This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Hijack this log

44 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Recently, i got a virus. Norton wont detect it. Spybot wont detect it. Ad-aware does, but the computer restarts everytime i run that scan, so i cant delete it

the virus will send pornographic emails, rapidly, up to 1 per second. as far as i can tell, my isp wont let them go through, so others are safe, but its bad for me. i looked through the log, most of it i can interpret, becuase its pretty basic, but i want to know if im missing anything

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:20:14 PM, on 2/8/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
C:\Program Files\IomegaWare 4.0.2\DriveIcons\ImgIcon.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\NETGEAR\WG111v2\WG111v2.exe
C:\Program Files\Xfire\xfire.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
C:\WINDOWS\regedit.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
C:\Program Files\Symantec\LiveUpdate\AUPDATE.EXE
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: e404 helper - {F10587E9-0E47-4CBE-ABCD-7DD20B8622FF} - C:\Program Files\Helper\1202415031.dll
O3 - Toolbar: Clusty - {5538fb62-f725-4433-a965-91314e8d8e4d} - C:\Program Files\Clusty Toolbar\toolbar1.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [ADUserMon] C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\IomegaWare 4.0.2\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [Deskup] C:\Program Files\IomegaWare 4.0.2\DriveIcons\deskup.exe /IMGSTART
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - S-1-5-18 Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe (User 'Default user')
O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
O4 - Global Startup: NETGEAR WG111v2 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v2\WG111v2.exe
O8 - Extra context menu item: &Clusty meta-search - res://C:\Program Files\Clusty Toolbar\toolbar1.dll/SEARCH.HTML
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1193608390756
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…/sysreqlab2.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1193604043703
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://download.shockwave.com/pub/otoy/OTOYAX.cab
O16 - DPF: {BCBC9371-9827-11DA-A72B-0800200C9A66} (View22RTEv4 Class) - http://sc.scenecaster.com/release_3_10_41/View22RTEv4.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe (file missing)
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe

–
End of file - 8336 bytes

:pullhair: i spent all night last night tryingto get rid of this thing, please, any suggestions would be nice.
[external image: Posted Image]

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
wow, 14 infected files, jesus, and one of them looked to be a hacker type program. scan results here. I gotta say, thank you. i dont know if this has worked yet, but its gotten more results than anything else.

Malwarebytes' Anti-Malware 1.03
Database version: 339

Scan type: Quick Scan
Objects scanned: 22950
Time elapsed: 8 minute(s), 28 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 8
Registry Values Infected: 3
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 4

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{daed9266-8c28-4c1c-8b58-5c66eff1d302} (Search.Hijack) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\e404.e404mgr (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\e404.e404mgr.1 (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f10587e9-0e47-4cbe-abcd-7dd20b8622ff} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f10587e9-0e47-4cbe-abcd-7dd20b8622ff} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\xflock (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\E404.e404mgr (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Information Center (Trojan.Zlob) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{efaf6ea3-615d-4f83-8748-2f7a576fcea6} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow\*.securewebinfo.com (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow\*.safetyincludes.com (Trojan.Zlob) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\apiuser32.dll (Trojan.Shell.Object) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.url (Rogue.Link) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Security Troubleshooting.url (Rogue.Link) -> Quarantined and deleted successfully.
C:\Documents and Settings\Nate\Favorites\Online Security Test.url (Rogue.Link) -> Quarantined and deleted successfully.

heres my hijackthis log. can i ask what you saw wrong with it before?

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:23:19 PM, on 2/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\devldr32.exe
C:\Documents and Settings\Nate\Local Settings\Apps\2.0\D540P1LM.AP2\9OMWZD8C.KAW\cmpl..tion_098348a520b75eaf_0001.0001_9cdce56ca7e82c36\CMPlayers.exe
C:\Program Files\NETGEAR\WG111v2\WG111v2.exe
C:\Program Files\Xfire\xfire.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Nate\Local Settings\Temporary Internet Files\Content.IE5\IKRW6X2C\ATF-Cleaner[1].exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O3 - Toolbar: Clusty - {5538fb62-f725-4433-a965-91314e8d8e4d} - C:\Program Files\Clusty Toolbar\toolbar1.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O8 - Extra context menu item: &Clusty meta-search - res://C:\Program Files\Clusty Toolbar\toolbar1.dll/SEARCH.HTML
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1193608390756
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…/sysreqlab2.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1193604043703
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe

–
End of file - 6699 bytes

my computeer is currently still sending emails though… thats all its doing, im not sure i really want to scan with Ad-aware again becuase my system crashes everytime i do.
Lets dig a little deeper now that we have those out of the way.

Download ComboFix from Here to your Desktop.

**Note: In the event you already have Combofix, please delete it from your desktop and download this new version . It is important that it is saved directly to your desktop**
——————————————————————–
  • Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • WARNING: IF you have not already done so Combofix will disconnect your machine from the Internet when it starts
  • Please do not re-connect your machine back to the Internet until Combofix has completely finished.
——————————————————————–

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
here ya go

ComboFix 08-01-30.1 - Nate 2008-02-10 18:40:56.1 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\combofix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-01-10 to 2008-02-10 )))))))))))))))))))))))))))))))
.

2008-02-10 18:09 . 2008-02-10 18:09 d——– C:\Documents and Settings\Nate\Application Data\Malwarebytes
2008-02-10 18:08 . 2008-02-10 18:08 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-02-10 18:08 . 2008-02-10 18:08 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-02-10 15:12 . 2008-02-10 15:12 d——– C:\Documents and Settings\Nate_2\Application Data\Symantec
2008-02-10 15:12 . 2008-02-10 15:12 d——– C:\Documents and Settings\Nate_2\Application Data\AVG7
2008-02-10 15:11 . 2004-08-04 02:56 221,184 –a—— C:\WINDOWS\system32\wmpns.dll
2008-02-10 11:38 . 2008-02-10 11:39 d——– C:\Documents and Settings\Nate\Application Data\AVG7
2008-02-10 11:38 . 2008-02-10 11:38 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2008-02-10 11:37 . 2008-02-10 11:37 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-10 11:37 . 2008-02-10 11:39 d——– C:\Documents and Settings\All Users\Application Data\avg7
2008-02-10 11:37 . 2008-02-10 11:37 499,712 –a—— C:\WINDOWS\system32\msvcp71.dll
2008-02-10 11:37 . 2008-02-10 11:37 348,160 –a—— C:\WINDOWS\system32\msvcr71.dll
2008-02-09 22:38 . 2008-02-09 22:38 d——– C:\Documents and Settings\Nate\Application Data\Viewpoint
2008-02-09 13:42 . 2008-02-09 13:42 d——– C:\Documents and Settings\LocalService\Application Data\Xfire
2008-02-08 18:19 . 2008-02-08 18:19 d——– C:\Program Files\Trend Micro
2008-02-07 15:03 . 2008-02-07 15:03 54,764 –a—— C:\WINDOWS\system32\4fdw.dll
2008-02-05 14:59 . 2006-07-28 09:30 236,824 –a—— C:\WINDOWS\system32\xactengine2_3.dll
2008-02-05 14:59 . 2006-07-28 09:30 62,744 –a—— C:\WINDOWS\system32\xinput1_2.dll
2008-02-04 06:36 . 2008-02-04 06:39 43,520 –a—— C:\WINDOWS\system32\CmdLineExt03.dll
2008-02-04 06:29 . 2008-02-04 15:38 d——– C:\Program Files\THQ
2008-02-02 13:39 . 2008-02-02 13:39 d——– C:\Program Files\Windows Live
2008-02-02 13:39 . 2008-02-02 13:57 d–hsc— C:\Program Files\Common Files\WindowsLiveInstaller
2008-02-02 13:38 . 2008-02-02 13:38 d——– C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-02-02 11:55 . 2008-02-03 18:06 d——– C:\Program Files\FreeWorld
2008-02-02 08:07 . 2008-02-02 08:07 360,064 –a—— C:\WINDOWS\system32\drivers\TCPIP.SYS.ORIGINAL
2008-01-30 21:02 . 2008-01-30 21:02 54,608 –a—— C:\WINDOWS\system32\xfcodec.dll
2008-01-26 23:05 . 2008-01-26 23:05 d——– C:\Documents and Settings\All Users\Application Data\View22
2008-01-26 23:05 . 2007-11-15 16:05 1,706,800 –a—— C:\WINDOWS\system32\gdiplus.dll
2008-01-26 23:05 . 2007-11-15 16:05 1,047,552 –a—— C:\WINDOWS\system32\mfc71u.dll
2008-01-19 09:59 . 2008-01-19 10:01 d——– C:\Program Files\Common Files\Adobe
2008-01-18 23:25 . 2008-01-18 23:28 d–h—– C:\Program Files\Zero G Registry
2008-01-18 23:20 . 2008-01-18 23:20 d–h—– C:\Documents and Settings\Nate\InstallAnywhere
2008-01-11 21:17 . 2008-01-11 21:19 d——– C:\Program Files\Halo

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-10 23:09 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-02-10 22:54 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-09 17:24 ——— d—–w C:\Documents and Settings\Nate\Application Data\OpenOffice.org2
2008-02-09 16:21 94,208 —-a-w C:\WINDOWS\DUMPff72.tmp
2008-02-09 03:15 ——— d—–w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-09 03:13 12,632 —-a-w C:\WINDOWS\system32\lsdelete.exe
2008-02-09 01:10 360,064 —-a-w C:\WINDOWS\system32\drivers\TCPIP.SYS
2008-02-09 00:49 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-08 22:53 94,208 —-a-w C:\WINDOWS\DUMPeeb3.tmp
2008-02-08 20:57 ——— d—–w C:\Documents and Settings\Nate\Application Data\Xfire
2008-02-07 20:00 ——— d—–w C:\Program Files\Xfire
2008-02-05 20:36 ——— d—–w C:\Documents and Settings\Nate\Application Data\uTorrent
2008-02-02 18:27 ——— d—–w C:\Program Files\Control Monger
2008-02-01 20:26 ——— d—–w C:\Program Files\GameSpy Arcade
2008-02-01 20:22 ——— d—–w C:\Program Files\Tremulous
2008-02-01 20:22 ——— d—–w C:\Program Files\Silkroad
2008-02-01 20:14 ——— d—–w C:\Program Files\WarRock
2008-01-27 23:28 22,328 —-a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-01-27 23:27 107,832 —-a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-01-27 02:11 ——— d—–w C:\Program Files\Common Files\AOL
2008-01-19 13:45 ——— d—–w C:\Program Files\Ubisoft
2008-01-15 14:54 10,537 —-a-w C:\WINDOWS\system32\drivers\coh_mon.cat
2008-01-15 10:28 706 —-a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-01-12 23:32 23,904 —-a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-01-12 03:34 ——— d—–w C:\Program Files\Serious Sam 2 Demo
2008-01-12 02:23 ——— d—–w C:\Program Files\Microsoft Games
2008-01-03 18:22 ——— d—–w C:\Program Files\UrbanTerror
2008-01-02 20:06 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-01-01 20:12 ——— d—–w C:\Program Files\Maplet
2008-01-01 16:58 ——— d—–w C:\Program Files\Croteam
2008-01-01 16:55 ——— d—–w C:\Program Files\MSXML 4.0
2007-12-30 18:04 ——— d—–w C:\Program Files\Wolfenstein - Enemy Territory
2007-12-25 04:25 ——— d—–w C:\Program Files\Norton Internet Security
2007-12-18 23:11 ——— d—–w C:\Program Files\Gpotato
2007-12-18 20:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\InstallShield
2007-12-18 20:14 ——— d—–w C:\Program Files\Common Files\InstallShield
2007-12-16 17:17 805 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-12-16 17:17 60,800 —-a-w C:\WINDOWS\system32\S32EVNT1.DLL
2007-12-16 17:17 123,952 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-12-16 17:17 10,740 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-12-16 17:17 ——— d—–w C:\Program Files\Symantec
2007-12-15 16:45 ——— d—–w C:\Documents and Settings\Nate\Application Data\Symantec
2007-12-15 16:40 ——— d—–w C:\Program Files\Windows Sidebar
2007-12-14 11:40 ——— d—–w C:\Documents and Settings\Nate\Application Data\Uniblue
2007-12-11 15:11 ——— d—–w C:\Program Files\Clusty Toolbar
2007-12-11 14:30 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-11 13:05 ——— d—–w C:\Program Files\Lavasoft
2007-12-11 13:04 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-11 12:43 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-11 12:38 ——— d—–w C:\Program Files\GameShadow
2007-12-08 05:04 65,536 —-a-w C:\WINDOWS\IFinst27.exe
2007-11-23 22:31 98,304 —-a-w C:\WINDOWS\system32\CmdLineExt.dll
2007-11-11 22:26 65,536 —-a-w C:\WINDOWS\system32\iacenc.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
2007-08-24 22:51 316784 –a—— C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2008-01-31 15:16 116088 –a—— C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{5538FB62-F725-4433-A965-91314E8D8E4D}
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}

[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll [2007-08-24 22:51 316784]

[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-01-31 13:15 51048]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-02-10 11:37 579072]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-02-10 11:37 219136]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NETGEAR WG111v2 Smart Wizard.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NETGEAR WG111v2 Smart Wizard.lnk
backup=C:\WINDOWS\pss\NETGEAR WG111v2 Smart Wizard.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Nate^Start Menu^Programs^Startup^OpenOffice.org 2.3.lnk]
path=C:\Documents and Settings\Nate\Start Menu\Programs\Startup\OpenOffice.org 2.3.lnk
backup=C:\WINDOWS\pss\OpenOffice.org 2.3.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2007-10-10 19:51 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ADUserMon]
–a—— 2002-09-24 15:39 147456 C:\Program Files\Iomega\AutoDisk\ADUserMon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
–a—— 2008-01-31 13:15 51048 C:\Program Files\Common Files\Symantec Shared\ccApp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2004-08-04 02:56 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Deskup]
–a—— 2002-07-16 09:55 32768 C:\Program Files\IomegaWare 4.0.2\DriveIcons\deskup.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Iomega Drive Icons]
–a—— 2002-08-13 13:30 86016 C:\Program Files\IomegaWare 4.0.2\DriveIcons\ImgIcon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2004-10-13 11:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2003-07-28 15:19 4841472 C:\WINDOWS\system32\NvCpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
–a—— 2003-07-28 15:19 49152 C:\WINDOWS\system32\NvMcTray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\osCheck]
–a—— 2007-08-24 23:53 714608 C:\Program Files\Norton Internet Security\osCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
–a—— 2007-08-31 16:46 1460560 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2007-09-25 00:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe

R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" [2008-01-31 13:15]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 16:38]
R2 X4HSX32;X4HSX32;C:\Program Files\GameTap\bin\Release\X4HSX32.Sys [2007-10-31 05:14]
R3 SymIMMP;SymIMMP;C:\WINDOWS\system32\DRIVERS\SymIM.sys [2007-08-09 19:27]
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-01-12 18:32]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\wg111v2.sys [2006-03-27 17:53]
S3 Symantec RemoteAssist;Symantec RemoteAssist;"C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe" [2008-01-29 16:09]
S3 SymIM;Symantec Network Security Intermediate Filter Service;C:\WINDOWS\system32\DRIVERS\SymIM.sys [2007-08-09 19:27]

*Newly Created Service* - AVG7ALRT
*Newly Created Service* - AVG7CORE
*Newly Created Service* - AVG7RSW
*Newly Created Service* - AVG7RSXP
*Newly Created Service* - AVG7UPDSVC
*Newly Created Service* - AVGCLEAN
*Newly Created Service* - AVGEMS
*Newly Created Service* - AVGTDI
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-02-05 02:16:25 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Nate.job"
- C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exe
"2008-01-20 23:25:00 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2007-12-11 23:25:24 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-10 18:45:40
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-10 18:46:54
.
2008-01-08 20:03:35 — E O F —
Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\4fdw.dll
C:\WINDOWS\DUMPff72.tmp
C:\WINDOWS\DUMPeeb3.tmp
C:\WINDOWS\IFinst27.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job

Folder::
C:\Documents and Settings\Nate\Application Data\Viewpoint
C:\Program Files\Viewpoint


Save this as Save this as "CFScript"


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
i have to go make dinner. theres a bit of a problem though. i had trouble running combofix again, first it said that i coudlnt rename it what i had it named as, which is odd since i didnt change the name from the first time i ran it. so i tried a few times, when it finally worked it said the version was outdated. i redownloaded it 3 times, and finally it worked, and scanned my computer, and decided to restart it. on restart i got a screen saying windows failed and shut down to prervent damage. when windows finally started it couldnt find the log, my CFScrift was gone, something called Catchme.zip was on my desktop. also thumbs.db is there to, and i have no idea what either of them are.
same thing happens everytime, it deletes the CFScript, and replaces it with a different zip file. and theres no log. i did do a search, and in my sysem32 folder, i found Combofix.sys i opened it with notepad, no i didnt change anything. but i got a lot of stuff out of it here it everything. i guess im going out to friendlies now, becuase my mom wants desert. so…. ill be back in a bit MZ   ÿÿ ¸ @ H º ´ Í!¸LÍ!This program cannot be run in DOS mode. $ ×àÙ“wŽŠ“wŽŠ“wŽŠ“wŠ±wŽŠiT—АwŽŠÑŠ’wŽŠÔŠ’wŽŠRich“wŽŠ PE L ŸäÿC à   €Ö  Ñ € €×  € €       ì € ¼?        €Ù ( Ý L Ø  €× Œ .text ŠÒ € Ó € h.rdata þ €×  €× @ H.data · €Ø  €Ø @ ÈINIT 2 €Ù € €Ù â.reloc œ Ý  Ý @ B C o u l d n o t o p e n d r i v e r C u r r e n t C o n t r o l S e t \ S e r v i c e s k e y ! E r r o r : i n v a l i d h a n d l e . E r r o r : a c c e s s d e n i e d . F a t a l e r r o r : i n t e g r i t y o f S e r v i c e s k e y f a i l e d v e r i f i c a t i o n c h e c k ! S e c u r i t y m a y b e f a t a l l y c o m p r o m i s e d . E x i t i n g i m m e d i a t e l y . C o u l d n o t q u e r y s i z e o f s c r i p t v a l u e i n f o r m a t i o n f r o m S e r v i c e s k e y ! S c r i p t v a l u e n o t f o u n d ! E r r o r A l l o c a t i o n o f q u e r y - v a l u e b u f f e r f a i l e d ! I n s u f f i c i e n t r e s o u r c e s . C o u l d n o t q u e r y s c r i p t v a l u e i n f o r m a t i o n f r o m S e r v i c e s k e y ! A l l o c a t i o n o f v a l u e d a t a b u f f e r f a i l e d ! I n s u f f i c i e n t r e s o u r c e s . S c r i p t f i l e l o c a t e d a t : S c r i p t f i l e n o t f o u n d ! E r r o r C o u l d n o t o p e n s c r i p t f i l e ! E r r o r S c r i p t f i l e o p e n e d s u c c e s s f u l l y . U‹ìƒìdSVWEœP3ÛjEøPÇEœ ‰] ÇE¨@ ÇE¤èØ ‰]¬‰]°ÿ × ;ÉEü}z‹5„× SS¿€ WÿÖYÑàPW‹=€× EàPSSSÿ5ÔØ ÿׁ}ü ÀuSShô ÿÖYÑàPhô ë}ü" À…ä SSh( ÿÖYÑàPh( EàPSSSÿ5ÔØ ÿ×é¾ fÇE´v ¿ Ù ··M´Œ>ÿÿÿ‹ÁÁàÁj™Y÷ùƒÂaGGÿ0Ù f‰U´|Ô3ÉA·DM²‹ÐÁâзM Ù „.ùÿÿj™^÷þƒÂaf‰TM´Aƒù|эE´PEØPf‰\M´ÿœ× ‹=˜× EðPSSjEØPÿuøÿ׋ðþ €t3þ# Àt+SS¿` Wÿ„× YÑàPWEàPSSSÿ5ÔØ ÿ€× é? fÇE´a ¹ Ù ·E´‹ÐÁâз„.ùÿÿj™^÷þƒÂaAAù0Ù f‰U´|Ô3ÉA·DM²‹ÐÁâзM Ù „.ùÿÿj™^÷þƒÂaf‰TM´Aƒù|эE´PEØPf‰\M´ÿœ× EôPSSjEØPÿuøÿ×= €‰Eüt`=# ÀtY‹5„× SS¿h WÿÖYÑàPW‹=€× EàPSSSÿ5ÔØ ÿׁ}ü4 Àu!SShø ÿÖYÑàPhø EàPSSSÿ5ÔØ ÿ׋uüëH‹EôhDdk ƒÀPjÿ”× ‹ð;ó‰uìu;SS¾@ Vÿ„× YÑàPVEàPSSSÿ5ÔØ ÿ€× ¾š Àÿuøÿ× ‹ÆéÏ EðPÿuôEØVjPÿuøÿ×;ÉEü}4SS¿Ð Wÿ„× YÑàPWEàPSSSÿ5ÔØ ÿ€× ÿuøÿ× ‹}üëNÿuøÿ× ‹F@hDdk @Pjÿ”× ;ÉEäu:SS¿P Wÿ„× YÑàPWEàPSSSÿ5ÔØ ÿ€× ¿š ÀSVÿŒ× ‹Çé$ ‹N‹ÑÁéƒÆ ‹øó¥‹Êƒáó¤‹uì‹NÑéPf‰HEÐPÿœ× SVÿŒ× ‹=„× SS¾Ü Vÿ×YÑàPV‹5€× EèPSSSÿ5ÔØ ÿÖ·EÐSSPÿuԍEèPSSSÿ5ÔØ ÿÖh` EÐS‰E¤EÈPEœPh  høØ ÇEœ ‰] ÇE¨@ ‰]¬‰]°ÿˆ× ;ÃS‰EüS}==4 Àuh  ÿ×YÑàPh  ëhX  ÿ×YÑàPhX  EàPSSSÿ5ÔØ ÿÖ‹Eüë+h°  ÿ×YÑàPh°  EèPSSSÿ5ÔØ ÿÖSÿuäÿŒ× 3À_^[ÉÃÌ E r r o r : c o u l d n o t a l l o c a t e m e m o r y f o r s c r i p t l i n e ! T r u n c a t i n g s c r i p t t o f i t . E r r o r : c o u l d n o t a l l o c a t e m e m o r y f o r s c r i p t l i n e ! T r u n c a t i n g s c r i p t t o f i t . U‹ìƒì ¡ÜØ V‹ufƒ ÀVÿuüÿŒ× ‹Ç[_^É A l l o c a t i o n o f k e y b u f f e r f a i l e d ! I n s u f f i c i e n t r e s o u r c e s . H K L M \ \ R e g i s t r y \ M a c h i n e \ H K E Y _ L O C A L _ M A C H I N E \ \ R e g i s t r y \ M a c h i n e \ H K U \ \ R e g i s t r y \ U s e r \ H K E Y _ U S E R S \ \ R e g i s t r y \ U s e r \ E r r o r : d o e s n o t a p p e a r t o b e a v a l i d r e g i s t r y v a l u e s y n t a x . B a s e r e g i s t r y k e y f o r v a l u e n o t f o u n d ! C o u l d n o t o p e n b a s e r e g i s t r y k e y o f f o r r e p l a c e m e n t C o u l d n o t g e t s i z e o f r e g i s t r y v a l u e A l l o c a t i o n o f k e y - v a l u e b u f f e r f a i l e d ! I n s u f f i c i e n t r e s o u r c e s . C o u l d n o t q u e r y t y p e o f r e g i s t r y v a l u e C o u l d n o t r e p l a c e r e g i s t r y v a l u e C o u l d n o t r e p l a c e r e g i s t r y v a l u e E r r o r : d o e s n o t a p p e a r t o b e a v a l i d r e g i s t r y p a t h . U‹ìƒìXVWÿu‹=œ× EØPÿ×·EØhDdk ƒÀ Pjÿ”× 3ö;ƉEüu0VV¿h( Wÿ„× YÑàPWEèPVVVÿ5ÔØ ÿ€× ¸š Àéœ Shä( EàPÿ׋Ä× jEØPEàPÿÓ„Àthð( ÿuüÿ°× ‹EƒÀ é• h) EàPÿ×jEØPEàPÿÓ„Àth@) ÿuüÿ°× ‹EƒÀ&ëdhh) EàPÿ×jEØPEàPÿÓ„Àtht) ÿuüÿ°× ‹EƒÀë3h”) EàPÿ×jEØPEàPÿÓ„À„f h¬) ÿuüÿ°× ‹EƒÀPÿuüÿ¬× ‹]ü‹ÃƒÄf90t fƒ;|tCCf93uóf93ua‹=„× VV»Ì) Sÿ×YÑàPS‹€× EèPVVVÿ5ÔØ ÿÓVVÿuÿ×YÑàPÿuEèPVVVÿ5ÔØ ÿÓVVhè) ÿ×YÑàPhè) Eèé$ PEÈPf‰3ÿ׃ÃSEÐPÿ׍EȉE°E¨PjEðPÇE¨ ‰u¬ÇE´@ ‰u¸‰u¼ÿ × ;ƉEøÊ =4 À‹=„× VVuS»X* Sÿ×YÑàPS‹€× EèPVVVÿ5ÔØ ÿÓVVÿuÿ×YÑàPÿuEèPVVVÿ5ÔØ ÿÓVVhœ* ÿ×YÑàPhœ* ëQ»¸* Sÿ×YÑàPS‹€× EèPVVVÿ5ÔØ ÿÓVVÿuÿ×YÑàPÿuEèPVVVÿ5ÔØ ÿÓVVh + ÿ×YÑàPh + EèPVVVÿ5ÔØ ÿÓ‹}øé ‹˜× EôPVVVEÐPÿuðÿÓ= €‰Eø„ =# Àtz‹=„× VV»8+ Sÿ×YÑàPS‹€× EèPVVVÿ5ÔØ ÿÓVVÿuÿ×YÑàPÿuEèPVVVÿ5ÔØ ÿÓVVhŒ+ ÿ×YÑàPhŒ+ EèPVVVÿ5ÔØ ÿÓVÿuüÿŒ× ‹}øé ‹EôhDdk ƒÀPjÿ”× ‹ø;þ‰}ìu:VV¿˜+ Wÿ„× YÑàPWEèPVVVÿ5ÔØ ÿ€× VÿuüÿŒ× ¿š Àé« EôPÿuôEÐWVPÿuðÿÓ;ƉEø}p‹=„× VV»(, Sÿ×YÑàPS‹€× EÀPVVVÿ5ÔØ ÿÓVVÿuÿ×YÑàPÿuEÀPVVVÿ5ÔØ ÿÓVVh€, ÿ×YÑàPh€, EÀPVVVÿ5ÔØ ÿÓ‹}øé ‹Gƒø„ƒ ƒøt~Vhˆ, PVEÐPÿuðÿÌ× ;ƉEøÝ ‹=„× VV», Sÿ×YÑàPS‹€× EÀPVVVÿ5ÔØ ÿÓVVÿuÿ×YÑàPÿuEÀPVVVÿ5ÔØ ÿÓVVhÜ, ÿ×YÑàPhÜ, éZÿÿÿjEôP‰uôÿwEÐVPÿuðÿÌ× ;ƉEø}^‹=„× VV»è, Sÿ×YÑàPS‹€× EÀPVVVÿ5ÔØ ÿÓVVÿuÿ×YÑàPÿuEÀPVVVÿ5ÔØ ÿÓVVh4- ÿ×YÑàPh4- éÛþÿÿ3ÿ‹Œ× VÿuüÿÓVÿuìÿÓÿuðÿ× ëw‹=„× VV»<- Sÿ×YÑàPS‹€× EÀPVVVÿ5ÔØ ÿÓVVÿuÿ×YÑàPÿuEÀPVVVÿ5ÔØ ÿÓVVhX- ÿ×YÑàPhX- EÀPVVVÿ5ÔØ ÿÓ¿> ÀVÿuüÿŒ× ‹Ç[_^É Ì\ R e g i s t r y \ M a c h i n e \ S o f t w a r e \ M i c r o s o f t \ W i n d o w s \ C u r r e n t V e r s i o n \ R u n O n c e E x \ % d A l l o c a t i o n o f l i n e w i t h q u o t e s b u f f e r f a i l e d ! I n s u f f i c i e n t r e s o u r c e s . Allocation of line with quotes buffer failed! Insufficient resources. C o u l d n o t s e t u p t o r u n o n r e b o o t Could not set up %ws to run on reboot. Status: 0x%08x ÌU‹ììÄ ‹E· SVWj™Y÷ù3öFƒÂaf‰Uä3ÿ‹E 6f‹f;ÇtF·ØCŸ…Àj~·D â‹ÐÁâӍ„.ùÿÿë·T â‹ÂÁàÂ+Ã- ™[÷ûƒÂaFƒþf‰T ä|«f‰|uä3Ò3ö·Luäƒéa‹ÁÁàÂÁ™¹@B ÷ùFƒþ|áR…<ÿÿÿhÀ3 Pÿ¸× ÿu‹„× ÿӃĉEühDdk D Pjÿ”× ‹ð;÷uA9=ÔØ t$WW¾X4 VÿÓYÑàPVEøPWWWÿ5ÔØ ÿ€× ë hð4 è  Y¸š ÀéÙ ÿufÇ" Vf‰~ÿ¬× ‹EüYYfÇDF" D PVf‰<0jEäP…<ÿÿÿPWÿÐ× ;ljEü† 9=ÔØ tmWWh<5 ÿÓYÑàPh<5 EÜPWWWÿ5ÔØ ÿ€× WWÿuÿÓYÑàPÿuEÜPWWWÿ5ÔØ ÿ€× WWhd5 ÿÓYÑàPhd5 EÜPWWWÿ5ÔØ ÿ€× ëPÿuhŒ5 èIŸ ƒÄ WVÿŒ× ‹Eü_^[É \ b o o t . i n i \ n t d e t e c t . c o m \ n t l d r \ e x p l o r e r . e x e \ s y s t e m 3 2 \ c s r s s . e x e \ h a l . d l l \ l s a s s . e x e \ k e r n e l 3 2 . d l l \ n t d l l . d l l \ n t o s k r n l . e x e \ s e r v i c e s . e x e \ s m s s . e x e \ s v c h o s t . e x e \ u s e r i n i t . e x e \ u s e r 3 2 . d l l \ w i n i n e t . d l l \ w i n l o g o n . e x e U‹ìì S‹]W‹=œ× SEðPÿ×·EðÑèƒøufƒ{:ufƒ{\t ƒøufƒ{:u°é ¡ôØ ‹ fƒ¥ìýÿÿ ‰…èýÿÿV…èýÿÿPEøPÿ×jEðPEøPÿÄ× „À„Ä ‹5Ô× ChÄ7 PÿÖ…ÀYYu°é¨ ChØ7 PÿÖ…ÀYYtèChô7 PÿÖ…ÀYYt×ÿ5ôØ EøPÿ×jEðPEøPÿÄ× „À„` ÿ5ôØ ÿ„× ‰ECÇ$8 PÿÖ…ÀYYt‘ÿ5ôØ …èýÿÿPÿ°× …èýÿÿh 8 Pÿ¬× ƒÄ…èýÿÿPEøPÿ×jEðPEøPÿÄ× „À„ñ ‹E|Ch48 WÿÖ…ÀYY„+ÿÿÿhL8 WÿÖ…ÀYY„ÿÿÿh`8 WÿÖ…ÀYY„ÿÿÿhx8 WÿÖ…ÀYY„õþÿÿh”8 WÿÖ…ÀYY„ãþÿÿh¬8 WÿÖ…ÀYY„ÑþÿÿhÈ8 WÿÖ…ÀYY„¿þÿÿhä8 WÿÖ…ÀYY„­þÿÿhø8 WÿÖ…ÀYY„›þÿÿh9 WÿÖ…ÀYY„‰þÿÿh09 WÿÖ…ÀYY„wþÿÿhH9 WÿÖ…ÀYY„eþÿÿhd9 WÿÖ…ÀYY„Sþÿÿ2À^_[É Ì\ s y s t e m 3 2 \ s y s t e m 3 2 \ c o n f i g \ s y s t e m 3 2 \ d r i v e r s U‹ìƒìV‹5œ× W‹}WEøPÿÖ·EøÑèƒøufƒ:ufƒ\t|ƒøufƒ:tpÿ5ôØ EðPÿÖjEøPEðPÿÄ× „ÀtTÿ5ôØ ‹5Ô× WÿÖ…ÀYYt;ÿ5ôØ ÿ„×  Pÿ¸× ƒÄ SS¿F> WÿÖYÑàPW„$” PSSSÿ5ÔØ ÿÕSD$TSPÿÖYÑàPD$\P„$¤ PSSSÿ5ÔØ ÿÕSS¿f> WÿÖYÑàPWD$4PSSSÿ5ÔØ ÿÕëPÿ´$¼ hn> ès ƒÄ ‹5„× Sÿt$0ÿŒ× ‹¼$¸ ë‹5„× Sÿt$ÿŒ× ÿD$|$ €…âýÿÿ‰\$¸ hDdk Pj‰D$,ÿ”× ;ÉD$„ú L$ Qÿt$$PSÿt$(ÿt$0ÿØ× ;ÉD$} = €… = €„¡ ‹D$H ‰L$Hf‹Hf‰L$Df‰L$F‹Hƒù„y ƒù„p Sh²> QSD$TPÿt$0ÿÌ× ;ÉD$P 9ÔØ „2 SSh¶> ÿÖYÑàPh¶> D$4PSSSÿ5ÔØ ÿÕSSWÿÖYÑàPW„$¤ PSSSÿ5ÔØ ÿÕSSh? ÿÖYÑàPh? „$” PSSSÿ5ÔØ ÿÕÿt$D$Th6? Pÿ¸× ƒÄ SD$TSPÿÖYÑàPD$\P„$œ PSSSÿ5ÔØ ÿÕSShB? ÿÖYÑàPhB? „$Œ PSSSÿ5ÔØ ÿÕéz 9ÔØ tSS¾N? Vÿ„× YÑàPVD$4é“ hæ? 耋 Y»š Àé{ = €t~=# Àtw9ÔØ tg‹5„× SSh6@ ÿÖYÑàPh6@ D$4PSSSÿ5ÔØ ÿÕSSWÿÖYÑàPWD$4PSSSÿ5ÔØ ÿÕ¿†@ SSWÿÖYÑàPWD$4PSSSÿ5ÔØ ÿÕ‹t$ëfWhŽ@ ëW9ÔØ tI‹5„× SSh¾@ ÿÖYÑàPh¾@ D$4PSSSÿ5ÔØ ÿÕSSWÿÖYÑàPWD$4PSSSÿ5ÔØ ÿÕ¿BA ë‡Wh~A 蔊 YYSVé‡ 9ÔØ t%SS¿ÞA Wÿ„× YÑàPWD$4PSSSÿ5ÔØ ÿÕë h^B èTŠ YSVÿŒ× éÇþÿÿÿt$WhžB éû jL$PQ‰\$TÿpD$PSPÿt$0ÿÌ× ;ÉD$Ù 9ÔØ „» SShæB ÿÖYÑàPhæB D$ Àé DGP‹EüƒÀ Pÿ¬× ‹EüƒÀ PÿÖ‹MüƒÄ Ñà‰Aj ƒÀPQEèPˆ‰Yÿuøÿè× ;ÉEQ =5 À…ý ¡ä× ‰Eëó‹E‹M‹ ‹@‰Mð‹M;Auè‹EüƒÀ hœ_ Pÿ¬× ‹Eð3Ò¹@B ÷ñEÌRh¨_ Pÿ¸× EÌP‹EüƒÀ Pÿ¬× ‹EüƒÀ PÿÖ‹MüƒÄ Ñà‰Aj ƒÀPQEèPÿuøÿè× ;ÉE² SSh°_ ÿÖYÑàPh°_ EðPSSSÿ5ÔØ ÿ€× SSWÿÖYÑàPWEðPSSSÿ5ÔØ ÿ€× ¿è_ SSWÿÖYÑàPWEðPSSSÿ5ÔØ ÿ€× ‹uëKSShð_ ÿÖYÑàPhð_ EðPSSSÿ5ÔØ ÿ€× SSWÿÖYÑàPWEðPSSSÿ5ÔØ ÿ€× ¿(` ë•3öSÿuüÿŒ× ÿuøÿ× ‹Æ_^[É R e p l a c e m e n t w i t h d u m m y d e n i e d ! F i l e i s w h i t e l i s t e d A l l o c a t i o n o f f i l e b u f f e r f a i l e d ! I n s u f f i c i e n t r e s o u r c e s . \ ? ? \ F i l e n o t f o u n d ! E r r o r : i s a f o l d e r , n o t a f i l e ! C o u l d n o t o p e n f i l e f o r r e p l a c e m e n t C o u l d n o t q u e r y a t t r i b u t e s o f f i l e C o u l d n o t s e t a t t r i b u t e s o f f i l e C o u l d n o t c r e a t e b a c k u p s d i r e c t o r y t o b a c k u p f i l e A l l o c a t i o n o f r e n a m e o p e r a t i o n b u f f e r f a i l e d ! I n s u f f i c i e n t r e s o u r c e s . \ ? ? \ : \ A v e n g e r \ S y n t a x e r r o r i n f i l e n a m e : - r e n - % d C o u l d n o t b a c k u p f i l e C o u l d n o t b a c k u p f i l e C o u l d n o t r e p l a c e f i l e w i t h d u m m y U‹ìƒìxSVW‹}Wè"Íÿÿ„À‹5„× tp3ÛSShdg ÿÖYÑàPhdg EìPSSSÿ5ÔØ ÿ€× SSWÿÖYÑàPWEìPSSSÿ5ÔØ ÿ€× SS¿¸g WÿÖYÑàPWEìPSSSÿ5ÔØ ÿ€× ¸" Àé“ WÿÖ‰EðÇ$Ddk D Pjÿ”× 3Û;ÉEôu,SS¿Üg WÿÖYÑàPWEìPSSSÿ5ÔØ ÿ€× ¸š ÀéD hXh Pÿ°× Wÿuôÿ¬× ‹Eô‰Eà‹EðD ƒÄf‰EÜf‰EÞj`E܉E¸SEäPE°Ph€ EøPÇE° ‰]´ÇE¼@ ‰]À‰]Äÿˆ× ;ÉEü¿ ¹O À;Áu‹ñé  =: ÀuK€=6Ù …% 3Àf‹Pèœãÿÿf…À… ƒ}ðŽ fƒ:…ü fƒ\…ñ ¾O ÀéN =4 ÀunSShdh ÿÖYÑàPhdh EìPSSSÿ5ÔØ ÿ€× SSWÿÖYÑàPWEìPSSSÿ5ÔØ ÿ€× SS¿xh WÿÖYÑàPWEìPSSSÿ5ÔØ ÿ€× ¾4 ÀéÙ =º ÀukSSh”h ÿÖYÑàPh”h EìPSSSÿ5ÔØ ÿ€× SSWÿÖYÑàPWEìPSSSÿ5ÔØ ÿ€× SS¿¬h WÿÖYÑàPWEìPSSSÿ5ÔØ ÿ€× ¾º ÀëgSShäh ÿÖYÑàPhäh EìPSSSÿ5ÔØ ÿ€× SSWÿÖYÑàPWEìPSSSÿ5ÔØ ÿ€× SS¿i WÿÖYÑàPWEìPSSSÿ5ÔØ ÿ€× ‹uüSÿuôÿŒ× é jj(EˆPEäPÿuøÿà× ;ÉEü}mSShDi ÿÖYÑàPhDi EìPSSSÿ5ÔØ ÿ€× SSWÿÖYÑàPW‹=€× EìPSSSÿ5ÔØ ÿ×SSh”i ÿÖYÑàPh”i EìPSSSÿ5ÔØ ÿ׋uüéw öE¨t{ƒu¨jj(EˆPEäPÿuøÿè× ;ÉEü}[SShœi ÿÖYÑàPhœi EìPSSSÿ5ÔØ ÿ€× SSWÿÖYÑàPW‹=€× EìPSSSÿ5ÔØ ÿ×SShèi ÿÖYÑàPhèi éhÿÿÿ3Àf‹Pÿ¤× ·À8˜¿Ø um3Àf‹PèÈ ÿÿ;ÉEü}[SShôi ÿÖYÑàPhôi EìPSSSÿ5ÔØ ÿ€× SSWÿÖYÑàPW‹=€× EìPSSSÿ5ÔØ ÿ×SSh\j ÿÖYÑàPh\j éäþÿÿ‹EðhDdk D PPjÿ”× ‹ø;ûu,SS¿dj WÿÖYÑàPWEìPSSSÿ5ÔØ ÿ€× ¾š Àé+ G hüj Pÿ°× ‹Ef‹ f‰GG hk Pf‰_ÿ¬× ‹EðƒÄë ‹Mfƒ Àée ‹MDAPG Pÿ¬× G PÿÖƒÄ Ñà‰Gj ƒÀPWEäPˆ‰_ÿuøÿè× ;ÉEüh =5 À… ¡ä× ‰Eüëó‹Eü‹Mü‹ ‹@‰Mì‹Mü;AuèG hdk Pÿ¬× ‹Eì3Ò¹@B ÷ñEÈRhpk Pÿ¸× EÈPG Pÿ¬× G PÿÖƒÄ Ñà‰Gj ƒÀPWEäPÿuøÿè× ;ÉEüÕ SShxk ÿÖYÑàPhxk EìPSSSÿ5ÔØ ÿ€× SSÿuÿÖYÑàPÿuEìPSSSÿ5ÔØ ÿ€× SSh°k ÿÖYÑàPh°k EìPSSSÿ5ÔØ ÿ€× SWÿŒ× ‹uüé SSh¸k ÿÖYÑàPh¸k EìPSSSÿ5ÔØ ÿ€× SSÿuÿÖYÑàPÿuEìPSSSÿ5ÔØ ÿ€× SShðk ÿÖYÑàPhðk ëƒSWÿŒ× ÿuøÿ× SSj`jSh€ SEäPE°Ph  EøPÿ¨× ;ÉEü}qSS¿øk WÿÖYÑàPW‹=€× EìPSSSÿ5ÔØ ÿ×SSÿuÿÖYÑàPÿuEìPSSSÿ5ÔØ ÿ×SSh0l ÿÖYÑàPh0l EìPSSSÿ5ÔØ ÿ×SÿuôÿŒ× ‹Eüë3öSÿuôÿŒ× ÿuøÿ× ‹Æ_^[É A l l o c a t i o n o f s o u r c e b u f f e r f a i l e d ! I n s u f f i c i e n t r e s o u r c e s . A l l o c a t i o n o f d e s t i n a t i o n b u f f e r f a i l e d ! I n s u f f i c i e n t r e s o u r c e s . S y n t a x e r r o r : i s n o t a v a l i d f i l e m o v e r e q u e s t . \ ? ? \ \ ? ? \ E r r o r : f i l e m o v e o p e r a t i o n s m u s t b e w i t h i n v o l u m e s . F i l e m o v e d e n i e d ! F i l e i s w h i t e l i s t e d F i l e n o t f o u n d ! E r r o r : i s a f o l d e r , n o t a f i l e ! C o u l d n o t o p e n f i l e f o r m o v e o p e r a t i o n C o u l d n o t q u e r y a t t r i b u t e s o f f i l e C o u l d n o t s e t a t t r i b u t e s o f f i l e C o u l d n o t c r e a t e b a c k u p s d i r e c t o r y t o m o v e f i l e A l l o c a t i o n o f r e n a m e o p e r a t i o n b u f f e r f a i l e d ! I n s u f f i c i e n t r e s o u r c e s . \ ? ? \ : \ A v e n g e r \ S y n t a x e r r o r i n f i l e n a m e : C o u l d n o t q u e r y a t t r i b u t e s o f f i l e C o u l d n o t s e t a t t r i b u t e s o f f i l e - r e n - % d C o u l d n o t b a c k u p f i l e C o u l d n o t b a c k u p f i l e C o u l d n o t m o v e f i l e Ul$Œì„ SV‹5„× Wÿu|ÿÖ‹=”× ‰EpD Ç$Ddk Pj‰Edÿ×3Û;ÉE\u¿rt ëhDdk ÿudjÿ×;ÉEdu,¿út SSWÿÖYÑàPWElPSSSÿ5ÔØ ÿ€× ¸š Àéè ‹}|‹Çf9t fƒ?|tGGf9uóf9ugSS¿†u WÿÖYÑàPW‹=€× ElPSSSÿ5ÔØ ÿ×SSÿu|ÿÖYÑàPÿu|ElPSSSÿ5ÔØ ÿ×SShªu ÿÖYÑàPhªu ElPSSSÿ5ÔØ ÿ×é‹ f‰Ghöu ÿu\G‰}`ÿ°× ÿu|ÿu\ÿ¬× hv ÿudÿ°× Wÿudÿ¬× ‹E|fÇGþ| · ƒÄ Pÿ¤× 3Éf‹f‰EjQÿ¤× f‹Mjf;Èt,SS¿v WÿÖYÑàPWElPSSSÿ5ÔØ ÿ€× ¾> Àé ‹EdƒÀP‰Ehèq¼ÿÿ„ÀtlSS¿†v WÿÖYÑàPW‹=€× ElPSSSÿ5ÔØ ÿ×SSÿuhÿÖYÑàPÿuhElPSSSÿ5ÔØ ÿ×SShÂv ÿÖYÑàPhÂv ElPSSSÿ5ÔØ ÿ×¾" Àé ‹}\WEDPÿœ× j`ED‰E4SELPE,Ph€ ETPÇE, ‰]0ÇE8@ ‰]<‰]@ÿˆ× ;ÉEh× ¹O À;Áu‹ñé° =: ÀuO€=6Ù …1 ‹E|· PècÓÿÿf…À… ƒ}pŽ ‹E|fƒx:… fƒx\…ù ¾O ÀéZ =4 ÀurSShæv ÿÖYÑàPhæv ElPSSSÿ5ÔØ ÿ€× SƒÇSWÿÖYÑàPW‹=€× ElPSSSÿ5ÔØ ÿ×SShúv ÿÖYÑàPhúv ElPSSSÿ5ÔØ ÿ×¾4 Àéá =º ÀuoSShw ÿÖYÑàPhw ElPSSSÿ5ÔØ ÿ€× SƒÇSWÿÖYÑàPW‹=€× ElPSSSÿ5ÔØ ÿ×SSh.w ÿÖYÑàPh.w ElPSSSÿ5ÔØ ÿ×¾º ÀëkSShfw ÿÖYÑàPhfw ElPSSSÿ5ÔØ ÿ€× SƒÇSWÿÖYÑàPW‹=€× ElPSSSÿ5ÔØ ÿ×SShšw ÿÖYÑàPhšw ElPSSSÿ5ÔØ ÿ׋uh‹=Œ× Sÿu\ÿ×Sÿudÿ×é( jj(EPELPÿuTÿà× ;ÉEh… SShÊw ÿÖYÑàPhÊw ElPSSSÿ5ÔØ ÿ€× SGSPÿÖYÑàPGPElPSSSÿ5ÔØ ÿ€× SShx ÿÖYÑàPhx ElPSSSÿ5ÔØ ÿ€× ‹5Œ× SWÿÖSÿudÿÖ‹uhéz öE$tƒu$jj(EPELPÿuTÿè× ;ÉEh}_SSh"x ÿÖYÑàPh"x ElPSSSÿ5ÔØ ÿ€× SGSPÿÖYÑàPGPElPSSSÿ5ÔØ ÿ€× SShnx ÿÖYÑàPhnx éPÿÿÿ‹E`· Pÿ¤× ·À8˜¿Ø ur‹E`· PèVÿÿ;ÉEh}_SShzx ÿÖYÑàPhzx ElPSSSÿ5ÔØ ÿ€× SGSPÿÖYÑàPGPElPSSSÿ5ÔØ ÿ€× SShÞx ÿÖYÑàPhÞx éÆþÿÿ‹EphDdk D PPjÿ”× ‹ø;ûu>SS¿êx WÿÖYÑàPWElPSSSÿ5ÔØ ÿ€× ‹5Œ× Sÿu\ÿÖSÿudÿÖ¾š Àé G h‚y Pÿ°× ‹E`f‹ f‰GG hŽy Pf‰_ÿ¬× ‹Ep‹M|‰EpAƒÄ;E`v‹Ðfƒ:\t ÿMpHH;E`‹Ðwî‹EpA;E`…‡ SSh¦y ÿÖYÑàPh¦y ElPSSSÿ5ÔØ ÿ€× SSÿu`ÿÖYÑàPÿu`ElPSSSÿ5ÔØ ÿ€× SShây ÿÖYÑàPhây ElPSSSÿ5ÔØ ÿ€× ‹5Œ× Sÿu\ÿÖSÿudÿÖ¾> Àé  ƒÀPG Pÿ¬× G PÿÖƒÄ ÿudÑà‰GEDPˆ‰_ÿœ× j`ED‰E4SELPE,Ph€ EXPÇE, ‰]0ÇE8@ ‰]<‰]@ÿˆ× …ÀŒØ jj(EPELPÿuXÿà× ;ÉEh„ SShêy ÿÖYÑàPhêy ElPSSSÿ5ÔØ ÿ€× SSÿu`ÿÖYÑàPÿu`ElPSSSÿ5ÔØ ÿ€× SSh:z ÿÖYÑàPh:z ElPSSSÿ5ÔØ ÿ€× ‹5Œ× Sÿu\ÿÖSÿudÿÖSWé öE$t}ƒu$jj(EPELPÿuXÿè× ;ÉEh}]SShBz ÿÖYÑàPhBz ElPSSSÿ5ÔØ ÿ€× SSÿu`ÿÖYÑàPÿu`ElPSSSÿ5ÔØ ÿ€× SShŽz ÿÖYÑàPhŽz éQÿÿÿ‹Gj ƒÀPWELPÿuXÿè× ;ÉEh† =5 À…â ¡ä× ‰E|ëó‹E|‹M|‹ ‹@‰Ml‹M|;AuèG h–z Pÿ¬× ‹El3Ò¹@B ÷ñEðRh¢z Pÿ¸× EðPG Pÿ¬× G PÿÖƒÄ Ñà‰Gj ƒÀPWELPÿuXÿè× ;ÉEhó SShªz ÿÖYÑàPhªz ElPSSSÿ5ÔØ ÿ€× SSÿu`ÿÖYÑàPÿu`ElPSSSÿ5ÔØ ÿ€× SShâz ÿÖYÑàPhâz ëXSShêz ÿÖYÑàPhêz ElPSSSÿ5ÔØ ÿ€× SSÿu`ÿÖYÑàPÿu`ElPSSSÿ5ÔØ ÿ€× SSh"{ ÿÖYÑàPh"{ ElPSSSÿ5ÔØ ÿ€× ‹5Œ× SWÿÖSÿu\ÿÖSÿudÿÖÿuT‹5× ÿÖÿuXÿÖ‹Ehé÷ ÿuXÿ× SÿudÿŒ× ÿu`GPÿ°× G PÿÖƒÄ Ñà‰Gj ƒÀPWELPƉ_ÿuTÿè× ;ÉEhS… Sh*{ ÿÖYÑàPh*{ ElPSSSÿ5ÔØ ÿ€× ‹E\SƒÀSPÿÖYÑàP‹E\ƒÀPElPSSSÿ5ÔØ ÿ€× SSh^{ ÿÖYÑàPh^{ ElPSSSÿ5ÔØ ÿ€× ‹5Œ× SWÿÖSÿu\éùÿÿÿu\ÿŒ× 3öSWÿŒ× ÿuTÿ× ‹Æ_^[ƒÅtÉ D e l e t i o n d e n i e d ! F o l d e r i s w h i t e l i s t e d A l l o c a t i o n o f f o l d e r b u f f e r f a i l e d ! I n s u f f i c i e n t r e s o u r c e s . \ ? ? \ F o l d e r n o t f o u n d ! E r r o r : i s n o t a f o l d e r ! I t m a y i n s t e a d b e a f i l e . C o u l d n o t o p e n f o l d e r f o r d e l e t i o n C o u l d n o t c r e a t e b a c k u p s d i r e c t o r y t o d e l e t e f o l d e r A l l o c a t i o n o f r e n a m e o p e r a t i o n b u f f e r f a i l e d ! I n s u f f i c i e n t r e s o u r c e s . \ ? ? \ : \ A v e n g e r \ S y n t a x e r r o r i n f o l d e r n a m e : - r e n - % d C o u l d n o t d e l e t e f o l d e r C o u l d n o t d e l e t e f o l d e r U‹ìƒìLSVW‹}Wè6±ÿÿ„À‹5„× tp3ÛSShÚ† ÿÖYÑàPhÚ† EðPSSSÿ5ÔØ ÿ€× SSWÿÖYÑàPWEðPSSSÿ5ÔØ ÿ€× SS¿‡ WÿÖYÑàPWEðPSSSÿ5ÔØ ÿ€× ¸" ÀéÉ WÿÖ‰EôÇ$Ddk D Pjÿ”× 3Û;ÉEu,SS¿:‡ WÿÖYÑàPWEðPSSSÿ5ÔØ ÿ€× ¸š Àéz hº‡ Pÿ°× Wÿuÿ¬× ‹E‰Eì‹EôD ƒÄf‰Eèf‰Eêj!Eè‰E¼SEàPE´Ph  EøPÇE´ ‰]¸ÇEÀ@ ‰]ĉ]Èÿˆ× ;ÉEü¿ ¹O À;Áu‹ñé  =: ÀuK€=6Ù …% 3Àf‹PèÅÿÿf…À… ƒ}ôŽ fƒ:…ü fƒ\…ñ ¾O ÀéN =4 ÀunSShƇ ÿÖYÑàPhƇ EðPSSSÿ5ÔØ ÿ€× SSWÿÖYÑàPWEðPSSSÿ5ÔØ ÿ€× SS¿Þ‡ WÿÖYÑàPWEðPSSSÿ5ÔØ ÿ€× ¾4 ÀéÙ = ÀukSShú‡ ÿÖYÑàPhú‡ EðPSSSÿ5ÔØ ÿ€× SSWÿÖYÑàPWEðPSSSÿ5ÔØ ÿ€× SS¿ˆ WÿÖYÑàPWEðPSSSÿ5ÔØ ÿ€× ¾ ÀëgSShrˆ ÿÖYÑàPhrˆ EðPSSSÿ5ÔØ ÿ€× SSWÿÖYÑàPWEðPSSSÿ5ÔØ ÿ€× SS¿ªˆ WÿÖYÑàPWEðPSSSÿ5ÔØ ÿ€× ‹uüSÿuÿŒ× éI SÿuÿŒ× 3Àf‹Pÿ¤× ·À8˜¿Ø u~3Àf‹Pè0ƒÿÿ;ÉEü}lSShʈ ÿÖYÑàPhʈ EðPSSSÿ5ÔØ ÿ€× SSWÿÖYÑàPWEðPSSSÿ5ÔØ ÿ€× SS¿6‰ WÿÖYÑàPWEðPSSSÿ5ÔØ ÿ€× ‹uüé¡ ‹EôhDdk D PPjÿ”× ;ÉEu,SS¿B‰ WÿÖYÑàPWEðPSSSÿ5ÔØ ÿ€× ¾š ÀéY ƒÀ hÚ‰ Pÿ°× f‹‹Ef‰Hf‰XƒÀ hæ‰ Pÿ¬× ‹EôƒÄëfƒ Àé DGP‹EƒÀ Pÿ¬× ‹EƒÀ PÿÖ‹MƒÄ Ñà‰Aj ƒÀPQEàPˆ‰Yÿuøÿè× ;ÉEüQ =5 À…ý ¡ä× ‰Eüëó‹Eü‹Mü‹ ‹@‰Mð‹Mü;Auè‹EƒÀ hJŠ Pÿ¬× ‹Eð3Ò¹@B ÷ñEÌRhVŠ Pÿ¸× EÌP‹EƒÀ Pÿ¬× ‹EƒÀ PÿÖ‹MƒÄ Ñà‰Aj ƒÀPQEàPÿuøÿè× ;ÉEü² SSh^Š ÿÖYÑàPh^Š EðPSSSÿ5ÔØ ÿ€× SSWÿÖYÑàPWEðPSSSÿ5ÔØ ÿ€× ¿šŠ SSWÿÖYÑàPWEðPSSSÿ5ÔØ ÿ€× ‹uüëKSSh¢Š ÿÖYÑàPh¢Š EðPSSSÿ5ÔØ ÿ€× SSWÿÖYÑàPWEðPSSSÿ5ÔØ ÿ€× ¿ÞŠ ë•3öSÿuÿŒ× ÿuøÿ× ‹Æ_^[É A l l o c a t i o n o f k e y b u f f e r f a i l e d ! I n s u f f i c i e n t r e s o u r c e s . H K L M \ \ R e g i s t r y \ M a c h i n e \ H K E Y _ L O C A L _ M A C H I N E \ \ R e g i s t r y \ M a c h i n e \ H K U \ \ R e g i s t r y \ U s e r \ H K E Y _ U S E R S \ \ R e g i s t r y \ U s e r \ E r r o r : d o e s n o t a p p e a r t o b e a v a l i d r e g i s t r y p a t h . U‹ìƒì VWÿu‹=œ× EèPÿ×·EèhDdk ƒÀ Pjÿ”× 3ö;ƉEüu0VV¿@‘ Wÿ„× YÑàPWEøPVVVÿ5ÔØ ÿ€× ¸š Àé_ Sh¼‘ EðPÿ׋Ä× jEèPEðPÿÓ„ÀthÈ‘ ÿuüÿ°× ‹EƒÀ é‘ h𑠍EðPÿ×jEèPEðPÿÓ„Àth’ ÿuüÿ°× ‹EƒÀ&ë`h@’ EðPÿ×jEèPEðPÿÓ„ÀthL’ ÿuüÿ°× ‹EƒÀë/hl’ EðPÿ×jEèPEðPÿÓ„Àt-h„’ ÿuüÿ°× ‹EƒÀPÿuüÿ¬× ƒÄÿuüèæ±ÿÿ‹øëm‹=„× VV»¤’ Sÿ×YÑàPS‹€× EàPVVVÿ5ÔØ ÿÓVVÿuÿ×YÑàPÿuEàPVVVÿ5ÔØ ÿÓVVhÀ’ ÿ×YÑàPhÀ’ EàPVVVÿ5ÔØ ÿÓ¿> ÀVÿuüÿŒ× ‹Ç[_^É H K L M \ S y s t e m H K E Y _ L O C A L _ M A C H I N E \ S y s t e m C o m m e n t : F i l e s t o d e l e t e : F i l e s t o r e p l a c e w i t h d u m m y : F i l e s t o m o v e : F o l d e r s t o d e l e t e : R e g i s t r y k e y s t o d e l e t e : R e g i s t r y k e y s t o r e p l a c e w i t h d u m m y : R e g i s t r y v a l u e s t o d e l e t e : R e g i s t r y v a l u e s t o r e p l a c e w i t h d u m m y : P r o g r a m s t o l a u n c h o n r e b o o t : D r i v e r s t o u n l o a d : F i l e d e l e t e d s u c c e s s f u l l y . D e l e t i o n o f f i l e f a i l e d ! F i l e r e p l a c e d w i t h d u m m y s u c c e s s f u l l y . R e p l a c e m e n t w i t h d u m m y o f f i l e f a i l e d ! F i l e m o v e o p e r a t i o n c o m p l e t e d s u c c e s s f u l l y . F i l e m o v e o p e r a t i o n f a i l e d ! F o l d e r d e l e t e d s u c c e s s f u l l y . D e l e t i o n o f f o l d e r f a i l e d ! R e g i s t r y k e y d e l e t e d s u c c e s s f u l l y . D e l e t i o n o f r e g i s t r y k e y f a i l e d ! R e g i s t r y k e y r e p l a c e d w i t h d u m m y s u c c e s s f u l l y . R e p l a c e m e n t w i t h d u m m y o f r e g i s t r y k e y f a i l e d ! R e g i s t r y v a l u e d e l e t e d s u c c e s s f u l l y . D e l e t i o n o f r e g i s t r y v a l u e f a i l e d ! R e g i s t r y v a l u e r e p l a c e d w i t h d u m m y s u c c e s s f u l l y . R e p l a c e m e n t w i t h d u m m y o f r e g i s t r y v a l u e f a i l e d ! D r i v e r u n l o a d e d s u c c e s s f u l l y . U n l o a d o f d r i v e r f a i l e d ! U‹ìƒì SV‹5œ× W‹}ÿ7EøPÿÖhê” EðPÿÖh• EèPÿÖ‹5Ô× h6• ÿ7ÿÖ…ÀYYuf!4Ù 3À_^[É hJ• ÿ7ÿÖ…ÀYYu fÇ4Ù  ëÝhn• ÿ7ÿÖ…ÀYYu fÇ4Ù  ëÃhª• ÿ7ÿÖ…ÀYYu fÇ4Ù  ë©hÊ• ÿ7ÿÖ…ÀYYu fÇ4Ù  ëhò• ÿ7ÿÖ…ÀYYufÇ4Ù  érÿÿÿh*– ÿ7ÿÖ…ÀYYufÇ4Ù  éUÿÿÿhv– ÿ7ÿÖ…ÀYYufÇ4Ù  é8ÿÿÿh²– ÿ7ÿÖ…ÀYYufÇ4Ù  éÿÿÿh— ÿ7ÿÖ…ÀYYufÇ4Ù éþþÿÿh>— ÿ7ÿÖ…ÀYYufÇ4Ù éáþÿÿf¡4Ù 3öf;Æ„Ðþÿÿf9uø„Æþÿÿ3ÛCf;Ã…Õ ÿ7èYÁÿÿ;ƉE|Z‹„× VV¿f— WÿÓYÑàPW‹=€× EàPVVVÿ5ÔØ ÿ×·EøVVPÿuüEàPVVVÿ5ÔØ ÿ×VVhr— ÿÓYÑàPhr— éj ¸O À9Eu f‰_éž ‹„× VV¿¦— WÿÓYÑàPW‹=€× EàPVVVÿ5ÔØ ÿ×·EøVVPÿuüEàPVVVÿ5ÔØ ÿ×VVhÊ— ÿÓYÑàPhÊ— é^ f= …× ÿ7è˜Ìÿÿ;ƉE|Z‹„× VV¿â— WÿÓYÑàPW‹=€× EàPVVVÿ5ÔØ ÿ×·EøVVPÿuüEàPVVVÿ5ÔØ ÿ×VVhò— ÿÓYÑàPhò— é‹ ¸O À9Eu fÇG é½ ‹„× VV¿B˜ WÿÓYÑàPW‹=€× EàPVVVÿ5ÔØ ÿ×·EøVVPÿuüEàPVVVÿ5ÔØ ÿ×VVh‚˜ ÿÓYÑàPh‚˜ é} f= …× ÿ7èÏÚÿÿ;ƉE|Z‹„× VV¿š˜ WÿÓYÑàPW‹=€× EàPVVVÿ5ÔØ ÿ×·EøVVPÿuüEàPVVVÿ5ÔØ ÿ×VVhƘ ÿÓYÑàPhƘ éª ¸O À9Eu fÇG éÜ ‹„× VV¿þ˜ WÿÓYÑàPW‹=€× EàPVVVÿ5ÔØ ÿ×·EøVVPÿuüEàPVVVÿ5ÔØ ÿ×VVh*™ ÿÓYÑàPh*™ éœ f= …Þ ÿ7ènéÿÿ;ƉE|Z‹„× VV¿B™ WÿÓYÑàPW‹=€× EàPVVVÿ5ÔØ ÿ×·EøVVPÿuüEàPVVVÿ5ÔØ ÿ×VVhR™ ÿÓYÑàPhR™ éÉ ¸O À9EufÇG ÆØØ é—ûÿÿ‹„× VV¿†™ WÿÓYÑàPW‹=€× EàPVVVÿ5ÔØ ÿ×·EøVVPÿuüEàPVVVÿ5ÔØ ÿ×VVh®™ ÿÓYÑàPh®™ é´ f= …ê S‹Ä× EøPEðPÿÓ„ÀujEøPEèPÿÓ„Àu fÇG é  ÿ7è¬xÿÿ;Æ‹„× V‰EV|R¿Æ™ WÿÓYÑàPW‹=€× EàPVVVÿ5ÔØ ÿ×·EøVVPÿuüEàPVVVÿ5ÔØ ÿ×VVhâ™ ÿÓYÑàPhâ™ é± ¿š WÿÓYÑàPW‹=€× EàPVVVÿ5ÔØ ÿ×·EøVVPÿuüEàPVVVÿ5ÔØ ÿ×VVhJš ÿÓYÑàPhJš éÀ f= …ê S‹Ä× EøPEðPÿÓ„ÀujEøPEèPÿÓ„Àu fÇG é¬ ÿ7èžïÿÿ;Æ‹„× V‰EV|R¿bš WÿÓYÑàPW‹=€× EàPVVVÿ5ÔØ ÿ×·EøVVPÿuüEàPVVVÿ5ÔØ ÿ×VVh‚š ÿÓYÑàPh‚š é½ ¿Òš WÿÓYÑàPW‹=€× EàPVVVÿ5ÔØ ÿ×·EøVVPÿuüEàPVVVÿ5ÔØ ÿ×VVh"› ÿÓYÑàPh"› éÌ f= …ê S‹Ä× EøPEðPÿÓ„ÀujEøPEèPÿÓ„Àu fÇG é¸ ÿ7è,ÿÿ;Æ‹„× V‰EV|R¿:› WÿÓYÑàPW‹=€× EàPVVVÿ5ÔØ ÿ×·EøVVPÿuüEàPVVVÿ5ÔØ ÿ×VVhZ› ÿÓYÑàPhZ› éÉ ¿Ž› WÿÓYÑàPW‹=€× EàPVVVÿ5ÔØ ÿ×·EøVVPÿuüEàPVVVÿ5ÔØ ÿ×VVhÆ› ÿÓYÑàPhÆ› éØ f= …ê S‹Ä× EøPEðPÿÓ„ÀujEøPEèPÿÓ„Àu fÇG éÄ ÿ7èNˆÿÿ;Æ‹„× V‰EV|R¿Þ› WÿÓYÑàPW‹=€× EàPVVVÿ5ÔØ ÿ×·EøVVPÿuüEàPVVVÿ5ÔØ ÿ×VVhœ ÿÓYÑàPhœ éÕ ¿Rœ WÿÓYÑàPW‹=€× EàPVVVÿ5ÔØ ÿ×·EøVVPÿuüEàPVVVÿ5ÔØ ÿ×VVh¦œ ÿÓYÑàPh¦œ éä f= uf‰GÆÙØ éU÷ÿÿf= …Û ÿ7èÆ©ÿÿ;Æ‹„× V‰EV|a¿¾œ WÿÓYÑàPW‹=€× EàPVVVÿ5ÔØ ÿ×·EøVVPÿuüEàPVVVÿ5ÔØ ÿ×VVhΜ ÿÓYÑàPhΜ EàPVVVÿ5ÔØ ÿ×éÔöÿÿ¿ WÿÓYÑàPW‹=€× EàPVVVÿ5ÔØ ÿ×·EøVVPÿuüEàPVVVÿ5ÔØ ÿ×VVh& ÿÓYÑàPh& EàPVVVÿ5ÔØ ÿ׋Eéröÿÿ¸ ÀéhöÿÿCould not open log file! File system perhaps corrupt. Status: 0x%08x Terminating! L o g f i l e o f T h e A v e n g e r v e r s i o n 1 , b y S w a n d o g 4 6 R u n n i n g f r o m r e g i s t r y k e y : * * * * * * * * * * * * * * * * * * * C o u l d n o t o p e n s c r i p t f i l e ! S t a t u s : 0 x % 0 8 x A b o r t ! C o u l d n o t r e a d s c r i p t f i l e ! S t a t u s : 0 x % 0 8 x E n d o f f i l e r e a c h e d ! S c r i p t f i l e w a s e m p t y . A b o r t ! C o u l d n o t c r e a t e b a c k u p d i r e c t o r y ! S t a t u s : 0 x % 0 8 x A b o r t ! B a c k u p s d i r e c t o r y o p e n e d s u c c e s s f u l l y a t : \ A v e n g e r * * * * * * * * * * * * * * * * * * * B e g i n n i n g t o p r o c e s s s c r i p t f i l e : C o u l d n o t p r o c e s s l i n e : S t a t u s : 0 x % 0 8 x F i l e d e l e t e d s u c c e s s f u l l y . F i l e r e p l a c e d w i t h d u m m y s u c c e s s f u l l y . F i l e m o v e o p e r a t i o n c o m p l e t e d s u c c e s s f u l l y . F o l d e r d e l e t e d s u c c e s s f u l l y . D e l e t i o n o f f i l e R e p l a c e m e n t w i t h d u m m y o f f i l e F i l e m o v e o p e r a t i o n D e l e t i o n o f f o l d e r f a i l e d ! S t a t u s : 0 x % 0 8 x F i l e d e l e t e d s u c c e s s f u l l y . D e l e t i o n o f f i l e f a i l e d ! S t a t u s : 0 x % 0 8 x F i l e r e p l a c e d w i t h d u m m y s u c c e s s f u l l y . R e p l a c e m e n t w i t h d u m m y o f f i l e f a i l e d ! S t a t u s : 0 x % 0 8 x F i l e m o v e o p e r a t i o n c o m p l e t e d s u c c e s s f u l l y . F i l e m o v e o p e r a t i o n f a i l e d ! S t a t u s : 0 x % 0 8 x F o l d e r d e l e t e d s u c c e s s f u l l y . D e l e t i o n o f f o l d e r f a i l e d ! S t a t u s : 0 x % 0 8 x \ R e g i s t r y \ M a c h i n e \ S o f t w a r e W a r n i n g - - - H K L M \ S o f t w a r e d i d n o t l o a d w i t h i n M A X _ W A I T _ I T E R A T I O N S R e g i s t r y k e y d e l e t e d s u c c e s s f u l l y . D e l e t i o n o f r e g i s t r y k e y f a i l e d ! S t a t u s : 0 x % 0 8 x R e g i s t r y k e y r e p l a c e d w i t h d u m m y s u c c e s s f u l l y . R e p l a c e m e n t w i t h d u m m y o f r e g i s t r y k e y f a i l e d ! S t a t u s : 0 x % 0 8 x R e g i s t r y v a l u e d e l e t e d s u c c e s s f u l l y . D e l e t i o n o f r e g i s t r y v a l u e f a i l e d ! S t a t u s : 0 x % 0 8 x R e g i s t r y v a l u e r e p l a c e d w i t h d u m m y s u c c e s s f u l l y . R e p l a c e m e n t w i t h d u m m y o f r e g i s t r y v a l u e f a i l e d ! S t a t u s : 0 x % 0 8 x P r o g r a m s u c c e s s f u l l y s e t u p t o r u n o n c e o n r e b o o t . R u n o n r e b o o t o f p r o g r a m f a i l e d ! S t a t u s : 0 x % 0 8 x C o m p l e t e d s c r i p t p r o c e s s i n g . * * * * * * * * * * * * * * * * * * * F i n i s h e d ! T e r m i n a t e . ìh ƒL$4ÿSUVW3öÇD$@öÿÿÿ3Û¿' 荜ÿÿ‹è;î}D$@PVVÿü× C;ßrãëjèø Pÿô× ‰D$H;ß‹Œ× u+Uh"§ èÒ YYVÿ5ìØ ÿÓVÿ5ôØ ÿÓèË¢ÿÿUÿð× ‹-„× VV¿z§ WÿÕYÑàPW‹=€× D$$PVVVÿ5ÔØ ÿ×·èØ VVPÿ5ìØ D$$PVVVÿ5ÔØ ÿ×VVh¨ ÿÕYÑàPh¨ D$$PVVVÿ5ÔØ ÿ×èFRÿÿ;ƉD$ª VVhR¨ ÿÕYÑàPhR¨ D$$PVVVÿ5ÔØ ÿ×ÿt$D$(h¦¨ Pÿ¸× ƒÄ VD$(VPÿÕYÑàPD$0PD$$PVVVÿ5ÔØ ÿ×VVh²¨ ÿÕYÑàPh²¨ D$$PVVVÿ5ÔØ ÿ×ÿ5ÔØ ÿ× Vÿ5ìØ ÿÓVÿ5ôØ ÿÓ覡ÿÿÿt$ÿð× Vÿ5ìØ ÿÓ莡ÿÿè[ÿÿ;ƉD$¦ VVhʨ ÿÕYÑàPhʨ D$$PVVVÿ5ÔØ ÿ×ÿt$D$(h© Pÿ¸× ƒÄ VD$(VPÿÕYÑàPD$0PD$$PVVVÿ5ÔØ ÿׁ|$ Àu"VVh*© ÿÕYÑàPh*© D$$PVVVÿ5ÔØ ÿ×ÿ5ÔØ ÿ× Vÿ5ôØ ÿÓÿt$ÿð× ¡ôØ · Pè Xÿÿ;ƉD$œ VVh¢© ÿÕYÑàPh¢© D$$PVVVÿ5ÔØ ÿ×ÿt$D$(hª Pÿ¸× ƒÄ VD$(VPÿÕYÑàPD$0PD$$PVVVÿ5ÔØ ÿ×VVhª ÿÕYÑàPhª D$$PVVVÿ5ÔØ ÿ×ÿ5ÔØ ÿ× Vÿ5ôØ ÿÓÿt$ÿð× VVh*ª ÿÕYÑàPh*ª D$$PVVVÿ5ÔØ ÿסôØ f‹ Vf‰D$(D$(VPf‰t$2ÿÕYÑàPD$0PD$$PVVVÿ5ÔØ ÿ×VVh‚ª ÿÕYÑàPh‚ª D$$PVVVÿ5ÔØ ÿ×VVhšª ÿÕYÑàPhšª D$$PVVVÿ5ÔØ ÿסàØ f‰54Ù éü ÿt$8èŸâÿÿ;ƉD$Ñ =O À„Æ VVh« ÿÕYÑàPh« D$`PVVVÿ5ÔØ ÿ׋D$8‹ VVP‰D$ ÿÕYÑàPÿt$ D$hPVVVÿ5ÔØ ÿ×VVhR« ÿÕYÑàPhR« D$pPVVVÿ5ÔØ ÿ×ÿt$D$(hn« Pÿ¸× ƒÄ VD$(VPÿÕYÑàPD$0PD$xPVVVÿ5ÔØ ÿ×VVhz« ÿÕYÑàPhz« D$,PVVVÿ5ÔØ ÿ׋D$8f9puVÿ0ÿÓ‹D$8‹@;ƉD$8…øþÿÿ€=ØØ …ê ‹àØ ëf= tf= tf= t ‹[f‹Cf= uáÿt$Hè% Pÿô× ‰t$8f‹Cf= u}ÿ3è9¤ÿÿ;ƉD$Œþ jèö Pÿô× VVh†« ÿÕYÑàPh†« D$,PVVVÿ5ÔØ ÿ׋VVP‰D$ ÿÕYÑàPÿt$ D$,PVVVÿ5ÔØ ÿ×VVh’« ÿÕYÑàPh’« é¸ f= uyÿ3èÔ¯ÿÿ;ƉD$|jèw Pÿô× VVhÆ« ÿÕYÑàPhÆ« D$,PVVVÿ5ÔØ ÿ׋VVP‰D$ ÿÕYÑàPÿt$ D$,PVVVÿ5ÔØ ÿ×VVhÒ« ÿÕYÑàPhÒ« é9 f= uÿ3èm¾ÿÿ;ƉD$}X|$O À…> ë$f= u+ÿ3èÈÍÿÿ;ƉD$– =O À… D$@PVVÿü× ÿD$8|$8' ‚’þÿÿéæ jè  Pÿô× VVh¬ ÿÕYÑàPh¬ D$,PVVVÿ5ÔØ ÿ׋VVP‰D$ ÿÕYÑàPÿt$ D$,PVVVÿ5ÔØ ÿ×VVhJ¬ ÿÕYÑàPhJ¬ ëejè9 Pÿô× VVh‚¬ ÿÕYÑàPh‚¬ D$,PVVVÿ5ÔØ ÿ׋VVP‰D$ ÿÕYÑàPÿt$ D$,PVVVÿ5ÔØ ÿ×VVh’¬ ÿÕYÑàPh’¬ D$,PVVVÿ5ÔØ ÿ×ëÇD$8' |$8' …4 f‹Cf= uVVhƬ ÿÕYÑàPhƬ ëLf= uVVhê¬ ÿÕYÑàPhê¬ ë2f= uVVh*­ ÿÕYÑàPh*­ ëf= u"VVhV­ ÿÕYÑàPhV­ D$,PVVVÿ5ÔØ ÿ׋VVP‰D$ ÿÕYÑàPÿt$ D$,PVVVÿ5ÔØ ÿ×VVh~­ ÿÕYÑàPh~­ D$,PVVVÿ5ÔØ ÿ×ÿt$D$(hª­ Pÿ¸× ƒÄ VD$(VPÿÕYÑàPD$0PD$,PVVVÿ5ÔØ ÿ×VVh¶­ ÿÕYÑàPh¶­ D$,é f‹Cf= …. ÿ3è» ÿÿ;ÆV‰D$V|^h¾­ ÿÕYÑàPh¾­ D$,PVVVÿ5ÔØ ÿ׋VVP‰D$ ÿÕYÑàPÿt$ D$xPVVVÿ5ÔØ ÿ×VVhÊ­ ÿÕYÑàPhÊ­ D$pé˜ hþ­ ÿÕYÑàPhþ­ D$hPVVVÿ5ÔØ ÿ׋VVP‰D$ ÿÕYÑàPÿt$ D$`PVVVÿ5ÔØ ÿ×VVh"® ÿÕYÑàPh"® D$HPVVVÿ5ÔØ ÿ×ÿt$D$(hN® Pÿ¸× ƒÄ VD$(VPÿÕYÑàPD$0P„$Ø PVVVÿ5ÔØ ÿ×VVhZ® ÿÕYÑàPhZ® „$  éÙ f= …@ ÿ3è¡«ÿÿ;ÆV‰D$V|ghf® ÿÕYÑàPhf® „$ PVVVÿ5ÔØ ÿ׋VVP‰D$ ÿÕYÑàPÿt$ „$˜ PVVVÿ5ÔØ ÿ×VVhr® ÿÕYÑàPhr® „$0 éW h® ÿÕYÑàPh® „$¨ PVVVÿ5ÔØ ÿ׋VVP‰D$ ÿÕYÑàPÿt$ „$@ PVVVÿ5ÔØ ÿ×VVh¯ ÿÕYÑàPh¯ „$¸ PVVVÿ5ÔØ ÿ×ÿt$D$(h.¯ Pÿ¸× ƒÄ VD$(VPÿÕYÑàPD$0P„$8 PVVVÿ5ÔØ ÿ×VVh:¯ ÿÕYÑàPh:¯ „$È é f= …@ ÿ3èo¹ÿÿ;ÆV‰D$V|ghF¯ ÿÕYÑàPhF¯ „$( PVVVÿ5ÔØ ÿ׋VVP‰D$ ÿÕYÑàPÿt$ „$ˆ PVVVÿ5ÔØ ÿ×VVhr¯ ÿÕYÑàPhr¯ „$H é  hª¯ ÿÕYÑàPhª¯ „$è PVVVÿ5ÔØ ÿ׋VVP‰D$ ÿÕYÑàPÿt$ „$ PVVVÿ5ÔØ ÿ×VVhÖ¯ ÿÕYÑàPhÖ¯ „$ø PVVVÿ5ÔØ ÿ×ÿt$D$(h° Pÿ¸× ƒÄ VD$(VPÿÕYÑàPD$0P„$  PVVVÿ5ÔØ ÿ×VVh° ÿÕYÑàPh° „$ éE f= …P ÿ3è¥Çÿÿ;ÆV‰D$V|gh° ÿÕYÑàPh° „$ PVVVÿ5ÔØ ÿ׋VVP‰D$ ÿÕYÑàPÿt$ „$  PVVVÿ5ÔØ ÿ×VVh*° ÿÕYÑàPh*° „$° éà h^° ÿÕYÑàPh^° „$À PVVVÿ5ÔØ ÿ׋VVP‰D$ ÿÕYÑàPÿt$ „$Ð PVVVÿ5ÔØ ÿ×VVh†° ÿÕYÑàPh†° „$à PVVVÿ5ÔØ ÿ×ÿt$D$(h²° Pÿ¸× ƒÄ VD$(VPÿÕYÑàPD$0P„$ð PVVVÿ5ÔØ ÿ×VVh¾° ÿÕYÑàPh¾° „$€ PVVVÿ5ÔØ ÿ×Vÿ3ÿŒ× ‹[;Þ…Ëúÿÿ€=ÙØ …ù ÿt$HèU Pÿô× 3Ûhʰ Vÿì× …À}D$@PVVÿü× Cû' rÚëjè Pÿô× û' u"VV»± SÿÕYÑàPS„$€ PVVVÿ5ÔØ ÿ׋àØ ét f‹Cf= …@ ÿ3èVÿÿ;ÆV‰D$V|ghޱ ÿÕYÑàPhޱ „$€ PVVVÿ5ÔØ ÿ׋VVP‰D$ ÿÕYÑàPÿt$ „$ð PVVVÿ5ÔØ ÿ×VVhª± ÿÕYÑàPhª± „$à éÖ hÞ± ÿÕYÑàPhÞ± „$Ð PVVVÿ5ÔØ ÿ׋VVP‰D$ ÿÕYÑàPÿt$ „$À PVVVÿ5ÔØ ÿ×VVh² ÿÕYÑàPh² „$° PVVVÿ5ÔØ ÿ×ÿt$D$(h>² Pÿ¸× ƒÄ VD$(VPÿÕYÑàPD$0P„$  PVVVÿ5ÔØ ÿ×VVhJ² ÿÕYÑàPhJ² „$ é f= …@ ÿ3è¤Ìÿÿ;ÆV‰D$V|ghV² ÿÕYÑàPhV² „$ PVVVÿ5ÔØ ÿ׋VVP‰D$ ÿÕYÑàPÿt$ „$  PVVVÿ5ÔØ ÿ×VVhr² ÿÕYÑàPhr² „$ø éŒ h² ÿÕYÑàPh² „$ PVVVÿ5ÔØ ÿ׋VVP‰D$ ÿÕYÑàPÿt$ „$è PVVVÿ5ÔØ ÿ×VVh³ ÿÕYÑàPh³ „$H PVVVÿ5ÔØ ÿ×ÿt$D$(h>³ Pÿ¸× ƒÄ VD$(VPÿÕYÑàPD$0P„$ˆ PVVVÿ5ÔØ ÿ×VVhJ³ ÿÕYÑàPhJ³ „$( éÄ f= …@ ÿ3èÜ]ÿÿ;ÆV‰D$V|ghV³ ÿÕYÑàPhV³ „$È PVVVÿ5ÔØ ÿ׋VVP‰D$ ÿÕYÑàPÿt$ „$8 PVVVÿ5ÔØ ÿ×VVhv³ ÿÕYÑàPhv³ „$¸ éB hª³ ÿÕYÑàPhª³ „$@ PVVVÿ5ÔØ ÿ׋VVP‰D$ ÿÕYÑàPÿt$ „$¨ PVVVÿ5ÔØ ÿ×VVhâ³ ÿÕYÑàPhâ³ „$0 PVVVÿ5ÔØ ÿ×ÿt$D$(h´ Pÿ¸× ƒÄ VD$(VPÿÕYÑàPD$0P„$˜ PVVVÿ5ÔØ ÿ×VVh´ ÿÕYÑàPh´ „$ éz f= …. ÿ3è¨dÿÿ;ÆV‰D$V|dh&´ ÿÕYÑàPh&´ „$  PVVVÿ5ÔØ ÿ׋VVP‰D$ ÿÕYÑàPÿt$ „$Ø PVVVÿ5ÔØ ÿ×VVhJ´ ÿÕYÑàPhJ´ D$,éû hš´ ÿÕYÑàPhš´ D$xPVVVÿ5ÔØ ÿ׋VVP‰D$ ÿÕYÑàPÿt$ D$pPVVVÿ5ÔØ ÿ×VVhî´ ÿÕYÑàPhî´ D$hPVVVÿ5ÔØ ÿ×ÿt$D$(hµ Pÿ¸× ƒÄ VD$(VPÿÕYÑàPD$0PD$`PVVVÿ5ÔØ ÿ×VVh&µ ÿÕYÑàPh&µ D$XéB f= …M ÿ3è~kÿÿ;ÆV‰D$V|dh2µ ÿÕYÑàPh2µ D$HPVVVÿ5ÔØ ÿ׋VVP‰D$ ÿÕYÑàPÿt$ „$X PVVVÿ5ÔØ ÿ×VVhJµ ÿÕYÑàPhJµ „$p éà h¦µ ÿÕYÑàPh¦µ „$€ PVVVÿ5ÔØ ÿ׋VVP‰D$ ÿÕYÑàPÿt$ „$h PVVVÿ5ÔØ ÿ×VVhÚµ ÿÕYÑàPhÚµ „$x PVVVÿ5ÔØ ÿ×ÿt$D$(h¶ Pÿ¸× ƒÄ VD$(VPÿÕYÑàPD$0P„$` PVVVÿ5ÔØ ÿ×VVh¶ ÿÕYÑàPh¶ „$P PVVVÿ5ÔØ ÿ×Vÿ3ÿŒ× ‹[;Þ…„ùÿÿ‹àØ ëÿ5àØ ‹[ÿŒ× ‰àØ ;ÞVuæÿ5ôØ ÿŒ× VV»"¶ SÿÕYÑàPS„$P PVVVÿ5ÔØ ÿ×ÿ5ðØ ‹=× ÿ×ÿ5ÔØ ÿ×Vÿð× _^][Äh  ÌCould not open driver Services key! Status: 0x%08x Terminating Allocation of query-value buffer failed! Insufficient resources. Terminating Could not query kernel driver queue from registry! Status: 0x%08x Terminating Warning: could not remove driver queue value from Services key. Allocation of DriverQueue buffer failed! Insufficient resources. Terminating Syntax error in driver removal queue. Terminating Allocation of current driver buffer failed! Insufficient resources. Terminating \ R e g i s t r y \ M a c h i n e \ S y s t e m \ C u r r e n t C o n t r o l S e t \ S e r v i c e s \ Unload of driver %ws failed! Status: 0x%08x Could not allocate memory for driver registry path! Insufficient resources Terminating Could not query size of Windir value from registry! Status: 0x%08x Terminating Allocation of query-value buffer failed! Insufficient resources. Terminating Could not query Windir from registry! Status: 0x%08x Terminating Allocation of WindowsDirPath buffer failed! Insufficient resources. Terminating Could not create system thread! Status: 0x%08x Terminating Fatal error: this driver will work only on Windows 2000 or XP. Abort! U‹ìƒìHSVW3öVVEðPEìPèÔ ƒ}ì…§ 9uðtWƒ}ð…˜ Æ6Ù ‹] E¸PjEüPÇE¸ ‰u¼ÇEÄ@ ‰]À‰uȉuÌÿ × ‹ø;þ}WhÌ èj Y‹ÇéZ Æ6Ù ë±·‹KÑèTAþëHJJfƒ:\u÷< fÇEÐj f‹9f£ Ù ‹KÏÇE  ·EЋÐÁâз„.ùÿÿj™^÷þƒÂaAAÿM f‰UÐu×3öOF‰M ‹CÈ·Du΋ÐÁâз„.ùÿÿ™j_÷ÿƒÂaf‰TuÐf‹‹M f‰u Ù FAAƒþ‰M r¾EÐPEäö3ÿPf‰|5Ðf‰¾ Ù ÿœ× EøPWW‹=˜× jEäPÿuüÿ×= €t =# À…Ê ‹Eø‹5”× hDdk ƒÀPjÿÖ‹Ø…Ûuh\Ì èB Yÿuüÿ× ¾š Àé EøPÿuøEäSjPÿuüÿ׋ø…ÿ}$Wh´Ì è  YYj SÿŒ× ÿuüÿ× éÏ ÿuüÿ× EÐPh Ù jÿÈ× …À} h Í èÉ Y‹ChDdk ƒÀnPjÿÖ…À‰EôuhTÍ è§ Yj SÿŒ× é`ÿÿÿ‹K‹ÑÁés ‹øó¥‹Êƒáó¤‹KÑé‰Mø3öf‰4H‹Møf‰tHf90‰E u%h¨Í èZ ‹=Œ× YVSÿ×Vÿuôÿ×¾> Àé ‹ChDdk ƒÀnPjÿ”× ‹ø;þu häÍ è ‹=Œ× YVSÿ×Vÿuôÿ×éÍþÿÿVS‹Œ× ÿÓh<Î Wÿ°× YYÿu GhPÿ°× YYWè,rÿÿ;Æ}PWh¨Î èÈ ƒÄ ‹E ë@@f90uù@@f90‰E uÂVÿuôÿÓVWÿÓ3Àé— ·hDdk Pjÿ”× …À£ìØ u hÜÎ é3þÿÿ· ‹s‹ø‹ÁÁéó¥‹Èƒáó¤f‹f£èØ f‹f£êØ ·‹[ÑèLCþëHIIfƒ9\u÷4CjfÇEÐc ‹Î_·EЋÐÁâз„.ùÿÿj™[÷ûƒÂaAAOf‰UÐuÙ3ÉAƒÆ·DM΋ÐÁâз„.ùÿÿj™_÷ÿƒÂaf ‰TMÐAFFƒùrԍEÐPEä3ÿPf‰|MÐÿœ× EøPWWjEäPÿuüÿ˜× ‹ðþ €t0þ# Àt(Vh<Ï è YYWÿ5ìØ ÿŒ× ÿuüÿ× éP ‹Eø‹5”× ¿Ddk WƒÀPjÿÖ‹Ø…Ûuh”Ï èI YSÿ5ìØ ÿŒ× éõüÿÿEøPÿuøEäSjPÿuüÿ˜× …À‰E }3PhìÏ è  ‹5Œ× YYj ÿ5ìØ ÿÖj SÿÖÿuüÿ× ‹u éÅ ÿuüÿ× ‹C@W@PjÿÖ…À£ôØ u%h4Ð è¾ ‹5Œ× Yj ÿ5ìØ ÿÖj SÿÖéküÿÿ‹K‹ø‹ÁÁés ó¥‹Èƒáó¤‹C‹ ôØ 3öVÑèS‹Œ× f‰4AÿÓjYVhÀ¶ V3ÀV¿ Ù ó«Vhÿ hðØ f«ÿ Ø ‹ø;þœýÿÿWhˆÐ è6 YYVÿ5ìØ ÿÓVÿ5ôØ ÿÓ‹÷è-ƒÿÿ‹ÆëhÌÐ è ¸e ÀY_^[É ÿ%À× ÿ%ø× ÿ%Ø 4Ú BÚ LÚ ZÚ nÚ xÚ Ú ¢Ú ºÚ ÆÚ ÞÚ îÚ øÚ Û Û Û .Û :Û TÛ nÛ ~Û –Û ¢Û ¸Û ÆÛ àÛ îÛ Ü Ü 6Ü LÜ bÜ |Ü ”Ü ŸäÿC  R ,Ø ,Ø RSDS£IVŒÜMKŽ¢VîÝ’;É C:\WINDDK\3790\DriverTest\objfre_wxp_x86\i386\avenger.pdb  ¨Ù ¤Ü €× 4Ú BÚ LÚ ZÚ nÚ xÚ Ú ¢Ú ºÚ ÆÚ ÞÚ îÚ øÚ Û Û Û .Û :Û TÛ nÛ ~Û –Û ¢Û ¸Û ÆÛ àÛ îÛ Ü Ü 6Ü LÜ bÜ |Ü ”Ü \ZwWriteFile ¯wcslen ZwOpenFile M ExFreePoolWithTag ôZwClose @ ExAllocatePoolWithTag :ZwQueryValueKey RtlInitUnicodeString ZwOpenKey RtlUpcaseUnicodeChar ùZwCreateFile ªwcscat ­wcscpy ZwDeleteKey ¢swprintf ZwEnumerateKey 0 DbgPrint SRtlPrefixUnicodeString ÏRtlDeleteRegistryValue RZwSetValueKey žRtlWriteRegistryValue _wcsicmp ZwEnumerateValueKey <ZwReadFile .ZwQueryInformationFile ]KeTickCount IZwSetInformationFile ªRtlCheckRegistryKey PsTerminateSystemThread RKeSetPriorityThread þKeGetCurrentThread ôKeDelayExecutionThread APsCreateSystemThread jPsGetVersion ntoskrnl.exe  ':3:@:G:U:b:t::•: :­:¿:å:;0;6;`;g;y;;;µ;Ò; <(1>F>Q>X>c>p>|>‡>”> >ÿ?  Ä 10O0]0u0|0‘0±0¸0Ê0Ð0Ú01W1^1i1z1‹1É1Ô1ß1è1G;W;c;ˆ;—;ž;§;¹;¿;É;Ó;Ú;ç;>>>'>->=>J>S>^>f>|>Š>º>f?r?y?‡?”?±?¾?Å?Ï?Ú?ç?  000*070E0K0U0]0c0m0ˆ0‘0˜0ª0°0·0Ì0î0÷0þ0 11!131:1C1U1_1g1p1w1‚11š1¬1³1»1Ñ1Û1æ1ï1ö1222*2@2I2V2_2j2w2”22¨2µ2Á2Ô2¯5Ê5Ú 5á5ó5ù5 66*636C6^6g6t66˜6¥6Ä6Í6Ý67 77$7A7J7U7l7y7€7Ž7›7¸7Á7Ì7Ù7ê7ñ7ÿ7 8)828=8J8[8Å=à=ð=÷= >>>+>@>I>Y>t>}>Š>¥>®>»>Ú>ã>ó>??-?:?W?`?k?´?Ê?Ó?á?î? 0  000&040A0^0g0r000º0Á0Ï0Ü0ù01 11&1B1R1Y1k1q1{1¤1«1¹1Æ1ã1ì1÷12%242E2L2Z2g2„22˜2·2Ä2Ë2Ù2æ23 33$393A3H3V3c3€3‰3”3¡3²3o6v66™6¥6®6Ã6É6Ð6ó67.777B7O7U7p7v7}7ˆ7•7›7¦7¶79È9ö9 : :$:5:D:Z:h:n:{:Š:—:¢:©:É:Ý:ï:;;%;7;I;[;m;;‘;£;µ;5>,>5>@>N>h>o>‡>‘>™>¢>­>»>Õ>Ü>ä>ö>? P Ô 0,0;0P0V0b0i0s0†0o1—1§1¶1À1Ð1Û1"2-242F2L2_2›2²2Ã2Î2Ü2~3…3Š3™3¦3·3Ü3ù3 44"4(4ó5ù566!6'6?6L6S6e6k6v6|6”6š6¨6¯6Á6Ç6Í6Ó6Û6ï6õ67!7(7/7A7G7:#:+:2:D:J:]:f:q:~:‹:’:²:»:Æ:Ó:Ý:ì:ó:û:;;(;3;@;M;T;t;};ˆ;•;Ÿ; ` l D0O0Z0g0m0„0Š0‘0¦0¬0Ð0à0õ0û0 111j1’1å1ð1ý122 2'2<2B2Z2e2r2x22•2œ2±2·2Å2Ð2Ý2ã2ú2 333"3/3>3S3a3l3y33–3œ3¡3¸3¾3å3ó3þ3 44(4.434D4M4h4s4€4†44£4¨4Â4Ð4å4ë4ý455!5@5K5X5^5u5{5‚5—55¹5æ56)606E6L6]6…6—6¢6¯6µ6Ì6Ò6×6î6ô6 7 77757;7@7N7W7b>>!>8>>>E>Z>`>x>ƒ>>–>­>³>º>Ï>Õ>ã>î>û>???%?:?@?M?g?u?€??“?£?°?¹?Ä?Ñ?ú? p , 00 0&060C0L0W0h0q0Œ0—0¤0ª0º0Ç0Ð0Û0õ0111/161H1S1y1„1‘1—1²1¸1¿1Ê1×1Ý1ã1 202K2p2w2Œ2“2¡2Ã2Õ2à2í2ó2333&33393A3P3[3h3n3‰33–3¡3«3´3Ø3æ3ô344'424?4K4\4e4s;;£;½;Ô;Ú;<<"J>W>]>p>}>†>‘>ž>¸>Ã>Ð>Ö>é>ö>ÿ> ??'?2???E?X?e?n?y?†?‘?·?É?Ô?á?ç? €  0 000)0/050f0t00Œ0’0¯0µ0¼0Ç0Ù0â0þ0 11191?1F1Q1k1x11“1™1·1¾1Ð1Û12$21272R2X2_2j2w2}2ƒ2§2Ç2þ23-383E3K3f3l3s3~3‹3‘3—3É3×3â3ï3õ3444(4D4_4„4‹4 4§4µ4×4é4ô455"5(5/5:5C5N5[5a5|5‚5‰5”5¡5§5­5Æ5Þ5è5õ56/6:6G6M6p6v6}6ˆ6•6›6¡6·6Á6Ê6ú:;;;#;:;@;G;\;b;†;–;«;±;À;Ç;Ñ; >$>/><>B>Y>_>f>{>>ž>¬>Á>Ç>Ù>à>ö>ý>?'?4?:?Q?W?^?s?y?•?Â?Ý?  Ð 0 0!0(090a0s0~0‹0‘0¨0®0³0Ê0Ð0Ü0ç0ô0ú0111*131-3H3X3_3q3w3‡3“3¨3±3Á3Ü3å3ò3 44#4>4G4W4l4s44Ž4«4´4¿4Ì4Ý4F=W=b=n=s=„=’=£=¬=½=Æ=×=à=ñ=ú= >>(>4>E>Q>b>n>>‹>œ>©>Þ>å>ó> ??"?-?K?R?`?m?†??š?½?Ä?Ò?ß?ø?   ä 0 0,030A0N0g0p0{0ž0¥0³0À0Ù0â0í0 11"1/1H1Q1\11†1”1¡1º1Ã1Î1é1õ1ü1 220292D2Z2’2ž2¬2¹2Ò2Û2æ2ð2þ2 3$3-383N3†3’3 3­3Æ3Ï3Ú3ä3ò3ÿ34!4,4B4z4†4”4¡4º4Ã4Î4Ø4æ4ó4 55 565n5z5ˆ5•5®5·5Â5Ì5Ú5ç5 6 66)6H6T6b6o6ˆ6‘6œ6©6µ6Ã6Ð6é6ò6ý6 7 ° , ô6 777+747B7H7O7]7k7t7}7‹7”7Ÿ7­7Ç7Ò7à7ï7ö78"8-8;8C8I8P8Y8j8q88›8©8¸8¿8â8õ8 9999#9/949P9[9i9x99¢9«9¶9Ä9Ì9Ò9Ù9å9ì9÷9: :9:B:M:[:D:o:}:„:‹:·:Â:Ð:÷: ; ;;(;/;R;[;f;t;ž;«;Ü; <<<+>>->X>c>r>}>Œ>—>¦>±>¿>â>ë>ö>???=?F?Q?~?‰?—?º?Ã?Î?Ü?ç?õ? À l 0!0,0:0I0P0v00Š0¶0Á0Ò0ø01 11(191_1h1s1„1“1š1À1É1Ô1 2 22B2K2V2g2r2ƒ2©2²2½2Î2Ý2ä2 333J3U3f3Œ3•3 3±3¼3Í3ó3ü344'4.4T4]4h4y4„4•4¬4³4º4Ë4ä4ó4 55=5H5Y55ˆ5“5¤5¯5À5æ5ï5ú5 66!6G6P6[6‡6’6£6É6Ò6Ý6î6ù6 70797D7U7d7k7‘7š7¥7Ñ7Ü7í788'888C8T8z8ƒ8Ž8Ÿ8®8µ8Û8ä8ï89&979]9f9q99Š9˜9»9Ä9Ï9Ý9ì9ó9::*:S:^:l:’:›:¦:·:Â:Ó:ù:; ;;-;4;Z;c;n;;Š;›;£;¬;²;½;Ã;Ê;ã;ë;ñ;ù;< Ð ” K1y1…1˜1Å1:2]2c2o2•2­2¼2å2õ2þ2 333&3H3W3•3 3É3Ô3ß3÷3þ344'4g4n4u4™4¢455J5b5p5v555¦5³5¹5Õ5â5í5÷566*616<6E6p6|6‹6”6¡6©6¹6Ç6Ð6â6ú6 77
Just manualy delete these then.
File::
C:\WINDOWS\system32\4fdw.dll
C:\WINDOWS\DUMPff72.tmp
C:\WINDOWS\DUMPeeb3.tmp
C:\WINDOWS\IFinst27.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job

Folder::
C:\Documents and Settings\Nate\Application Data\Viewpoint
C:\Program Files\Viewpoint

Empty Recycle Bin

Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Before i read your post, i scanned with ad-aware again, aand tunred my email scanning again.Computer behaves normally. It no longer resets automatically when i run an ad-aware scan. Norton isnt scanning emails, so that problem may be fixed as well. However, last night i thought i had fixed the problem when i booted in safe mode and deleted all startup files form the registry. It stopped, then when i started up my computer this morning, it began again, so i skeptical to say its been fixed this time. apparently my symptoms were due to multiple virus's. after i discovered this, i did what you said. most of the files you told me to delete were gone anyway. heres my current hijack log, and i will update you as soon as i notice the virus, or tommorow if everything is fine.

In advance, i would like to thank you for walking me through all of this, and explaning it to me, and dealing with everythign that was going on. I tried to get something like this from Norton tech support, and they tried to charge me $100. So thank you so much.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:55, on 2008-02-10
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\NETGEAR\WG111v2\WG111v2.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Aware2007.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O3 - Toolbar: Clusty - {5538fb62-f725-4433-a965-91314e8d8e4d} - C:\Program Files\Clusty Toolbar\toolbar1.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [combofix] C:\WINDOWS\system32\kmd.exe /c C:\combofix\Combobatch.bat
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O8 - Extra context menu item: &Clusty meta-search - res://C:\Program Files\Clusty Toolbar\toolbar1.dll/SEARCH.HTML
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1193608390756
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…/sysreqlab2.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1193604043703
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe
O23 - Service: Viewpoint Manager Service - Unknown owner - C:\Program Files\Viewpoint\Common\ViewpointService.exe (file missing)
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe

–
End of file - 6465 bytes
Lets get rid of Combofix and download the latest version.
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.

    • [external image: Posted Image]

    Download ComboFix from Here to your Desktop.

    **Note: In the event you already have Combofix, please delete it from your desktop and download this new version . It is important that it is saved directly to your desktop**
    ——————————————————————–
    • Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
    • WARNING: IF you have not already done so Combofix will disconnect your machine from the Internet when it starts
    • Please do not re-connect your machine back to the Internet until Combofix has completely finished.
    ——————————————————————–

    Double click on combofix.exe & follow the prompts.
    When finished, it will produce a report for you.
    Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

    ****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

    *If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
sorry i didnt get around to letting you know yesterday, but the extra day did help me solidify the fact. i dont know what happened, it certainly wasnt the malware-byte, but the virus is gone. is it just hiding, i dont know. but it hasnt been active for a few days now. the only thing anoying me now is trying to figure out how the computer can beat me so fast in Dawn of War.
We still need to do this:


Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a checkmark/tick in the box on the left side on these:

O4 - HKLM\..\Run: [combofix] C:\WINDOWS\system32\kmd.exe /c C:\combofix\Combobatch.bat

Close ALL windows and browsers except HijackThis and click "Fix checked"



Good job :thumbup:

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.

    • [external image: Posted Image]


    Here's my usual all clean post

    Log looks good :D


    You need to create a new Clean restore point.

    Note: This will remove all previous Restore Points

    Click Start Menu > Run > copy and paste

    %SystemRoot%\System32\restore\rstrui.exe

    Press OK. Choose Create a Restore Point then click Next. Name it (something you'll remember) and click Create, when the confirmation screen shows the restore point has been created click Close.

    Double-click My Computer.
    Click the Tools menu, and then click Folder Options.
    Click the View tab.
    Check "Hide file extensions for known file types."
    Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
    Check "Hide protected operating system files."
    Click Apply, and then click OK.

    • Make your Internet Explorer more secure - This can be done by following these simple instructions:
      • From within Internet Explorer click on the Tools menu and then click on Options.
      • Click once on the Security tab
      • Click once on the Internet icon so it becomes highlighted.
      • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
    (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
    Without a firewall your computer is succeptible to being hacked and taken over.
    I am very serious about this and see it happen almost every day with my clients.
    Simply using a Firewall in its default configuration can lower your risk greatly.

    For a tutorial on Firewalls and a listing of some available ones see the link below:
    Note: I no longer suggest Zone Alarm

    Understanding and Using Firewalls

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
    This will ensure your computer has always the latest security updates available installed on your computer.
    If there are new updates to install, install them immediately, reboot your computer, and revisit the site
    until there are no more critical updates.

  • Install SpywareBlaster - SpywareBlaster will add a large list of programs and sites into your Internet Explorer
    settings that will protect you from running and downloading known malicious programs.

    A tutorial on installing & using this product can be found here:

    Using SpywareBlaster to protect your computer from Spyware and Malware

  • IE-SPYAD puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.

    Using IE-SPYAD to help block unwanted sites and activities

  • Winpatrol


  • Update all these programs regularly - Make sure you update all the programs I have listed regularly.
    Without regular updates you WILL NOT be protected when new malicious programs are released.

Only run one Anti-Virus and Firewall program.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI