Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

bad spyware, malware infection


  • Please log in to reply

#1
guruwannabe

guruwannabe

    Member

  • Member
  • PipPip
  • 14 posts
It is in the task bar, can't be clicked on or removed. It just sits there and flashes between the two different circles and pops up all kinds of popups and webpages for virus removal software. I use McAfee and apparently this did not stop it. I ran a scan with it, then adaware, then spybot S & D. To no avail.
Here is the highjack this log that I ran. Please help me. The pop ups are out of control

Logfile of HijackThis v1.99.1
Scan saved at 12:18:28 AM, on 4/24/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\SiteAdvisor\6066\SAService.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\Video AX Object\smmain.exe
C:\Program Files\Video AX Object\bpmon.exe
C:\Program Files\Video AX Object\smmon.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Video AX Object\bpmini.exe
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\WINDOWS\System32\CTHELPER.EXE
C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\2Wire\2PortalMon.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\SiteAdvisor\6066\SiteAdv.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\MMJB.EXE
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Yahoo!\browser\ybrowser.exe
C:\Program Files\Adobe\Acrobat 6.0\Reader\AcroRd32.exe
C:\WINDOWS\System32\wisptis.exe
C:\Documents and Settings\Hammer\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapp.../search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapp...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://att.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapp...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapp.../search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapp...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapp...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: (no name) - {F423D68E-F65A-2225-943D-C76A505B0334} - UserSp1.dll (file missing)
R3 - URLSearchHook: (no name) - {4422343C-8407-265A-8366-14404A72C498} - porka_.dll (file missing)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O1 - Hosts: localhost 127.0.0.1
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {73364D99-1240-4dff-B12A-67E448373148} - C:\WINDOWS\System32\ipv6mons.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: McAfee Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - c:\program files\mcafee\mps\mcpopup.dll
O2 - BHO: (no name) - {D34F5D71-99E4-4D96-91CA-F4104F69B8AE} - C:\Program Files\Video AX Object\bpvol.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O3 - Toolbar: Protection Bar - {F0993251-2512-4710-AF6E-0A13EA199D02} - C:\Program Files\Video AX Object\splug.dll
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe"
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire\2PortalMon.exe
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [sound64] new32.exe
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6066\SiteAdv.exe
O4 - HKCU\..\Run: [TForm1] browsebar.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [KillAndClean] "C:\Program Files\KillAndClean\KillAndClean.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [br0ken] PasswdMon.exe
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [typeconf] ssweeper.exe
O4 - HKCU\..\Run: [SB Audigy 2 Startup Menu] /L:ENG
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Startup: Registration Myst V
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: AT&T Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\program files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\program files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {0713E8D2-850A-101B-AFC0-4210102A8DA7} (Microsoft ProgressBar Control, version 5.0 (SP2)) - http://download.mcaf...22/ComCtl32.cab
O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcaf...,19/mcgdmgr.cab
O16 - DPF: {FFFFFFFF-CACE-BABE-BABE-00AA0055595A} - http://www.trueswitc...eInstallSBC.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{24BF6395-1A3E-4592-AE30-DE77A624D7F2}: NameServer = 85.255.116.163,85.255.112.121
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.163 85.255.112.121
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: SiteAdvisor Service - McAfee, Inc. - C:\Program Files\SiteAdvisor\6066\SAService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE


P.S. in my haste cause i'm freaking out i had not read the do this first before posting hijack this log. If that is really important let me know and i will do that first.

Edited by guruwannabe, 23 April 2007 - 11:29 PM.

  • 0

Advertisements


#2
logreeval

logreeval

    Visiting Staff

  • Member
  • PipPipPipPip
  • 1,230 posts
Hello and welcome to GeeksToGo!

I am logreeval and will be helping you clean your computer.

Please download SmitfraudFix (by S!Ri) to your Desktop.

You should print out these instructions, or copy them to a NotePad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

Next, please reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
Once in Safe Mode, double-click on SmitfraudFix.exe
Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".

The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart it into Normal Windows.
A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply.
The report can also be found at the root of the system drive, usually at C:\rapport.txt

Warning : running option #2 on a non infected computer will remove your Desktop background.

===============

Please download FixWareout from here:
http://downloads.sub.../Fixwareout.exe

Save it to your desktop and run it. Click Next, then Install, make sure "Run fixit" is checked and click Finish.
The fix will begin; follow the prompts. If your firewall gives an alert, (because this tool will download an additional file from the internet), please don't let your firewall block it, but allow it instead.
Then you will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal.
Once the desktop loads please post the text that will open (report.txt) and a new Hijackthis log

===============

When done post the SmitfraudFix log, FixWareout log and a fresh HijackThis log.

logreeval
  • 0

#3
guruwannabe

guruwannabe

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Ok, that seems to have fixed at least the problem I new about. I'm not sure if your done fixing yet so Thanks in advance. You guys rock. Here are the three logs you requested.

SmitFraudFix v2.171

Scan done at 21:26:03.54, Tue 04/24/2007
Run from C:\Documents and Settings\Hammer\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{0e4e5110-a772-4c4a-a7dc-137fe10abd6e}"="calocarpum"

[HKEY_CLASSES_ROOT\CLSID\{0e4e5110-a772-4c4a-a7dc-137fe10abd6e}\InProcServer32]
@="C:\WINDOWS\System32\czxtyx.dll"

[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{0e4e5110-a772-4c4a-a7dc-137fe10abd6e}\InProcServer32]
@="C:\WINDOWS\System32\czxtyx.dll"


»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» hosts

localhost 127.0.0.1

»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

C:\WINDOWS\kl.exe Deleted
C:\WINDOWS\ms1.exe Deleted
C:\WINDOWS\secure32.html Deleted
C:\WINDOWS\tool1.exe Deleted
C:\WINDOWS\tool2.exe Deleted
C:\WINDOWS\tool3.exe Deleted
C:\WINDOWS\tool4.exe Deleted
C:\WINDOWS\tool5.exe Deleted
C:\WINDOWS\toolbar.exe Deleted
C:\WINDOWS\system32\czxtyx.dll Deleted
C:\WINDOWS\system32\paytime.exe Deleted
C:\DOCUME~1\Hammer\FAVORI~1\Online Security Test.url Deleted
C:\Program Files\SpywareLocked 3.5\ Deleted
C:\Program Files\Video AX Object\ Deleted

»»»»»»»»»»»»»»»»»»»»»»»» DNS



»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"="csipu.exe"


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End

Fixwareout Last edited 4/5/2007
Post this report in the forums please
...
»»»»»Prerun check
HKLM\SOFTWARE\~\Winlogon\ "System"="csipu.exe"

»»»»» System restarted

»»»»» Postrun check
HKLM\SOFTWARE\~\Winlogon\ "system"=""
....
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "pgtshlld" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "nidnsdr" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "ywbil" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "23rtcdaol" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "6" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "23rtcdool" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "23naelch" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "mrmmd" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}401D41515C6C-39F8-9534-F021-BD93F9F8{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}163A14664D5B-24B8-0B44-158F-EA34B4A2{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}B98A66F51B15-EFF8-9AD4-968A-6CCA0BCD{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}9D12F5E5B820-F789-A294-1EA1-5AA1F2FC{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}07A3DA9252EA-3B48-9884-C907-D8ED9499{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}7D267BE09680-DB2B-0334-31D7-6D4F0596{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}B22D4B332C9C-7C99-B3C4-637F-030376C3{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}BAAD7A9827C6-4D48-AC04-D45A-4FCAEDC8{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}B09F0F87D244-42A9-0294-DF55-8E580846{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}2C63601A66C7-7C78-6764-31B8-C68D6071{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}221085F760B6-262A-F5E4-C46C-FAEA9B43{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}3F929FC76E68-3648-AD14-20C4-14AC6B65{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}7505EF356195-2849-C264-3268-873B06AB{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}8762AB7A1A39-7109-2F94-5982-B9183274{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}313C28D3E57D-1598-B194-4575-1CA266EB{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}28FCF9283253-829A-5524-F815-6839EE78{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}862744CE2C53-C5BB-B524-14C0-AE59278C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}207C8AD45937-D03A-5D44-D038-AB3C8E2D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}CA061371944B-CC6B-8984-00D9-AFC7B37C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}DADE52E54882-6CEB-F124-5304-6C50BA03{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}40CEF8722CDB-1F4B-91E4-110B-AC52A5CC{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}F92112508E11-4D4B-ED44-4B88-57A167A0{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}53A382D3D0BB-B0A8-2994-5D7F-7DA99129{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4D96A5F2513A-1A9A-4134-C5EC-ECA304F9{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}3DC13E642285-7AC9-1564-AD93-91DE931A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}7117A8CF44ED-B459-3334-1759-725D14C3{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}C733971319F4-7038-20D4-B927-9D9CDE54{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}8FE3530CFBC5-6369-6484-6BAB-076C9594{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}94AD3A0CB398-3F2A-94D4-EE96-1C36B654{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}03B148316CEC-2E5A-7514-C395-F1AA2A42{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}846BA456D75A-9E39-3A44-CA96-C69EFCA4{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4E25149CD7CF-B6EB-B814-4F2E-A9267040{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}F204F972B2D2-C9F9-4354-F142-F23CD0A3{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}00AB8A064808-E12B-39E4-8996-2CDF992A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}BCF24B7DABC1-4718-FDB4-C995-A4290E5C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}90D27035E88D-36DB-37B4-3009-5155F89E{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}F69A8FBA7392-24EB-7F74-FE12-8A379CBB{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}C9797A793843-914B-C2F4-96C1-FB4C9603{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}5BEEEFD5B255-9209-73B4-64B7-22453843{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}8CDBDBED35D9-7759-4D74-D758-52D879AD{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}219C3404E14D-5DEA-CBE4-AE8F-B3BB32BC{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}D4B906B9C5CE-1B89-DB94-3F5A-E4091830{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}6599E18F4CB2-6EF8-39A4-6A3A-35E6B547{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}42397847BCD2-632B-EBD4-D908-A3A6107F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4D2971783234-E7E9-BC24-3FA7-582E1B88{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}88367D581478-C9D8-4C14-CA46-DC108035{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}003D33837266-050A-1EE4-585A-458DEEBB{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}F5E9D84B805E-5A79-2D54-E52C-9A1270BA{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}70D9EC748FFD-4B89-5934-18FC-F88A3085{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}86224C9F88B2-8EB8-A9F4-C731-74E5C981{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}68364336CA94-540A-FFB4-82BE-5FA8B893{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}9286BFDD7949-3EBA-B7A4-AF60-48B835D0{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}25DB207410F4-6828-22E4-6FB7-7DF17570{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}FF0AE26E5293-6569-A6D4-1380-AD91C077{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}AD4D2D43C3FC-7BE9-CD64-5299-AB048370{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}B77655134385-3DB8-C984-15BF-05AC69C6{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}CAB398CA3616-2958-3664-550D-B66C53D3{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}ACBF0B509E81-6C09-18A4-5211-419631CC{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}147F66485C54-070B-B874-EF6A-D94A3048{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}644C24DF2FB5-1969-24D4-4668-44ED909F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}F2A535CE0D98-198A-8B74-99A5-11829585{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}1CE7380357A3-73A9-8124-FDFB-2C04DF3E{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}9AA739AD95F2-8FEB-6BB4-C72D-3AE1CEEA{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}509FCBF04F74-FB2B-53C4-1931-8F452184{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}F687BBA5C57B-9ED8-1E44-2149-EDD44A6A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}C27758E4F7C9-A96B-9BF4-0910-DA4F2CD3{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}F2DB4DBC516D-7CC8-F624-6E27-8F98936C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}C0DE161797B6-F16B-ACD4-7E57-9D87B438{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}33E5D66B9CA8-7EC8-58D4-8712-152B702F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}D2ED1902C6B7-3D58-5E74-C610-61A5B85F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}96329BA9F56A-1CA9-7D64-20EE-03839202{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}5ECCC5582FD8-C31B-8E24-3237-44944C5F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}131B7CD92D09-45B9-5374-73F5-04228798{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}EF44CC2A70B0-73B9-69C4-4A7A-5772DFFB{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}466BDA8F57D0-ABC9-EA54-83BA-61D41E67{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}F7CEC75D21F7-AE78-FF04-50FB-948784DE{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}26274176300C-3978-8654-1188-B239E3FF{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}2D018F92FDB6-BB4A-15C4-4277-8BC144A3{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}D9AF114AC0A4-52C8-51E4-5719-60EE43F9{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}E945198F8A7D-83D9-97C4-986F-B86B5ECD{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}0988FAF0388B-9EDB-8824-3517-E6810002{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}D4010CD0F5FC-F77A-3044-1940-DA5A7A49{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}FE2FDE072820-E0CB-2B84-8D9F-5D852C6C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}B2F114CCBAEA-D9AA-E944-F7F7-E87EC282{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}F803B0C9B10D-7BC9-1D24-B717-35414047{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}47CF773AA728-3339-02A4-3BD7-EB29F51F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}25285BA21322-75BB-BBB4-2F4C-B8F4B5A6{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}7C17FF57AD59-DE48-4434-CED4-1B256C16{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}9AE4E0FE8494-EB49-99D4-7560-AC57F35D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}D81B9B6F27F4-6CF8-F224-1005-C51D52A1{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}EAAE4293FC0F-6D0B-6BC4-2AB4-B2BA30FD{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}CE43E4B7886D-96BB-C584-6CDA-027CD9D8{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}11F088A0AFD7-04EB-AF94-ECF1-26E19E20{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}AF9DA47D6176-0068-DEB4-6250-A5D0D200{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}344CDF4D64A0-DE8A-CC64-957E-E2457DBE{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}D97CDB45E599-451B-86E4-B855-46A78F8F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}80BB9FA01E70-BB78-B4B4-382A-BD0BE5DA{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}60ED545C946B-9FBA-41D4-9F7A-76391816{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}956EAF5D19B0-55AB-BB64-F0BA-0BC2F7D5{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}DE533CC56CFD-C93A-8D84-62BF-289114F7{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}C1F616EB88C4-574A-F324-56A7-7BEADFB0{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}518B42543B34-22BA-4B64-E111-F32DE66A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}911ABF18B51B-6E7B-9844-4E8C-15C471CA{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}267854EA22D1-EAD9-4F14-8F3B-B66357CF{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}ECCBC1A21C0C-63AB-F8E4-061F-85FAA911{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4D95BB4476F2-59C8-7624-F437-4BF5EB08{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}65E2CEAD8DD6-BF58-CD54-3B3D-72CBDCD4{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}ADBF67084613-6ADB-1164-555E-866BA502{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}064DB18BF4B3-682A-3FC4-9A34-7E96FC9B{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}13020B63C7B8-152A-7AF4-C540-A7C9D098{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}0AF52695EE28-BA69-B704-4BC0-E8705DAA{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}1EBAB9CF39DB-402B-5C94-79FC-3EF57DA5{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}09F8338ABC0A-94E9-2C54-1F99-CEF8929A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}D23642687DEF-0D68-5C94-D44F-4B8E0440{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}8264DB4E8A52-6749-B054-6665-59E79206{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}B610B09500CA-B6BB-E684-022A-7DDF764D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}05A60E39A119-2FEB-2334-F730-E8E73290{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}8EDC0A0A8DF6-62C8-0794-91CF-B21B2B44{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}018805021370-CBE8-1634-BF28-41916A5B{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}839F70DBA029-856A-B4E4-5FBF-53CF86C8{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}F0E28DEB44A5-9F4A-52E4-13BA-02C9278E{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}C838AB17F29F-5A3B-1A44-A60B-38343B4F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}47C60F128318-CE0A-2314-1A3A-C46D685C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}E87388499DFB-D5C8-4AA4-6BC2-18636FAA{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}592177AE212F-AF9A-4DF4-001C-911E6957{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}E08D497C3049-AF88-8254-EB03-7DA25AE7{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}0F3260863E0C-3F08-0334-330B-7115255B{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}7378D0DD5C3A-8D6A-74C4-E69E-E9ABF073{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}59105CCA049D-D009-8AC4-929B-78A6C618{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}3F9E410FE28E-08A8-8404-AE0F-172C8214{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}084058201601-0B79-D184-D530-B1CF998D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}B2D337369E30-2F48-EB14-8054-4D29B915{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}36D25F1D6E3E-11CB-57B4-FC95-E6483147{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}6E51096DBCEB-4A4A-0FE4-F265-BE34AB66{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}F902D6E31C28-44CB-5D74-CD19-D777F14A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}33B3190AFDD4-022B-0004-0BD3-A287408C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}D645D3F482E0-478A-A734-DFC3-8C65532B{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}1D7FEA763C53-FFFA-E2E4-DD45-E6355C90{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}CACD719B1783-7EEB-6714-0924-5643FEE1{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4E4C2F83BF34-438B-8E64-9725-A9CC3537{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}076A24977CCF-43A9-6424-C5BD-22FAA5EB{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}A0C368394EDD-4DFA-F2E4-587F-8ACCE184{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}08AF3C703692-B839-63C4-2D22-6AD2B7E3{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4F2386BEB3A2-C168-0154-EC1A-DFB4749A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}DD5185905BC8-D57A-8354-6437-A7F4895C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}C73CCE3AF101-D249-CAD4-473D-DB96FA6F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}0C58F33753F0-4D2B-2004-AD8C-7D813925{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}637E5AD4F54F-4E7B-81A4-BE73-10A5D4D6{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}0D517874A48A-BE08-4284-50DA-D1CB341C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}B4469E578409-51D9-0744-E074-6DDCAD6C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}73455E5D29B4-5FBB-E464-BD61-0D708B53{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}02C51133325F-0F29-7274-AC3D-D8635F23{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}0A1F882F56E0-9F58-2024-58CF-ACDB6C10{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}9722A6D75FDC-604A-C1E4-1740-F39A0033{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}1EB2EB999672-F7CA-FC04-893A-4E8DA65D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}7D7FF24D4F50-0B7B-61B4-0EDD-AA39EC98{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}A15C60C65C37-8368-81A4-953C-0DB10F1F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}E0084C76CFBA-8A39-25C4-C05E-CC8C5D97{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}0D53A446F242-447B-3424-32F7-CBEFF998{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}8C0E2241C185-1BB8-EEB4-E808-2EEFE8CA{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}7DF46D6E94FC-13FB-44D4-DA4E-0CD92FFC{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}054629ED4E3A-CEB8-7374-62E9-9926B779{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}88D043DD019B-B1A9-F144-1066-E17DAE57{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}16189DC4DAFC-A44B-6ED4-67A9-8B875838{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}A04E697268C7-ABA9-78F4-10AA-DBEF2CF5{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}782973C48F83-6198-84A4-017C-ECB3FBA2{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}A9DF6F38ED4B-1A19-E4B4-8A9F-C2AB29F3{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4194EA95B7E8-BDCA-7D04-9862-5CE9B5D6{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}B4E802A11549-C269-7A34-4ED5-CD1B84E5{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}F4D8A1D6A54B-9559-0EE4-734F-2787A594{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}13C08C15302C-B0C8-4224-4D21-C7C3A2D7{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}A87DFF56C7A5-303B-BCC4-1626-7300890C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}422C6CA5777E-096A-0EB4-06EC-09EBB3E5{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}1AE65F3EAD4D-B478-6784-9AD9-5DBC720F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}331A662DE9BB-387A-5404-A3AE-6B4C0616{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}9972B3F200C8-8529-CE74-DC12-6E16F549{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}768DBA25DD7F-7789-C7B4-FECA-EA4E4E05{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4DB6498F4EA1-CEFA-2344-9B9D-8F3EBC16{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}9ECF1A42B49D-94C8-4384-B81E-DC807191{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}0E7CC58C7991-0BA8-73D4-82E9-656B799B{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}601B15B00ABF-673B-1E94-5C8C-5F70DA62{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}207D2F6EEA7E-897A-7CD4-9233-8DFA3D8A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}B07C8AEA52DC-1199-5E64-5FB3-E44FFF0B{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}82E61BA4CE59-1DB9-FD94-7F43-DE2966CE{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}8FF58F47321D-6C48-5CF4-F254-F6127EF2{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}5FFB00CF0C7D-B5E9-4074-ADAD-86A00329{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}73155B5FEE93-8898-CCD4-DDEA-78BA2D90{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4736109BAF91-C3D9-2A24-984C-C0C62D62{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}DA0025DF1C82-45E8-8904-2FA0-B8F56D3D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}40EFEF495A95-6F0A-0F34-4640-B5C4E9A3{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}AA01F525E9F7-FEAB-7704-32D4-F0C3AED8{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}0F2DD6E55EC2-1368-9D64-7865-455A92A2{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4333769C5CAF-53BA-BCD4-F881-A474FAE1{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}1490CAF4693C-27CB-2364-BF86-95D8F21D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}A6254F926F45-46BB-CDA4-2D55-204911FD{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}9129F789F641-DBFB-B114-6EB9-704F0E82{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}A25F4359E961-68EA-BC84-C4AC-CD305D8C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}E27BECE47890-07E8-5854-CA54-BAB26CEA{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}3CC9A5903D58-E46A-BDC4-494C-AAB608C5{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}012D28E8BAEB-B888-67E4-E3B7-472ED2FE{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}CB3B47E0AFE7-929B-1DD4-3776-69780C72{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}336570294BD7-43FA-5F64-8390-3D636133{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}5D6EEF5620BA-877A-6FE4-FFB9-2B504A06{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}07D0AC1D798E-B91A-5984-CCC6-D7C641A0{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}A64F2453664E-376B-7524-0A18-297BD99A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}C3301E2A91DF-05A8-78A4-71B0-716438F3{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4E10496EAC79-99B9-8134-6EA0-5201A19E{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}BEF05FA9DE86-6F48-8DF4-780E-C423AE03{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}50E2783AD2BC-F4B8-68B4-9DA5-C3FC6C17{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}C63594DA8AFA-A46B-F794-B3D6-28691F66{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}DA7AF6C53798-347B-7994-6630-B5BA86E7{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}54B941B0C5BD-74C9-3904-063B-1F2C2814{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}8A1C07FA0AC9-9518-C5E4-7B26-A5FE8C4C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}A33432A1EE19-F27B-ECC4-324C-3DCC6323{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}A3F09AEFDF4F-4BDB-CCF4-FF54-B3DD77C4{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}8208AD79C039-CED8-0664-E442-F1C2022D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}B242C0061969-6EA9-B744-B52A-90E999CF{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}84788B9C9448-C62A-8074-4CEC-7B89C4B0{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}962ABEE1D862-A1AA-FFF4-8548-1E850F30{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4A6756920535-F219-05D4-3803-0154A245{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}9006EE14746D-7B2B-EE44-6BD9-0AE314C9{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}5C58D084281B-AFCA-D484-D4C6-F558E2BD{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}5FD32D888B0F-F92B-79A4-386F-89947AB8{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}6D67A85337F2-598B-6334-1FC9-C388A6CA{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}D9D23AA35318-81EA-6684-8D86-B8AF5C12{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}558B7244292D-1DC9-5F24-F3EC-34A28C98{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}9581BCB93CDA-45FA-0D14-F14B-3F412FBF{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}5907A3A138C7-1CDA-8154-3994-2875E551{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}0AFED2E23D33-06D8-0654-A646-7D99DCDA{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}82376A8759B2-BAD9-4B84-A394-0A60106A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}DF234742B512-FD89-33D4-3EE8-22445059{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}EB7B350C96FE-9CCB-8304-FD1E-0A2205C6{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}E06D4BEAE9D4-35E9-AFD4-0487-95DDDBBA{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}D1D2CFDA0490-693B-97A4-D8DE-5943718E{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}FFE10A32019E-9DEA-1234-5132-724926AC{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4AA6D5A27217-4268-0514-594F-BEB2D926{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}7C07C32818EE-CE2B-52D4-E008-ECBEF329{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}B56959060FF1-3F9B-2D84-E70B-AE1B5E3A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}F49A6027DE8C-BF6B-7C74-F054-10C0C4C7{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}005164F5712F-7BF9-1954-3664-7D71777B{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}9BC7E8DA93D1-230A-D414-B56E-FEE88DBC{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}600B2D96636C-6F5A-9804-70C8-C687177F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4200A9C2A88F-C92B-6B94-823B-7F2B7C19{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}92D25D31C0B2-09C8-0C14-3417-D04BF110{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}6EA93B4C392B-89CB-8624-CD32-299C4397{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}8788237AD622-345A-41B4-D7DF-45006F47{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}3E5116FA69BD-7E69-82B4-FA50-D717D9C6{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}8B3D19A9AA43-22EA-99E4-E074-42775150{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}A8AA050CBB24-04FB-E254-3464-7B4C04A2{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4A061615BE4A-535A-2104-83F9-6F50D03D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}CD4D8479EEFD-389B-58D4-6D2B-CAFB8BF3{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}8C13D261B97C-2E1B-7644-E1E1-3E5E9EBE{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}C410D1363BED-B939-B2C4-2D48-F061ED05{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}2B5C142F86B2-B328-D8D4-F201-9239700E{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}10EA727E1EBC-528A-FFF4-D0E4-922FC0AF{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}297FAE15A06A-2C6B-8F84-E84D-FA34AA8A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}7AE96B100B97-9EE8-8474-2018-6498284F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}E80ADF41492A-65FA-FD84-A7E0-E24DCFBB{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}CB0BD081B992-811A-6434-F18C-32EF7E70{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}2C918DB1CAEE-647A-B1C4-F0CE-C5E937B3{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}E2960293397A-C54B-45E4-DD63-8869F117{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}03141E474B7D-797A-9364-AC2F-CCECB435{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}DE0D30467882-234B-1454-AF31-88AF7F9C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}BE3E565C3B65-927A-5174-CDF9-03FC9C2C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}E48BC7FE73DC-2628-8F74-0F66-7781B9DA{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}C983FE642B40-96E9-F254-5DA5-71EF8EED{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}99CDADDF66C9-2A0A-3E04-466C-0A46408A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}3D3FF7D19655-FEAA-7764-39FC-C0CB1CB0{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}9CE03F7F0400-66DB-7044-FC09-AB6AA772{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}A38019401BEC-256A-7E54-D52F-8CF7228D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}71E5BB990962-87E8-0414-0512-E536E2E6{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}426C36BBAF6B-53BB-F284-469D-00C5E756{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}B7717C4785B1-5CF8-4DE4-E770-D80232B6{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}1941C261A121-9E48-6CD4-AEC0-F579ED33{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}90332E0DA248-70CA-7F34-2B9E-D8ADA9B6{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}B7BA86E7ED61-D2E8-42C4-27F5-12271E02{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}34871A40F699-8F18-E8B4-10DC-6CCF2352{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}C15D9A9A125B-1F2B-1614-1509-8E1D0D4D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}C29CD61FE0BF-C38A-0ED4-9151-AD49E5DA{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}E01B8BF6BC3D-7CD8-45E4-F342-23917EFF{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}EDEF9AE418BE-6678-6844-3439-D3BFF15C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}8B406A29DB05-1A3A-B494-AB30-572C42FF{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}1BC3B69A8005-7C09-2514-3123-91A4EBBD{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}C2EF09BC46BF-FA2A-EF84-9724-E925D3A7{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}44009126C108-730B-C3A4-4F60-6532E61A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}82D136348781-E859-2364-DEFD-77B844BC{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}8E17C5A9B4AE-BAEB-54E4-F139-9D77DAD0{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}38241A7C2905-B93A-E424-D3D7-306669C8{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}777F05AD73E6-B8AB-BBB4-21CB-3E96CF6D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}DB096176497A-F6FB-5EF4-408C-217F131D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}424E6874B27F-FFAB-7E74-1764-1F71A7AD{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}759C3B97C975-7759-6614-6DDD-050C4A35{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}D577AC1F7E6B-893A-CE74-C758-716BFC0E{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}716619A00E71-133B-1B24-88BE-E910F564{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}BDB56CF76429-E04A-B1E4-FC99-46FE2FB3{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4AA0BB7639B2-86C9-17E4-F4C1-86A600F7{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}AD475E0E6E3D-AC6B-C294-785A-9926EEA7{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}C0ABD2BE49E9-6C0B-0744-AC96-ACAF5099{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}D7E92813A2D7-3189-1B24-B237-105E93DF{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}268FFE88A4A7-F739-68F4-9B64-EA613E31{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}74386522A904-7FC9-7224-905B-067DC10A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}717C4C6F9A7A-D4A8-13D4-BC78-214E2E2A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}3B6FFB73FA00-BE19-9FC4-7B7F-9C10A6FD{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}CB789FA0D9EB-5BEB-65D4-BBA5-4CE80A94{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}D9CF900B344A-A798-2524-EF49-45AFB113{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}72145A3294B1-DB58-A0E4-50D9-82046587{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}47AAC30CDECD-73B9-3444-EC73-B8ADCD93{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}BF406096F8C3-D71B-FF44-A988-CD7C15E3{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}64055D0E3821-3D4B-8C04-FC38-F9D1FD30{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}BAEBE84CF053-90E8-D804-9C97-B2B7EBEB{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}62FCA7C73F8C-FEC9-9474-F16B-6FDF7654{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}22DF4BFE68DA-BD7A-D564-8C59-112CD455{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}C1B5985A2B02-683A-9C84-E3CB-C400ED84{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}6CCD965CAD01-023A-AFA4-4C67-F645421D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}D8A35E2ED82D-BFF9-34D4-03C8-D5911A8D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}0CA723B39D04-EB5A-66D4-91D6-AB4EB10A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4DE6D5D3E596-9A8B-5764-2587-6423F8D5{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}DEBAD9DB6D05-37D9-EFF4-6EB7-AEA92ABB{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}E7BA1595FF1F-9B79-4FA4-8D46-FA732A43{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}B28574954159-33EA-56C4-27DB-16EFAEFC{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}30B9214FAF2F-376B-6F84-585E-A4CD1644{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}838C180D0CBB-476B-8E94-12EB-4922BE43{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}AD5529531AF2-8548-FFA4-6A24-2A5BCAAC{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}3605A0738413-A4B8-5C24-FE6A-9C8B175C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}1BC4CAC3D8EF-47C8-3B14-DD88-2EF7D86E{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}EEDAECE6F1A2-226A-5854-E704-230D1908{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}262095DB8920-259B-D4D4-929A-08FBD8A1{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}99DD6C62E9CE-A50A-A3B4-309B-C3A80E85{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}5501E816E9C3-EAC9-C2C4-5EFA-54A1B609{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}E22E8B745B44-7009-0CD4-35A3-DCA0D45D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}3B14A8A65A8B-0B69-1BA4-37BF-A211CF43{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}DA8776C3D217-C30A-5314-D76D-187D44FE{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}1112F1B4743B-8359-3F04-6B26-1A0A7C96{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}FADE801284AB-13B9-7164-4EF4-BBB57DE5{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}A3F6EFDA26A8-F02A-F5D4-9EFF-C1FBA00D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}86ED99B4831D-D14A-38B4-89F4-4E8A8CC4{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}F6D9F600021D-AB58-A804-B544-D82C361E{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}11DE9FD2D9C5-F4F9-7354-E949-616143E4{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}96FEB8134B76-816A-6634-6589-AAD66AA1{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}DAB51A0AF17D-AADB-E0F4-AB94-43ABE638{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}9DAC2AD0A7D4-C96A-5F24-D8FE-EE71B5A7{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}5CA461BF75A7-193B-D954-3C3F-F2478E3C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}56E12C32C7A6-4BE8-EFB4-EADD-1A49C7D5{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}17BB411013D5-0AA8-E134-2F18-664EE7F6{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}CD419B81223D-BA7A-3714-8C7A-1BB2F128{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}58AA1A7E651A-AB78-9D24-FA52-516310FC{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}37C1CC72077C-0168-A664-3724-333E6DF5{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}AD411DE22C26-0768-EC64-2B51-6C604277{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}5CB392A947E2-9EFA-A2E4-28D5-AA98C209{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}8F78CB307082-9859-E6C4-3244-0C846469{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}B3CDFB5808FD-9F1B-CFB4-755C-DC5AC287{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}AFE2A6B04E34-79D8-C8E4-079A-33170DBD{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}20B326D77702-750B-6BA4-856A-3D412910{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4E69DD7C2849-826A-B344-4861-11B79B39{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}1BC6C79B4497-C1CB-E6F4-2565-3D184357{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}96F22DF67940-C429-9834-B15E-D4337FF8{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}54937DE90596-E72B-30A4-FCD9-C3323060{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}19E3BA299071-9C29-9684-D1DE-0191A9A1{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}38347A771295-83B9-90C4-79DF-19927037{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}39E5A842EADF-83D9-B5A4-A59F-6B8ED48F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}318530FC97D5-FCD9-7204-BDF0-3B1691BF{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}544B4A43DE81-B00A-C494-9BAB-812B24D0{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}3610FB9AD647-440A-2F04-729A-AFF53976{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}51A62AC33571-B47A-F984-5B48-D832143D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}84F8ECF0076B-B699-D314-5573-F0C52172{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}3D2F64829B8F-CDB9-4874-956A-E16414D6{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}9F3E16A949A1-B8C8-C674-287C-D93D9D08{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}6AB4692FA885-C6D9-5764-5CD4-7DA9934A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}2E56D62DEEA7-A699-95B4-F78A-0426FE88{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}E98069C9863B-DC5A-8F34-FFC3-3D5F8CCA{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}5BD683F88B88-A868-CB64-2A15-B8C9C7BF{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}EF21424ED101-D98B-35D4-4620-D98CE209{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}44FC7C4F314A-0FF8-5134-1738-3BE51608{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}DDA8165DAB34-EC39-8914-2A93-725C0294{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4B4C3023980D-6E98-1334-D13C-60BA4E20{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}3CD7BBC6AD36-0718-9B84-7A0E-4D5BC68A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}6543360120DA-E86A-4A14-375F-BC854C0E{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4DE7087EA77C-5408-BDA4-C8CD-BCCDEA4F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}45D9D4E26A0C-1C5B-7E74-060F-CB2288F7{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}90BBF367F7FC-F7E8-D6F4-0FD0-6DB0F949{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}DC6ECAF8C2FD-F9B8-1534-2A9C-92BEA4EE{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}60A8C05E5F31-7DD9-7A14-8D9E-D7B04C00{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}7F64EC2DDA9F-18A9-12E4-494B-8DB830B7{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}CB867CE32A8E-E4D8-3364-5F34-944A20DC{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}6ABC0F7D7E9A-8EEB-46B4-8F84-8C6D9DD9{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}701EEE77D927-6C49-1DD4-82EA-A33A84AF{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}594A1F9B257C-3F4A-03D4-DFAF-29EC32F4{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}1855218A8F81-D958-5224-2A35-65D08393{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}F67FCBD6A4D0-7D29-DD64-38CB-984DAC08{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}F25959E0620E-E8FB-8A34-C685-27E10D24{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4138849CC0A9-0B49-F9A4-8495-971C9B0F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}3C36C74C61F1-1E68-4484-F6C4-CF719CFA{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}D31033585661-079A-AD14-0C66-9C3DB83C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}2470A483A5E9-C03B-7284-4FE2-88C70AFE{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}5E95A2281602-840B-3F64-F2D8-D3060A1A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}8CD327B961D7-EAF9-8064-C44F-8E5313F7{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}D17C7C04E76E-BAA9-C9B4-AB2B-18951F72{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}BA24A24F623F-0559-F0A4-330B-B62240EC{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}165288428E5A-A02A-CA64-2E23-979EA25F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}34AC744D1578-32A9-3D94-21FD-9298BB1C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}1C6741E5AEF6-8F59-85A4-6502-CE3AA684{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}8046BE3EBD41-03B8-1DE4-019E-E434F5C6{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}C75CD03F5112-6AAB-00B4-DC45-DD80F4BF{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}EB9D55CC0CCD-E83B-6874-CEDA-1F051DEC{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}51597AE23556-C7EB-34C4-0A33-0A846ACC{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}8969F594C893-EE98-0234-E3AD-6C63794E{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}06C4A6DFF1DC-A778-EF04-B7E0-4D044455{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}3454B7855162-8B9B-62F4-1C1B-5D50D8CF{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}8614AFFC017B-DBA8-D414-51D3-8380908C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}75E2555AA750-0179-2024-C349-545946BD{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}06FDC587C74B-7D7B-DDE4-CCF4-7A2126B6{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}311522433318-26F9-8244-0F1B-D416DAD5{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}FD602094586F-586B-9954-014E-D773F5D4{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}7E2EE472233E-1368-1D64-AF9D-ABA1C81B{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}832859159BD8-3748-E7A4-1C63-EBB02B9E{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}C5BED3A461F6-6368-D9D4-FC1F-D9422BA4{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}3FCDED3C89C4-27E8-51E4-E8CA-F0A44C6D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}821D9EFA1D55-64BB-E874-2DE9-9A337122{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}1372C2AA2ECA-0F39-6064-67E7-401A7276{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}C4521186A120-918A-8744-F1A5-31D6F3CE{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}65EB780704E5-2239-C4F4-0BDC-3A9359BF{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}82FDF4BA6AEE-1A0A-6724-BD34-4FBACC19{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}02F1AA0CEBB9-2648-0C94-2FF1-559EA1C8{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}F0F2EF5DA370-36E8-2854-AC34-9FF5F22D{" Deleted

Edited by guruwannabe, 24 April 2007 - 08:56 PM.

  • 0

#4
guruwannabe

guruwannabe

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}21F18D84CBDB-0E3A-0A34-E667-C0E6A178{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4A1E76C02266-74D9-A264-6BFC-20B50D5F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}5AA107340AB7-FD3A-B8B4-A6B0-282DC310{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}2FE1ABC8658B-94F9-4804-73FE-62EC7BF0{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}474E480954E1-D70A-8674-4393-98397543{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}CC192673E065-EE79-EAB4-AFF8-C4C44A41{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}43C31637D284-80A8-BD84-DCB7-17C6F407{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}8575051D4EEF-2DD9-20A4-90E3-B9A98696{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}085C0C949424-ACCA-82B4-129E-87B8B2E2{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}2C85C11AF4F9-13AA-A704-8C4F-93092380{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}9343AF2FA459-BCA9-EE84-3631-17818D93{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}6D4184EF3C61-9638-C564-DC94-EC2F55B8{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}AD3637E44813-6AD8-6B94-0943-3E5A3CEE{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}673B95366C93-2338-7F74-4994-4CD8A1E8{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}1C60C9C49DE8-F58A-6834-5C15-BD1CC3FE{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}6D3C85CCB351-3B79-A544-1EFD-EF1D7957{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}31F1805ACC8C-95FB-4404-35D4-53915DD7{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}918C2F002B86-9F5A-71B4-2C1D-E10FD9ED{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}63BAC54E11B7-1F18-E824-98A6-EF12E0EF{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}BF0F545EFA9E-6DD8-6844-F5B5-6CA75B04{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4050C891C93B-AA48-67A4-CA8E-C1D88B53{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}683D4F9B0CC2-07C8-4004-6B7A-8EE3210A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}BD1F1C59F1C5-1BAA-14D4-FAC7-4CB4D22D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}9F45DEC30829-A5A8-4CD4-C9C7-1575D5F1{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}496FE456F526-58A9-3434-D671-F6E8EDC1{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}185C8E20CB52-0B9A-E494-4FA8-FD6BEDC0{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}3ED4660EFF82-8D1B-7784-4646-980E5C2C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}286949EAE156-B898-6594-F841-FB5F54F0{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}1127A0E62040-B41B-D1E4-B4A7-1A8AA563{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4DEEB0017C8F-963A-21E4-98FD-D663D7DD{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}F267D7D23CE0-A28A-B5E4-DB7E-CCABCEE4{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}130DEEBA5C49-1069-20A4-34F8-37DCBB99{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}87B0295D1E73-E45B-A4D4-A853-B2D88E6F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}EBE54DFB8667-8D39-FF64-F218-76381E15{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}9876C2604F14-53F8-2A64-F593-18F80612{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}001255B1FED1-7FD8-E964-9A61-25BC30EE{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}06BC4D47DF5A-919A-A554-3C8E-A520A327{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}27FC2906321E-36FB-B1F4-EDBD-69AD613B{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}A10663E279CF-9A6A-FB14-122F-53D8C261{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}BF8DD7885ABE-9ED9-1784-DEEC-486FE743{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}F6DCFA6233C2-27B9-E9B4-CA26-09AFDF92{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}5E39742D52EA-C969-96E4-7DDE-7DE0D0A8{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}DB34CC443CB1-6658-9E04-F244-2CF04D67{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}41D01232EB34-AA1A-7EE4-1BDE-43B7C869{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}CCE8B9D09116-6FBB-4794-E756-487ED8E5{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}CEAE4C94E745-2C0A-1054-62E5-79023D1B{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}5CBA0E7CA9ED-5C3A-D5F4-6888-CF095902{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}0F861E924F73-5719-28C4-658F-1CBAD4F2{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}5C23EC61AD30-7DFB-2F04-76BF-29AC87EB{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}89C437930D90-A188-CD64-295C-7DA116E8{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}060A52A0DBE6-B33A-D0A4-8F9E-04993BBA{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4C63F047FC80-5DF9-9014-2BB9-032C7961{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}3B409036B3A6-B3CB-B3B4-7BB9-18FD3E26{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}07D10C8B289B-7D2B-6CC4-6994-3A1BFC7F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}EB14AA862872-593A-DFD4-5C9C-C69F58F7{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}DB0E040D3E7B-E0CA-85A4-E643-DE6E9245{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}BE82ADD06F1C-8FC8-1004-616C-FF9E2656{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}61657C5C0F46-8CB9-0C04-0BEF-5A12951B{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}3FD0446EDE33-AB49-9004-EF39-CE7F0BB6{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}929784432420-ABDB-C284-2635-C9B49D8A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}37A541DD2471-DD7A-87F4-D31C-76CCECEA{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}3C5A78206147-ACDB-0F44-0B3D-24CFA57E{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}101600972EC1-4D0A-A624-72A0-CB58E7BC{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}D18C7AAEEFE0-95E9-8B84-40FA-1BA4795D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}7B4127CB6933-EE3A-D934-F2C8-728BA77F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}F5429F58A578-AC38-3384-7556-4BD7467A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}1387E3491148-7ACB-6914-58BD-40566EB6{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}F24AFFB57548-15D8-6634-0924-BFF0E826{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}675DB1275C82-3D0A-2B64-7412-AB028FA3{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}5B3BEE5AD042-A4BA-9324-C0D1-3C2C30E7{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}EDBBF0096EC5-B789-4364-5B70-042CD70B{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}6DC4CE124734-6C3A-EF34-51B5-462141E9{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}58723950A82D-989A-1D84-1966-F8BD7FDE{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}C2BD427BFB7D-CA39-D8D4-2CD2-658441F6{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}2EDF1226ABCD-4499-D0A4-C65F-BB5B3DC9{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}69AED23284CB-354B-5024-70CF-DF76BE0D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}760F8671D76D-A58B-57D4-FB7B-40ED3A1F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}63ECB78DE587-8C59-4B64-70BE-06127692{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}5F21403FAC3A-F71A-8F04-05E1-E79E08EB{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4863A5C4B716-A6D9-2024-0D0A-C527E1D8{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}E8D4B12EB1FE-91BA-A424-1F94-8B478882{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}7D9503E777DE-3908-FAD4-9130-43EC6A74{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}8B2BF49C5FBC-974B-0D44-0F10-7B1D4750{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}CFC1463F92DC-4808-4A04-AC43-21A424F4{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}A46167D12FF4-470B-8364-D4BE-97776E5D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}AA8FD1D6728A-369A-C034-DC54-E195BA05{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}37C466C95227-AB5A-BCC4-544E-B8C81E14{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}354C698E4040-90A8-2F14-70FD-3CD234FA{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}68C3D7793A6C-340A-BA84-F37F-E2F229D2{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}16C63E12245A-9E5A-F7C4-C9EA-4BBCA66D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}9ECF532ACB73-F888-48D4-A56B-FFCACBE4{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}789678CB3684-1089-CA74-AF8F-5D81BFF7{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}DCAFDCE45F97-CC88-7DB4-B050-047B0B02{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}0F64D11F9E04-A4BB-A794-7C8C-1098B157{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}9503DB029FFF-09C8-7FA4-9406-9B6C975D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}D0CA95F5E033-2F2B-0324-C2E4-63A84B0B{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}EFC43B73FB8D-094B-1C04-9A1D-3525D1E9{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}EA60E6B2DE7D-1109-0184-274F-6EAF5845{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}A6961FB79E82-81AB-1EE4-72DB-E40ED3F4{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}020CCF7C3586-3079-C384-34E3-DCE6D178{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}43BFE8338600-ADA9-89B4-6F06-EB0A1835{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}EFB1E3D59EDB-39BA-DC64-9995-43FB0579{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}090E4105108F-765B-33E4-FFF2-D963A7DB{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}19AEC1540E7E-7CF9-6DB4-3FE0-89E168C7{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}CA9D325E09C2-A1DB-AD04-B43C-1F83C761{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}58E80EB1209A-09FA-1924-08A1-8E388011{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}BDDD4BAE9F93-B28B-8CF4-2E39-0EFAFE7F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}816BF3391904-A3E8-B064-AFD3-F66CAF89{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}69F2A6313F62-25EA-D3C4-868E-EF39FACC{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}6E2F26E0C6AE-559A-78E4-95F7-9BF98DA5{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}1F68C952EEAE-509B-D734-BE4D-A0871FFD{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}E2F6BD5913EA-BE28-DBA4-2B58-AE4AE766{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}55BCBB7D8ED3-E3BA-E5A4-1BED-1F3F5B2C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}305D852E8CBB-8BEB-0924-3D4D-049284BC{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}9EA986BD8B13-AD48-80A4-1C04-040C31C4{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}25D3B20FF13D-5069-BD84-B577-B6684DB1{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4259A76A441E-34DA-AFF4-2838-12582E16{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}2A7311FA59FA-A1DA-E714-1889-1D81DEC3{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}61842472B0DE-9F8A-BD04-0B37-BC83E8A3{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}0AD06661250F-1169-3224-D1BC-1A42C317{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}E0856141BAED-95C9-C894-F473-AB4A6C4A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}2804A7F09187-DA88-DCB4-6048-34785E7D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}15A97759A672-0759-74D4-7DD9-CE7AABAD{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}014027C431F0-7D48-C414-1E6C-B1D5645E{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}CCE93B385D5A-1859-8794-26B0-8EBD466C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}F00F15FC91C9-1D7A-BEF4-9D22-FED49811{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}11597CB557F3-52E9-4A54-425F-FF1DB773{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}078675BBD4D0-231B-9F14-9A75-FB03A830{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}650934B3515C-FEFB-3AF4-C086-4632070F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}73FC5ED001BB-9C2B-DEB4-5939-551F2A33{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4A67622C179B-E6B8-44E4-8391-41052F1D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}1A3B3B2BCC10-89BB-ADE4-D472-41787EE6{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}03A94C82A3F8-2AEB-9334-C1F4-E8652736{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}E3C095233EFC-C59A-6954-8380-E8E4FC50{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}0D66ADD88318-F73A-2C04-19A8-803ECD17{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}E7F5FFD73700-BC48-6634-AF4D-9A9E42B2{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}100FCB9E1000-038A-C494-5BA7-3E8AC6A0{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}9BDDAA4E9A52-2159-E644-2B31-CC15CDA0{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}8FBB82D302F4-E708-ED54-FAF4-1954B070{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}10AC50D7FD44-6ED9-15E4-98AC-BE830DFA{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}2D65ACFD4C9D-4D7A-CFA4-A758-4AF5683D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}AA6CD1285C72-23CA-8454-E51B-7C336246{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}1CE16565B368-1CE9-8764-4F55-DA6D55C5{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4368B568C8B4-911B-35B4-76F4-B0175CCF{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}ADA7D3026037-CFEA-5E94-EAE0-580C6336{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}767485699192-E749-E384-95B3-A3ED8986{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}C7A374465477-2DC9-9CE4-B113-BAB048F5{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}30CA8B7B5808-DFBA-B2C4-FD10-28D0EB64{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}879DF0E7D56D-25BB-4104-C6CB-CD1B8EDC{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}ED694FF41C65-0AC8-CBF4-1A1A-438FC375{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}E6B565C24BD3-078B-2154-9650-08E389C3{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}6ED568F29880-157B-D524-11A5-0DB7E44B{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}47061BDBB398-680A-EBA4-8815-51413A98{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}65396FC4278B-2FB8-2154-AFFB-935B4B81{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}FAF8B083BC6E-19A9-D1B4-8E40-794A32E9{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}182787AF7C03-C02A-6D14-A8FF-1805247A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}7370A3FB3913-4F0A-82E4-481D-69BD819D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}611B7047AF5E-FC98-3934-DA42-E675149D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}B597320756F0-BE28-2134-19E6-CD14CFAB{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}AFC18AF6CE4E-960B-3914-9FEA-0C88D015{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}CC6DA4D245DE-FF7B-B094-0E78-152F8737{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}62A39E0DF119-9A39-6424-438A-22B919E3{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}291E1272D02A-B9B9-04D4-9A38-46BD618C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}1EE4CF480838-4ECB-85B4-3909-6CAF7EF6{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}283ECD871229-6889-1024-5BDD-71DB53A5{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}BE7BD58EED09-6159-3734-7EFF-F78F6F70{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}E4B6108572D3-F088-3B14-BA1C-3760854C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}14166EFF4F92-353A-C1B4-0D73-7D9BF14D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}AB1092E7FDBF-DD5A-68B4-101D-E4539E5F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}592B7A3A79D1-9FCA-FCD4-66CC-E25E282A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}E08680959F8E-BB18-D004-2988-577A09EE{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}F22101C21D04-F47A-6864-64E0-5F3F038B{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}93AD6591251C-AAEB-E434-D1A2-0A85C061{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}780EAE664D13-C14A-EE14-C293-084DADB5{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}EB357A796A62-BF4A-5584-476E-9DC405A9{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}C8F4AA027443-7F8A-7D64-7691-D3F57E4B{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}D87514488B1A-F0CA-28D4-2889-5D0406E5{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}C75122F566BB-D75A-3114-0E33-ABC0D6F9{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}1F8969C434E0-C189-8174-8370-CACAAE2D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}5BBFA5A159A8-124B-18A4-DFC4-3B58B48C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}6AB600786252-82D8-BB34-7DDD-A1CA838E{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}FADA0E2D34AA-3A7A-2EF4-8FF3-200D5E05{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}D7C3B06487FC-2E58-CE14-BE83-2B370BF3{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}1ACB31323078-2958-17E4-0CA0-A4A344FC{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}AEAED944270A-23F9-1214-0DEE-F3317EEE{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}1A5E84945A77-3BC8-ADD4-6572-510D3A6A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}A8AAD61287F6-295A-A564-AA5E-FBF4C810{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}724ADA6FCA66-E2B8-AD74-2710-6399AE0E{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}FB928C71955D-DC69-6FE4-F553-2C3413CE{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}111DFD3201F0-9DB8-0814-8A26-69EF8D2C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}ACC7717F6E4E-DD6B-F344-F3B7-B752574F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}82A814601D5A-4399-5234-3B4E-12E2D19F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}183F29F83B7A-5A29-B714-F072-19ED19C7{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}E267B266B756-C10A-6E84-62B4-7B46DACC{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4F8F96FE988C-FD58-A624-FB42-42827DA7{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}253E7581A794-6CFA-B1A4-3F19-23D35EB3{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}FE798637BA72-565A-CF94-0655-98A5CFAA{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}9BF6143B4D9E-E96B-EA44-B2D7-557EC08F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}8AD959651038-D20B-0C14-9C64-8E50B8BA{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}BAEEBB3D2754-31BB-7794-BC75-BA890233{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}B6CCB5DA1603-3459-8D54-7E5E-3BED97E5{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4822396F64CD-3B88-D1B4-69FD-BDF03D9A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}B81ACC76C649-344B-EAD4-C46F-11035FBC{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}6A5EF9F083D4-6B9A-0374-80DD-D2BAA1B4{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}6E0D47693592-4EF8-BAA4-A034-788592E9{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}8D82EC8B0145-A99A-7134-2F20-271F5928{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}BC64FBCA6B85-53CB-DDC4-5643-6C2E771A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}BDA66B530F3F-E5EA-D534-FA57-51C0D1C4{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}9A4B426FA321-8749-6C64-5FC4-E281B147{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}D9DB0E9D3577-29E8-9EB4-82DE-E690F038{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4B5E48172EFB-6B59-3BA4-98B8-C893BE6E{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}970162F5C81F-8CD8-0BE4-1BB3-A05EB28C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}19DE2EBAAF39-8AC8-6DB4-1DBF-FD021C64{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}E9DD84DC2A51-263B-DE54-355C-34D832B2{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}B98AADFE0858-C01A-5B34-63D0-2FC1C58D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}FA0D7841F7BE-3F79-E164-E41B-C17EDCBB{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}80791410C7B9-EEF9-7EE4-6B01-5F99A3E5{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}426DD3A11C96-E468-35E4-D088-5810C58C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}3A35811BDBBF-747B-3BE4-F6A1-9E9A53EB{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}983DFC038132-06FB-D354-DC32-21B3594B{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}369C8FCF194D-698B-C674-2DB9-FA516E9F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}21414430361A-5858-CC84-60FF-DF8A10F4{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}AF42BE077265-EC19-8494-E5A6-8E1A1EDC{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}50251C33D6CF-6ECB-3414-785A-F105F55C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}176FBDD2F73B-CB4B-1534-4915-9F2940F3{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}6DE7430E8871-59FB-3164-A0C4-39E9B0AA{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}552F5D1097B9-84E9-B0E4-332F-3F6CF379{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}E5908979653C-6F98-3C34-C282-2A9A688C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}2F391D7F78A7-C8A8-9014-671E-D9A1F6CD{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}F68B81C2C918-1018-2144-11ED-95F06837{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}F790A0038BAE-7418-7D74-2870-78017D4F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}0CBDC8B324BD-F3C9-D044-8E30-34889907{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}59E25916D269-E429-FC04-E902-6FD9E9EF{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}5AAE2A19D721-C708-2FB4-579A-180426D8{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}F64CFE4FC3EF-F91B-7044-FC52-27C2931E{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}1C3A7804108E-7FEB-62F4-3E4B-E750157E{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}81BC8652BB09-77A9-03A4-05E1-B03B8B94{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}C059C6A4D387-AAF9-FEB4-F6FB-2F1C82FE{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}05808F282010-D889-9114-DC92-FE95E099{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}25A79D5D059B-C86A-1C64-2CE7-CAE4BF19{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}E96A8AFA9C1F-C03A-BB74-D404-F3FB6183{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}74D87A95F6F9-83A9-1E14-EDFC-274D603F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}74C809DFE77E-667B-6754-9BC3-47829DFF{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}A1C128822163-3D99-40C4-CB19-809F8103{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}F1172642429D-98A8-4D44-E9F0-177CFC7E{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}398740C087AC-7C09-1324-C391-FE7DDFDD{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4C9A20D71B04-B978-97B4-96D7-BC1CC62C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}92C0240D3AD5-A92A-5354-BA72-1EE82F84{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}ADCA84AA1DE7-881A-F224-C5C3-1E7E7879{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}A12984321A57-C68B-ED04-B537-37A47650{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}F39AC16F5B8A-23D9-2384-B01D-4BFB7ABB{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}895D3CF189A6-9CA8-0774-B0E3-8B7DC940{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}E960BE32E398-8678-9C54-F64F-E4E99B55{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}6674FA419997-3C4A-A6D4-CF36-4678D3C1{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}47BDC308AFB9-23AB-C984-8488-2DAEC2E0{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}89214B6D34ED-3538-DB14-1888-39C37406{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}00DA860F58D9-C089-07E4-0DC6-CE68B90F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}532E10595C62-0BEB-6834-E0FF-505B6E45{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}CAFADFA4F7B9-9F8A-4DE4-4EF0-A0D6E140{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}87A4868A3513-505B-8CB4-EACB-5413B5E3{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4106ABB596BD-A0DB-1F74-986B-00778DED{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}96DE481A2A45-23C9-3A54-069C-7D746F08{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}31D74C3E12B1-4459-91C4-F683-E390F095{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}462FA54D86A8-6B4B-A934-2A73-D0323176{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}754458638A30-DC08-BEA4-E3C8-D9F011B1{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}8AC85DAED3AD-4F09-2F74-6E7A-8E6A69C6{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}9250B5C6FBD5-3239-D2D4-CA46-A23938F2{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}ECBD02A533C6-382B-8B44-AA6F-77E28C9C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}32052F7A2691-9E7B-3504-F5AF-6269500B{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}7D5A16E44EFB-6519-3F74-9948-4D377CB1{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}74EB10A57955-CAAB-7A14-35CD-FF7A3E50{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}C0BA9B5FC9A2-9588-3D34-EDFE-7EC7BE39{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}CEFD5F10E764-157A-E824-8FDC-9C306A4C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}FF688BC15913-F7D9-3434-EEF8-4C74B464{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}77184B404C3D-2319-3CD4-81B2-04F488C8{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}8D05271531B4-F9C8-A584-8042-DE2382AC{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}F89F4AB3BC4D-6BAA-1E14-6F54-96151322{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}6348B3F43CE8-D4BB-F804-E0A6-524C3983{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}E4B9EA4E2FB2-7488-4E54-2CD0-39520966{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}AEAF2D1EF5F2-C878-5884-BB38-3A8A7BD0{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}BD3FF6876BE2-1618-52F4-76C5-A614938B{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}017763A2180F-7EEB-3974-2FF2-83B5D4AF{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}51A1A3427197-0F89-9D24-39A1-88257840{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}6D32C2EC9BCD-7AFB-E474-BFC7-A0A8E614{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}C25A6EC74CB9-6F6B-00F4-0866-EE8FCCB8{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}5A21C071E527-B51A-6F24-A33F-B70D3D59{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}9AF8CCB7A43C-FE7B-52D4-EA4C-1434F16A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}7E575805B43E-98AB-04B4-0BD0-EBB569D8{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}FC42BD8D2753-9A6A-53C4-9986-D398B51E{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}122BAE36AF49-2EDA-66C4-F08A-707E8AEE{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}493C61671EB2-4B09-5024-8736-D0802802{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}99577B45D3AA-97A8-C804-B2BA-18C9289A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}DC6DA5B243FC-F7AB-C874-C032-BFCA87BB{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}03CAB1C56136-9798-2194-442C-F59F6C1F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}F445B50AC4FB-0EC9-0954-57D3-DDB027D4{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}719A55066734-4B5B-7314-B8E4-BDA07250{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}9F0047EDDA1F-268A-DAE4-E70F-7F54A500{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}04BC837803E2-8F88-06E4-4015-50303DD2{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}1FCE648FFCA8-EA69-5A84-3173-53EC5411{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}5FB58789121A-4D4A-EDF4-42E1-1AF0BC00{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}AB7745A0DDD8-6C09-3E94-77CA-E7D20F2D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}768B21D9A134-13AB-7A74-5DD1-FF846AB5{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}2DDF82667B05-7DDB-3134-79CC-E84DF9BA{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}424C64946DF3-B1BB-C864-A1E2-8A9256B3{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}BF6C35014428-EF7B-5B04-7994-7DB7D6F9{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}78F1E5023E38-EEC8-8E54-1CB2-6266313E{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}6C03EFC63AC1-E068-FFB4-0BD8-FB6D4974{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}D4BFCF11B029-6369-0C54-AD13-E654C296{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}6CDA2B4CC1EF-997A-7024-758F-9AC4F8B9{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}66236BC52FC9-A7AA-3BB4-EE08-EB5A159D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}E9E142500B99-E3FA-1AB4-C67F-71D9990C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}B2D42B6E4C5A-AD0B-ACD4-6C1B-836156EE{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}0A7B8F882152-9649-5264-BF48-EE8E4AC7{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}1DE368166D7F-4758-0AB4-A45A-4317E63E{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}E5E7FEB28AE0-0CA9-B4D4-DFE3-46F247C7{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}AF0D975B403E-5619-F544-08AF-3EA6E924{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}C51DDD3C002B-D949-CAD4-B467-0DF3ED7B{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}6A1320859307-EA7B-0DD4-A1CB-C1729AF3{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}8B9156728706-E3D9-DF04-1126-9022C802{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}0487195F2185-EB89-96D4-EE30-E02BB3B4{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}93A6D0BDFE10-F6A8-1EA4-7FAB-2D2E47D5{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}0658AB607DB5-8408-59F4-04B0-3AD0E99B{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}BA7F841C1767-4A69-45A4-34E3-4AC00AF1{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}107440A62BA5-F90B-EFD4-1D90-67F87D91{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}57331109E93C-7CC9-F804-3EEF-822C29CE{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}0A4F81A97945-6FCA-BF54-FEDB-0115A8CD{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}37EE8EB9DB71-356A-E7C4-1558-05D3810C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}9CD141E33E2F-1D18-4354-AA6E-DF0FCFAB{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}89EB788BFE8C-CF7B-A694-7DD2-CB3CE61F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}AFC99F280D09-3BC8-0D34-56EA-3F835AAF{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}FDA718193CAF-C168-3264-F6B1-A95DF78C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}6202564210C8-37D9-B8A4-F748-2A77E70D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}E36A733EB28E-B2A9-78B4-E369-41D396C1{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}429DC8EE97BB-5D1A-9744-F1C2-82A6DE45{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}3CE0A2D7D540-B3F9-5BE4-2681-0676BEE5{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}460D8EEB2F5C-428A-7D64-BA4B-82E88AD9{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}B356EE4B228C-D3C8-6494-B575-A03575CD{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}950573A44D2E-5169-99F4-36DB-5E24BA52{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}A893AD61B9E3-AD5A-B614-1020-C778DCDC{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}77C1492C61D7-3C1A-A5F4-6020-DF02ED9B{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}D6FAA7F76F61-3E5B-7A14-268F-CB6AB2BC{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}0BDC776154EE-0DFA-6EE4-90AE-3D9C493D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}9AD484C52311-5ADB-8AB4-E572-8B320EA0{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}B04499BA8B13-FEB9-2814-7A12-4D176933{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}3D0AC3D2985F-16D8-43E4-7EB0-E0C83B8A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}430154648B42-69FB-6004-8599-C35F47A9{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}5215ECEA6636-1BC8-D4E4-A391-E960B5AA{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}2283240FC02C-7D3A-AA54-EA6E-EE267EA4{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}E9E1523E271D-7D48-9604-5D2E-3935211D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}450634194E40-9869-1DC4-50BA-EA3A9128{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}E4F063D6B135-9649-A4E4-31B2-2E7DB63F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}BA5528A8F6CA-D378-A5B4-A3CE-7C6EA69C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}1534EEA04873-ABA8-9154-B6E6-D527BFDE{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}E789C6689A79-E78B-67C4-AE36-D937661E{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}6F90B3E6E94C-2C88-0E64-CF92-3BC186B7{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}35AF4EE50CA3-3CC8-59E4-C7A7-EF5BF7BA{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}2056DA316FC0-899B-D5B4-C567-96178B2C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4EE9888A148B-8219-D2F4-CD49-1A13AA32{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}A0A6498B21DD-BBC9-A644-2D1D-9E2A696B{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}8D64A70FCC86-759B-8B84-6995-AB0C06F7{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}DEF26003994B-BEFB-EC34-72F6-FA035D78{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}8310280FDC1A-AB9A-45B4-D9C9-E6E5E1EB{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}FD049B28C20D-B929-F394-3121-E89CAF13{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}3A7B41542153-8638-A0C4-F5C9-DE81792F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}9A8878A309F0-9719-D084-4589-363926E8{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}7D4FE5698F7D-8AAA-4924-44FE-1B0BF4D1{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}DB87BEF8FE9E-CF7A-CC74-15CC-4355F090{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}052FBD096E4B-C929-F544-6107-B4954405{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}95664B64661B-A279-4144-23FC-17BED22A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}143BAC5DCF40-1839-0C14-3F9D-333EC092{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}2B64FF51854F-A058-7804-7629-F6DA657B{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}AC122F03FA13-53A9-39E4-41F1-F587B3B3{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}123BC6EAFFBE-96CA-DD54-A063-2B0D83C2{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}96E15D9C38A6-EEF8-1EE4-3CD1-F59CF558{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}7203BE0D3BB3-D37A-A504-65BA-20727CB3{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}016590724A95-3FE9-2024-F561-F9C62339{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}0FCCBBB71FF6-EE7B-2344-9008-E1A7E022{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}E290FF2F403B-F629-5E94-E205-D882217F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}289AE30E4D23-5C98-5874-A3E7-E7B8A73A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}D626FB71B644-7C8A-FF14-0122-D6A78121{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}303E902A48C2-A1EA-68F4-DD05-E9C9F8B5{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}8D546FA28FE7-CFFB-D164-CDA9-3FFEAA1C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}17AE8DC0E3B5-182B-3F14-2312-405FD313{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}AC753A89A6D9-8EE9-2764-14A9-639D6347{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}B008CB734602-5B49-4EC4-E08B-6CF1B35E{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}7032905EA90F-0228-A694-93F5-C938C36B{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}BE64EBCB6E99-42B8-4FE4-42B3-D26FB0AB{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}E7D80E3970A3-B1D8-A234-917B-9A83DB32{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}97A6096597AF-0FDA-2774-A84E-6D6CC598{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}BDD3614B1E78-1FB9-B984-F3D5-1DDB5D7E{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}720956614EEC-0539-8724-1EEE-8848704C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}E6E7FF9CD499-EC69-4EE4-5A1F-DDE28C28{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}BC441D68460C-29A9-EC54-9CC3-E19236F6{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4C7AC6DDE421-C118-CB14-A8DB-873A4719{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}BDF11A36348F-8E9B-13B4-BFE8-13DF7E82{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}57DA32C37E7D-860A-A584-3134-3CD62735{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}F2F5C311B45D-3089-DF04-9B11-2B38D41F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}7C78DF6A55F8-F3EB-3044-8F99-452832F0{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}7A2137BBA0FD-377B-0024-D7EB-4F29065C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}FBAAEB68277A-5B5A-DAD4-C1EC-2ECF86D2{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}F6E139798098-8478-7BF4-4753-FD1FE855{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}6BAE9402CEC6-9978-8B04-69C5-E67F557A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4D5CB30D07E0-B068-B354-EDA1-BE315A09{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}CF8B82C37EF2-7058-B014-9405-AD118A64{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4CFFA6D7E6E8-C299-6704-55FD-93B8728D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4E1D6E5C7CC3-F64A-15C4-91A5-32183C41{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}90BEFF140C68-2F4A-5214-1050-E8F52713{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}0B394DD9637C-C23B-8EC4-1CF4-2C849A0A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}56A9FAF0F07A-D3FB-1AA4-86E5-46624976{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}BAAD1C6B6240-3979-8D94-FF3F-1137C0FF{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}6E8CC03C87F4-594B-CB04-0126-E431FDBF{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}5A16D3A44996-C619-13A4-5A22-9B959F7A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}EB3100597780-EABB-3004-C622-3414E7B0{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}DBC55A892EE7-439B-FB54-4FA1-BC02CB71{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}16017C887FB9-492A-24E4-5004-BAAA6F0F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}86AE077E6F59-2899-0BF4-7AA1-6650055F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}C71B13E37470-0499-6B04-0B81-DB3778FB{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}431A2DA0F634-D2BB-B2A4-B7BE-3EBCCBFF{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}3B1E83F2AA84-CBDA-FFE4-AD4B-9D4809DC{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}DCF1F6D7947E-085B-2974-BBEC-58A498F7{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}B45F5172AB85-F21A-4374-76FA-D859713E{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}37CD7E2EA78D-E86A-0274-6EC6-35D67E21{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}C968C70AC597-085A-3D74-E0ED-57153B20{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}61504E8500D8-5DF8-6A04-3210-D9D0BE96{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}70F342BDAE4F-15F8-3FC4-5E22-4DA469C4{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}511FFBF64A7F-AADB-2104-B7F1-18FC573C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}205C35C97012-DE7A-8844-42F6-82D7EEBE{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}FBA9E4CFFFB7-7F19-04E4-E841-C27F957D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}D8E04BBA740A-954B-CB44-45C6-129D50BD{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}9354207A1617-C6CB-0FA4-2932-CE0D8EEF{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}857A2577E9C4-00F8-AB94-9978-B4932B25{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}12CCB0A9D9E2-1939-FDF4-8A91-860FFFAC{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}9F374945EF79-79F9-39B4-E85E-AA6DB7CF{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}AFD42891545F-474A-9204-F9EA-11FD2A44{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}317C62E9EAA3-6F9B-7FD4-23F7-1DC96C0D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}8BCCB1D8F46B-B809-89B4-78CD-ED715245{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}1721963619AE-625A-7034-6E31-5ABDB07D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}E284724B5AC1-E67A-AD34-48B3-7D5F8B5A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}A3E73314249F-6B3B-2824-9024-B669BD09{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}BB9A9796B384-CA3A-7614-76EF-750004C8{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}259B76CFF6B1-2F69-4104-0C88-A5160025{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}AB3AD30DF066-0349-2CF4-2834-A022E6E0{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}315F6EF69E9D-DD19-E9E4-6629-0AA74D2C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}38AE5B52D777-67F9-31D4-28F5-EFC61CDC{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}B27961D561BF-965B-7214-E0FC-12DF5B87{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}67D72D7F827D-719A-D2B4-C045-485C7C89{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}620D638B9359-E168-F574-78B3-8BF6AA4C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}CA7DDEBFBB2B-4F7A-FF04-9422-3F14E026{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}467424CD5183-6C19-6D64-F5F8-F51BD8D8{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}1C3406234C6B-4CF8-69A4-4DB1-D27BA19C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}EA95B2501E8D-69C8-0F34-1FFA-F8A79E70{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}3D48E6A926A0-044B-DA84-03E9-57F5CFE4{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}908837E1F2FC-CFB9-7A14-D049-652D862E{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}24C2AD394584-2939-E214-3B54-F89B8007{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}89F28FE8B777-6D8A-85B4-1808-C7132326{" Deleted

Edited by guruwannabe, 24 April 2007 - 08:56 PM.

  • 0

#5
logreeval

logreeval

    Visiting Staff

  • Member
  • PipPipPipPip
  • 1,230 posts
Appears it is still cut off :whistling:

Just post as many as you need.
  • 0

#6
guruwannabe

guruwannabe

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}BBADDAEAD7F1-564B-BCB4-6AAA-036A19D5{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}57CF8B07E5B8-070B-BD54-9E51-F267FFAE{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}AB273C360031-DBFB-B7D4-EC43-C58B59DB{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}7E09D289A17A-3619-0094-6E5D-E11FC937{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}3A35D3BB9CA5-603B-97C4-5C08-2FA8EAC3{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}14FD583F6776-70B9-E204-7B6D-195726B8{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}3A0C1FD5280F-852A-E7A4-B15E-5159CFEC{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}6BAC7AEECEBE-8FB9-3C94-AE7D-80744771{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}987E35F1F645-4168-95C4-BE93-150C9251{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}D28DBDAF4B08-612B-CF04-5EF8-F3980373{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}3AF4FE7D9E0F-A82A-53A4-A951-05000BCB{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}AB62CB657ED9-769B-9C94-F830-EBC359BF{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}5ED55AAB407A-A22A-B214-554E-3D1D858F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}566A139815EF-D5D9-AEB4-F860-D9B0277F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}E4CEC54EB28B-146B-70E4-B04B-8E3D8287{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}BAFFF9DDB2D8-916A-3774-9529-F262CBB0{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}95080FEA07EA-138A-85A4-C6F9-CA2A98EC{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}5DAEB391253A-2C38-5B84-4A23-5EFD662F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}9A5BB5076F99-B28A-9E44-22CC-1EEA1AF2{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}C3D27E33CFCB-30A8-D3B4-D3B7-672AB63E{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}A444CD594803-C34A-F184-6D8E-D65EF3D4{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}BAA63A233936-A69B-3564-AEAA-215CAABC{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}91F704C37024-E4CA-F984-4019-893D5510{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}CA3719F8A960-7BA8-2164-6A90-C2520B4C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}DE9543204470-94DA-C5D4-B5E6-386F5C6B{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}FD451B4E03DC-FA99-AB64-693C-BFFC7C60{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}ACCF6D872E51-F4AB-22E4-1116-ADA89823{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}E386DE0BA03C-2278-05A4-6DF9-E2FAFC1A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}0F6A4781FC2C-1D19-EEB4-6C84-E72B13C8{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}58DC4AEE7DCA-DDE9-A9F4-4F7B-BA05B2B7{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}91A84B83A54F-BE9A-1D34-5DBC-9A00DDF6{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}D868421B4099-58D9-A774-BC30-DEA7AF4F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}9577E98685AD-DCCA-2CA4-4E6D-E07E392D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}5D0B8AAB7FB4-3D4A-02C4-6B0B-09063D9E{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}8F4158E92BAE-B93B-5434-A140-A20DC43A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}8E39307F5DC2-7CF8-2B94-9BAE-FDDC5FBE{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}8DF5C461FCF5-158B-5314-F394-A055B564{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}5BFD67F84291-C3C8-80E4-9B5B-B800E7A1{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}D0689C212E85-6AAB-0AC4-DA5C-21B9D8B3{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}30CF9410870B-96CB-4E84-8241-4E753DA8{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}B9B3A15BE739-E748-3864-7457-75AE9CE9{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}D9B8D521D553-2199-5954-6A97-E4CE9E6D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}11ECBABC0407-08EA-04E4-546D-1E4340C4{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}AC2F1BD1A4B7-D0AB-65C4-03FC-0A16C3DF{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}36AF962EB4AD-94DA-E7F4-6598-A69E3D94{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}1F536A18ED31-96F8-91D4-AC1C-CFFF9E66{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}2CF106279D65-C4BA-7424-A1BC-F78B1EED{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}EBB6E9B93DB6-6B48-C014-380E-66EA4DB0{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}BDD2A853ABBF-15F8-4BB4-109D-7DFE9054{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}79D6D97B931E-9F7A-3E84-BCBD-E4F60CF0{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}7CC23C753FBA-354B-94A4-5474-5FA383EE{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}5F2EEE3CCE1D-5858-79E4-CE01-A22E0E66{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}6A7FB556F840-19C9-8AD4-5D04-03B6F05F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}D616DA897E6D-B83B-03E4-6FF8-956CCF81{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}BC7B1A04617B-5B28-6D74-4124-2D5679B2{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}C5D49BD30565-C7DA-8284-E149-46D83907{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}B84AEBA14D57-0908-DBA4-BDEA-56BA255B{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}527DD1C4DED9-17CB-A9B4-D86B-9566A7BC{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}A97C32658325-6C09-CF64-77F8-7901B1E6{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}9A2CA871F9F2-FACA-C454-05A9-1A1F7AAB{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}565ADDD29370-C218-04A4-A719-702DB728{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}BC3F06E174EC-C2AA-1584-9950-89E2A53B{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}64ECC57760AC-8739-6994-EAB5-91376F67{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}ADAD75940751-E6EB-66C4-CC93-3FAACA28{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}422A8858A25F-8EB8-88A4-67A5-AB16D3A7{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}27F724ED7D33-0E28-DA64-9525-DB39A748{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}098105A2D434-4E59-3C54-C9AE-CFE6B5BA{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}FDD17191FFF9-D6FA-DE14-F451-6D0161DB{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4AFACFD27953-C28A-3FD4-5767-389B1965{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}AE4E1FD28C49-47C9-CA24-D885-EBEDB80B{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}D1D6171BECC3-762B-7994-7C83-A7AE9D3D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}D486DFCAB882-4D68-D3D4-BEBE-B25AEF03{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}F5AAA509BE19-60A8-5AD4-FD0C-E4B15919{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}007DE1E246E5-766B-FA44-7F96-149266BD{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}5095F971AB61-F748-EDE4-D9B5-41A1D3B4{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}39E61A49C6F9-31DB-3F14-B646-8CFAA418{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}52BB79C1370B-7CFB-1EF4-BB6D-03B7A7BB{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}6321F2FADB4B-2788-5234-BFBD-501ABC9E{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}58A045336354-900B-C4E4-350B-FC504523{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}06FFCE5BB899-60AB-2354-5A11-F7B16191{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}92297174E417-D148-6B54-AA78-20E21BA4{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}3E91759D44C8-5769-6A14-5FCF-7C69CC0B{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}476265C456E8-DF8B-56C4-7FF8-AE4349FA{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}6AE447E2BEF9-2ADB-63F4-530C-4EA1265A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}372B95CFD857-3A1B-F9C4-AC34-7903BAE7{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}A86B415D2047-1BDA-E684-4DD4-89DAEF6C{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}21E0928FE3C9-FD59-6834-A4C4-850D745F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}1C58714F89FC-7E7A-EDE4-0913-0E8221BF{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}BB80672967EB-6E4B-9124-982B-F153A152{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}D885128BECC9-E709-E514-AC97-6E8C78FE{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}49F7100F8AE8-CE8B-F814-C6D5-19663CA0{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}604B378B73F2-9FA9-71C4-0A57-73A579D7{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}40D633642F55-D6E9-6554-1183-037145AB{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}291AA2C95E46-1369-1B24-DE13-E59484EC{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}599A5DAB4C8E-101A-A284-B9BB-5C4553FA{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}7A68DED7664F-D129-F5B4-7F04-371ACA92{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}8D967225D5E0-A118-26A4-F54B-6216221D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}6ADA44617D52-C0E8-C364-AD7A-98563C87{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}AA86FF67B7C0-0A0A-F8E4-B672-99D941DF{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}3319E31B0C3F-BF4A-4D44-09C4-E36A9BE2{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4B9D6D1E73A7-FE3A-2C34-08F9-7AF9075D{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}0AC71D2C016C-721A-5014-74FC-0541BA6A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}3C6261CD39C0-BCA9-5CE4-91E9-4409F217{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}B152F040096E-6198-3D64-D062-B28DF72A{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}569B0CBE62D1-2D8B-A2E4-11C5-E7477F87{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}66E466A54073-1DDA-E0B4-57C1-9815E09B{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}5CE1C854FFD2-C5CA-B6B4-F9B7-3DE5FC13{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}063CBB08D8BB-D358-B8E4-D640-32E640D6{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}362C7B023E23-0B18-BC64-2B66-9880D504{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}4698DBCD6D50-8BFB-DCE4-CA32-63F32D81{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}14F60FFB5F4D-0198-AEA4-78C1-5AE6671F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}C0F18DB0EF9B-5A29-4444-00F9-E169C63F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}097DC0D5B992-72A8-0A64-7091-12679CB0{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}0EBB3AD1B307-D949-D444-D2D4-9A30BD58{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}D0DD08FF5FF3-B838-6F44-B8CA-DB34AD61{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}9A6712199543-CBB8-4614-0E0F-E474A1D8{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "afqmd" Deleted
C:\WINDOWS\System32\cssxu.exe Deleted
....
»»»»» Misc files.
C:\Documents and Settings\Hammer\Application Data\kc.tmp Deleted
C:\Documents and Settings\All Users\Favorites\Download Free Spyware Remover.url Deleted
C:\Documents and Settings\All Users\Favorites\NEW VIAGRA at Half Price!.url Deleted
C:\Documents and Settings\All Users\Favorites\Online Chat With Nude Girls.url Deleted
C:\Documents and Settings\All Users\Favorites\Order CIALIS online without leaving home..url Deleted
C:\Documents and Settings\All Users\Favorites\PC protection in under 2 minutes!.url Deleted
C:\Documents and Settings\All Users\Favorites\SEX Dating - Real Girls For Real SEX.url Deleted
C:\Documents and Settings\All Users\Favorites\Stop PopUps On Your Computer.url Deleted
C:\Documents and Settings\All Users\Favorites\VIAGRA at incredible low price. Bonus Pills!.url Deleted
C:\Documents and Settings\All Users\Favorites\View ADULT photos of REAL GIRLS!.url Deleted
C:\WINDOWS\BALLOON.WAV Deleted
C:\WINDOWS\System32\LOADCTR32.EXE Deleted
C:\Documents and Settings\All Users\Favorites\Online Pharmacy Deleted
C:\Documents and Settings\All Users\Favorites\Sex and Dating Deleted
C:\Documents and Settings\All Users\Favorites\Spyware Uninstall Deleted
C:\Documents and Settings\Hammer\Favorites\Spyware Uninstall Deleted
C:\Program Files\WareOut Deleted
C:\Casino Deleted
....
»»»»» Checking for older varients.
....

Search five digit cs, dm, kd, jb, other, files.
The following files NEED TO BE SUBMITTED to one of the following URL'S for further inspection.



Click browse, find the file then click submit.
http://www.virustota...h/index_en.html
Or http://virusscan.jotti.org/

»»»»» Other



»»»»» Current runs
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"YBrowser"="C:\\PROGRA~1\\Yahoo!\\browser\\ybrwicon.exe"
"UpdReg"="C:\\WINDOWS\\UpdReg.EXE"
"UpdateManager"="\"C:\\Program Files\\Common Files\\Sonic\\Update Manager\\sgtray.exe\" /r"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"PCMService"="\"C:\\Program Files\\Dell\\Media Experience\\PCMService.exe\""
"Motive SmartBridge"="C:\\PROGRA~1\\SBCSEL~1\\SMARTB~1\\MotiveSB.exe"
"MMTray"="C:\\Program Files\\MUSICMATCH\\MUSICMATCH Jukebox\\mm_tray.exe"
"mmtask"="C:\\Program Files\\MUSICMATCH\\MUSICMATCH Jukebox\\mmtask.exe"
"MimBoot"="C:\\PROGRA~1\\MUSICM~1\\MUSICM~2\\mimboot.exe"
"IPInSightMonitor 01"="\"C:\\Program Files\\SBC Yahoo!\\Connection Manager\\IP InSight\\IPMon32.exe\""
"DVDSentry"="C:\\WINDOWS\\System32\\DSentry.exe"
"dla"="C:\\WINDOWS\\system32\\dla\\tfswctrl.exe"
"CTSysVol"="C:\\Program Files\\Creative\\SBAudigy2\\Surround Mixer\\CTSysVol.exe"
"CTHelper"="CTHELPER.EXE"
"CTDVDDet"="C:\\Program Files\\Creative\\SBAudigy2\\DVDAudio\\CTDVDDet.EXE"
"ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"AsioReg"="REGSVR32.EXE /S CTASIO.DLL"
"2wSysTray"="C:\\Program Files\\2Wire\\2PortalMon.exe"
"YOP"="C:\\PROGRA~1\\Yahoo!\\YOP\\yop.exe /autostart"
"ViewMgr"="C:\\Program Files\\Viewpoint\\Viewpoint Manager\\ViewMgr.exe"
"sound64"="new32.exe"
"SiteAdvisor"="C:\\Program Files\\SiteAdvisor\\6066\\SiteAdv.exe"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TForm1"="browsebar.exe"
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"DellSupport"="\"C:\\Program Files\\DellSupport\\DSAgnt.exe\" /startup"
"br0ken"="PasswdMon.exe"
"Steam"="\"C:\\Program Files\\Steam\\Steam.exe\" -silent"
"Yahoo! Pager"="\"C:\\PROGRA~1\\Yahoo!\\MESSEN~1\\YAHOOM~1.EXE\" -quiet"
"MoneyAgent"="\"C:\\Program Files\\Microsoft Money\\System\\mnyexpr.exe\""
"typeconf"="ssweeper.exe"
"Sonic RecordNow!"=""
"SB Audigy 2 Startup Menu"="/L:ENG"
....
Hosts file was reset, If you use a custom hosts file please replace it
»»»»» End report »»»»»
  • 0

#7
guruwannabe

guruwannabe

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Logfile of HijackThis v1.99.1
Scan saved at 9:41:13 PM, on 4/24/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\SiteAdvisor\6066\SAService.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\WINDOWS\System32\CTHELPER.EXE
C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\2Wire\2PortalMon.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\SiteAdvisor\6066\SiteAdv.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Yahoo!\browser\ybrowser.exe
C:\Documents and Settings\Hammer\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: (no name) - {F423D68E-F65A-2225-943D-C76A505B0334} - UserSp1.dll (file missing)
R3 - URLSearchHook: (no name) - {4422343C-8407-265A-8366-14404A72C498} - porka_.dll (file missing)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {73364D99-1240-4dff-B12A-67E448373148} - C:\WINDOWS\System32\ipv6mons.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: McAfee Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - c:\program files\mcafee\mps\mcpopup.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe"
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire\2PortalMon.exe
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [sound64] new32.exe
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6066\SiteAdv.exe
O4 - HKCU\..\Run: [TForm1] browsebar.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [br0ken] PasswdMon.exe
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [typeconf] ssweeper.exe
O4 - HKCU\..\Run: [SB Audigy 2 Startup Menu] /L:ENG
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Startup: Registration Myst V
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: AT&T Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\program files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\program files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {0713E8D2-850A-101B-AFC0-4210102A8DA7} (Microsoft ProgressBar Control, version 5.0 (SP2)) - http://download.mcaf...22/ComCtl32.cab
O16 - DPF: {FFFFFFFF-CACE-BABE-BABE-00AA0055595A} - http://www.trueswitc...eInstallSBC.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{24BF6395-1A3E-4592-AE30-DE77A624D7F2}: NameServer = 85.255.116.163,85.255.112.121
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.163 85.255.112.121
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: SiteAdvisor Service - McAfee, Inc. - C:\Program Files\SiteAdvisor\6066\SAService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE
  • 0

#8
logreeval

logreeval

    Visiting Staff

  • Member
  • PipPipPipPip
  • 1,230 posts
Hey :whistling:

You should print out these instructions, or copy them to a NotePad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.

R3 - URLSearchHook: (no name) - {F423D68E-F65A-2225-943D-C76A505B0334} - UserSp1.dll (file missing)
R3 - URLSearchHook: (no name) - {4422343C-8407-265A-8366-14404A72C498} - porka_.dll (file missing)
O2 - BHO: (no name) - {73364D99-1240-4dff-B12A-67E448373148} - C:\WINDOWS\System32\ipv6mons.dll
O4 - HKLM\..\Run: [sound64] new32.exe
O4 - HKCU\..\Run: [TForm1] browsebar.exe
O4 - HKCU\..\Run: [br0ken] PasswdMon.exe
O4 - HKCU\..\Run: [typeconf] ssweeper.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{24BF6395-1A3E-4592-AE30-DE77A624D7F2}: NameServer = 85.255.116.163,85.255.112.121
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.163 85.255.112.121

Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis. Reboot into safe mode.

Restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode.

Using Windows Explorer (to get there right-click your Start button and go to "Explore"), please delete these files (if present):

C:\Windows\System32\new32.exe
C:\Windows\System32\browsebar.exe
C:\Windows\System32\PasswdMon.exe
C:\Windows\System32\ssweeper.exe


After that, Reboot.

===============

Download and scan with SUPERAntiSpyware Free for Home Users
  • Double-click SUPERAntiSypware.exe and use the default settings for installation.
  • An icon will be created on your desktop. Double-click that icon to launch the program.
  • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here.)
  • Under "Configuration and Preferences", click the Preferences button.
  • Click the Scanning Control tab.
  • Under Scanner Options make sure the following are checked (leave all others unchecked):
    • Close browsers before scanning.
    • Scan for tracking cookies.
    • Terminate memory threats before quarantining.
  • Click the "Close" button to leave the control center screen.
  • Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
  • On the left, make sure you check C:\Fixed Drive.
  • On the right, under "Complete Scan", choose Perform Complete Scan.
  • Click "Next" to start the scan. Please be patient while it scans your computer.
  • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
  • Make sure everything has a checkmark next to it and click "Next".
  • A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
  • If asked if you want to reboot, click "Yes".
  • To retrieve the removal information after reboot, launch SUPERAntispyware again.
    • Click Preferences, then click the Statistics/Logs tab.
    • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    • If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    • Please copy and paste the Scan Log results in your next reply.
  • Click Close to exit the program.
================

When done post the SUPERAntispyware log, a fresh HijackThis log and how things are running.

logreeval
  • 0

#9
guruwannabe

guruwannabe

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
ok everything seems to be running great so far. Thanks so much. One quick question before i post the hijack and anitsprware logs. What should I be using to prevent this. Between my service provider and McAfee I thought i was covered. What do you recommend.

SUPERAntiSpyware Scan Log
Generated 04/26/2007 at 02:37 AM

Application Version : 3.6.1000

Core Rules Database Version : 3225
Trace Rules Database Version: 1236

Scan type : Complete Scan
Total Scan Time : 02:01:11

Memory items scanned : 487
Memory threats detected : 0
Registry items scanned : 6337
Registry threats detected : 21
File items scanned : 119906
File threats detected : 116

Parasite.Porka
HKLM\Software\Classes\CLSID\{4422343C-8407-265A-8366-14404A72C498}
HKCR\CLSID\{4422343C-8407-265A-8366-14404A72C498}
HKCR\CLSID\{4422343C-8407-265A-8366-14404A72C498}\InprocServer32
PORKA_.DLL

Trojan.Media-Codec/V2
HKLM\Software\Classes\CLSID\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE}
HKCR\CLSID\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE}
HKCR\CLSID\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE}
HKCR\CLSID\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE}\InprocServer32
HKCR\CLSID\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE}\InprocServer32#ThreadingModel
C:\PROGRAM FILES\VIDEO AX OBJECT\BPVOL.DLL
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Browser Protection Volume
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Browser Protection Volume#DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Browser Protection Volume#UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Explorer Secure Plug-in
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Explorer Secure Plug-in#DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Explorer Secure Plug-in#UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Security Messenger
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Security Messenger#DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Security Messenger#UninstallString
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0012074.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0012075.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0012076.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0012090.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0012091.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0012092.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0012105.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0012106.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0012107.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0012211.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0012212.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0012213.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0013212.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0013213.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0013214.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0013249.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0013250.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0013251.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0013252.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0013254.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0013255.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0013256.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0013257.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0013258.EXE

Parasite.WareOut
HKLM\Software\Classes\CLSID\{F423D68E-F65A-2225-943D-C76A505B0334}
HKCR\CLSID\{F423D68E-F65A-2225-943D-C76A505B0334}
HKCR\CLSID\{F423D68E-F65A-2225-943D-C76A505B0334}\InprocServer32
USERSP1.DLL

Adware.Tracking Cookie
C:\Documents and Settings\Hammer\Cookies\[email protected][1].txt
C:\Documents and Settings\Hammer\Cookies\[email protected][1].txt
C:\Documents and Settings\Hammer\Cookies\hammer@interclick[2].txt
C:\Documents and Settings\Hammer\Cookies\hammer@advertising[2].txt
C:\Documents and Settings\Hammer\Cookies\hammer@doubleclick[1].txt
C:\Documents and Settings\Hammer\Cookies\hammer@nextag[1].txt
C:\Documents and Settings\Hammer\Cookies\hammer@casalemedia[2].txt
C:\Documents and Settings\Hammer\Cookies\[email protected][1].txt
C:\Documents and Settings\Hammer\Cookies\hammer@247realmedia[1].txt
C:\Documents and Settings\Hammer\Cookies\hammer@mediaplex[1].txt
C:\Documents and Settings\Hammer\Cookies\[email protected][1].txt
C:\Documents and Settings\Hammer\Cookies\hammer@adultfriendfinder[2].txt
C:\Documents and Settings\Hammer\Cookies\[email protected][2].txt
C:\Documents and Settings\Hammer\Cookies\hammer@xiti[1].txt
C:\Documents and Settings\Hammer\Cookies\hammer@statcounter[1].txt
C:\Documents and Settings\Hammer\Cookies\hammer@atdmt[2].txt
C:\Documents and Settings\Hammer\Cookies\hammer@ad[2].txt
C:\Documents and Settings\Hammer\Cookies\hammer@fortunecity[1].txt
C:\Documents and Settings\Hammer\Local Settings\Temp\Cookies\hammer@rightmedia[1].txt

Adware.AdSponsor
HKCR\AppId\{73364D99-1240-4dff-B12A-67E448373148}

Trojan.Downloader-YAY
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006812.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006813.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006814.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006815.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006816.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006817.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006818.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006819.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006820.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006821.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006822.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006823.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006824.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006825.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006826.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006827.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006828.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006829.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006830.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006831.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006832.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006833.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006834.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006835.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006836.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006837.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006838.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006839.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006840.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006841.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006608.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006609.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006610.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006611.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006612.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006613.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006614.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006615.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006616.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006617.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006618.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006619.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006620.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006621.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006622.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006623.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006624.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006625.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006626.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006627.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006628.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006629.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006630.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006631.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006632.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006633.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006634.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006635.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006636.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006637.EXE

Trojan.Unknown Origin
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0013253.ICO
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0013259.ICO

Trojan.DOmen
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0013277.EXE

Trojan.Downloader-UDL2
C:\WINDOWS\35D748NE.EXE
C:\WINDOWS\3W73U98M.EXE
C:\WINDOWS\EGMIBQ5J.EXE
C:\WINDOWS\HD7II2XS.EXE
C:\WINDOWS\P3PHH32D.EXE
C:\WINDOWS\SSSSDF1F.EXE

Trojan.XDUD
C:\WINDOWS\SYSTEM32\FK.DLL


Logfile of HijackThis v1.99.1
Scan saved at 2:02:57 PM, on 4/26/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\SiteAdvisor\6066\SAService.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\WINDOWS\System32\CTHELPER.EXE
C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\2Wire\2PortalMon.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\SiteAdvisor\6066\SiteAdv.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\System32\notepad.exe
C:\Program Files\Yahoo!\browser\ybrowser.exe
C:\Documents and Settings\Hammer\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: McAfee Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - c:\program files\mcafee\mps\mcpopup.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe"
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire\2PortalMon.exe
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6066\SiteAdv.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [SB Audigy 2 Startup Menu] /L:ENG
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Startup: Registration Myst V
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: AT&T Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\program files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\program files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {0713E8D2-850A-101B-AFC0-4210102A8DA7} (Microsoft ProgressBar Control, version 5.0 (SP2)) - http://download.mcaf...22/ComCtl32.cab
O16 - DPF: {FFFFFFFF-CACE-BABE-BABE-00AA0055595A} - http://www.trueswitc...eInstallSBC.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: SiteAdvisor Service - McAfee, Inc. - C:\Program Files\SiteAdvisor\6066\SAService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE
  • 0

#10
guruwannabe

guruwannabe

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
ok everything seems to be running great so far. Thanks so much. One quick question before i post the hijack and anitspyware logs. What should I be using to prevent this. Between my service provider and McAfee I thought i was covered. What do you recommend?

SUPERAntiSpyware Scan Log
Generated 04/26/2007 at 02:37 AM

Application Version : 3.6.1000

Core Rules Database Version : 3225
Trace Rules Database Version: 1236

Scan type : Complete Scan
Total Scan Time : 02:01:11

Memory items scanned : 487
Memory threats detected : 0
Registry items scanned : 6337
Registry threats detected : 21
File items scanned : 119906
File threats detected : 116

Parasite.Porka
HKLM\Software\Classes\CLSID\{4422343C-8407-265A-8366-14404A72C498}
HKCR\CLSID\{4422343C-8407-265A-8366-14404A72C498}
HKCR\CLSID\{4422343C-8407-265A-8366-14404A72C498}\InprocServer32
PORKA_.DLL

Trojan.Media-Codec/V2
HKLM\Software\Classes\CLSID\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE}
HKCR\CLSID\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE}
HKCR\CLSID\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE}
HKCR\CLSID\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE}\InprocServer32
HKCR\CLSID\{D34F5D71-99E4-4D96-91CA-F4104F69B8AE}\InprocServer32#ThreadingModel
C:\PROGRAM FILES\VIDEO AX OBJECT\BPVOL.DLL
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Browser Protection Volume
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Browser Protection Volume#DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Browser Protection Volume#UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Explorer Secure Plug-in
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Explorer Secure Plug-in#DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Explorer Secure Plug-in#UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Security Messenger
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Security Messenger#DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Security Messenger#UninstallString
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0012074.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0012075.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0012076.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0012090.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0012091.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0012092.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0012105.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0012106.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0012107.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0012211.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0012212.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0012213.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0013212.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0013213.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0013214.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0013249.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0013250.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0013251.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0013252.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0013254.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0013255.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0013256.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0013257.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0013258.EXE

Parasite.WareOut
HKLM\Software\Classes\CLSID\{F423D68E-F65A-2225-943D-C76A505B0334}
HKCR\CLSID\{F423D68E-F65A-2225-943D-C76A505B0334}
HKCR\CLSID\{F423D68E-F65A-2225-943D-C76A505B0334}\InprocServer32
USERSP1.DLL

Adware.Tracking Cookie
C:\Documents and Settings\Hammer\Cookies\[email protected][1].txt
C:\Documents and Settings\Hammer\Cookies\[email protected][1].txt
C:\Documents and Settings\Hammer\Cookies\hammer@interclick[2].txt
C:\Documents and Settings\Hammer\Cookies\hammer@advertising[2].txt
C:\Documents and Settings\Hammer\Cookies\hammer@doubleclick[1].txt
C:\Documents and Settings\Hammer\Cookies\hammer@nextag[1].txt
C:\Documents and Settings\Hammer\Cookies\hammer@casalemedia[2].txt
C:\Documents and Settings\Hammer\Cookies\[email protected][1].txt
C:\Documents and Settings\Hammer\Cookies\hammer@247realmedia[1].txt
C:\Documents and Settings\Hammer\Cookies\hammer@mediaplex[1].txt
C:\Documents and Settings\Hammer\Cookies\[email protected][1].txt
C:\Documents and Settings\Hammer\Cookies\hammer@adultfriendfinder[2].txt
C:\Documents and Settings\Hammer\Cookies\[email protected][2].txt
C:\Documents and Settings\Hammer\Cookies\hammer@xiti[1].txt
C:\Documents and Settings\Hammer\Cookies\hammer@statcounter[1].txt
C:\Documents and Settings\Hammer\Cookies\hammer@atdmt[2].txt
C:\Documents and Settings\Hammer\Cookies\hammer@ad[2].txt
C:\Documents and Settings\Hammer\Cookies\hammer@fortunecity[1].txt
C:\Documents and Settings\Hammer\Local Settings\Temp\Cookies\hammer@rightmedia[1].txt

Adware.AdSponsor
HKCR\AppId\{73364D99-1240-4dff-B12A-67E448373148}

Trojan.Downloader-YAY
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006812.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006813.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006814.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006815.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006816.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006817.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006818.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006819.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006820.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006821.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006822.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006823.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006824.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006825.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006826.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006827.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006828.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006829.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006830.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006831.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006832.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006833.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006834.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006835.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006836.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006837.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006838.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006839.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006840.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0006841.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006608.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006609.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006610.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006611.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006612.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006613.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006614.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006615.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006616.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006617.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006618.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006619.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006620.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006621.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006622.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006623.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006624.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006625.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006626.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006627.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006628.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006629.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006630.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006631.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006632.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006633.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006634.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006635.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006636.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\A0006637.EXE

Trojan.Unknown Origin
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0013253.ICO
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0013259.ICO

Trojan.DOmen
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP29\A0013277.EXE

Trojan.Downloader-UDL2
C:\WINDOWS\35D748NE.EXE
C:\WINDOWS\3W73U98M.EXE
C:\WINDOWS\EGMIBQ5J.EXE
C:\WINDOWS\HD7II2XS.EXE
C:\WINDOWS\P3PHH32D.EXE
C:\WINDOWS\SSSSDF1F.EXE

Trojan.XDUD
C:\WINDOWS\SYSTEM32\FK.DLL


Logfile of HijackThis v1.99.1
Scan saved at 2:02:57 PM, on 4/26/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\SiteAdvisor\6066\SAService.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\WINDOWS\System32\CTHELPER.EXE
C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\2Wire\2PortalMon.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\SiteAdvisor\6066\SiteAdv.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\System32\notepad.exe
C:\Program Files\Yahoo!\browser\ybrowser.exe
C:\Documents and Settings\Hammer\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: McAfee Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - c:\program files\mcafee\mps\mcpopup.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe"
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire\2PortalMon.exe
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6066\SiteAdv.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [SB Audigy 2 Startup Menu] /L:ENG
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Startup: Registration Myst V
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: AT&T Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\program files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\program files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {0713E8D2-850A-101B-AFC0-4210102A8DA7} (Microsoft ProgressBar Control, version 5.0 (SP2)) - http://download.mcaf...22/ComCtl32.cab
O16 - DPF: {FFFFFFFF-CACE-BABE-BABE-00AA0055595A} - http://www.trueswitc...eInstallSBC.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: SiteAdvisor Service - McAfee, Inc. - C:\Program Files\SiteAdvisor\6066\SAService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE
  • 0

#11
logreeval

logreeval

    Visiting Staff

  • Member
  • PipPipPipPip
  • 1,230 posts
Congratulations! You are clean :blink:

Now that you are clean of all malware, there are a few steps I need you to complete:

Defrag your Hard Drive, to do this:
  • Click Start>> Run>> Type Compmgmt.msc.
  • Click Disk Defragmenter.
  • Click the volume that you want to defragment(Usually C:) and then click Defragment.
Now, you need to clear your restore points. Here is a tutorial on how-to.

The following are some tips to prevent future infection:

Anti-Spyware Scanners are important to have, I recommend you scan at least once every 2 weeks:
AVG Antispyware
A-Squared Antispyware


Real Time Anti-Spyware Programs protect you in Real-Time, not just scan after you infected, they are nice to have to prevent infections:
SpywareGuard
SpywareBlaster
SpywareTerminator


Internet Explorer is not the most secure browser available. I recommend using one of these browsers:
Firefox
Opera

*NOTE*If you keep Internet Explorer, here is a link to tighten up the security of Internet Explorer.

It is important to clear out temporary files, many types of malware hide in the temp, here are some programs to clear out the temp folders:
CCleaner
ATF Cleaner


Windows Update is a very important thing to do. It contains critical security patches for Internet Explorer and Windows.

If you want to read a little bit, you can check this out - Must Read Info!

Congratulations and happy surfing! :whistling:
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP