404e09da3641cebbc491f84007_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1cfd7c0b8b4b47888473aee1d8af0f0a_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1cffba34de1dba888c12378043913298_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1d3e28ac05cfed5b5ffe04c7246bfa8a_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1f95874754857c6d27ff8042951423f2_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\200a7ac1442652c25133eb391f02f189_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\20a7b0edeb06e38e891271d301496f08_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\214abd829122d97c768f6c132b4d3aec_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\216acc073fe3e345a06778c11ffa699f_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\219fbfaeda7316b5031644e0cfcf6462_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\21c816d14f15e5f7040dc824192633ce_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\21de4dcd3eb2c990a337080596cc58e3_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2211c0ec2094cfc62bffefe6700a7be4_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2369d8a6d9dd40c7bba349cf63e377d0_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2375551bcc66b1911023c0fb29382451_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\237b9b9aabf4896b5f7fda09fb7759c7_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\23be5cc5139d1c86612a2b569118cc82_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\23f1680895179e913c2eddec2c3df714_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2469a11d6ab03499365fddd1e86f893a_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\25005c5b0fabdfd251f9f8e01d794684_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\27bd482c31f638da1eef28dee7b17501_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\28a41811f2d1c8aea9ef5c498fee1ff3_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\29b175612b6a0d72dd678c1e83fcaf0c_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\29f3aec46b93ec7be15d906a2a2a5f62_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2a3488f0be481392cb459c12c8e8b776_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2a6dbc96a9c92b5db551a03355491fba_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2a94c9a666fd460cd6b4dc3c021d1454_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2b270d1ecfd70326701bbd3de3d50cb4_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2bc36f8dcefc4b48a8c55af39ed551e5_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2bd08881d46a45cc54fb37d751b3daa0_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2c12d089e7e511e06e010a2b01bca7bd_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2c64915f22a21111104adaea03dcf5df_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2ca2b6859b7f62dbce8bcdfcbe58e22e_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2e9a3bdca7d910ee373a9c08382ec667_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2f1e4c366de40a033080de8d198d5ca4_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2f357f9f7b2a38b0661c86586d96280e_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3017ba61da845e91d9c77a6de2cc9fa9_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3173e0b75844f1c28569e1d1e3efebf0_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\31e8689e5b8c2f8692d1f1276ff53093_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\32bf9a5b6190dcc2004825cd0e984dd6_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\333cc987b50e922528922b1ca834dec2_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\336f36c0a9cce5f35bfdbebd6b2dcbd1_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3426fbb5090c28352aa8062e28b94950_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\343211cf459e5792bd79dcaf75422751_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3448940e1e218fcad2c29b8f26d97b64_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\346b40620e7fe3e5a8f4f6dd7ff5f340_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\34822160c049537122c95783d6fe218a_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\34d134fb641ed2f7d1d8e3359aef3dba_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\356533388f9322c8d6f03bb49a0169af_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\35b4a3b5bc06a52a99af05d05aceb076_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\36d8ef16233bb04c8405d74e0296568f_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\36e923c48f98bf5622ec526b12852826_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\36f35390db1d8b1d9e9471b6354dbfaf_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\37b5d8b8d2ac2741ba3cb6470171eda0_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3819a4e6005d4ad834a34c5c41401f05_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3900780e1716c3a46a274d4dc6d522c6_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3a21401840c4989559ef207227e6bbf6_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3a4d10e93878a95b407e7a0fc594a21c_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3a58fcb25c0274f1237d5b093e134be8_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3b7eb2d1266583d89f7074a0fe912485_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3c505dba368bc2e9ce496d34b91a0a90_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3d87a9a2e7bfbc3c6595f5c0bb888aa7_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3e2caae64204f236131a8fce01873000_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3e595de541ab22c0d152acc6a3dc3d18_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3e5f3fadc5ac238cc8ec2aa7cd67b70b_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3e99d3fa046d34c13d8accdb1f9cecb2_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3e9a5df6b96119df704889314a11a658_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3eb92c54186d6a982a27e8e2f239d2c0_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3fb9085e890e6d3f435138952ef376d3_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\401155d7f667f84190cd6afbb06583b8_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4056da7bb2723be81991eaa266cfd358_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4088bc38627bf4a2407f09019eba8a73_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\410bd04c13b2164dc201956b15cfabdd_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\41500552f712bfa542f81403fee8e600_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4512044cab9b321d5cd147f12d1a4fe7_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\468a2317ee96253b02c45fa2eedfe3f2_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\46b9c576b29f8a661a3fec89abb7c9d8_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\46c6f657eb1ccbb8961384685cd060fd_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\46f467378916b24856b9e807aa0610f2_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\47b63a311fb10219551526bc6d163eb2_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\47e730fb6e7efecd916635ce72af8f55_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\493546299cb1b2e940696b206f46e0b2_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\498535cc81823867a8c8033af5d865cc_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\498627d0e7a77191038a5cebee951a1f_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\49960a071bbf04da3c79899cf04d6b7c_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\49e45be9744f4ae4d8b43e31aa618872_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4cc8acc611c067cb1e5d596fbe11b4b4_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4d0620770328d385d9da01b8b8fc74eb_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4dbb0060eca6e2e0a2797ca4b0e9db52_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4de05767f1a40a0cb52b818870dd9666_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4e06b87b80e747a1cc430f2fefd14047_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4e5707fc4dee43abe90eb6b5030fd494_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4eac30e5ba0fa66fdd55a98a925c8774_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4f0bd8b63c297d860349dca9b934bb21_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4fbaf07bf76ebef46c3af9752aed1f8b_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\501666b6f7aa6194cfdf750780282b1f_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\502b7ab8811bcc656bd12d51cf76abc8_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\506b66c5c668e5c85be96601f3c4bbce_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\516d5da0f67d9fab3107aa3fccdb5a5d_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\51f4b78df7e1af2f2d5af9e7134136d2_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\52675f8944abb6bdb2a534c187da7909_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\538b372d8783f01f3f5d148bb3f1a467_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\53b4fe5c0635c7747630b01d956b7701_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\53be420f9c98d48e27cbee1f3232eebf_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\53f756c9711a271ec4d23259543e0398_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\55451ee0bd377880bad81fc6703a65a0_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\563b64e18d94ddbcf2758ba1bdc420cf_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\569f99299b45b2681226f05d501d1984_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\572a14560b509d1a1ee0ba8795797d33_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\574b431bca8eb5139b582e63b564915e_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\576e62365ed09ef89c2d64cf7c4ef736_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\576f3f90d99cd0b0456432ba1110c9e1_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\57e301a95e0b2f8483b9494419f513bc_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\584ce1f6e5c635d6e22ac55adfaa5fee_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\58b600d7c7526fec6e23aa974b6abb7f_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\58c90636261d2d015433fe6ddd0cdb03_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\58eb87b39ab3017f8086b1327efb7437_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\599184fb08fe7399bcb3fff0a5d3acae_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5a3e26bc89ea237da113f8c4577e47cf_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5adc6e4ede614819fbcd095c2cab81a4_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5b5db7316e15c57c83cf8058ba67550c_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5b5ee7f812ea12f58087ee6ea7baa745_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5bb7e75c84950e5f2f9ecfedcea8901a_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5c7d99fc8dc63ac5bcf543d0a8ebe1ea_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5cf58529e2497e1aa63f574bab4ed200_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5e3b2ea2bd48619f1118448e58737ad5_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5ebd3de96bac4d89baf378fc91db8692_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5fceb4451b70021b5dc7b99629f1a5d7_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\60177996a8b08831400bca8572552ced_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\60c9ef6848b6eb86689d2c9c8094f9be_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\60e1787be5c1baa56c5e58eb603a79bc_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\60f8260dc616253f8bf1a3fb03c44b48_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\61a8e559c8c7947df3abacc8800b66a4_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\62cf8ddf82a6880e9dce69eb81eaebf9_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\62d38d57762bb88a16b9028c639136da_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\639cd13d84bc0763ce36f7c884bb3c8c_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\63d0797850854dbac85284fe11ab44d8_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6406ed8fac6aa4030185f6583ad9c9b3_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\65485a33f518c6401983c5a071ff4b5a_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\657fd24f2a5bf0331411352307e8314e_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\65b072a6433665efa52867ab60b32553_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\65f7a5cf842e39f339badcbbb2981ad6_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6606ea301328fce29d7e164369809d9c_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6818b4e85b4e6827af1dcacbfd8987d7_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\68b2d6e377a589a3e0357439296fa12a_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6943f1f406ad2a8bb144056db1f0e42b_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\698aec421a65a7836795fc5295160dac_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6a34b322a71cd7e5f43e7158160d4844_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6ba29b22dba4b947e432a4c3f8fc94b6_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6bfc478c42de7bd43e32d653e2dad9c9_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6bfcd1effd494da15913a79e36a60a15_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6c88a3654f9e5ef129b853ef99527caf_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6caa9026e812104bbf2050974158c95d_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6d60a1d09dc7756ed4dcfe8a6813d9d0_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6e1a660d15a89186fc94442ecc0b0bb4_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6fe2ae18d408fa61d631ab2c06b190a0_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6fe2ec31300f71d89f91f700618e9454_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7030479b255ebee8e4e68866ad7903f2_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\70860fc9a7432e7be4a395d17f9b6c40_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7126e2f3acf8c7c7f90b672d86f6fceb_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\716d1b9e8998e866f16f8476013a0f3c_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\71a930b6b75b108386c240d8b59a1cab_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\725963020329d199426f94772c8a7a1b_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7386b850862a587844935422b5fd6d3a_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\74d27246a37914ef5d3b582b0a6b68ba_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7597eb08c7e483e4fb24d579c7667caa_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\763407f9bc0a965a9bbd2bb0a1aab445_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\764ffb7a27d4b895ff051d874c0ed08b_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\76a2a5d5271da2d01e7777321b671ea5_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\76c97bd4a32e1eb62d4282ce83b72356_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7990ed7f125c0b320c34958c9e621114_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\79e76da2101036cb165a80a1109bff51_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7a26ec48a974f64f051169998b8b23cf_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7b06c2f91e2a2e1996392990b6ca343c_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7b0e290d968882370b3780a71615c677_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7bb778402ba437a37e8c152adb2c9f72_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7c383bd81cfb5b83a0cbd62a9d24dda7_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7d0a6c30e63393d5fb852b036930ccf0_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7d2b7512cdfaa50606f099e8c4970b10_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7dd97b0beb1e2fa410c4a7836b433c27_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7ddf473b558bc7b57763ec2f5492715c_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7e1dd73690c08763499b2fe269fb84aa_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7e29bfccdf01154a68cc1abfe5cc4f59_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7e9f2f484cad83081525fb92f8d6bde5_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7eeab87096dc2404d3d5cfb152c96062_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7f69b6c1909b7bdfb0c6ff578e1715e8_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7fdc4b9439ff5e1b60073a999e60749f_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\806adab0b05c17bf86b8887a1d18b09e_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\81614a3fc5446b0088c3ea8ee7198c80_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\81a739005e1f157f33951ff68e2d6fd2_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\82312f1c9ea7087ae4e5717374cc951a_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8256ca7c11776fba22e7ae9bf0ea2220_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8327093ce3e7be9fdcc44431f91c2f74_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\83bd87d669b65068f27b915f5a1b9935_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\83dca31f9f921442dfdf811155642987_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\848fa9d27854280d0d0fae8736d39fd3_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8587f3c045b9a9f85111b8b23265fbd3_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\860a706435ed353509b35c345641d1d1_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\866b5b2d2759535e9d01039b60ef8a72_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\871684cf740abdcdab0ed8623622420c_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8771a4c5337113481998034f9df6f959_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8826b3a94fd24298f3d99cf52465ba54_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\885b6af5d96079f4b2c9db34f5bb5d5d_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\889a9eea64cc11fec19c267f765ee6e1_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\88fe88d89d476ea57c906a2913c295f4_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\89230c39406b5c846e5f8a6d5c217200_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\892940bd9c0413929066b28c61ffb116_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\894bd3aa6a65f257bb12f591d2f29dd6_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8955a4120383650592e7d7e948693c13_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8993eed216737522b10c5fc2ebfdcd7e_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\89cefcc469c1055eb233c5b4599e77a3_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8a5db9cac16e7f81b17e8493e0019c90_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8b01c90382408c6c31134a2e67222cce_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8bdd72baab4d7260e128e18fe87596d1_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8bfb2f4daa9468639fe8b9eb478c226e_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8ca9317fcd8874ca75f39c24a56270d0_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8cc21ab373b0c7b4201eba8d4ebfefe7_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8d1f93036eea5de1361ed88af36a6c39_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8e43de7e77f9e1e5fe7003913dda586c_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8e708f4992b9c536cc997c8eaff41893_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8f8d6f80c8e27942c930ffc788c4fda5_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8f98f584556c15a228e0bb0c0806dbfe_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys&#

#14 trojanedbrian

trojanedbrian

    New Member

  • Authentic Member
  • Pip
  • 14 posts

Posted 02 March 2007 - 04:47 PM

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a3f1f3c0d91ce3b76ee63017bd94bfd7_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a4a403e84d8ad063452707ad0f59779d_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a4fa146079a041e312d7b554efb81baf_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a524c986e46af5b3d8960a97443435af_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a5896bc45385486382be094d2062f202_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a67eb5960ebb9fef916caab204c096c5_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a7e74cd3f89eea44ab0eb20aea410711_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a7ee383845f36dc0a9a929afe0a3b99b_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a805b422fc73808e9f61c1a57d4934da_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a82f52198fa91d8978d86ca83ec808fc_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a8c6e40da7fe91522ba9b85aef4b31f8_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a8c86f417547e979947e7cc1af563453_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a8d142d438e56a909201626cd7d1b62a_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a94d3c5b1770a84aa99e6b2d734420a5_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a9782c65d95046204d3c5d065c3ac2aa_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\aa1bed9a4e9a7c5a3d6a9b991254f6eb_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\aae3d2875e99a8fdcf7e8b5000e928b3_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ab3208d78c426af3dd8b419b0c65a62c_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ac500415ad28bc84c7b6f414cdb725fc_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\aca1f3281665ec8d8eaefa6e456b2d60_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\adda56eb0caec2411c7322b1fd52f57a_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ae2ec7128918f94d341476cc295fd3fe_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ae8fc0b578536f8949fc85b6d0435707_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\af2d727dae038177f305ef8785083692_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\afa728881f091b4dcd4ff3a9a31b98cd_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b05962f9816380f64d2cff47e95d7c2a_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b07e217ad080f1003f74860b71e4751d_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b0ba4e85f62b97bfadf4b4b857dba7b2_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b147100c664d05b500819b5f90afcf21_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b3104ac95d7dcd586fba2a9d37990dac_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b4863efcb5cd0735fbe44b30f08b01a1_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b4e3e00fd6b90727b304447fabd88104_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b53288a3d026a5ec160da021c6c58158_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b5512bdc0d3db2c828b73e79c5f75dcb_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b58bb067c28941c83e29387395bb0923_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b5e274ebebea095728de112d4b73a4dc_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b619e362d4560013003a83c2f077bc04_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b68d4fb3ddaf8bd30b3a7ed2cafe0707_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b71c825e97b8af5417c2dd20f944f1d6_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b8397471ed87b29bbe1baeef5b91aa24_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b852afdb87f0beaceb24224064003ea7_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b97a2e5d89c723e8837ca34fc3467ff5_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b9e1d32566ff85c71b7957bfbac07327_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ba14e0b62a286f7d8ef4b1f0a601b2be_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\baeb797ba808decddeac6c04010d6c4a_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bbd83b9af4e4add79fc970e42ee70899_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bc6991ee968b8f03d837183f89ecf38e_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bce028034c303d1745d000bee8f9803c_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bd5f9911685ad0ec92dd00e011238a36_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bd8ac50fd909f8917f75171c5cd44d54_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bd8e85ed1ef06d513dec6a5b66953ddd_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bdd07a83b1b56a2a30373ceb14a90c5e_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\be5affbce28ac573cf6b9fb9df13f165_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c02cdcaeba60e5b6c8b47f171de9172c_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c0465b20991a83f24ac46aa6a25ee1d5_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c07c1674232e9d77380ce208dc856f1e_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c10db6776c3ef5483b681df747104a9e_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c136efd040734b53bc38e906b0baa89b_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c211adf2433f77ea996eeafea991aaf7_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c2728f2a6992b8291abe0a9365d28ca4_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c2c94c14d71c4dc0818009da8537ac8e_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c2d48fe5a547e006af5dd1413d3b3c31_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c2e3b65f3b4eadda679b12b96d346497_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c34d02939ec776e2999b63fe246ccddc_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c36d102a0886a08fc6c711487b1ead0b_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c55b082f2fd728f65a4d093783368188_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c5a7f101f89292adf03a67a84c5b71e9_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c5da34c710c74f970d34e4c5f19c2d3b_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c65333dbefe62690de5b094f4c455fc7_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c68d6cef43235e2a739033c232e09caa_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c709836246354f65b9536bd2dfecca16_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c82cdb488b9b82d3ed2081013bb27b26_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c8cd834538cc3001984f1b36389e7230_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c93527130ab2824e135146bff562c930_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c9354d05c38bf2b807786e7d4f36f56c_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cca08f1a1cb5ebd383d5284b083d6d50_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ccc3ed8f5de4765a8e400bf34b2dd0a3_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cd36bfc85c4091796d7545bf91e5f0e3_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cdf7f7aef852bd03ad9edcfccbcec44e_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ce12a4674d1e96bc3e42c4116ca4e65e_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ce7aaeb066d3f33d8b018b2727eba5e5_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cec0e297d441735aeca37c476ae9df57_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cee0484ffea93d9e523d55128b64736d_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cf21e2a699b3dcfb0f3888d8be7ac472_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cf95cce62b51f8ff585e41c9837c0b14_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cff9314f34142ec40fc2c571aed74358_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d0841a1d971c0e13cac24096a3f6eec1_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d09d6843341ab992e0a95edf2ae831aa_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d09f575ac4f287d3033e6f616e928833_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d0c4865d0365e175d740f61acb164e5e_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d0d0137663094030113a380f0c754525_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d1f174a366ec56290dec684c5b0c0c0f_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d273528f3f781fdfc2e8b01dff8bbd20_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d3f62de85bd2f5e5c87ec2c08d993474_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d47feca35147ce78dd86947b4225fba7_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d50d99e5a685529b3227e284516f0e52_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d64603f669f24a21ee1e849c9634888b_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d695b304d9567670beeada60924ea293_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d82a06c0b0f6a15e34139e0fc3bdae49_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d82b88a523c944f6be1232a6ab384a55_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d8644b427c146bcd3a530920fc301230_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d8a04dc3b8d529cacf790edeb1bbf355_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d90ea2e1f7c0c7eb57dd4e67239bcde3_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d952f7f90bf38a7d2a5c26f2adbf72e7_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d97ee0d17982909ed7c5f077259f5811_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d9c8b94fb143ba0c01b3b9d5a9f477bf_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d9f0458cf77781f4b898d0401229a573_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\db0af9dbe666242e364f337e750233ff_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\db904a548ff797b97447bbf70f010ecb_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\db9f4fb77c69a89ef11b3757628c95ec_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dbd3bf0528ec72b70936cd15d4431283_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dc40e136e370a43c14d6ade400be9f0c_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dc8d2873b09ac3c4545a9c6a4a5cf4b1_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dcbad418b6e9127f845922f13656fbf2_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dce0f781d3d632ea7ed8ff73fd6e7aa2_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dda8d37e49ce9cefa94f131591ff8a1e_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\de034e087388a1a8203dc444357176de_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\deb3469f77635e6d8f9ae6574cbc40ca_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\df21bad4c29c663dc0713b41153b720a_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e17ce7af3351c451e4d2e9a52af0ae94_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e1a34471b604486ce9545d67e9e60d9a_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e27ac6e3cc471d67a0114f8a1e03f4f5_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e33bfd0b1335cba7ff481788721be1ee_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e33fa0622eede262bf8bf6f6c5887a40_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e3bf9f76582a5e63b10e5459c29df8cd_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e3ed8719aa8986fcf52f28dbe34928ce_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e4444a65d8529c8db46c1a0545cb2ab4_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e579623bd963c94b6933707163f6f7b7_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e670070e9715ad8742bb7505a7ce0bed_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e7004cb035bcffcb4b7ceddd063c63da_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e70914e69dfabd23314e8ee2ade96448_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e86c2a00e795ccce14c6bee25a15e241_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e95ab9f92d8e9c957b08d247b4996822_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e9e611313d718f6916f8425cdc903784_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ea58ed034788aa00eff738cfd6229314_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\eaee49768273f374386fba3eb246ce6f_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\eb0010b7d6ec5dbb807e69481b8af0dd_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\eb61bb980dd430a4f3034de69a761fcd_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\eb912ee3a1d13e0a9056aac3ed08428a_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ec004115d8b5a89d33d26958064a9909_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ecca7bdd57475fbb39ae44aedb12d8fc_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ed07ca200c08238d502fc425f4b9d72b_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ed1a1a3c32c7c7f2a4ef08204511c881_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ed822adec499492a7413e62ba07bbd25_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\eed64152f4d2e1facfa2be3d62a24d9b_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\efdb93bcd3408639a6106e99c2991dc9_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f0de7b1cdcd9091bec82e13a9abbbd01_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f10fbdb6c58e247cbd15dedb5f1464b9_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f1ba72ca70c17191b92ea21bf9e8ce34_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f25a1bd52487565e385aebce7484c5a8_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f27f48b9c827c3b5f2cc8ff544939ec7_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f28b9c5345ad69550663a1be86707e6c_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f36994f49a771315af7443a1ab2e9a67_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f3cb3846c83898deab2d6f0c5bc6ed8b_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f3de8fcfd03a402869ff6317d64259ee_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f42335b1920709535e463736a912a363_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f4a89cbb1d2ee86c71dae7e459cee3e4_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f4c31c648d2f9bc8a1b5e3a67f0f8a9a_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f4c54fd87097e1555d15b8b5f3f57ab9_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f4c89fbe7f964ae0e3fd4e54fb3103bf_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f565de6bee1c07ae8d9e2bc9c35f1775_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f83fe2f1d6beb43a141d1609947bb7c7_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f8bddcff1f2bf8f94082711168aac49b_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f90ae0be0ce509a527197c56ffcefe55_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f9b44a82a90183c869a803fee06de018_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\faad028d7da553caa42b52fa9e52febd_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\faba3fc9d0797e49e38761491bd21414_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fb6dc5e4d6e619bc81abafc29a7bd5f4_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fd075afb3dff13f7c00704756cf185f5_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fdab5742f342f520b92e61b28f541211_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fdf30008fcc551546ae8df7a1f02abf2_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fe3184ffa791ec28d165dd3af255e9bc_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fe3cc8aa647482ab384d3c9abbf04e13_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fed466afa2e7e79feb4e4ae4abbd947f_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ff247df8030431b92e2338a6010f6f9d_2df4a75e-cee0-46ca-864f-5ecd42a479df Object is locked skipped

C:\Documents and Settings\Dad\Application Data\Microsoft\Outlook\Outlook.srs Object is locked skipped

C:\Documents and Settings\Dad\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\Dad\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped

C:\Documents and Settings\Dad\Local Settings\Application Data\Microsoft\Outlook\archive.pst Object is locked skipped

C:\Documents and Settings\Dad\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst Object is locked skipped

C:\Documents and Settings\Dad\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\Dad\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\Dad\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Dad\Local Settings\History\History.IE5\MSHist012007030220070303\index.dat Object is locked skipped

C:\Documents and Settings\Dad\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped

C:\Documents and Settings\Dad\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Dad\ntuser.dat Object is locked skipped

C:\Documents and Settings\Dad\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\Dad\UserData\index.dat Object is locked skipped

C:\Documents and Settings\Guest\Local Settings\Temporary Internet Files\Content.IE5\GNYXELW3\prompt[1].htm Infected: Trojan-Downloader.JS.IstBar.ab skipped

C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc138\bksolutions.gif Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc138\chip_7..jpg Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc138\ZbThumbnail.info Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc21\Bet, Play & Win.url Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc21\Broadband.url Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc21\Entertainment.url Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc21\Mobile.url Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc21\Money.url Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc21\Music.url Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc21\Sport.url Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc21\Travel.url Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc21\Woman.url Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc22\Search.url Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc228\basket_aw03.gif Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc228\btn_go(1).gif Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc228\btn_go.gif Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc228\checkout.css Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc228\cmdatatagutils.js Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc228\dots_white.gif Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc228\eluminate.js Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc228\help_aw03.gif Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc228\imrg-small.gif Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc228\kays_logo_ss05.gif Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc228\main-v2.js Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc228\main.css Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc228\myaccount_aw03.gif Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc228\myoffers_aw03.gif Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc228\payment_methods_qw02.gif Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc228\pro2-emergency_aw04.gif Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc228\spacer(1).gif Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc228\Spacer.gif Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc228\techprops.js Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc228\Thumbs.db Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc228\wishlist_aw03.gif Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc23\Build a website.url Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc23\Call from your PC.url Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc23\Chat.url Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc23\Domains.url Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc23\Email.url Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc23\Forums.url Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc23\Join a club.url Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc23\Messenger.url Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc23\Share and print photos.url Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc24\A2Z of stores.url Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc24\Shopping.url Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc24\Welcome to QVCUK.com.url Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc341\sudoku.htm Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc341\sudoku_files\counter.js Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc341\sudoku_files\counter.png Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc60\Scrap Book.htm Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc60\Scrap Book_files\991056062776572QVC.htm Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc60\Scrap Book_files\border.htm Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc60\Scrap Book_files\cmframeset.js Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc60\Scrap Book_files\MastHeadBottom_QVCUK.htm Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc60\Scrap Book_files\MastHeadBottom_QVCUK_files\frameset.css Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc60\Scrap Book_files\MastHeadBottom_QVCUK_files\home_go.gif Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc60\Scrap Book_files\MastHeadBottom_QVCUK_files\phome_NewSpacer.gif Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc60\Scrap Book_files\MastHeadBottom_QVCUK_files\pNewhome_Search.gif Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc60\Scrap Book_files\MastHeadBottom_QVCUK_files\Thumbs.db Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc60\Scrap Book_files\MastHeadMiddle_QVCUK.htm Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc60\Scrap Book_files\MastHeadMiddle_QVCUK_files\frameset.css Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc60\Scrap Book_files\MastHeadMiddle_QVCUK_files\pNewhome_Clea.gif Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc60\Scrap Book_files\MastHeadMiddle_QVCUK_files\pNewhome_CO.gif Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc60\Scrap Book_files\MastHeadMiddle_QVCUK_files\pNewhome_Elec.gif Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc60\Scrap Book_files\MastHeadMiddle_QVCUK_files\pNewhome_Fashion.gif Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc60\Scrap Book_files\MastHeadMiddle_QVCUK_files\pNewhome_HB.gif Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc60\Scrap Book_files\MastHeadMiddle_QVCUK_files\pNewhome_HG.gif Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc60\Scrap Book_files\MastHeadMiddle_QVCUK_files\pNewhome_Jewellery.gif Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc60\Scrap Book_files\MastHeadMiddle_QVCUK_files\pNewHome_MQTVG.gif Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc60\Scrap Book_files\MastHeadMiddle_QVCUK_files\pNewHome_QVCUK.comlogo.gif Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc60\Scrap Book_files\MastHeadTop_QVCUK.htm Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc60\Scrap Book_files\MastHeadTop_QVCUK_files\frameset.css Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc60\Scrap Book_files\MastHeadTop_QVCUK_files\go_left.gif Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc60\Scrap Book_files\MastHeadTop_QVCUK_files\Thumbs.db Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc60\Scrap Book_files\MastHeadTop_QVCUK_files\transparent.gif Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc68\firstrun.log Object is locked skipped

C:\RECYCLER\S-1-5-21-1659004503-113007714-725345543-1005\Dc69\MSForms.exd Object is locked skipped

C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

C:\System Volume Information\_restore{0E024C5D-03DF-4DE5-AC56-9A1BE5B97F9C}\RP428\change.log Object is locked skipped

C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

C:\WINDOWS\SchedLgU.Txt Object is locked skipped

C:\WINDOWS\SoftwareDistribution\EventCache\{7EFA611F-7499-4028-B92B-EEB1DFA4D155}.bin Object is locked skipped

C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

C:\WINDOWS\Sti_Trace.log Object is locked skipped

C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\default Object is locked skipped

C:\WINDOWS\system32\config\default.LOG Object is locked skipped

C:\WINDOWS\system32\config\Internet.evt Object is locked skipped

C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped

C:\WINDOWS\system32\config\OSession.evt Object is locked skipped

C:\WINDOWS\system32\config\SAM Object is locked skipped

C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\SECURITY Object is locked skipped

C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

C:\WINDOWS\system32\config\software Object is locked skipped

C:\WINDOWS\system32\config\software.LOG Object is locked skipped

C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\system Object is locked skipped

C:\WINDOWS\system32\config\system.LOG Object is locked skipped

C:\WINDOWS\system32\h323log.txt Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

C:\WINDOWS\wiadebug.log Object is locked skipped

C:\WINDOWS\wiaservc.log Object is locked skipped

C:\WINDOWS\WindowsUpdate.log Object is locked skipped

E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

G:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

Scan process completed.




Logfile of HijackThis v1.99.1
Scan saved at 22:47:05, on 02/03/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Dad\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.co.uk/0SEENGB/SAOS01
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bbc.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [hpppta] C:\Program Files\Hewlett-Packard\HP PrecisionScan\PrecisionScan\hpppta.exe /ICON
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [Qu

#15 Susan528

Susan528

    SuperMember

  • Authentic Member
  • PipPipPipPipPip
  • 3,194 posts

Posted 02 March 2007 - 04:55 PM

Your hijackthis log got cut off. Please post (reply) with the complete log.
Posted Image

Proud member of ASAP since 2005

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Want to help others? Come join us in the Class Room and learn how.

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users