This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Help Adware / Spy Removal

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Need some help. The adware and Spy Infections have taken over the PC. It's real bad no navigate on the internet lie this.
Besides there is something strange that moves my cursor location when i'm typing, and my types gets messed up Noidea what this could be.
Here is my first Hijackthis log.

Logfile of HijackThis v1.99.1
Scan saved at 9:44:54 AM, on 1/19/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\EIA\ETS\EIATSService.exe
C:\EIA\SDA\QckAuditSvr.exe
C:\EIA\USAGE\UsageSvr.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\WINDOWS\System32\CCM\CcmExec.exe
C:\WINDOWS\System32\CCM\SMSCliUI.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\Msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
d:\User Folders\dgranadi\Application Data\U3\0000167186732EE8\LaunchPad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = A2k-adcprx-01.lsgsc.com:8080
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [BM6f06eb26] Rundll32.exe "C:\WINDOWS\system32\erpoores.dll",s
O4 - HKLM\..\Run: [6c35d8ba] rundll32.exe "C:\WINDOWS\system32\teojaygq.dll",b
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\Msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\AccessXP\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://*.americas.lsgsc.com
O15 - Trusted Zone: http://*.lsgsc.com
O15 - Trusted Zone: http://www.servicecenter.unisys.com
O15 - Trusted IP range: http://10.192.252.71
O15 - Trusted IP range: http://10.192.252.71 (HKLM)
O16 - DPF: Yahoo! Canasta - http://download2.games.yahoo.com/games/clients/y/yt2_x.cab
O16 - DPF: {0a454840-7232-11d5-b63d-00c04faedb18} -
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1191941202941
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://orangebusiness.webex.com/client/v_m…bex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = americas.lsgsc.com
O17 - HKLM\Software\..\Telephony: DomainName = americas.lsgsc.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = americas.lsgsc.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = americas.lsgsc.com
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: CMF PDF - LAN SuperVision, Inc. - C:\CMF\CMFTDF\CMFWPDF.EXE
O23 - Service: CMF Windows Installer - LAN SuperVision Inc. - C:\CMF\CMFTDF\CMFWINST.EXE
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: EIA Auditor - Unknown owner - C:\EIA\ETS\EIATSService.exe
O23 - Service: EIA PMP Server (EIAPMP) - Unknown owner - C:\EIA\SDA\QckAuditSvr.exe
O23 - Service: EIA Usage Tracker (EIAUsage) - Lan Supervision - C:\EIA\USAGE\UsageSvr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpdj - HP - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\hpdj.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program Files\McAfee\Common Framework\FrameworkService.exe" /ServiceStart (file missing)
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: OracleOracleHome90ClientCache - Unknown owner - C:\Oracle\ora90\BIN\ONRSD.EXE
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service (file missing)

Thanks
Daniel
Hello dgb and welcome to the What the Tech Forums

My name is Trevuren and I will be helping you with your problem. Some trojans have a way of masking their presence from the HijackThis program when they recognize the name. I think that this is the case here because there are no 02 or 020 entries visible in your log. This vundo trojan has a tendancy to bring a few of its friends to the party.


Please print out or copy this page to Notepad. Make sure to download all the required tools to your desktop before starting. If there is anything that you do not understand, ask your question(s) before proceeding with the fixes.

A. Tools to download:
  • Right click HERE and Save As (in IE it's "Save Target As") in order to download DelDomains.inf to your desktop.
  • Download SDFix and save it to your Desktop.
  • Download ComboFix and save it to your desktop.

**Note: In the event you already have SDFix and/or ComboFix, these are new versions that I need you to download. It is important that they are saved directly to your desktop**


B. Running the Tools


1. Run DelDomains:

Right click DelDomains.inf and select: Install (no need to restart)
Note: This will remove all entries in the "Trusted Zone" and "Ranges" also.


Very Important!

Before running SDFix and ComboFix
:
  • Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with both SDFix and ComboFix and remove some of their embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
  • Also, make sure you are physically disconnected from the Internet (unplug the cable) after downloading the programs but before running the files.


2. Run SDFix:

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Now reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually
  • Instead of Windows loading as normal, the Advanced Options Menu should appear
  • Select the first option, to run Windows in Safe Mode, then press Enter
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
  • Finally, copy the content of Report.txt to Notepad and Save it to your Desktop as you will be asked to post it later on.


3. Run ComboFix:

WARNING:
  • IF you have not already done so ComboFix will disconnect your machine from the Internet when it starts.
  • Do not re-connect your machine back to the Internet until ComboFix has completely finished.
  • If there is no Internet connection when Combofix has completely finished, just restart your computer to restore the connection.

Double-click on combofix.exe and follow the prompts. When finished, it will produce a report for you.


**Note: Do not mouseclick comboFix's window while it's running. That may cause it to stall**


C. After ComboFix has finished its run:
  • Restart/re-enable all the programs that you disabled before running the tools.
  • Physically reconnect to the internet.

D. Posting Logs/Reports:
  • Report.txt
  • C:\ComboFix.txt
  • A new HijackThis log run after all the tools have been run.
Thank you Trevuren for your help.
I followed your instructions and here are the logs.

SDFIX


SDFix: Version 1.129

Run by [removed] on Sat 01/19/2008 at 04:47 PM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting…


Normal Mode:
Checking Files:

Trojan Files Found:

C:\WINDOWS\b10?.exe - Deleted
C:\WINDOWS\b14?.exe - Deleted
C:\WINDOWS\b15?.exe - Deleted
C:\WINDOWS\system32\pac.txt - Deleted





Removing Temp Files…

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-19 17:29:28
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden services & system hive …

scanning hidden registry entries …

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Reporting\EventCache\Sus]
"FlushCacheFiles"=str(7):"\x6264\2\x1e8(\x1e8(\xfff8\xffff\xddb8\x15d\xfff8\xffff\xcfc8\x145\xff10\xffff\x6b73\17\xc5f8\x81\x6628\0\1\0\xd8\0\1\x8004\xbc\0\xcc\0\0\0\24\0\2\xa8\6\0\0$\31\2\x501\0\0\x500\25\0\xe75e\x56ed\xe10c\xd877\xaac3\x1471\xf318\0\xb00$\0\x8000\x501\0\0\x500\25\0\xe75e\x56ed\xe10c\xd877\xaac3\x1471\xf318\0\0\24?\17\x101\0\0\x500\22\0\xb00\24\0\x1000\x101\0\0\x500\22\0\0\30?\17\x201\0\0\x500 \0\x220\0\xb00\30\0\x1000\x201\0\0\x500 \0\x220\0\x201\0\0\x500 \0\x220\0\x101\0\0\x500\22\0\xffa8\xffff\x6b6e \xf080\xc804\x61fc\x1c5\0\0\x2218\0\0\0\0\0\xffff\xffff\xffff\xffff\2\0\x7c80\0\x210\0\xffff\xffff\0\0\0\0\30\0*\0\0\0\4\0\x632e\x6c72\0\0\xffe8\xffff\x6b76\0\20\0\x7c08\0\1\0\0\0\xffe8\xffffCRLFile\0\0\0\xfff8\xffff\x7f08\0\xffd8\xffff\x6b76\f*\0\x7c50\0\1\0\1\0\x6f43\x746e\x6e65\x2074\x7954\x6570\0\0\xffd0\xffffapplication/pkix-crl\0\0\xfff0\xffff\x7bf0\0\x7c28\0st\xffa8\xffff\x6b6e \xf080\xc804\x61fc\x1c5\0\0\x2218\0\0\0\0\0\xffff\xffff\xffff\xffff\2\0\x7d80\0\x210\0\xffff\xffff\0\0\0\0\30\0006\0\0\0\4\0\x632e\x7472\0\0\xffe8\xffff\x6b76\0\20\0\x7d00\0\1\0\0\0\xffe8\xffffCERFile\0\0\0\xffd8\xffff\x6b76\f6\0\x7d40\0\1\0\1o\x6f43\x746e\x6e65\x2074\x7954\x6570-c\xffc0\xffffapplication/x-x509-ca-cert\0\0\0\0\xfff0\xffff\x7ce8\0\x7d18\0\x7475\x5420\xffa8\xffff\x6b6e \x1c08\x811a\xb3b\x1c8\0\0\x2218\0\3\0\0\0\x9fb0\xf8\xffff\xffff\3\0\x7e50\0\x210\0\xffff\xffff"\0\0\0\32\0\22\0\0\0\4\0\x632e\x7373\0\0\xffd8\xffff\x6b76\r\n\0\x7e10\0\1\0\1\x5252\x6550\x6372\x6965\x6576\x5464\x7079\x3c65\x666c\xfff0\xfffftext\0\x4120\xffe8\xffff\x6b76\0\20\0\x7e38\0\1\0\08\xffe8\xffffCSSfile\0\x39a8:\xfff0\xffff\x7de8\0\x7e20\0\x7e60\0\xffd8\xffff\x6b76\f\22\0\x7e88\0\1\0\1\0\x6f43\x746e\x6e65\x2074\x7954\x6570\x92f8\0\xffe8\xfffftext/css\0\0\xff98\xffff\x6b6e \x52c0\xfea0\x6227\x1c5\0\0\x7d90\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x7c20\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\0\0\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656cr\0\0\0\xffe8\xffff\x6b76\0N\0\x7f20\0\1\0\0\0\xffa8\xffff{eec97550-47a9-11cf-b952-00aa0051fe20}\0\0\0\0\xfff0\xffff\x5780\xfa\x58e0\xfa\x614\x439a\xffa8\xffff\x6b76>\xa0\0\x540\1\1\0\1\0\x3a43\x575c\x4e49\x4f44\x5357\x4d5c\x4955\x465c\x6c61\x626c\x6361\x5c6b\x3430\x3730\x615c\x7664\x7061\x3369\x2e32\x6c64\x2e6c\x756d\x5b69\x6f4d\x5266\x7365\x756f\x6372\x4e65\x6d61\x5d65\x3d3d\xffe8\xffff\x6b76\0n\0\x4170t\1\0\0\3\xfff8\xffff\xc170p\x6268\x6e69\x8000\0\x1000\0\0\0\0\0\0\0\0\0\0\0\xfff8\xffff\x6810,\xfff0\xffff\x7fe0\0\x4fd8\3\xa130\x95\xfff0\xffff\x9d28,\x9fd8,\xa170\x95\xff88\xffff\x6b6e \x40a5\xcc4b\xcad2\x1c7\0\0\x1aa0m\0\0\0\0\xffff\xffff\xffff\xffff\2\0\x19d8m\x9600\x121\xffff\xffff\0\0\0\0\16\0\4\0\22\0&\0\x387b\x4433\x3634\x3937\x2d46\x3642\x3744\x312d\x4431\x2d32\x4642\x3633\x302d\x4330\x3430\x4246\x3039\x3041\x7d33e\xffe0\xffff\x6b76\a\4\x8000\1\0\4\0\1a\x6e45\x6261\x656cd\xfff8\xffff\xb870&\xffa8\xffff\x6b6e \x83b0\xfe8f\x6227\x1c5\0\0\x2218\0\1\0\0\0\x8258\0\xffff\xffff\1\0\x8170\0\x210\0\xffff\xffff"\0\0\0\0\0\20\0le\4\0\x632e\x7275KC\xffe8\xffff\x6b76\0\20\0\x8158\0\1\0\0$\xffe8\xffffcurfile\0\xf861$\xfff8\xffff\x8140\0\xff98\xffff\x6b6e \x83b0\xfe8f\x6227\x1c5\0\0\x80e8\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x8250\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\xe758\16\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656c\x4372\26\xcd61\x1011\xffe8\xffff\x6b76\0N\0\x81f8\0\1\0\0\xb9f9\xffa8\xffff{098f2470-bae0-11cd-b579-08002b30bfeb}\0\30\xf0f0\x5d3b\xfff8\xffff\x81e0\0\xfff0\xffff\x686c\1\x8178\0\x3a37\xaac9\xff30\xffff\\americas.lsgsc.com\SysVol\americas.lsgsc.com\Policies\{9749AE93-6AEE-449B-8CA0-35A3F584CCFA}\User\0\xffff\xffff\xffa0\xffffLDAP://OU=Regions,DC=americas,DC=lsgsc,DC=com\0\xffe0\xffff\x6b76\aN\0\x69e0$\1\0\1a\x5047\x4e4f\x6d61e\xffe0\xffff\x6b76\6\4\x8000\0\0\4\0\1\x120\x506c\x7261\x6d61m\xfff8\xffff\x7a70\0\xfff8\xffff\xd18\x15e\xfff8\xffff\xec68\x14b\xffa8\xffff\x6b6e \x988f\xeb9\x1bea\x1c8\0\0\x2218\0\1\0\0\0\x37a8\0\xffff\xffff\3\0\x3d68\0\x210\0\xffff\xffff\30\0\0\0\32\0"\0\xb398\0\4\0\x642e\x7461\xb3a4\0\xffe0\xffff\x6b76\6\2\x8000\0\0\1\0\1\0\x6f4e\x704f\x6e65\0\xfff8\xffff\xf7d85\xffa8\xffff\x6b6e \x9f60\x3b11\x6228\x1c5\0\0\x2218\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x84f8\0\x210\0\xffff\xffff\0\0\0\0\0\0\16\0\x2c52\x5220\3\0\x642e\x7362\x202c\x3c22\xffe8\xffff\x6b76\0\16\0\x84e0\0\1\0\0\x3e72\xffe8\xffffdbfile\0\x2020\x2020\x2020\xfff8\xffff\x84c8\0\xffa8\xffff\x6b6e \x83b0\xfe8f\x6227\x1c5\0\0\x2218\0\1\0\0\0\x8638\0\xffff\xffff\0\0\xffff\xffff\x210\0\xffff\xffff"\0\0\0\0\0\0\0\x9140\31\4\0\x642e\x6762\x4c3c\x5f6c\xff98\xffff\x6b6e \x83b0\xfe8f\x6227\x1c5\0\0\x8500\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x8630\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\xc2c8\20\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656c\xc872\20\x6c7e\xaed3\xffe8\xffff\x6b76\0N\0\x85d8\0\1\0\0\x4260\xffa8\xffff{098f2470-bae0-11cd-b579-08002b30bfeb}\0\20\x7737\xb2fe\xfff8\xffff\x85c0\0\xfff0\xffff\x686c\1\x8558\0\x3a37\xaac9\xffd8\xffff\x6b76\v4\0\x7a10\0\1\0\1s\x6944\x7073\x616c\x4e79\x6d61eup\xffe8\xffff\x6b76\0B\0\x6a18\xd8\1\0\0\x116\xfff8\xffff\x8670\0\xfff8\xffff\x86a8\0\xfff8\xffff\x1f68\x117\xfff8\xffff\x2700Y\xffe8\xffff\x6b76\0B\0\x9210\b\1\0\0\0\xfff8\xffff\xe248\x132\xffe8\xffff\x6b76\0\4\x80004\0\1\0\0\0\xffe0\xffff\x6b76\a\30\0\xd8f0\0\1\0\1}\x6f4c\x6767\x6e69\x167\xffe0\xffff\x6b76\3\4\x8000\x30d9\x333b\4\0\1\0\x7263c\x8390\0\xffe0\xffff\x6b76\4\\0\x8338\0\1\0\1\0\x694c\x6b6e\x616c\x4e79\xfff8\xffff\x86c8\0\xfff0\xffff\xe168&\xe190&\xe1b8&\xffe8\xffff\x686c\2\xd570\0\x6fce\x6bd0\xb900\0\x3da2\x3df\xfff0\xffff\x2858\x107\x7208\x121\xf575\x540f\xfff0\xffff\xe0e8&\xe278&\x8758\0\xffa8\xffff\x6b6e \x1830\x3b10\x6228\x1c5\0\0\x2218\0\1\0\0\0\x8908\0\xffff\xffff\1\0\x8820\0\x210\0\xffff\xffff"\0\0\0\32\0\n\0\0\0\4\0\x642e\x6665\0\0\xffd8\xffff\x6b76\r\n\0\x8810\0\1\0\1\x2e73\x6550\x6372\x6965\x6576\x5464\x7079\x7265\x7669\xfff0\xfffftext\0\x4774\xfff8\xffff\x87e8\0\xff98\xffff\x6b6e \x1940\xfe94\x6227\x1c5\0\0\x8790\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x8900\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\0\0\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656cr\0\0\0\xffe8\xffff\x6b76\0N\0\x88a8\0\1\0\0\0\xffa8\xffff{5e941d80-bf96-11cd-b579-08002b30bfeb}\0\0\0\0\xfff8\xffff\x8890\0\xfff0\xffff\x686c\1\x8828\0\x3a37\xaac9\xffa8\xffff\x6b6e \xf080\xc804\x61fc\x1c5\0\0\x2218\0\0\0\0\0\xffff\xffff\xffff\xffff\2\0\x8a10\0\x210\0\xffff\xffff\0\0\0\0\30\0006\0\0\0\4\0\x642e\x7265\0\0\xffe8\xffff\x6b76\0\20\0\x8988\0\1\0\0\0\xffe8\xffffCERFile\0\0\0\xfff8\xffff\x8a80\0\xffd8\xffff\x6b76\f6\0\x89d0\0\1\0\1\0\x6f43\x746e\x6e65\x2074\x7954\x6570\0\0\xffc0\xffffapplication/x-x509-ca-cert\0\0\0\0\xfff0\xffff\x8970\0\x89a8\0yb\xffa0\xffff\x6b6e \xcd80\x3fc8\x6228\x1c5\0\0\x2218\0\1\0\0\0\x8bd8\0\xffff\xffff\1\0\x89a0\0\x210\0\xffff\xffff"\0\0\0\0\0Z\0\0\0\t\0\x442e\x7365\x4c6b\x6e69k\0\0\0\xffe8\xffff\x6b76\0Z\0\x8a98\0\1\0\0\0\xffa0\xffffCLSID\{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}\0\0\xff98\xffff\x6b6e \xfc80\xfe8d\x6227\x1c5\0\0\x8a20\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x8bd0\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\0\0\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656cr\0\0\0\xffe8\xffff\x6b76\0N\0\x8b78\0\1\0\0\0\xffa8\xffff{098f2470-bae0-11cd-b579-08002b30bfeb}\0\0\0\0\xfff8\xffff\x8b60\0\xfff0\xffff\x686c\1\x8af8\0\x3a37\xaac9\xffa8\xffff\x6b6e \x9580\x4213\x6228\x1c5\0\0\x2218\0\2\0\0\0\x74e8\0\xffff\xffff\3\0\x8cc0\0\x210\0\xffff\xffff"\0\0\0\32\0\34\0\xc300\b\4\0\x642e\x6269\x7d5b\x2f3a\xffd8\xffff\x6b76\r\f\0\x8c68\0\1\0\1\x7263\x6550\x6372\x6965\x6576\x5464\x7079\x3465\x3032\xfff0\xffffimage\0\xfff8\xffff\x73e0\0\xffd8\xffff\x6b76\f\24\0\x8ca8\0\1\0\1F\x6f43\x746e\x6e65\x2074\x7954\x6570\P\xffe8\xffffimage/bmp\0\xfff0\xffff\x8c40\0\x8c80\0\x8cd0\0\xffe8\xffff\x6b76\0\34\0\x8ce8\0\1\0\0t\xffe0\xffffPaint.Picture\0\xff20\xffffLDAP://CN=User,CN={9749AE93-6AEE-449B-8CA0-35A3F584CCFA},CN=Policies,CN=System,DC=americas,DC=lsgsc,DC=com\0\0\x8d70\0\xffa8\xffff\x6b6e \x5230\x2b97\x6228\x1c5\0\0\x2218\0\1\0\0\0\x8f88\0\xffff\xffff\1\0\x8ea0\0\x210\0\xffff\xffff"\0\0\0\30\0002\0\0\0\4\0\x682e\x7871\0\0\xffd8\xffff\x6b76\f2\0\x8e68\0\1\0\1\0\x6f43\x746e\x6e65\x2074\x7954\x6570\0\0\xffc8\xffffapplication/mac-binhex40\0\0\xfff8\xffff\x8e40\0\xff98\xffff\x6b6e \x83b0\xfe8f\x6227\x1c5\0\0\x8de8\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x8f80\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\0\0\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656cr\0\0\0\xffe8\xffff\x6b76\0N\0\x8f28\0\1\0\0\0\xffa8\xffff{098f2470-bae0-11cd-b579-08002b30bfeb}\0\0\0\0\xfff8\xffff\x8f10\0\xfff0\xffff\x686c\1\x8ea8\0\x3a37\xaac9\xffa8\xffff\x6b6e \xd7a0\xf3e4\x6227\x1c5\0\0\x2218\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xbe70\0\x210\0\xffff\xffff\0\0\0\0\0\0\16\0\x8baa\x166d\3\0\x682e\x6c74\x1b0f\xc6b6\xfff8\xffff\x7558\0\xfff8\xffff\x9148\0\x6268\x6e69\x9000\0\x1000\0\0\0\0\0\0\0\0\0\0\0\xff98\xffff\x6b6e \x1940\xfe94\x6227\x1c5\0\0\x7500\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x8ff0\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\0\0\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656cr\0\0\0\xffa8\xffff{5e941d80-bf96-11cd-b579-08002b30bfeb}\0\0\0\0\xfff0\xffff\x686c\1\x9020\0\x3a37\xaac9\xffa8\xffff\x6b6e \x1830\x3b10\x6228\x1c5\0\0\x2218\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x8ff8\0\x210\0\xffff\xffff\0\0\0\0\32\0\n\0\x2020\x203d\4\0\x642e\x7a69\x2020\x2020\xffd8\xffff\x6b76\r\n\0\x9170\0\1\0\1\x4e5f\x6550\x6372\x6965\x6576\x5464\x7079\x6565\x6942\xfff0\xfffftext\0\x7367\xffa8\xffff\x6b6e \x5230\x2b97\x6228\x1c5\0\0\x2218\0\1\0\0\0\x9358\0\xffff\xffff\2\0\x9270\0\x210\0\xffff\xffff"\0\0\0\30\0002\0002,\4\0\x642e\x6c6cmd\xffe8\xffff\x6b76\0\20\0\x91f0\0\1\0\0$\xffe8\xffffdllfile\0\xffdd$\xfff8\xffff\x92e8\0\xffd8\xffff\x6b76\f2\0\x9238\0\1\0\1\0\x6f43\x746e\x6e65\x2074\x7954\x6570\0\0\xffc8\xffffapplication/x-msdownload\0\0\xfff0\xffff\x91d8\0\x9210\0\xa3d8\6\xff98\xffff\x6b6e \x83b0\xfe8f\x6227\x1c5\0\0\x9180\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x9208\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\x2da8\23\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656c\x972\t\x12a4\x9f2\xffe8\xffff\x6b76\0N\0\x9300\0\1\0\0\x3572\xffa8\xffff{098f2470-bae0-11cd-b579-08002b30bfeb}\0\0\0\0\xfff0\xffff\x686c\1\x9280\0\x3a37\xaac9\xffa8\xffff\x6b6e \x83b0\xfe8f\x6227\x1c5\0\0\x2218\0\1\0\0\0\x94a0\0\xffff\xffff\0\0\xffff\xffff\x210\0\xffff\xffff"\0\0\0\0\0\0\0\xfd08\b\4\0\x642e\x5f6c\x9aec\x11fe\xff98\xffff\x6b6e \x83b0\xfe8f\x6227\x1c5\0\0\x9368\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x9498\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\xe158"\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656c\xf672"\x3063\x5b24\xffe8\xffff\x6b76\0N\0\x9440\0\1\0\0\xf0ca\xffa8\xffff{098f2470-bae0-11cd-b579-08002b30bfeb}\0\26\x10d1\x3a16\xfff8\xffff\x9428\0\xfff0\xffff\x686c\1\x93c0\0\x3a37\xaac9\xffa8\xffff\x6b6e \x47f0\xd1de\x6235\x1c5\0\0\x2218\0\a\0\0\0\x9928\0\xffff\xffff\2\0\xd00\x8c\x210\0\xffff\xffff$\0\0\0\30\0&\0e"\4\0\x642e\x636fCR\xffe8\xffff\x6b76\0 \0\x9520\0\1\0\0000\xffd0\xffffWord.Document.8\0.1\0"\r\n\xfff8\xffff\x6fd0\x91\xffa0\xffff\x6b6e \xebd0\xf3cd\x6227\x1c5\0\0\x94b0\0\1\0\0\0\x9648\0\xffff\xffff\0\0\xffff\xffff\x210\0\xffff\xffff\26\0\0\0\0\0\0\0\x45d2\xfb92\f\0\x704f\x6e65\x6957\x6874\x694c\x7473\x39b0\x9a28\xfff8\xffff\x9888\0\xfff8\xffff\x97a8\0\xffa0\xffff\x6b6e \xebd0\xf3cd\x6227\x1c5\0\0\x9558\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x9640\0\x210\0\xffff\xffff\0\0\0\0\0\0\2\0\xe4a6\xa4ce\v\0\x6f57\x6472\x6150\x2e64\x7865\x1c65\x241f\x946e\xffe8\xffff\x6b76\0\2\x8000\0\0\1\0\0 \xfff8\xffff\x9628\0\xfff0\xffff\x686c\1\x95c8\0\xe389\x9e72\xff98\xffff\x6b6e \x6120\xfea3\x6227\x1c5\0\0\x94b0\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x9730\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\0\0\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656cr\0\0\0\xffe8\xffff\x6b76\0N\0\x96d8\0\1\0\0\0\xffa8\xffff{98de59a0-d175-11cd-a7bd-00006b827d94}\0\0\0\0\xfff8\xffff\x96c0\0\xfff0\xffff\x686c\1\x9830\0\xcfbe\xb66d\xfff8\xffff\x9ab0\0\xffa8\xffff\x6b6e \x9e20\xf3d8\x6227\x1c5\0\0\x94b0\0\0\0\0\0\xffff\xffff\xffff\xffff\0\0\xffff\xffff\x210\0\xffff\xffff\0\0\0\0\0\0\0\0\nH\b\0\x6853\x6c65\x4e6c\x7765\xffe0\xffff\x6b76\b\32\0\x99c0\0\1\0\1\0\x6946\x656c\x614e\x656d\xfff8\xffff\x9b38\0\xffa0\xffff\x6b6e \x9e20\xf3d8\x6227\x1c5\0\0\x94b0\0\1\0\0\0\x9738\0\xffff\xffff\0\0\xffff\xffff\x210\0\xffff\xffff\20\0\0\0\0\0\0\0\x1750 \17\0\x6f57\x6472\x442e\x636f\x6d75\x6e65\x2e746\xffa8\xffff\x6b6e \x9e20\xf3d8\x6227\x1c5\0\0\x97d0\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x95b8\0\x210\0\xffff\xffff\0\0\0\0\20\0\30\0\0\0\b\0\x6853\x6c65\x4e6c\x7765\xffe0\xffff\x6b76\b\30\0\x98a8\0\1\0\1 \x6946\x656c\x614e\x656d\xffe0\xffffwinword.doc\0\0\0\xffa0\xffff\x6b6e \x9e20\xf3d8\x6227\x1c5\0\0\x94b0\0\1\0\0\0\x99e0\0\xffff\xffff\0\0\xffff\xffff\x210\0\xffff\xffff\20\0\0\0\0\0\0\0\0\0\f\0\x6f57\x6472\x6f44\x7563\x656d\x746e\0\0\xffc0\xffff\x686c\a\x9558\0\x54c2\x711f\x9658\0\x3a37\xaac9\x9750\0\xcfbe\xb66d\x97d0\0\x3281\xf79a\xbe0\x8c\x3283\xf79a\x98c8\0\x4dff\x74a\x99f0\0\x1391\xba21\xffa8\xffff\x6b6e \x9e20\xf3d8\x6227\x1c5\0\0\x98c8\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x95c0\0\x210\0\xffff\xffff\0\0\0\0\20\0\32\0\0\0\b\0\x6853\x6c65\x4e6c\x7765\xffe0\xffffwinword2.doc\0\0\xfff0\xffff\x686c\1\x9968\0\xcfbe\xb66d\xff98\xffff\x6b6e \x9e20\xf3d8\x6227\x1c5\0\0\x94b0\0\1\0\0\0\x9ad0\0\xffff\xffff\0\0\xffff\xffff\x210\0\xffff\xffff\20\0\0\0\0\0\0\0\0\0\22\0\x6f57\x6472\x6150\x2e64\x6f44\x7563\x656d\x746e\x312e\0\0\0\xffa8\xffff\x6b6e \x9e20\xf3d8\x6227\x1c5\0\0\x99f0\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x9748\0\x210\0\xffff\xffff\0\0\0\0\20\0\2\0\0\0\b\0\x6853\x6c65\x4e6c\x7765\xffe0\xffff\x6b76\b\2\x8000\0\0\1\0\1\xb66d\x754e\x6c6c\x6946\x656c\xfff0\xffff\x686c\1\x9a58\0\xcfbe\xb66d\xffa8\xffff\x6b6e \x4920\x3aff\x6228\x1c5\0\0\x2218\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x97c8\0\x210\0\xffff\xffff\0\0\0\0\f\0\2\0\xb398\0\4\0\x642e\x736f\xb3a4\0\xffe0\xffff\x6b76\6\2\x8000\0\0\1\0\1\0\x6f4e\x704f\x6e65\0\xffa8\xffff\x6b6e \x5650\xd1e1\x6235\x1c5\0\0\x2218\0\2\0\0\0\x1c00\x8c\xffff\xffff\2\0\x9c90\0\x210\0\xffff\xffff"\0\0\0\30\0&\0\0\0\4\0\x642e\x746f\0\0\xff98\xffff\x6b6e \x6120\xfea3\x6227\x1c5\0\0\x9b58\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x9c88\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\0\0\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656cr\0\0\0\xffe8\xffff\x6b76\0N\0\x9c30\0\1\0\0\0\xffa8\xffff{98de59a0-d175-11cd-a7bd-00006b827d94}\0\0\0\0\xfff8\xffff\x9c18\0\xfff0\xffff\x1c80\x8c\x1ce0\x8c\x3a37\xaac9\xffa8\xffff\x6b6e \x83b0\xfe8f\x6227\x1c5\0\0\x2218\0\1\0\0\0\x9e50\0\xffff\xffff\2\0\x9d68\0\x210\0\xffff\xffff"\0\0\0\16\0\20\0il\4\0\x642e\x7672HK\xffe8\xffff\x6b76\0\20\0\x9d10\0\1\0\0n\xffe8\xffffdrvfile\0st\xfff8\xffff\x9de0\0\xffe0\xffff\x6b76\a\16\0\x9d50\0\1\0\1"\x6547\x656e\x6972c\xffe8\xffffsystem\0002,"\xfff0\xffff\x9cf8\0\x9d30\0st\xff98\xffff\x6b6e \x83b0\xfe8f\x6227\x1c5\0\0\x9ca0\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x9d28\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\0\0\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656cr\0\0\0\xffe8\xffff\x6b76\0N\0\x9df8\0\1\0\0\xb66d\xffa8\xffff{098f2470-bae0-11cd-b579-08002b30bfeb}\0\0\0\0\xfff0\xffff\x686c\1\x9d78\0\x3a37\xaac9\xffa0\xffff\x6b6e \x2f27\x5b28\xdf52\x1c7\0\0\x2218\0\1\0\0\0\x9ee0\0\xffff\xffff\1\0\x9ed8\0\xc670\x180\xffff\xffff\n\0\0\0\0\0V\0ap\t\0\x534d\x4144\x5153\x2e4c1\0\x6b76\0\xffe8\xffff\x6b76\0V\0\xa518\36\1\0\0S\xfff8\xffff\x9ec0\0\xfff0\xffff\x686c\1\xa0e8\36\x8b5b\x7b8\xffa8\xffff\x6b6e \xf080\xc804\x61fc\x1c5\0\0\x2218\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x9f78\0\x210\0\xffff\xffff\0\0\0\0\0\0\20\0\0\0\4\0\x642e\x6e75\0\0\xffe8\xffff\x6b76\0\20\0\x9f60\0\1\0\0\0\xffe8\xffffdunfile\0\0\0\xfff8\xffff\x9f48\0\xffc8\xffffWed Nov 17 11:41:24 2004\0007\xffd8\xffff\x6b76\r\f\0\x9fe0\0\1\0\1\0\x7542\x6c69\x4364\x6568\x6b63\x7553\x6c6d\x656c\xfff0\xffff5b5f2\0\xfff0\xffff\x4170\37\x3ee8\37\x1505\x3985\x6268\x6e69\xa000\0\x1000\0\0\0\0\0\0\0\0\0\0\0\xffe8\xffff\x5418\0\x5460\0\x54b0\0\x9fb8\0\xa038\0\xffe0\xffff\x6b76\b(\0\xa058\0\1\0\1\5\x6f4c\x6163\x6974\x6e6f\xffd0\xffffC:\WINDOWS\System32\0\x6464\x656c\xffd8\xffff\x6b76\r \0\xa0b0\0\1\0\1\0\x6150\x6572\x746e\x654b\x4e79\x6d61e0\xffd8\xffffOperatingSystem\0\xffff\xffff\xffd8\xffff\x6b76\r\4\x8000\1\0\4\0\1\x1d2\x694d\x7267\x7461\x6465\x6f43\x6e75\x6374\x1d2\xfff8\xffff\x7318\r\xfff0\xffff\xfa8\x111\x1148\x111\x81da\x642e\xffa8\xffff\x6b6e \x9580\x4213\x6228\x1c5\0\0\x2218\0\2\0\0\0\xa360\0\xffff\xffff\2\0\xa1e0\0\x210\0\xffff\xffff"\0\0\0\32\0\20\0\0\0\4\0\x652e\x666d\0\0\xffd8\xffff\x6b76\r\f\0\xa198\0\1\0\1\x7365\x6550\x6372\x6965\x6576\x5464\x7079\x4e65\x454e\xfff0\xffffimage\0\xfff8\xffff\xa250\0\xffe8\xffff\x6b76\0\20\0\xa1c8\0\1\0\0\0\xffe8\xffffemffile\0\x1fd\x409\xfff0\xffff\xa170\0\xa1b0\0st\xffa0\xffff\x6b6e \x9580\x4213\x6228\x1c5\0\0\xa118\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xa1a8\0\x210\0\xffff\xffff\0\0\0\0\16\0\0\0\x48107\17\0\x704f\x6e65\x6957\x6874\x7250\x676f\x6469\x773\xffe0\xffff\x6b76\a\0\x8000\0\0\0\0\1\x864\x6d65\x6666\x6c69\x6165\xfff8\xffff\xafc8\x172\xfff8\xffff\xa5b0\0\xff98\xffff\x6b6e \x83b0\xfe8f\x6227\x1c5\0\0\xa118\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xa358\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\0\0\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656cr\0\0\0\xffe8\xffff\x6b76\0N\0\xa300\0\1\0\0\0\xffa8\xffff{098f2470-bae0-11cd-b579-08002b30bfeb}\0\0\0\0\xfff8\xffff\xa2e8\0\xffe8\xffff\x686c\2\xa1f0\0\xaa6\x4cb5\xa280\0\x3a37\xaac9\xffa8\xffff\x6b6e \x5a40\x8492\x6228\x1c5\0\0\x2218\0\0\0\0\0\xffff\xffff\xffff\xffff\2\0\xa480\0\x210\0\xffff\xffff\0\0\0\0\30\0@\0\0\0\4\0\x652e\x6c6d\0\0\xffe8\xffff\x6b76\0@\0\xa3e8\0\1\0\0\0\xffb8\xffffMicrosoft Internet Mail Message\0\0\0\xffd8\xffff\x6b76\f\36\0\xa458\0\1\0\1\x6a7a\x6f43\x746e\x6e65\x2074\x7954\x6570\x4cb5\x7c8c\xffd8\xffffmessage/rfc822\0\0\0\0\xfff0\xffff\xa3d0\0\xa430\0\x1408\a\xffa8\xffff\x6b6e \x16f0\x254c\xce0e\x1c7\0\0\x2218\0\1\0\0\0\xa620\0\xffff\xffff\3\0\x6a70\x100\x210\0\xffff\xffff"\0\0\0\32\0004\0\0\0\4\0\x652e\x7370\0\0\xffd8\xffff\x6b76\f.\0\xa510\0\1\0\1\0\x6f43\x746e\x6e65\x2074\x7954\x6570\0\0\xffc8\xffffapplication/postscript\0\0\0\0\xff98\xffff\x6b6e \x83b0\xfe8f\x6227\x1c5\0\0\xa490\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xa278\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\0\0\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656cr\0\0\0\xffe8\xffff\x6b76\0N\0\xa5c8\0\1\0\0\0\xffa8\xffff{098f2470-bae0-11cd-b579-08002b30bfeb}\0\0\0\0\xfff0\xffff\x686c\1\xa548\0\x3a37\xaac9\xffa8\xffff\x6b6e \x5230\x2b97\x6228\x1c5\0\0\x2218\0\1\0\0\0\xa808\0\xffff\xffff\2\0\xa720\0\x210\0\xffff\xffff"\0\0\0\30\0002\0"t\4\0\x652e\x6578le\xffe8\xffff\x6b76\0\20\0\xa6a0\0\1\0\0x\xffe8\xffffexefile\00000\xfff8\xffff\xa798\0\xffd8\xffff\x6b76\f2\0\xa6e8\0\1\0\1\0\x6f43\x746e\x6e65\x2074\x7954\x6570\0\0\xffc8\xffffapplication/x-msdownload\0\0\xfff0\xffff\xa688\0\xa6c0\0\x324c\x6ae6\xff98\xffff\x6b6e \x83b0\xfe8f\x6227\x1c5\0\0\xa630\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xa6b8\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\0\0\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656cr\0\0\0\xffe8\xffff\x6b76\0N\0\xa7b0\0\1\0\0\0\xffa8\xffff{098f2470-bae0-11cd-b579-08002b30bfeb}\0\0\0\0\xfff0\xffff\x686c\1\xa730\0\x3a37\xaac9\xffa8\xffff\x6b6e \x83b0\xfe8f\x6227\x1c5\0\0\x2218\0\1\0\0\0\xa950\0\xffff\xffff\0\0\xffff\xffff\x210\0\xffff\xffff"\0\0\0\0\0\0\0\0\0\4\0\x652e\x7078\0\0\xff98\xffff\x6b6e \x83b0\xfe8f\x6227\x1c5\0\0\xa818\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xa948\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\0\0\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656cr\0\0\0\xffe8\xffff\x6b76\0N\0\xa8f0\0\1\0\0\0\xffa8\xffff{098f2470-bae0-11cd-b579-08002b30bfeb}\0\0\0\0\xfff8\xffff\xa8d8\0\xfff0\xffff\x686c\1\xa870\0\x3a37\xaac9\xffa8\xffff\x6b6e \x83b0\xfe8f\x6227\x1c5\0\0\x2218\0\1\0\0\0\xaa98\0\xffff\xffff\0\0\xffff\xffff\x210\0\xffff\xffff"\0\0\0\0\0\0\0\0\0\4\0\x652e\x5f78\0\0\xff98\xffff\x6b6e \x83b0\xfe8f\x6227\x1c5\0\0\xa960\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xaa90\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\0\0\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656cr\0\0\0\xffe8\xffff\x6b76\0N\0\xaa38\0\1\0\0\0\xffa8\xffff{098f2470-bae0-11cd-b579-08002b30bfeb}\0\0\0\0\xfff8\xffff\xaa20\0\xfff0\xffff\x686c\1\xa9b8\0\x3a37\xaac9\xffa8\xffff\x6b6e \x83b0\xfe8f\x6227\x1c5\0\0\x2218\0\1\0\0\0\xabe0\0\xffff\xffff\0\0\xffff\xffff\x210\0\xffff\xffff"\0\0\0\0\0\0\0\0\0\4\0\x652e\x6279\0\0\xff98\xffff\x6b6e \x83b0\xfe8f\x6227\x1c5\0\0\xaaa8\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xabd8\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\0\0\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656cr\0\0\0\xffe8\xffff\x6b76\0N\0\xab80\0\1\0\0\0\xffa8\xffff{098f2470-bae0-11cd-b579-08002b30bfeb}\0\0\0\0\xfff8\xffff\xab68\0\xfff0\xffff\x686c\1\xab00\0\x3a37\xaac9\xffa8\xffff\x6b6e \x5230\x2b97\x6228\x1c5\0\0\x2218\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xaca0\0\x210\0\xffff\xffff\0\0\0\0\30\0*\0\0\0\4\0\x662e\x6669\0\0\xffd8\xffff\x6b76\f*\0\xac70\0\1\0\1\0\x6f43\x746e\x6e65\x2074\x7954\x6570\0\0\xffd0\xffffapplication/fractals\0\0\xfff8\xffff\xac48\0\xffa8\xffff\x6b6e \x83b0\xfe8f\x6227\x1c5\0\0\x2218\0\1\0\0\0\xae18\0\xffff\xffff\1\0\xad30\0\x210\0\xffff\xffff"\0\0\0\0\0\20\0,"\4\0\x662e\x646eFi\xffe8\xffff\x6b76\0\20\0\xad18\0\1\0\0000\xffe8\xfffffndfile\0R,\xfff8\xffff\xad00\0\xff98\xffff\x6b6e \x83b0\xfe8f\x6227\x1c5\0\0\xaca8\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xae10\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\0\0\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656cr\0\0\0\xffe8\xffff\x6b76\0N\0\xadb8\0\1\0\0\0\xffa8\xffff{098f2470-bae0-11cd-b579-08002b30bfeb}\0\0\0\0\xfff8\xffff\xada0\0\xfff0\xffff\x686c\1\xad38\0\x3a37\xaac9\xffa8\xffff\x6b6e \x83b0\xfe8f\x6227\x1c5\0\0\x2218\0\1\0\0\0\xaf60\0\xffff\xffff\0\0\xffff\xffff\x210\0\xffff\xffff"\0\0\0\0\0\0\0\0\0\4\0\x662e\x746e\0\0\xff98\xffff\x6b6e \x83b0\xfe8f\x6227\x1c5\0\0\xae28\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xaf58\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\0\0\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656cr\0\0\0\xffe8\xffff\x6b76\0N\0\xaf00\0\1\0\0\0\xffa8\xffff{098f2470-bae0-11cd-b579-08002b30bfeb}\0\0\0\0\xfff8\xffff\xaee8\0\xfff0\xffff\x686c\1\xae80\0\x3a37\xaac9\xffd0\xffff\x6b76\21<\0\xafa0\0\1\0\1\0\x6150\x6572\x746e\x6944\x7073\x616c\x4e79\x6d61e\x8000\0\0\xffc0\xffffWindows XP - Software Updates\0\xffe8\xffffrdbss.sys\0\xfff8\xffff\xeca8\xb5\x6268\x6e69\xb000\0\x1000\0\0\0\0\0\0\0\0\0\0\0\xffe0\xffff\x6b76\b\4\x8000\1\0\4\0\1\0\x6f4e\x6552\x6f6d\x6576\xffe0\xffff\x6b76\b\24\0\xafe0\0\1\0\0012\x6946\x656c\x614e\x656d\xfff8\xffff\x5eb8\xb9\xffc8\xffff\xe230\x1cf\x60b8\x1d2\x9630\x1cf\x60e0\x1d2\x6200\x1d2\x6258\x1d2\x6298\x1d2\x6310\x1d2\x63a0\x1d2\xa088\0\xaf70\0\xb020\0\xa0d8\0\xffa8\xffff\x6b6e \x56cf\x422e\xaa3\x1c8\0\0\xe078\x1d4\0\0\0\0\xffff\xffff\xffff\xffff\5\0\xef78\2\x2e8\xc5\xffff\xffff\0\0\0\0\32\08\0\1\0\2\0\x3232\x6373\x6972\x7470\xfff8\xffff\xd8c0\6\xfff0\xffff\x1708\x111\x1868\x111\x3a37\xaac9\xffa8\xffff\x6b6e \x83b0\xfe8f\x6227\x1c5\0\0\x2218\0\1\0\0\0\xb280\0\xffff\xffff\1\0\xb198\0\x210\0\xffff\xffff"\0\0\0\0\0\20\0wa\4\0\x662e\x6e6fen\xffe8\xffff\x6b76\0\20\0\xb180\0\1\0\0$\xffe8\xfffffonfile\0\xf861$\xfff8\xffff\xb168\0\xff98\xffff\x6b6e \x83b0\xfe8f\x6227\x1c5\0\0\xb110\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xb278\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\0\0\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656cr\0\0\0\xffe8\xffff\x6b76\0N\0\xb220\0\1\0\0\0\xffa8\xffff{098f2470-bae0-11cd-b579-08002b30bfeb}\0\0\0\0\xfff8\xffff\xb208\0\xfff0\xffff\x686c\1\xb1a0\0\x3a37\xaac9\xffa8\xffff\x6b6e \x83b0\xfe8f\x6227\x1c5\0\0\x2218\0\1\0\0\0\xb3c8\0\xffff\xffff\0\0\xffff\xffff\x210\0\xffff\xffff"\0\0\0\0\0\0\0\0\0\4\0\x672e\x6968\0\0\xff98\xffff\x6b6e \x83b0\xfe8f\x6227\x1c5\0\0\xb290\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xb3c0\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\0\0\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656cr\0\0\0\xffe8\xffff\x6b76\0N\0\xb368\0\1\0\0\0\xffa8\xffff{098f2470-bae0-11cd-b579-08002b30bfeb}\0\0\0\0\xfff8\xffff\xb350\0\xfff0\xffff\x686c\1\xb2e8\0\x3a37\xaac9\xffa8\xffff\x6b6e \xdd80\xd1e2\x6235\x1c5\0\0\x2218\0\3\0\0\0\x2a30\x8c\xffff\xffff\3\0\xb4a0\0\x210\0\xffff\xffff"\0\0\0\32\0\24\0\0\0\4\0\x672e\x6669\0\0\xffd8\xffff\x6b76\r\f\0\xb458\0\1\0\1\x3020\x6550\x6372\x6965\x6576\x5464\x7079\x4b65\x2c52\xfff0\xffffimage\0\xfff8\xffff\xb550\0\xffe8\xffff\x6b76\0\20\0\xb488\0\1\0\0e\xffe8\xffffgiffile\0dg\xfff0\xffff\xb430\0\xb470\0\xb4b0\0\xffd8\xffff\x6b76\f\24\0\xb4d8\0\1\0\1i\x6f43\x746e\x6e65\x2074\x7954\x6570Co\xffe8\xffffimage/gif\0\xffa0\xffff\x6b6e \x9580\x4213\x6228\x1c5\0\0\xb3d8\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xb468\0\x210\0\xffff\xffff\0\0\0\0\16\0\0\0\x35ac\0\17\0\x704f\x6e65\x6957\x6874\x7250\x676f\x6469s\xffe0\xffff\x6b76\a\0\x8000\0\0\0\0\1\xffff\x6967\x6666\x6c69\xff65\xfff8\xffff\xb6d0\0\xfff8\xffff\xb880\0\xff98\xffff\x6b6e \x83b0\xfe8f\x6227\x1c5\0\0\xb3d8\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xb658\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\0\0\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656cr\0\0\0\xffe8\xffff\x6b76\0N\0\xb600\0\1\0\0\0\xffa8\xffff{098f2470-bae0-11cd-b579-08002b30bfeb}\0\0\0\0\xfff8\xffff\xb5e8\0\xffe8\xffff\x6b76\0 \0\x2bf0\x8c\1\0\0\xaac9\xffa8\xffff\x6b6e \xf080\xc804\x61fc\x1c5\0\0\x2218\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xb570\0\x210\0\xffff\xffff\0\0\0\0\0\0\36\0\xd974\x6f2e\4\0\x672e\x7072\x3b78\xf4e1\xffe8\xffff\x6b76\0\36\0\xb6e8\0\1\0\0\n\xffd8\xffffMSProgramGroup\0\x3955\xba78\x792c\xffa8\xffff\x6b6e \x1830\x3b10\x6228\x1c5\0\0\x2218\0\1\0\0\0\xb8f0\0\xffff\xffff\2\0\xb808\0\x210\0\xffff\xffff"\0\0\0\32\0&\0\0\0\3\0\x672ez\0\0\xffd8\xffff\x6b76\f&\0\xb790\0\1\0\1\0\x6f43\x746e\x6e65\x2074\x7954\x6570\0\0\xffd0\xffffapplication/x-gzip\0\0\0\0\xffd8\xffff\x6b76\r\26\0\xb7e8\0\1\0\1\x202c\x6550\x6372\x6965\x6576\x5464\x7079\x3065\x2c30\xffe0\xffffcompressed\0\x3c22\x7263\x3c3e\xfff0\xffff\xb768\0\xb7c0\00000\xff98\xffff\x6b6e \x83b0\xfe8f\x6227\x1c5\0\0\xb710\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xb578\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\0\0\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656cr\0\0\0\xffe8\xffff\x6b76\0N\0\xb898\0\1\0\0\0\xffa8\xffff{098f2470-bae0-11cd-b579-08002b30bfeb}\0\0\0\0\xfff0\xffff\x686c\1\xb818\0\x3a37\xaac9\xff98\xffff\x6b6e \x8b98\x1ae8\xd3a3\x1c7\0\0\xbd98\0\0\0\0\0\xffff\xffff\xffff\xffff\4\0\xb978\0\x72a8\xa6\xffff\xffff\0\0\0\0\26\0\b\0\0\0\24\0\x6553\x7574\x5770\x7a69\x7261\x2d64\x3031\x3333\x452d\x544e\xb980\0\xfff0\xffff\xea50\x4e4c\22\0\x6965\x6576\xffe8\xffff\xd5f0\0\xba40\0\xba68\0\xd5d0\0\0\x6c3c\xffd8\xffff\x6b76\v`\0\xb9b8\0\1\0\1\x1c5\x7356\x6f43\x6d6d\x6e6f\x6944r\0\0\xff98\xffffC:\Program Files\Microsoft Visual Studio\Common\0{5\xffe0\xffff\x6b76\4\4\x8000\x5356\x3839\4\0\0016\x7361\x6f701c\xffd8\xffff\x6b76\v\4\x8000\a\0\4\0\0012\x6957\x617a\x6472\x7453\x7461\x5765\x7a69\x7261\xffe0\xffff\x6b76\b\4\x8000\2\0\4\0\1\x4078\x5053\x5320\x6174\x6574\xffa8\xffff\x6b6e \x906f\xa10e\xce00\x1c7\0\0\x2218\0\1\0\0\0\xbbc0\0\xffff\xffff\1\0\xd30\x148\x210\0\xffff\xffff"\0\0\0\0\0\20\0\0\0\4\0\x682e\x6368\0\0\xff98\xffff\x6b6e \x52c0\xfea0\x6227\x1c5\0\0\xba88\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xbbb8\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\0\0\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656cr\0\0\0\xffe8\xffff\x6b76\0N\0\xbb60\0\1\0\0\0\xffa8\xffff{eec97550-47a9-11cf-b952-00aa0051fe20}\0\0\0\0\xfff8\xffff\xbb48\0\xfff0\xffff\x686c\1\xbae0\0\x3a37\xaac9\xffa8\xffff\x6b6e \x1a0\xc83f\x61fc\x1c5\0\0\x2218\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xbd90\0\xbc28\0\xffff\xffff\0\0\0\0\0\0\20\0\x6920\3\4\0\x682e\x706c\xf96%\xfec8\xffff\x6b73\x5420\xe7f0\x106\x6788\x16d$\0\x11c\0\1\x9404\x100\0\x110\0\0\0\24\0\2\xec\n\0\0\30\31\2\x201\0\0\x500 \0\x221\0\xa00\30\0\x8000\x201\0\0\x500 \0\x221\0\0\30\31\2\x201\0\0\x500 \0\x223\0\xa00\30\0\x8000\x201\0\0\x500 \0\x223\0\0\30?\17\x201\0\0\x500 \0\x220\0\xa00\30\0\x1000\x201\0\0\x500 \0\x220\0\0\24?\17\x101\0\0\x500\22\0\xa00\24\0\x1000\x101\0\0\x500\22\0\0\30?\17\x201\0\0\x500 \0\x220\0\xa00\24\0\x1000\x101\0\0\x300\0\0\x201\0\0\x500 \0\x220\0\x101\0\0\x500\22\00000\xffe8\xffff\x6b76\0\20\0\xbd78\0\1\0\0R\xffe8\xffffhlpfile\0,0\xfff8\xffff\xbd60\0\xffa0\xffff\x6b6e \xa078\x9fb6\xd39f\x1c7\0\0\xa1e0\x121\2\0\0\0\x8758\0\xffff\xffff\0\0\xffff\xffff\x72a8\xa6\xffff\xffff(\0\0\0\0\0\0\0\0\0\20\0\x6956\x7573\x6c61\x5320\x7574\x6964\x206f\x3839\xffd8\xffff\x6b76\r\4\x8000\1\0\4\0\1\x6576\x6544\x4370\x6568\x6b63\x6f4c\x4f67\x7a6e\x7261\xfff8\xffff\xbdf8\0\xfff0\xffffMDM\0\xe4f1\x4078\xfff8\xffff\xd860\0\xffe8\xffff\x6b76\0\16\0\xbe58\0\1\0\0\x40b3\xffe8\xffffhtfile\0\x71a0\x82be\x4c13\xfff8\xffff\xbe40\0\xffa8\xffff\x6b6e \xd6e8\x8141\xb3b\x1c8\0\0\x2218\0\3\0\0\0\xa508\xf9\xffff\xffff\2\0\xbf58\0\x210\0\xffff\xffff"\0\0\0\30\0 \0\0\0\4\0\x682e\x6174\0\0\xffe8\xffff\x6b76\0\20\0\xbee8\0\1\0\0%\xffe8\xffffhtafile\0\x3788%\xfff8\xffff\xbfc0\0\xffd8\xffff\x6b76\f \0\xbf30\0\1\0\1\0\x6f43\x746e\x6e65\x2074\x7954\x6570\x7369\x6574\xffd8\xffffapplication/hta\0\x6b76\0\xfff0\xffff\xbed0\0\xbf08\0\xffff\xffff\xffa8\xffff\x6b6e \xe7d0\x3f0f\x6228\x1c5\0\0\x2218\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xbf00\0\x210\0\xffff\xffff\0\0\0\0\30\0"\0hr\4\0\x682e\x6374ng\xffd8\xffff\x6b76\f"\0\xc480\0\1\0\1a\x6f43\x746e\x6e65\x2074\x7954\x6570"\r\xfff0\xfffftext\0\x2220\xfff8\xffff\xc6f0\0\x6268\x6e69\xc000\0\x1000\0\0\0\0\0\0\0\0\0\0\0\xffa0\xffff\x6b6e \x6160\x3f99\xc8d5\x1c7\0\0\x420\1\2\0\0\0\x5988\x121\xffff\xffff\0\0\xffff\xffff\x210\0\xffff\xffff\34\0\0\0\0\0\0\0\xc008\xe1f2\f\0\x704f\x6e65\x6957\x6874\x694c\x7473\1\0\xffa0\xffff\x6b6e \x920\x8a75\x6228\x1c5\0\0\xc020\0\0\0\0\0\xffff\xffff\xffff\xffff\0\0\xffff\xffff\x210\0\xffff\xffff\0\0\0\0\0\0\0\0\x8d40\x8054\f\0\x6d77\x6c70\x7961\x7265\x652e\x6578\0\0\xfff0\xffffLocal\0\xff98\xffff\x6b6e \xae0\xfe91\x6227\x1c5\0\0\x420\1\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xc1c8\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\0\0\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656cr\0\0\0\xffe8\xffff\x6b76\0N\0\xc170\0\1\0\0\0\xffa8\xffff{098f2470-bae0-11cd-b579-08002b30bfeb}\0\0\0\0\xfff8\xffff\xc158\0\xffe8\xffff\xa0f8X\x9f50X\xa148X\xa750X\xd708\x16f\xffa8\xffff\x6b6e \x13e0\xf4b7\xce0d\x1c7\0\0\x2218\0\3\0\0\0\xa7a0X\xffff\xffff\3\0\xc2d0\0\x210\0\xffff\xffff"\0\0\0\32\0 \0\0\0\4\0\x6d2e\x7533\0\0\xffd8\xffff\x6b76\r\f\0\xc268\0\1\0\1\x2c30\x6550\x6372\x6965\x6576\x5464\x7079\x6565\x7073\xfff0\xffffaudio\0\xfff8\xffff\xc458\0\xffd8\xffff\x6b76\f \0\xc2a8\0\1\0\1\x6f43\x746e\x6e65\x2074\x7954\x6570\xba98\xffd8\xffffaudio/x-mpegurl\0\0\0\xfff0\xffff\xc240\0\xc280\0\xc2e0\0\xffe8\xffff\x6b76\0\20\0\xc2f8\0\1\0\0\xffe8\xffffm3ufile\0\0\0\xffa0\xffff\x6b6e \x1780\x8a78\x6228\x1c5\0\0\xc1e8\0\1\0\0\0\xc3e0\0\xffff\xffff\0\0\xffff\xffff\x210\0\xffff\xffff\30\0\0\0\0\0\0\0\0\0\f\0\x704f\x6e65\x6957\x6874\x694c\x7473\x8d40\x8054\xfff0\xffff\x1138\1\x1168\1\x54c2\x711f\xffa0\xffff\x6b6e \x1780\x8a78\x6228\x1c5\0\0\xc310\0\0\0\0\0\xffff\xffff\xffff\xffff\0\0\xffff\xffff\x210\0\xffff\xffff\0\0\0\0\0\0\0\0\0\0\f\0\x6d77\x6c70\x7961\x7265\x652e\x6578\0\0\xfff0\xffff\x686c\1\xc380\0\x4cb5\x7c8c\xff98\xffff\x6b6e \xae0\xfe91\x6227\x1c5\0\0\xc1e8\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xc278\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\0\0\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656cr\0\0\0\xffe8\xffff\x6b76\0N\0\xbd0\1\1\0\0\0\xfff0\xffff\x1210\1\x1240\1\x30c4%\xffd8\xfffftext/x-component\0I\xffa8\xffff\x6b6e \x6aaf\x2e09\x513c\x1c8\0\0\x2218\0\3\0\0\0\xabe0\xf9\xffff\xffff\3\0\xc558\0\x210\0\xffff\xffff"\0\0\0\32\0\30\0\0\0\4\0\x682e\x6d74\0\0\xffd8\xffff\x6b76\r\n\0\xbfe8\0\1\0\1\x3030\x6550\x6372\x6965\x6576\x5464\x7079\xd65\x480a\xffe8\xffff\x6b76\0\30\0\xd270\x180\1\0\0\0\xffe8\xffff\x6b76\0N\0\x2790\xc5\1\0\0\0\xfff0\xffff\xc500\0\xc528\0\xc568\0\xffd8\xffff\x6b76\f\24\0\xc590\0\1\0\1\0\x6f43\x746e\x6e65\x2074\x7954\x6570\0\0\xffe8\xfffftext/html\0\xffa0\xffff\x6b6e \xcd40\x2c1\x5a53\x1c8\0\0\xc4a8\0\a\0\0\0\xd548\x215\xffff\xffff\0\0\xffff\xffff\x210\0\xffff\xffff\36\0\0\0\0\0\0\0\x6e6f\x6573\f\0\x704f\x6e65\x6957\x6874\x694c\x7473\x2f30\x4552\xfff0\xfffftext\0\x3030\xffa0\xffff\x6b6e \x9320\x3c55\x6228\x1c5\0\0\xc5a8\0\0\0\0\0\xffff\xffff\xffff\xffff\0\0\xffff\xffff\x210\0\xffff\xffff\0\0\0\0\0\0\0\0\x3034\x2f30\v\0\x6f6e\x6574\x6170\x2e64\x7865\x3065\x2c32\x3020\xfff0\xffff\x7fd0\x170\x1af0r\xd670q\xff98\xffff\x6b6e \x52c0\xfea0\x6227\x1c5\0\0\xc4a8\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xbff8\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\0\0\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656cr\0\0\0\xffe8\xffff\x6b76\0N\0\xc708\0\1\0\0\0\xffa8\xffff{eec97550-47a9-11cf-b952-00aa0051fe20}\0\0\0\0\xffe8\xffff\x6b76\0\x92\0\xacb0\xf9\1\0\0\xaac9\xffa8\xffff\x6b6e \x6aaf\x2e09\x513c\x1c8\0\0\x2218\0\3\0\0\0\xd380\xf9\xffff\xffff\3\0\xc830\0\x210\0\xffff\xffff"\0\0\0\32\0\30\0\0\0\5\0\x682e\x6d74l\0\xffd8\xffff\x6b76\r\n\0\xc608\0\1\0\1\x92c\x6550\x6372\x6965\x6576\x5464\x7079\x2c65\x3435\xfff8\xffff\xc8e8\0\xffe8\xffff\x6b76\0\30\0\xd478\x215\1\0\0\0\xfff8\xffff\xc540\0\xfff0\xffff\x686c\1\xb118\xd9\x843\xdac7\xfff0\xffff\xc7d0\0\xc800\0\xc840\0\xffd8\xffff\x6b76\f\24\0\xc868\0\1\0\1\0\x6f43\x746e\x6e65\x2074\x7954\x6570\0\0\xffe8\xfffftext/html\0\xff98\xffff\x6b6e \x52c0\xfea0\x6227\x1c5\0\0\xc778\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xc7f8\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\0\0\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656cr\0\0\0\xffe8\xffff\x6b76\0N\0\xc900\0\1\0\0\0\xffa8\xffff{eec97550-47a9-11cf-b952-00aa0051fe20}\0\0\0\0\xfff0\xffff\x5b20\xfa\x5c80\xfa\x3a37\xaac9\xffa8\xffff\x6b6e \xa530\x3af7\x6228\x1c5\0\0\x2218\0\1\0\0\0\xcb30\0\xffff\xffff\2\0\xca48\0\x210\0\xffff\xffff"\0\0\0\30\0"\0\0\0\4\0\x682e\x7474\0\0\xffe8\xffff\x6b76\0\20\0\xc9d8\0\1\0\0\0\xffe8\xffffHTTfile\0\x1670\0\xfff8\xffff\xcac0\0\xffd8\xffff\x6b76\f"\0\xca20\0\1\0\1\0\x6f43\x746e\x6e65\x2074\x7954\x6570\x1708\0\xffd8\xfffftext/webviewhtml\0\0\xfff0\xffff\xc9c0\0\xc9f8\0\0\0\xff98\xffff\x6b6e \x52c0\xfea0\x6227\x1c5\0\0\xc968\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xc9f0\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\0\0\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656cr\0\0\0\xffe8\xffff\x6b76\0N\0\xcad8\0\1\0\0\0\xffa8\xffff{eec97550-47a9-11cf-b952-00aa0051fe20}\0\0\0\0\xfff0\xffff\x686c\1\xca58\0\x3a37\xaac9\xffa8\xffff\x6b6e \x17d3\xa110\xce00\x1c7\0\0\x2218\0\1\0\0\0\xcc78\0\xffff\xffff\1\0\xde8\x148\x210\0\xffff\xffff"\0\0\0\0\0\22\0\0\0\4\0\x682e\x7774\0\0\xff98\xffff\x6b6e \x52c0\xfea0\x6227\x1c5\0\0\xcb40\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xcc70\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\0\0\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656cr\0\0\0\xffe8\xffff\x6b76\0N\0\xcc18\0\1\0\0\0\xffa8\xffff{eec97550-47a9-11cf-b952-00aa0051fe20}\0\0\0\0\xfff8\xffff\xcc00\0\xfff0\xffff\x686c\1\xcb98\0\x3a37\xaac9\xffa8\xffff\x6b6e \x17d3\xa110\xce00\x1c7\0\0\x2218\0\1\0\0\0\xcdc0\0\xffff\xffff\2\0\xd68\x148\x210\0\xffff\xffff"\0\0\0\30\0\24\0\0\0\4\0\x682e\x7874\0\0\xff98\xffff\x6b6e \x52c0\xfea0\x6227\x1c5\0\0\xcc88\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xcdb8\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\0\0\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656cr\0\0\0\xffe8\xffff\x6b76\0N\0\xcd60\0\1\0\0\0\xffa8\xffff{eec97550-47a9-11cf-b952-00aa0051fe20}\0\0\0\0\xfff8\xffff\xcd48\0\xfff0\xffff\x686c\1\xcce0\0\x3a37\xaac9\xffa8\xffff\x6b6e \x8280\x572\xd3ad\x1c7\0\0\xda28e\1\0\0\0\xcf48\0\xffff\xffff\1\0\xbe20\0\x72a8\xa6\xffff\xffffP\0\0\0\32\0\4\0p\\6\0\x4656\x5750\x5543i\xffe0\xffff\x6b76\a \0\xce48\0\1\0\1S\x734d\x5069\x7461h\xffd8\xffffe:\vs_setup.msi\0E:\xfff8\xffff\x36d0[\xffd0\xffff\x6b76\21\4\x8000\x6dc\x3831\4\0\1\0\x4656\x3750\x505f\x6f72\x6566\x7373\x6f69\x616el\0\x6e69\xff67\xffd8\xffff\x6b76\f\b\0\xbe28\0\1\0\1\0\x6f4c\x6163\x536c\x7265\x6976\x6563\x7465\x7075\xff98\xffff\x6b6e \x9bf0\x8d99\xd3b0\x1c7\0\0\x2218\0\1\0\0\0\xcf38\0\xffff\xffff\1\0\xbe38\0\x210\0\xffff\xffff\n\0\0\0\0\0,\0\0\0\30\0\x614d\x6863\x6e69\x4465\x6265\x6775\x614d\x616e\x6567\x4172\x3144\x372e\xfff0\xffff\x686c\1\xd550\x162\x8b5b\x7b8\xfff0\xffff\x686c\1\x46a0\1\x2c7f\xbf4b\xffa8\xffff\x6b6e \xf080\xc804\x61fc\x1c5\0\0\x2218\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xcfe0\0\x210\0\xffff\xffff\0\0\0\0\0\0\20\0x0\4\0\x692e\x636300\xffe8\xffff\x6b76\0\20\0\xcfc8\0\1\0\0"\xffe8\xfffficmfile\0Fr\xfff8\xffff\xcfb0\0\xffe8\xffff\x6b76\0\20\0\xd078\0\1\0\0x\x6268\x6e69\xd000\0\x1000\0\0\0\0\0\0\0\0\0\0\0\xffa8\xffff\x6b6e \x83b0\xfe8f\x6227\x1c5\0\0\x2218\0\1\0\0\0\xd178\0\xffff\xffff\1\0\xd090\0\x210\0\xffff\xffff"\0\0\0\0\0\20\0%\\4\0\x692e\x6d63em\xffe8\xfffficmfile\0CR\xfff8\xffff\xcfe8\0\xff98\xffff\x6b6e \x83b0\xfe8f\x6227\x1c5\0\0\xd020\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xd170\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\0\0\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656cr\0\0\0\xffe8\xffff\x6b76\0N\0\xd118\0\1\0\0\0\xffa8\xffff{098f2470-bae0-11cd-b579-08002b30bfeb}\0\0\0\0\xfff8\xffff\xd100\0\xfff0\xffff\x686c\1\xd098\0\x3a37\xaac9\xffa8\xffff\x6b6e \xe7d0\x3f0f\x6228\x1c5\0\0\x2218\0\1\0\0\0\xd380\0\xffff\xffff\3\0\xd250\0\x210\0\xffff\xffff"\0\0\0\32\0\32\0ys\4\0\x692e\x6f63oo\xffe8\xffff\x6b76\0\20\0\xd1f8\0\1\0\0\\xffe8\xfffficofile\0,0\xfff8\xffff\xd310\0\xffd8\xffff\x6b76\r\f\0\xd240\0\1\0\1\x3230\x6550\x6372\x6965\x6576\x5464\x7079\x3065\x302c\xfff0\xffffimage\0\xfff0\xffff\xd1e0\0\xd218\0\xd260\0\xffd8\xffff\x6b76\f\32\0\xd288\0\1\0\1r\x6f43\x746e\x6e65\x2074\x7954\x6570Fi\xffe0\xffffimage/x-icon\0F\xff98\xffff\x6b6e \x83b0\xfe8f\x6227\x1c5\0\0\xd188\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xd210\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\0\0\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656cr\0\0\0\xffe8\xffff\x6b76\0N\0\xd328\0\1\0\0\0\xffa8\xffff{098f2470-bae0-11cd-b579-08002b30bfeb}\0\0\0\0\xfff0\xffff\x686c\1\xd2a8\0\x3a37\xaac9\xfe20\xffff[{25537BA6-77A8-11D2-9B6C-0000F8080861}{88E729D6-BDC1-11D1-BD2A-00C04FB9603F}][{35378EAC-683F-11D2-A89A-00C04FBBCFA2}{0F6B957E-509E-11D1-A7CC-0000F87571E3}][{A2E30F80-D7DE-11D2-BBDE-00C04F86AE3B}{FC715823-C5FB-11D1-9EEF-00A0C90347FF}]\0\0\0\0\xffa0\xffff\x6b6e \xf0f0\xd18\xd3a3\x1c7\0\0\xbd98\0\0\0\0\0\xffff\xffff\xffff\xffff\2\0\x6f50\0\x72a8\xa6\xffff\xffff\0\0\0\0\b\0\4\0e9\v\0\x6553\x7574\x5770\x7a69\x7261d96\xffe0\xffff\x6b76\b\4\x8000\2\0\4\0\0010\x4549\x5320\x6174\x6574\xffd8\xffff\x6b76\n\b\0\xb968\0\3\0\1\0\x6568\x7275\x7369\x6974\x7363\0\x686c\0\xfff8\xffff\xb990\0\xffa8\xffff\x6b6e \x1940\xfe94\x6227\x1c5\0\0\x2218\0\1\0\0\0\xd758\0\xffff\xffff\0\0\xffff\xffff\x210\0\xffff\xffff"\0\0\0\0\0\0\0\0\0\4\0\x692e\x7164\0\0\xff98\xffff\x6b6e \x1940\xfe94\x6227\x1c5\0\0\xd620\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xd750\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\0\0\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656cr\0\0\0\xffe8\xffff\x6b76\0N\0\xd6f8\0\1\0\0\0\xffa8\xffff{5e941d80-bf96-11cd-b579-08002b30bfeb}\0\0\0\0\xfff8\xffff\xd6e0\0\xfff0\xffff\x686c\1\xd678\0\x3a37\xaac9\xffa8\xffff\x6b6e \xe280\x2fa4\x6228\x1c5\0\0\x2218\0\0\0\0\0\xffff\xffff\xffff\xffff\2\0\xd850\0\x210\0\xffff\xffff\0\0\0\0\30\0*\0\0\0\4\0\x692e\x6969\0\0\xffe8\xffff\x6b76\0\20\0\xd7d8\0\1\0\0\0\xffe8\xffffiiifile\0\0\0\xfff8\xffff\xd960\0\xffd8\xffff\x6b76\f*\0\xd820\0\1\0\1\0\x6f43\x746e\x6e65\x2074\x7954\x6570\0\0\xffd0\xffffapplication/x-iphone\0\0\xfff0\xffff\xd7c0\0\xd7f8\0\x47d0\a\xffe8\xffff\x6b76\0,\0\xd878\0\1\0\0\0\xffd0\xffffMachine Debug Manager\0\xffe8\xffff\x6b76\0N\0\xd5a8\x162\1\0\0 \xfff8\xffff\xd8a8\0\xffe8\xffff\x6b76\0,\0\xf578\x126\1\0\0u\xfff0\xffff\xa588\x121\xf828\x126\xffff\xffff\xffe0\xffffvoicewarmup\0\x4548\x5346\xffe8\xffff\x6b76\0006\0\x6998\x18a\1\0\0\x14c\xfff8\xffff\xf030\20\xfff8\xffff\xce78\0\xfff8\xffff\xdf98\x12e\xffe0\xffff\x6b76\6h\0\xf5d0\x14b\1\0\1\0\x6f43\x6d6d\x6e6fc\xffd8\xffff\x6b76\v\4\x80001\0\1\0\0012\x6142\x6573\x696c\x656e\x4d20\x734d\x5c69}\xffe8\xffff\xc70\x18d\xcf0\x18d\xaf40\x194\xf598\xc8\x3d10\x1c6\xffa8\xffff\x6b6e \x83b0\xfe8f\x6227\x1c5\0\0\x2218\0\1\0\0\0\xdad8\0\xffff\xffff\0\0\xffff\xffff\x210\0\xffff\xffff"\0\0\0\0\0\0\0\0\0\4\0\x692e\x636d\0\0\xff98\xffff\x6b6e \x83b0\xfe8f\x6227\x1c5\0\0\xd9a0\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xdad0\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\0\0\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656cr\0\0\0\xffe8\xffff\x6b76\0N\0\xda78\0\1\0\0\0\xffa8\xffff{098f2470-bae0-11cd-b579-08002b30bfeb}\0\0\0\0\xfff8\xffff\xda60\0\xfff0\xffff\x686c\1\xd9f8\0\x3a37\xaac9\xffa8\xffff\x6b6e \x1830\x3b10\x6228\x1c5\0\0\x2218\0\1\0\0\0\xdc60\0\xffff\xffff\1\0\xdb78\0\x210\0\xffff\xffff"\0\0\0\32\0\n\0\0\0\4\0\x692e\x636e\0\0\xffd8\xffff\x6b76\r\n\0\xdb68\0\1\0\1\x250a\x6550\x6372\x6965\x6576\x5464\x7079\x4d65\xa0d\xfff0\xfffftext\0\x5d73\xfff8\xffff\xdb40\0\xff98\xffff\x6b6e \x1940\xfe94\x6227\x1c5\0\0\xdae8\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xdc58\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\0\0\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656cr\0\0\0\xffe8\xffff\x6b76\0N\0\xdc00\0\1\0\0\0\xffa8\xffff{5e941d80-bf96-11cd-b579-08002b30bfeb}\0\0\0\0\xfff8\xffff\xdbe8\0\xfff0\xffff\x686c\1\xdb80\0\x3a37\xaac9\xffa8\xffff\x6b6e \x1940\xfe94\x6227\x1c5\0\0\x2218\0\1\0\0\0\xdde0\0\xffff\xffff\1\0\xdcf8\0\x210\0\xffff\xffff"\0\0\0\0\0\20\0R,\4\0\x692e\x666efi\xffe8\xffff\x6b76\0\20\0\xdce0\0\1\0\0e\xffe8\xffffinffile\00000\xfff8\xffff\xdcc8\0\xff98\xffff\x6b6e \x1940\xfe94\x6227\x1c5\0\0\xdc70\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xddd8\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\0\0\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656cr\0\0\0\xffe8\xffff\x6b76\0N\0\xdd80\0\1\0\0\0\xffa8\xffff{5e941d80-bf96-11cd-b579-08002b30bfeb}\0\0\0\0\xfff8\xffff\xdd68\0\xfff0\xffff\x686c\1\xdd00\0\x3a37\xaac9\xffa8\xffff\x6b6e \x1940\xfe94\x6227\x1c5\0\0\x2218\0\1\0\0\0\xdf60\0\xffff\xffff\1\0\xde78\0\x210\0\xffff\xffff"\0\0\0\0\0\20\0,0\4\0\x692e\x696e20\xffe8\xffff\x6b76\0\20\0\xde60\0\1\0\0m\xffe8\xffffinifile\0em\xfff8\xffff\xde48\0\xff98\xffff\x6b6e \x1940\xfe94\x6227\x1c5\0\0\xddf0\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xdf58\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\0\0\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656cr\0\0\0\xffe8\xffff\x6b76\0N\0\xdf00\0\1\0\0\0\xffa8\xffff{5e941d80-bf96-11cd-b579-08002b30bfeb}\0\0\0\0\xfff8\xffff\xdee8\0\xfff0\xffff\x686c\1\xde80\0\x3a37\xaac9\xffa8\xffff\x6b6e \xa070\x2f7b\x6228\x1c5\0\0\x2218\0\0\0\0\0\xffff\xffff\xffff\xffff\2\0\xdfe8\0\x210\0\xffff\xffff\0\0\0\0\30\0<\0\x3346\x3439\4\0\x692e\x736e\x3841\x2d30\xffe8\xffff\x6b76\0$\0\xe020\0\1\0\0\x4c4b\xfff8\xffff\xe170\0\xfff0\xffff\xdfc8\0\xe048\0\0\0\xfff8\xffff\xe2b0\0\x6268\x6e69\xe000\0\x1000\0\0\0\0\0\0\0\0\0\0\0\xffd8\xffffx-internet-signup\0\xffd8\xffff\x6b76\f<\0\xe070\0\1\0\1\x5c7d\x6f43\x746e\x6e65\x2074\x7954\x6570\x6e65\x6564\xffc0\xffffapplication/x-internet-signup\0\xffa8\xffff\x6b6e \xae0\xfe91\x6227\x1c5\0\0\x2218\0\1\0\0\0\xe1e0\0\xffff\xffff\0\0\xffff\xffff\x210\0\xffff\xffff"\0\0\0\0\0\0\0\0\0\4\0\x692e\x766e\0\0\xff98\xffff\x6b6e \xae0\xfe91\x6227\x1c5\0\0\xe0b0\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xdfe0\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\0\0\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656cr\0\0\0\xffe8\xffff\x6b76\0N\0\xe188\0\1\0\0\0\xffa8\xffff{098f2470-bae0-11cd-b579-08002b30bfeb}\0\0\0\0\xfff0\xffff\x686c\1\xe108\0\x3a37\xaac9\xffa8\xffff\x6b6e \x1940\xfe94\x6227\x1c5\0\0\x2218\0\1\0\0\0\xe320\0\xffff\xffff\0\0\xffff\xffff\x210\0\xffff\xffff"\0\0\0\0\0\0\0\0\0\4\0\x692e\x786e\0\0\xff98\xffff\x6b6e \x1940\xfe94\x6227\x1c5\0\0\xe1f0\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xdff8\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\0\0\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656cr\0\0\0\xffe8\xffff\x6b76\0N\0\xe2c8\0\1\0\0\0\xffa8\xffff{5e941d80-bf96-11cd-b579-08002b30bfeb}\0\0\0\0\xfff0\xffff\x686c\1\xe248\0\x3a37\xaac9\xffa8\xffff\x6b6e \xae0\xfe91\x6227\x1c5\0\0\x2218\0\1\0\0\0\xe468\0\xffff\xffff\0\0\xffff\xffff\x210\0\xffff\xffff"\0\0\0\0\0\0\0\0\0\4\0\x692e\x5f6e\0\0\xff98\xffff\x6b6e \xae0\xfe91\x6227\x1c5\0\0\xe330\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xe460\0\x210\0\xffff\xffff\0\0\0\0\0\0N\0\0\0\21\0\x6550\x7372\x7369\x6574\x746e\x6148\x646e\x656cr\0\0\0\xffe8\xffff\x6b76\0N\0\xe408\0\1\0\0\0\xffa8\xffff{098f2470-bae0-11cd-b579-08002b30bfeb}\0\0\0\0\xfff8\xffff\xe3f0\0\xfff0\xffff\x686c\1\xe388\0\x3a37\xaac9\xffa8\xffff\x6b6e \xa070\x2f7b\x6228\x1c5\0\0\x2218\0\0\0\0\0\xffff\xffff\xffff\xffff\2\0\xe580\0\x210\0\xffff\xffff\0\0\0\0\30\0<\0\x2229\xa0d\4\0\x692e\x7073\x5754\x5241\xffe8\xffff\x6b76\0$\0\xe4e8\0\1\0\0\x3541\xffd8\xffffx-internet-signup\0\xfff8\xffff\xe5e8\0\xffd8\xffff\x6b76\f<\0\xe540\0\1\0\1\x4568\x6f43\x746e\x6e65\x2074\x7954\x6570\x6f73\x7466\xffc0\xffffapplication/x-internet-signup\0\xfff0\xffff\xe4d0\0\xe518\0\x5500\a\xffa8\xffff\x6b6e \xd570\x40f5\x6228\x1c5\0\0\x2218\0\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xe510\0\x210\0\xffff\xffff\0\0\0\0\0\0\22\0\x4b54\0\4\0\x692e\x7374\x556c\0\xffe8\xffff\x6b76\0\22\0\xe600\0\1\0\0\0\xffe8\xffffITS File\0\0\xff98\xffff\x6b6e \x2983\x6552\xaa1\x1c8\0\0\x1740m\0\0\0\0\xffff\xffff\xffff\xffff\3\0\xe718\0\x210\0\xffff\xffff\0\0\0\0\30\0\b\0\0\0\22\0\x6e49\x7473\x6c61\x656c\x2064\x6556\x7372\x6f69\x736e\0\x3a37\xaac9\xfff8\xffff\x9fe8\2\xffe8\xffff\x686c\1\x76f8l\x446a\xdca1\xe2c0d\xc943\xf756\xfff0\xffff\xb988d\xe738d\xe690d\xffe0\xffff\x6b76\a\b\0\xe6d0\0\3\0\1\0\x6d77\x2e70\x6c64l\xfff0\xffff\0\t\xd15\0\xe788\0\xffd8\xffff\x6b76\n\b\0\xe708\0\3\0\1\0\x6d77\x6c70\x636f\x642e\x6c6c\x7372\x7369\x6574\xfff0\xffff\0\t\xcb2\0\0\0\xfff0\xffff\xe6b0\0\xe6e0\0\xe728\0\xffd8\xffff\x6b76\f\b\0\xe750\0\3\0\0012\x6d77\x6c70\x7961\x7265\x652e\x6578e0\xfff0\xffff\0\t\xcb2\0b5\xffd0\xffff\x6b76\24\2\x8000\0\0\1\0\1b\x534d\x4d57\x4250\x7275\x436e\x4f44\x416e\x7272\x7669\x6c61\xe718\0\xfff0\xffff\x4b8p\x5a28\x16e\x5838\x16e\xffa8\xffff\x6b6e \x872f\x844b\xce00\x1c7\0\0\x2218\0\0\0\0\0\xffff\xffff\xffff\xffff\2\0\xe150\x135\x210\0\xffff\xffff\0\0\0\0\32\0\16\0\xd32\xd0a\5\0\x6a2e\x7661\x4161\x6464\xffd8\xffff\x6b76\r\n\0\xe820\0\1\0\1\x4122\x6550"

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services:
——————



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Messenger\\Msmsgs.exe"="C:\\Program Files\\Messenger\\Msmsgs.exe:*:Disabled:Windows Messenger"
"C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"="C:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe:*:Enabled:McAfee Framework Service"
"C:\\Program Files\\Messenger\\Msmsgs.exe"="C:\\Program Files\\Messenger\\Msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\WINDOWS\\system32\\mmc.exe"="C:\\WINDOWS\\system32\\mmc.exe:*:Enabled:Microsoft Management Console"
"C:\\Program Files\\EditPlus 2\\editplus.exe"="C:\\Program Files\\EditPlus 2\\editplus.exe:*:Enabled:EditPlus"

Remaining Files:
—————

File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes:

Tue 3 Aug 2004 60,416 A.SH. — "C:\Program Files\Outlook Express\msimn.exe"
Sat 15 Dec 2007 186,608 A..H. — "C:\Documents and Settings\dgranadi\Local Settings\Temp\BIT6F.tmp"
Fri 11 Jan 2008 103,988 A..H. — "C:\Documents and Settings\dgranadi\Local Settings\Temp\tmp11B.tmp"
Tue 9 Oct 2007 49,243,173 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\54f4dd895e1790ab11941a72be5ea063\BIT2B.tmp"
Mon 12 Feb 2007 3,096,576 A..H. — "C:\Documents and Settings\Administrator\Application Data\U3\temp\Launchpad Removal.exe"

Finished!


ComboFIX

ComboFix 08-01-20.1 - DGranadi 2008-01-19 17:52:27.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.674 [GMT -6:00]
Running from: d:\User Folders\dgranadi\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Temp\tpBe12
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\abocktry.dll
C:\WINDOWS\system32\agjclios.dll
C:\WINDOWS\system32\Cache
C:\WINDOWS\system32\cihinpcu.dll
C:\WINDOWS\system32\cqhlastd.dll
C:\WINDOWS\system32\cvoyxich.dll
C:\WINDOWS\system32\dauatbve.dll
C:\WINDOWS\system32\erpoores.dll
C:\WINDOWS\system32\etqtkmnh.dll
C:\WINDOWS\system32\evhgyisu.dll
C:\WINDOWS\system32\gfyqsgsm.dll
C:\WINDOWS\system32\hcqsdxcw.ini
C:\WINDOWS\system32\ieswcfqm.dll
C:\WINDOWS\system32\ijdxormr.dll
C:\WINDOWS\system32\ilncdajq.dll
C:\WINDOWS\system32\ineWc01
C:\WINDOWS\system32\jbgregpg.dll
C:\WINDOWS\system32\jemifhgu.ini
C:\WINDOWS\system32\kfibtnmu.dll
C:\WINDOWS\system32\lhntlhyb.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mfpvvptn.dll
C:\WINDOWS\system32\mhojgjon.dll
C:\WINDOWS\system32\mhwevteb.dll
C:\WINDOWS\system32\mqfcwsei.ini
C:\WINDOWS\system32\nbdrdfdm.dll
C:\WINDOWS\system32\nbvqbomi.dll
C:\WINDOWS\system32\oiexakgx.dll
C:\WINDOWS\system32\orpyuwlf.dll
C:\WINDOWS\system32\phabnnrp.dll
C:\WINDOWS\system32\prtgrwct.dll
C:\WINDOWS\system32\qgyajoet.ini
C:\WINDOWS\system32\qimtdpoq.dll
C:\WINDOWS\system32\qitvniug.dll
C:\WINDOWS\system32\qslfirfo.dll
C:\WINDOWS\system32\rmroxdji.ini
C:\WINDOWS\system32\smysstqx.dll
C:\WINDOWS\system32\sxsfemfn.dll
C:\WINDOWS\system32\teojaygq.dll
C:\WINDOWS\system32\ughfimej.dll
C:\WINDOWS\system32\ukriecnb.dll
C:\WINDOWS\system32\utiwwjas.dll
C:\WINDOWS\system32\voeqsvik.dll
C:\WINDOWS\system32\vqrdtdsa.dll
C:\WINDOWS\system32\vuwlbibi.dll
C:\WINDOWS\system32\wcxdsqch.dll
C:\WINDOWS\system32\wkjckpvg.dll
C:\WINDOWS\system32\wyrktqij.dll
C:\WINDOWS\system32\xahlxsqc.dll
C:\WINDOWS\system32\xciepkxx.dll
C:\WINDOWS\system32\xxyxvst.dll
C:\WINDOWS\system32\xxyyx.dll
C:\WINDOWS\system32\xyyxx.ini
C:\WINDOWS\system32\xyyxx.ini2
C:\WINDOWS\system32\yvxtavgi.dll
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat . . . . failed to delete
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat . . . . failed to delete

—– Unknown downloads made by BITS: —-
http://80.93.48.74
http://A2K-ADCSMS-01:80
http://D2K-MIA361-01:80õj+|Cü¤Ì›v÷+È…©½ºD˜QÄ{¶ÀzÎtç Ò»ÌHžG†.XóƉoß›7M¦·í
http://D2K-MIA361-01:80
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_CMDSERVICE
——-\LEGACY_DOMAINSERVICE


((((((((((((((((((((((((( Files Created from 2007-12-21 to 2008-01-21 )))))))))))))))))))))))))))))))
.

2008-01-19 17:49 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-19 16:35 . 2008-01-19 16:36 d——– C:\WINDOWS\ERUNT
2008-01-18 08:41 . 2008-01-19 07:02 1,475,553 –ahs—- C:\WINDOWS\system32\rmwrujwh.ini
2008-01-17 08:24 . 2008-01-18 08:34 1,493,974 –ahs—- C:\WINDOWS\system32\lwcvdinl.ini
2008-01-16 08:22 . 2008-01-17 08:23 1,526,775 –ahs—- C:\WINDOWS\system32\ldltixvw.ini
2008-01-15 08:18 . 2008-01-16 08:18 1,625,299 –ahs—- C:\WINDOWS\system32\gltukcyn.ini
2008-01-14 08:17 . 2008-01-15 08:17 1,861,308 –ahs—- C:\WINDOWS\system32\puprogrc.ini
2008-01-13 11:34 . 2008-01-14 08:11 1,894,014 –ahs—- C:\WINDOWS\system32\ercjxeam.ini
2008-01-12 09:49 . 2008-01-13 11:23 1,056,967 –ahs—- C:\WINDOWS\system32\grjdbvwn.ini
2008-01-11 09:55 . 2008-01-12 07:41 1,056,727 –ahs—- C:\WINDOWS\system32\cxccpsxn.ini
2008-01-11 09:46 . 2008-01-19 17:44 15,565 –a—— C:\WINDOWS\BM6f06eb26.xml
2008-01-11 09:46 . 2008-01-20 17:52 21 –a—— C:\WINDOWS\pskt.ini
2008-01-10 09:45 . 2008-01-11 09:46 1,060,199 –ahs—- C:\WINDOWS\system32\raqawksg.ini
2008-01-09 09:49 . 2008-01-10 08:13 1,049,037 –ahs—- C:\WINDOWS\system32\mahksudh.ini
2008-01-08 09:45 . 2008-01-09 09:46 1,048,857 –ahs—- C:\WINDOWS\system32\junsvedy.ini
2008-01-07 09:49 . 2008-01-08 07:58 1,044,635 –ahs—- C:\WINDOWS\system32\egmrsbeh.ini
2008-01-06 18:40 . 2008-01-06 18:40 d——– C:\WINDOWS\Sun
2008-01-06 18:40 . 2007-09-24 23:31 69,632 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-01-06 18:38 . 2008-01-06 18:40 d——– C:\Program Files\Java
2008-01-06 18:37 . 2008-01-06 18:37 d——– C:\Program Files\Common Files\Java
2008-01-06 18:36 . 2008-01-13 08:13 1,469 –a—— C:\WINDOWS\mozver.dat
2008-01-06 18:27 . 2008-01-06 18:27 0 –a—— C:\WINDOWS\nsreg.dat
2008-01-06 09:47 . 2008-01-07 09:47 1,044,455 –ahs—- C:\WINDOWS\system32\aoonqlbi.ini
2008-01-05 09:47 . 2008-01-06 09:47 1,044,280 –ahs—- C:\WINDOWS\system32\ttgywcpb.ini
2008-01-04 09:47 . 2008-01-05 09:00 1,044,067 –ahs—- C:\WINDOWS\system32\nrywllwt.ini
2008-01-02 18:40 . 2008-01-02 18:57 d——– C:\Documents and Settings\Administrator\Application Data\U3
2008-01-02 00:42 . 2008-01-02 00:42 d——– C:\Program Files\Enigma Software Group
2008-01-02 00:25 . 2008-01-13 12:24 d——– C:\Program Files\XoftSpySE
2008-01-02 00:02 . 2008-01-02 00:11 d——– C:\Program Files\EMCO MoveOnBoot
2008-01-01 22:25 . 2008-01-01 22:25 d——– C:\VundoFix Backups
2008-01-01 09:46 . 2008-01-02 09:36 987,291 –ahs—- C:\WINDOWS\system32\wkircucr.ini
2007-12-31 09:26 . 2008-01-01 09:40 986,492 –ahs—- C:\WINDOWS\system32\xqtjmlog.ini
2007-12-30 09:22 . 2007-12-31 09:23 986,372 –ahs—- C:\WINDOWS\system32\yvdtxucb.ini
2007-12-29 09:23 . 2007-12-30 08:23 986,252 –ahs—- C:\WINDOWS\system32\cojitdec.ini
2007-12-28 09:20 . 2007-12-29 09:21 986,132 –ahs—- C:\WINDOWS\system32\nhcrpeet.ini
2007-12-28 07:16 . 2007-12-28 07:16 d——– C:\Program Files\GiPo@Utilities
2007-12-28 07:16 . 2007-12-28 07:16 d——– C:\Program Files\Common Files\Gibinsoft Shared
2007-12-27 12:50 . 2008-01-02 18:59 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-27 09:22 . 2007-12-28 08:48 1,030,553 –ahs—- C:\WINDOWS\system32\ctsfodvi.ini
2007-12-26 09:18 . 2007-12-27 09:18 1,031,199 –ahs—- C:\WINDOWS\system32\kjmnqnrq.ini
2007-12-25 08:03 . 2008-01-19 10:36 d——– d:\User Folders\dgranadi\Application Data\U3
2007-12-25 04:20 . 2007-12-25 04:21 d——– C:\Program Files\Google
2007-12-25 04:20 . 2005-09-23 08:29 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-12-23 09:16 . 2007-12-24 09:18 993,346 –ahs—- C:\WINDOWS\system32\twytetcs.ini
2007-12-22 08:30 . 2007-12-23 09:15 991,530 –ahs—- C:\WINDOWS\system32\jsktwjdc.ini
2007-12-21 13:38 . 2007-12-22 08:11 992,367 –ahs—- C:\WINDOWS\system32\gbejjjle.ini

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-17 19:42 ——— d—–w d:\User Folders\dgranadi\Application Data\AdobeUM
2008-01-12 04:32 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-27 17:26 ——— d—–w C:\Program Files\EditPlus 2
2007-12-25 10:53 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-14 17:09 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-12-14 17:05 ——— d—–w C:\Program Files\Microsoft SQL Server
2007-12-11 18:36 ——— d—–w C:\Program Files\UADataProcessor
2007-12-04 16:38 ——— d—–w d:\User Folders\dgranadi\Application Data\gnupg
2007-12-04 16:22 ——— d—–w C:\Program Files\GNU
2007-11-29 20:01 51,392 —-a-w C:\WINDOWS\system32\drivers\atnt40k.sys
2007-11-19 18:44 57,344 —-a-w C:\WINDOWS\uneng.exe
2007-07-26 20:20 45,344 —-a-w d:\User Folders\dgranadi\Application Data\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]
"MSMSGS"="C:\Program Files\Messenger\Msmsgs.exe" [2005-08-31 19:27 1658592]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-12-25 04:21 171448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-03 23:56 15360]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-07-24 10:17:42 113664]
Cisco Systems VPN Client.lnk - C:\Program Files\Cisco Systems\VPN Client\vpngui.exe [2007-07-24 09:57:41 1459392]
Microsoft Office.lnk - C:\Program Files\AccessXP\Office10\OSA.EXE [2001-02-13 00:01:04 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"disablecad"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoDispBackgroundPage"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSetTaskbar"= 1 (0x1)
"NoSimpleStartMenu"= 1 (0x1)
"NoPropertiesMyDocuments"= 1 (0x1)
"NoPropertiesMyComputer"= 1 (0x1)
"NoPropertiesRecycleBin"= 1 (0x1)
"NoRecentDocsNetHood"= 1 (0x1)
"DisablePersonalDirChange"= 1 (0x1)
"NoCloseDragDropBands"= 1 (0x1)
"NoMovingBands"= 1 (0x1)
"DisallowCpl"= 1 (0x1)
"NoAutoUpdate"= 1 (0x1)
"ForceStartMenuLogOff"= 1 (0x1)
"DisallowRun"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\disallowrun]
"1"= msgr6suite.exe
"2"= msiexec.exe
"3"= weather.exe

R2 CcmExec;SMS Agent Host;C:\WINDOWS\System32\CCM\CcmExec.exe [2006-02-09 01:50]
R2 EIA Auditor;EIA Auditor;C:\EIA\ETS\EIATSService.exe [2000-01-17 16:41]
R2 EIAPMP;EIA PMP Server;C:\EIA\SDA\QckAuditSvr.exe [2003-04-09 13:25]
R2 EIAUsage;EIA Usage Tracker;C:\EIA\USAGE\UsageSvr.exe [2004-01-12 13:26]
R3 O2SCBUS;O2Micro SmartCardBus Reader;C:\WINDOWS\system32\DRIVERS\ozscr.sys [2002-11-07 17:13]
R3 prepdrvr;SMS Process Event Driver;C:\WINDOWS\System32\CCM\prepdrv.sys [2006-02-09 01:50]
S2 CMF PDF;CMF PDF;C:\CMF\CMFTDF\CMFWPDF.EXE [2004-03-09 18:24]
S2 CMF Windows Installer;CMF Windows Installer;C:\CMF\CMFTDF\CMFWINST.EXE [2004-08-26 17:08]
S3 OracleOracleHome90ClientCache;OracleOracleHome90ClientCache;C:\Oracle\ora90\BIN\ONRSD.EXE [2001-08-14 15:25]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\##dgx270-fv8zt51#d]
\Shell\AutoRun\command - Y:\Start.exe
\Shell\install\command - Y:\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\##dgx270-fv8zt51.americas.lsgsc.com#d]
\Shell\AutoRun\command - V:\setup.exe

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-20 18:22:12
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-20 18:28:13 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-21 00:28:08


Hijackthis log

Logfile of HijackThis v1.99.1
Scan saved at 18:31, on 2008-01-20
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\EIA\ETS\EIATSService.exe
C:\EIA\SDA\QckAuditSvr.exe
C:\EIA\USAGE\UsageSvr.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\WINDOWS\System32\CCM\CcmExec.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\Msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\WINDOWS\System32\CCM\SMSCliUI.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = A2k-adcprx-01.lsgsc.com:8080
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\Msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\AccessXP\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: Yahoo! Canasta - http://download2.games.yahoo.com/games/clients/y/yt2_x.cab
O16 - DPF: {0a454840-7232-11d5-b63d-00c04faedb18} -
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1191941202941
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://orangebusiness.webex.com/client/v_m…bex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = americas.lsgsc.com
O17 - HKLM\Software\..\Telephony: DomainName = americas.lsgsc.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = americas.lsgsc.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = americas.lsgsc.com
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: CMF PDF - LAN SuperVision, Inc. - C:\CMF\CMFTDF\CMFWPDF.EXE
O23 - Service: CMF Windows Installer - LAN SuperVision Inc. - C:\CMF\CMFTDF\CMFWINST.EXE
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: EIA Auditor - Unknown owner - C:\EIA\ETS\EIATSService.exe
O23 - Service: EIA PMP Server (EIAPMP) - Unknown owner - C:\EIA\SDA\QckAuditSvr.exe
O23 - Service: EIA Usage Tracker (EIAUsage) - Lan Supervision - C:\EIA\USAGE\UsageSvr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpdj - Unknown owner - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\hpdj.exe (file missing)
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program Files\McAfee\Common Framework\FrameworkService.exe" /ServiceStart (file missing)
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: OracleOracleHome90ClientCache - Unknown owner - C:\Oracle\ora90\BIN\ONRSD.EXE
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service (file missing)


Your turn now.
Please print out or copy this page to Notepad because your system will be totally disconnected from the internet and you will not have access to this information. Make sure to work through the fixes in the exact order in which they are mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes.


1. Open Notepad and copy the content of the following codebox into the Notepad File which I want you to save to your Desktop as CFScript.txt:

KillAll::

File::
C:\WINDOWS\system32\rmwrujwh.ini
C:\WINDOWS\system32\lwcvdinl.ini
C:\WINDOWS\system32\ldltixvw.ini
C:\WINDOWS\system32\gltukcyn.ini
C:\WINDOWS\system32\puprogrc.ini
C:\WINDOWS\system32\ercjxeam.ini
C:\WINDOWS\system32\grjdbvwn.ini
C:\WINDOWS\system32\cxccpsxn.ini
C:\WINDOWS\BM6f06eb26.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\raqawksg.ini
C:\WINDOWS\system32\mahksudh.ini
C:\WINDOWS\system32\junsvedy.ini
C:\WINDOWS\system32\egmrsbeh.ini
C:\WINDOWS\system32\aoonqlbi.ini
C:\WINDOWS\system32\ttgywcpb.ini
C:\WINDOWS\system32\nrywllwt.ini
C:\WINDOWS\system32\wkircucr.ini
C:\WINDOWS\system32\xqtjmlog.ini
C:\WINDOWS\system32\yvdtxucb.ini
C:\WINDOWS\system32\cojitdec.ini
C:\WINDOWS\system32\nhcrpeet.ini
C:\WINDOWS\system32\ctsfodvi.ini
C:\WINDOWS\system32\kjmnqnrq.ini
C:\WINDOWS\system32\twytetcs.ini
C:\WINDOWS\system32\jsktwjdc.ini
C:\WINDOWS\system32\gbejjjle.ini
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat 
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat

Driver::
hpdj

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\##dgx270-fv8zt51#d]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\##dgx270-fv8zt51.americas.lsgsc.com#d]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{0a454840-7232-11d5-b63d-00c04faedb18}]

2. Physically disconnect your computer from the internet (Unplug the cable)

3. Go Start>>Run and type sc stop BITS and press ENTER

4. Now I need you to reboot your system into Safe Mode:


How to use the F8 method to Start Your Computer in Safe Mode*Restart the computer.
*as soon as BIOS is loaded begin tapping the F8 key until the Advanced Options menu appears.
*Use the arrow keys to select the Safe mode menu item
*press Enter.


5. Now drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


6. Save the new ComboFix.txt to your Desktop for easy retrieval. If you are unable to do so, you can always find it later at C:\ComboFix.txt.

7. If your system does not restart on its own, restart it manually and boot into Normal Windows Mode.

8. Next go Start>>Run and type sc start BITS and press ENTER.

9. It is now time to physically reconnect to the internet.

10.
Please post the following Logs/Reports in your reply:
  • ComboFix.txt
  • A new HijackThis log

11. Also, in your reply, please tell me if you set the Control Panel and Internet Explorer Restrictions that I saw in the 06 Section of your HijackThis log.
Regarding the IE AND CONTROL PANEL RESTRICTIONS, NO i did not set them.

COMBO FIX LOG

ComboFix 08-01-20.1 - DGranadi 2008-01-20 0:16:00.2 - NTFSx86 NETWORK
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.904 [GMT -6:00]
Running from: d:\User Folders\dgranadi\Desktop\ComboFix.exe
Command switches used :: d:\User Folders\dgranadi\Desktop\CFScript.txt

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\WINDOWS\BM6f06eb26.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\aoonqlbi.ini
C:\WINDOWS\system32\cojitdec.ini
C:\WINDOWS\system32\ctsfodvi.ini
C:\WINDOWS\system32\cxccpsxn.ini
C:\WINDOWS\system32\egmrsbeh.ini
C:\WINDOWS\system32\ercjxeam.ini
C:\WINDOWS\system32\gbejjjle.ini
C:\WINDOWS\system32\gltukcyn.ini
C:\WINDOWS\system32\grjdbvwn.ini
C:\WINDOWS\system32\jsktwjdc.ini
C:\WINDOWS\system32\junsvedy.ini
C:\WINDOWS\system32\kjmnqnrq.ini
C:\WINDOWS\system32\ldltixvw.ini
C:\WINDOWS\system32\lwcvdinl.ini
C:\WINDOWS\system32\mahksudh.ini
C:\WINDOWS\system32\nhcrpeet.ini
C:\WINDOWS\system32\nrywllwt.ini
C:\WINDOWS\system32\puprogrc.ini
C:\WINDOWS\system32\raqawksg.ini
C:\WINDOWS\system32\rmwrujwh.ini
C:\WINDOWS\system32\ttgywcpb.ini
C:\WINDOWS\system32\twytetcs.ini
C:\WINDOWS\system32\wkircucr.ini
C:\WINDOWS\system32\xqtjmlog.ini
C:\WINDOWS\system32\yvdtxucb.ini
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\WINDOWS\BM6f06eb26.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\aoonqlbi.ini
C:\WINDOWS\system32\cojitdec.ini
C:\WINDOWS\system32\ctsfodvi.ini
C:\WINDOWS\system32\cxccpsxn.ini
C:\WINDOWS\system32\egmrsbeh.ini
C:\WINDOWS\system32\ercjxeam.ini
C:\WINDOWS\system32\gbejjjle.ini
C:\WINDOWS\system32\gltukcyn.ini
C:\WINDOWS\system32\grjdbvwn.ini
C:\WINDOWS\system32\jsktwjdc.ini
C:\WINDOWS\system32\junsvedy.ini
C:\WINDOWS\system32\kjmnqnrq.ini
C:\WINDOWS\system32\ldltixvw.ini
C:\WINDOWS\system32\lwcvdinl.ini
C:\WINDOWS\system32\mahksudh.ini
C:\WINDOWS\system32\nhcrpeet.ini
C:\WINDOWS\system32\nrywllwt.ini
C:\WINDOWS\system32\puprogrc.ini
C:\WINDOWS\system32\raqawksg.ini
C:\WINDOWS\system32\rmwrujwh.ini
C:\WINDOWS\system32\ttgywcpb.ini
C:\WINDOWS\system32\twytetcs.ini
C:\WINDOWS\system32\wkircucr.ini
C:\WINDOWS\system32\xqtjmlog.ini
C:\WINDOWS\system32\yvdtxucb.ini

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_HPDJ
——-\hpdj


((((((((((((((((((((((((( Files Created from 2007-12-20 to 2008-01-20 )))))))))))))))))))))))))))))))
.

2008-01-19 17:49 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-19 16:35 . 2008-01-19 16:36 d——– C:\WINDOWS\ERUNT
2008-01-06 18:40 . 2008-01-06 18:40 d——– C:\WINDOWS\Sun
2008-01-06 18:40 . 2007-09-24 23:31 69,632 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-01-06 18:38 . 2008-01-06 18:40 d——– C:\Program Files\Java
2008-01-06 18:37 . 2008-01-06 18:37 d——– C:\Program Files\Common Files\Java
2008-01-06 18:36 . 2008-01-13 08:13 1,469 –a—— C:\WINDOWS\mozver.dat
2008-01-06 18:27 . 2008-01-06 18:27 0 –a—— C:\WINDOWS\nsreg.dat
2008-01-02 18:40 . 2008-01-02 18:57 d——– C:\Documents and Settings\Administrator\Application Data\U3
2008-01-02 00:42 . 2008-01-02 00:42 d——– C:\Program Files\Enigma Software Group
2008-01-02 00:25 . 2008-01-13 12:24 d——– C:\Program Files\XoftSpySE
2008-01-02 00:02 . 2008-01-02 00:11 d——– C:\Program Files\EMCO MoveOnBoot
2008-01-01 22:25 . 2008-01-01 22:25 d——– C:\VundoFix Backups
2007-12-28 07:16 . 2007-12-28 07:16 d——– C:\Program Files\GiPo@Utilities
2007-12-28 07:16 . 2007-12-28 07:16 d——– C:\Program Files\Common Files\Gibinsoft Shared
2007-12-27 12:50 . 2008-01-02 18:59 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-25 08:03 . 2008-01-19 10:36 d——– d:\User Folders\dgranadi\Application Data\U3
2007-12-25 04:20 . 2007-12-25 04:21 d——– C:\Program Files\Google
2007-12-25 04:20 . 2005-09-23 08:29 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-12-20 11:57 . 2007-12-21 13:33 988,114 –ahs—- C:\WINDOWS\system32\qngylryt.ini

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-17 19:42 ——— d—–w d:\User Folders\dgranadi\Application Data\AdobeUM
2008-01-12 04:32 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-27 17:26 ——— d—–w C:\Program Files\EditPlus 2
2007-12-25 10:53 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-14 17:09 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-12-14 17:05 ——— d—–w C:\Program Files\Microsoft SQL Server
2007-12-11 18:36 ——— d—–w C:\Program Files\UADataProcessor
2007-12-04 16:38 ——— d—–w d:\User Folders\dgranadi\Application Data\gnupg
2007-12-04 16:22 ——— d—–w C:\Program Files\GNU
2007-11-29 20:01 51,392 —-a-w C:\WINDOWS\system32\drivers\atnt40k.sys
2007-11-19 18:44 57,344 —-a-w C:\WINDOWS\uneng.exe
2007-07-26 20:20 45,344 —-a-w d:\User Folders\dgranadi\Application Data\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((( snapshot@2008-01-20_18.27.37.31 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-19 23:50:17 237,568 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-20 06:15:17 237,568 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
- 2008-01-19 23:50:17 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-20 06:15:17 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
- 2008-01-19 23:50:18 237,568 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-20 06:15:17 237,568 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
- 2008-01-19 23:50:18 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-20 06:15:17 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
- 2008-01-19 23:50:19 2,310,144 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
+ 2008-01-20 06:15:18 5,365,760 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\ntuser.dat
- 2008-01-19 23:50:19 147,456 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-20 06:15:18 147,456 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]
"MSMSGS"="C:\Program Files\Messenger\Msmsgs.exe" [2005-08-31 19:27 1658592]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-12-25 04:21 171448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-03 23:56 15360]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-07-24 10:17:42 113664]
Cisco Systems VPN Client.lnk - C:\Program Files\Cisco Systems\VPN Client\vpngui.exe [2007-07-24 09:57:41 1459392]
Microsoft Office.lnk - C:\Program Files\AccessXP\Office10\OSA.EXE [2001-02-13 00:01:04 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"disablecad"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoDispBackgroundPage"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSetTaskbar"= 1 (0x1)
"NoSimpleStartMenu"= 1 (0x1)
"NoPropertiesMyDocuments"= 1 (0x1)
"NoPropertiesMyComputer"= 1 (0x1)
"NoPropertiesRecycleBin"= 1 (0x1)
"NoRecentDocsNetHood"= 1 (0x1)
"DisablePersonalDirChange"= 1 (0x1)
"NoCloseDragDropBands"= 1 (0x1)
"NoMovingBands"= 1 (0x1)
"DisallowCpl"= 1 (0x1)
"NoAutoUpdate"= 1 (0x1)
"ForceStartMenuLogOff"= 1 (0x1)
"DisallowRun"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\disallowrun]
"1"= msgr6suite.exe
"2"= msiexec.exe
"3"= weather.exe

R2 CcmExec;SMS Agent Host;C:\WINDOWS\System32\CCM\CcmExec.exe [2006-02-09 01:50]
R2 EIA Auditor;EIA Auditor;C:\EIA\ETS\EIATSService.exe [2000-01-17 16:41]
R2 EIAPMP;EIA PMP Server;C:\EIA\SDA\QckAuditSvr.exe [2003-04-09 13:25]
R2 EIAUsage;EIA Usage Tracker;C:\EIA\USAGE\UsageSvr.exe [2004-01-12 13:26]
R3 O2SCBUS;O2Micro SmartCardBus Reader;C:\WINDOWS\system32\DRIVERS\ozscr.sys [2002-11-07 17:13]
R3 prepdrvr;SMS Process Event Driver;C:\WINDOWS\System32\CCM\prepdrv.sys [2006-02-09 01:50]
S2 CMF PDF;CMF PDF;C:\CMF\CMFTDF\CMFWPDF.EXE [2004-03-09 18:24]
S2 CMF Windows Installer;CMF Windows Installer;C:\CMF\CMFTDF\CMFWINST.EXE [2004-08-26 17:08]
S3 OracleOracleHome90ClientCache;OracleOracleHome90ClientCache;C:\Oracle\ora90\BIN\ONRSD.EXE [2001-08-14 15:25]

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-20 00:25:33
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-20 0:31:22 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-20 06:31:17
ComboFix2.txt 2008-01-21 00:28:14


HIJACKTHIS LOG

Logfile of HijackThis v1.99.1
Scan saved at 00:37, on 2008-01-20
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\EIA\ETS\EIATSService.exe
C:\EIA\SDA\QckAuditSvr.exe
C:\EIA\USAGE\UsageSvr.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\WINDOWS\System32\CCM\CcmExec.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\Msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\WINDOWS\System32\CCM\SMSCliUI.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = A2k-adcprx-01.lsgsc.com:8080
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\Msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\AccessXP\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: Yahoo! Canasta - http://download2.games.yahoo.com/games/clients/y/yt2_x.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1191941202941
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://orangebusiness.webex.com/client/v_m…bex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = americas.lsgsc.com
O17 - HKLM\Software\..\Telephony: DomainName = americas.lsgsc.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = americas.lsgsc.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = americas.lsgsc.com
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: CMF PDF - LAN SuperVision, Inc. - C:\CMF\CMFTDF\CMFWPDF.EXE
O23 - Service: CMF Windows Installer - LAN SuperVision Inc. - C:\CMF\CMFTDF\CMFWINST.EXE
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: EIA Auditor - Unknown owner - C:\EIA\ETS\EIATSService.exe
O23 - Service: EIA PMP Server (EIAPMP) - Unknown owner - C:\EIA\SDA\QckAuditSvr.exe
O23 - Service: EIA Usage Tracker (EIAUsage) - Lan Supervision - C:\EIA\USAGE\UsageSvr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program Files\McAfee\Common Framework\FrameworkService.exe" /ServiceStart (file missing)
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: OracleOracleHome90ClientCache - Unknown owner - C:\Oracle\ora90\BIN\ONRSD.EXE
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service (file missing)

Thank you

Your turn now.
Starting to look good!!

A.
  • First we need to make all files and folders VISIBLE:

    • Go to start>control panel>folder options>view
    • Choose to "show hidden files and folders,"
    • Uncheck the "hide protected operating system files" and the "hide extensions for know file types" boxes.
    • Close the window with ok

  • Please RUN HijackThis.
    . Click the SCAN button to produce a log.

  • Place a check mark beside each one of the following items:

    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present


  • Now with all the items selected, and all windows closed except for HJT, delete them by clicking the FIX checked button. Close the HijackThis window.

  • Using Windows Explorer (Windows Key + E), locate the following files/folders, and DELETE them (if still present): (If you are unable to delete he file in Normal Windows Mode, try to delete it in Safe Mode)


    C:\WINDOWS\system32\qngylryt.ini

  • Exit Explorer

  • Finally, RUN Hijackthis again and produce a new HJT log. Post it in the forum for review


B. We need to check over your entire system. To make sure that no "baddies" have slipped under our radar.

I need you to run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
I was not able to run Eset Online Scanner
When it attempted to install and update the update failed
Error update failed (108)
Rebooted tried a couple of additional times with no luck.

here is the Hijackthislog

Logfile of HijackThis v1.99.1
Scan saved at 17:30, on 2008-01-20
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\EIA\ETS\EIATSService.exe
C:\EIA\SDA\QckAuditSvr.exe
C:\EIA\USAGE\UsageSvr.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\WINDOWS\System32\CCM\CcmExec.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\Msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\WINDOWS\System32\CCM\SMSCliUI.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = A2k-adcprx-01.lsgsc.com:8080
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\Msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\AccessXP\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: Yahoo! Canasta - http://download2.games.yahoo.com/games/clients/y/yt2_x.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1191941202941
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://orangebusiness.webex.com/client/v_m…bex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = americas.lsgsc.com
O17 - HKLM\Software\..\Telephony: DomainName = americas.lsgsc.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = americas.lsgsc.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = americas.lsgsc.com
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: CMF PDF - LAN SuperVision, Inc. - C:\CMF\CMFTDF\CMFWPDF.EXE
O23 - Service: CMF Windows Installer - LAN SuperVision Inc. - C:\CMF\CMFTDF\CMFWINST.EXE
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: EIA Auditor - Unknown owner - C:\EIA\ETS\EIATSService.exe
O23 - Service: EIA PMP Server (EIAPMP) - Unknown owner - C:\EIA\SDA\QckAuditSvr.exe
O23 - Service: EIA Usage Tracker (EIAUsage) - Lan Supervision - C:\EIA\USAGE\UsageSvr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program Files\McAfee\Common Framework\FrameworkService.exe" /ServiceStart (file missing)
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: OracleOracleHome90ClientCache - Unknown owner - C:\Oracle\ora90\BIN\ONRSD.EXE
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service (file missing)

Thanks
Please use the Internet Explorer browser, and do an online scan with Kaspersky Online Scanner
Select "Global" from the drop down menu at the top of the page.
Click Yes, when prompted to install its ActiveX component.
(Note.. for Internet Explorer 7 users: If at any time you have trouble with the "Accept" button of the license, click on the "Zoom" tool located at the bottom right of the IE window and set the zoom to 75 %. Once the license has been accepted, reset to 100%.)
The program launches and downloads the latest definition files.
  • Once the files are downloaded click on Next
  • Click on Scan Settings and configure as follows:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:Scan Archives
      Scan Mail Bases
  • Click OK and, under select a target to scan, select My Computer
When the scan is done, in the Scan is completed window (below), any infection is displayed.
There is no option to clean/disinfect, however, we need to analyze the information on the report.
[external image: Posted Image]
[external image: Posted Image]
To obtain the report:
Click on: Save Report As (above - red blinking arrow)
Next, in the Save as prompt, Save in area, select: Desktop
In the File name area, use KScan, or something similar
In Save as type, click the drop arrow and select: Text file [*.txt]
Then, click: Save
Please post the Kaspersky Online Scanner Report in your reply, along with a fresh HijackThis log
Just wanted to notify you on what's going on, I tried to leave Kaspersky overnight running and it hang up, so i will need to run it by folders, and i will post you the results when done.
I hope you are well and not experiencing any difficulties carrying out my last set of instructions. If you are, do not hesitate to ask for further explanations. If however, your problem has been solved or you no longer require our assistance, please advise us accordingly and we will archive your topic.

Trevuren
I was able to run kaspersky by folders and it looks like we are clean with hte exception of the following (catchme):

Kaspersky Log

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
January 22, 2008 06:33
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 21/01/2008
Kaspersky Anti-Virus database records: 526188
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 33003
Number of viruses found: 2
Number of infected objects: 3
Number of suspicious objects: 0
Duration of the scan process: 10:25:53

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\McAfee\Common Framework\Db\Agent_ND600-2W3ZT51.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\Common Framework\Db\PrdMgr_ND600-2W3ZT51.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\DesktopProtection\AccessProtectionLog.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\DesktopProtection\BufferOverflowProtectionLog.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\DesktopProtection\OnAccessScanLog.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\dgranadi\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\dgranadi\Desktop\catchme.zip/xxyxvst.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.byj skipped
C:\Documents and Settings\dgranadi\Desktop\catchme.zip/xxyyx.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.dit skipped
C:\Documents and Settings\dgranadi\Desktop\catchme.zip ZIP: infected - 2 skipped
C:\Documents and Settings\dgranadi\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\dgranadi\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\dgranadi\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\dgranadi\Local Settings\History\History.IE5\MSHist012008012120080122\index.dat Object is locked skipped
C:\Documents and Settings\dgranadi\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\dgranadi\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\dgranadi\ntuser.dat Object is locked skipped
C:\Documents and Settings\dgranadi\NTUSER.DAT.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

Latest Hijackthis log

Logfile of HijackThis v1.99.1
Scan saved at 07:05, on 01/27/08
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\EIA\ETS\EIATSService.exe
C:\EIA\SDA\QckAuditSvr.exe
C:\EIA\USAGE\UsageSvr.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\WINDOWS\System32\CCM\CcmExec.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\Msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = A2k-adcprx-01.lsgsc.com:8080
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\Msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\AccessXP\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: Yahoo! Canasta - http://download2.games.yahoo.com/games/clients/y/yt2_x.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1191941202941
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://orangebusiness.webex.com/client/v_m…bex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = americas.lsgsc.com
O17 - HKLM\Software\..\Telephony: DomainName = americas.lsgsc.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = americas.lsgsc.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = americas.lsgsc.com
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: CMF PDF - LAN SuperVision, Inc. - C:\CMF\CMFTDF\CMFWPDF.EXE
O23 - Service: CMF Windows Installer - LAN SuperVision Inc. - C:\CMF\CMFTDF\CMFWINST.EXE
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: EIA Auditor - Unknown owner - C:\EIA\ETS\EIATSService.exe
O23 - Service: EIA PMP Server (EIAPMP) - Unknown owner - C:\EIA\SDA\QckAuditSvr.exe
O23 - Service: EIA Usage Tracker (EIAUsage) - Lan Supervision - C:\EIA\USAGE\UsageSvr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program Files\McAfee\Common Framework\FrameworkService.exe" /ServiceStart (file missing)
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: OracleOracleHome90ClientCache - Unknown owner - C:\Oracle\ora90\BIN\ONRSD.EXE
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service (file missing)

Sorry about the delay, Thanks
Congratulations, your logs look CLEAN

There are a few things you must do once you system is completely clean:

Time for some housekeeping
  • A. Please DELETE the following folder and all its content: C:\SDFIX.

    B. Also DELETE the file catchme.zip from your desktop.


    C. Go to [external image: Posted Image] -> Run -> copy/paste in the following single line command & click OK


    combofix /u



    [external image: Posted Image]

    This will uninstall ComboFix. It will also implement some cleanup procedures and reset System Restore points.

    Now that your system is clean, to help protect your computer in the future I recommend that you follow these steps and use the following free programs:

    • Microsoft Windows Update - http://www.windowsupdate.com
      Visit regularly. This will ensure your computer always has the latest security updates. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
    • SpywareBlaster to help prevent spyware from installing in the first place.
        Install & update SpywareBlaster with the latest definitions.
        After you have updated, click the button - enable protection for all unprotected items
    • IE-SpyAd - IE/Spyad places more than 4000 dubious websites and domains in the IE Restricted list. This severely impairs attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites. An installation tutorial is available here.

    • MVPS HOST FILE
      The MVPS Hosts file replaces your current HOSTS file with one that will restrict known ad sites form serving you unsolicited advertisements. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is the IP of your local computer.
      • Download Host.zip to your desktop.
      • From your Desktop right-click (hosts.zip) and select:
        Extract All from the menu.
      • Click Next, click Next, select the option:
        "Show Extracted files", click Finish
      • This will open the newly created hosts folder on your Desktop.
      • Double-click on the included mvps.bat file, this will rename the existing HOSTS file to HOSTS.MVP, then it will copy the included updated HOSTS file to the correct location on your machine.
      • Once updated you should see another prompt that the task was completed.
    • ANTIVIRUS SOFTWARE
      It is very important that you have anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future. It is imperative that you update your antivirus software at least once a week (even more if you wish). If you do not update your antivirus software then it will not be able to catch new malware that may have come out.

      Do not install more than one AntiVirus program because they will conflict with each other.

    • FIREWALL
      Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. A tutorial on Firewalls and a listing of some available ones can be found here

      Do not install more than one firewall program because they will conflict with each other.

    Scan here http://secunia.com/software_inspector/ for out of date & vulnerable common applications on your computer

    Here are some additional utilities that will further enhance your safety.
    • http://www.trillian.cc ? Trillian or http://www.miranda-im.com ? Miranda-IM - These are Malware free Instant Messenger programs which allow you to connect to multiple IM services in one program! (AOL, Yahoo, ICQ, IRC, MSN)

    • http://www.mozilla.org/products/firefox/ - Firefox - Use this alternate browser. While Internet Explorer is not a bad browser, almost every exploit crafted is targeted to take advantage of an IE weakness.

    • http://java.com/en/index.jsp - Sun's Java - It's much more secure than Microsoft's Java Virtual Machine.

    • http://www.aumha.org/downloads/erunt-setup.exe - ERUNT - A useful freeware utility for users of Windows 2000/XP. It's made up of two parts - ERUNT & NTREGOPT.

      ERUNT will create daily complete backups of your computer's Registry. Whilst System Restore does the same thing, a corrupt registry file may prevent Windows from booting & this effectively renders disables System Restore. With ERUNT, you're able to restore the damaged Registry.

      NTREGOPT works by recreating each registry hive "from scratch", thus removing any slack space that may be left from previously modified or deleted keys. In other words, it compacts the Registry to a small size which allows Windows to load & perform faster.


    In light of your recent troubles, I'm sure you'll like to avoid any future infections. Please take a look at these well written articles
Sorry there were still a couple folders that i had not scanned, and while doing it some things came up Kaspersky log ——————————————————————————- KASPERSKY ONLINE SCANNER REPORT January 27, 2008 09:36 Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.98.0 Kaspersky Anti-Virus database last update: 27/01/2008 Kaspersky Anti-Virus database records: 534065 ——————————————————————————- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - Folders: C:\QooBox\ C:\System Volume Information\ C:\Temp\ C:\VundoFix Backups\ Scan Statistics: Total number of scanned objects: 4068 Number of viruses found: 12 Number of infected objects: 38 Number of suspicious objects: 0 Duration of the scan process: 00:03:07 Infected Object Name / Virus Name / Last Action C:\QooBox\Quarantine\C\WINDOWS\system32\abocktry.dll.vir Infected: Trojan.Win32.Pakes.bwd skipped C:\QooBox\Quarantine\C\WINDOWS\system32\agjclios.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.dnp skipped C:\QooBox\Quarantine\C\WINDOWS\system32\ieswcfqm.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.din skipped C:\QooBox\Quarantine\C\WINDOWS\system32\ijdxormr.dll.vir Infected: Backdoor.Win32.Agent.dlj skipped C:\QooBox\Quarantine\C\WINDOWS\system32\kfibtnmu.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.is skipped C:\QooBox\Quarantine\C\WINDOWS\system32\prtgrwct.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.dnl skipped C:\QooBox\Quarantine\C\WINDOWS\system32\ughfimej.dll.vir Infected: Backdoor.Win32.Agent.dlj skipped C:\QooBox\Quarantine\C\WINDOWS\system32\utiwwjas.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.dim skipped C:\QooBox\Quarantine\C\WINDOWS\system32\wcxdsqch.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.din skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{B29EB15A-A202-4487-B501-DA9B901618B7}\RP261\A0037608.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.din skipped C:\System Volume Information\_restore{B29EB15A-A202-4487-B501-DA9B901618B7}\RP262\A0037761.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.din skipped C:\System Volume Information\_restore{B29EB15A-A202-4487-B501-DA9B901618B7}\RP262\A0037878.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.din skipped C:\System Volume Information\_restore{B29EB15A-A202-4487-B501-DA9B901618B7}\RP263\A0037951.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.din skipped C:\System Volume Information\_restore{B29EB15A-A202-4487-B501-DA9B901618B7}\RP264\A0038167.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.din skipped C:\System Volume Information\_restore{B29EB15A-A202-4487-B501-DA9B901618B7}\RP264\A0038428.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.din skipped C:\System Volume Information\_restore{B29EB15A-A202-4487-B501-DA9B901618B7}\RP269\A0039352.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.din skipped C:\System Volume Information\_restore{B29EB15A-A202-4487-B501-DA9B901618B7}\RP269\A0039419.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.din skipped C:\System Volume Information\_restore{B29EB15A-A202-4487-B501-DA9B901618B7}\RP271\A0039930.exe/stream/data0002 Infected: Trojan-Downloader.Win32.Small.buy skipped C:\System Volume Information\_restore{B29EB15A-A202-4487-B501-DA9B901618B7}\RP271\A0039930.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped C:\System Volume Information\_restore{B29EB15A-A202-4487-B501-DA9B901618B7}\RP271\A0039930.exe/stream Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped C:\System Volume Information\_restore{B29EB15A-A202-4487-B501-DA9B901618B7}\RP271\A0039930.exe NSIS: infected - 3 skipped C:\System Volume Information\_restore{B29EB15A-A202-4487-B501-DA9B901618B7}\RP271\A0039932.exe Infected: Trojan-Downloader.Win32.Agent.fjn skipped C:\System Volume Information\_restore{B29EB15A-A202-4487-B501-DA9B901618B7}\RP271\A0039971.exe/stream/data0002 Infected: Trojan-Downloader.Win32.Small.buy skipped C:\System Volume Information\_restore{B29EB15A-A202-4487-B501-DA9B901618B7}\RP271\A0039971.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped C:\System Volume Information\_restore{B29EB15A-A202-4487-B501-DA9B901618B7}\RP271\A0039971.exe/stream Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped C:\System Volume Information\_restore{B29EB15A-A202-4487-B501-DA9B901618B7}\RP271\A0039971.exe NSIS: infected - 3 skipped C:\System Volume Information\_restore{B29EB15A-A202-4487-B501-DA9B901618B7}\RP271\A0039973.exe Infected: Trojan-Downloader.Win32.Agent.fjn skipped C:\System Volume Information\_restore{B29EB15A-A202-4487-B501-DA9B901618B7}\RP272\A0040019.dll Infected: Trojan.Win32.Pakes.bwd skipped C:\System Volume Information\_restore{B29EB15A-A202-4487-B501-DA9B901618B7}\RP272\A0040020.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.dnp skipped C:\System Volume Information\_restore{B29EB15A-A202-4487-B501-DA9B901618B7}\RP272\A0040029.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.din skipped C:\System Volume Information\_restore{B29EB15A-A202-4487-B501-DA9B901618B7}\RP272\A0040030.dll Infected: Backdoor.Win32.Agent.dlj skipped C:\System Volume Information\_restore{B29EB15A-A202-4487-B501-DA9B901618B7}\RP272\A0040033.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.is skipped C:\System Volume Information\_restore{B29EB15A-A202-4487-B501-DA9B901618B7}\RP272\A0040043.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.dnl skipped C:\System Volume Information\_restore{B29EB15A-A202-4487-B501-DA9B901618B7}\RP272\A0040050.dll Infected: Backdoor.Win32.Agent.dlj skipped C:\System Volume Information\_restore{B29EB15A-A202-4487-B501-DA9B901618B7}\RP272\A0040052.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.dim skipped C:\System Volume Information\_restore{B29EB15A-A202-4487-B501-DA9B901618B7}\RP272\A0040056.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.din skipped C:\System Volume Information\_restore{B29EB15A-A202-4487-B501-DA9B901618B7}\RP272\A0040071.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.byj skipped C:\System Volume Information\_restore{B29EB15A-A202-4487-B501-DA9B901618B7}\RP272\A0040072.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.dit skipped C:\System Volume Information\_restore{B29EB15A-A202-4487-B501-DA9B901618B7}\RP277\change.log Object is locked skipped Scan process completed. Thanks
Nothing to worry about there. They are all either in Quarantine or in your System Restore Cache both of which will be cleansed in the final cleanup procedures. Trevuren

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI