XP Loss of Control Panel - Manager restrictions - Geeks to Go Forums

Jump to content

Log in Register Register Malware removal guide How it works

XP Loss of Control Panel - Manager restrictions No Control panel and increasing restrictions on operations

#1 JThomas

  • Group: Member
  • Posts: 5
  • Joined: 16-November 07

Posted 16 November 2007 - 03:50 AM

Hi, for some time I have had problems with Windows XP Home. No Control Panel, so I cannot for example add or delete programs. If I launch in Safe mode and choose "Administrator" account there is still no Control Panel so I cannot create or change accounts.
I saw someone else had a similar problem but I think your advice is to post a new topic.
This is a Dell PC with no Windows CD. I have always relied on the "restore" function, but now if I run it it runs and then finishes with a message like "restore was not possible".
I am the only user and at home, but it is for my work so I need it to run OK. I have no computer training.

(NB: I am a Brit working in France on a French version of XP Home, so in some cases I am (mis-) translating the messages etc. I failed to find a French-language forum offering a solution. Btw I was in contact with the Theeldergeek forum and now strangely I cannot open it at all, direct or via Google.)

In addition to this, more and more functions are giving a message like "not available -restrictions by Manager" (in my French version "Administrateur"). Including : "configure default programs". Or running regedit..
Even things like: Rclick on desktop – properties – screen etc" or (since yesterday) "Control -Alt-Delete" give a message "This function has been deactivated by the Administrator" or "Task Manager deactivated by Administrator"
I have followed the initial stages given in the GeekToGo advice (ATF cleaner – AVGAS – SuperAntiSpyware –AVG Free - Panda). I have kept the reports/logs, except for AVGas in which I got a message "No reports available, although it found 14 items of malware including 3 of High risk (sorry I did not note them). I will paste the Hijackthis.log below.
I tried Windows Update for Service Pack 1a but could not get a download link anywhere.
Grateful for any help.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:01:20, on 16/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\SPAMfighter\sfus.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BE.EXE
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\SPAMfighter\SFAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\vTuner\vTuner.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\OLIFAXVX\TOOLBAR.EXE
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\RegistryClear\RegistryClear.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
F2 - REG:system.ini: Shell=Explorer.exe
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - (no file)
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\Run: [EPSON Stylus CX3600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BE.EXE /P26 "EPSON Stylus CX3600 Series" /O6 "USB001" /M "Stylus CX3600"
O4 - HKLM\..\Run: [winwp.exe] C:\WINDOWS\system32\winwp.exe
O4 - HKLM\..\Run: [4F.tmp] C:\DOCUME~1\JULIAN~1\LOCALS~1\Temp\4F.tmp.exe
O4 - HKLM\..\Run: [4F.tmp.exe] C:\DOCUME~1\JULIAN~1\LOCALS~1\Temp\4F.tmp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SDR6V_Check] "C:\Program Files\Fichiers communs\DriveCleaner Free\udcsdr.exe"
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SPAMfighter Agent] "C:\Program Files\SPAMfighter\SFAgent.exe" update delay 60
O4 - HKLM\..\Run: [ErrorKiller] C:\Program Files\ErrorKiller\ErrorKiller.exe
O4 - HKLM\..\Run: [RegistryClear] C:\Program Files\RegistryClear\RegistryClear.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [vTunerStartUp] C:\PROGRA~1\vTuner\vTuner.exe WinStart=Yes
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [EPSON Stylus CX3600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BE.EXE /P26 "EPSON Stylus CX3600 Series" /M "Stylus CX3600" /EF "HKCU"
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [^SetupICWDesktop] (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] (User 'Default user')
O4 - Startup: Barre d'Outils Olitec.lnk = C:\OLIFAXVX\TOOLBAR.EXE
O4 - Startup: Moniteur Fax-Voix.lnk = C:\OLIFAXVX\MONITEUR.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/...arch.jhtml?p=ZN
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Internet Radio by Endicosoft.com - {1F958B09-3312-7f0e-9723-4C1324C57B20} - C:\Program Files\Internet Radio\Radio.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.orange.fr (file missing) (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1195150083812
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\sulimo.dat
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: SPAMfighter Update Service - SPAMfighter ApS - C:\Program Files\SPAMfighter\sfus.exe

--
End of file - 9348 bytes

#2 JThomas

  • Group: Member
  • Posts: 5
  • Joined: 16-November 07

Posted 16 November 2007 - 12:40 PM

I had no replies to my post this morning (16 Nov). But I read in your advice that one should look first at similar cases. After spending days on this problem I found the fix you suggested to Mr Urrieta (sorry fulll name not onthis screen), involving SmitFraudFix and SDFix. To my inexpressible joy, it brought back my Control Panel. I have not tried everything again, but thanks and congratulations.
SmitFraud did not yield a usable report - it was in French and was barred by a message saying "registry changes disabled by Manager". It had no headers (File etc) and would not highlight for copying. Below is the SDFix report.


SDFix: Version 1.114

Run by Julian Thomas on 16/11/2007 at 19:09

Microsoft Windows XP [version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting...


Normal Mode:
Checking Files:

Trojan Files Found:

C:\WINDOWS\SYSTEM32\ADDPS32.EXE - Deleted
C:\WINDOWS\SYSTEM32\ATLQC32.EXE - Deleted
C:\WINDOWS\SYSTEM32\CRLM.EXE - Deleted
C:\WINDOWS\SYSTEM32\D3YP.EXE - Deleted
C:\WINDOWS\SYSTEM32\IEVE.EXE - Deleted
C:\WINDOWS\SYSTEM32\NTCX32.EXE - Deleted
C:\WINDOWS\SYSTEM32\APIGM32.DLL - Deleted
C:\WINDOWS\SYSTEM32\APPYN32.DLL - Deleted
C:\WINDOWS\SYSTEM32\ATLPM32.DLL - Deleted
C:\WINDOWS\SYSTEM32\ATLVJ32.DLL - Deleted
C:\WINDOWS\SYSTEM32\ATLXV.DLL - Deleted
C:\WINDOWS\SYSTEM32\CRMY.DLL - Deleted
C:\WINDOWS\SYSTEM32\CRMZ32.DLL - Deleted
C:\WINDOWS\SYSTEM32\IEKK32.DLL - Deleted
C:\WINDOWS\SYSTEM32\IPWS32.DLL - Deleted
C:\WINDOWS\SYSTEM32\JAVASL.DLL - Deleted
C:\WINDOWS\SYSTEM32\MFCMQ32.DLL - Deleted
C:\WINDOWS\SYSTEM32\NETFT.DLL - Deleted
C:\WINDOWS\SYSTEM32\NETPT.DLL - Deleted
C:\WINDOWS\SYSTEM32\SDKSD32.DLL - Deleted
C:\WINDOWS\SYSTEM32\SYSEI32.DLL - Deleted
C:\WINDOWS\SYSTEM32\SYSRM.DLL - Deleted
C:\WINDOWS\SYSTEM32\VUEJI.DLL - Deleted



Removing Temp Files...

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

catchme 0.3.1262.1 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-16 19:14:13
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

scanning hidden registry entries ...

scanning hidden files ...

C:\Documents and Settings\Julian Thomas\Local Settings\Application Data\Microsoft\Messenger\sgtsamy@hotmail.fr\SharingMetadata\gassventu@hotmail.fr\DFSR\Staging\CS{3490CF8D-126B-E8C5-B2EF-BAD83B2D8BDA}\01\10-{3490CF8D-126B-E8C5-B2EF-BAD83B2D8BDA}-v1-{937CE049-ABC3-40B8-9E7F-C765610A24F6}-v10-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 1


Remaining Services:
------------------



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe:*:Enabled:avgemc.exe"
"C:\\WINDOWS\\Temp\\NavBrowser.exe"="C:\\WINDOWS\\Temp\\NavBrowser.exe:*:Disabled:NAVBrowser"
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"="C:\\Program Files\\Real\\RealPlayer\\realplay.exe:*:Enabled:RealPlayer"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe:*:Enabled:avgcc.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\concept design\\onlineTV 3\\onlineTV.exe"="C:\\Program Files\\concept design\\onlineTV 3\\onlineTV.exe:*:Enabled:onlineTV"
"C:\\Program Files\\Windows Media Player\\wmplayer.exe"="C:\\Program Files\\Windows Media Player\\wmplayer.exe:*:Enabled:Lecteur Windows Media"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.0"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\Twonkyvision\\TwonkyMusic.exe"="C:\\Program Files\\Twonkyvision\\TwonkyMusic.exe:*:Enabled:TwonkyMusic"
"C:\\Program Files\\Outlook Express\\msimn.exe"="C:\\Program Files\\Outlook Express\\msimn.exe:*:Enabled:Outlook Express"
"C:\\Program Files\\MSN Gaming Zone\\Windows\\shvlzm.exe"="C:\\Program Files\\MSN Gaming Zone\\Windows\\shvlzm.exe:*:Enabled:Atout Pique sur Internet"
"%windir%\\system32\\winav.exe"="%windir%\\system32\\winav.exe:*:Enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\concept design\\onlineTV 3\\onlineTV.exe"="C:\\Program Files\\concept design\\onlineTV 3\\onlineTV.exe:*:Enabled:onlineTV"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.0"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"%windir%\\system32\\winav.exe"="%windir%\\system32\\winav.exe:*:Enabled:@xpsp2res.dll,-22019"

Remaining Files:
---------------

File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes:

Sat 25 Mar 2006 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Mon 12 Nov 2007 52,736 ...H. --- "C:\Documents and Settings\Julian Thomas\Bureau\DellAdminProb1107\~WRL0001.tmp"
Sun 17 Oct 2004 159,232 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\Voc\~WRL2304.tmp"
Sun 17 Oct 2004 160,256 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\Voc\~WRL2676.tmp"
Fri 13 Feb 2004 2,688 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\admin\~WRL0001.tmp"
Mon 24 Jun 2002 21,504 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\admin\~WRL1662.tmp"
Tue 27 Jan 2004 24,576 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\corresp\~WRL0001.tmp"
Thu 9 Dec 2004 25,600 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\corresp\~WRL0003.tmp"
Wed 22 May 2002 23,552 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\corresp\~WRL0005.tmp"
Wed 28 Sep 2005 11,264 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\Cucuron\~WRL0459.tmp"
Sat 1 Jun 2002 19,456 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\Family\~WRL2241.tmp"
Wed 2 Mar 2005 25,088 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\IT\~WRL0005.tmp"
Thu 10 Jul 2003 20,480 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\Location\~WRL0003.tmp"
Tue 2 Dec 2003 19,456 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\Location\~WRL3165.tmp"
Fri 12 Sep 2003 162 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\PROcorresp\~$TECOUV.BAK"
Thu 31 Mar 2005 19,456 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\PROcorresp\~WRL0001.tmp"
Mon 9 Nov 1998 11,264 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\Profadm\~WRL0606.tmp"
Fri 13 Feb 2004 2,688 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\admin\~WRL0001.tmp"
Mon 24 Jun 2002 21,504 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\admin\~WRL1662.tmp"
Tue 27 Jan 2004 24,576 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\corresp\~WRL0001.tmp"
Thu 9 Dec 2004 25,600 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\corresp\~WRL0003.tmp"
Wed 22 May 2002 23,552 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\corresp\~WRL0005.tmp"
Wed 28 Sep 2005 11,264 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\Cucuron\~WRL0459.tmp"
Sat 1 Jun 2002 19,456 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\Family\~WRL2241.tmp"
Wed 2 Mar 2005 25,088 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\IT\~WRL0005.tmp"
Thu 10 Jul 2003 20,480 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\Location\~WRL0003.tmp"
Tue 2 Dec 2003 19,456 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\Location\~WRL3165.tmp"
Fri 12 Sep 2003 162 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\PROcorresp\~$TECOUV.BAK"
Thu 31 Mar 2005 19,456 ...H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\PROcorresp\~WRL0001.tmp"
Fri 20 Jul 2007 63,488 ...H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\Profadm\~WRL0003.tmp"
Mon 9 Nov 1998 11,264 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\Profadm\~WRL0606.tmp"
Wed 30 Mar 2005 11,264 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsBSS\BEYA\~WRL0806.tmp"
Sat 1 Jul 2006 24,576 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsBSS\BEYA\~WRL0936.tmp"
Wed 14 Jan 2004 20,992 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsBSS\MAYA\~WRL1366.tmp"
Sat 25 Mar 2006 4,348 ...H. --- "C:\Documents and Settings\Julian Thomas\Mes documents\Ma musique\Sauvegarde de la licence\drmv1key.bak"
Sat 25 Mar 2006 20 A..H. --- "C:\Documents and Settings\Julian Thomas\Mes documents\Ma musique\Sauvegarde de la licence\drmv1lic.bak"
Sat 25 Mar 2006 312 ...H. --- "C:\Documents and Settings\Julian Thomas\Mes documents\Ma musique\Sauvegarde de la licence\drmv2key.bak"
Sat 25 Mar 2006 1,536 A..H. --- "C:\Documents and Settings\Julian Thomas\Mes documents\Ma musique\Sauvegarde de la licence\drmv2lic.bak"
Sat 15 Jul 2006 21,504 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\admin\Banks\~WRL1421.tmp"
Thu 2 Feb 2006 22,528 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\admin\Banks\~WRL3412.tmp"
Tue 27 Jul 2004 11,264 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\Cucuron\Terrasse\~WRL1735.tmp"
Mon 7 Feb 2005 11,264 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\Cucuron\Terrasse\~WRL3985.tmp"
Tue 23 Nov 2004 20,992 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\Profadm\ClientInfo\~WRL0003.tmp"
Fri 7 Jan 2005 20,480 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\Profadm\ClientInfo\~WRL0004.tmp"
Sun 12 Dec 2004 22,528 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\Profadm\ClientInfo\~WRL1278.tmp"
Sun 12 Dec 2004 20,480 A..H. --- "C:\unzipped\MesDocsJu\MesDocsJu\Profadm\ClientInfo\~WRL3181.tmp"
Sat 15 Jul 2006 21,504 ...H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\admin\Banks\~WRL1421.tmp"
Thu 2 Feb 2006 22,528 ...H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\admin\Banks\~WRL3412.tmp"
Tue 27 Jul 2004 11,264 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\Cucuron\Terrasse\~WRL1735.tmp"
Mon 7 Feb 2005 11,264 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\Cucuron\Terrasse\~WRL3985.tmp"
Tue 23 Nov 2004 20,992 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\Profadm\ClientInfo\~WRL0003.tmp"
Fri 7 Jan 2005 20,480 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\Profadm\ClientInfo\~WRL0004.tmp"
Sun 12 Dec 2004 22,528 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\Profadm\ClientInfo\~WRL1278.tmp"
Sun 12 Dec 2004 20,480 A..H. --- "C:\Documents and Settings\Julian Thomas\Bureau\MesDocsJu\Profadm\ClientInfo\~WRL3181.tmp"

Finished!

Share this topic: