Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Trojan horse Generic.XFV/XKSTrojan horse Clicker [CLOSED]


  • This topic is locked This topic is locked

#1
billfredrickson

billfredrickson

    New Member

  • Member
  • Pip
  • 3 posts
Good evening/morning/afternoon.
I have had some trouble with a couple of trojan horses and was wondering if someone could help me. I use AVG antivirus and it constantly tells me I have Trojan horse Generic.XFV, trojan horse XKS and Trojan horse Clicker.FR files. They appear to self-replicate, and show up in my Windows/System32 folder. I've tried to use ewido (which always has an error when attempting to delete the viruses), avg, search and destroy, CW shredder, and trojan hunter to no avail. In addition, when I run AVG, it always shows a reading error on an .exe file named uvwvz.exe located in windows/system32. I don't know if any of that will help, but i would be extremely grateful to anyone who could help me eradicate these viruses from my registry, or wherever they are so as to keep them from continuing to propagate on my machine.
Below is my Hijack this log. Thank you so much in advance for your help.
-Bill fredrickson


Logfile of HijackThis v1.99.1
Scan saved at 11:35:17 AM, on 9/2/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ezSP_Px.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\PowerPanel\Program\PcfMgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgwb.dat
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgvv.exe
C:\Program Files\HijackThis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [MNTP] ssweeper.exe
O4 - HKLM\..\Run: [TForm1] StartCpl.exe
O4 - HKLM\..\Run: [tgpfh.exe] C:\WINDOWS\system32\tgpfh.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [bhinh.exe] C:\WINDOWS\system32\bhinh.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NukeSpan] ATLIEHELPER.exe
O4 - HKCU\..\Run: [stuffmon] StatusCheck.exe
O4 - HKCU\..\Run: [SYSTRAV] 321102.exe
O4 - HKCU\..\Run: [nmdllw] ssweeper.exe
O4 - Global Startup: Billminder.lnk = C:\Program Files\Quicken\billmind.exe
O4 - Global Startup: PowerPanel.lnk = ?
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{AC2ED2C5-2596-4BE3-9830-89ACA5565A5C}: NameServer = 85.255.114.9,85.255.112.204
O17 - HKLM\System\CCS\Services\Tcpip\..\{F2326252-AF4B-4F29-9529-0325F49F48C5}: NameServer = 85.255.114.9,85.255.112.204
O17 - HKLM\System\CCS\Services\Tcpip\..\{F46D72A9-3890-4319-9A07-54C1E26EED10}: NameServer = 85.255.114.9,85.255.112.204
O17 - HKLM\System\CCS\Services\Tcpip\..\{FF1B6BDE-2CC1-4328-B2E6-74532E4FFD08}: NameServer = 85.255.114.9,85.255.112.204
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.9 85.255.112.204
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.9 85.255.112.204
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: VAIO Media Music Server (VAIOMediaPlatform-MusicServer-AppServer) - Unknown owner - C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe" /Service=VAIOMediaPlatform-MusicServer-AppServer /DisplayName="VAIO Media Music Server (file missing)
O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP (file missing)
O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
O23 - Service: VAIO Media Photo Server (VAIOMediaPlatform-PhotoServer-AppServer) - Sony Corporation - C:\Program Files\Sony\Photo Server\appsrv\PhotoAppSrv.exe
O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-PhotoServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\PhotoServer\HTTP (file missing)
O23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
  • 0

Advertisements


#2
Crustyoldbloke

Crustyoldbloke

    Old Malware Surgeon with a shaky scalpel

  • Retired Staff
  • 15,131 posts
Hello Bill and welcome to Geeks to Go

As an introduction, please note that I am not Superhuman, I do not know everything, but what I do know has taken me years to learn. I am happy to pass on this information to you, but please bear in mind that I am also fallible.

Please note that you should have Administrator rights to perform the fixes. Also note that multiple identity PC’s (family PC’s) present a different problem; please tell me if your PC has more than one individual’s setting, but continue with the fix.

Before we get underway, you may wish to print these instructions for easy reference during the fix, although please be aware that many of the required URLs are hyperlinks in the red names shown on your screen. Part of the fix may require you to be in Safe Mode, which will not allow you to access the internet, or my instructions!

You have quite a mixture of malware and have been hijacked by our comrades in Belrus or the Ukraine. This normally means the Wareout infection. Let’s see what we can do.

Please disable Ewido Guard from as it will hinder our attempts to change anything. Right click on the orange icon in the taskbar (near the clock) and uncheck Resident Shield. The icon will change to a grey colour.

You may want to print out these instructions for reference, since you will have to restart your computer during the fix.

Please download FixWareout from one of these sites:
http://downloads.sub.../Fixwareout.exe
http://www.bleepingc.../Fixwareout.exe

Save it to your desktop and run it. Click Next, then Install, make sure "Run fixit" is checked and click Finish.
The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal.

Once the desktop loads a text file will open (report.txt), you can close it - the file has already been saved.

Run HijackThis. Click "Do a System Scan Only", and place a check next to the following items (if found):

O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: [MNTP] ssweeper.exe
O4 - HKLM\..\Run: [TForm1] StartCpl.exe
O4 - HKLM\..\Run: [tgpfh.exe] C:\WINDOWS\system32\tgpfh.exe
O4 - HKLM\..\Run: [bhinh.exe] C:\WINDOWS\system32\bhinh.exe
O4 - HKCU\..\Run: [NukeSpan] ATLIEHELPER.exe
O4 - HKCU\..\Run: [stuffmon] StatusCheck.exe
O4 - HKCU\..\Run: [SYSTRAV] 321102.exe
O4 - HKCU\..\Run: [nmdllw] ssweeper.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{AC2ED2C5-2596-4BE3-9830-89ACA5565A5C}: NameServer = 85.255.114.9,85.255.112.204
O17 - HKLM\System\CCS\Services\Tcpip\..\{F2326252-AF4B-4F29-9529-0325F49F48C5}: NameServer = 85.255.114.9,85.255.112.204
O17 - HKLM\System\CCS\Services\Tcpip\..\{F46D72A9-3890-4319-9A07-54C1E26EED10}: NameServer = 85.255.114.9,85.255.112.204
O17 - HKLM\System\CCS\Services\Tcpip\..\{FF1B6BDE-2CC1-4328-B2E6-74532E4FFD08}: NameServer = 85.255.114.9,85.255.112.204
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.9 85.255.112.204
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.9 85.255.112.204


Click FIX CHECKED. Close HijackThis.

Finally, please post the contents of the text file that opened earlier (you can find it at C:\fixwareout\report.txt ), along with a new HijackThis log into this topic.
  • 0

#3
billfredrickson

billfredrickson

    New Member

  • Topic Starter
  • Member
  • Pip
  • 3 posts
Well, even if your not superhuman, you're quite friendly for a crusty old bloke :whistling:.
Before posting my logs, I'd like to thank you. I understand that it takes quite some time to learn about all the crap that gets uploaded onto people's computers and I really appreciate that you've been taking the time to help out the less fortunate/knowledgeable.
Just out of curiosity, what exactly did you mean i was hijacked by our friends in people in Belarus or Ukraine. Are those the places that these malwares originated? Or is there evidence of people utilizing such malware and hacking my comp? I'm sorry if that's a stupid question. Just wondering. Actually, as my old boss used to tell me...there are no stupid questions...just stupid people. :blink:
Okay. I'm sure you don't want to waste your time reading my blathering so I'll post my logs now. Looks like they got quite a few programs in my registry. Let me know if there's anything I can do to further fix my compy. Or if there's anything you'd like from Japan (my current residence).

Here is my new hijack this log:

Logfile of HijackThis v1.99.1
Scan saved at 9:21:14 PM, on 9/4/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\PowerPanel\Program\PcfMgr.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\HijackThis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Billminder.lnk = C:\Program Files\Quicken\billmind.exe
O4 - Global Startup: PowerPanel.lnk = ?
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: VAIO Media Music Server (VAIOMediaPlatform-MusicServer-AppServer) - Unknown owner - C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe" /Service=VAIOMediaPlatform-MusicServer-AppServer /DisplayName="VAIO Media Music Server (file missing)
O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP (file missing)
O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
O23 - Service: VAIO Media Photo Server (VAIOMediaPlatform-PhotoServer-AppServer) - Sony Corporation - C:\Program Files\Sony\Photo Server\appsrv\PhotoAppSrv.exe
O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-PhotoServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\PhotoServer\HTTP (file missing)
O23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe


and my fixwareout log:


Fixwareout ver 1.003
Last edited 8/11/2006
Post this report in the forums please

Reg Entries that were deleted
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6421F9F3BAF2-0CAA-7934-93C0-F5ED9F6C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A3157A7352D6-372B-6814-A444-3EDC3A4A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1D0F920B739A-2D7B-27E4-874A-1C2BAEF8{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}37FC514451B7-3C1B-AD64-454D-C20AF505{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C5021D9B3364-8478-8E74-D646-AAC7BF21{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}26E343B2B6A2-EE68-A664-D557-2674AB2F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}84F65B04FBCC-8DBB-2124-6DF5-4B7A6FA5{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0D39BE9EE995-B03B-3D84-1D08-99F80FD3{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0960C66DCE04-94D9-42C4-F7A9-A022AC68{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3CE8006087BC-307A-B6E4-9846-8025B04D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2053948876AB-83F8-9BB4-133D-2CCC7E67{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AC489F853E32-2379-68D4-79EB-0D36058A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B9CB73BC2B2F-EFE9-0B04-7D57-447928A2{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F53F069963DE-89BB-52E4-DFF3-A0DC5C73{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}BA380CE3639A-B59B-9054-50D8-1FCAEA8F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}541A6CEF7427-2D28-57C4-8EA2-340ED46C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}31A81A10513D-E8EB-9364-F884-2D359E58{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6C256944E26E-905A-5854-7125-7BA3C69C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CD236717B245-9EEA-5674-BC78-0B0E7351{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CEEBD6A24455-5DA9-B244-E5AA-282683DD{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}237C80282995-7CEB-0254-DE94-4A3D7713{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0858E921319C-8A1B-5694-2F63-F129463A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}BB84EA4D8CFF-C9F8-2664-D7D9-909BE3C3{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}09083C9D1D0D-201B-B354-0A7D-9F679031{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E40D61C7BB73-1DA9-3E34-CFDC-AE446741{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8D677EC72FF8-0E5B-B3C4-9460-0AB5DB03{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9CC11AA1A0FC-2B79-FF64-C2F3-6D5C7218{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}353B8D474785-9FFB-BF34-4199-D40D50FE{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E8823F4B0FF4-BE59-E634-B159-A7E2610C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3B03A76A98C3-2D68-C804-CAA9-4C353C24{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}16C06306087F-04AB-7004-7B3A-DC7BF3FC{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7AF6964833FF-FFEA-2AC4-FF16-672A4C5F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}706AE5760D0F-F03A-9654-594F-AFEF9A64{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}32EAA400288F-134B-1964-9000-FD3FC2FF{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3C6DFBFC1B29-7E39-F1B4-19A4-D03A1B9A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F266B94A522A-4C79-3C84-1B31-B041C91B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}834621B65934-987A-69F4-4A95-D52E78EA{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8425E0EA0D89-D51B-CEA4-CBC5-E00D4260{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}ABB9E62A444E-A73A-88D4-6C4A-F8E278E4{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}BB347F9A9A5F-4D49-16B4-6556-DDC62DA4{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7B3C50563527-18AA-5E84-3EA3-86609504{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E38DDA42122C-5FFB-18E4-C2C1-3A2CE8FA{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0BE8EB9604B8-B2FB-F104-D551-E4100CD9{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5A629064C128-6758-7F54-5894-FA575DBF{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}587DB373684D-957A-7A74-32DB-E7BA76BC{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}615A9D9DC38A-970A-72D4-50F4-25490F07{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9F0C4CB675EE-EC9B-6314-043B-FBE0C9CD{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8F2C024147CC-5838-61E4-D98A-87940C93{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}662E28E58044-14B9-75D4-C93C-F70BF68D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}EC7DE1E75D9B-D738-5044-967F-DC7688C9{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B4B515C5F91C-9CEA-AF54-4D64-1A2D3F97{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C3217CB3A1B3-69D8-73A4-9A72-9185D6C1{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}042B4D73B4EF-1709-A7A4-5D85-97BE2BF1{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}97D1E6D3B0B6-C9A9-8974-3D83-849F5396{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D7C9DE451B17-B66A-AC44-7AD8-E9D2D1CD{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}99C09A4F4C45-7EE8-B5E4-957E-EC17B587{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B04A0B6ACD11-E17B-A7B4-E0B2-57D5EC03{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}91FC1F2A5E6F-819A-AC54-9129-26916A98{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}56565A5D5686-CCFA-E884-6208-31DA8CF5{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}498E4A0737D3-F7EA-8494-4231-B5038EBB{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FBC7A0F9D4EA-60D9-84E4-7044-83280E97{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E748CC217616-429B-9DC4-3132-81E6CF37{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0913C3F38727-88D8-1714-A506-A3ABAD28{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}EF174BDC4E37-8E79-9F24-2BEA-9E36FE9D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}331439132E3B-BA9B-6EE4-2DB9-FF8D9117{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}DE3B1D0766FC-D86B-9224-AF9F-6CDF0EA8{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}01288A887990-6278-E454-82D3-B9BEFDA1{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7E1A9A0BF157-112B-E524-9A37-5777F67D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}81FFDA71619C-C8DA-2774-4972-DBCC6F0F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}94AFF39DE62A-54DB-F164-B52A-D14C0371{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9DD9A33EDEA5-C839-95E4-9CBF-AA7C70A1{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}030C08CF24E0-5039-82F4-0086-F84260B8{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}96EF31732F58-465B-7D24-D7B3-29C98E19{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}630605A0B7AA-0AA8-F654-444E-9BA89CCF{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8380DD9C1E1E-BA5B-0FE4-F67D-6D2FEC2B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5F29551A9EAD-5FAB-6284-E95B-1BED8128{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}786ADD1C4845-7AE8-7D14-796C-B82274D9{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}88990AF26EDD-1588-48F4-A145-1F5B3DB1{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}129DB356C820-D3E8-3394-7733-41AA7DEF{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2D5FBB2F6F2C-A3BA-5764-350B-03179E4F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5AA75DF95D37-50CB-2034-A570-EB4369BF{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}025196726C7C-C8CA-85E4-A87D-A800D494{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}EC70734184E7-C168-0CE4-6663-5A55098F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6EBBE1215FA7-513A-54A4-B757-E9032B0B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4D9C81A284D1-3828-E094-DEDE-365D04CD{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0A3DD494A3D9-8AEA-5904-BFBB-F7D1D5F8{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}64FAA82C4B84-CF98-5944-F3EA-4CB86E8D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}06C46FA7C687-A869-2234-9F72-2187353C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}00347ED6C704-B58A-8264-21DE-E238216F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}65D35EA89A45-EC0A-B614-0C1F-F271A847{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C27ECC29D58E-70F8-9754-F62B-61B79CF1{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}89D7D1B61E94-A89B-6224-5EE2-513F193F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1198B6D9D817-CDF8-48B4-E8CB-E87C1DF2{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A3D7147AA9E4-A58B-B5B4-14E4-841CBE55{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B652EB759505-54FB-ADF4-DC8B-567FC25D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D23A4FD226BF-4CE9-B874-0210-B470BE8C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}EB445DFD5A4D-5E28-9DD4-C905-4AD151D5{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}249BC423A2E0-375A-8AF4-0DC1-A8CD340B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8F59D037B169-918B-E864-51E8-05AE2A05{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3912DCC67318-562A-42D4-5D29-FAA25320{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D16ECCC979D6-DC98-29C4-7BB3-9816EC09{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}78088F101C45-475B-5DD4-E16B-B22CF227{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}916D1B747CFF-EACB-01A4-D9B0-F4BDC69D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}039C7C479C8F-197A-7B24-B74D-7313706B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}EA8224DFBAA4-7BE8-B384-C945-544643D1{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C3426A12D4BA-BEBA-CD84-F7D5-09B751F5{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}99AB3CE10349-3D88-F734-B0ED-1B282861{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F1422F3610A0-D0C8-6764-39DC-8D72F2AD{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}89A2C611BAEA-71DB-FAA4-00F4-C07CB55C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1F8790192509-64E8-D784-576C-E9CCD89E{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1C1F67970D55-32BA-9354-D20B-84EC770C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}83DFEB6DC89A-32DB-0E14-5E05-99E8B317{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8BDA64A65C6A-F34A-3CD4-238D-4C03C36A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}889C628A6C5B-987A-5FF4-A753-8ECF2F4C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8923E29CC8CC-91B8-FF74-074B-E3F6A2E6{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E985B77EBE0F-6CB8-BD54-7125-ADA77DDF{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9A8FEB7AC550-E42A-8144-F4F4-862F32A8{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}83FB8B16C905-D5A8-C7C4-5841-C19F7B72{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0B9172A906F2-38A8-8204-A119-935DE9C7{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}488665E6702B-ED8A-7C24-EC29-375D5CF2{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4B41236CDF29-C088-2694-49FC-71D7BC21{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}65293EBBE22E-17BA-5104-7978-80238EDD{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FC04E3F0A6F4-1AFA-11C4-B3CD-4D3B203E{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FC57803CF683-AE38-D1E4-388C-0181CAEF{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}962532FCB88C-3C4B-BD34-6C5E-FDF9CF22{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B01A14F2FD27-87D8-6F94-F5A9-93FDC33B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}DBA01BA2A760-7AC9-51B4-2020-4C57BCEB{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3087F4D5B190-745B-D754-71A0-58E2D3C4{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0C00AAB377CF-FDCA-F344-9582-839C7296{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9203FE6A009A-F158-FC04-623E-47C9066F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4ABA4E6B445F-1148-8544-CD7D-A6036603{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0F8E72678F79-54CA-F7C4-3185-327D312C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}533C2823C69E-D659-08C4-3D1B-41A6A2BF{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1A7525DC9E16-656A-A9B4-CF76-1C640FC4{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}ACBFF4A47F0A-1DC9-FA84-FC2A-29081FB7{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D2177C7B2FFE-FB29-B604-2833-2A50A350{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9593CFD3963C-6E3B-A194-6DFA-CBF146EA{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}ABB7B3840994-E8C9-A874-78BD-AA8A4E0F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A8E57F1576CC-BE08-E494-CEA9-53AA3944{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AABE5A52C5B7-A36A-DEA4-3F30-50A1944B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7E86FB1B60D0-0B6B-FD64-3DEF-F7ECE0EB{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A96DE1527924-C87A-3DF4-9A05-F14FD9B3{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}31FE593AEBE8-1DC9-0D34-5230-F70369C2{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}79864D3F79AC-4288-9A54-E11D-CB45B5C5{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}50BBC3FD4522-FC78-BDE4-C3A0-E25C2C75{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}DD087ACB501F-7C08-7434-6A7B-BE552429{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}11055C03E656-B9DA-0624-F19C-C1842387{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}89E396C7F4FF-5228-B504-3E22-95FA9441{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}29FFD122765F-B5F9-0734-B843-C35694AE{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1271548EA39C-FC8A-9EF4-4F4B-33748CC4{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A78684585553-EC08-BFF4-EDAB-C9BB4318{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8CE70947A239-421A-89F4-377E-37E2C2EC{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}25E68FCF4C97-BB5A-7834-8E58-90B31081{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}188C3EA187A3-9D5B-E2E4-2D4E-16FA6011{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}43EF4BFA5854-9E69-5424-FB4D-D2402C62{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}DB912CA2F2B6-AE7B-8914-7396-2A9A2721{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F7DAE0D294D6-620A-7FA4-CA3C-5961ADFC{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6D7075096BE2-49AB-4744-359D-E1D8E822{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A814AE446724-8B58-DE34-7121-A07A2AF5{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}622AE46C49AD-5BD9-3B84-FF7C-D2C05655{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1ECFAE373A15-1D6A-FC94-66F9-75372BDB{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}33B30F01A3A1-0BA8-78F4-5931-ED2E3608{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C62933360726-74B8-3F04-6CC8-4AF4703C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CC23528F8094-BEAA-DE54-C3A7-DF528CC8{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}28672533DC36-AA0A-D9E4-47DB-736233E3{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B435286AA743-74EA-7A24-491D-62C64B68{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}852781F1DB93-98F9-45C4-7B19-569287DC{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9F424FA6E55A-0FDA-D3E4-5025-ED5F4196{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C2BAB8340021-EE39-2804-3A30-E394414E{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}32AD307C5A4C-A089-0CC4-EA91-70A845C3{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8772B49D4407-DCF8-D1E4-34A2-39453A1D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}18BD747A9E5B-862B-08D4-DCF6-0DCEFBC5{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}70C770949D71-35E8-2184-F13D-5EB9619E{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}03E753CF8627-C6BA-8BB4-A48B-5C339597{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1D1EE47E3837-A308-1314-285F-E0D0516A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5E3B98F0E046-CE4A-9FE4-47FE-14073B26{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1B799CEEC936-1449-4944-6742-A5E5797B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A10040AC3E81-C97A-C4B4-25BA-CD34EAD8{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C3AE782DA2CA-EB9B-8104-D1EC-98A3D585{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A35BFEDC2F92-1CA9-F0E4-247F-85535C1D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}421D3B4334CB-FE99-CBA4-3B11-2679E03D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}73D2569A6912-75C8-2C04-2343-DC72DD79{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6710BA83A739-A2EA-86D4-81C6-E2C74286{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7F07CBFECDC0-3B18-CD04-0754-1DE78474{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}BED27D46F7FA-EEFA-7A94-CB1F-5F7F271E{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}116B7E2FF985-AD6A-0364-21BD-D00186E9{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}64AC985D2658-86BB-1064-DAB7-08DFBF56{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}79281E1E9568-3968-DBB4-8432-7321D995{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4F564533BD7F-09EA-12B4-1157-25A5363A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}32E119D7FCAA-AB2A-0124-8200-2807C898{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2A4542252AE7-8638-B994-CA93-F40913BB{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}33D2CA6B1F52-8F98-2934-65DF-BBF68982{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5554CA703566-BD9B-BE14-09CD-B5CC0A6E{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}66C63B056624-6D59-40E4-D441-F7FEEF49{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}29EE84E02B35-62AA-BBB4-7901-CDBBF0E3{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9A34FFEBF4C8-654A-CEA4-9A96-E23F5907{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A03DFFA08210-1F2A-94D4-76B1-A94A4660{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C6AB0E96907C-7159-86F4-AF54-57382D33{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FC28AAFEC724-68FB-CC44-364E-50F9A0CE{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C08EE32E914F-5079-78C4-618A-A3F73676{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D3C2DFBC58F1-856B-9764-8F1E-8C406CF9{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CA6400B92907-98BB-5BD4-CA58-CA05A65B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3C74048FF0DE-D99B-3054-5A81-3F722CBA{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B40C0EBAE888-32CA-9E64-2E15-090F7EBB{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7E735E69AC23-1A58-72A4-03AD-9C48E9E1{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}749C1DCC8BAD-0219-1704-DE19-B4ECE35B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}820B4D84BEB6-2E8B-BE94-88AE-BBAEC1D1{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3CEB2CC5A299-B98A-4514-516A-5B2EC68E{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1C073089EE97-3CC9-02F4-560C-0C34C773{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}81251CE2D444-B35B-6454-036A-77A26CB8{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}387D11D15C12-18E8-3CD4-1B89-7DC3F1D9{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2E1469BFC293-9B1A-8AB4-5CE5-931E4E85{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C6148CE8B4D6-3D58-A7F4-3CCF-92810911{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}33C0FDDFD609-201B-0A84-05DC-63FD5C4C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B84653DB7C5C-438A-9074-AB64-ED2580BC{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}819F6CAAFD6C-4DAB-3644-E731-CFDAA020{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}68DAD4A18E0D-1DBB-B504-9A81-0340EC20{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F79B0E030312-5F1B-54D4-1E15-702EFA35{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1428DADEC915-66FB-9924-710C-07738588{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}84917ED5237B-C34A-BEB4-AD22-239A20E8{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9E6E558C7DA3-D9B9-89D4-2BD7-B52CFC00{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}40C27B375CD0-7048-2054-BEEC-966BA08C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D4553B571151-0D5A-2EB4-F8B3-4D1EFFFA{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3A1AA2D41CCF-09FA-FAE4-5087-2EF21146{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A45411666028-0D1A-BE94-9BC6-81A92025{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3915CCECF85B-BED8-4524-5EFA-7604A2F9{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}19A79AABF6C9-C84B-0404-32F5-1F3CA137{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AED5E259D137-94A9-7C64-5142-DF1CFCBB{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B1F3E3C6E801-DC7B-E5E4-031D-000121F1{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E69746FCFC24-41DB-3264-033B-AF995215{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}85F4C09EA205-6BCA-BCC4-0055-1B715221{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4085037CBFE0-FAC8-9DE4-37B5-CDE08812{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}34CD4724EFEA-7F09-20A4-B829-6FE9C494{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}25DCB9E467C7-022A-94C4-5B4E-16E0EEFD{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}243C9FEE8C8D-F738-B634-C0F7-1709EA45{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FC022840C834-135B-4174-E8CB-523CA646{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}22229227156C-EEE9-2004-46ED-24E05070{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D07A53353667-2D99-AF54-56F4-4FD6A242{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}04355CAC5A15-4B78-E194-7667-F3846E71{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2BDCE0FCF63F-B80B-D304-EB32-055CD2DB{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}51B24419BB62-A86B-A224-9453-B2582E9F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CC779154CF33-C91B-86A4-CD86-156B1DCD{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2200BD894DED-80CB-D884-5AFA-B35DF207{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4FFC4F35B2A7-45FA-BD44-C89D-987327E5{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}EA954EE9D5C9-7A6B-2334-4611-BF9D194F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2E8C4EB8ACD5-DC2A-6344-DD58-09F20CC3{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6C3D94406D40-8069-1FC4-8922-89480226{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}88195B5C205A-21F8-0B74-E678-49C2A834{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}77630B7C5767-E49A-BB64-0D8E-62ECB6A8{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E2E8D0D90BEE-41BA-5854-D80E-9DAE88FD{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}DDEFD89E562B-1348-78F4-9667-7DE33CA3{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B2C917BADB3B-575B-31B4-E8E3-131C9E2D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E94ABAB683D3-A7D9-AC54-2FBB-C0B3FE2C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5DF1502E54A6-4EB9-5A74-6DD1-FABDC06A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}485A549BF518-C728-E764-258B-F453674E{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8DC4ADE7D08F-665A-8474-341E-492B9FCF{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0B641C353528-9A8B-D034-32B2-5E0BBCF3{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D1027505049E-5E7A-65B4-DF68-9F3C83CD{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D1E5642B0D96-0E1B-7304-6DDD-9EF1F0DA{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2CAC6F1421E8-6439-FE74-E4F8-CAA5673F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FFBCF0A14EDE-B879-B404-3A0E-5EEF031F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3F5183F9D198-AF5A-9B14-8837-73A2672B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4D48418B91EF-6DDB-6E44-0895-9E0C16CE{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CCC2D455F5ED-E859-84B4-E1D1-A2362418{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}550B2919211C-C08A-F9A4-AAD6-1CE70B02{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A9F840BE7BF8-A019-5B44-4A47-7B3436E1{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}BD858E736871-BC3A-5534-F28F-8E291F27{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4CA6E4108448-965B-3EA4-41DB-2C0680B3{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8DEF6408A1CC-23EB-2624-EB61-C2FE099F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B6318244A657-5A68-3184-E041-3AC72B8C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3D9B04E3DA03-5B28-B954-01D7-7413E02F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A1613392792C-D07A-4A04-A7B1-0115E8D2{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AC439EF5CF97-4EA8-7424-58A1-F27292D3{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}34C7C0E2A749-0EDB-0DE4-D4C8-DABE08AE{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B47CF3EF435E-B909-B314-BB4B-8A18A812{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C68D86779BF0-DF6B-28E4-DA5B-53C4A51D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}49A172389016-37E8-AEB4-7B88-5F5642D9{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9A1F2652F3E8-BC58-5324-026D-CD7795B0{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2DBBC7CD001E-A569-40B4-B1E8-492BD962{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E7FD26B73156-82FB-8124-88CE-883A1B27{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}40697034858A-19E8-B0A4-9F67-D58AA4FD{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}DE6769149A77-444A-D7A4-2D6E-1E1EBB8E{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2BAC8E61B64D-A1E9-0C24-950B-8C2E2679{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FDBD5098A9E9-D258-15A4-3B38-89A3D588{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}779360325207-0F3B-6EF4-1263-B4D21E1F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B455B3114CE1-9078-6594-C433-F70BAA88{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7977F23E7604-24B9-CD84-678C-C4B3164A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B1A751674C34-CA28-A164-2FAB-01DF61F7{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F665946DCA47-4D5A-0E34-D7EB-B3E02968{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}24E0AEE516A5-B548-01D4-A9EA-FE1BE9B1{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0C4D53666473-2928-06B4-9851-DDFA63E7{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2109CA0FD573-985A-6CD4-B3EC-8EA81799{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CCC49A8854CC-3DD8-46D4-D5E3-EABD5387{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E839E43AD016-6DA8-02A4-79A7-E067F603{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FA5A40F051AD-4F49-0144-23AC-FC57F58F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5AD8D370A92E-132A-7874-880F-491D6614{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D601BEE02BD8-B2F8-F624-E704-D4ABBBF2{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1CB3DA379E33-1109-3D14-0158-ECF463AD{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F7AAB044F53A-3ECA-4104-9AF2-E2EAD370{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}055C00E5B14A-CA29-7CC4-EBCC-18C4064B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}41EE88B0053E-D27B-6A74-7C47-461EF323{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}DFB1CB835329-ED99-A754-4693-16D3FF56{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0CA1D95726C5-0749-7574-199E-6A58FC79{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CFDA2D86149E-34FB-E794-864A-709ED775{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}695C5E6162A1-DE89-98F4-56A1-098903C9{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8AFBD271A1F5-C3E9-9A94-F8F8-16B706A6{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6FB51CE8988D-A539-E484-9B79-14DF4B94{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}ECDB55C975D6-045B-FCE4-A844-C66F2D83{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CCC0DBE94044-7AE9-7C14-E735-D8E1EDA2{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E399DDAC296E-B499-4094-8D06-44C8BC7B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7D72F41FE5DC-1C3A-EE04-BA42-4E639633{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}EBAD613CAA95-8558-E9E4-F778-7DED91E9{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D62DE1059389-C228-8004-D281-DA7956B7{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}576103FFE81F-A9A9-C124-834F-1064697C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1852A6360891-B819-AC04-D4BA-00555DF5{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4BDFE06092B6-C31B-2014-7197-388B8AAE{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D89C26C50858-B879-2EF4-D174-BF570BFC{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7B06CD9E2393-D9FA-8B24-91BD-096FB637{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B4E7C2974251-0308-E7A4-3FA2-F2BD38D7{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AED059932D83-6128-7644-F0CB-F54A7557{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}BA633C248313-3ECA-0684-6D89-BC246A21{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}136978159EA6-70E8-5B04-8051-393734DB{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}334E2CD7A739-B90A-8714-C262-D5B46822{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0F2844DC456D-665A-C9F4-982F-0667F6FF{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}56EE1B61E226-AE0B-F5B4-F4AD-EA9E1561{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E5A262D3D471-8B9A-6E34-330C-8F14C6C4{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7D943ADD5019-8E48-5944-1EB8-F498B379{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AFB7C6912000-61AB-5C54-0324-96A6A910{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9DB83B8618EC-2058-C274-7303-55C5C147{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AFCFA205BC94-0FAB-D6E4-7AD4-ACD36455{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3B554528331C-8EBB-A5A4-4662-9A681AA1{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}07B799E2107C-F588-A014-490D-89EAE133{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FBE531F6532E-8029-87B4-1282-66DAAB7D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2951E795568B-1868-E574-CAC8-07FB493F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FF3D38A74D9E-0259-5014-F2A2-84067EC8{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7885AA81C503-07EB-FF84-59C5-80A71729{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}14550C786ABE-CF1B-A644-8E0D-694E3795{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}00E8E894FD79-E86A-6A04-4FF7-ECD12DCB{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1FEBA2D49324-6168-EDA4-F7AA-836A5FBE{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A6D3D3132291-B1FB-C1B4-1253-36062986{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}53F86F3EBACE-B959-CEF4-561F-58AA424C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6288295D42CC-073A-9B54-9085-1668BFA6{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C877D97C2926-1C59-8094-A1FA-F8EBA3D4{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4405C11A4D35-5B0B-D574-0072-F0693AEC{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}089FBCA7E747-6EAA-EB34-F3C1-EF7053B4{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D0757E2570BA-F86A-F364-42E7-6560563B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}400A3522566B-1CE8-90C4-554F-C61A1EDC{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A326A329EF28-CE7A-5354-ADFD-442FBD88{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B0D3FFA15394-633B-3BB4-3232-4040ED92{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}936BAF197754-60BA-7C64-DE83-3767EF62{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}735D92B22FE5-E408-3234-F9A7-4EB0B391{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C680BDE4D24E-5F6B-AD74-471B-539699C8{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D5620DDECA96-9958-5E64-B9CC-CAA23506{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8DBFC5CC6BFB-2059-A884-9D2F-3CFF05B7{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}53D46890ECD7-C8BB-0B84-CEF2-905F5E8C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}78C5CF428F43-86B8-0974-206F-AC081355{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D7902FBB866B-F35A-AB74-D055-AC8965A8{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6B0016416B6B-5F4B-5964-B082-BB9CAC2F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CAF18B3C86C6-4A7B-88A4-15E0-772D865C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}563559E0D335-B569-FE74-98CF-5553BA7F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B0EC28DA27C7-B6E9-9694-FDC5-9E21F4D9{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5064273607A3-D798-AE64-7AB6-8DBBB96A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}88617F25C1DC-0329-5094-3A60-94E3893B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}05BB78ECC1E0-36FA-50A4-123D-D78BDE69{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}45305E4D927F-1898-D594-8692-EB4A96F3{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5CF549EFF389-3C8A-EFD4-62E2-BACF6AE0{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9346A943EDC9-F19B-1614-987F-F1B3C1D9{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3D9194029FB9-C8EB-1CD4-3FD5-646FB47C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}254D51445009-9288-50E4-51AE-E8266F33{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C5FFB6875C55-4A68-BAF4-41D5-09103098{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8813475DF7A1-45EA-3A54-8F88-B58381D8{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6C1FA120BCB9-3B48-B704-4937-C895B3FC{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AF6D680A8E8A-A03A-7934-D2FA-199F4AF3{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AF367790A278-CA19-5E14-99A5-A00F291A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B271C4CF36C4-D30B-8A24-5700-8D8C5478{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}51C74740CF0C-A54A-6A74-F9FC-166D4038{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}664E5A0072C8-3849-C1B4-12CE-F48D32A5{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5498FB7369D7-005A-94E4-14BA-3ED231ED{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5A8D817D8910-FC6B-7EC4-801D-3832E76C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}BEEEFADE9147-DDD8-9754-5E79-1883016A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F842BB2E4D0D-837B-27B4-5ECF-F310ABAB{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F829923737C1-BEDA-ACD4-1A44-F2A00205{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}08DF51FE09CF-A66A-41F4-B841-357CC3E0{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}44F4EC6F131E-C8CA-F3C4-4775-28758152{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F65E0A4477D5-EB7B-FA34-43CA-8F645744{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4D6BAFFD41F3-2E2A-7BE4-EEF8-129D9425{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}43302E168702-6D68-A3C4-D237-E9571747{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D7DFD77EA6B4-242B-7A84-69FC-23A2BC37{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CC8B1B9979AF-76BB-4E54-AC3A-B06B854C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2A46D2546E8C-96EA-1C84-196F-5A82CF8A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FAC040E77B50-1B98-A024-0944-0F731FEE{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7D831631A90C-3779-1544-BD7E-9BCEA43A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C1D91C0239E8-8CA8-0D94-AE4D-A201F540{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2AD3E31F7AE0-BE2B-2164-B2A7-21D17011{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}13D120590D05-0ECB-CF54-7F47-B4DA9A95{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}EF557C3B6EB1-846A-BCF4-5E45-9289D527{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}33F13CA86E45-0A79-1504-C06E-50768511{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9593D830F2C1-9DBA-1974-C2B0-45762E73{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}320BEFB520D1-1D8A-4604-7378-7EE383FE{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2756C3C769F0-C21B-D1D4-E360-C3C25062{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B8739FBF086D-FEBA-A6B4-B9CC-48DC9BB2{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}71EA117D5A97-B919-13F4-301C-172523A7{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6419296196C2-E818-63C4-8BB8-4E075585{
HKEY_LOCAL_MACHINE
  • 0

#4
Crustyoldbloke

Crustyoldbloke

    Old Malware Surgeon with a shaky scalpel

  • Retired Staff
  • 15,131 posts
Hello again Bill

By hijacked, I mean that your PC was being controlled by persons at this internet address:85.255.112.0 - which points to this company, Inhoster hosting company, Poltavskij Shliax 24, Kharkiv, 61000, Ukraine

You'll be pleased to hear that you are no longer under their control.

The Wareout log you posted was incomplete, probably due to its length. I am interested in the last bit, which highlights a few files that may be bad files.

Also please run ComBofix.

Download this file: combofix.exe to your Desktop

Double click combofix.exe & follow the prompts.

When it has finished, it will produce a log. Please post that log in your next reply.

Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

BTW, you are right, it does take a while to learn these skills and I haven't stopped learning yet.
  • 0

#5
billfredrickson

billfredrickson

    New Member

  • Topic Starter
  • Member
  • Pip
  • 3 posts
Hey Crusty,
Thanks for the timely reply. Sorry I didn't get you the whole fixwareout post. I didn't realize it was missing the bottom section. Anyway, I was wondering how you knew the ip address/info of the place you said had control of my computer. If I can easily check to see that some strange ip address is controlling my computer I can protect myself more easily. If it's really difficult to explain, you don't have to spend your time. I'm sure you do too much of that for everyone anyway.
I ran combo fix and will post the the end of my last fixwareout post, and the combo fix post.
Thanks again for all your help. You're nice
oh, and sorry for taking so long to respond. My internet settings got erased so I had to set them up again, and didn't time until tonight to set everything back up.

;D :whistling:





Groblock - 06-09-11 21:33:18.03
ComboFix 06.09.11B - Running from: C:\Documents and Settings\Groblock\Desktop

Microsoft Windows XP [Version 5.1.2600]

((((((((((((((((((((((((((((((( Files Created from 2006-08-11 to 2006-09-11 ))))))))))))))))))))))))))))))))))


2006-08-11 01:49 127,208 --a------ C:\WINDOWS\system32\mucltui.dll


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-09-04 22:00 -------- d-------- C:\Program Files\HijackThis
2006-08-27 22:21 -------- d-------- C:\Program Files\ewido anti-spyware 4.0
2006-08-11 03:13 -------- d-------- C:\Program Files\Messenger
2006-08-11 03:12 -------- d-------- C:\Program Files\Internet Explorer
2006-08-11 03:10 -------- d-------- C:\Program Files\Windows Media Player
2006-08-11 03:03 -------- d-------- C:\Program Files\Outlook Express
2006-08-11 02:38 -------- d-------- C:\Program Files\TrojanHunter 4.5
2006-08-10 09:30 777472 --a------ C:\WINDOWS\system32\drivers\avg7core.sys
2006-08-10 09:30 27904 --a------ C:\WINDOWS\system32\drivers\avg7rsxp.sys
2006-07-27 22:24 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-07-21 17:24 72704 --a------ C:\WINDOWS\system32\hlink.dll
2006-07-05 21:50 724992 --a------ C:\WINDOWS\iun6002.exe


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIModeChange"="Ati2mdxx.exe"
"Mouse Suite 98 Daemon"="ICO.EXE"
"ezShieldProtector for Px"="C:\\WINDOWS\\System32\\ezSP_Px.exe"
"IMJPMIG8.1"="\"C:\\WINDOWS\\IME\\imjp8_1\\IMJPMIG.EXE\" /Spoil /RemAdvDef /Migration32"
"MSPY2002"="C:\\WINDOWS\\System32\\IME\\PINTLGNT\\ImScInst.exe /SYNC"
"PHIME2002ASync"="C:\\WINDOWS\\System32\\IME\\TINTLGNT\\TINTSETP.EXE /SYNC"
"PHIME2002A"="C:\\WINDOWS\\System32\\IME\\TINTLGNT\\TINTSETP.EXE /IMEName"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000000

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"


HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll


Completion time: Mon 09/11/2006 21:33:45.31
ComboFix.txt






and the end of the fixwareout log:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A2141FC1CFF4-F749-63B4-A6EE-DDF5594D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A6D983B95AC9-5CF8-FD54-2DE9-BC8208B3{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B90DB75DF25C-361A-A004-0423-76367DD0{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B8AE5007EAF4-B68A-D0E4-D8A5-F7AB5F8B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8D4060A6429C-D38B-AE84-6B78-9BDD44DE{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}30F323ACD735-1FA9-38E4-BB64-354CCC6D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D735310E41A9-D808-6FD4-D20A-2CB383D2{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B835D475FCF3-5DFB-2284-B230-80B6E777{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\swen
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\ogol
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\llun
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\eerht
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\evif
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\ypszr
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\putesprpgd
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\onisacputes
...

Microsoft ® Windows Script Host Version 5.6
Random Runs removed from HKLM
...

PLEASE NOTE, There WILL be LEGITIMATE FILES LISTED. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.

サササササ Searching by size/names...

サササササ
Search five digit cs, dm and jb files.
This WILL/CAN also list Legit Files, Submit them at Virustotal
C:\WINDOWS\SYSTEM32\DMTDJ.EXE 61,958 2004-08-04

Other suspects.
Directory of C:\WINDOWS\system32
{777E6B08-032B-4822-BFD5-3FCF574D538B}.exe
{2D383BC2-A02D-4DF6-808D-9A14E013537D}.exe
{D6CCC453-46BB-4E83-9AF1-537DCA323F03}.exe
{22F63968-1F4D-49EA-A2F9-8ABF0666AD67}.exe
{606B9C66-E0B0-4AA9-9278-C05EA7593056}.exe
{A94F1BED-6DF8-459E-A34E-147EB74E17CE}.exe
{E2783634-5E65-48AC-B4EB-53CB5A2EF7B2}.exe
{F3D15FEB-6CB9-4851-9E90-D18FE01B3E10}.exe
{B237CDB6-23BD-446A-A557-CBB820353F0D}.exe
{5974AEA0-7D16-4E88-9559-ADD3C6BDBEE7}.exe
{6BA1DBAE-DA4E-4671-88E9-299816393810}.exe
{99ACD4D8-2F61-4DC8-9F07-F3D9E876BD96}.exe
{6D319513-D4FE-422E-A09C-FC7BDB4850BB}.exe
{5A15DEEC-1917-414F-9247-F22B2D6E1B5F}.exe
{182D4C0C-C8E7-42EB-A8B9-C216EB91CB6B}.exe
{3B0C26C0-E4ED-4B13-931B-2E6EEBC2D766}.exe
{B316D8BD-A312-41A7-9F4B-655405BBFB3D}.exe
{F813C19B-A79D-4C2E-A92A-76453FF7960A}.exe
{D5A434AC-4F1C-46D5-8C9F-7C480855DCD1}.exe
{34760E2A-E698-4EDA-A2EB-C852F2F26AD1}.exe
{1996B1EE-15F2-4274-838F-F9E8FC12C29F}.exe
{E7EF0BF0-2B75-44CB-A344-D116282F0FD8}.exe
{2C83C2AE-F493-4E12-BA5F-A0C01D5793B6}.exe
{33C8B844-4BF5-4D95-85D5-C6E1BED2FC49}.exe
{E422BCE1-048A-48BF-9458-D018AF308922}.exe
{13C9D71F-D604-456B-838C-D073F8446DEC}.exe
{0ED357AD-ADA7-4F39-96C3-029DBB8891D6}.exe
{F63B0462-85A5-4497-A8C8-BC1B47A5EAE3}.exe
{723B3B39-E4D7-42F1-B710-1BD61EC37FB7}.exe
{17A0E7FD-73F3-460B-BC26-055127222760}.exe
{1A686CBB-729A-485E-B15C-EA2EDF4C02FC}.exe
{F9C53BD1-F053-4F31-AC67-2147FEA9DDF3}.exe
{42BDC1CF-B19A-4551-87DE-F578BA19BDCE}.exe
{C028B506-F3C2-4F2D-B2EF-46F3B7FE8761}.exe
{ABDBF05B-69D8-498B-863D-F35D907B6219}.exe
{970B9669-678C-48A5-83F4-15CEBA22D849}.exe
{2CA79CA7-62B3-4DA5-807C-DE491016C39F}.exe
{BEAFA44C-BBB2-4A43-BEC5-2CB2AE3564BF}.exe
{0DF0672D-6713-483A-AEC8-BAE9F6A99B54}.exe
{9D5F4D91-6640-4444-AD07-E7164CF40167}.exe
{FBBC32A3-FD1C-4FAC-800C-DBCD392B31EC}.exe
{587EB9EE-2F77-4A51-8E4F-03F11729C778}.exe
{DE58E44D-3528-43D3-8A70-8E5D83A1D05A}.exe
{ED526E4D-9DB3-4385-8304-91E47BA50E5F}.exe
{EAF22D32-5F9D-4C19-B6D2-E2F5883C6EB1}.exe
{83090756-5A43-4252-AD7A-97A0F37F22FE}.exe
{17EAFFE3-56DE-4FE2-A64E-8763957F9AA0}.exe
{389C576C-D68E-4462-8416-2188777FAC79}.exe
{86559CD9-0C30-4959-8A7B-E6938EB4BC4E}.exe
{9B798364-C6D4-4F16-8E79-133A646DCE90}.exe
{04C40180-30B4-4896-BD7A-2AA3A9AA2BAD}.exe
{DF9902D1-86D4-464E-B896-52A9A41A7E73}.exe
{351E5B25-86F8-4218-80A5-6F3F963991BA}.exe
{6F4B88B1-E316-40C7-AEFF-81514A3EC7C2}.exe
{EEBF5C63-EB12-4937-996B-33110FB516D9}.exe
{89608B42-0BB4-4C82-A68D-8422753487FE}.exe
{AD06A6AE-C6BB-477E-86D0-81F52B38F334}.exe
{03D7E68C-56F3-48F5-B15C-C32C3E95B75B}.exe
{56B2C86C-8194-493D-A92F-F6F145913C39}.exe
{030A37AC-8658-41CC-B441-4A3A24EAB034}.exe
{115C1B14-28B8-48D6-A594-CC15F6EF7E06}.exe
{109E8AB6-17B0-4224-9A0A-D43000061FEE}.exe
{DAFA83E0-F547-42AA-B47B-9E11C6288599}.exe
{9FF0EC68-5508-4883-9425-02BCB0C9AB67}.exe
{93557AB4-2717-4FD7-8D67-212AF89698D5}.exe
{45974E01-A5E7-45BC-99E8-A416F4A150CF}.exe
{30A98D89-3BB2-40A0-AD1E-EA40C57015CE}.exe
{88C3BDC5-3599-44E9-A914-C52463F9D32A}.exe
{B5016C0D-7272-4C8E-937A-EF5252036B0E}.exe
{1126D7DF-E444-4778-9154-F16D07D105FC}.exe
{092B7CDF-EA06-4734-AE12-83375D3214DF}.exe
{1FA48BC1-44EA-44F3-9745-B7CC96EBE051}.exe
{EF89A081-D45A-4645-A6C9-38A199EC5F88}.exe
{1306CE1D-1769-4294-B9CB-39C1F42275C6}.exe
{442DAD51-63FE-4865-8BDD-C8F15A25BC2D}.exe
{444106AC-66D2-4957-8F90-99B81CB61522}.exe
{8D220DB7-E2BB-4AC8-B415-E776B37572AF}.exe
{0023560D-436F-4CA5-8473-5A194A56E355}.exe
{7FE5A95D-F482-4DA1-B598-23025961B142}.exe
{9F25E914-0AFE-47E3-84C0-E90B2E534F43}.exe
{E4B852E4-2C67-4C4C-99BA-9AD690A1E845}.exe
{D5C8998D-F2DA-4634-BDBC-A5260BF9196A}.exe
{920C4EC8-1181-4C64-86F2-A3F0807E532A}.exe
{651F5B0D-C750-4EFF-A55F-122F27A3F626}.exe
{A07965D6-2185-4546-81D9-D493D0005E04}.exe
{600A6101-995B-47D7-95A4-EFD4159535A2}.exe
{851AD2CA-EBEE-46E2-B01B-D334F2398102}.exe
{8E72FE3F-1B9A-44C8-92AB-4F0F1FF15D17}.exe
{7CCAF87E-A03F-40E5-90B2-E792EF71FF1C}.exe
{9AB5AB31-CE84-4FB4-A8B8-1E9AECAC4DD9}.exe
{EAE44CB5-DACC-4F57-9988-66EA1EE95E22}.exe
{4B4AD781-4330-4653-AF78-C75FE88FEFDE}.exe
{3F5D10E6-FDA9-4AFC-9EF5-6F0B7193EFBA}.exe
{B7E5D81A-4F40-4825-A7B9-F28DCCD156B6}.exe
{F5921278-3393-4BBE-A9C9-4FA959AB6CC9}.exe
{CC723F4F-BB49-4533-83D1-00E93BD49941}.exe
{8CDAF3EF-2132-47EF-A084-7028495DDD50}.exe
{45427DBA-A2B0-4518-AD70-B644B94D29D2}.exe
{6BF8A4E9-5821-4C85-AC36-0F5C5B04C193}.exe
{37E2552D-DFB1-44A7-B9E3-ADF21E37D8BF}.exe
{D9A62DBC-377A-43E3-B76A-65B1D8DFE535}.exe
{9B1CCC5F-4D6B-4F87-8712-0197DADF06EA}.exe
{7AD746BD-9BA2-4924-986E-E809F3AC733D}.exe
{B9EE37F1-0DB1-47A5-ACDF-834C4AD9DF17}.exe
{F7639BBB-C3FC-4643-AE61-84611425A886}.exe
{F2B292E3-4BCD-41FC-8975-E719F94D78D5}.exe
{03BEF2CE-805F-4D3F-856F-BED71804AA86}.exe
{234F6E6C-1F56-4792-A27C-E707330802D3}.exe
{A44135D9-7897-4D67-974B-51B4259A8D45}.exe
{119DE8E4-9027-4FF8-9DC9-58CBE8C90B83}.exe
{E0F959E6-AF4E-4B59-969D-FA90AF76F966}.exe
{0DDABDF9-2998-4E0D-9360-3AFD3BDBE611}.exe
{02DF84FF-41F3-43DF-90D3-A419AB545C4A}.exe
{36078A51-C1F2-4844-ACBB-63EB6D240BB9}.exe
{F11F60B9-CF4C-43F6-A778-E529E11CB879}.exe
{BF301668-9B75-47A6-8683-1DB94BD60815}.exe
{847457F7-4C52-4322-AE87-37D58CBF51F6}.exe
{C3556AF1-D81C-4D68-A18C-2ABEE1483952}.exe
{9452DAC7-6F55-4145-880C-3CA00F26F323}.exe
{BA5B32D9-A3A8-4EE8-83BE-C061ACCAFF45}.exe
{91140404-E4CC-4380-B193-A6C6D068C1A9}.exe
{65DE54FB-5C90-4FF7-A4BE-2CAA74804294}.exe
{A90AB9EC-7110-479F-9252-0CAA79E3AA36}.exe
{16349E9E-0D60-4BDB-9DE3-040B5753F5AB}.exe
{4F959E48-2DA3-42A2-BF67-E9DB47509F73}.exe
{5082E51D-62D5-4012-B9C7-087439C126D2}.exe
{80529769-A1A0-4CC5-98B7-4E674D2C85F1}.exe
{3DEFE49C-580B-49BB-A655-759C3528CC65}.exe
{05CB654C-DB4A-4DC7-A89E-891F6EBA189D}.exe
{934C91DA-90FB-4A3B-9785-DDDBAF905D40}.exe
{65BBBD8F-FF66-4B26-898C-CC8CA44B4590}.exe
{5B0C5A56-775B-4A1D-8F0B-D9F619910931}.exe
{75993BD9-0355-4F19-836D-B22BB201B36F}.exe
{52F56181-D610-4C38-825C-1F5D566BECEB}.exe
{752833AA-E420-4B6D-8E55-C5CB8BEE19E9}.exe
{B2CBC7F5-E432-45B5-B858-2204B520660F}.exe
{737D4F58-3314-4104-AB6B-6A211F4ABD67}.exe
{C3BB460B-B38A-433B-9EE4-B6690681E8F8}.exe
{559A901A-9F37-479E-80D2-A8544BC55789}.exe
{4572254E-9C48-4A97-8C2E-A426B9595AB9}.exe
{460D08DD-666D-4AD4-BD8D-F5867E708D3E}.exe
{6B2523DA-E8D2-4F2D-939E-704C92A85E11}.exe
{F052EF43-5CB5-41C8-9DE7-3FD889D962D7}.exe
{70E123D4-293F-4077-A45E-8378864E2503}.exe
{8F03031C-5B2B-4329-8999-76CF370E544E}.exe
{E191E346-5F91-4148-8BA8-67DAAC973961}.exe
{4EA0DC9E-9EFF-4B0D-AB1F-F449BA41BEF9}.exe
{800D764A-143E-4A3D-BA24-A169DA9AC6A2}.exe
{DBFD2D35-33FD-42E9-BFC3-4C641917E64A}.exe

サササササ Misc files.

サササササ Checking for older varients covered by the Rem3 tool.
  • 0

#6
Crustyoldbloke

Crustyoldbloke

    Old Malware Surgeon with a shaky scalpel

  • Retired Staff
  • 15,131 posts
Hello again Bill

That's better. One bad file in Combofix log and loads in Wareout log.

The IP address can be looked up in an ip address directory. We spot them in the 017 entry space. Some you get used to, AOL, BT etc, just like the rogue ones too, 85.255.114.9

Please download: Killbox by Option^Explicit

Please install Killbox by Option^Explicit.
  • Please double-click Killbox.exe to run it.
  • Select Delete on Reboot
  • then Click on the All Files button.
  • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
I suggest batches of 10 at a time

C:\WINDOWS\iun6002.exe
C:\WINDOWS\system32\{777E6B08-032B-4822-BFD5-3FCF574D538B}.exe
C:\WINDOWS\system32\{2D383BC2-A02D-4DF6-808D-9A14E013537D}.exe
C:\WINDOWS\system32\{D6CCC453-46BB-4E83-9AF1-537DCA323F03}.exe
C:\WINDOWS\system32\{22F63968-1F4D-49EA-A2F9-8ABF0666AD67}.exe
C:\WINDOWS\system32\{606B9C66-E0B0-4AA9-9278-C05EA7593056}.exe
C:\WINDOWS\system32\{A94F1BED-6DF8-459E-A34E-147EB74E17CE}.exe
C:\WINDOWS\system32\{E2783634-5E65-48AC-B4EB-53CB5A2EF7B2}.exe
C:\WINDOWS\system32\{F3D15FEB-6CB9-4851-9E90-D18FE01B3E10}.exe
C:\WINDOWS\system32\{B237CDB6-23BD-446A-A557-CBB820353F0D}.exe
C:\WINDOWS\system32\{5974AEA0-7D16-4E88-9559-ADD3C6BDBEE7}.exe
C:\WINDOWS\system32\{6BA1DBAE-DA4E-4671-88E9-299816393810}.exe
C:\WINDOWS\system32\{99ACD4D8-2F61-4DC8-9F07-F3D9E876BD96}.exe
C:\WINDOWS\system32\{6D319513-D4FE-422E-A09C-FC7BDB4850BB}.exe
C:\WINDOWS\system32\{5A15DEEC-1917-414F-9247-F22B2D6E1B5F}.exe
C:\WINDOWS\system32\{182D4C0C-C8E7-42EB-A8B9-C216EB91CB6B}.exe
C:\WINDOWS\system32\{3B0C26C0-E4ED-4B13-931B-2E6EEBC2D766}.exe
C:\WINDOWS\system32\{B316D8BD-A312-41A7-9F4B-655405BBFB3D}.exe
C:\WINDOWS\system32\{F813C19B-A79D-4C2E-A92A-76453FF7960A}.exe
C:\WINDOWS\system32\{D5A434AC-4F1C-46D5-8C9F-7C480855DCD1}.exe
C:\WINDOWS\system32\{34760E2A-E698-4EDA-A2EB-C852F2F26AD1}.exe
C:\WINDOWS\system32\{1996B1EE-15F2-4274-838F-F9E8FC12C29F}.exe
C:\WINDOWS\system32\{E7EF0BF0-2B75-44CB-A344-D116282F0FD8}.exe
C:\WINDOWS\system32\{2C83C2AE-F493-4E12-BA5F-A0C01D5793B6}.exe
C:\WINDOWS\system32\{33C8B844-4BF5-4D95-85D5-C6E1BED2FC49}.exe
C:\WINDOWS\system32\{E422BCE1-048A-48BF-9458-D018AF308922}.exe
C:\WINDOWS\system32\{13C9D71F-D604-456B-838C-D073F8446DEC}.exe
C:\WINDOWS\system32\{0ED357AD-ADA7-4F39-96C3-029DBB8891D6}.exe
C:\WINDOWS\system32\{F63B0462-85A5-4497-A8C8-BC1B47A5EAE3}.exe
C:\WINDOWS\system32\{723B3B39-E4D7-42F1-B710-1BD61EC37FB7}.exe
C:\WINDOWS\system32\{17A0E7FD-73F3-460B-BC26-055127222760}.exe
C:\WINDOWS\system32\{1A686CBB-729A-485E-B15C-EA2EDF4C02FC}.exe
C:\WINDOWS\system32\{F9C53BD1-F053-4F31-AC67-2147FEA9DDF3}.exe
C:\WINDOWS\system32\{42BDC1CF-B19A-4551-87DE-F578BA19BDCE}.exe
C:\WINDOWS\system32\{C028B506-F3C2-4F2D-B2EF-46F3B7FE8761}.exe
C:\WINDOWS\system32\{ABDBF05B-69D8-498B-863D-F35D907B6219}.exe
C:\WINDOWS\system32\{970B9669-678C-48A5-83F4-15CEBA22D849}.exe
C:\WINDOWS\system32\{2CA79CA7-62B3-4DA5-807C-DE491016C39F}.exe
C:\WINDOWS\system32\{BEAFA44C-BBB2-4A43-BEC5-2CB2AE3564BF}.exe
C:\WINDOWS\system32\{0DF0672D-6713-483A-AEC8-BAE9F6A99B54}.exe
C:\WINDOWS\system32\{9D5F4D91-6640-4444-AD07-E7164CF40167}.exe
C:\WINDOWS\system32\{FBBC32A3-FD1C-4FAC-800C-DBCD392B31EC}.exe
C:\WINDOWS\system32\{587EB9EE-2F77-4A51-8E4F-03F11729C778}.exe
C:\WINDOWS\system32\{DE58E44D-3528-43D3-8A70-8E5D83A1D05A}.exe
C:\WINDOWS\system32\{ED526E4D-9DB3-4385-8304-91E47BA50E5F}.exe
C:\WINDOWS\system32\{EAF22D32-5F9D-4C19-B6D2-E2F5883C6EB1}.exe
C:\WINDOWS\system32\{83090756-5A43-4252-AD7A-97A0F37F22FE}.exe
C:\WINDOWS\system32\{17EAFFE3-56DE-4FE2-A64E-8763957F9AA0}.exe
C:\WINDOWS\system32\{389C576C-D68E-4462-8416-2188777FAC79}.exe
C:\WINDOWS\system32\{86559CD9-0C30-4959-8A7B-E6938EB4BC4E}.exe
C:\WINDOWS\system32\{9B798364-C6D4-4F16-8E79-133A646DCE90}.exe
C:\WINDOWS\system32\{04C40180-30B4-4896-BD7A-2AA3A9AA2BAD}.exe
C:\WINDOWS\system32\{DF9902D1-86D4-464E-B896-52A9A41A7E73}.exe
C:\WINDOWS\system32\{351E5B25-86F8-4218-80A5-6F3F963991BA}.exe
C:\WINDOWS\system32\{6F4B88B1-E316-40C7-AEFF-81514A3EC7C2}.exe
C:\WINDOWS\system32\{EEBF5C63-EB12-4937-996B-33110FB516D9}.exe
C:\WINDOWS\system32\{89608B42-0BB4-4C82-A68D-8422753487FE}.exe
C:\WINDOWS\system32\{AD06A6AE-C6BB-477E-86D0-81F52B38F334}.exe
C:\WINDOWS\system32\{03D7E68C-56F3-48F5-B15C-C32C3E95B75B}.exe
C:\WINDOWS\system32\{56B2C86C-8194-493D-A92F-F6F145913C39}.exe
C:\WINDOWS\system32\{030A37AC-8658-41CC-B441-4A3A24EAB034}.exe
C:\WINDOWS\system32\{115C1B14-28B8-48D6-A594-CC15F6EF7E06}.exe
C:\WINDOWS\system32\{109E8AB6-17B0-4224-9A0A-D43000061FEE}.exe
C:\WINDOWS\system32\{DAFA83E0-F547-42AA-B47B-9E11C6288599}.exe
C:\WINDOWS\system32\{9FF0EC68-5508-4883-9425-02BCB0C9AB67}.exe
C:\WINDOWS\system32\{93557AB4-2717-4FD7-8D67-212AF89698D5}.exe
C:\WINDOWS\system32\{45974E01-A5E7-45BC-99E8-A416F4A150CF}.exe
C:\WINDOWS\system32\{30A98D89-3BB2-40A0-AD1E-EA40C57015CE}.exe
C:\WINDOWS\system32\{88C3BDC5-3599-44E9-A914-C52463F9D32A}.exe
C:\WINDOWS\system32\{B5016C0D-7272-4C8E-937A-EF5252036B0E}.exe
C:\WINDOWS\system32\{1126D7DF-E444-4778-9154-F16D07D105FC}.exe
C:\WINDOWS\system32\{092B7CDF-EA06-4734-AE12-83375D3214DF}.exe
C:\WINDOWS\system32\{1FA48BC1-44EA-44F3-9745-B7CC96EBE051}.exe
C:\WINDOWS\system32\{EF89A081-D45A-4645-A6C9-38A199EC5F88}.exe
C:\WINDOWS\system32\{1306CE1D-1769-4294-B9CB-39C1F42275C6}.exe
C:\WINDOWS\system32\{442DAD51-63FE-4865-8BDD-C8F15A25BC2D}.exe
C:\WINDOWS\system32\{444106AC-66D2-4957-8F90-99B81CB61522}.exe
C:\WINDOWS\system32\{8D220DB7-E2BB-4AC8-B415-E776B37572AF}.exe
C:\WINDOWS\system32\{0023560D-436F-4CA5-8473-5A194A56E355}.exe
C:\WINDOWS\system32\{7FE5A95D-F482-4DA1-B598-23025961B142}.exe
C:\WINDOWS\system32\{9F25E914-0AFE-47E3-84C0-E90B2E534F43}.exe
C:\WINDOWS\system32\{E4B852E4-2C67-4C4C-99BA-9AD690A1E845}.exe
C:\WINDOWS\system32\{D5C8998D-F2DA-4634-BDBC-A5260BF9196A}.exe
C:\WINDOWS\system32\{920C4EC8-1181-4C64-86F2-A3F0807E532A}.exe
C:\WINDOWS\system32\{651F5B0D-C750-4EFF-A55F-122F27A3F626}.exe
C:\WINDOWS\system32\{A07965D6-2185-4546-81D9-D493D0005E04}.exe
C:\WINDOWS\system32\{600A6101-995B-47D7-95A4-EFD4159535A2}.exe
C:\WINDOWS\system32\{851AD2CA-EBEE-46E2-B01B-D334F2398102}.exe
C:\WINDOWS\system32\{8E72FE3F-1B9A-44C8-92AB-4F0F1FF15D17}.exe
C:\WINDOWS\system32\{7CCAF87E-A03F-40E5-90B2-E792EF71FF1C}.exe
C:\WINDOWS\system32\{9AB5AB31-CE84-4FB4-A8B8-1E9AECAC4DD9}.exe
C:\WINDOWS\system32\{EAE44CB5-DACC-4F57-9988-66EA1EE95E22}.exe
C:\WINDOWS\system32\{4B4AD781-4330-4653-AF78-C75FE88FEFDE}.exe
C:\WINDOWS\system32\{3F5D10E6-FDA9-4AFC-9EF5-6F0B7193EFBA}.exe
C:\WINDOWS\system32\{B7E5D81A-4F40-4825-A7B9-F28DCCD156B6}.exe
C:\WINDOWS\system32\{F5921278-3393-4BBE-A9C9-4FA959AB6CC9}.exe
C:\WINDOWS\system32\{CC723F4F-BB49-4533-83D1-00E93BD49941}.exe
C:\WINDOWS\system32\{8CDAF3EF-2132-47EF-A084-7028495DDD50}.exe
C:\WINDOWS\system32\{45427DBA-A2B0-4518-AD70-B644B94D29D2}.exe
C:\WINDOWS\system32\{6BF8A4E9-5821-4C85-AC36-0F5C5B04C193}.exe
C:\WINDOWS\system32\{37E2552D-DFB1-44A7-B9E3-ADF21E37D8BF}.exe
C:\WINDOWS\system32\{D9A62DBC-377A-43E3-B76A-65B1D8DFE535}.exe
C:\WINDOWS\system32\{9B1CCC5F-4D6B-4F87-8712-0197DADF06EA}.exe
C:\WINDOWS\system32\{7AD746BD-9BA2-4924-986E-E809F3AC733D}.exe
C:\WINDOWS\system32\{B9EE37F1-0DB1-47A5-ACDF-834C4AD9DF17}.exe
C:\WINDOWS\system32\{F7639BBB-C3FC-4643-AE61-84611425A886}.exe
C:\WINDOWS\system32\{F2B292E3-4BCD-41FC-8975-E719F94D78D5}.exe
C:\WINDOWS\system32\{03BEF2CE-805F-4D3F-856F-BED71804AA86}.exe
C:\WINDOWS\system32\{234F6E6C-1F56-4792-A27C-E707330802D3}.exe
C:\WINDOWS\system32\{A44135D9-7897-4D67-974B-51B4259A8D45}.exe
C:\WINDOWS\system32\{119DE8E4-9027-4FF8-9DC9-58CBE8C90B83}.exe
C:\WINDOWS\system32\{E0F959E6-AF4E-4B59-969D-FA90AF76F966}.exe
C:\WINDOWS\system32\{0DDABDF9-2998-4E0D-9360-3AFD3BDBE611}.exe
C:\WINDOWS\system32\{02DF84FF-41F3-43DF-90D3-A419AB545C4A}.exe
C:\WINDOWS\system32\{36078A51-C1F2-4844-ACBB-63EB6D240BB9}.exe
C:\WINDOWS\system32\{F11F60B9-CF4C-43F6-A778-E529E11CB879}.exe
C:\WINDOWS\system32\{BF301668-9B75-47A6-8683-1DB94BD60815}.exe
C:\WINDOWS\system32\{847457F7-4C52-4322-AE87-37D58CBF51F6}.exe
C:\WINDOWS\system32\{C3556AF1-D81C-4D68-A18C-2ABEE1483952}.exe
C:\WINDOWS\system32\{9452DAC7-6F55-4145-880C-3CA00F26F323}.exe
C:\WINDOWS\system32\{BA5B32D9-A3A8-4EE8-83BE-C061ACCAFF45}.exe
C:\WINDOWS\system32\{91140404-E4CC-4380-B193-A6C6D068C1A9}.exe
C:\WINDOWS\system32\{65DE54FB-5C90-4FF7-A4BE-2CAA74804294}.exe
C:\WINDOWS\system32\{A90AB9EC-7110-479F-9252-0CAA79E3AA36}.exe
C:\WINDOWS\system32\{16349E9E-0D60-4BDB-9DE3-040B5753F5AB}.exe
C:\WINDOWS\system32\{4F959E48-2DA3-42A2-BF67-E9DB47509F73}.exe
C:\WINDOWS\system32\{5082E51D-62D5-4012-B9C7-087439C126D2}.exe
C:\WINDOWS\system32\{80529769-A1A0-4CC5-98B7-4E674D2C85F1}.exe
C:\WINDOWS\system32\{3DEFE49C-580B-49BB-A655-759C3528CC65}.exe
C:\WINDOWS\system32\{05CB654C-DB4A-4DC7-A89E-891F6EBA189D}.exe
C:\WINDOWS\system32\{934C91DA-90FB-4A3B-9785-DDDBAF905D40}.exe
C:\WINDOWS\system32\{65BBBD8F-FF66-4B26-898C-CC8CA44B4590}.exe
C:\WINDOWS\system32\{5B0C5A56-775B-4A1D-8F0B-D9F619910931}.exe
C:\WINDOWS\system32\{75993BD9-0355-4F19-836D-B22BB201B36F}.exe
C:\WINDOWS\system32\{52F56181-D610-4C38-825C-1F5D566BECEB}.exe
C:\WINDOWS\system32\{752833AA-E420-4B6D-8E55-C5CB8BEE19E9}.exe
C:\WINDOWS\system32\{B2CBC7F5-E432-45B5-B858-2204B520660F}.exe
C:\WINDOWS\system32\{737D4F58-3314-4104-AB6B-6A211F4ABD67}.exe
C:\WINDOWS\system32\{C3BB460B-B38A-433B-9EE4-B6690681E8F8}.exe
C:\WINDOWS\system32\{559A901A-9F37-479E-80D2-A8544BC55789}.exe
C:\WINDOWS\system32\{4572254E-9C48-4A97-8C2E-A426B9595AB9}.exe
C:\WINDOWS\system32\{460D08DD-666D-4AD4-BD8D-F5867E708D3E}.exe
C:\WINDOWS\system32\{6B2523DA-E8D2-4F2D-939E-704C92A85E11}.exe
C:\WINDOWS\system32\{F052EF43-5CB5-41C8-9DE7-3FD889D962D7}.exe
C:\WINDOWS\system32\{70E123D4-293F-4077-A45E-8378864E2503}.exe
C:\WINDOWS\system32\{8F03031C-5B2B-4329-8999-76CF370E544E}.exe
C:\WINDOWS\system32\{E191E346-5F91-4148-8BA8-67DAAC973961}.exe
C:\WINDOWS\system32\{4EA0DC9E-9EFF-4B0D-AB1F-F449BA41BEF9}.exe
C:\WINDOWS\system32\{800D764A-143E-4A3D-BA24-A169DA9AC6A2}.exe
C:\WINDOWS\system32\{DBFD2D35-33FD-42E9-BFC3-4C641917E64A}.exe
  • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
  • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).
If your computer does not restart automatically, please restart it manually.

If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run Killbox, click here to download and run missingfilesetup.exe. Then try Killbox again.

Post back a fresh HijackThis log (from normal mode) and I will take another look.
  • 0

#7
Crustyoldbloke

Crustyoldbloke

    Old Malware Surgeon with a shaky scalpel

  • Retired Staff
  • 15,131 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0

#8
Crustyoldbloke

Crustyoldbloke

    Old Malware Surgeon with a shaky scalpel

  • Retired Staff
  • 15,131 posts
Re-opened at the request of the topic starter.
  • 0

#9
Crustyoldbloke

Crustyoldbloke

    Old Malware Surgeon with a shaky scalpel

  • Retired Staff
  • 15,131 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP