Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Hijack This Log and questions [RESOLVED]


  • This topic is locked This topic is locked

#1
Redlazer

Redlazer

    Member

  • Member
  • PipPip
  • 82 posts
Ok, im back with a few problems once again.

Also, being a computer technician, i would appreciate it if someone could either explain to me, or point me in the right direction, of how to determine what is good and what is not with Hijack This.

For example, i dont understand how to determine which IP Address ranges are good and which are bad with the NameServers, and other things.

Thank you for your help : )

Heres my log:

Logfile of HijackThis v1.99.1
Scan saved at 11:37:07 AM, on 9/8/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Belkin Wireless Network Utility\WLService.exe
C:\Belkin Wireless Network Utility\WLanCfgG.exe
C:\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Trend Micro\Internet Security 2005\pccguide.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Trillian\trillian.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\TRENDM~1\INTERN~1\tmproxy.exe
C:\Documents and Settings\Fred\Desktop\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\TRENDM~1\INTERN~1\TSC.EXE

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - D:\Flashget\jccatch.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - D:\Flashget\fgiebar.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Trend Micro\Internet Security 2005\pccguide.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [adffq.exe] C:\WINDOWS\system32\adffq.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [KillAndClean] "C:\Program Files\KillAndClean\KillAndClean.exe"
O4 - Startup: Folding@Home 5.03.lnk = ?
O8 - Extra context menu item: Download All by FlashGet - D:\Flashget\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - D:\Flashget\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\Flashget\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\Flashget\flashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.worldofwarcraft.com
O15 - Trusted Zone: http://www.writely.com
O16 - DPF: {040F4385-8DAD-4306-94BF-B8291D841FAE} (USBAPTester Class) - http://www.nintendow...g/usbaptest.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplane...DC_2.2.2.89.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-sec.../ols3/fscax.cab
O16 - DPF: {AECD14A8-F662-11D1-A395-00805F535788} (Plotwon Control) - http://www.investors...ocx/plotwon.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{2AC55373-A462-4870-84E6-FF655C9E8960}: NameServer = 85.255.113.140,85.255.112.201
O17 - HKLM\System\CCS\Services\Tcpip\..\{354B367E-E1A4-4B8D-B00B-058C19713760}: NameServer = 85.255.113.140,85.255.112.201
O17 - HKLM\System\CCS\Services\Tcpip\..\{7F80E355-C3AB-4438-9C03-2AF01C8BE82B}: NameServer = 85.255.113.140,85.255.112.201
O17 - HKLM\System\CCS\Services\Tcpip\..\{8BACBFFA-8336-49B6-BD3B-46D5CEDCB952}: NameServer = 85.255.113.140,85.255.112.201
O17 - HKLM\System\CCS\Services\Tcpip\..\{8D6ADB90-FA8C-4CD4-B38E-9E653E636136}: NameServer = 85.255.113.140,85.255.112.201
O17 - HKLM\System\CCS\Services\Tcpip\..\{E269FDF4-FE0D-4867-AD87-88001071222D}: NameServer = 85.255.113.140,85.255.112.201
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.113.140 85.255.112.201
O17 - HKLM\System\CS1\Services\Tcpip\..\{2AC55373-A462-4870-84E6-FF655C9E8960}: NameServer = 85.255.113.140,85.255.112.201
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.113.140 85.255.112.201
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Belkin 54g Wireless USB Network Adapter (Belkin 54g Wireless USB Network Adapter Service) - Unknown owner - C:\Belkin Wireless Network Utility\WLService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Pro Home 2007.SP1\Win32\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Pro Home 2007.SP1\RpcSandraSrv.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\TRENDM~1\INTERN~1\tmproxy.exe

Oh, i have a browser Hijacker, a trojan of some sort, and a Windows-esque popup baloon.

Thanks!

-Red
  • 0

Advertisements


#2
Cookiegal

Cookiegal

    Visiting Consultant

  • Visiting Consultant
  • 889 posts
There are several sites that list startup items and whether they are good or bad but you must be careful as the nasties often use the same or similar name to valid files. A lot depends on where they are located, their properties and what else is present in the log.

Here are a few that I use:

http://castlecops.com/StartupList.html
http://www.bleepingc...r.com/startups/
http://www.answersth...es/tasklist.htm


You have a Wareout infection and I will post back with removal instructions shortly.


Concerning the O17s, if you check them at http://www.all-nettools.com/toolbox you will see they belong to Inhoster which is used by the Wareout infection.
  • 0

#3
Cookiegal

Cookiegal

    Visiting Consultant

  • Visiting Consultant
  • 889 posts
Click Here and download Killbox and save it to your desktop but don’t run it yet.


You may want to print out these instructions for reference, since you will have to restart your computer during the fix.

Please download FixWareout from one of these sites:
http://downloads.sub.../Fixwareout.exe
http://www.bleepingc.../Fixwareout.exe

Save it to your desktop and run it. Click Next, then Install, make sure "Run fixit" is checked and click Finish.

The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal.

Once the desktop loads a text file will open (report.txt), you can close it - the file has already been saved.


Open HijackThis – rescan and put a check mark beside these entries and click “fix checked”:

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

O4 - HKLM\..\Run: [adffq.exe] C:\WINDOWS\system32\adffq.exe

O4 - HKCU\..\Run: [KillAndClean] "C:\Program Files\KillAndClean\KillAndClean.exe"

O17 - HKLM\System\CCS\Services\Tcpip\..\{2AC55373-A462-4870-84E6-FF655C9E8960}: NameServer = 85.255.113.140,85.255.112.201

O17 - HKLM\System\CCS\Services\Tcpip\..\{354B367E-E1A4-4B8D-B00B-058C19713760}: NameServer = 85.255.113.140,85.255.112.201

O17 - HKLM\System\CCS\Services\Tcpip\..\{7F80E355-C3AB-4438-9C03-
2AF01C8BE82B}: NameServer = 85.255.113.140,85.255.112.201

O17 - HKLM\System\CCS\Services\Tcpip\..\{8BACBFFA-8336-49B6-BD3B-46D5CEDCB952}: NameServer = 85.255.113.140,85.255.112.201

O17 - HKLM\System\CCS\Services\Tcpip\..\{8D6ADB90-FA8C-4CD4-B38E-9E653E636136}: NameServer = 85.255.113.140,85.255.112.201

O17 - HKLM\System\CCS\Services\Tcpip\..\{E269FDF4-FE0D-4867-AD87-88001071222D}: NameServer = 85.255.113.140,85.255.112.201

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.113.140 85.255.112.201

O17 - HKLM\System\CS1\Services\Tcpip\..\{2AC55373-A462-4870-84E6-FF655C9E8960}: NameServer = 85.255.113.140,85.255.112.201

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.113.140 85.255.112.201



Then boot to safe mode:


How to restart to safe mode


Double-click on Killbox.exe to run it.
  • Put a tick by Standard File Kill.
  • In the "Full Path of File to Delete" box, copy and paste each of the following lines one at a time:

    C:\WINDOWS\system32\adffq.exe
    C:\Program Files\KillAndClean

  • Click on the button that has the red circle with the X in the middle after you enter each file.
  • It will ask for confirmation to delete the file.
  • Click Yes.
  • Continue with that procedure until you have pasted all of these in the "Paste Full Path of File to Delete" box.
  • Killbox may tell you that one or more files do not exist.
  • If that happens, just continue on with all the files. Be sure you don't miss any.
  • Next in Killbox go to Tools > Delete Temp Files
  • In the window that pops up, put a check by ALL the options there except these three:
    • XP Prefetch
    • Recent
    • History
  • Now click the Delete Selected Temp Files button.
  • Exit the Killbox.



Now we need to flush DNS but before doing the next step please write down all the settings. Note that not all system/setups even have these settings while some connection services will require them.

These instructions are basically for home users.

In the windows control panel. If you are using Windows XP's Category View, select the Network and Internet Connections category otherwise double click on Network Connections. Then right click on your default connection, usually local area connection for cable and dsl, and left click on properties. Double-click on the Internet Protocol (TCP/IP) item and select the radio dial that says Obtain DNS servers automatically

Press OK twice to get out of the properties screen and reboot if it asks.
That option might not be avaiable one some systems


Next Go start run type cmd and hit OK
type
ipconfig /flushdns
then hit enter, type exit hit enter
(that space between g and / is needed)


Finally, please post the contents of the text file that opened earlier (you can find it at C:\fixwareout\report.txt ), along with a new HijackThis log into this topic.
  • 0

#4
Redlazer

Redlazer

    Member

  • Topic Starter
  • Member
  • PipPip
  • 82 posts
Ok, all done!

New logs:

Logfile of HijackThis v1.99.1
Scan saved at 12:29:24 PM, on 9/9/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Belkin Wireless Network Utility\WLService.exe
C:\Belkin Wireless Network Utility\WLanCfgG.exe
C:\ewido anti-spyware 4.0\guard.exe
C:\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Trend Micro\Internet Security 2005\pccguide.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Fred\Desktop\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - D:\Flashget\jccatch.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - D:\Flashget\fgiebar.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Trend Micro\Internet Security 2005\pccguide.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - Startup: Folding@Home 5.03.lnk = ?
O8 - Extra context menu item: Download All by FlashGet - D:\Flashget\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - D:\Flashget\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\Flashget\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\Flashget\flashget.exe
O15 - Trusted Zone: http://www.worldofwarcraft.com
O15 - Trusted Zone: http://www.writely.com
O16 - DPF: {040F4385-8DAD-4306-94BF-B8291D841FAE} (USBAPTester Class) - http://www.nintendow...g/usbaptest.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplane...DC_2.2.2.89.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-sec.../ols3/fscax.cab
O16 - DPF: {AECD14A8-F662-11D1-A395-00805F535788} (Plotwon Control) - http://www.investors...ocx/plotwon.ocx
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Belkin 54g Wireless USB Network Adapter (Belkin 54g Wireless USB Network Adapter Service) - Unknown owner - C:\Belkin Wireless Network Utility\WLService.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Pro Home 2007.SP1\Win32\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Pro Home 2007.SP1\RpcSandraSrv.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\TRENDM~1\INTERN~1\tmproxy.exe

--------


Fixwareout ver 1.003
Last edited 8/11/2006
Post this report in the forums please

Reg Entries that were deleted
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}66647E32253B-66CB-F904-22F3-3C6EA5E5{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}331CCD120F83-C2DB-1B54-FA79-6AB08FFB{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6CC37B79E86E-EFE9-0A44-198C-B4FE7E1C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}EA4D635E9BBD-3219-2634-03E7-4B46F1CC{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5B9520E72637-7BB8-FF54-3875-4BF3E454{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}831DBE532A2C-DDA9-14C4-6831-0D4C1C38{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}063E31C8DA7E-6AFA-0134-4556-A09FA140{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}21C8E27AE317-3299-2964-CF73-0824B308{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}29A628752D64-98A9-0E24-22A3-92069CB0{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B101525609DA-6BC9-F784-4EBF-ED2491E5{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8FB01DF58B2B-8088-C644-3E61-471D0B25{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5AE802B6D5CF-C588-B384-DE3C-9C3E6AD7{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}425676C4A241-DCF9-8074-61C0-1A04CED2{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}82647A05088C-D138-9084-5B3E-BBADC5BA{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5371646ABB70-1EC9-E304-3572-79C5E1F3{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}339800E82561-DC98-7644-6C39-DC41E70B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}95859D7E27CC-C468-8894-8310-34683273{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8CE99DAE942D-BA2B-8FD4-6461-34E2DA26{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4CA84F86F62A-27CA-E724-D386-98E99196{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}69AF7C4B22AE-1919-1654-3F3E-049F2048{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E58471BCD075-577B-3984-2EFD-85ABD7CC{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7675902B1D93-746A-9624-FA53-BA8BE753{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}20ABBC0BCB47-493A-8E54-5CC5-3ECF0441{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C4333815D866-CF6A-8AC4-A599-6C59FC96{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9B710B400305-4A9A-E124-0B6F-7CB1B06E{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CEB71CE5B45D-8C5B-3AB4-7D84-0F254423{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CBD684EDB7DC-438A-8C94-238F-D24FB530{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F5E7D64C586D-8A1A-0AD4-A25C-94F1BF1E{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A3E0917276B9-527B-7A84-5D5B-EAD26F29{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0613CC5F37C0-A4D8-F324-5540-C676BC3A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2F303027CA3D-61E8-1EC4-9967-87A5C63E{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C3A30FCB8AA4-7FEB-7F94-B7C5-6F4B666B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4BE3D44EB479-9048-CFE4-25DF-FD7D0DE0{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4103A898606E-00E8-45C4-C717-1BCD9531{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F1961C78BCC5-B33B-F944-1E8B-C6533034{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D88E05028D4B-60B8-7604-305A-BEEDD95E{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C81E4644907D-BA09-8664-66A2-C31AF94D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}500F2AA0A2E6-0E1A-20E4-0AAE-56B7E8CC{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}87248A266535-01CA-0924-3E95-710A136D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}000E61F1D0B4-DB08-B224-E347-02F85870{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}631DDE98B97A-A8BB-6224-DE97-9650A2B2{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5A64D87AA2D5-7FCB-2BA4-09FE-1BD9A3EC{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B1640697E8A6-E608-4EC4-DD11-A403E707{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D45097AE5C08-EDD9-C324-72B2-AD73BC86{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6DE1BC25F98A-084A-2DC4-5180-98BF9D49{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}60884D1EB0D4-BC08-3CC4-9A9E-284EAB97{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1F622C79FD90-D84A-C944-7687-8718996B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A8833DC9BB64-477B-7924-E392-B0147CAC{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}50F026F44077-E229-96D4-3200-85E452B8{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}50A97C7F07D3-AD69-49E4-0F72-4DA4BE93{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}17E7DEA10C2D-94A8-5F94-D812-46944F8C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4162872FC24B-E1E8-B874-A964-6E500592{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}053D211F7C15-5D4A-AF64-3A34-1992E494{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}BDE75563DC67-847B-5374-8CDA-0E9EFF0C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}07E998FC77A3-5558-2344-89C5-40F05320{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}909BE2CB7CC2-5738-FB64-B2F3-CA792566{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4775821C3FD9-576B-E0B4-0157-31B96CDB{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}DE366223881F-4E18-E194-1007-9073BE63{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E2D700DD0E6F-C0BA-8A14-0337-9A6701D7{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}63A404D34946-C229-E694-4CDE-2A80FC91{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3FA643761183-4359-DCC4-A0AC-D5DF57A6{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}96AEE8E0054B-A38A-1274-ED44-75A73D97{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}53A1A31F1750-21BA-8564-85C1-BF954065{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}ADDDA3B6DAA5-1E3B-0F44-203C-BE0DF61B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C23D9CA9F27D-69BB-8EE4-8211-41E20E88{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C0093F31CD8E-55E9-3554-0912-1FB089F9{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6B6493603160-4838-D724-E1F7-168EA85E{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3B9B141786B5-527B-E0B4-7D2C-33473550{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}ECE957370571-CCBB-F214-141C-56A00B0E{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F848443D4B68-A999-8DD4-F5D4-77A866CE{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}23C7E27DB228-3C4B-F2F4-0AAB-37464A6C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}DC16A8D6482B-03F9-C694-B97F-F505055A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6066F5D3190F-DE7A-F4E4-0150-C3AB0099{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B9FE1C02FEDA-59D9-ACD4-F4DD-C41A875D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3767174B3AE4-DBC8-5504-2910-865D5C89{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4C4D85E919BF-F0EB-C0D4-9662-9FFA9CBF{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}DCF1DCA5161C-1A29-F784-E715-EA07AF22{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}DA2A9EB8CC3B-A988-81F4-1643-9CAAE62B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0909B340CF67-7DD8-6DE4-F006-E893291E{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D4DE90A93619-C2DA-5CE4-891A-793CFB2A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6B718F1A66FB-68E9-78B4-D738-A832418B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AD886282AC72-8C69-DB04-A02A-E6C8095B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A492F8C0D84C-646A-9CD4-97A6-70AC539D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}DFBA74ACC74B-9138-4D94-6087-3EDA0F01{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}87271681F453-C11B-03B4-CD04-2F0026C3{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9B46DDFED37D-4DC9-C524-B636-49F7E7BC{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2A55078F0A2D-250B-0D74-37E7-0924F8FE{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D1EB63F5EB05-640B-DA94-D44E-1AE43804{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3FC25748136D-978A-17F4-D4BB-402BA099{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}95D865E41A8B-7F6B-5B94-BA68-18BFE020{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}EB39A66326B9-3778-A444-5813-0BC008E5{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0266524A28E1-D4B9-84B4-DC8C-29CAFDAE{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CD333A9DCFE8-3D5B-9B34-286C-F10F84AA{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}69D6E3184B86-F46B-B494-43C1-C52FB1F5{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0A6C77AB6858-F8E8-86C4-E4D9-32EB0500{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2270FEF3BFD1-DDAB-82C4-FD63-70C24341{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5CE5A7959D52-3108-7374-7746-F79B8EAC{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}BEB8219D7AB1-60B8-EE44-5CA1-3BE7FE51{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A0D05250C595-B8EA-70C4-27D1-378823EC{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A96B451186A7-D6A9-FF74-5251-35096575{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8A462B23D008-2DBA-6DE4-B92E-69891BDA{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}BFEA4CC64025-8B3B-8954-7AE3-3B527C28{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5F1E145D50D4-5809-3E44-F63C-DDC23CB7{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}94288BBF3157-6A79-FD64-9809-E3231C30{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D2A68493E428-E1D8-DFC4-BC12-AACCB1DF{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}85ECA3DD1469-F51B-2434-CDD7-8A709F0A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0F12251C0F0D-3FAB-33A4-C4AB-D45708D9{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3F920CACBCEF-0B39-7C04-6F5A-A2D5D307{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}434AABA26736-F3D9-5804-E676-F0780522{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7BFBD25D6304-BA1A-7AD4-AA00-60F4B772{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CC5D97F1944E-4588-68F4-7795-8D012357{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}DBC867F02FDC-68D8-DC34-4E7D-9853D424{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}079175601CD2-1B29-7F94-19FF-54F0E9BB{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C8567D513FC6-5108-9154-607B-7DBE9AEE{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}38C8A1609E2F-F2EA-7174-8558-9BC2025B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}158140F024F9-E939-7AE4-71A9-48AFAA41{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FB0F7BC1BAB7-9908-9404-0674-43DF631B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5CF5E843D3A9-9BAA-0D24-6CAC-6E96793B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3590BA6904E6-EAF9-4CC4-2C12-1E04FA9E{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CC5583C452AA-FEDB-CA94-0AE7-B5A1F88D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}80AAF9564C44-516A-8B44-F100-21D3720C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3C16E2936DAC-1D9B-4444-66CC-F80537C6{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0D9A38EA63D7-1D69-3464-708B-A798F6AF{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}762E9616367E-6C2A-0274-EA09-1F00DBAA{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9B30FFFE3C47-A5B9-A174-72BB-F0B09B37{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6AD7C33C3C09-A54A-1F44-2327-4D38C07D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9A1F13D9CEE8-4A8A-9874-C2C7-91515A85{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}427BCFBFBA7E-0748-EA94-CA14-593B9239{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AE212EF3F5FC-EA99-0294-3D7C-734D1F36{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0576F5E69244-1FEB-BCE4-9950-94CB3225{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7BF9076BCD2F-CCDB-2624-EBF7-E6399A09{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4DAB8CC8A16D-A369-CE34-19CC-A0ECDC7D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C11B0901FCC4-5F89-3414-DC44-379CDCE1{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E0D27A0B63E0-BBB8-B114-AE75-A0FC1706{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}BEA5A23C7119-3609-9214-3E6D-8AA80D07{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}EE46203BAC70-1EE9-36D4-8980-0A3DA9FA{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}13B03F80ACCA-42DB-AD04-0314-9B1A9A75{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E646F53828F3-E6DB-0CC4-E323-DDF074CB{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}502F18D6C6D2-9928-D7D4-B266-1799C59D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2D9EFD7BBC49-140B-8F04-A6A9-5068C78D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5BEE9DCF8FF7-CFB8-D6D4-9FA1-7717AAF9{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}26D884DF99AA-CC6A-AD34-61CF-FF870157{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}EFE03992032B-4D18-7354-C63E-6BE0795B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}611C0B4FB98E-6B2A-2034-9D5E-844CB698{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B5916C1852C2-67A9-6B04-181E-244F8870{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B6A04120C1F8-6B68-4804-D298-54ED51F1{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A4ED203B372B-5259-AAE4-9F34-41E42096{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7E60D73FD602-0EF8-CFB4-995D-95A6AD4C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C0AB780F84E3-B9B9-4D24-EA4F-11FF1707{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3164977C4C99-B59A-56A4-8141-C2296481{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}878158D3A4B2-4DFB-0D64-84F8-FE68799A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CACD963174A2-9EAB-D794-CE4E-81A13B18{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}00FBF2FBA859-DD59-07C4-29D7-148E590F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C2B7F0523B60-DBEB-7F04-9612-954CB00A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}10DC48CF9A3A-EB1A-1654-151C-CBAD5FB6{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8C66F62B089E-33EB-9D54-29D7-A18C48D3{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A3651A4BCA94-129A-9424-879A-64541483{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}865DAD86A601-EB9B-C554-8DAD-6F56234F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8D33F9516573-C069-9054-52BB-1E27215C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4F503036CB70-F669-DDF4-0C27-F0AA2F2B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B52624F5F476-3EC8-A134-56FD-8EB14601{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}044ACFE8BDDA-79BB-07B4-2602-3805056A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}43D61F803130-E0B8-00E4-AAB4-677C67AA{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0D2D882A5E69-265A-79C4-3972-D978E006{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C01039CBAB11-0789-FA34-C3BC-0018435A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}ABADB1402385-CBFB-F544-4F1D-A7972CB5{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D50ABA375CFC-C41B-7434-99F3-E849E7AB{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}531F6682160E-3629-92E4-7E7F-5654DEFF{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3A07959AA41D-9E6A-F954-3D33-CB1E7D17{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FB75EEEBC3B3-FC3A-E384-03C5-EA7403A0{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}462267C71180-FB5A-0FB4-6A62-28DC307C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}80D7C34E2718-C1D9-0694-8497-B6FF9D7A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6065C485A537-D819-A314-F28B-3572124C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4ECB0F419080-42AB-4024-8311-65F04114{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}48C0653DD526-3598-36D4-0B86-935325A4{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A0628F35EAC1-C7EB-D7F4-3938-70A6793E{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9A44132B5ECB-5DEA-C104-FDD9-A44F8833{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7A44CF49B8B6-2569-0D64-05B8-F79972B2{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0A7EB99C5B6A-2D3B-D3E4-E3B6-F3A50E4D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FCE9940B027B-F859-B0F4-C84F-7094D9A5{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A0D84C2CFD81-1AD9-2254-FB75-7663E9EA{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3A105619F2D0-CDF8-E094-8CB9-8A37E6EA{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6BCCE9DC6965-3E2A-B634-2CE7-EB2789C4{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}854A99F46F43-52DA-4F94-CED9-EFA73522{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7427386432D4-E69B-EC44-A86C-23D0C51C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CF00AFE840ED-EF59-2584-27E7-F2B3E5FF{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0BEB79EF1C9E-A0B8-7424-E5B0-FCC795DC{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5B901E13FB91-864B-A8E4-5B7E-872480E8{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AE0979A720B1-397B-13F4-366D-DCBBEE55{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4E97358FA3CE-A61B-CC44-B3D4-EE1039C5{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}BA3E5149E7F8-7848-5434-BBAD-C1949200{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FB6D8AE0F58D-194B-8AF4-99E9-F46EF56A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9315EE751D11-3688-8314-B069-88F2406A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5A97BBCEEE23-6429-2AF4-2BDD-B0AC649F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}28915CD2001B-5A69-26B4-952F-254A9D32{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}DE0E0D3F9D2F-ADD8-4FF4-21C8-84835CC2{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}67F3658799A3-91AA-14D4-FDCC-3753A98F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A3CB7FAEAC76-915A-6DC4-CE39-4F33C1E2{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}56F201392A30-61B8-1674-1C71-FE4DD56B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3697D409C5C4-3899-A4A4-3854-7AFCD8F2{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}74BF0CF930EC-79FA-3944-18C2-8F945D08{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}53F52817AF32-9C78-5D34-3302-485A474E{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}869D22F35D2E-3F5B-8694-0A4A-A52AA489{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}EF4FDDE5C1CC-F9CA-8544-D29C-1CC28CA2{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7D029556702B-CCA9-ECD4-6966-8643F91F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8F4E6C12AAD3-E77B-F924-A485-C8AD798E{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}026950B0D599-0D4B-C4C4-754E-0F89D55F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}24A1980ABFE5-C1EB-B064-1F7A-6EC8B5AE{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6092678ED962-0E18-05E4-7661-04BBC2B9{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1856861EBA61-D1C8-BC64-4D5B-B3E47281{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}18498FC829A1-98FA-6394-3D44-11E3ECEB{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A4846D4B055E-6999-3A64-F65D-4E8A6480{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A26155B6860F-2738-33C4-5635-BD306921{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}698121976A2F-B94B-E4C4-EC70-D494D541{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C8830D1A282D-F7AA-7F24-64EB-E12116ED{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9805BA871E46-D1A8-3F94-14B4-4686AAFF{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7F4B2E43546B-367A-BFB4-B0D9-79BFF821{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D65B801A8A81-B99A-A224-58D0-474111EF{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}DCD506C62765-9AD8-56D4-B786-2AA5242E{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7BF0135694FC-3CA8-0C44-9AF7-0370AC7A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}76920559FDFB-609B-0CC4-C8ED-757500EC{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5D35C7B6DE61-0E59-1F34-50A0-06E15131{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F3A98C159919-C668-BBA4-7192-04F63BB7{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F0E8F8289E9C-978A-BE34-9B55-A32C4114{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2BCD3EFABA4C-EF19-1374-B2FB-A650F7C7{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}38B281DA55B9-5319-A5F4-389D-798CF8E5{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4FBDD63CD8D0-A65B-3AD4-EE54-399FBFF1{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0943E44F35A7-E738-F684-2661-0D8FA425{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4D45627C2A01-6D49-4A74-1315-0337DC96{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A7CCE9EBC11A-6BB8-9D04-29B8-E73EA9F7{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}ACF283C63712-9CA8-5984-7A92-2E16575F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FB01D0C92FC5-544B-6DC4-37EE-9E47641B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}71A0C036840B-A27B-2724-F77E-58E4FEB0{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9E85F2F68FB5-9B2B-01F4-3E19-E4538C8F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}BB18DEF6BED0-682A-1D44-FCF2-F2174FDA{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7302D7B2BF63-DA88-0CA4-CB13-61B27E10{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6EE50EB2557D-F08B-AC34-D498-9C735C67{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F7DAE2B4C5BE-4C99-C504-6829-9FFADE21{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}960EA97F3A2F-53FB-8594-51F5-18A24F3E{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E77289917190-FA69-2784-3A94-976ED4A3{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AF7E52887010-E18B-27A4-4D00-1B3CD0BB{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}69AEAF5C7FBD-3DE8-F484-E000-8FF7C17B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}75443F217FD1-7F39-8564-289F-A2E7655F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4315ACB5A899-7BA8-8ED4-916F-9FA2FFD5{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}60433B4C74AF-B57A-0E24-49D8-CB28E1FB{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CEE8BD659083-DA5B-4154-C505-A4D7CC46{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CBD867AD54B5-8E3A-FD94-6C4D-0940896B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}93BEF9C335B0-16D9-6574-DB1C-D054AD96{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9F9398729EFD-141B-8C54-F709-70480B13{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FE3B19FD4C84-6E5B-EAF4-23E9-149ABBBC{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C09180BC917E-5BDA-E1D4-8BC7-F6C461B6{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6F62883B2717-2689-3354-2E13-D59EA6ED{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\bjwmd
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CAC4FEA1B4E8-8F29-0074-4C13-EA25984D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1D5C174F20BA-BE6A-01E4-4DA1-763C2047{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8F5CBD04E623-E59B-2384-BFA6-51DEB0BA{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}03BE3E78FCA9-9CF9-BC44-FBD3-8C8B1297{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}EE3A9BA5D6F8-65AB-D604-1096-76B3369F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0EBF5E3404D6-2E48-3C94-72E1-04CED000{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8804979E842D-512B-E874-D4DB-02B405AF{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}059647477EB7-70FB-BDF4-D87C-22006F18{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}ADCA7AE172B7-4C3A-4B34-831E-6B3DF1C7{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0AB423A2A7DB-F23B-A914-4627-450C2B87{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}977B601C74AA-AB28-8BC4-6A2F-4CAEB010{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D9220B02FC18-C798-3224-4627-89837E96{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A27A5626B625-EFD9-63E4-4BC7-19B2C415{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}20040AEE0B49-2979-F924-29E9-FEDC7498{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B09B55C05343-4E4B-F084-7961-53D21269{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}73B1872BE58E-8BD9-5B24-9E54-3A7CF0CC{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}394684EDF39F-750A-99F4-D76C-6FEACF17{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AD539DD2BC98-597B-2BE4-3B28-1665AFFA{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}755F687C47A7-85BB-6724-8443-BD75F3C8{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B592F008C402-9FBB-1A54-FA8B-20BEF961{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F67FC7A5F39C-367A-4604-2EB6-7F7C03CD{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0A26697EC673-113B-B604-43FA-EA791641{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}383DBCECBF1B-C8D8-8794-7840-CC7B5FAB{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0714CF5FF44D-F008-D534-E4FB-CDBDB8C1{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}36593E0C868A-D298-E174-A4D3-5F3DF137{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E81F1D015F4B-E5A8-54F4-F124-4EA011B6{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7EA0DC3F3531-B159-12E4-B784-5C692FCB{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}22C28C982505-702B-55A4-1102-04C2D036{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}418A138BF734-ED39-33C4-E735-3076281A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6E84A7EE10FC-9EA9-9374-5294-4EB86F06{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AF245D4C8FF0-1939-79A4-3DB7-54BC966D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0A2260C9493D-C71B-9014-A11C-1F512D74{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}153A09D41413-7D58-6D84-0613-0C8E0B6F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}DE51A1488AD2-3639-7734-5A2A-E4F93F9A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}469DD61153F5-4B89-F034-80A7-8F9B0014{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A5BF11E08AD0-8E79-B954-6C08-10E4B1C3{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2FDF9E50358B-35DB-9464-DA41-6678C547{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2BE2CDD3F269-FB4B-1E04-A95E-653CAF11{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E7C38D435731-15AA-3294-D8B6-300D2436{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1C74D9291839-C4EA-B9C4-83E7-D6349C8E{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}EE2D5A87BE9B-BB1A-DFA4-6AE5-B85FF216{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F2163F41177B-7EEA-3D64-A0D3-25424655{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}64FA046C4801-88B8-B874-C9C8-991D79FC{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}10F4E1165AC2-E8CB-2CA4-27BA-5E40D72F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5D915DF50E1D-4959-8994-6B7C-5603E73D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0366A37743B0-9908-84E4-8211-E9A9C7E9{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D53DDE14DC8E-B4D9-9B94-FB29-D69C3E4C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4F9D6BB0BBA3-776A-8CE4-B723-969BCF16{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}99D7DDDCAE2F-0739-87D4-A425-B88DB9A8{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4516BAD3551C-14E8-FCD4-2ABA-7A3CFEC7{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1DA11FEBD5D7-146A-BFD4-1176-1703185F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D1A8C0516C0F-B41A-1914-6B0C-B668BC40{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FDCAB46E215B-2E1B-C094-4A2B-80E13F93{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4F17C83E9FED-F668-3DC4-6ABE-A326C3CA{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B19E4880BC62-28D9-9AF4-A4CA-28E02586{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}091E4A2E3FCB-85EA-55D4-E3E8-3C1F6FD8{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}024DBC98E488-E268-AB74-4E50-5BB4D551{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5F13CB7056FC-A259-B504-5FD9-7550C533{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}46F9F2B8E173-C498-2604-33E9-AF4DB228{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}BED215620BA1-4DFB-4734-784E-C0560265{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8A22ECD438B2-77FB-2604-7FD8-F24DB5EE{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}52F9067AA579-2A68-A564-1F75-8D538E65{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}BE3B1FC3AB3F-EA9A-F844-5E94-31619FEE{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4F49A2087792-D34B-EBE4-1A0B-D5F54085{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3D010538DC9F-F32B-7DD4-94CF-EC274BAA{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1DD11D1204FE-B76A-05F4-B8A9-289D59EC{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}824A79FDC4DC-1299-FE44-68DA-CD01C621{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}40B72CFF8575-92E9-6B94-93D0-BBA428B9{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4A9B8CBB64CA-5E98-6954-41F3-0FF2E773{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E78E7B0055F5-9A0B-47F4-ECB9-594F8F0B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}EA9DACFF8CC1-E218-4624-60BE-E2199AAF{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}56E683BE715D-C2B9-5264-5672-DF15116D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AE107DC8108A-7DBA-B134-C5DE-A81457AC{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}BDF9A81CA654-E4BB-0F54-D012-D68BE607{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5EDF50417A81-86FA-B034-1865-7F76D06B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4F69766C0F50-34DA-5274-17D6-693CE88B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3F2D82A85D43-E839-AD14-998D-B8D569B1{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3A3062A43C09-68A9-DBF4-95E9-2C56EA2C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0A81DF81FBA5-D0B9-0404-CE6F-9F8BA1A7{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4E88FFD670E2-ADA9-B394-0977-0E89B1B1{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}BFF9A3CA5175-4EFB-D0B4-0C56-43BE99B8{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}EC5B43726018-313B-1E04-9CEC-35D143C9{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C1DF52A34440-424A-F094-BAA9-235D5635{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E877AD26C390-24B8-87A4-2AE7-C5D72868{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}DBCCBC633841-BA08-0B64-BEB6-143A612B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5E3522C718C8-4F6B-1AB4-9872-BAC427DA{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E46E82676D9C-BACB-05A4-B97C-CCD3EB22{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FCE4CF061E97-F9D9-4854-FADE-70909F29{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4E05F37EF8A2-BB2A-C5A4-CA70-F5E4CFF3{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8348CE0289D5-0B78-7154-6860-8CFE297A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}961D81C804A8-BD7A-2FD4-D75E-0F041EDA{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}04149BD0D6DD-B8EA-1414-2E73-29832B29{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AD84E95DF9AE-ACBA-3174-2AEA-3814B1F7{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}434F43D5EC44-0A1A-3FA4-0AAD-8881AF39{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9EDF3BCCB064-219B-4BE4-E649-56088768{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9DD0967E0554-AB1B-3194-DC62-40158492{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8950EB6A4683-1C89-BCF4-9B8E-A76D122F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A0D45B0AEB17-9E68-B7D4-9037-217FF317{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}20ECCE2AEE0A-FF6A-6EB4-BC89-7E272277{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}40877B3C1DF7-D5AA-85C4-108F-8A9D021A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}046F6488785C-350A-9014-789E-5EF51FBB{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2B7A9FB639B2-777B-7234-743F-06E9A0D5{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8607C4F4B664-A399-9774-6ABC-D590FB3D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2497256529BA-197A-B864-3C07-7DE09E2A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}31EEE7A30A80-EF19-0004-96EB-21BF1710{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}104E1F6B4E05-C598-8244-7949-D6362AB8{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0CFE32448DDC-7938-47B4-95A0-68DF366D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9D435CB992B3-C90A-3974-9292-3324B77D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2F686B7B30CE-43B9-E464-DD94-2E89B9EB{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C176248F0836-4C79-CB54-507C-62243421{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}90D4185D9A39-1278-A1A4-2F2D-7AB847B9{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1548E1055640-5F89-7444-7BC9-6FECD5D7{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E008C1C90A7C-17D9-A664-D9B6-0AA2D244{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}935C83A5F961-177A-62F4-0612-81C54EA4{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}824441595A76-778B-FCD4-CDE4-198C6D3A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CA9FDD7F6D07-C9C8-9C04-EFA6-2EF3A0E1{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}999272A63DC5-B839-0204-8463-8B6B9B0F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8D81F2FC1800-9BD9-DC44-6413-3F8BD82E{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}BDE797D24A33-F3F8-9D44-ECB1-A3766958{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}EADE1009092C-5C39-0ED4-90DB-333253DC{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}722DEC7BAFFB-728B-65F4-485E-D32DD79D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}75D24FAEE2A2-9F99-9A64-1C8F-4E06C32F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}ABD4ED8113F2-4699-07A4-9D97-072A36E6{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}147FB7773CD1-F6CA-DDC4-8BBE-B1B5E1D3{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AD9FBF111F8B-5579-E6A4-A30A-904EBDC9{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AA8D7D75AFB6-F6C8-3684-9221-9A0C83D7{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8BB382F0C191-A00A-5174-9839-02E90E44{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}BDE1F1FF6B8B-3378-8D84-E03B-259DFB74{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}98D1C5A0FFA1-FF4B-ED94-C8F0-4317D30C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}63CA103740C5-3EF9-28A4-24D6-FBBF4F23{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A1222A5182D5-6C6B-3F94-568C-6DF92423{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F50AE55BB740-42B8-8CC4-2A99-7332AE24{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}038C2EB87AAF-893A-8094-11B8-6BAF684E{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9A92F962A540-371A-E654-E051-06D6B410{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8C1A89C7AA89-7458-E7F4-B082-5B62FF2F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5F876064E1A2-2DF8-9374-438E-B6A59F3A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}414439CB89D7-499A-6E04-C7FA-DCCF22FF{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}BAAFAC066942-0C3A-DB44-B5C9-FBE3CD89{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E8B98FA61AD3-DEFB-92E4-1462-CB7FD43E{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A804D06EC57A-83A8-7B44-B9CC-2C2A7204{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}DDEF5E63EBF1-2C38-5014-023C-CF70CC63{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7311D811255B-587B-8F84-AB79-DC9A722A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A400460D4028-CFCA-2E74-0D1D-52E230C2{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0707F00A1B52-C619-0F24-7E88-58F17C75{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}439F83F777CB-0699-6104-4802-ECFC16D0{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A04AD1F88B30-F979-14C4-27E4-E4C57818{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AE3A119DEEC5-996B-E384-7043-5D7A3967{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8595040984C5-4FAA-3524-73A7-22D355A6{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D7802280388A-0D98-EF24-6427-9706BF71{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8B23C337A5A1-BBA8-2CA4-7CEF-71011C0C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6E8A493AE454-FDD9-1134-1F4A-841D9879{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1032FE0EB804-C4FA-7104-BDE1-F2A159BE{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5AFBC6AFE549-25FA-E274-0C13-A70311AE{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}DAB17E7177E3-0F9B-0A04-72B7-5C2D012A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}BCA65E6597AF-88AA-F4B4-E1D9-A18811FE{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B5CA466FE5F8-2A8A-E5B4-E0AF-5AE7B670{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windo
  • 0

#5
Cookiegal

Cookiegal

    Visiting Consultant

  • Visiting Consultant
  • 889 posts
Did you add these sites to the trusted zone intentionally?


The log looks good. How are things running?
  • 0

#6
Redlazer

Redlazer

    Member

  • Topic Starter
  • Member
  • PipPip
  • 82 posts
yes i did. And i do frequently check that list. hehe

Way better. So nice to get rid of that lag and that virus. Thanks a bunch!

-Red
  • 0

#7
Cookiegal

Cookiegal

    Visiting Consultant

  • Visiting Consultant
  • 889 posts
That's good. I would like to do an on-line scan just for good measure.

Please go HERE to run Panda's ActiveScan
  • Once you are on the Panda site click the Scan your PC button
  • A new window will open...click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan report

  • 0

#8
Redlazer

Redlazer

    Member

  • Topic Starter
  • Member
  • PipPip
  • 82 posts
Sorry i took so long. Here's the Panda log.

The results are probably from browsing done in that past couple days - although ive never seen them before. I realize they are just cookies, so they couldnt be too bad.

Also worth noting is that i have a tiny window on my desktop, which i can move, but does not show up in Task Manager, Alt+Tab, or has a right click menu. Alt+F4 does close it - but it cant be a good thing, lol.

Any ideas?

Log:


Incident Status Location

Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Fred\Cookies\[email protected][2].txt
Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\Fred\Cookies\fred@bluestreak[2].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Fred\Cookies\fred@go[2].txt


-Fred

Edited by Redlazer, 11 September 2006 - 09:44 AM.

  • 0

#9
Cookiegal

Cookiegal

    Visiting Consultant

  • Visiting Consultant
  • 889 posts
Can you post a screen shot of it please?
  • 0

#10
Redlazer

Redlazer

    Member

  • Topic Starter
  • Member
  • PipPip
  • 82 posts
After i rebooted, its gone. i Swear i had rebooted before and it came back - but whatever.

Although, i just managed to recover from a very strange issue - my desktop would not load. I do not know why, but it is working now.

I checked explorer.exe, and it was loaded - i forced it to close and reloaded, and nothing changed. I opened two other instances of explorer.exe, and nothing changed.

I rebooted, nothing changed.

Safe mode worked fine.

Locked up on the login screen.

Hard reset brought me back to a fully functional desktop.

A similar technique worked with Vista - but XP and Vista are quite different. And, Vista is not longer on my computer. hehe.

-Red
  • 0

#11
Redlazer

Redlazer

    Member

  • Topic Starter
  • Member
  • PipPip
  • 82 posts
So, i gave up.

Everything was working ok, but there where strange problems here and there, so i gave in, bought a new HDD, and reformatted.

Everythings happy now : )

-Red
  • 0

#12
Cookiegal

Cookiegal

    Visiting Consultant

  • Visiting Consultant
  • 889 posts
I'm sorry but I didn't receive a notification of your previous reply, just this last one, or I would have replied sooner.

I'm sorry you found it necessary to go that route but at least you know you're starting fresh with no problems.

Good luck! :whistling:
  • 0

#13
Redlazer

Redlazer

    Member

  • Topic Starter
  • Member
  • PipPip
  • 82 posts
i think it was hard problems. Ive had that drive for years - i guess its finally time to lay it to rest : (

-Fred
  • 0

#14
Cookiegal

Cookiegal

    Visiting Consultant

  • Visiting Consultant
  • 889 posts
Eventually, yes. Especially if you've never reformatted. The system would become unstable. :whistling:
  • 0

#15
Cookiegal

Cookiegal

    Visiting Consultant

  • Visiting Consultant
  • 889 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :whistling:

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP