This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Random popups while watching videos

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, my computer has been acting funny lately. Whenever I watch videos, (avi, mkv, dvds) while watching them, I'll get kicked out of full screen and I'll have numerous pop-ups going off. At times I even have to go to task manager and close down iexplorer to stop it.

Logfile of HijackThis v1.99.1
Scan saved at 2:58:09 AM, on 3/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe
C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Nexon\Mabinogi\npkcmsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Hijackthis\HijackThis.exe

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ndetect.exe,
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BHO-X - {317833AD-3A96-11DC-8314-0911200C9A66} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Home Theater SchSvr] "C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe"
O4 - HKLM\..\Run: [WINCINEMAMGR] "C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [Active Desktop Calendar] C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe
O4 - HKCU\..\Run: [WeatherEye] C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe
O4 - HKCU\..\Run: [Firewall auto setup] C:\DOCUME~1\Jinx\LOCALS~1\Temp\winlogon.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: WC3Banlist.lnk = C:\Program Files\Warcraft III\WC3Banlist\WC3Banlist.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {D88C7675-7CEE-4C9A-BDD4-7A43EED7794D} (Logout Class) - http://www.gamengame.com/KALogoutComponent.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\sof629.txt
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\Nexon\Mabinogi\npkcmsvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)

Thanks in advance for helping me.
Download Malwarebytes' Anti-Malware from here and save it to your Desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • Ensure a checkmark is placed next to both Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware and then click Finish.
  • If an update is found, it will download and install the latest version - you'll need to clear it with your firewall.
  • Once the program has loaded, select Perform full scan and then Scan.
  • When the scan has finished, click OK and then Show Results to view the results - no surprise there!
  • If MBAM finds anything, check the box(es) and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt
Let me have the MBAM log, a fresh HJT log (run in Nornmal Mode) AND a description of how your PC is behaving.

Also, run HJT and click on Open the Misc Tools section.
  • Click Open Uninstall Manager…
  • Click Save list… and save it to your Desktop.
  • Copy and paste the file uninstall_list.txt into your next reply.
I installed Malwarebyes' Anti-Malware, after it updated itself, the program won't run. I get an error message stating: An error occurred. Please report the following error code to the Malwarebytes' Anti-Malware support team. Error code: 730 (0) I tried reinstalling it and I still get the same error.
Malwarebytes' Anti-Malware 1.07
Database version: 470

Scan type: Full Scan (C:\|D:\|E:\|H:\|)
Objects scanned: 187042
Time elapsed: 33 minute(s), 1 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\xpre (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\meedia (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Firewall auto setup (Rootkit.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\WINDOWS\system32\nGpxx01 (Trojan.Downloader) -> Quarantined and deleted successfully.

Files Infected:
(No malicious items detected)

Logfile of HijackThis v1.99.1
Scan saved at 6:36:02 PM, on 3/8/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe
C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Warcraft III\WC3Banlist\WC3Banlist.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Nexon\Mabinogi\npkcmsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Hijackthis\HijackThis.exe

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ndetect.exe,
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BHO-X - {317833AD-3A96-11DC-8314-0911200C9A66} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Home Theater SchSvr] "C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe"
O4 - HKLM\..\Run: [WINCINEMAMGR] "C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [Active Desktop Calendar] C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe
O4 - HKCU\..\Run: [WeatherEye] C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Firewall auto setup] C:\DOCUME~1\Jinx\LOCALS~1\Temp\winlogon.exe
O4 - Global Startup: WC3Banlist.lnk = C:\Program Files\Warcraft III\WC3Banlist\WC3Banlist.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {D88C7675-7CEE-4C9A-BDD4-7A43EED7794D} (Logout Class) - http://www.gamengame.com/KALogoutComponent.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\sof629.txt
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\Nexon\Mabinogi\npkcmsvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)


Active Desktop Calendar 7.1
Ad-Aware SE Personal
Adobe Reader 8.1.2
ASUS TV FM CARD
ATI Display Driver
ATI DVD Decoder 2.1.0.1
AVG 7.5
Azureus
Casino Empire
Celestia 1.4.1
CoreVorbis Audio Decoder (remove only)
Creative Audio Console
DivX Pro Codec
DivX Web Player
ETHER VAPOR
Exteel
FATAL/FAKE
ffdshow [rev 918] [2007-02-12]
Fraps (remove only)
Haali Media Splitter
Heroes of Might and Magic V Collector Edition
Hijackthis 1.99.1
HijackThis 1.99.1
HydraVision
InterVideo Home Theater
Java™ 6 Update 3
Java™ SE Runtime Environment 6 Update 1
KSignAccessToolkit v1.0
LimeWire PRO 4.12.11
Logitech IM Video Companion
Logitech ImageStudio
Logitech iTouch Software
Malwarebytes' Anti-Malware
MapleStory
Messenger Plus! Live
Microsoft .NET Framework 2.0
Microsoft Office XP Professional with FrontPage
Microsoft Windows Media Video 9 VCM
mIRC
Mozilla Firefox (2.0.0.12)
neroxml
PlayNC Launcher
ProFile
PS to USB convert cable
QBFC3.0b
Registry Mechanic
Sound Blaster Audigy 2
Spybot - Search & Destroy
Spybot - Search & Destroy 1.5.2.20
Stellarium 0.9.0
VCRedistSetup
VSFilter 2.37
WC3Banlist
Winamp (remove only)
Windows Live Messenger
Windows Media Format Runtime
Windows XP Service Pack 2
WinPcap 4.0.2
WinRAR archiver
WinWay Resume ESD
XviD MPEG-4 Video Codec

At first, I thought it was when I watch videos, but after yesterday, the pop-ups would occur at random times. My computer could be idle and pop-ups in internet explorer would start opening creating a continuous loop.

Another thing I noticed was that my virtual memory also "runs out" even tho the computer is idling.

Thanks you for your help so far Novicate.
Download gmer.zip from here and save it to your Desktop.
You will need to unzip it before you run it.

To do this: Right click on the zipped folder and from the menu that appears, click on Extract All…
In the 'Extraction Wizard' window that opens, click on Next> and in the next window that appears, click on Next> again.
In the final window, click on Finish


Double click gmer.exe to begin:
  • If you get a message about "system modification", click Yes and work through the rest of the instructions.
  • Ensure that the Rootkit Tab at the top is selected.
  • Make sure all the boxes on the right of the screen are checked, EXCEPT for ‘Show All’.
  • Click the Scan button on the right.
  • When the scan has completed, (you'll have time for a snack and a cuppa!), click the Copy button underneath - this will save the report to your Clipboard.
  • Paste it into Notepad (Start > All Programs > Accessories > Notepad) and save it somewhere convenient.
  • Click the >>> Tab at the top and select the Autostart Tab.
  • Click the Scan button on the right - this one should only take seconds to complete.
  • Save the log as before.
Copy and paste both reports into your next reply - you may need to post them separately.
The Preview option may show the whole logs being posted, but they sometimes get cut down when the actual post is made, so check the post once it is completed.
GMER 1.0.14.14116 - http://www.gmer.net
Rootkit scan 2008-03-09 19:11:50
Windows 5.1.2600 Service Pack 2


—- Kernel code sections - GMER 1.0.14 —-

.text USBPORT.SYS!DllUnload F68BF62C 5 Bytes JMP 86C381C8
? C:\WINDOWS\system32\drivers\sptd.sys The process cannot access the file because it is being used by another process.
? System32\Drivers\a6q5br2j.SYS The system cannot find the file specified. !

—- System - GMER 1.0.14 —-

SSDT sptd.sys ZwCreateKey [0xF74E90B0]
SSDT sptd.sys ZwEnumerateKey [0xF74EEA92]
SSDT sptd.sys ZwEnumerateValueKey [0xF74EEE20]
SSDT sptd.sys ZwOpenKey [0xF74E9090]
SSDT sptd.sys ZwQueryKey [0xF74EEEF8]
SSDT sptd.sys ZwQueryValueKey [0xF74EED78]
SSDT sptd.sys ZwSetValueKey [0xF74EEF8A]

—- User code sections - GMER 1.0.14 —-

.text C:\Program Files\MSN Messenger\MsnMsgr.Exe[632] kernel32.dll!LoadResource 7C80A065 7 Bytes JMP 28001CC0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\MSN Messenger\MsnMsgr.Exe[632] kernel32.dll!FindResourceExW 7C80AB10 4 Bytes JMP 28001B00 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\MSN Messenger\MsnMsgr.Exe[632] kernel32.dll!FindResourceExW + 5 7C80AB15 2 Bytes [ CC, CC ]
.text C:\Program Files\MSN Messenger\MsnMsgr.Exe[632] kernel32.dll!FindResourceW 7C80BA56 7 Bytes JMP 28001A80 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\MSN Messenger\MsnMsgr.Exe[632] kernel32.dll!SizeofResource 7C80BAF1 7 Bytes JMP 28001D80 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\MSN Messenger\MsnMsgr.Exe[632] kernel32.dll!LockResource 7C80C6CF 5 Bytes JMP 28001DF0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\MSN Messenger\MsnMsgr.Exe[632] kernel32.dll!FindResourceA 7C80C7B1 7 Bytes JMP 28001B90 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\MSN Messenger\MsnMsgr.Exe[632] kernel32.dll!SetUnhandledExceptionFilter 7C810386 5 Bytes JMP 004DE392 C:\Program Files\MSN Messenger\MsnMsgr.Exe (Messenger/Microsoft Corporation)
.text C:\Program Files\MSN Messenger\MsnMsgr.Exe[632] kernel32.dll!CreateEventA 7C81E4BD 5 Bytes JMP 28001840 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\MSN Messenger\MsnMsgr.Exe[632] kernel32.dll!FindResourceExA 7C822C2D 7 Bytes JMP 28001C20 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\MSN Messenger\MsnMsgr.Exe[632] kernel32.dll!OutputDebugStringW 7C85A215 5 Bytes JMP 28001E50 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\MSN Messenger\MsnMsgr.Exe[632] ADVAPI32.dll!CryptDeriveKey 77DEA685 7 Bytes JMP 28001000 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\MSN Messenger\MsnMsgr.Exe[632] ADVAPI32.dll!CryptDecrypt 77DEA7B1 2 Bytes JMP 28001060 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\MSN Messenger\MsnMsgr.Exe[632] ADVAPI32.dll!CryptDecrypt + 3 77DEA7B4 4 Bytes [ 21, B0, CC, CC ]
.text C:\Program Files\MSN Messenger\MsnMsgr.Exe[632] USER32.dll!PeekMessageW 77D49278 5 Bytes JMP 28003F90 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\MSN Messenger\MsnMsgr.Exe[632] USER32.dll!CreateWindowExW 77D51AD5 5 Bytes JMP 280037C0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\MSN Messenger\MsnMsgr.Exe[632] USER32.dll!SetWindowRgn 77D51DE0 7 Bytes JMP 28005880 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\MSN Messenger\MsnMsgr.Exe[632] USER32.dll!LoadIconW 77D52174 5 Bytes JMP 28006240 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\MSN Messenger\MsnMsgr.Exe[632] USER32.dll!LoadImageW 77D542A4 5 Bytes JMP 28006050 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\MSN Messenger\MsnMsgr.Exe[632] USER32.dll!CreateDialogParamW 77D6629F 5 Bytes JMP 28005A50 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\MSN Messenger\MsnMsgr.Exe[632] USER32.dll!SetWindowPlacement 77D6FBEA 5 Bytes JMP 28005740 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\MSN Messenger\MsnMsgr.Exe[632] USER32.dll!MessageBoxIndirectW 77D960B7 5 Bytes JMP 28005C40 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\MSN Messenger\MsnMsgr.Exe[632] USER32.dll!TrackPopupMenuEx 77D9CAFE 5 Bytes JMP 28004870 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\MSN Messenger\MsnMsgr.Exe[632] WS2_32.dll!send 71AB428A 5 Bytes JMP 2800A360 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\MSN Messenger\MsnMsgr.Exe[632] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 2800A140 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\MSN Messenger\MsnMsgr.Exe[632] WS2_32.dll!recv 71AB615A 5 Bytes JMP 28009FA0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\MSN Messenger\MsnMsgr.Exe[632] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 2800A540 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\MSN Messenger\MsnMsgr.Exe[632] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 2800A780 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\MSN Messenger\MsnMsgr.Exe[632] SHELL32.dll!Shell_NotifyIconW 7CA37CE1 5 Bytes JMP 28002FE0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\MSN Messenger\MsnMsgr.Exe[632] ole32.dll!CoInitializeEx 774F42F3 5 Bytes JMP 28002100 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\MSN Messenger\MsnMsgr.Exe[632] ole32.dll!CoRegisterClassObject 77541BFC 1 Byte [ E9 ]
.text C:\Program Files\MSN Messenger\MsnMsgr.Exe[632] ole32.dll!CoRegisterClassObject + 2 77541BFE 3 Bytes [ 05, AC, B0 ]
.text C:\Program Files\MSN Messenger\MsnMsgr.Exe[632] WININET.dll!HttpOpenRequestA 771C4AC5 5 Bytes JMP 28008E60 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\MSN Messenger\MsnMsgr.Exe[632] WININET.dll!InternetCloseHandle 771C61DC 5 Bytes JMP 280091A0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\MSN Messenger\MsnMsgr.Exe[632] WININET.dll!HttpSendRequestA 771C76B8 5 Bytes JMP 280090D0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\MSN Messenger\MsnMsgr.Exe[632] WININET.dll!InternetReadFile 771C9555 5 Bytes JMP 28008FF0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Winamp\winamp.exe[3084] USER32.dll!SetScrollInfo 77D4902C 7 Bytes JMP 02DDAAA2 C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[3084] USER32.dll!GetScrollPos 77D4F66F 5 Bytes JMP 02DDAA52 C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[3084] USER32.dll!SetScrollRange 77D4F6BB 5 Bytes JMP 02DDAAF8 C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[3084] USER32.dll!SetScrollPos 77D4F780 5 Bytes JMP 02DDAACD C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[3084] USER32.dll!GetScrollRange 77D4F7B7 5 Bytes JMP 02DDAA77 C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[3084] USER32.dll!ShowScrollBar 77D50142 5 Bytes JMP 02DDAB26 C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[3084] USER32.dll!GetScrollInfo 77D53A2F 7 Bytes JMP 02DDAA2A C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[3084] USER32.dll!EnableScrollBar 77D97BAD 7 Bytes JMP 02DDAA02 C:\Program Files\Winamp\Plugins\gen_jumpex.dll

—- Kernel IAT/EAT - GMER 1.0.14 —-

IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!IoConnectInterrupt] [F74FD97E] sptd.sys
IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F74FD92A] sptd.sys
IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F7518B4E] sptd.sys
IAT atapi.sys[ntoskrnl.exe!IoConnectInterrupt] [F74FD97E] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F74E9AB4] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F74E9BFA] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F74E9B7C] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F74EA728] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F74EA5FE] sptd.sys

—- Devices - GMER 1.0.14 —-

Device \FileSystem\Ntfs \Ntfs 86F581E8

AttachedDevice \FileSystem\Ntfs \Ntfs avg7rsw.sys (AVG Resident Shield Unload Helper/GRISOFT, s.r.o.)

Device \FileSystem\Fastfat \FatCdrom 84B8D980
Device \Driver\Tcpip \Device\Ip avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \Driver\PCI_NTPNP2890 \Device\00000050 sptd.sys
Device \Driver\PCI_NTPNP2890 \Device\00000050 sptd.sys
Device \Driver\usbuhci \Device\USBPDO-0 86C371E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 86FD11E8
Device \Driver\dmio \Device\DmControl\DmConfig 86FD11E8
Device \Driver\dmio \Device\DmControl\DmPnP 86FD11E8
Device \Driver\dmio \Device\DmControl\DmInfo 86FD11E8
Device \Driver\usbuhci \Device\USBPDO-1 86C371E8
Device \Driver\usbuhci \Device\USBPDO-2 86C371E8
Device \Driver\usbuhci \Device\USBPDO-3 86C371E8
Device \Driver\usbehci \Device\USBPDO-4 86C02888
Device \Driver\Tcpip \Device\Tcp avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \Driver\Ftdisk \Device\HarddiskVolume1 86F5A1E8
Device \Driver\Ftdisk \Device\HarddiskVolume2 86F5A1E8
Device \Driver\Ftdisk \Device\HarddiskVolume3 86F5A1E8
Device \Driver\atapi \Device\Ide\IdePort0 86F591E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 86F591E8
Device \Driver\atapi \Device\Ide\IdePort1 86F591E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c 86F591E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 86F591E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 86F591E8
Device \Driver\Ftdisk \Device\HarddiskVolume4 86F5A1E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{3C2F8179-B9F8-4BF5-9BEA-79290F32E63E} 852F2708
Device \Driver\NetBT \Device\NetBt_Wins_Export 852F2708
Device \Driver\NetBT \Device\NetbiosSmb 852F2708
Device \Driver\Tcpip \Device\Udp avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \Driver\Tcpip \Device\RawIp avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \Driver\usbuhci \Device\USBFDO-0 86C371E8
Device \Driver\usbuhci \Device\USBFDO-1 86C371E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 852E4490
Device \Driver\usbuhci \Device\USBFDO-2 86C371E8
Device \Driver\Tcpip \Device\IPMULTICAST avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \FileSystem\MRxSmb \Device\LanmanRedirector 852E4490
Device \Driver\usbuhci \Device\USBFDO-3 86C371E8
Device \Driver\Ftdisk \Device\FtControl 86F5A1E8
Device \Driver\usbehci \Device\USBFDO-4 86C02888
Device \Driver\a6q5br2j \Device\Scsi\a6q5br2j1Port2Path0Target0Lun0 86B1A980
Device \Driver\a6q5br2j \Device\Scsi\a6q5br2j1 86B1A980
Device \FileSystem\Fastfat \Fat 84B8D980

AttachedDevice \FileSystem\Fastfat \Fat avg7rsw.sys (AVG Resident Shield Unload Helper/GRISOFT, s.r.o.)

Device \FileSystem\Cdfs \Cdfs 86AFE3C8

—- Registry - GMER 1.0.14 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000d180120b9
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000d180120b9@0015b91247ef 0x9E 0xDE 0x82 0xD8 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 551162623
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 1775694906
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xB7 0x0B 0x88 0xD3 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x05 0xC5 0x70 0x6B …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x78 0x0E 0x05 0xDB …
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\000d180120b9
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\000d180120b9@0015b91247ef 0x9E 0xDE 0x82 0xD8 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xB7 0x0B 0x88 0xD3 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x05 0xC5 0x70 0x6B …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x78 0x0E 0x05 0xDB …
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes@\31j ?? ??
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes@\31j ?? ????
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes@@ @?? ????
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes@\xff740\xff770\xff830\xff6f0 ?? ????
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes@z\xf8f3\x30fb|\xf8f3o\xf8f3x\xf8f3 ?? ????
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes@x\xf8f3p\xf8f3\x30fbt\xf8f3 Courier
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes@\x80\xf8f3r\xf8f3\x30fb}\xf8f3\x30fb\x30fb\x30fb\x30fb\0\0\0\0 Times New Roman
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes@\x30fb\x30fb\x30fb\x30fb\x30fbv\xf8f3\0\0\0\0 Arial
Reg HKLM\SOFTWARE\Classes\CLSID\{33D9A760-90C8-11d0-BD43-00A0C911CE86}\Instance\Indeo
Reg HKLM\SOFTWARE\Classes\CLSID\{33D9A760-90C8-11d0-BD43-00A0C911CE86}\Instance\Indeo@FriendlyName Indeo? video 5.10 Compression Filter
Reg HKLM\SOFTWARE\Classes\CLSID\{33D9A760-90C8-11d0-BD43-00A0C911CE86}\Instance\Indeo@CLSID {1F73E9B1-8C3A-11D0-A3BE-00A0C9244436}
Reg HKLM\SOFTWARE\Classes\CLSID\{33D9A760-90C8-11d0-BD43-00A0C911CE86}\Instance\Indeo@FilterData 0x02 0x00 0x00 0x00 …
Reg HKLM\SOFTWARE\Classes\CLSID\{33D9A760-90C8-11d0-BD43-00A0C911CE86}\Instance\Indeo@EncoderType 1

—- EOF - GMER 1.0.14 —-
GMER 1.0.14.14116 - http://www.gmer.net
Autostart scan 2008-03-09 19:13:13
Windows 5.1.2600 Service Pack 2


HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems@Windows = %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon@Userinit = C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ndetect.exe,

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent@DLLName = Ati2evxx.dll

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows@AppInit_DLLs = C:\WINDOWS\system32\sof629.txt

HKLM\SYSTEM\CurrentControlSet\Services\ >>>
Ati HotKey Poller@ = %SystemRoot%\system32\Ati2evxx.exe
ATI Smart@ = C:\WINDOWS\system32\ati2sgag.exe
Avg7Alrt@ = C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
Avg7UpdSvc@ = C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
AVGEMS@ = C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
npkcmsvc@ = C:\Nexon\Mabinogi\npkcmsvc.exe
ScsiPort@ = %SystemRoot%\system32\drivers\scsiport.sys
UMWdf@ = C:\WINDOWS\system32\wdfmgr.exe
WMDM PMSP Service@ = C:\WINDOWS\system32\MsPMSPSv.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\Run >>>
@SBDrvDetC:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r /*file not found*/ = C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r /*file not found*/
@IMJPMIG8.1"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 = "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
@MSPY2002C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC = C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
@PHIME2002ASyncC:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC = C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
@PHIME2002AC:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName = C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
@Home Theater SchSvr"C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe" = "C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe"
@WINCINEMAMGR"C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe" = "C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe"
@AVG7_CCC:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP = C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
@CTHelperCTHELPER.EXE = CTHELPER.EXE
@CTxfiHlpCTXFIHLP.EXE = CTXFIHLP.EXE
@BluetoothAuthenticationAgentrundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent = rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
@SunJavaUpdateSched"C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" = "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
@zBrowser LauncherC:\Program Files\Logitech\iTouch\iTouch.exe = C:\Program Files\Logitech\iTouch\iTouch.exe
@Adobe Reader Speed Launcher"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" = "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
@LVCOMSC:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE = C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
@LogitechImageStudioTrayC:\Program Files\Logitech\ImageStudio\LogiTray.exe = C:\Program Files\Logitech\ImageStudio\LogiTray.exe
@LogitechGalleryRepairC:\Program Files\Logitech\ImageStudio\ISStart.exe = C:\Program Files\Logitech\ImageStudio\ISStart.exe
@KernelFaultCheck%systemroot%\system32\dumprep 0 -k = %systemroot%\system32\dumprep 0 -k

HKCU\Software\Microsoft\Windows\CurrentVersion\Run >>>
@MsnMsgr"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background = "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
@DAEMON Tools"C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 = "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
@Active Desktop CalendarC:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe = C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe
@WeatherEyeC:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe = C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe
@ctfmon.exeC:\WINDOWS\system32\ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
@SpybotSD TeaTimerC:\Program Files\Spybot - Search & Destroy\TeaTimer.exe = C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
@Firewall auto setupC:\DOCUME~1\Jinx\LOCALS~1\Temp\winlogon.exe /*file not found*/ = C:\DOCUME~1\Jinx\LOCALS~1\Temp\winlogon.exe /*file not found*/
@Steam"c:\progra~1\steam\steam.exe" -silent = "c:\progra~1\steam\steam.exe" -silent

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved >>>
@{42071714-76d4-11d1-8b24-00a0c9068ff3} /*Display Panning CPL Extension*/deskpan.dll /*file not found*/ = deskpan.dll /*file not found*/
@{32683183-48a0-441b-a342-7c2a440a9478} /*Media Band*/(null) =
@{596AB062-B4D2-4215-9F74-E9109B0A8153} /*Previous Versions Property Page*/C:\WINDOWS\System32\twext.dll = C:\WINDOWS\System32\twext.dll
@{9DB7A13C-F208-4981-8353-73CC61AE2783} /*Previous Versions*/C:\WINDOWS\System32\twext.dll = C:\WINDOWS\System32\twext.dll
@{692F0339-CBAA-47e6-B5B5-3B84DB604E87} /*Extensions Manager Folder*/C:\WINDOWS\System32\extmgr.dll = C:\WINDOWS\System32\extmgr.dll
@{B446400D-0030-457b-8F64-422A19605186} /*Logitech Gallery*/C:\Program Files\Logitech\ImageStudio\NameSpc.dll = C:\Program Files\Logitech\ImageStudio\NameSpc.dll
@{B41DB860-8EE4-11D2-9906-E49FADC173CA} /*WinRAR shell extension*/C:\Program Files\WinRAR\rarext.dll = C:\Program Files\WinRAR\rarext.dll
@{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D} /*Messenger Sharing Folders*/C:\Program Files\MSN Messenger\fsshext.8.1.0178.00.dll = C:\Program Files\MSN Messenger\fsshext.8.1.0178.00.dll
@{BDEADF00-C265-11D0-BCED-00A0C90AB50F} /*Web Folders*/C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
@{42042206-2D85-11D3-8CFF-005004838597} /*Microsoft Office HTML Icon Handler*/C:\Program Files\Microsoft Office\Office10\msohev.dll = C:\Program Files\Microsoft Office\Office10\msohev.dll
@{0561EC90-CE54-4f0c-9C55-E226110A740C} /*Haali Column Provider*/C:\Program Files\Haali\MatroskaSplitter\mmfinfo.dll = C:\Program Files\Haali\MatroskaSplitter\mmfinfo.dll
@{5574006C-28F5-4a65-A28C-74DE6BFBE0BB} /*Haali Matroska Shell Property Page*/C:\Program Files\Haali\MatroskaSplitter\mmfinfo.dll = C:\Program Files\Haali\MatroskaSplitter\mmfinfo.dll
@{327669A0-59A7-4be9-B99E-1C9F3A57611A} /*Haali Matroska Thumbnail Exctractor*/C:\Program Files\Haali\MatroskaSplitter\mmfinfo.dll = C:\Program Files\Haali\MatroskaSplitter\mmfinfo.dll
@{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} /*AVG7 Shell Extension*/C:\Program Files\Grisoft\AVG7\avgse.dll = C:\Program Files\Grisoft\AVG7\avgse.dll
@{9F97547E-460A-42C5-AE0C-81C61FFAEBC3} /*AVG7 Find Extension*/C:\Program Files\Grisoft\AVG7\avgse.dll = C:\Program Files\Grisoft\AVG7\avgse.dll
@{e82a2d71-5b2f-43a0-97b8-81be15854de8} /*ShellLink for Application References*/C:\WINDOWS\system32\dfshim.dll = C:\WINDOWS\system32\dfshim.dll
@{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75} /*Shell Icon Handler for Application References*/C:\WINDOWS\system32\dfshim.dll = C:\WINDOWS\system32\dfshim.dll

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ >>>
AVG7 Shell Extension@{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = C:\Program Files\Grisoft\AVG7\avgse.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ >>>
AVG7 Shell Extension@{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = C:\Program Files\Grisoft\AVG7\avgse.dll
MBAMShlExt@{57CE581A-0CB6-4266-9CA0-19364C90A0B3} = C:\Program Files\Malwarebytes' Anti-Malware\mbamext.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects >>>
@{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll = C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
@{53707962-6F74-2D53-2644-206D7942484F}C:\Program Files\Spybot - Search & Destroy\SDHelper.dll = C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
@{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll = C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

HKCU\Control Panel\[removed] = C:\PROGRA~1\XEMICO~1\ACTIVE~1\ADCWOR~1.SCR

HKLM\Software\Microsoft\Internet Explorer\Main >>>
@Default_Page_URLhttp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome = http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
@Start Pagehttp://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home = http://www.microsoft.com/isapi/redir.dll?p…ER}&ar=home

HKCU\Software\Microsoft\Internet Explorer\Main@Start Page = about:blank

HKLM\Software\Classes\PROTOCOLS\Handler\ >>>
cdo@CLSID = C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL
dvd@CLSID = C:\WINDOWS\system32\msvidctl.dll
its@CLSID = C:\WINDOWS\System32\itss.dll
lid@CLSID = C:\WINDOWS\System32\msvidctl.dll
livecall@CLSID = C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
mhtml@CLSID = %SystemRoot%\System32\inetcomm.dll
ms-its@CLSID = C:\WINDOWS\System32\itss.dll
msnim@CLSID = C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
mso-offdap@CLSID = C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
tv@CLSID = C:\WINDOWS\system32\msvidctl.dll
wia@CLSID = C:\WINDOWS\System32\wiascr.dll

HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004@LibraryPath = %SystemRoot%\system32\wshbth.dll

C:\Documents and Settings\All Users\Start Menu\Programs\Startup = WC3Banlist.lnk

—- EOF - GMER 1.0.14 —-
Take a trip to this webpage for download links and instructions for running Combofix by sUBs: http://www.bleepingcomputer.com/combofix/how-to-use-combofix
  • Please Note: This tool may require the PC to be rebooted so close any programs you have open before you start.
  • When CF has finished, it will produce a log C:\ComboFix.txt - copy and paste it into your next reply.
  • Post a fresh HJT log as well.
  • Let me know how the PC is behaving.
ComboFix 08-03-10.1 - Jinx 2008-03-10 20:29:32.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.932.81.1033.18.589 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\Jinx\Application Data\macromedia\Flash Player\#SharedObjects\9LNTUUZA\iforex.com
C:\Documents and Settings\Jinx\Application Data\macromedia\Flash Player\#SharedObjects\9LNTUUZA\iforex.com\Emerp\Events\flash_object.swf\user_data.sol
C:\Documents and Settings\Jinx\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com
C:\Documents and Settings\Jinx\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com\settings.sol
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\testdll.dll

—– BITS: Possible infected sites —–

hxxp://ygsondheks.info
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\smtpdrv


((((((((((((((((((((((((( Files Created from 2008-02-11 to 2008-03-11 )))))))))))))))))))))))))))))))
.

2008-03-09 19:19 . 2008-03-09 19:20 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-03-09 18:29 . 2008-03-09 18:54 250 –a—— C:\WINDOWS\gmer.ini
2008-03-09 12:02 . 2008-03-09 12:02 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-03-09 12:02 . 2008-03-09 12:02 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-09 00:42 . 2008-03-10 20:33 d——– C:\Program Files\Steam
2008-03-08 01:10 . 2008-03-08 01:10 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-03-08 01:01 . 2002-12-10 17:54 127,022 –a—— C:\WINDOWS\system32\LVComS.exe
2008-03-08 00:56 . 2008-03-08 00:56 d——– C:\Documents and Settings\Jinx\Application Data\Malwarebytes
2008-03-08 00:53 . 2008-03-08 00:53 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-03-07 16:32 . 2008-03-07 15:50 691,545 –a—— C:\WINDOWS\unins000.exe
2008-03-07 16:32 . 2008-03-07 16:32 2,538 –a—— C:\WINDOWS\unins000.dat
2008-03-05 14:16 . 2008-03-05 14:16 0 –a—— C:\WDM.vbi
2008-02-14 22:42 . 2008-02-14 22:42 d——– C:\Program Files\Ocean Technologies & Media
2008-02-14 01:52 . 2008-02-14 01:53 d——– C:\Program Files\WinWay Resume ESD

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-11 00:35 ——— d—–w C:\Program Files\Warcraft III
2008-03-10 21:07 ——— d—–w C:\Program Files\mIRC
2008-03-10 14:25 ——— d—–w C:\Documents and Settings\Jinx\Application Data\Azureus
2008-03-10 11:00 ——— d—–w C:\Documents and Settings\All Users\Application Data\avg7
2008-03-10 00:19 ——— d—–w C:\Documents and Settings\Jinx\Application Data\Lavasoft
2008-03-07 21:37 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-07 21:36 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-03-06 22:01 ——— d—–w C:\Program Files\Azureus
2008-03-06 05:06 ——— d—–w C:\Program Files\ProFile
2008-03-06 05:06 ——— d—–w C:\Documents and Settings\All Users\Application Data\GreenPoint
2008-02-20 10:54 ——— d—–w C:\Documents and Settings\Jinx\Application Data\AVG7
2008-02-15 04:24 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-07 03:04 ——— d—–w C:\Program Files\Common Files\Adobe
2008-02-01 14:17 ——— d—–w C:\Program Files\Common Files\Intuit
2008-02-01 14:17 ——— d—–w C:\Documents and Settings\Jinx\Application Data\GreenPoint
2008-01-31 17:06 ——— d—–w C:\Program Files\Common Files\Logitech
2008-01-31 16:49 ——— d—–w C:\Program Files\Logitech
2008-01-31 00:16 ——— d—–w C:\Program Files\Common Files\INCA Shared
2008-01-23 17:37 ——— d—–w C:\Program Files\PartyGaming
2008-01-16 16:27 12,800 —-a-w C:\WINDOWS\system32\linksave.dll
2008-01-15 04:50 ——— d—–w C:\Program Files\Stellarium
2008-01-15 04:36 ——— d—–w C:\Program Files\Celestia
2008-01-14 04:01 ——— d—–w C:\Program Files\Edelweiss
2007-12-11 22:34 200,704 —-a-w C:\WINDOWS\system32\ssldivx.dll
2007-12-11 22:34 1,044,480 —-a-w C:\WINDOWS\system32\libdivx.dll
2002-07-26 22:02 153,088 —-a-w C:\WINDOWS\Fonts\UNWISE.EXE
2007-02-19 20:54 1,056 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{317833AD-3A96-11DC-8314-0911200C9A66}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54 5674352]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2006-11-12 05:48 157592]
"Active Desktop Calendar"="C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe" [2007-06-07 12:38 3670016]
"WeatherEye"="C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe" [2007-09-26 14:14 4484816]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
"Steam"="c:\progra~1\steam\steam.exe" [2008-03-09 00:43 1266936]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SBDrvDet"="C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe" [2002-12-03 18:06 45056]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-03 22:32 208952]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-03 22:31 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-03 22:32 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-03 22:32 455168]
"Home Theater SchSvr"="C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe" [2004-09-20 02:53 106496]
"WINCINEMAMGR"="C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe" [2004-09-20 02:06 233472]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-21 04:41 579072]
"CTHelper"="CTHELPER.EXE" [2006-08-11 14:56 17920 C:\WINDOWS\CTHELPER.EXE]
"CTxfiHlp"="CTXFIHLP.EXE" [2006-08-11 14:56 18944 C:\WINDOWS\system32\CTXFIHLP.EXE]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 00:56 110592 C:\WINDOWS\system32\bthprops.cpl]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"zBrowser Launcher"="C:\Program Files\Logitech\iTouch\iTouch.exe" [2004-03-18 09:33 892928]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"LVCOMS"="C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE" [2002-12-10 17:54 127022]
"LogitechImageStudioTray"="C:\Program Files\Logitech\ImageStudio\LogiTray.exe" [2002-12-10 18:31 61440]
"LogitechGalleryRepair"="C:\Program Files\Logitech\ImageStudio\ISStart.exe" [2002-12-10 18:32 155648]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-10-23 04:41 219136]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
WC3Banlist.lnk - C:\Program Files\Warcraft III\WC3Banlist\WC3Banlist.exe [2007-12-20 23:53:37 907776]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\mIRC\\mirc.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"C:\\Program Files\\ObjectX\\uninstall.exe"=
"C:\\Program Files\\NCsoft\\Exteel\\System\\Exteel.exe"=
"C:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"C:\\Program Files\\Warcraft III\\war3.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"C:\\Nexon\\MapleStory\\MapleStory.exe"=
"C:\\Program Files\\Steam\\SteamApps\\jinx350\\counter-strike\\hl.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"57858:TCP"= 57858:TCP:BT
"57858:UDP"= 57858:UDP:BT
"6115:UDP"= 6115:UDP:WC3
"6115:TCP"= 6115:TCP:WC3

R2 npkcmsvc;npkcmsvc;C:\Nexon\Mabinogi\npkcmsvc.exe [2007-08-02 12:33]
R3 Cap713x;Cap713x Video Capture;C:\WINDOWS\system32\DRIVERS\Cap713x.sys [2004-10-14 02:19]
R3 ctgame;Game Port;C:\WINDOWS\system32\DRIVERS\ctgame.sys [2002-12-30 10:53]
R3 LCcfltr;Logitech USB Filter Driver;C:\WINDOWS\system32\Drivers\LCcFltr.Sys [2004-03-03 09:50]
R3 PhilCam8116;Logitech QuickCam Pro 3000(PID_08B0);C:\WINDOWS\system32\DRIVERS\CamDrL21.sys [2002-12-10 17:53]

.
Contents of the 'Scheduled Tasks' folder
"2008-03-10 05:00:00 C:\WINDOWS\Tasks\At1.job"
- C:\WINDOWS\system32\V2ArPddr.exe
"2008-03-10 14:00:00 C:\WINDOWS\Tasks\At10.job"
- C:\WINDOWS\system32\V2ArPddr.exe
"2008-03-10 15:00:00 C:\WINDOWS\Tasks\At11.job"
- C:\WINDOWS\system32\V2ArPddr.exe
"2008-03-10 16:00:00 C:\WINDOWS\Tasks\At12.job"
- C:\WINDOWS\system32\V2ArPddr.exe
"2008-03-10 17:00:00 C:\WINDOWS\Tasks\At13.job"
- C:\WINDOWS\system32\V2ArPddr.exe
"2008-03-10 18:00:00 C:\WINDOWS\Tasks\At14.job"
- C:\WINDOWS\system32\V2ArPddr.exe
"2008-03-10 19:00:00 C:\WINDOWS\Tasks\At15.job"
- C:\WINDOWS\system32\V2ArPddr.exe
"2008-03-10 20:00:00 C:\WINDOWS\Tasks\At16.job"
- C:\WINDOWS\system32\V2ArPddr.exe
"2008-03-10 21:00:00 C:\WINDOWS\Tasks\At17.job"
- C:\WINDOWS\system32\V2ArPddr.exe
"2008-03-10 22:00:00 C:\WINDOWS\Tasks\At18.job"
- C:\WINDOWS\system32\V2ArPddr.exe
"2008-03-10 23:00:00 C:\WINDOWS\Tasks\At19.job"
- C:\WINDOWS\system32\V2ArPddr.exe
"2008-03-10 06:00:00 C:\WINDOWS\Tasks\At2.job"
- C:\WINDOWS\system32\V2ArPddr.exe
"2008-03-11 00:00:00 C:\WINDOWS\Tasks\At20.job"
- C:\WINDOWS\system32\V2ArPddr.exe
"2008-03-11 01:00:00 C:\WINDOWS\Tasks\At21.job"
- C:\WINDOWS\system32\V2ArPddr.exe
"2008-03-10 02:00:00 C:\WINDOWS\Tasks\At22.job"
- C:\WINDOWS\system32\V2ArPddr.exe
"2008-03-10 03:00:00 C:\WINDOWS\Tasks\At23.job"
- C:\WINDOWS\system32\V2ArPddr.exe
"2008-03-10 04:00:00 C:\WINDOWS\Tasks\At24.job"
- C:\WINDOWS\system32\V2ArPddr.exe
"2008-03-10 05:00:00 C:\WINDOWS\Tasks\At25.job"
- C:\WINDOWS\system32\yMjyrBh8.exe
"2008-03-10 06:00:00 C:\WINDOWS\Tasks\At26.job"
- C:\WINDOWS\system32\yMjyrBh8.exe
"2008-03-10 07:00:00 C:\WINDOWS\Tasks\At27.job"
- C:\WINDOWS\system32\yMjyrBh8.exe
"2008-03-10 08:00:00 C:\WINDOWS\Tasks\At28.job"
- C:\WINDOWS\system32\yMjyrBh8.exe
"2008-03-10 09:00:00 C:\WINDOWS\Tasks\At29.job"
- C:\WINDOWS\system32\yMjyrBh8.exe
"2008-03-10 07:00:00 C:\WINDOWS\Tasks\At3.job"
- C:\WINDOWS\system32\V2ArPddr.exe
"2008-03-10 10:00:00 C:\WINDOWS\Tasks\At30.job"
- C:\WINDOWS\system32\yMjyrBh8.exe
"2008-03-10 11:00:00 C:\WINDOWS\Tasks\At31.job"
- C:\WINDOWS\system32\yMjyrBh8.exe
"2008-03-10 12:00:00 C:\WINDOWS\Tasks\At32.job"
- C:\WINDOWS\system32\yMjyrBh8.exe
"2008-03-10 13:00:00 C:\WINDOWS\Tasks\At33.job"
- C:\WINDOWS\system32\yMjyrBh8.exe
"2008-03-10 14:00:00 C:\WINDOWS\Tasks\At34.job"
- C:\WINDOWS\system32\yMjyrBh8.exe
"2008-03-10 15:00:00 C:\WINDOWS\Tasks\At35.job"
- C:\WINDOWS\system32\yMjyrBh8.exe
"2008-03-10 16:00:00 C:\WINDOWS\Tasks\At36.job"
- C:\WINDOWS\system32\yMjyrBh8.exe
"2008-03-10 17:00:00 C:\WINDOWS\Tasks\At37.job"
- C:\WINDOWS\system32\yMjyrBh8.exe
"2008-03-10 18:00:00 C:\WINDOWS\Tasks\At38.job"
- C:\WINDOWS\system32\yMjyrBh8.exe
"2008-03-10 19:00:00 C:\WINDOWS\Tasks\At39.job"
- C:\WINDOWS\system32\yMjyrBh8.exe
"2008-03-10 08:00:00 C:\WINDOWS\Tasks\At4.job"
- C:\WINDOWS\system32\V2ArPddr.exe
"2008-03-10 20:00:00 C:\WINDOWS\Tasks\At40.job"
- C:\WINDOWS\system32\yMjyrBh8.exe
"2008-03-10 21:00:00 C:\WINDOWS\Tasks\At41.job"
- C:\WINDOWS\system32\yMjyrBh8.exe
"2008-03-10 22:00:00 C:\WINDOWS\Tasks\At42.job"
- C:\WINDOWS\system32\yMjyrBh8.exe
"2008-03-10 23:00:00 C:\WINDOWS\Tasks\At43.job"
- C:\WINDOWS\system32\yMjyrBh8.exe
"2008-03-11 00:00:00 C:\WINDOWS\Tasks\At44.job"
- C:\WINDOWS\system32\yMjyrBh8.exe
"2008-03-11 01:00:00 C:\WINDOWS\Tasks\At45.job"
- C:\WINDOWS\system32\yMjyrBh8.exe
"2008-03-10 02:00:00 C:\WINDOWS\Tasks\At46.job"
- C:\WINDOWS\system32\yMjyrBh8.exe
"2008-03-10 03:00:00 C:\WINDOWS\Tasks\At47.job"
- C:\WINDOWS\system32\yMjyrBh8.exe
"2008-03-10 04:00:00 C:\WINDOWS\Tasks\At48.job"
- C:\WINDOWS\system32\yMjyrBh8.exe
"2008-03-10 09:00:00 C:\WINDOWS\Tasks\At5.job"
- C:\WINDOWS\system32\V2ArPddr.exe
"2008-03-10 10:00:00 C:\WINDOWS\Tasks\At6.job"
- C:\WINDOWS\system32\V2ArPddr.exe
"2008-03-10 11:00:00 C:\WINDOWS\Tasks\At7.job"
- C:\WINDOWS\system32\V2ArPddr.exe
"2008-03-10 12:00:00 C:\WINDOWS\Tasks\At8.job"
- C:\WINDOWS\system32\V2ArPddr.exe
"2008-03-10 13:00:00 C:\WINDOWS\Tasks\At9.job"
- C:\WINDOWS\system32\V2ArPddr.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-10 20:34:12
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.2180]
-> C:\Program Files\XemiComputers\Active Desktop Calendar\MouseHook.dll
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\conime.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\MsPMSPSv.exe
.
**************************************************************************
.
Completion time: 2008-03-10 20:36:54 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-11 01:36:51


Logfile of HijackThis v1.99.1
Scan saved at 9:10:11 PM, on 3/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\conime.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
C:\Nexon\Mabinogi\npkcmsvc.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe
C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe
C:\WINDOWS\system32\ctfmon.exe
C:\progra~1\steam\steam.exe
C:\Program Files\Warcraft III\WC3Banlist\WC3Banlist.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Home Theater SchSvr] "C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe"
O4 - HKLM\..\Run: [WINCINEMAMGR] "C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [Active Desktop Calendar] C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe
O4 - HKCU\..\Run: [WeatherEye] C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] "c:\progra~1\steam\steam.exe" -silent
O4 - HKCU\..\Run: [Firewall auto setup] C:\DOCUME~1\Jinx\LOCALS~1\Temp\winlogon.exe
O4 - Global Startup: WC3Banlist.lnk = C:\Program Files\Warcraft III\WC3Banlist\WC3Banlist.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {D88C7675-7CEE-4C9A-BDD4-7A43EED7794D} (Logout Class) - http://www.gamengame.com/KALogoutComponent.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\Nexon\Mabinogi\npkcmsvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)



The pop-ups aren't as frequent anymore. Maybe a few over the course of the day.

I haven't seen the virtual memory used up lately either.
1) You will need to disable Spybot's Tea Timer function, if it is running, as it may interfere with this fix. - this is a two step process.
First step:
  • Right-click the Spybot Icon in the System Tray (looks like a blue/white calendar with a padlock symbol)
  • If you have the new version 1.5, Click once on Resident Protection, then Right click the Spybot icon again and make sure Resident Protection is now Unchecked. The Spybot icon in the System tray should now be now colorless.
  • If you have Version 1.4, Click on Exit Spybot S&D Resident
Second step, For Either Version :
  • Open Spybot S&D
  • Click Mode, choose Advanced Mode
  • Go To the bottom of the Vertical Panel on the Left, Click Tools
  • then, also in left panel, click Resident shows a red/white shield.
  • If your firewall raises a question, say OK
  • In the Resident protection status frame, Uncheck the box labelled Resident "Tea-Timer"(Protection of over-all system settings) active
  • OK any prompts.
  • Use File, Exit to terminate Spybot
  • Reboot your machine for the changes to take effect.
2) Copy and paste the following into Notepad (Start > All Programs > Accessories > Notepad):

del C:\WINDOWS\Tasks\*.job

Save it to your Desktop with the following filename, including quotation marks: "delete.bat"

Simply double click delete.bat to run it and then delete it.

3) Run HijackThis as you did to generate a log, but this time click on 'Do a system scan only'.
Place a checkmark in the boxes to the left of the following entries, by clicking on them:

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [Firewall auto setup] C:\DOCUME~1\Jinx\LOCALS~1\Temp\winlogon.exe


CLOSE ALL OPEN WINDOWS AND BROWSERS - EXCEPT HJT and click on Fix checked

4) Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
5) Remove any/all of the following files/folders that you can find:

Files

C:\WINDOWS\system32\V2ArPddr.exe
C:\WINDOWS\system32\yMjyrBh8.exe


As an example:
To delete C:\WINDOWS\system32\filetogo.bye
Double click the My Computer icon on your Desktop.
Double click on Local Disc (C:)
Double click on the Windows folder,
Double click on the System 32 folder,
Right click on filetogo.bye and from the menu that appears, click on 'Delete'


6) Go here and click the Kaspersky Online Scanner button - I.E. is required for this scan.
  • Read the Requirements and limitations before you click Accept.
  • Allow the ActiveX download if necessary.
  • Once the database has downloaded click Next.
  • Click Scan Settings and check the "Scan using the following antivirus database" is set to extended, not standard, and then click OK.
  • Click on "My Computer" and then put the kettle on!
  • When the scan has completed, click Save Report As…
  • Enter a name for the file in the Filename: text box and then click the down arrow to the right of Save as type: and select text file (*.txt)
  • Click Save - by default the file will be saved to your Desktop, but you can change this if you wish.
Copy and paste the report into your next reply along with a fresh HJT log, run in Normal Mode, and a description of how your PC is behaving.

Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.
Logfile of HijackThis v1.99.1
Scan saved at 12:09:19 AM, on 3/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe
C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\progra~1\steam\steam.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Warcraft III\WC3Banlist\WC3Banlist.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Nexon\Mabinogi\npkcmsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Home Theater SchSvr] "C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe"
O4 - HKLM\..\Run: [WINCINEMAMGR] "C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [Active Desktop Calendar] C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe
O4 - HKCU\..\Run: [WeatherEye] C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] "c:\progra~1\steam\steam.exe" -silent
O4 - Global Startup: WC3Banlist.lnk = C:\Program Files\Warcraft III\WC3Banlist\WC3Banlist.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {D88C7675-7CEE-4C9A-BDD4-7A43EED7794D} (Logout Class) - http://www.gamengame.com/KALogoutComponent.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\Nexon\Mabinogi\npkcmsvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Wednesday, March 12, 2008 12:04:36 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 12/03/2008
Kaspersky Anti-Virus database records: 625083
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\

Scan Statistics:
Total number of scanned objects: 138650
Number of viruses found: 5
Number of infected objects: 6
Number of suspicious objects: 0
Duration of the scan process: 01:25:30

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Jinx\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Jinx\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Jinx\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Jinx\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Jinx\Local Settings\History\History.IE5\MSHist012008031120080312\index.dat Object is locked skipped
C:\Documents and Settings\Jinx\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Jinx\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Jinx\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.621 skipped
C:\Program Files\Trend Micro\PC-cillin 2003\chiii.exe Infected: Packed.Win32.Klone.j skipped
C:\Program Files\Trend Micro\PC-cillin 2003\efvcxj.exe Infected: Trojan-Downloader.Win32.Tiny.fl skipped
C:\Program Files\Trend Micro\PC-cillin 2003\installer.exe Infected: Trojan-Spy.Win32.BZub.gr skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{4932F91A-374C-4031-9329-EF7248A85CA6}\RP2\change.log Object is locked skipped
C:\WINDOWS\CSC\00000001 Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
E:\Nero 8 Ultra 8.2.8.0 with Keygen\Nero 8 Ultra Edition 8.2.8.0+Keymaker\Nero-8.2.8.0_eng_trial.exe/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
E:\Nero 8 Ultra 8.2.8.0 with Keygen\Nero 8 Ultra Edition 8.2.8.0+Keymaker\Nero-8.2.8.0_eng_trial.exe 7-Zip: infected - 1 skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002826.inf Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002827.ver Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002828.msi Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002829.inf Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002830.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002831.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002832.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002833.CAT Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002834.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002835.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002836.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002837.inf Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002838.ini Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002839.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002840.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002841.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002842.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002843.inf Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002844.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002845.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002846.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002847.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002848.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002849.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002850.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002851.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002852.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002853.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002854.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002855.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002856.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002857.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002858.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002859.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002860.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002861.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002862.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002863.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002864.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002865.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002866.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002867.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002868.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002869.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002870.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002871.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002872.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002873.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002874.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002875.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002876.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002877.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002878.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002879.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002880.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002881.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002882.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002883.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002884.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002885.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002886.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002887.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002888.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002889.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002890.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002891.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002892.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002893.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002894.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002895.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002896.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002897.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002898.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002899.tlb Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002900.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002901.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002902.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002903.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002904.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002905.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002906.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002907.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002908.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002909.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002910.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002911.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002912.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002913.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002914.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002915.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002916.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002917.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002918.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002919.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002920.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002921.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002922.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002923.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002924.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002925.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002926.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002927.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002928.sys Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002929.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002930.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002931.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002932.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002933.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002934.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002935.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002936.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002937.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002938.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002939.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002940.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002941.cat Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002942.sys Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002943.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002944.com Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002945.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002946.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002947.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002948.ocx Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002949.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002950.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002951.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002952.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002953.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002954.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002955.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002956.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002957.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002958.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002959.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002960.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002961.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002962.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002963.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002964.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002965.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002966.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002967.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002968.tlb Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002969.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002970.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002971.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002972.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002973.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002974.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002975.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002976.msc Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002977.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002978.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002979.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002980.cmd Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002981.mof Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002982.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002983.sys Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002984.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002985.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002986.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002987.msi Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002988.inf Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002989.inf Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002990.inf Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002991.sif Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002992.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002993.inf Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002994.inf Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002995.inf Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002996.inf Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002997.inf Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002998.inf Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0002999.inf Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003000.inf Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003001.inf Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003002.inf Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003003.inf Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003004.inf Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003005.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003006.cat Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003007.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003008.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003009.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003010.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003011.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003012.msi Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003013.inf Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003014.inf Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003015.inf Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003016.sif Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003017.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003018.inf Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003019.inf Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003020.inf Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003021.inf Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003022.inf Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003023.inf Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003024.inf Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003025.inf Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003026.inf Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003027.inf Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003028.inf Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003029.inf Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003030.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003031.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003032.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003033.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003034.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003035.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003036.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003037.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003038.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003039.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003040.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003041.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003042.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003043.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003044.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003045.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003046.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003047.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003048.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003049.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003050.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003051.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003052.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003053.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003054.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003055.sdb Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003056.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003057.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003058.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003059.ini Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003060.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003061.inf Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003062.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003063.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003064.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003065.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003066.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003067.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003068.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003069.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003070.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003071.ini Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003072.ini Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003073.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003074.cat Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003075.cat Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003076.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003077.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003078.cat Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003079.cat Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003080.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003081.cat Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003082.cat Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003083.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003084.cat Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003085.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003086.cat Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003087.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003088.cat Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003089.cat Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003090.cat Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003091.cat Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003092.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003093.cat Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003094.exe Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003095.dll Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003096.wa_ Object is locked skipped
E:\System Volume Information\_restore{5578B12B-0E4D-401C-BD4F-17B7A48F07E4}\RP2\A0003097.wa_ Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014500.inf Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014501.ver Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014502.msi Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014503.inf Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014504.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014505.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014506.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014507.CAT Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014508.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014509.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014510.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014511.inf Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014512.ini Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014513.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014514.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014515.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014516.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014517.inf Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014518.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014519.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014520.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014521.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014522.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014523.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014524.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014525.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014526.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014527.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014528.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014529.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014530.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014531.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014532.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014533.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014534.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014535.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014536.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014537.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014538.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014539.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014540.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014541.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014542.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014543.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014544.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014545.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014546.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014547.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014548.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014549.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014550.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014551.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014552.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014553.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014554.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014555.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014556.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014557.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014558.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014559.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014560.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014561.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014562.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014563.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014564.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014565.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014566.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014567.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014568.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014569.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014570.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014571.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014572.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014573.tlb Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014574.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014575.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014576.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014577.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014578.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014579.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014580.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014581.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014582.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014583.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014584.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014585.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014586.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014587.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014588.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014589.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014590.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014591.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014592.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014593.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014594.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014595.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014596.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014597.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014598.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014599.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014600.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014601.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014602.sys Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014603.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014604.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014605.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014606.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014607.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014608.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014609.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014610.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014611.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014612.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014613.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014614.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014615.cat Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014616.sys Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014617.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014618.com Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014619.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014620.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014621.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014622.ocx Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014623.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014624.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014625.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014626.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014627.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014628.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014629.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014630.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014631.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014632.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014633.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014634.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014635.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014636.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014637.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014638.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014639.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014640.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014641.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014642.tlb Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014643.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014644.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014645.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014646.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014647.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014648.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014649.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014650.msc Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014651.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014652.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014653.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014654.cmd Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014655.mof Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014656.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014657.sys Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014658.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014659.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014660.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014661.msi Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014662.inf Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014663.inf Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014664.inf Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014665.sif Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014666.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014667.inf Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014668.inf Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014669.inf Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014670.inf Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014671.inf Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014672.inf Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014673.inf Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014674.inf Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014675.inf Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014676.inf Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014677.inf Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014678.inf Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014679.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014680.cat Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014681.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014682.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014683.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014684.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014685.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014686.msi Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014687.inf Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014688.inf Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014689.inf Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014690.sif Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014691.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014692.inf Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014693.inf Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014694.inf Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014695.inf Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014696.inf Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014697.inf Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014698.inf Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014699.inf Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014700.inf Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014701.inf Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014702.inf Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014703.inf Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014704.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014705.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014706.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014707.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014708.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014709.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014710.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014711.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014712.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014713.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014714.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014715.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014716.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014717.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014718.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014719.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014720.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014721.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014722.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014723.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014724.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014725.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014726.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014727.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014728.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014729.sdb Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014730.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014731.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014732.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014733.ini Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014734.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014735.inf Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014736.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014737.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014738.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014739.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014740.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014741.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014742.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014743.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014744.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014745.ini Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014746.ini Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014747.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014748.cat Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014749.cat Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014750.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014751.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014752.cat Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014753.cat Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014754.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014755.cat Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014756.cat Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014757.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014758.cat Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014759.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014760.cat Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014761.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014762.cat Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014763.cat Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014764.cat Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014765.cat Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014766.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014767.cat Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014768.exe Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014769.dll Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014770.wa_ Object is locked skipped
E:\System Volume Information\_restore{7FF8F417-9DA3-49FE-A6C9-0D805867AC30}\RP29\A0014771.wa_ Object is locked skipped
H:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

Scan process completed.

I couldn't find

C:\WINDOWS\system32\V2ArPddr.exe
C:\WINDOWS\system32\yMjyrBh8.exe

on my computer when I went to look for them. Those files weren't hidden either.
At the moment I have no idea what's causing the pop-ups - I don't see anything I can identify as malicious in any of the logs you've posted. Can you give me some more information about the pop-ups: When did they start? Did you install anything at that time? What do the pop-ups point to? Generally anything and everything that may be relevant in helping to identify the cause.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI