Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

XP Loss of Control Panel - Manager restrictions


  • Please log in to reply

#1
JThomas

JThomas

    New Member

  • Member
  • Pip
  • 5 posts
Hi, for some time I have had problems with Windows XP Home. No Control Panel, so I cannot for example add or delete programs. If I launch in Safe mode and choose "Administrator" account there is still no Control Panel so I cannot create or change accounts.
I saw someone else had a similar problem but I think your advice is to post a new topic.
This is a Dell PC with no Windows CD. I have always relied on the "restore" function, but now if I run it it runs and then finishes with a message like "restore was not possible".
I am the only user and at home, but it is for my work so I need it to run OK. I have no computer training.

(NB: I am a Brit working in France on a French version of XP Home, so in some cases I am (mis-) translating the messages etc. I failed to find a French-language forum offering a solution. Btw I was in contact with the Theeldergeek forum and now strangely I cannot open it at all, direct or via Google.)

In addition to this, more and more functions are giving a message like "not available -restrictions by Manager" (in my French version "Administrateur"). Including : "configure default programs". Or running regedit..
Even things like: Rclick on desktop – properties – screen etc" or (since yesterday) "Control -Alt-Delete" give a message "This function has been deactivated by the Administrator" or "Task Manager deactivated by Administrator"
I have followed the initial stages given in the GeekToGo advice (ATF cleaner – AVGAS – SuperAntiSpyware –AVG Free - Panda). I have kept the reports/logs, except for AVGas in which I got a message "No reports available, although it found 14 items of malware including 3 of High risk (sorry I did not note them). I will paste the Hijackthis.log below.
I tried Windows Update for Service Pack 1a but could not get a download link anywhere.
Grateful for any help.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:01:20, on 16/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\SPAMfighter\sfus.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BE.EXE
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\SPAMfighter\SFAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\vTuner\vTuner.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\OLIFAXVX\TOOLBAR.EXE
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\RegistryClear\RegistryClear.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
F2 - REG:system.ini: Shell=Explorer.exe
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - (no file)
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\Run: [EPSON Stylus CX3600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BE.EXE /P26 "EPSON Stylus CX3600 Series" /O6 "USB001" /M "Stylus CX3600"
O4 - HKLM\..\Run: [winwp.exe] C:\WINDOWS\system32\winwp.exe
O4 - HKLM\..\Run: [4F.tmp] C:\DOCUME~1\JULIAN~1\LOCALS~1\Temp\4F.tmp.exe
O4 - HKLM\..\Run: [4F.tmp.exe] C:\DOCUME~1\JULIAN~1\LOCALS~1\Temp\4F.tmp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SDR6V_Check] "C:\Program Files\Fichiers communs\DriveCleaner Free\udcsdr.exe"
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SPAMfighter Agent] "C:\Program Files\SPAMfighter\SFAgent.exe" update delay 60
O4 - HKLM\..\Run: [ErrorKiller] C:\Program Files\ErrorKiller\ErrorKiller.exe
O4 - HKLM\..\Run: [RegistryClear] C:\Program Files\RegistryClear\RegistryClear.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [vTunerStartUp] C:\PROGRA~1\vTuner\vTuner.exe WinStart=Yes
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [EPSON Stylus CX3600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BE.EXE /P26 "EPSON Stylus CX3600 Series" /M "Stylus CX3600" /EF "HKCU"
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [^SetupICWDesktop] (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] (User 'Default user')
O4 - Startup: Barre d'Outils Olitec.lnk = C:\OLIFAXVX\TOOLBAR.EXE
O4 - Startup: Moniteur Fax-Voix.lnk = C:\OLIFAXVX\MONITEUR.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Search - http://edits.mywebse...arch.jhtml?p=ZN
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Internet Radio by Endicosoft.com - {1F958B09-3312-7f0e-9723-4C1324C57B20} - C:\Program Files\Internet Radio\Radio.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.orange.fr (file missing) (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.mi...b?1195150083812
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\sulimo.dat
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: SPAMfighter Update Service - SPAMfighter ApS - C:\Program Files\SPAMfighter\sfus.exe

--
End of file - 9348 bytes
  • 0

Advertisements


#2
JThomas

JThomas

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts
I had no replies to my post this morning (16 Nov). But I read in your advice that one should look first at similar cases. After spending days on this problem I found the fix you suggested to Mr Urrieta (sorry fulll name not onthis screen), involving SmitFraudFix and SDFix. To my inexpressible joy, it brought back my Control Panel. I have not tried everything again, but thanks and congratulations.
SmitFraud did not yield a usable report - it was in French and was barred by a message saying "registry changes disabled by Manager". It had no headers (File etc) and would not highlight for copying. Below is the SDFix report.


SDFix: Version 1.114

Run by Julian Thomas on 16/11/2007 at 19:09

Microsoft Windows XP [version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting...


Normal Mode:
Checking Files:

Trojan Files Found:

C:\WINDOWS\SYSTEM32\ADDPS32.EXE - Deleted
C:\WINDOWS\SYSTEM32\ATLQC32.EXE - Deleted
C:\WINDOWS\SYSTEM32\CRLM.EXE - Deleted
C:\WINDOWS\SYSTEM32\D3YP.EXE - Deleted
C:\WINDOWS\SYSTEM32\IEVE.EXE - Deleted
C:\WINDOWS\SYSTEM32\NTCX32.EXE - Deleted
C:\WINDOWS\SYSTEM32\APIGM32.DLL - Deleted
C:\WINDOWS\SYSTEM32\APPYN32.DLL - Deleted
C:\WINDOWS\SYSTEM32\ATLPM32.DLL - Deleted
C:\WINDOWS\SYSTEM32\ATLVJ32.DLL - Deleted
C:\WINDOWS\SYSTEM32\ATLXV.DLL - Deleted
C:\WINDOWS\SYSTEM32\CRMY.DLL - Deleted
C:\WINDOWS\SYSTEM32\CRMZ32.DLL - Deleted
C:\WINDOWS\SYSTEM32\IEKK32.DLL - Deleted
C:\WINDOWS\SYSTEM32\IPWS32.DLL - Deleted
C:\WINDOWS\SYSTEM32\JAVASL.DLL - Deleted
C:\WINDOWS\SYSTEM32\MFCMQ32.DLL - Deleted
C:\WINDOWS\SYSTEM32\NETFT.DLL - Deleted
C:\WINDOWS\SYSTEM32\NETPT.DLL - Deleted
C:\WINDOWS\SYSTEM32\SDKSD32.DLL - Deleted
C:\WINDOWS\SYSTEM32\SYSEI32.DLL - Deleted
C:\WINDOWS\SYSTEM32\SYSRM.DLL - Deleted
C:\WINDOWS\SYSTEM32\VUEJI.DLL - Deleted



Removing Temp Files...

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

catchme 0.3.1262.1 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-16 19:14:13
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

scanning hidden registry entries ...

scanning hidden files ...

C:\Documents and Settings\Julian Thomas\Local Settings\Application Data\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{3490CF8D-126B-E8C5-B2EF-BAD83B2D8BDA}\01\10-{3490CF8D-126B-E8C5-B2EF-BAD83B2D8BDA}-v1-{937CE049-ABC3-40B8-9E7F-C765610A24F6}-v10-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 1


Remaining Services:
------------------



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe:*:Enabled:avgemc.exe"
"C:\\WINDOWS\\Temp\\NavBrowser.exe"="C:\\WINDOWS\\Temp\\NavBrowser.exe:*:Disabled:NAVBrowser"
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"="C:\\Program Files\\Real\\RealPlayer\\realplay.exe:*:Enabled:RealPlayer"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe:*:Enabled:avgcc.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\concept design\\onlineTV 3\\onlineTV.exe"="C:\\Program Files\\concept design\\onlineTV 3\\onlineTV.exe:*:Enabled:onlineTV"
"C:\\Program Files\\Windows Media Player\\wmplayer.exe"="C:\\Program Files\\Windows Media Player\\wmplayer.exe:*:Enabled:Lecteur Windows Media"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.0"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\Twonkyvision\\TwonkyMusic.exe"="C:\\Program Files\\Twonkyvision\\TwonkyMusic.exe:*:Enabled:TwonkyMusic"
"C:\\Program Files\\Outlook Express\\msimn.exe"="C:\\Program Files\\Outlook Express\\msimn.exe:*:Enabled:Outlook Express"
"C:\\Program Files\\MSN Gaming Zone\\Windows\\shvlzm.exe"="C:\\Program Files\\MSN Gaming Zone\\Windows\\shvlzm.exe:*:Enabled:Atout Pique sur Internet"
"%windir%\\system32\\winav.exe"="%windir%\\system32\\winav.exe:*:Enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\concept design\\onlineTV 3\\onlineTV.exe"="C:\\Program Files\\concept design\\onlineTV 3\\onlineTV.exe:*:Enabled:onlineTV"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.0"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"%windir%\\system32\\winav.exe"="%windir%\\system32\\winav.exe:*:Enabled:@xpsp2res.dll,-22019"

Remaining Files:
---------------

File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes:

Sat 25 Mar 2006 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Mon 12 Nov 2007 52,736 ...H. --- "C:\Documents and Settings\Julian Thomas\Bureau\DellAdminProb1107\~WRL0001.tmp"
Sun 17 Oct 2004 159,232 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\Voc\~WRL2304.tmp"
Sun 17 Oct 2004 160,256 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\Voc\~WRL2676.tmp"
Fri 13 Feb 2004 2,688 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\admin\~WRL0001.tmp"
Mon 24 Jun 2002 21,504 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\admin\~WRL1662.tmp"
Tue 27 Jan 2004 24,576 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\corresp\~WRL0001.tmp"
Thu 9 Dec 2004 25,600 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\corresp\~WRL0003.tmp"
Wed 22 May 2002 23,552 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\corresp\~WRL0005.tmp"
Wed 28 Sep 2005 11,264 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\Cucuron\~WRL0459.tmp"
Sat 1 Jun 2002 19,456 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\Family\~WRL2241.tmp"
Wed 2 Mar 2005 25,088 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\IT\~WRL0005.tmp"
Thu 10 Jul 2003 20,480 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\Location\~WRL0003.tmp"
Tue 2 Dec 2003 19,456 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\Location\~WRL3165.tmp"
Fri 12 Sep 2003 162 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\PROcorresp\~$TECOUV.BAK"
Thu 31 Mar 2005 19,456 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\PROcorresp\~WRL0001.tmp"
Mon 9 Nov 1998 11,264 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\Profadm\~WRL0606.tmp"
Fri 13 Feb 2004 2,688 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\admin\~WRL0001.tmp"
Mon 24 Jun 2002 21,504 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\admin\~WRL1662.tmp"
Tue 27 Jan 2004 24,576 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\corresp\~WRL0001.tmp"
Thu 9 Dec 2004 25,600 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\corresp\~WRL0003.tmp"
Wed 22 May 2002 23,552 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\corresp\~WRL0005.tmp"
Wed 28 Sep 2005 11,264 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\Cucuron\~WRL0459.tmp"
Sat 1 Jun 2002 19,456 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\Family\~WRL2241.tmp"
Wed 2 Mar 2005 25,088 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\IT\~WRL0005.tmp"
Thu 10 Jul 2003 20,480 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\Location\~WRL0003.tmp"
Tue 2 Dec 2003 19,456 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\Location\~WRL3165.tmp"
Fri 12 Sep 2003 162 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\PROcorresp\~$TECOUV.BAK"
Thu 31 Mar 2005 19,456 ...H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\PROcorresp\~WRL0001.tmp"
Fri 20 Jul 2007 63,488 ...H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\Profadm\~WRL0003.tmp"
Mon 9 Nov 1998 11,264 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\Profadm\~WRL0606.tmp"
Wed 30 Mar 2005 11,264 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsBSS\BEYA\~WRL0806.tmp"
Sat 1 Jul 2006 24,576 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsBSS\BEYA\~WRL0936.tmp"
Wed 14 Jan 2004 20,992 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsBSS\MAYA\~WRL1366.tmp"
Sat 25 Mar 2006 4,348 ...H. --- "C:\Documents and Settings\Julian Thomas\Mes documents\Ma musique\Sauvegarde de la licence\drmv1key.bak"
Sat 25 Mar 2006 20 A..H. --- "C:\Documents and Settings\Julian Thomas\Mes documents\Ma musique\Sauvegarde de la licence\drmv1lic.bak"
Sat 25 Mar 2006 312 ...H. --- "C:\Documents and Settings\Julian Thomas\Mes documents\Ma musique\Sauvegarde de la licence\drmv2key.bak"
Sat 25 Mar 2006 1,536 A..H. --- "C:\Documents and Settings\Julian Thomas\Mes documents\Ma musique\Sauvegarde de la licence\drmv2lic.bak"
Sat 15 Jul 2006 21,504 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\admin\Banks\~WRL1421.tmp"
Thu 2 Feb 2006 22,528 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\admin\Banks\~WRL3412.tmp"
Tue 27 Jul 2004 11,264 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\Cucuron\Terrasse\~WRL1735.tmp"
Mon 7 Feb 2005 11,264 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\Cucuron\Terrasse\~WRL3985.tmp"
Tue 23 Nov 2004 20,992 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\Profadm\ClientInfo\~WRL0003.tmp"
Fri 7 Jan 2005 20,480 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\Profadm\ClientInfo\~WRL0004.tmp"
Sun 12 Dec 2004 22,528 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\Profadm\ClientInfo\~WRL1278.tmp"
Sun 12 Dec 2004 20,480 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\Profadm\ClientInfo\~WRL3181.tmp"
Sat 15 Jul 2006 21,504 ...H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\admin\Banks\~WRL1421.tmp"
Thu 2 Feb 2006 22,528 ...H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\admin\Banks\~WRL3412.tmp"
Tue 27 Jul 2004 11,264 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\Cucuron\Terrasse\~WRL1735.tmp"
Mon 7 Feb 2005 11,264 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\Cucuron\Terrasse\~WRL3985.tmp"
Tue 23 Nov 2004 20,992 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\Profadm\ClientInfo\~WRL0003.tmp"
Fri 7 Jan 2005 20,480 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\Profadm\ClientInfo\~WRL0004.tmp"
Sun 12 Dec 2004 22,528 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\Profadm\ClientInfo\~WRL1278.tmp"
Sun 12 Dec 2004 20,480 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\Profadm\ClientInfo\~WRL3181.tmp"

Finished!
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP