Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

antispyspider infection [RESOLVED]


  • This topic is locked This topic is locked

#1
Robin Miller

Robin Miller

    Member

  • Member
  • PipPip
  • 32 posts
I hate to post but I looked at some of the previous posts on this topic, and all that stuff just goes right over my head. My daughter got a pop up on our home computer and x'd out of it, then the desktop was a red screen with Danger, you are infected with spyware, etc. We had tons of pop ups after that, all going to the homepage of antispyspider.

I have Windows XP on this Dell computer. I also have AVG Antivirus and Spybot S&D. Neither of those caught it.

I have since done lots of things, not knowing that maybe I should have come here for help first! Yay.

I don't even know how to post a log here for help, and I'm at work anyway. What has me concerned is it's still on the desktop, but I don't seem to be getting the pop ups anymore. Each time I ran the Spybot and AVG and it found things, I'd delete them or put them in the vault. I also tried the Malwarebytes Malware scanner and the Spyhunter scanner. The Spyhunter found tons of stuff that was Wild Tangent, but my daughter told me it was Dell game stuff. It was registry keys, that kind of thing. It also found a rouge antivirus 2008, in C:\Program Files\Dell Support Center\bin\sprtcmd.exe. That's what concerns me. I'm wondering if this is the rogue malware that I have and if it's okay to delete that file. When I get home, I can try to do some logs , if somebody can tell me what and how!

Sorry to be so ignorant on this topic, it's really beyond my capability of understanding at the moment! I know I've worked on this problem each night for the last 3 nights without any luck of getting rid of that red desktop thing.

TIA!
  • 0

Advertisements


#2
Mike

Mike

    Malware Monger

  • Retired Staff
  • 2,745 posts
Hi there Robin Miller,

Let's see what you have running. Please follow my instructions in the order they were given, if you come across something you don't understand or don't feel comfortable doing, don't hesitate to ask and I will get you sorted out :)

Please download Deckard's System Scanner (DSS) and save it to your Desktop.
  • Close all other windows before proceeding.
  • Double-click on dss.exe and follow the prompts.
  • When it has finished, dss will open two Notepads main.txt and extra.txt -- please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.
Note:These logs may be too large to post in one reply, if so, please post extra.txt in a seperate reply.
  • 0

#3
Robin Miller

Robin Miller

    Member

  • Topic Starter
  • Member
  • PipPip
  • 32 posts
Hi, and thanks for your help. I seem to have improved matters alot with my computer since my original post. There are no longer any of those terrible pop-ups, and I was able to change the desktop back to my original theme, so there's no more red background.

However, I still am concerned that whatever it was is not completely gone. Okay, here's my logs from the DSS Scan:

Deckard's System Scanner v20071014.68
Run by Robin Miller on 2008-05-15 22:34:01
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 5 Restore Point(s) --
97: 2008-05-16 03:34:08 UTC - RP789 - Deckard's System Scanner Restore Point
96: 2008-05-15 23:17:27 UTC - RP788 - System Checkpoint
95: 2008-05-14 22:52:47 UTC - RP787 - Removed Ad-Aware 2007
94: 2008-05-14 12:21:24 UTC - RP786 - Software Distribution Service 3.0
93: 2008-05-14 03:45:47 UTC - RP785 - Installed Ad-Aware 2007


-- First Restore Point --
1: 2008-02-16 23:03:15 UTC - RP693 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.



-- HijackThis Clone ------------------------------------------------------------


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-05-15 22:36:03
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\Program Files\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\CTSVCCDA.EXE
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Real\RealPlayer\realplay.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\MMDiag.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\dla\DLACTRLW.EXE
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\BlueLight Internet\exec.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\BlueLight Internet\exec.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\Program Files\FinePixViewer\QuickDCF2.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Documents and Settings\Robin Miller\Desktop\dss.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mybluelight.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://home.microsof...search.asp?p=%s
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://v4.windowsupdate.microsoft.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.microsoft...amp;ar=iesearch
R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\Program Files\BlueLight Internet\SearchEnh1.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll
O3 - Toolbar: MyBlueLight - {25EEFF3E-58EE-4811-95CC-78F922605006} - C:\Program Files\BlueLight Internet\Toolbar.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [PE2CKFNT SE] C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SpyHunter Security Suite] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BlueLight_uoltray] C:\Program Files\BlueLight Internet\exec.exe regrun
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: ExifLauncher2.lnk = ?
O4 - Global Startup: Photo Express Calendar Checker SE.lnk = ?
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnote...ad/mnviewer.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmar...martActivia.cab
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} () - http://fpdownload.ma...t/ultrashim.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.ma...ash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL
O18 - Protocol: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL
O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\ati2evxx.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG8\avgwdsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTSVCCDA.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - Unknown owner - C:\Program Files\Dell


--
End of file - 10926 bytes

-- File Associations -----------------------------------------------------------

.reg - regfile - shell\open\command - regedit.exe "%1" %*
.scr - scrfile - shell\open\command - "%1" %*


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R1 OMCI - c:\windows\system32\drivers\omci.sys <Not Verified; Dell Computer Corporation; OMCI Driver>
R2 ASCTRM - c:\windows\system32\drivers\asctrm.sys <Not Verified; Windows ® 2000 DDK provider; Windows ® 2000 DDK driver>


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 sprtsvc_dellsupportcenter (SupportSoft Sprocket Service (dellsupportcenter)) - c:\program files\dell support center\bin\sprtsvc.exe /service /p dellsupportcenter


-- Device Manager: Disabled ----------------------------------------------------

No disabled devices found.


-- Files created between 2008-04-15 and 2008-05-15 -----------------------------

2008-05-15 06:50:44 0 d-------- C:\Documents and Settings\J.E. Miller\Application Data\AVGTOOLBAR
2008-05-14 23:25:12 0 d-------- C:\Documents and Settings\Amanda Miller\Application Data\Malwarebytes
2008-05-14 23:17:11 82944 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-05-14 23:17:11 82944 --a------ C:\WINDOWS\system32\404Fix.exe
2008-05-14 23:11:36 0 d-------- C:\Documents and Settings\Amanda Miller\Application Data\AVGTOOLBAR
2008-05-13 22:45:49 0 d-------- C:\Program Files\Lavasoft
2008-05-13 22:45:48 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-13 22:03:40 0 d-------- C:\Program Files\Enigma Software Group
2008-05-13 19:55:33 0 d--h----- C:\$AVG8.VAULT$
2008-05-13 19:38:22 0 d-------- C:\WINDOWS\system32\drivers\Avg
2008-05-13 19:38:22 0 d-------- C:\Documents and Settings\Robin Miller\Application Data\AVGTOOLBAR
2008-05-13 19:38:07 0 d-------- C:\Program Files\AVG
2008-05-13 19:38:06 0 d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-05-13 17:55:45 0 d-------- C:\Documents and Settings\Robin Miller\Application Data\Malwarebytes
2008-05-13 17:55:33 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-13 17:55:32 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-12 17:47:33 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2008-05-12 17:46:34 5346 --a------ C:\WINDOWS\system32\tmp.reg
2008-05-12 17:45:50 25600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-05-12 17:45:50 289144 --a------ C:\WINDOWS\system32\VCCLSID.exe <Not Verified; S!Ri; >
2008-05-12 17:45:50 86528 --a------ C:\WINDOWS\system32\VACFix.exe <Not Verified; S!Ri.URZ; VACFix>
2008-05-12 17:45:50 288417 --a------ C:\WINDOWS\system32\SrchSTS.exe <Not Verified; S!Ri; SrchSTS>
2008-05-12 17:45:50 53248 --a------ C:\WINDOWS\system32\Process.exe <Not Verified; http://www.beyondlogic.org; Command Line Process Utility>
2008-05-12 17:45:50 51200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-05-11 21:32:04 0 d-------- C:\Program Files\SpyZooka
2008-05-11 21:31:47 0 d-------- C:\Program Files\Common Files\Download Manager


-- Find3M Report ---------------------------------------------------------------

2008-05-15 22:32:42 4184 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
2008-05-15 22:32:38 104 -r-hs---- C:\WINDOWS\system32\07C2B389ED.sys
2008-05-14 22:32:23 1024 --a------ C:\Documents and Settings\Robin Miller\Application Data\WavCodec.wff
2008-05-13 22:45:17 0 d-------- C:\Program Files\Common Files
2008-05-13 20:16:32 0 d-------- C:\Program Files\DIGStream
2008-05-11 17:41:34 0 d-------- C:\Program Files\LimeWire
2008-05-04 18:39:40 0 d-------- C:\Program Files\FinePixViewer
2008-04-24 17:18:02 0 d-------- C:\Program Files\NCH Swift Sound
2008-04-04 15:49:09 0 d-------- C:\Program Files\VCW VicMan's Photo Editor
2008-03-23 10:36:18 0 d-------- C:\Program Files\Free Video Converter
2008-03-19 22:25:13 0 d-------- C:\Documents and Settings\Robin Miller\Application Data\Creative
2008-03-18 20:39:36 0 d-------- C:\Program Files\NCH Software
2008-03-18 20:36:38 0 d-------- C:\Documents and Settings\Robin Miller\Application Data\NCH Swift Sound
2008-03-17 20:56:09 0 d-------- C:\Program Files\K-Lite Codec Pack
2008-03-15 10:09:57 0 d-------- C:\Program Files\audible
2008-03-15 09:00:13 1028 --a------ C:\Documents and Settings\Robin Miller\Application Data\AVIEncoder.wff
2008-03-08 10:50:55 6656 --a------ C:\WINDOWS\strictions.dll


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
05/13/2008 07:38 PM 2050816 --a------ C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [05/13/2008 07:38 PM 2050816]

[-HKEY_CLASSES_ROOT\CLSID\{A057A204-BACC-4D26-9990-79A187E2698E}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [05/11/2000 02:00 AM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [09/25/2007 01:11 AM]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [11/16/2005 09:45 AM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [11/16/2005 09:45 AM]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [08/10/2004 06:00 AM]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [08/10/2004 06:00 AM]
"PE2CKFNT SE"="C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe" [07/03/1998 12:51 PM]
"P17Helper"="P17.dll" [06/10/2004 05:51 PM C:\WINDOWS\system32\P17.dll]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [08/10/2004 06:00 AM]
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [09/08/2005 08:20 PM]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe" [09/08/2005 08:20 PM]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [06/10/2005 11:44 AM]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [06/10/2005 11:44 AM]
"IntelMeM"="C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" [09/03/2003 09:12 PM]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [08/10/2004 06:00 AM]
"IMEKRMIG6.1"="C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE" [08/10/2004 06:00 AM]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe" [11/07/2001 11:45 AM]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [02/17/2005 12:11 AM]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [08/05/2005 02:56 PM]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [02/23/2005 05:19 PM]
"CTSysVol"="C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe" [09/17/2003 11:43 AM]
"Corel Photo Downloader"="C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe" [11/16/2005 06:08 PM]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [08/05/2005 10:05 PM]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [11/15/2007 10:24 AM]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [11/07/2005 06:20 AM]
"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.exe" [02/04/2002 11:32 PM]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [05/13/2008 07:38 PM]
"SpyHunter Security Suite"="C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe" [01/23/2008 03:47 PM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [10/13/2004 11:24 AM]
"BlueLight_uoltray"="C:\Program Files\BlueLight Internet\exec.exe" [03/07/2007 08:38 PM]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [11/15/2007 10:23 AM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/10/2004 06:00 AM]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [01/28/2008 11:43 AM]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [9/23/2005 11:05:26 PM]
America Online 9.0 Tray Icon.lnk - C:\Program Files\America Online 9.0\aoltray.exe [11/16/2005 9:44:44 AM]
ExifLauncher2.lnk - C:\Program Files\FinePixViewer\QuickDCF2.exe [2/24/2008 8:37:32 PM]
Photo Express Calendar Checker SE.lnk - C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe [4/26/2006 9:38:12 PM]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [11/11/2004 12:59:36 PM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
AutoRun\command- E:\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{74e4183c-a510-11dc-a02d-00038a000015}]
AutoRun\command- E:\LaunchU3.exe -a




-- End of Deckard's System Scanner: finished at 2008-05-15 22:37:19 ------------

Edited by Robin Miller, 15 May 2008 - 10:05 PM.

  • 0

#4
Robin Miller

Robin Miller

    Member

  • Topic Starter
  • Member
  • PipPip
  • 32 posts
And here's the other one:

Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft Windows XP Professional (build 2600) SP 2.0
Architecture: X86; Language: English

CPU 0: Intel® Pentium® 4 CPU 3.00GHz
CPU 1: Intel® Pentium® 4 CPU 3.00GHz
Percentage of Memory in Use: 57%
Physical Memory (total/avail): 1022.07 MiB / 430 MiB
Pagefile Memory (total/avail): 2458.93 MiB / 1959.25 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1930.58 MiB

C: is Fixed (NTFS) - 144.31 GiB total, 117.31 GiB free.
D: is CDROM (No Media)

\\.\PHYSICALDRIVE0 - ST3160023AS - 149.01 GiB - 3 partitions
\PARTITION0 - Unknown - 54.88 MiB
\PARTITION1 (bootable) - Installable File System - 144.31 GiB - C:
\PARTITION2 - Unknown - 4.64 GiB



-- Security Center -------------------------------------------------------------

AUOptions is scheduled to auto-install.
Windows Internal Firewall is enabled.

FirstRunDisabled is set.

AV: AVG Anti-Virus Free v8.0 (AVG Technologies)

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:America Online 9.0"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:America Online 9.0"
"C:\\Program Files\\HP\\Image Zone Express\\HP_IZE.exe"="C:\\Program Files\\HP\\Image Zone Express\\HP_IZE.exe:*:Enabled:HP Image Zone Express"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\Program Files\\Common Files\\AOL\\1151290770\\ee\\aolsoftware.exe"="C:\\Program Files\\Common Files\\AOL\\1151290770\\ee\\aolsoftware.exe:*:Enabled:AOL Services"
"C:\\Program Files\\Common Files\\AOL\\1151290770\\ee\\aim6.exe"="C:\\Program Files\\Common Files\\AOL\\1151290770\\ee\\aim6.exe:*:Enabled:AIM"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Program Files\\Morpheus\\Morpheus.exe"="C:\\Program Files\\Morpheus\\Morpheus.exe:*:Enabled:M5Shell"
"C:\\Program Files\\Common Files\\PocketSoft\\RTPatch\\AutoRTP\\artpschd.exe"="C:\\Program Files\\Common Files\\PocketSoft\\RTPatch\\AutoRTP\\artpschd.exe:*:Enabled:artpschd"
"C:\\StubInstaller.exe"="C:\\StubInstaller.exe:*:Enabled:LimeWire swarmed installer"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\MUSICMATCH\\Musicmatch Jukebox\\mim.exe"="C:\\Program Files\\MUSICMATCH\\Musicmatch Jukebox\\mim.exe:*:Disabled:mim"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"="C:\\Program Files\\AVG\\AVG8\\avgupd.exe:*:Enabled:avgupd.exe"
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"="C:\\Program Files\\AVG\\AVG8\\avgemc.exe:*:Enabled:avgemc.exe"


-- Environment Variables -------------------------------------------------------

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Robin Miller\Application Data
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=MILLER
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Robin Miller
LOGONSERVER=\\MILLER
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\ATI Technologies\ATI Control Panel
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 4 Stepping 3, GenuineIntel
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=0403
ProgramFiles=C:\Program Files
PROMPT=$P$G
SESSIONNAME=Console
SonicCentral=C:\Program Files\Common Files\Sonic Shared\Sonic Central\
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\ROBINM~1\LOCALS~1\Temp
TMP=C:\DOCUME~1\ROBINM~1\LOCALS~1\Temp
USERDOMAIN=MILLER
USERNAME=Robin Miller
USERPROFILE=C:\Documents and Settings\Robin Miller
windir=C:\WINDOWS
__COMPAT_LAYER=DisableNXShowUI


-- User Profiles ---------------------------------------------------------------

Robin Miller (admin)
Amanda Miller (admin)
J.E. Miller (admin)
Administrator (admin)


-- Add/Remove Programs ---------------------------------------------------------

--> "C:\Program Files\Creative Installation Information\CD_RIPPER_UNICODE_2\Setup.exe" /remove /l0x0009
--> "C:\Program Files\Creative Installation Information\CREATIVE_MEDIASOURCE_U\Setup.exe" /remove /l0x0009
--> "C:\Program Files\Creative Installation Information\CREATIVE_SYNC_MANAGER_U\Setup.exe" /remove /l0x0009
--> "C:\Program Files\Creative Installation Information\CREATIVE_VIDEO_CONVERTER\Setup.exe" /remove /l0x0009
--> "C:\Program Files\Creative Installation Information\E-CENTER_NET_CONTENT_U\Setup.exe" /remove /l0x0009
--> "C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_CDBURNER_U\Setup.exe" /remove /l0x0009
--> "C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_MTP_U\Setup.exe" /remove /l0x0009
--> "C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_MUSICPLAYER_MSS_U\Setup.exe" /remove /l0x0009
--> "C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_NOMADJUKEBOXTYPE2_U\Setup.exe" /remove /l0x0009
--> "C:\Program Files\Creative Installation Information\MEDIASOURCE_PLAYER_SKINPACK_U\Setup.exe" /remove /l0x0009
--> "C:\Program Files\Creative Installation Information\ZEN_MTP_MEDIA_EXPLORER\Setup.exe" /remove /l0x0009
--> "C:\Program Files\Creative\Sound Blaster Live! 24-bit\Program\Ctzapxx.EXE" /X /U /S
--> C:\WINDOWS\system32\\MSIEXEC.EXE /x {075473F5-846A-448B-BCB3-104AA1760205}
--> C:\WINDOWS\system32\\MSIEXEC.EXE /x {1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
--> C:\WINDOWS\system32\\MSIEXEC.EXE /x {AB708C9B-97C8-4AC9-899B-DBF226AC9382}
--> C:\WINDOWS\system32\\MSIEXEC.EXE /x {B12665F4-4E93-4AB4-B7FC-37053B524629}
--> C:\WINDOWS\uninst.exe -fC:\Maxis\SimFarm\DeIsL1.isu
--> MsiExec.exe /I{403EF592-953B-4794-BCEF-ECAB835C2095}
--> MsiExec.exe /I{F543B12A-13F5-487E-9314-F7D25E1BBE3E}
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{435E969D-867E-4364-8E74-3DC8A69C5BDB}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{435E969D-867E-4364-8E74-3DC8A69C5BDB}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{44DC86A0-248D-11D6-9BAF-0090271AF8A4}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{44DC86A0-248D-11D6-9BAF-0090271AF8A4}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5210ED6D-52A9-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5210ED6D-52A9-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5CDDF96A-BC34-4D72-9ABA-E1FFF0C39977}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{67AEFC4C-69E4-11D7-85F4-00E018013273}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{67AEFC4C-69E4-11D7-85F4-00E018013273}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7201B853-5833-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7201B853-5833-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7A900EAB-DA37-4554-AF19-9C337476D05D}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7A900EAB-DA37-4554-AF19-9C337476D05D}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A1185190-514F-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A1185190-514F-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AC157741-3285-4D6A-B934-9174587A3493}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AC157741-3285-4D6A-B934-9174587A3493}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C6866B7D-ACFD-4C49-B77B-3B2F8CF54B96}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C6866B7D-ACFD-4C49-B77B-3B2F8CF54B96}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DEBD7BF3-5856-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DEBD7BF3-5856-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F865C2FE-25E7-11D6-9BAF-0090271AF8A4}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F865C2FE-25E7-11D6-9BAF-0090271AF8A4}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB2292C6-1F0A-11D7-AB2D-0090271A23A2}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB2292C6-1F0A-11D7-AB2D-0090271A23A2}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FC0DD8AE-3DC0-11D7-AB2D-0090271A23A2}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FC0DD8AE-3DC0-11D7-AB2D-0090271A23A2}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{19822917-61F6-4221-B1D0-1C3B8A06BE60}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{19822917-61F6-4221-B1D0-1C3B8A06BE60}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{88B1984E-36F0-47B8-B8DC-728966807A9C}\SETUP.EXE" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9B7A778E-AF38-4341-9EA0-1FC981106ADA}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9B7A778E-AF38-4341-9EA0-1FC981106ADA}\setup.exe" -l0x9 /remove
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 7.0.9 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70900000002}
AOL Coach Version 1.0(Build:20040229.1 en) --> C:\Program Files\Common Files\aolshare\Coach\AolCInUn.exe
AOL Connectivity Services --> C:\PROGRA~1\COMMON~1\AOL\ACS\AcsUninstall.exe /c
AOL Uninstaller (Choose which Products to Remove) --> C:\Program Files\Common Files\AOL\uninstaller.exe
AOLIcon --> MsiExec.exe /I{62BD0AE0-4EB1-4BBB-8F43-B6400C8FEB2C}
ArcSoft PhotoImpression 3.0 --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\ArcSoft\PhotoImpression\Uninst.isu"
ArcSoft PhotoStudio 5.5 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63B8997E-EB2D-41D3-984C-C44D6D67A571}\SETUP.EXE" -l0x9
ATI Control Panel --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
ATI Display Driver --> rundll32 C:\WINDOWS\system32\atiiiexx.dll,[email protected] -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
AVG Free 8.0 --> C:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
BlueLight Internet --> "C:\Program Files\BlueLight Internet\BlueLightUninstaller.exe"
Canon Camera Support Core Library --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{A1D0D14A-B776-4907-BC00-5149F2298086} /l1033
Canon Camera Window DC_DV 5 for ZoomBrowser EX --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{001AB29C-5468-4972-8D24-2EBDB2B12133}
Canon Camera Window DS for ZoomBrowser EX --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{6B8BDABA-6737-4998-AEE4-E218EDE5FC7A}
Canon Camera Window MC 5 for ZoomBrowser EX --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{89EB3ED7-225A-412E-B048-623D502C000F}
Canon MovieEdit Task for ZoomBrowser EX --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{68D27126-BF6A-457D-8DD0-5F35E8D41310}
Canon PhotoRecord --> MsiExec.exe /X{6693BD7C-CB4E-43AC-A0D6-10D1A1B88DCF}
Canon RAW Image Task for ZoomBrowser EX --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{001EB665-D9EC-415E-9E13-AD2125B2B992}
Canon Utilities PhotoStitch 3.1 --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{218BBBE3-FE63-4BB2-81A8-7435575A84FA}
Canon ZoomBrowser EX --> MsiExec.exe /X{C1D76D7A-F3BB-47EA-A746-5B1E2FFC1DF2}
CCleaner (remove only) --> "C:\Program Files\CCleaner\uninst.exe"
Copy Utility --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\EPSON\Copy Utility\Uninst.isu"
Corel Photo Album 6 --> MsiExec.exe /X{8A9B8148-DDD7-448F-BD6C-358386D32354}
Crash Analysis Tool --> MsiExec.exe /X{D5F881C2-B134-474E-AA60-B25DD218AE0D}
Creative MediaSource --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{56F3E1FF-54FE-4384-A153-6CCABA097814}\setup.exe" -l0x9 /remove
Creative MediaSource 5 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}\SETUP.EXE" -l0x9 /remove
Creative Software AutoUpdate --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{88B1984E-36F0-47B8-B8DC-728966807A9C}\SETUP.EXE" -l0x9 /remove
Creative System Information --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x9 /remove
Creative ZEN --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1B2DBF55-05D4-4072-87D8-689141E262BD}\SETUP.EXE" -l0x9 /remove
Creative ZEN Nano Plus --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BA63612E-0458-416A-ADCD-B2349194F20F}\SETUP.EXE" -l0x9 /remove
Dell Digital Jukebox Driver --> C:\Program Files\Dell\Digital Jukebox Drivers\DrvUnins.exe /s
Dell Driver Reset Tool --> MsiExec.exe /I{5905F42D-3F5F-4916-ADA6-94A3646AEE76}
Dell Game Console --> "C:\Program Files\WildTangent\Apps\Dell Game Console\Uninstall.exe"
Dell ResourceCD --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D78653C3-A8FF-415F-92E6-D774E634FF2D}\setup.exe"
Dell Support Center --> MsiExec.exe /X{E3BFEE55-39E2-4BE0-B966-89FE583822C1}
Digital Content Portal --> MsiExec.exe /I{6D5FCA42-1486-4E32-AFE8-1B7E2AA59D33}
DrawPlus 3.0 --> C:\WINDOWS\UNINST.EXE -f"C:\PROGRA~1\BRODER~1\DrawPlus\DeIsL1.isu"
EarthLink setup files --> MsiExec.exe /X{728278A1-0BB7-45E4-AC5E-91D7C0FD1EDE}
EducateU --> MsiExec.exe /I{A683A2C0-821C-486F-858C-FA634DB5E864}
EPSON Photo Print --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\EPSON\Photo Print\Uninst.isu"
EPSON Smart Panel --> C:\Program Files\EPSON\Smart Panel\SPUninst.exe
EPSON TWAIN 5 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9A3EABC0-CA06-11D4-BF77-00104B130C19}\setup.exe" UNINSTALL
ESPNMotion --> C:\PROGRA~1\ESPNMO~1\UNWISE.EXE /u C:\PROGRA~1\ESPNMO~1\INSTALL.LOG
FinePixViewer Ver.5.4 --> C:\Program Files\InstallShield Installation Information\{24ED4D80-8294-11D5-96CD-0040266301AD}\SETUP.EXE -runfromtemp -l0x0009 -removeonly
Free Video Converter V 1.1 --> "C:\Program Files\Free Video Converter\unins000.exe"
FUJIFILM USB Driver --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5490882C-6961-11D5-BAE5-00E0188E010B}\SETUP.EXE"
Get High Speed Internet! --> MsiExec.exe /I{7A3F0566-5E05-4919-9C98-456F6B5CF831}
High Definition Audio Driver Package - KB835221 --> C:\WINDOWS\$NtUninstallKB835221WXP$\spuninst\spuninst.exe
Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
hp deskjet 950c series (Remove only) --> C:\Program Files\hp deskjet 950c series\hpfiui.exe -c -vdivid=HPF -vpnum=95 -vinstport=USB001 -vproduct=950c -huninstall
HP Software Update --> MsiExec.exe /X{15EE79F4-4ED1-4267-9B0F-351009325D7D}
Intel® 537EP V9x DF PCI Modem --> rundll32 IntelCci.dll,iSMUninstallation "Intel® 537EP V9x DF PCI Modem"
Intel® PRO Network Connections Drivers --> Prounstl.exe
Intel® PROSet for Wired Connections --> MsiExec.exe /I{83F793B5-8BBF-42FD-A8A6-868CB3E2AAEA}
Internet Explorer Default Page --> MsiExec.exe /I{35BDEFF1-A610-4956-A00D-15453C116395}
J2SE Runtime Environment 5.0 Update 10 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150100}
Java 2 Runtime Environment, SE v1.4.2_03 --> MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142030}
Java™ 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
K-Lite Codec Pack 3.4.0 Standard --> "C:\Program Files\K-Lite Codec Pack\unins000.exe"
Learn2 Player (Uninstall Only) --> C:\Program Files\Learn2.com\StRunner\stuninst.exe
Macromedia Flash Player --> MsiExec.exe /X{0456ebd7-5f67-4ab6-852e-63781e3f389c}
Malwarebytes' Anti-Malware --> "C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Office Professional Edition 2003 --> MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
Microsoft Plus! Digital Media Edition Installer --> MsiExec.exe /X{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}
Microsoft Plus! Photo Story 2 LE --> MsiExec.exe /X{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}
Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Web Publishing Wizard 1.52 --> RunDll32 ADVPACK.DLL,LaunchINFSection C:\WINDOWS\INF\wpie4x86.inf,WebPostUninstall
Modem Event Monitor --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7A0EFAFB-AC4B-4B88-8C6B-6731BE88DB68}\setup.exe" -l0x9
Modem Helper --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F142D56-3326-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanel
Modem On Hold --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3F92ABBB-6BBF-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanelAnyText
MSN --> C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
Musicmatch® Jukebox --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{85D3CC30-8859-481A-9654-FD9B74310BEF}\setup.exe" -l0x9 -uninst
PF1250-1650 Guide --> C:\WINDOWS\uninst.exe -f"C:\Program Files\EPSON\PF1250-1650\DeIsL1.isu"
PowerDVD 5.5 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall
QuickBooks Simple Start Special Edition --> msiexec.exe /I {F543B12A-13F5-487E-9314-F7D25E1BBE3E} UNIQUE_NAME="atomlimited" QBFULLNAME="QuickBooks Simple Start Special Edition" ADDREMOVE=1
QuickTime --> C:\WINDOWS\unvise32qt.exe C:\WINDOWS\system32\QuickTime\Uninstall.log
QuickTime 3.0 --> C:\WINDOWS\uninst.exe -f"C:\Program Files\QuickTime\DeIsL1.isu" -c"C:\WINDOWS\system32\QTUninst.dll
RealPlayer Basic --> C:\Program Files\Common Files\Real\Update\\rnuninst.exe RealNetworks|RealPlayer|6.0
Roxio DLA --> MsiExec.exe /I{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
ScanToWeb --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EBAE381B-60A6-4863-AA9F-FCAB755BC9E5}\Setup.exe" ADDREMOVEDLG
Shockwave --> C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\INSTALL.LOG
Sonic Encoders --> MsiExec.exe /I{9941F0AA-B903-4AF4-A055-83A9815CC011}
Sonic MyDVD LE --> MsiExec.exe /I{21657574-BD54-48A2-9450-EB03B2C7FC29}
Sonic RecordNow Audio --> MsiExec.exe /I{AB708C9B-97C8-4AC9-899B-DBF226AC9382}
Sonic RecordNow Copy --> MsiExec.exe /I{B12665F4-4E93-4AB4-B7FC-37053B524629}
Sonic RecordNow Data --> MsiExec.exe /I{075473F5-846A-448B-BCB3-104AA1760205}
Sonic Update Manager --> MsiExec.exe /I{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
Sound Blaster Live! 24-bit --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CEB481CC-F57C-4397-81A0-DADD22257047}\setup.exe" -l0x9
Spybot - Search & Destroy --> "C:\Program Files\Spybot - Search & Destroy\unins000.exe"
SpyHunter --> "C:\Program Files\Enigma Software Group\SpyHunter\Uninstall.exe" "C:\Program Files\Enigma Software Group\SpyHunter\install.log" -u
The Print Shop --> C:\WINDOWS\UNINST.EXE -f"C:\PROGRA~1\BRODER~1\THEPRI~1\DeIsL1.isu" -c"C:\PROGRA~1\BRODER~1\THEPRI~1\psfinst.dll"
Ulead Photo Express 2.0 SE --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\Uninst.isu" -c"C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\IS32Inst.dll"
Update Rollup 2 for Windows XP Media Center Edition 2005 --> C:\WINDOWS\$NtUninstallKB900325$\spuninst\spuninst.exe
USB Driver Vers. 3.2 --> C:\Program Files\USB Driver Vers. 3.2\uninstall.exe
Viewpoint Media Player --> C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
WavePad Uninstall --> C:\Program Files\NCH Swift Sound\WavePad\uninst.exe
WebCyberCoach 3.2 Dell --> "C:\Program Files\WebCyberCoach\b_Dell\WCC_Wipe.exe" "WebCyberCoach ext\wtrb" /inf "engine.inf,RealUninstallSection,,4" /infcfg "enginecf.inf,RealUninstallSection,,4"
Windows Installer Clean Up --> MsiExec.exe /I{121634B0-2F4A-11D3-ADA3-00C04F52DD53}
Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows XP Media Center Edition 2005 KB925766 --> "C:\WINDOWS\$NtUninstallKB925766$\spuninst\spuninst.exe"
WinZip --> "C:\Program Files\WinZip\WINZIP32.EXE" /uninstall
WordPerfect Office 12 --> MsiExec.exe /I{AF19F291-F22F-4798-9662-525305AE9E48}
ZENcast Organizer --> "C:\Program Files\Creative Installation Information\ZENCAST_ORGANIZER\Setup.exe" /remove /l0x0009


-- Application Event Log -------------------------------------------------------

Event Record #/Type103905 / Warning
Event Submitted/Written: 05/15/2008 03:44:04 PM
Event ID/Source: 1001 / MsiInstaller
Event Description:
Detection of product '{8A9B8148-DDD7-448F-BD6C-358386D32354}', feature 'PaintShopPhotoAlbum' failed during request for component '{D2D7B4BF-6CCA-11D5-8B3F-00105A9846E9}'

Event Record #/Type103904 / Warning
Event Submitted/Written: 05/15/2008 03:44:04 PM
Event ID/Source: 1004 / MsiInstaller
Event Description:
Detection of product '{8A9B8148-DDD7-448F-BD6C-358386D32354}', feature 'PaintShopPhotoAlbum', component '{25F669D8-9DC1-44D1-A06B-28E42E930387}' failed. The resource 'HKEY_CURRENT_USER\Software\Corel\Auto Update\{8A9B8148-DDD7-448F-BD6C-358386D32354}\Interval' does not exist.

Event Record #/Type103903 / Warning
Event Submitted/Written: 05/15/2008 03:44:03 PM
Event ID/Source: 1001 / MsiInstaller
Event Description:
Detection of product '{8A9B8148-DDD7-448F-BD6C-358386D32354}', feature 'PaintShopPhotoAlbum' failed during request for component '{D2D7B4BF-6CCA-11D5-8B3F-00105A9846E9}'

Event Record #/Type103902 / Warning
Event Submitted/Written: 05/15/2008 03:44:03 PM
Event ID/Source: 1004 / MsiInstaller
Event Description:
Detection of product '{8A9B8148-DDD7-448F-BD6C-358386D32354}', feature 'PaintShopPhotoAlbum', component '{25F669D8-9DC1-44D1-A06B-28E42E930387}' failed. The resource 'HKEY_CURRENT_USER\Software\Corel\Auto Update\{8A9B8148-DDD7-448F-BD6C-358386D32354}\Interval' does not exist.

Event Record #/Type103901 / Warning
Event Submitted/Written: 05/15/2008 03:44:03 PM
Event ID/Source: 1001 / MsiInstaller
Event Description:
Detection of product '{8A9B8148-DDD7-448F-BD6C-358386D32354}', feature 'PaintShopPhotoAlbum' failed during request for component '{D2D7B4BF-6CCA-11D5-8B3F-00105A9846E9}'



-- Security Event Log ----------------------------------------------------------

No Errors/Warnings found.


-- System Event Log ------------------------------------------------------------

Event Record #/Type46221 / Error
Event Submitted/Written: 05/14/2008 11:22:49 PM
Event ID/Source: 10005 / DCOM
Event Description:
DCOM got error "%%1084" attempting to start the service EventSystem with arguments ""
in order to run the server:
{1BE1F766-5536-11D1-B726-00C04FB926AF}

Event Record #/Type46220 / Error
Event Submitted/Written: 05/14/2008 11:21:55 PM
Event ID/Source: 10005 / DCOM
Event Description:
DCOM got error "%%1084" attempting to start the service netman with arguments ""
in order to run the server:
{BA126AE5-2166-11D1-B1D0-00805FC1270E}

Event Record #/Type46219 / Error
Event Submitted/Written: 05/14/2008 11:17:03 PM
Event ID/Source: 7026 / Service Control Manager
Event Description:
The following boot-start or system-start driver(s) failed to load:
AFD
AvgLdx86
AvgMfx86
Fips
intelppm
IPSec
MRxSmb
NetBIOS
NetBT
OMCI
RasAcd
Rdbss
Tcpip

Event Record #/Type46218 / Error
Event Submitted/Written: 05/14/2008 11:17:03 PM
Event ID/Source: 7001 / Service Control Manager
Event Description:
The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error:
%%31

Event Record #/Type46217 / Error
Event Submitted/Written: 05/14/2008 11:17:03 PM
Event ID/Source: 7001 / Service Control Manager
Event Description:
The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error:
%%31



-- End of Deckard's System Scanner: finished at 2008-05-15 22:37:19 ------------
  • 0

#5
Mike

Mike

    Malware Monger

  • Retired Staff
  • 2,745 posts
Hi Robin Miller,

Looks like you did a good job cleaning that computer of yours :)

We have a few things to take care of though.

Preparation
  • Download the latest version of Java Runtime Environment (JRE) 6 Update 6.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Select your Platform and check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement.".
  • Click on Continue.
  • Click on the link to download Windows Offline Installation (jre-6u6-windows-i586-p.exe) and save it to your desktop. Do NOT use the Sun Download Manager..
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on the download to install the newest version.

  • Please go to Jotti's malware scan
  • Copy and paste the following file path into the "File to upload & scan"box on the top of the page:

    • C:\WINDOWS\system32\07C2B389ED.sys
  • Click on the submit button
  • Please post the results in your next reply.

Now I will need you to temporarily disable Spybot Search & destroy, we will re-enable it afterwards.

Spybot S&D (Teatimer)

1. Run Spybot-S&D in Advanced Mode.
2. If it is not already set to do this Go to the Mode menu select "Advanced Mode"
3. On the left hand side, Click on Tools
4. Then click on the Resident Icon in the List
5. Uncheck "Resident TeaTimer" and OK any prompts.
6. Restart your computer.

Optional

You have LimeWire installed. These are Peer to Peer programs. These types of programs are very dangerous as you literally allow anyone to access your computer. Please read Dangers of P2P.

If you wish to uninstall them please go to Start >Control Panel > Add or Remove Programs an uninstall:
LimeWire

Using Windows Explorer (to get there right-click your Start button and go to "Explore"), please delete these folders (if present):

C:\program files\LimeWire
C:\Documents and Settings\Robin Miller\Application Data\LimeWire

I would also like to point out to you that the Anti-Spyware programs you are using (Spy Hunter & Spy ZooKa) have a bad history as they were considered "rouge applications" in the past.
Because of this I would recommend you uninstall them through Add or Remove Programs and delete the following folders(if present).

C:\Program Files\SpyHunter
C:\Program Files\SpyZooKa
C:\Documents and Settings\Robin Miller\Application Data\SpyHunter
C:\Documents and Settings\Robin Miller\Application Data\SpyZooKa

Step 1. Running OTMoveIt2

Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    C:\WINDOWS\system32\07C2B389ED.sys
    C:\WINDOWS\strictions.dll
    E:\setup.exe
    HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}
    HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{74e4183c-a510-11dc-a02d-00038a000015}
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{92780B25-18CC-41C8-B9BE-3C9C571A8263}
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the light Yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Step 2. Running Kaspersky Online Virusscaner

Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 onlyDouble-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

Please run a free online scan with Kaspersky AntiVirus (works only with MS Internet Explorer 5.0 or higher).
Go to http://www.kaspersky.com/virusscanner and click the "Kaspersky Online Scanner" button (NOT "Kaspersky File Scanner").
  • In the new window that opens, click the "Accept" button to accept the user agreement, install the ActiveX control, and download the program.
  • When you get the Windows dialog asking if you want to install this software, click the "Install" button.
  • When the "Update progress" line changes to "Ready" and the "NEXT ->" button lights up with a green arrow, click it.
  • Click on the "Scan Settings" button, and in the next window select the "extended" database, and click Ok.
  • Under "Please select a target to scan:", click My Computer to start the scan.
When the scan is finished, click the "Save as Text" button, and save the file as kavscan.txt to your Desktop, close the Kaspersky On-line Scanner window, and post the text in kavscan.txt in your next reply.

Then re-run Deckards' System scanner (it will only produce main.txt)

In your next reply

Results from Jotti Scan.
Please post the log from OTMoveIt2.
Please post the log from Kaspersky.
Please post main.txt from Deckards' System Scanner.

If the logs are to big to fit in one reply, please use as many replies you need to get them all to fit.

Edited by Mike, 16 May 2008 - 08:02 AM.
Add some information.

  • 0

#6
Robin Miller

Robin Miller

    Member

  • Topic Starter
  • Member
  • PipPip
  • 32 posts
Okay, let's see. I did the Java update. The Jotti's malware scan says it can't run because a firewall or a piece of malware may be prohibiting it from running. I disabled the Teatimer, and deleted the Limewire files (I had already uninstalled the program). Got rid of the Spy Hunter and Spy Zooka. The OTMoveIt2 by OldTimer doesn't work right - it stalls when I click Moveit! then I try to x out of it and it says the program is not responding - end now. I next did the ATF. Here's the log from the Kaspersky AntiVirus:

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Saturday, May 17, 2008 10:14:42 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 18/05/2008
Kaspersky Anti-Virus database records: 782067
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\

Scan Statistics:
Total number of scanned objects: 85179
Number of viruses found: 4
Number of infected objects: 16
Number of suspicious objects: 0
Duration of the scan process: 01:02:04

Infected Object Name / Virus Name / Last Action
C:\d055753fc35576d481\update\update.exe Object is locked skipped
C:\d055753fc35576d481\update\updspapi.dll Object is locked skipped
C:\Documents and Settings\Administrator\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\All Users\Application Data\avg8\emc\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgcore.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avglng.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgrs.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgsched.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgsrm.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgwd.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\commonpriv.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\BlueLight\Isp\BootExceptions.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\BlueLight\Isp\ExecExceptions.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\BlueLight\Isp\IspDblog.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\BlueLight\Isp\MainExceptions.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\34b6b454f78f576ac2d0552f39fe259d_24adf822-76f7-4481-b30b-ff1b40f8687f Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3ad391678a806ec4d691e83aaa393b6f_24adf822-76f7-4481-b30b-ff1b40f8687f Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\eHome\logs\ehRecvr.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\SupportSoft\DellSupportCenter\SYSTEM\state\logs\sprtcmd.log Object is locked skipped
C:\Documents and Settings\Amanda Miller\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Robin Miller\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Robin Miller\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Robin Miller\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Robin Miller\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Robin Miller\Local Settings\Application Data\Musicmatch\Jukebox\mmjbaltlog.txt Object is locked skipped
C:\Documents and Settings\Robin Miller\Local Settings\Application Data\Musicmatch\Jukebox\mmjblog.txt Object is locked skipped
C:\Documents and Settings\Robin Miller\Local Settings\Application Data\Musicmatch\MIM\Database\Default.ldb Object is locked skipped
C:\Documents and Settings\Robin Miller\Local Settings\Application Data\Musicmatch\MIM\Database\Default.mdb Object is locked skipped
C:\Documents and Settings\Robin Miller\Local Settings\Application Data\SupportSoft\DellSupportCenter\Robin Miller\state\logs\sprtcmd.log Object is locked skipped
C:\Documents and Settings\Robin Miller\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Robin Miller\Local Settings\Temp\JETFF8D.tmp Object is locked skipped
C:\Documents and Settings\Robin Miller\Local Settings\Temp\Perflib_Perfdata_b10.dat Object is locked skipped
C:\Documents and Settings\Robin Miller\Local Settings\Temp\~DF71B8.tmp Object is locked skipped
C:\Documents and Settings\Robin Miller\Local Settings\Temp\~DF71C5.tmp Object is locked skipped
C:\Documents and Settings\Robin Miller\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Robin Miller\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Robin Miller\ntuser.dat.LOG Object is locked skipped
C:\fbba63bf00fc7b896631ff26\update\update.exe Object is locked skipped
C:\fbba63bf00fc7b896631ff26\update\updspapi.dll Object is locked skipped
C:\fbba63bf00fc7b896631ff26\update\wpdinstallutil.dll Object is locked skipped
C:\Program Files\filesubmit\megaman_x4.zip\atoolbar400134.exe/WISE0001.BIN Infected: not-a-virus:AdWare.Win32.Accoona.b skipped
C:\Program Files\filesubmit\megaman_x4.zip\atoolbar400134.exe WiseSFX: infected - 1 skipped
C:\Program Files\filesubmit\megaman_x4.zip\atoolbar400134.exe WiseSFXDropper: infected - 1 skipped
C:\Program Files\filesubmit\mmxserieszero.exe\atoolbar400134.exe/WISE0001.BIN Infected: not-a-virus:AdWare.Win32.Accoona.b skipped
C:\Program Files\filesubmit\mmxserieszero.exe\atoolbar400134.exe WiseSFX: infected - 1 skipped
C:\Program Files\filesubmit\mmxserieszero.exe\atoolbar400134.exe WiseSFXDropper: infected - 1 skipped
C:\Program Files\Morpheus\morpheustoolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc100\spyzookasetup1.exe Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1000.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1001.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1002.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1003.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1004.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1005.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1006.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1007.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1008.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1009.txt Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc101\SZPro5.msi Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1010.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1011.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1012.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1013.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1014.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1015.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1016.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1017.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1018.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1019.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1020.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1021.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1022.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1023.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1024.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1025.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1026.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1027.emf Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1028.emf Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1029.emf Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc103.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1030.emf Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1031.emf Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1032.emf Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1033.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1034.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1035.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1036.exe Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1037.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1038.txt Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1039.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc104.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1040.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1041.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1042.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1043.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1044.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1045.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1046.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1047.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1048.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1049.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc105.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1050.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1051.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1052.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1053.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1054.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1055.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1056.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1057.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1058.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1059.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc106.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1060.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1061.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1062.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1063.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1064.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1065.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1066.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1067.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1068.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1069.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc107.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1070.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1071.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1072.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1073.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1074.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1075.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1076.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1077.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1078.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1079.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc108.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1080.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1081.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1082.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1083.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1084.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1085.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1086.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1087.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1088.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1089.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc109.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1090.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1091.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1092.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1093.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1094.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1095.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1096.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1097.emf Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1098.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1099.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc110.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1100.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1101.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1102.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1103.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1104.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1105.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1106.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1107.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1108.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1109.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc111.dll Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1110.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1111.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1112.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1113.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1114.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1115.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1116.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1117.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1118.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1119.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc112.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1120.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1121.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1122.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1123.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1124.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1125.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1126.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1127.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1128.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1129.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc113.dll Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1130.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1131.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1132.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1133.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1134.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1135.dll Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1136.dll Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1137.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1138.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1139.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc114.cdas Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1140.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1141.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1142.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1143.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1144.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1145.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1146.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1147.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1148.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1149.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc115.cdas Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1150.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1151.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1152.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1153.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1154.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1155.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1156.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1157.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1158.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1159.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc116.cdas Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1160.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1161.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1162.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1163.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1164.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1165.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1166.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1167.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1168.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1169.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc117.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1170.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1171.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1172.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1173.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1174.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1175.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1176.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1177.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1178.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1179.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc118.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1180.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1181.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1182.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1183.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1184.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1185.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1186.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1187.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1188.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1189.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc119.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1190.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1191.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1192.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1193.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1194.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1195.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1196.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1197.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1198.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1199.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc120.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1200.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1201.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1202.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1203.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1204.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1205.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1206.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1207.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1208.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1209.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc121.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1210.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1211.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1212.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1213.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1214.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1215.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1216.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1217.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1218.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1219.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc122.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1220.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1221.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1222.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1223.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1224.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1225.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1226.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1227.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1228.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1229.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc123.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1230.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1231.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1232.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1233.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1234.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1235.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1236.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1237.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1238.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1239.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc124.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1240.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1241.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1242.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1243.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1244.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1245.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1246.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1247.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1248.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1249.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc125.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1250.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1251.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1252.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1253.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1254.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1255.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1256.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1257.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1258.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1259.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc126.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1260.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1261.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1262.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1263.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1264.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1265.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1266.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1267.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1268.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1269.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc127.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1270.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1271.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1272.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1273.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1274.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1275.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1276.txt Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1277.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1278.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1279.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc128.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1280.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1281.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1282.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1283.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1284.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1285.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1286.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1287.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1288.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1289.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc129.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1290.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1291.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1292.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1293.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1294.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1295.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1296.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1297.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1298.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1299.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc130.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1300.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1301.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1302.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1303.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1304.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1305.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1306.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1307.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1308.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1309.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc131.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1310.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1311.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1312.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1313.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1314.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1315.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1316.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1317.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1318.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1319.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc132.exe Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1320.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1321.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1322.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1323.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1324.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1325.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1326.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1327.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1328.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1329.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc133.exe Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1330.rra Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1331.rra Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1332.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1333.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1334.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1335.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1336.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1337.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1338.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1339.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc134.exe Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1340.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1341.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1342.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1343.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1344.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1345.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1346.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1347.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1348.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1349.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc135.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1350.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1351.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1352.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1353.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1354.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1355.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1356.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1357.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1358.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1359.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc136.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1360.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1361.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1362.txt Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1363.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1364.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1365.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1366.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1367.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1368.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1369.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc137.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1370.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1371.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1372.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1373.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1374.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1375.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1376.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1377.log Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1378.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1379.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc138.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1380.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1381.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1382.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1383.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1384.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1385.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1386.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1387.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1388.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1389.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc139.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1390.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1391.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1392.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1393.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1394.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1395.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1396.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1397.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1398.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1399.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc140.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1400.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1401.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1402.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1403.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1404.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1405.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1406.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1407.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1408.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1409.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc141.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1410.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1411.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1412.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1413.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1414.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1415.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1416.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1417.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1418.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1419.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc142 Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1420.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1421.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1422.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1423.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1424.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1425.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1426.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1427.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1428.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1429.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc143.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1430.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1431.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1432.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1433.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1434.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1435.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1436.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1437.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1438.tmp Object is locked skipped
C:\RECYCLER\S-1-5-21-1258873628-1485194396-1333552478-1006\Dc1439.tmp Object is locked skipped
  • 0

#7
Mike

Mike

    Malware Monger

  • Retired Staff
  • 2,745 posts
Hi there Robin Miller,

Let's do this.

Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, in the menu, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.

  • 0

#8
Robin Miller

Robin Miller

    Member

  • Topic Starter
  • Member
  • PipPip
  • 32 posts
Hi,
I was working on your other directions last night, and my internet is so horribly slow, it kept getting bogged down with the text from the log of the Kaspersky Antivirus. That's what I was doing, trying to get all that posted, because there was so much, that I never even got to the DSS again.
  • 0

#9
Mike

Mike

    Malware Monger

  • Retired Staff
  • 2,745 posts
Hi robin,

Just go ahead and run Dr.Web CureIt, just forget about the DSS log at the moment.

Edited by Mike, 18 May 2008 - 07:57 AM.

  • 0

#10
Mike

Mike

    Malware Monger

  • Retired Staff
  • 2,745 posts
Edited post, refresh please.
  • 0

Advertisements


#11
Robin Miller

Robin Miller

    Member

  • Topic Starter
  • Member
  • PipPip
  • 32 posts
Hi,
Up until now, I wasn't able to download the dr. web, but it seems to be working now. It will take awhile, tho - I'm on dialup.

Bad news is my daughter got on the internet today to check her myspace, and these windows popped up. We didn't click on them to close them, I tried going to task manager and it wouldn't open, so I just shut down and restarted. Now my desktop is blue, and it says "Warning, spyware threat has been detected on your pc..." Same thing I had before only it was red, now it's blue. And a little yellow triangle pops up on the lower right of the taskbar, warning me that I have spyware detected on my computer and need to do a full system scan. What can I do?

I am downloading the dr. web at the moment.
  • 0

#12
Robin Miller

Robin Miller

    Member

  • Topic Starter
  • Member
  • PipPip
  • 32 posts
Here's the results from the Dr. Web:

Process.exe;C:\Documents and Settings\Administrator\Desktop\SmitfraudFix;Tool.Prockill;;
restart.exe;C:\Documents and Settings\Administrator\Desktop\SmitfraudFix;Tool.ShutDown.11;;
inst.exe;C:\Documents and Settings\All Users\Application Data\AOL Downloads\AIMSUD338;Probably BACKDOOR.Trojan;;
inst.exe;C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_suite_install_2.2.71.1;Probably BACKDOOR.Trojan;;
RegUBP2b-Robin Miller.reg;C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2;Trojan.StartPage.1505;Deleted.;
Process.exe;C:\Documents and Settings\Amanda Miller\Desktop\SmitfraudFix;Tool.Prockill;;
restart.exe;C:\Documents and Settings\Amanda Miller\Desktop\SmitfraudFix;Tool.ShutDown.11;;
Process.exe;C:\Documents and Settings\Robin Miller\Desktop\SmitfraudFix;Tool.Prockill;;
restart.exe;C:\Documents and Settings\Robin Miller\Desktop\SmitfraudFix;Tool.ShutDown.11;;
A0092524.dll;C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP732;Adware.OneStep;;
A0096804.reg;C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP787;Trojan.StartPage.1505;Deleted.;
A0096907.exe;C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP787;Tool.Prockill;;
A0096909.exe;C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP787;Tool.ShutDown.11;;
A0097385.reg;C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP794;Trojan.StartPage.1505;Deleted.;
A0097538.exe;C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP795;Trojan.PWS.Gamania.origin;Incurable.Moved.;
A0097539.exe;C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP795;Tool.Prockill;;
A0097540.reg;C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP795;Trojan.StartPage.1505;Deleted.;
  • 0

#13
Mike

Mike

    Malware Monger

  • Retired Staff
  • 2,745 posts
Hi Robin,

I apologize for having you download that, I did not realize that you were running dial-up. This may take a while to download but we can do most (if not all) or fixes with it if needed.

Before running a new scan let's clean out the temporary folders.

Download ATF Cleaner to your Desktop.

  • Double-click ATF-Cleaner.exe to run the program.
  • Click Select All found at the bottom of the list.
  • Click the Empty Selected button.
If you use Firefox browser, do this also:
  • Click Firefox at the top and choose Select All from the list.
  • Click the Empty Selected button.
  • NOTE : If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser, do this also:
  • Click Opera at the top and choose Select All from the list.
  • Close ALL Internet browsers (very important).
  • Click the Empty Selected button.
  • NOTE : If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.

Now download OTScanIt.exe to your Desktop and double-click on it to extract the files. It will create a folder named OTScanIt on your desktop.

Note: You must be logged on to the system with an account that has Administrator privileges to run this program.
  • Close ALL OTHER PROGRAMS.
  • Open the OTScanIt folder and double-click on OTScanIt.exe to start the program (if you are running on Vista then right-click the program and choose Run as Administrator).
  • In the Drivers section click on Non-Microsoft.
  • Under Additional Scans click the checkboxes in front of the following items to select them:
    • Reg - BotCheck
      File - Additional Folder Scans
  • Do not change any other settings.
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Use the Add Reply button and Copy/Paste the information back here. I will review it when it comes in. Make sure that the first line is code with brackets around it [] and that the last line is /code with brackets around it [].

If, after posting, the last line is not <End of Report> then the log is too big to fit into a single post and you will need to split it into multiple posts or attach it as a file.
  • 0

#14
Robin Miller

Robin Miller

    Member

  • Topic Starter
  • Member
  • PipPip
  • 32 posts
Attached File  OTScanIt.Txt   237.71KB   54 downloads

I am attaching the results from the OTScanIt as a file
  • 0

#15
Mike

Mike

    Malware Monger

  • Retired Staff
  • 2,745 posts
Hi there Robin,

You have a heavily infected machine running there.

Very Important!

You have a backdoor trojan installed on your computer.
Backdoor Trojans, IRCBots and Infostealers are very dangerous because they provide a means of accessing a computer system that bypasses security mechanisms and steal sensitive information like passwords, personal and financial data which they send back to the hacker. Remote attackers use backdoor Trojans as part of an exploit to to gain unauthorized access to a computer and take control of it without your knowledge.

If your computer was used for online banking, has credit card information or other sensitive data on it, you should immediately disconnect from the Internet until your system is cleaned.
All passwords should be changed immediately to include those used for banking, email, eBay and forums. You should consider them to be compromised. They should be changed by using a different computer and not the infected one. If not, an attacker may get the new passwords and transaction information. Banking and credit card institutions should be notified of the possible security breach.

Although the backdoor Trojan has been identified and may be removed, your PC has likely been compromised and there is no way to be sure the computer can ever be trusted again.
It is dangerous and incorrect to assume that because the backdoor Trojan has been removed the computer is now secure.
Many experts in the security community believe that once infected with this type of malware, the best course of action is to reformat and reinstall the OS. When should I re-format?

If you choose to reformat please let me know in your next post. Otherwise please proceed with the rest of my instructions.

Fixes With OTScanIt

Start OTScanIt. Copy/Paste the information in the Code box below into the pane where it says "Paste fix here" and then click the Run Fix button.

[Processes - Non-Microsoft Only]
 YY -> xwusuhzh.exe -> %SystemRoot%\system32\xwusuhzh.exe
 [Registry - Non-Microsoft Only]
 < Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
 *UserInit* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit
 YN -> C:\WINDOWS\system32\xwusuhzh.exe -> %SystemRoot%\system32\xwusuhzh.exe
 < Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
 < CurrentVersion Policy Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\
 YN -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\DisableTaskMgr -> 1
 < CurrentVersion Policy Settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\
 YN -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableTaskMgr -> 1
 < Drives - Autoruns > -> 
 NY -> AUTOEXEC.BAT [] -> %SystemDrive%\AUTOEXEC.BAT [ NTFS ]
 < Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> 
 YN -> HKEY_LOCAL_MACHINE\: Main\\Local Page -> C:\windows\system32\blank.htm
 < Internet Explorer Settings [HKEY_CURRENT_USER\] > -> 
 YN -> HKEY_CURRENT_USER\: Main\\Local Page -> C:\windows\system32\blank.htm
 YN -> HKEY_CURRENT_USER\: Main\\Search Bar -> http://my.netzero.net/s/search?r=minisearch
 YN -> HKEY_CURRENT_USER\: Main\\Search Page -> http://my.netzero.net/s/search?r=minisearch
 YN -> HKEY_CURRENT_USER\: Main\\Start Page -> http://www.mybluelight.com/
 YN -> HKEY_CURRENT_USER\: SearchURL\\ -> http://my.netzero.net/s/search?r=minisearch[Reg Error: Value provider does not exist or could not be read.]
 < BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
 YN -> {00110011-4b0b-44d5-9718-90c88817369b} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
 YN -> {086ae192-23a6-48d6-96ec-715f53797e85} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
 YN -> {150fa160-130d-451f-b863-b655061432ba} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
 YN -> {17da0c9e-4a27-4ac5-bb75-5d24b8cdb972} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
 YN -> {1f48aa48-c53a-4e21-85e7-ac7cc6b5ffb1} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
 YN -> {1f48aa48-c53a-4e21-85e7-ac7cc6b5ffb2} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
 YN -> {2d38a51a-23c9-48a1-a33c-48675aa2b494} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
 YN -> {2e9caff6-30c7-4208-8807-e79d4ec6f806} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
 YN -> {467faeb2-5f5b-4c81-bae0-2a4752ca7f4e} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
 YN -> {5321e378-ffad-4999-8c62-03ca8155f0b3} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
 YN -> {587dbf2d-9145-4c9e-92c2-1f953da73773} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
 YN -> {6cc1c91a-ae8b-4373-a5b4-28ba1851e39a} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
 YN -> {79369d5c-2903-4b7a-ade2-d5e0dee14d24} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
 YN -> {799a370d-5993-4887-9df7-0a4756a77d00} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
 YN -> {98dbbf16-ca43-4c33-be80-99e6694468a4} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
 YN -> {a55581dc-2cdb-4089-8878-71a080b22342} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
 YN -> {b847676d-72ac-4393-bfff-43a1eb979352} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
 YN -> {bc97b254-b2b9-4d40-971d-78e0978f5f26} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
 YN -> {cf021f40-3e14-23a5-cba2-717765721306} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
 YN -> {e2ddf680-9905-4dee-8c64-0a5de7fe133c} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
 YN -> {e3eebbe8-9cab-4c76-b26a-747e25ebb4c6} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
 YN -> {e7afff2a-1b57-49c7-bf6b-e5123394c970} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
 YN -> {fcaddc14-bd46-408a-9842-cdbe1c6d37eb} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
 YN -> {fd9bc004-8331-4457-b830-4759ff704c22} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
 YN -> {ff1bf4c7-4e08-4a28-a43f-9d60a9f7a880} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
 [Files/Folders - Created Within 30 days]
 NY -> hljwugsf.bin -> %SystemRoot%\System32\hljwugsf.bin
 NY -> 28 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp
 NY -> xwusuhzh.exe -> %SystemRoot%\System32\xwusuhzh.exe
 NY -> accesss.exe -> %SystemRoot%\accesss.exe
 NY -> astctl32.ocx -> %SystemRoot%\astctl32.ocx
 NY -> avpcc.dll -> %SystemRoot%\avpcc.dll
 NY -> clrssn.exe -> %SystemRoot%\clrssn.exe
 NY -> cpan.dll -> %SystemRoot%\cpan.dll
 NY -> ctfmon32.exe -> %SystemRoot%\ctfmon32.exe
 NY -> ctrlpan.dll -> %SystemRoot%\ctrlpan.dll
 NY -> default.htm -> %SystemRoot%\default.htm
 NY -> directx32.exe -> %SystemRoot%\directx32.exe
 NY -> dnsrelay.dll -> %SystemRoot%\dnsrelay.dll
 NY -> editpad.exe -> %SystemRoot%\editpad.exe
 NY -> 2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp
 NY -> estrictions.dll -> %SystemRoot%\estrictions.dll
 NY -> explore.exe -> %SystemRoot%\explore.exe
 NY -> explorer32.exe -> %SystemRoot%\explorer32.exe
 NY -> funniest.exe -> %SystemRoot%\funniest.exe
 NY -> funny.exe -> %SystemRoot%\funny.exe
 NY -> gfmnaaa.dll -> %SystemRoot%\gfmnaaa.dll
 NY -> helpcvs.exe -> %SystemRoot%\helpcvs.exe
 NY -> iedll.exe -> %SystemRoot%\iedll.exe
 NY -> iexplorer.exe -> %SystemRoot%\iexplorer.exe
 NY -> index.html -> %SystemRoot%\index.html
 NY -> inetinf.exe -> %SystemRoot%\inetinf.exe
 NY -> internet.exe -> %SystemRoot%\internet.exe
 NY -> loader.exe -> %SystemRoot%\loader.exe
 NY -> mainms.vpi -> %SystemRoot%\mainms.vpi
 NY -> megavid.cdt -> %SystemRoot%\megavid.cdt
 NY -> msconfd.dll -> %SystemRoot%\msconfd.dll
 NY -> msspi.dll -> %SystemRoot%\msspi.dll
 NY -> mssys.exe -> %SystemRoot%\mssys.exe
 NY -> msupdate.exe -> %SystemRoot%\msupdate.exe
 NY -> mswsc10.dll -> %SystemRoot%\mswsc10.dll
 NY -> mswsc20.dll -> %SystemRoot%\mswsc20.dll
 NY -> mtwirl32.dll -> %SystemRoot%\mtwirl32.dll
 NY -> muotr.so -> %SystemRoot%\muotr.so
 NY -> notepad32.exe -> %SystemRoot%\notepad32.exe
 NY -> olehelp.exe -> %SystemRoot%\olehelp.exe
 NY -> qttasks.exe -> %SystemRoot%\qttasks.exe
 NY -> quicken.exe -> %SystemRoot%\quicken.exe
 NY -> rundll16.exe -> %SystemRoot%\rundll16.exe
 NY -> rundll32.vbe -> %SystemRoot%\rundll32.vbe
 NY -> searchword.dll -> %SystemRoot%\searchword.dll
 NY -> sistem.exe -> %SystemRoot%\sistem.exe
 NY -> svchost32.exe -> %SystemRoot%\svchost32.exe
 NY -> svcinit.exe -> %SystemRoot%\svcinit.exe
 NY -> systeem.exe -> %SystemRoot%\systeem.exe
 NY -> systemcritical.exe -> %SystemRoot%\systemcritical.exe
 NY -> time.exe -> %SystemRoot%\time.exe
 NY -> users32.exe -> %SystemRoot%\users32.exe
 NY -> win32e.exe -> %SystemRoot%\win32e.exe
 NY -> win64.exe -> %SystemRoot%\win64.exe
 NY -> winajbm.dll -> %SystemRoot%\winajbm.dll
 NY -> window.exe -> %SystemRoot%\window.exe
 NY -> winmgnt.exe -> %SystemRoot%\winmgnt.exe
 NY -> x.exe -> %SystemRoot%\x.exe
 NY -> xplugin.dll -> %SystemRoot%\xplugin.dll
 NY -> xxxvideo.hta -> %SystemRoot%\xxxvideo.hta
 NY -> y.exe -> %SystemRoot%\y.exe
 [Files Created - Additional Folder Scans - Non-Microsoft Only]
 NY -> @Alternate Data Stream - 26 bytes -> %UserProfile%\Desktop\ATF-Cleaner.exe:Zone.Identifier
 NY -> @Alternate Data Stream - 26 bytes -> %UserProfile%\Desktop\drweb-cureit.exe:Zone.Identifier
 NY -> @Alternate Data Stream - 26 bytes -> %UserProfile%\Desktop\OTScanIt.exe:Zone.Identifier
 [Empty Temp Folders]

The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. CLick the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here along with a new OTScanIt scan.

I will review the information when it comes back in.

Also let me know of any problems you encountered performing the steps above or any continuing problems you are still having with the computer.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP