Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Not Sure If Its A Virus Or Spyware


  • This topic is locked This topic is locked
12 replies to this topic

#1 mummsie39

mummsie39

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Delta BC
  • Local time:12:38 AM

Posted 14 October 2007 - 09:52 PM

I did all the steps in your Preperation Gueide for Use Befor Positng A Hijackthis Log. Was able to preforme all the steps except the disk clean which wouldn't budge however after the scans were complete I was abe to do the disk clean. That said the performance of my machine is somewhat better but still a little slow to load pages. Here is the Hijackthis Log:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:46:51 PM, on 10/14/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Software\Panda Antivirus 2007\pavsrv51.exe
C:\Program Files\Panda Software\Panda Antivirus 2007\AVENGINE.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Creative\Shared Files\CTDevSrv.exe
C:\WINDOWS\system32\dlcicoms.exe
C:\Program Files\Panda Software\Panda Antivirus 2007\PsCtrls.exe
C:\Program Files\Panda Software\Panda Antivirus 2007\psimsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\TELUSE~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\VTTimer.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\TELUS\eProtect Advisor\TEPA.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Dell AIO Printer 946\dlcimon.exe
C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Panda Software\Panda Antivirus 2007\WebProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\DOCUME~1\Owner\LOCALS~1\Temp\Temporary Directory 1 for HiJackThis 2.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\en-us\msntb.dll
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\TELUSE~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [Ulead AutoDetector] "C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] "C:\Program Files\Ahead\InCD\InCD.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TEPA.exe] "C:\Program Files\TELUS\eProtect Advisor\TEPA.exe" /AUTORUN
O4 - HKLM\..\Run: [capfaem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfaem.exe
O4 - HKLM\..\Run: [cafwc] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
O4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [DLCICATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCItime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlcimon.exe] "C:\Program Files\Dell AIO Printer 946\dlcimon.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Dell Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [CTRegRun] C:\WINDOWS\CTRegRun.EXE
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O8 - Extra context menu item: &Search -
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Owner\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .UVR: C:\Program Files\Internet Explorer\Plugins\NPUPano.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15030/CTSUEng.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1C11B948-582A-433F-A98D-A8C4D5CC64F2} (20-20 3D Viewer) - http://design-concept.ca/Core/Player/2020PlayerAX_Win32.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/...nst20040510.cab
O16 - DPF: {33E54F7F-561C-49E6-929B-D7E76D3AFEB1} (Pool Control) - http://www.worldwinner.com/games/v48/pool/pool.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1138855071213
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://download.shockwave.com/pub/otoy/OTOYAX.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9FC9C569-BBEE-491A-A57C-A5E3F048DA31} (Setup Object) - http://services.yummy.net/download/Player3...PlayerSetup.CAB
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} -
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} (Java Plug-in 1.6.0_01) -
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} (Java Plug-in 1.6.0_02) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.shockwave.com/content/heavyweap...aploader_v6.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15030/CTPID.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: CT Device Query service (CTDevice_Srv) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTDevSrv.exe
O23 - Service: dlci_device - - C:\WINDOWS\system32\dlcicoms.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Panda Software Controller - Panda Software International - C:\Program Files\Panda Software\Panda Antivirus 2007\PsCtrls.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Software\Panda Antivirus 2007\pavsrv51.exe
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program Files\Panda Software\Panda Antivirus 2007\psimsvc.exe

--
End of file - 11365 bytes

BC AdBot (Login to Remove)

 


m

#2 SifuMike

SifuMike

    malware expert


  • Staff Emeritus
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:01:38 AM

Posted 23 October 2007 - 06:55 PM

Hello mummsie39,

I see you put your Hijackthis in a temp folder :thumbsup:

C:\DOCUME~1\Owner\LOCALS~1\Temp\Temporary Directory 1 for HiJackThis 2.zip\HijackThis.exe


It needs to be in its own folder, but not a temp folder.
It won't save the backups if it is run from a temporary folder, and we will be deleting the temp folder.

Here is how to make a Hijackthis folder:

Click My Computer, then C:\
In the menu bar, File->New->Folder.
That will create a folder named New Folder, which you can rename to "HJT". Now you have C:\HJT\ folder.
Put your hijackthis.exe there.
Please post a new Hijackthis log.


Also, llet's look in a different place for signs.

Open HijackThis 2.0.2
Press the button 'View Misc Tools Section'
Press the button 'open uninstall manager'
Press the button 'save list'
A notepad file will open.
Post the content here in your reply.
Close HijackThis.
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#3 mummsie39

mummsie39
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Delta BC
  • Local time:12:38 AM

Posted 24 October 2007 - 08:40 AM

Well hopefully I did this right here are the logs you asked for

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:36:12 AM, on 10/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Software\Panda Antivirus 2007\pavsrv51.exe
C:\Program Files\Panda Software\Panda Antivirus 2007\AVENGINE.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Creative\Shared Files\CTDevSrv.exe
C:\Program Files\Panda Software\Panda Antivirus 2007\PsCtrls.exe
C:\Program Files\Panda Software\Panda Antivirus 2007\psimsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\UPHClean\uphclean.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\TELUSE~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\VTTimer.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\TELUS\eProtect Advisor\TEPA.exe
C:\Program Files\Dell AIO Printer 946\dlcimon.exe
C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dlcicoms.exe
C:\Program Files\Panda Software\Panda Antivirus 2007\WebProxy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HiJackThis 2\HijackThis.exe
C:\WINDOWS\system32\notepad.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\en-us\msntb.dll
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\TELUSE~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [Ulead AutoDetector] "C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] "C:\Program Files\Ahead\InCD\InCD.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TEPA.exe] "C:\Program Files\TELUS\eProtect Advisor\TEPA.exe" /AUTORUN
O4 - HKLM\..\Run: [capfaem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfaem.exe
O4 - HKLM\..\Run: [cafwc] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
O4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [DLCICATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCItime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlcimon.exe] "C:\Program Files\Dell AIO Printer 946\dlcimon.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Dell Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O8 - Extra context menu item: &Search -
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Owner\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .UVR: C:\Program Files\Internet Explorer\Plugins\NPUPano.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15030/CTSUEng.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1C11B948-582A-433F-A98D-A8C4D5CC64F2} (20-20 3D Viewer) - http://design-concept.ca/Core/Player/2020PlayerAX_Win32.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/...nst20040510.cab
O16 - DPF: {33E54F7F-561C-49E6-929B-D7E76D3AFEB1} (Pool Control) - http://www.worldwinner.com/games/v48/pool/pool.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1138855071213
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://download.shockwave.com/pub/otoy/OTOYAX.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9FC9C569-BBEE-491A-A57C-A5E3F048DA31} (Setup Object) - http://services.yummy.net/download/Player3...PlayerSetup.CAB
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} -
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} (Java Plug-in 1.6.0_01) -
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} (Java Plug-in 1.6.0_02) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.shockwave.com/content/heavyweap...aploader_v6.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15030/CTPID.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: CT Device Query service (CTDevice_Srv) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTDevSrv.exe
O23 - Service: dlci_device - - C:\WINDOWS\system32\dlcicoms.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Panda Software Controller - Panda Software International - C:\Program Files\Panda Software\Panda Antivirus 2007\PsCtrls.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Software\Panda Antivirus 2007\pavsrv51.exe
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program Files\Panda Software\Panda Antivirus 2007\psimsvc.exe

--
End of file - 11017 bytes




Unistall List
Ad-Aware SE Personal
Adobe Flash Player 9 ActiveX
Adobe Flash Player ActiveX
Adobe Flash Player Plugin
Adobe Reader 8.1.0
Adobe Shockwave Player
Amazing Windows XP Screen Saver 1.2
Anark Client 1.0
Apple Mobile Device Support
Apple Software Update
ArcSoft Camera Suite 1.3
a-squared Free 3.0
BroadJump Client Foundation
Browser Mouse
Canon Camera Support Core Library
Canon Camera Window for ZoomBrowser EX
Canon MovieEdit Task for ZoomBrowser EX
Canon PhotoRecord
Canon RAW Image Task for ZoomBrowser EX
Canon RemoteCapture Task for ZoomBrowser EX
Canon Utilities PhotoStitch 3.1
Canon Utilities ZoomBrowser EX
CBN Selector 3
CCleaner (remove only)
Creative Media Lite
Creative ZEN Stone User's Guide
Dell AIO Printer 946
Dell PC Fax
Fish Tycoon
Fish Tycoon (remove only)
Google Earth
HijackThis 2.0.2
Holiday Snowflakes Screen Saver 1.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB900485)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
IncrediMail Xe
iTunes
Jasc Paint Shop Photo Album 5
Jasc Paint Shop Pro Studio, Dell Editon
Java™ 6 Update 3
Lernout & Hauspie TruVoice American English TTS Engine
Magentic
Messenger Plus! 3 & Sponsor
Messenger Plus! Live & Sponsor (CiD)
Microsoft .NET Framework 2.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Excel Viewer 2003
Microsoft Office PowerPoint Viewer 2003
Microsoft Text-to-Speech Engine 4.0 (English)
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Windows Journal Viewer
mIRC
Mozilla Firefox (2.0.0.8)
MSN
MSN Toolbar
MSXML 4.0 SP2 (KB925672)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
Muiltmedia keyboard utility 1.1
myTaxExpress 2005
myTaxExpress NETFILE 2006
Nero Suite
OTOY
Panda ActiveScan
Panda Antivirus 2008
Panda TotalScan
Photo Explosion SE 2.0
PowerDVD
Print to Fax
QuickTime
RealPlayer
Realtek AC'97 Audio
Rhapsody Player Engine
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 2.0 (KB928365)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB911565)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893066)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB938829)
ShortKeys Lite
Sony USB Driver
Spybot - Search & Destroy 1.4
SpywareBlaster v3.5.1
Stop the Morbuzakh (remove only)
SUPERAntiSpyware Free Edition
TELUS 2006 Calendar Screen Saver
TELUS 2007 Calendar Wallpaper
TELUS eCare
TELUS eCare Plugin
TELUS eProtect Advisor 1.5.11
The Sims Complete Collection
Tux Paint 0.9.16
Tux Paint Stamps 2006-10-21
Ulead COOL 360 1.0
Ulead Photo Explorer 8.0 SE Basic
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB904942)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB938828)
USB PC Camera (SN9C103)
User Profile Hive Cleanup Service
Windows Defender Signatures
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Winter Fun Pack Screensavers
Yummy Player

#4 SifuMike

SifuMike

    malware expert


  • Staff Emeritus
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:01:38 AM

Posted 24 October 2007 - 01:48 PM

Hi mummsie39,

Ad-Aware SE Personal and Spybot - Search & Destroy 1.4 are both outdated so you need to uninstall them.


Please download, update and run (one at a time of course!)
Spybot 1.5 and Ad-Aware 2007 Free

Fix whatever they suggest.

If you need help running these tools, here are some helpful tutorials.
Spybot Tutorial
Ad-Aware 2007 Free tutorial

*******************************************


Select the following with HijackThis.
With all windows (including this one!) closed (close browser/explorer windows), please select "fix checked"

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O8 - Extra context menu item: &Search -
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Owner\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} -
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} (Java Plug-in 1.6.0_01) -
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} (Java Plug-in 1.6.0_02)
O16 - DPF: {33E54F7F-561C-49E6-929B-D7E76D3AFEB1} (Pool Control) - http://www.worldwinner.com/games/v48/pool/pool.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab


These are optinal fixes. The following are not necessarily spyware/malware, but we suggest you place a check mark next to the following entries, as these programs may be taking up system resources.

O4 - HKLM\..\Run: [TkBellExe] \"C:\Program Files\Common Files\Real\Update_OB\realsched.exe\" -osboot
(Description: RealPlayer scheduler. Completely unnecessary. Removing this entry will free up a small amount of system resources.)

O4 - HKLM\..\Run: [SunJavaUpdateSched] \"C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe\"
(Description: Sun Java update scheduler. Checks for updates. Not necessary. Removing this entry will free up a small amount of system resources.)

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
(Description: Background task installed by Apple's iTunes music player and also by version 7 of QuickTime which now comes inseparably bundled with iTunes. This task does not actually need to be installed as a startup since iTunes starts it up anyway when it needs it. Let iTunes start it up whenever it needs to, particularly since it has a history of occasionally conflicting with other software and it uses nearly 6Mb of memory. )

*******************************************

*NOTE* CCleaner deletes EVERYTHING out of temp/temporary folders and does not make backups.

Let's empty the temp files:

Run CCleaner.

CAUTION: Please do NOT use the Issues or Registry button. This is a built-in registry cleaner. If you don't know how to use it, you may cause irreparable damage to your system.

1. Starting with v1.27.260, CCleaner installs the Yahoo Toolbar as an option which IS checkmarked by default during the installation.
IF you do NOT want it, REMOVE the checkmark when provided with the option OR download the toolbarfree Basic version instead of the Standard Build.


2. Before first use, select Options > Advanced and UNCHECK "Only delete files in Windows Temp folder older than 48 hours"

3. Then select the items you wish to clean up.

In the Windows Tab:
• Clean all entries in the "Internet Explorer" section except Autocomplete Forum History.
• Clean all the entries in the "Windows Explorer" section.
• Clean all entries in the "System" section except for Start Menu Shortcuts and Desktop Shortcuts.
• Clean any others that you choose.

In the Applications Tab:
• Clean all including cookies in the Firefox/Mozilla section if you use it.
• Clean all in the Opera section if you use it.
• Clean Sun Java in the Internet Section.
• Clean any others that you choose.

4. Click the "Run Cleaner" button.
5. A pop up box will appear advising this process will permanently delete files from your system.
6. Click "OK" and it will scan and clean your system.
7. Click "exit" when done.

If it asks you to reboot at the end, click NO.

CCleaner should be run with the above settings for each User Account!

*******************************************

Reboot your computer.

If you have used Combofix before, please delete the version you are having and redownload it again, because Combofix is being updated everyday.

Disconnect from the Internet while running ComboFix.

If your Antivirus or any other realtime scanner is displaying an alert after you downloaded Combofix or while you use Combofix, please disable your Antivirus and scanner and redownload Combofix again. Some scanners may see some combofix related components as suspicious and block or delete them while there's nothing wrong with them.



1. Download this file - combofix.exe to your Desktop.
Note:
It is important that it is saved directly to your desktop

2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you, C:\ComboFix.txt. Post the ComboFix  log and a fresh Hijackthis log in your next reply.
Do NOT post the ComboFix-quarantined-files.txt - unless I ask you to.
 
Note:
Do not mouseclick combofix's window while it's running. That may cause it to stall
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#5 mummsie39

mummsie39
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Delta BC
  • Local time:12:38 AM

Posted 24 October 2007 - 11:38 PM

Hi SifuMike
Okay phew that took a while and here are the logs you've asked for:

Combofix log:
ComboFix 07-10-23.1 - Owner 2007-10-24 19:19:40.2 - NTFSx86
Script execution time was exceeded on script "C:\ComboFix\osid.vbs".
Script execution was terminated.
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix(2).exe
.

((((((((((((((((((((((((( Files Created from 2007-09-25 to 2007-10-25 )))))))))))))))))))))))))))))))
.

2007-10-24 18:58 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-24 17:36 <DIR> d-------- C:\Documents and Settings\army man daniel\Application Data\DellFaxCtr
2007-10-24 06:28 <DIR> d-------- C:\HiJackThis 2
2007-10-24 06:23 <DIR> d-------- C:\New Folder
2007-10-20 16:15 <DIR> d-------- C:\Program Files\Common Files\Insight Software Solutions
2007-10-19 11:13 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Creative
2007-10-14 19:45 318,369 --a------ C:\HiJackThis 2.zip
2007-10-11 14:48 <DIR> d-------- C:\Program Files\iTunes
2007-10-09 13:34 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-10-09 13:34 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
2007-10-09 13:31 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-10-07 22:06 <DIR> d-------- C:\Program Files\Panda Security
2007-10-05 07:49 53,248 --------- C:\WINDOWS\Ctregrun.exe
2007-10-05 07:48 44,032 --a------ C:\WINDOWS\system32\CTSVCCDA.EXE
2007-10-05 07:48 25,088 --------- C:\WINDOWS\system32\CTSVCCTL.EXE
2007-10-05 07:47 <DIR> d-------- C:\Program Files\Creative
2007-09-27 07:02 248 --a------ C:\WINDOWS\system32\PavCPL.dat
2007-09-26 17:42 83,640 --a------ C:\WINDOWS\system32\drivers\pavdrv51.sys
2007-09-26 17:40 <DIR> d-------- C:\WINDOWS\system32\PAV
2007-09-26 17:39 <DIR> d-------- C:\Program Files\Panda Software
2007-09-26 17:39 50,736 --a------ C:\WINDOWS\system32\avldr.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-25 01:15 --------- d-----w C:\Program Files\Dl_cats
2007-10-25 00:36 --------- d-----w C:\Documents and Settings\army man daniel\Application Data\TELUS
2007-10-24 23:03 --------- d-----w C:\Program Files\Lavasoft
2007-10-24 21:35 --------- d-----w C:\Documents and Settings\Owner\Application Data\Lavasoft
2007-10-20 23:15 --------- d-----w C:\Program Files\ShortKeys2
2007-10-16 00:54 --------- d-----w C:\Program Files\MSN Messenger
2007-10-14 19:56 --------- d-----w C:\Program Files\a-squared Free
2007-10-14 18:16 --------- d-----w C:\Program Files\UPHClean
2007-10-14 18:16 --------- d-----w C:\Program Files\Dell Fax Solutions
2007-10-14 18:15 --------- d-----w C:\Program Files\Dell AIO Printer 946
2007-10-14 13:23 --------- d-----w C:\Program Files\Yahoo!
2007-10-14 13:22 --------- d-----w C:\Program Files\Oberon Media
2007-10-11 21:49 --------- d-----w C:\Program Files\iPod
2007-10-05 21:38 --------- d-----w C:\Program Files\Java
2007-10-05 14:46 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-09-29 03:40 --------- d-----w C:\Program Files\TuxPaint
2007-09-26 08:38 --------- d-----w C:\Program Files\QuickTime
2007-09-26 08:23 --------- d-----w C:\Program Files\Common Files\Motive
2007-09-26 06:22 --------- d-----w C:\Program Files\Messenger Plus! Live
2007-09-16 14:11 --------- d-----w C:\Program Files\Apple Software Update
2007-09-08 23:04 --------- d-----w C:\Documents and Settings\Owner\Application Data\IMVU
2007-09-06 23:14 --------- d-----w C:\Documents and Settings\AlYsSa\Application Data\IMVU
2007-08-28 00:13 --------- d-----w C:\Documents and Settings\Owner\Application Data\DellFaxCtr
2007-08-26 16:06 --------- d-----w C:\Program Files\ColorByNumbers
2007-08-17 23:52 424 ----a-w C:\delete.bat
2007-04-12 05:59 374 ----a-w C:\Documents and Settings\Owner\Application Data\internaldb6334.dat
2007-04-12 05:52 18,432 ----a-w C:\Documents and Settings\Owner\Application Data\internaldb41.dat
2007-04-12 05:49 538 ----a-w C:\Documents and Settings\Owner\Application Data\internaldb8467.dat
2007-03-15 17:38 14,729,096 ----a-w C:\Program Files\DivXBundle.exe
2007-02-25 19:58 14,098,984 ----a-w C:\Program Files\tuxpaint-stamps-2006-10-21-win32-installer.exe
2006-09-25 04:03 32 ----a-r C:\Documents and Settings\All Users\hash.dat
2005-12-06 02:28 916,806 ------w C:\Program Files\Dec2005_MDX1_x86.cab
2005-12-06 02:28 86,925 ------w C:\Program Files\Oct2005_xinput_x64.cab
2005-12-06 02:28 46,247 ------w C:\Program Files\Oct2005_xinput_x86.cab
2005-12-06 02:28 41,888 ------w C:\Program Files\dxdllreg_x86.cab
2005-12-06 02:28 3,673,932 ------w C:\Program Files\Dec2005_MDX1_x86_Archive.cab
2005-12-06 02:28 1,358,864 ------w C:\Program Files\Dec2005_d3dx9_28_x64.cab
2005-12-06 02:27 1,080,344 ------w C:\Program Files\Dec2005_d3dx9_28_x86.cab
2005-12-06 02:00 976,020 ------w C:\Program Files\BDAXP.cab
2005-12-06 02:00 81,092 ------w C:\Program Files\dxupdate.cab
2005-12-06 02:00 74,448 ------w C:\Program Files\DSETUP.dll
2005-12-06 02:00 703,080 ------w C:\Program Files\BDA.cab
2005-12-06 02:00 484,560 ------w C:\Program Files\DXSETUP.exe
2005-12-06 02:00 2,247,888 ------w C:\Program Files\dsetup32.dll
2005-12-06 02:00 15,493,481 ------w C:\Program Files\DirectX.cab
2005-12-06 02:00 13,265,040 ------w C:\Program Files\dxnt.cab
2005-12-06 02:00 1,351,430 ------w C:\Program Files\Aug2005_d3dx9_27_x64.cab
2005-12-06 02:00 1,348,242 ------w C:\Program Files\Apr2005_d3dx9_25_x64.cab
2005-12-06 02:00 1,336,890 ------w C:\Program Files\Jun2005_d3dx9_26_x64.cab
2005-12-06 02:00 1,248,387 ------w C:\Program Files\Feb2005_d3dx9_24_x64.cab
2005-12-06 02:00 1,156,363 ------w C:\Program Files\BDANT.cab
2005-12-06 02:00 1,079,850 ------w C:\Program Files\Apr2005_d3dx9_25_x86.cab
2005-12-06 02:00 1,078,532 ------w C:\Program Files\Aug2005_d3dx9_27_x86.cab
2005-12-06 02:00 1,065,813 ------w C:\Program Files\Jun2005_d3dx9_26_x86.cab
2005-12-06 02:00 1,014,113 ------w C:\Program Files\Feb2005_d3dx9_24_x86.cab
2003-08-16 09:04 850,536 ------w C:\Program Files\PJGrid11.ocx
2003-08-16 09:03 318,568 ------w C:\Program Files\PJTextConv11.dll
2003-08-16 09:03 301,672 ------w C:\Program Files\PJRes11C.dll
2003-08-16 09:03 219,752 ------w C:\Program Files\PJUpdate11.ocx
2003-08-16 09:03 219,752 ------w C:\Program Files\PJQuery11.ocx
2003-08-16 09:03 195,176 ------w C:\Program Files\PJOutlook11.ocx
2003-08-16 09:03 174,696 ------w C:\Program Files\PJCalendar11.ocx
2003-08-16 09:02 35,432 ------w C:\Program Files\PJPrint11.dll
2003-08-16 09:02 162,408 ------w C:\Program Files\PJ11ENUC.dll
2003-08-16 09:02 158,312 ------w C:\Program Files\PJOffline11.ocx
2003-08-16 08:45 1,559 ------w C:\Program Files\PJClient11.inf
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Motive SmartBridge"="C:\PROGRA~1\TELUSE~1\SMARTB~1\MotiveSB.exe" [2006-10-19 15:56]
"Ulead AutoDetector"="C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe" [2003-02-27 19:48]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50]
"InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [2004-09-07 08:25]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-12-08 18:35]
"VTTimer"="VTTimer.exe" [2005-05-12 21:57 C:\WINDOWS\system32\VTTimer.exe]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"TEPA.exe"="C:\Program Files\TELUS\eProtect Advisor\TEPA.exe" [2007-03-20 17:48]
"capfaem"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfaem.exe" []
"cafwc"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe" []
"capfasem"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe" []
"capfupgrade"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24]
"DLCICATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCItime.dll" [2006-10-20 15:01]
"dlcimon.exe"="C:\Program Files\Dell AIO Printer 946\dlcimon.exe" [2007-01-12 11:52]
"FaxCenterServer"="C:\Program Files\Dell Fax Solutions\fm3032.exe" [2006-12-07 22:19]
"APVXDWIN"="C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.exe" [2007-07-19 15:23]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 09:24]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr]
avldr.dll 2007-02-15 20:02 50736 C:\WINDOWS\system32\avldr.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^TELUS eCare.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\TELUS eCare.lnk
backup=C:\WINDOWS\pss\TELUS eCare.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\csrss]
"C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EzPrint]
"C:\Program Files\Lexmark 2300 Series\ezprint.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FaxCenterServer]
"C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FLMK08KB]
"C:\Program Files\Muiltmedia keyboard utility\1.1\MMKEYBD.EXE"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FLMOFFICE4DMOUSE]
"C:\Program Files\Browser Mouse\mouse32a.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LXCFCATS]
rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll,_RunDLLEntry@16

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LXCGCATS]
rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxcgmon.exe]
"C:\Program Files\Lexmark 2300 Series\lxcgmon.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MessengerPlus3]
"C:\Program Files\MessengerPlus! 3\MsgPlus.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\My Web Search Bar]
rundll32 C:\PROGRA~1\MYWEBS~1\bar\5.bin\MWSBAR.DLL,S

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
SOUNDMAN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TELUS Security service]
"C:\Program Files\TELUS\TELUS Security service\Freedom.exe"

*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2007-10-18 15:27:21 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
"2007-10-24 08:34:00 C:\WINDOWS\Tasks\Disk Cleanup.job"
- C:\WINDOWS\system32\cleanmgr.exe
.
**************************************************************************

catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-24 19:24:43
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs = ????????????
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCICATS = rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCItime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files ...

**************************************************************************
.
Completion time: 2007-10-24 19:28:33
C:\ComboFix2.txt ... 2007-10-24 19:09
.
--- E O F ---
Hijackthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:33:14 PM, on 10/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Software\Panda Antivirus 2007\pavsrv51.exe
C:\Program Files\Panda Software\Panda Antivirus 2007\AVENGINE.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Creative\Shared Files\CTDevSrv.exe
C:\WINDOWS\system32\dlcicoms.exe
C:\Program Files\Panda Software\Panda Antivirus 2007\PsCtrls.exe
C:\Program Files\Panda Software\Panda Antivirus 2007\psimsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\UPHClean\uphclean.exe
C:\PROGRA~1\TELUSE~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\VTTimer.exe
C:\Program Files\TELUS\eProtect Advisor\TEPA.exe
C:\Program Files\Dell AIO Printer 946\dlcimon.exe
C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Panda Software\Panda Antivirus 2007\WebProxy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HiJackThis 2\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (file missing)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\en-us\msntb.dll
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\TELUSE~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [Ulead AutoDetector] "C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] "C:\Program Files\Ahead\InCD\InCD.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TEPA.exe] "C:\Program Files\TELUS\eProtect Advisor\TEPA.exe" /AUTORUN
O4 - HKLM\..\Run: [capfaem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfaem.exe
O4 - HKLM\..\Run: [cafwc] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
O4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [DLCICATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCItime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlcimon.exe] "C:\Program Files\Dell AIO Printer 946\dlcimon.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Dell Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE" /s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .UVR: C:\Program Files\Internet Explorer\Plugins\NPUPano.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15030/CTSUEng.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1C11B948-582A-433F-A98D-A8C4D5CC64F2} (20-20 3D Viewer) - http://design-concept.ca/Core/Player/2020PlayerAX_Win32.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/...nst20040510.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1138855071213
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://download.shockwave.com/pub/otoy/OTOYAX.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9FC9C569-BBEE-491A-A57C-A5E3F048DA31} (Setup Object) - http://services.yummy.net/download/Player3...PlayerSetup.CAB
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.shockwave.com/content/heavyweap...aploader_v6.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15030/CTPID.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: CT Device Query service (CTDevice_Srv) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTDevSrv.exe
O23 - Service: dlci_device - - C:\WINDOWS\system32\dlcicoms.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Panda Software Controller - Panda Software International - C:\Program Files\Panda Software\Panda Antivirus 2007\PsCtrls.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Software\Panda Antivirus 2007\pavsrv51.exe
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program Files\Panda Software\Panda Antivirus 2007\psimsvc.exe

--
End of file - 10387 bytes

#6 SifuMike

SifuMike

    malware expert


  • Staff Emeritus
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:01:38 AM

Posted 25 October 2007 - 10:54 AM

Hi mummsie39,

The ComboFix log you posted if from the second run of ComboFix.
Why did you run ComboFix 2 times? :thumbsup:

Please post the results of ComobFix2.txt, as that is results of the first time you ran it.
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#7 mummsie39

mummsie39
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Delta BC
  • Local time:12:38 AM

Posted 25 October 2007 - 11:32 AM

Hi SifuMike

I had stepped away from the computer for a few minutes and my evil teenager took over I couldn't find the log and accidently dowlowded combofix twice sorry about that. I found the log (opps) so here are the results from the first scan:

ComboFix 07-10-23.1 - Owner 2007-10-24 19:00:55.1 - NTFSx86
Script execution time was exceeded on script "C:\ComboFix\osid.vbs".
Script execution was terminated.
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\AlYsSa\Application Data\FunWebProducts
C:\Documents and Settings\AlYsSa\Application Data\FunWebProducts\Data\AlYsSa\avatar.dat
C:\Documents and Settings\AlYsSa\Desktop\internet.lnk
C:\Documents and Settings\army man daniel\Desktop\internet.lnk
C:\Documents and Settings\Owner\Desktop\internet.lnk
C:\Program Files\SoftwareOnline
C:\Program Files\SoftwareOnline\SZVersionChecker.exe
C:\WINDOWS\hosts
C:\WINDOWS\system32\UpMedia

.
((((((((((((((((((((((((( Files Created from 2007-09-25 to 2007-10-25 )))))))))))))))))))))))))))))))
.

2007-10-24 18:58 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-24 17:36 <DIR> d-------- C:\Documents and Settings\army man daniel\Application Data\DellFaxCtr
2007-10-24 06:28 <DIR> d-------- C:\HiJackThis 2
2007-10-24 06:23 <DIR> d-------- C:\New Folder
2007-10-20 16:15 <DIR> d-------- C:\Program Files\Common Files\Insight Software Solutions
2007-10-19 11:13 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Creative
2007-10-14 19:45 318,369 --a------ C:\HiJackThis 2.zip
2007-10-11 14:48 <DIR> d-------- C:\Program Files\iTunes
2007-10-09 13:34 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-10-09 13:34 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
2007-10-09 13:31 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-10-07 22:06 <DIR> d-------- C:\Program Files\Panda Security
2007-10-05 07:49 53,248 --------- C:\WINDOWS\Ctregrun.exe
2007-10-05 07:48 44,032 --a------ C:\WINDOWS\system32\CTSVCCDA.EXE
2007-10-05 07:48 25,088 --------- C:\WINDOWS\system32\CTSVCCTL.EXE
2007-10-05 07:47 <DIR> d-------- C:\Program Files\Creative
2007-09-27 07:02 248 --a------ C:\WINDOWS\system32\PavCPL.dat
2007-09-26 17:42 83,640 --a------ C:\WINDOWS\system32\drivers\pavdrv51.sys
2007-09-26 17:40 <DIR> d-------- C:\WINDOWS\system32\PAV
2007-09-26 17:39 <DIR> d-------- C:\Program Files\Panda Software
2007-09-26 17:39 50,736 --a------ C:\WINDOWS\system32\avldr.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-25 01:15 --------- d-----w C:\Program Files\Dl_cats
2007-10-25 00:36 --------- d-----w C:\Documents and Settings\army man daniel\Application Data\TELUS
2007-10-24 23:03 --------- d-----w C:\Program Files\Lavasoft
2007-10-24 21:35 --------- d-----w C:\Documents and Settings\Owner\Application Data\Lavasoft
2007-10-20 23:15 --------- d-----w C:\Program Files\ShortKeys2
2007-10-16 00:54 --------- d-----w C:\Program Files\MSN Messenger
2007-10-14 19:56 --------- d-----w C:\Program Files\a-squared Free
2007-10-14 18:16 --------- d-----w C:\Program Files\UPHClean
2007-10-14 18:16 --------- d-----w C:\Program Files\Dell Fax Solutions
2007-10-14 18:15 --------- d-----w C:\Program Files\Dell AIO Printer 946
2007-10-14 13:23 --------- d-----w C:\Program Files\Yahoo!
2007-10-14 13:22 --------- d-----w C:\Program Files\Oberon Media
2007-10-11 21:49 --------- d-----w C:\Program Files\iPod
2007-10-05 21:38 --------- d-----w C:\Program Files\Java
2007-10-05 14:46 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-09-29 03:40 --------- d-----w C:\Program Files\TuxPaint
2007-09-26 08:38 --------- d-----w C:\Program Files\QuickTime
2007-09-26 08:23 --------- d-----w C:\Program Files\Common Files\Motive
2007-09-26 06:22 --------- d-----w C:\Program Files\Messenger Plus! Live
2007-09-16 14:11 --------- d-----w C:\Program Files\Apple Software Update
2007-09-08 23:04 --------- d-----w C:\Documents and Settings\Owner\Application Data\IMVU
2007-09-06 23:14 --------- d-----w C:\Documents and Settings\AlYsSa\Application Data\IMVU
2007-08-28 00:13 --------- d-----w C:\Documents and Settings\Owner\Application Data\DellFaxCtr
2007-08-26 16:06 --------- d-----w C:\Program Files\ColorByNumbers
2007-08-17 23:52 424 ----a-w C:\delete.bat
2007-04-12 05:59 374 ----a-w C:\Documents and Settings\Owner\Application Data\internaldb6334.dat
2007-04-12 05:52 18,432 ----a-w C:\Documents and Settings\Owner\Application Data\internaldb41.dat
2007-04-12 05:49 538 ----a-w C:\Documents and Settings\Owner\Application Data\internaldb8467.dat
2007-03-15 17:38 14,729,096 ----a-w C:\Program Files\DivXBundle.exe
2007-02-25 19:58 14,098,984 ----a-w C:\Program Files\tuxpaint-stamps-2006-10-21-win32-installer.exe
2006-09-25 04:03 32 ----a-r C:\Documents and Settings\All Users\hash.dat
2005-12-06 02:28 916,806 ------w C:\Program Files\Dec2005_MDX1_x86.cab
2005-12-06 02:28 86,925 ------w C:\Program Files\Oct2005_xinput_x64.cab
2005-12-06 02:28 46,247 ------w C:\Program Files\Oct2005_xinput_x86.cab
2005-12-06 02:28 41,888 ------w C:\Program Files\dxdllreg_x86.cab
2005-12-06 02:28 3,673,932 ------w C:\Program Files\Dec2005_MDX1_x86_Archive.cab
2005-12-06 02:28 1,358,864 ------w C:\Program Files\Dec2005_d3dx9_28_x64.cab
2005-12-06 02:27 1,080,344 ------w C:\Program Files\Dec2005_d3dx9_28_x86.cab
2005-12-06 02:00 976,020 ------w C:\Program Files\BDAXP.cab
2005-12-06 02:00 81,092 ------w C:\Program Files\dxupdate.cab
2005-12-06 02:00 74,448 ------w C:\Program Files\DSETUP.dll
2005-12-06 02:00 703,080 ------w C:\Program Files\BDA.cab
2005-12-06 02:00 484,560 ------w C:\Program Files\DXSETUP.exe
2005-12-06 02:00 2,247,888 ------w C:\Program Files\dsetup32.dll
2005-12-06 02:00 15,493,481 ------w C:\Program Files\DirectX.cab
2005-12-06 02:00 13,265,040 ------w C:\Program Files\dxnt.cab
2005-12-06 02:00 1,351,430 ------w C:\Program Files\Aug2005_d3dx9_27_x64.cab
2005-12-06 02:00 1,348,242 ------w C:\Program Files\Apr2005_d3dx9_25_x64.cab
2005-12-06 02:00 1,336,890 ------w C:\Program Files\Jun2005_d3dx9_26_x64.cab
2005-12-06 02:00 1,248,387 ------w C:\Program Files\Feb2005_d3dx9_24_x64.cab
2005-12-06 02:00 1,156,363 ------w C:\Program Files\BDANT.cab
2005-12-06 02:00 1,079,850 ------w C:\Program Files\Apr2005_d3dx9_25_x86.cab
2005-12-06 02:00 1,078,532 ------w C:\Program Files\Aug2005_d3dx9_27_x86.cab
2005-12-06 02:00 1,065,813 ------w C:\Program Files\Jun2005_d3dx9_26_x86.cab
2005-12-06 02:00 1,014,113 ------w C:\Program Files\Feb2005_d3dx9_24_x86.cab
2003-08-16 09:04 850,536 ------w C:\Program Files\PJGrid11.ocx
2003-08-16 09:03 318,568 ------w C:\Program Files\PJTextConv11.dll
2003-08-16 09:03 301,672 ------w C:\Program Files\PJRes11C.dll
2003-08-16 09:03 219,752 ------w C:\Program Files\PJUpdate11.ocx
2003-08-16 09:03 219,752 ------w C:\Program Files\PJQuery11.ocx
2003-08-16 09:03 195,176 ------w C:\Program Files\PJOutlook11.ocx
2003-08-16 09:03 174,696 ------w C:\Program Files\PJCalendar11.ocx
2003-08-16 09:02 35,432 ------w C:\Program Files\PJPrint11.dll
2003-08-16 09:02 162,408 ------w C:\Program Files\PJ11ENUC.dll
2003-08-16 09:02 158,312 ------w C:\Program Files\PJOffline11.ocx
2003-08-16 08:45 1,559 ------w C:\Program Files\PJClient11.inf
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Motive SmartBridge"="C:\PROGRA~1\TELUSE~1\SMARTB~1\MotiveSB.exe" [2006-10-19 15:56]
"Ulead AutoDetector"="C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe" [2003-02-27 19:48]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50]
"InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [2004-09-07 08:25]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-12-08 18:35]
"VTTimer"="VTTimer.exe" [2005-05-12 21:57 C:\WINDOWS\system32\VTTimer.exe]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"TEPA.exe"="C:\Program Files\TELUS\eProtect Advisor\TEPA.exe" [2007-03-20 17:48]
"capfaem"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfaem.exe" []
"cafwc"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe" []
"capfasem"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe" []
"capfupgrade"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24]
"DLCICATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCItime.dll" [2006-10-20 15:01]
"dlcimon.exe"="C:\Program Files\Dell AIO Printer 946\dlcimon.exe" [2007-01-12 11:52]
"FaxCenterServer"="C:\Program Files\Dell Fax Solutions\fm3032.exe" [2006-12-07 22:19]
"APVXDWIN"="C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.exe" [2007-07-19 15:23]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 09:24]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr]
avldr.dll 2007-02-15 20:02 50736 C:\WINDOWS\system32\avldr.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^TELUS eCare.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\TELUS eCare.lnk
backup=C:\WINDOWS\pss\TELUS eCare.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\csrss]
"C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EzPrint]
"C:\Program Files\Lexmark 2300 Series\ezprint.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FaxCenterServer]
"C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FLMK08KB]
"C:\Program Files\Muiltmedia keyboard utility\1.1\MMKEYBD.EXE"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FLMOFFICE4DMOUSE]
"C:\Program Files\Browser Mouse\mouse32a.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LXCFCATS]
rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll,_RunDLLEntry@16

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LXCGCATS]
rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxcgmon.exe]
"C:\Program Files\Lexmark 2300 Series\lxcgmon.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MessengerPlus3]
"C:\Program Files\MessengerPlus! 3\MsgPlus.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\My Web Search Bar]
rundll32 C:\PROGRA~1\MYWEBS~1\bar\5.bin\MWSBAR.DLL,S

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
SOUNDMAN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TELUS Security service]
"C:\Program Files\TELUS\TELUS Security service\Freedom.exe"

*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2007-10-18 15:27:21 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
"2007-10-24 08:34:00 C:\WINDOWS\Tasks\Disk Cleanup.job"
- C:\WINDOWS\system32\cleanmgr.exe
.
**************************************************************************

catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-24 19:07:00
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs = ????????????
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCICATS = rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCItime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files ...

**************************************************************************
.
Completion time: 2007-10-24 19:09:14
.
--- E O F ---

#8 SifuMike

SifuMike

    malware expert


  • Staff Emeritus
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:01:38 AM

Posted 25 October 2007 - 01:25 PM

Hi mummsie39,

ComboFix log looks clean but I see some items in your hijackthis log that need cleaning. :thumbsup:

Please follow these steps to update Java

Updating Java:
  • Download the latest version of  Java Runtime Environment (JRE) 6 Update 3.
  • Scroll down to where it says "Java Runtime Environment (JRE) 6 Update 3".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation, Multi-language  jre-6-windows-i586.exe and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
    Examples of older versions in Add or Remove Programs:
    Java 2 Runtime Environment, SE v1.4.2
    J2SE Runtime Environment 5.0
    J2SE Runtime Environment 5.0 Update 6
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u3-windows-i586-p.exe to install the newest version.
Select the following with HijackThis.
With all windows (including this one!) closed (close browser/explorer windows), please select "fix checked"

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (file missing)
(O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab


Reboot your computer, post a new Hijackthis log, and tell me how your computer is running.
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#9 mummsie39

mummsie39
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Delta BC
  • Local time:12:38 AM

Posted 25 October 2007 - 08:36 PM

GRR that didn't go to well earlier after one of the steps I did my java started acting strange it wouldn't work on IE and on Mozila a java box would open so when I did that download you asked to update it did not go on my desktop it downloaded straight to java and in the add/remove programs it is the only java in there. The java did work for playing games but I did notice a window opens up when I play. My machine is still a little slow to load and I got rid of Superantispy cause it was taking to long to load. I have also been having problems with our Windows Live Messenger. I fixed and it was working but as soon as my daughter logged on to her account it stopped working and came up with a different error code that I can't find a fix for. But anyhow here is the log:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:21:20 PM, on 10/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Software\Panda Antivirus 2007\pavsrv51.exe
C:\Program Files\Panda Software\Panda Antivirus 2007\AVENGINE.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Creative\Shared Files\CTDevSrv.exe
C:\WINDOWS\system32\dlcicoms.exe
C:\Program Files\Panda Software\Panda Antivirus 2007\PsCtrls.exe
C:\Program Files\Panda Software\Panda Antivirus 2007\psimsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\TELUSE~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\VTTimer.exe
C:\Program Files\TELUS\eProtect Advisor\TEPA.exe
C:\Program Files\Dell AIO Printer 946\dlcimon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Panda Software\Panda Antivirus 2007\ApvxdWin.exe
C:\Program Files\Panda Software\Panda Antivirus 2007\WebProxy.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\HiJackThis 2\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\en-us\msntb.dll
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\TELUSE~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [Ulead AutoDetector] "C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] "C:\Program Files\Ahead\InCD\InCD.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TEPA.exe] "C:\Program Files\TELUS\eProtect Advisor\TEPA.exe" /AUTORUN
O4 - HKLM\..\Run: [capfaem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfaem.exe
O4 - HKLM\..\Run: [cafwc] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
O4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [DLCICATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCItime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlcimon.exe] "C:\Program Files\Dell AIO Printer 946\dlcimon.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Dell Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE" /s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .UVR: C:\Program Files\Internet Explorer\Plugins\NPUPano.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15030/CTSUEng.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1C11B948-582A-433F-A98D-A8C4D5CC64F2} (20-20 3D Viewer) - http://design-concept.ca/Core/Player/2020PlayerAX_Win32.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/...nst20040510.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1138855071213
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://download.shockwave.com/pub/otoy/OTOYAX.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9FC9C569-BBEE-491A-A57C-A5E3F048DA31} (Setup Object) - http://services.yummy.net/download/Player3...PlayerSetup.CAB
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.shockwave.com/content/heavyweap...aploader_v6.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15030/CTPID.cab
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: CT Device Query service (CTDevice_Srv) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTDevSrv.exe
O23 - Service: dlci_device - - C:\WINDOWS\system32\dlcicoms.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Panda Software Controller - Panda Software International - C:\Program Files\Panda Software\Panda Antivirus 2007\PsCtrls.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Software\Panda Antivirus 2007\pavsrv51.exe
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program Files\Panda Software\Panda Antivirus 2007\psimsvc.exe

--
End of file - 10640 bytes

#10 SifuMike

SifuMike

    malware expert


  • Staff Emeritus
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:01:38 AM

Posted 25 October 2007 - 11:22 PM

Hi mummsie39,


Do you know what this program is?
C:\Program Files\TELUS\eProtect Advisor\TEPA.exe


How much memory do you have on this computer?

Also, how many accounts do you have on this computer?

There may be a problem with one of your other accounts, so that would require a seperate Hijackthis log to see if it is clean.

Lets run one more scanner. This one will take hours to run, so plan for that.

Please perform this online scan: Kaspersky Webscan

Note that you need to run this scan with Internet Explorer for it to work correctly.

If you have any problem running the scan to completion, disable your Antivirus and/or firewall temporarily, just refrain from surfing around while the scan is running and be sure to re-enable when done.

Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the license, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license is accepted, reset to 100%.

1. Read the Requirements and Privacy statement, then select "Accept"
2. A dialogue box will appear asking "Do you want to install this software?" Name: kavwebscan_unicode.cab
NOTE: If you are running XP SP2, you may need to click on the Information Bar to allow the ActiveX to install and may need to repeat step 1.
3. Select "Install" to download the ActiveX controls that allows Kaspersky to run.
4. If running MSAS beta you may receive an alert that an IE ActiveX program requires your approval. Click "Allow"
5. Wait for the scanner to initialize and update its databases. When the download is complete it will say ready, click "Next"
6. Click "Scan Settings" and check the option to use the EXTENDED DATABASE, then click "OK"
7. Select a target to scan: Click on "My Computer" and the scan will begin.
8. When the scan is complete choose save the results by clicking "Save Report As HTML" Give the Report a name and save it to your desktop.
If you have any problem saving the report, copy its text to the clipboard, then paste it into an empty Notepad and save it to your desktop.
9. Post the Kaspersky scan results in your next reply.

Edited by SifuMike, 25 October 2007 - 11:24 PM.

If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#11 mummsie39

mummsie39
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Delta BC
  • Local time:12:38 AM

Posted 26 October 2007 - 01:52 PM

Hi SifuMike,
You sure weren't kidding about the scan taking a long time. I have posted the results below:
As for this:C:\Program Files\TELUS\eProtect Advisor\TEPA.exe
I am not 100% sure but I beleive it is some sort of alert that is provided by my Internet provider It very rarely alerts me to anything can't even think of the last time it poped up.
I have a very small memory I beleive it is 1.81GHZ 192MB RAM I plan on upgrading it very soon.
There were four accounts but we have since deleted two leaving two. Also the Java doesn't work for my games anymore on either browser on IE I get a message that Java is found not working and on Mozilla I get as far as the games main page the Java console opens and then closes Mozilla.








KASPERSKY ONLINE SCANNER REPORT
Friday, October 26, 2007 11:39:44 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 26/10/2007
Kaspersky Anti-Virus database records: 446581
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
C:\
D:\
F:\
G:\
H:\
I:\
Scan Statistics
Total number of scanned objects 118096
Number of viruses found 9
Number of infected objects 17
Number of suspicious objects 0
Duration of the scan process 03:16:09

Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\DSS\MachineKeys\4206e00ba6a80722ecd036032a758fd2_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\DSS\MachineKeys\8926cd4be3bd99a6b1fa488ee44d57c9_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0064cd2206ffc6e8d9784c94e750c53c_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\01051408cbad5546643a6d868f5c7d06_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\01b15416eb5969a0be3d410fa0dc50fc_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\03221fc1bb356edbddef7ce5e6b75f87_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\03640028a00b4e7fe745d493a2de418b_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0382b8bedb8786256c98e8dad81c8922_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\04ee9cfafc6b96389a79b09d8d5e8693_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\04fe68af1c1e579cd0ce21a62e85ff60_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\05456ae281544a5814c49468591ba993_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\06ad4c4d7590225ad22f31ee72c8facd_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0a2ba302358681abbccce5401dc45617_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0a2e7f49094997adebae4f7c41f3c7a8_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0b00fbd7c685c5a53d9ae60b5d6bd79f_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0bba85f754cd1fcb7e0d04ba461736e7_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0c532469638fc90c297b81e0650ae437_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0d5c8c1fa07e163ddb4f562735e50a1c_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0d75cdba10be9245e6289191329354a6_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0dc278c42c3be05e75dca0ddfe7a4bdc_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0e48d8994d1b07952e700996f7107a08_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0e5eb15dc06e2886017fce6a98bc61ba_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0e95bbb4432a63dca061d9ad7018a6a7_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0eb46ff8369c42a2bbf216a70c661887_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0f30677d1aaf8ed56751176aa93e4871_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0f6434ac02fe3495b3320d8631ed2826_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0f7f2c335b00ba94608edad1a7552de4_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0f961764a889f30925745a678b69f771_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\104441ba86b0f9905c9bc70daf084852_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\112d2f28aaa2525a7da1bbbc3f39b372_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\116d9c766004f424b84a65cd61ac13cf_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\117482d2840b3fcd352a3556755c35a7_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\117e5b7f26563fb6436d7fa6d65add82_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\121b64fec640755af13d5618b10a79bb_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\133d7855a0e2aef54d61ca473103aa84_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\13457bb584e0cf50e4686f1af99a37a7_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\13e7a52d08c409591da907e10d784f17_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\140ad647ee63015fbb6ef2820ffe7e27_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\148d30bdbcae00f9bbe5ea8203b986bb_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\149af92cf12cd2826ba1a97be5cf3f70_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\15a9df47240dcfd827445202367cf1cc_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\15f9329cc1ddd75ce51bbddfb9eb7403_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\15fb8753dfbeb39d869245edaff5492e_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\16511b52b5b2cdfda86a780fdb073091_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1667b622cdfcaff2585091dcfb0cc03d_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\17586452afbe911244ed32ee1cbbb0e5_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\18a1b91369960faf9551aa5ec180155d_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1936c4a8a62e2dd4328ad8966f9e1e20_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1bfdeae1f2ecf1ec725f44bdd6f1ea1e_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1c3583b07fb50873575d8b31e2f5abd3_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1d5e491159484a1e4e12eea8700386fd_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1d8248001cff97c317f72774e75b6a7e_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1da47ada96d88cddcbd555af899bb359_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1e078313bebab597e86ca8404a0a7266_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1ec5132f656017f92189002d6e74afef_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1f579e7c6e599f2bd235e98664a8f963_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2074cd633f8aee201d1001f6bffe3e39_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\20d66847a14ad1e65fed271284792abe_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\21129ee46f2e298fe2816d8469379f34_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\219610a6c19d5481f5652764257ced64_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\220b294fae2ea7306e167b9e9bc10e01_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\22e488d0cf8d858f57bad87be191106c_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2357e1732027a6377b89115372aa73ae_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\236e544ddf8c9cbb5b3efc9af66d7fe0_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\24b517d818b04651295b3a31e3574111_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\24d4b9a672e5f12eaf211c6f139595c6_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\25d122eba6e6cfebf007b4e49831565a_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\26563dafd7601cce686a54407c76f028_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\268207e9d9794da47b9bcf5fea666b6c_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\26f0d4f8173a05c82ed8a10eef35e987_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\270294b832560e48d08d90cdb5cabf04_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\27b265bbc81598fcdc8d2938ffb1f7dc_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\28e38b65556392ae08a3d60b613a6267_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\290307f0c8c70d7a912e9e3007add347_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2a45773535a00a3ae8273f850c5bfb74_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2a4b130a482ffb062272381770171151_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2abb0a1a061215a1421f1cf797598b1a_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2aff0d5b910041039acf159c50741d7e_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2b687f08499e4f397baa6bdf1cf2cbae_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2bb172147f759a0b512ac95fedaa94d0_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2c042a5369d87be9a844f5d2906e74e0_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2c68444e0901d921c0c76d928e160f99_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2c9dcd5f28995e5546a8ee29dde4c7bf_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2cbd9c9cdb89514902906064473b8b5a_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2dcf4859c6a38ff3e01633d78a297168_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2e065c177911b56dce0abc9de5f59b25_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2e3048699083250a11f08c786fe76777_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2e61b151c5642012335e9f264543f9b1_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2f0f3f8d95ac990b696623cbbf8dbb99_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2f52be698fcd27ca28b2e13c91d8c8f7_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3084898bc3108669385a49374af118b1_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\30e6301cb13a1379207fc487d70f3cf8_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\30e818fa821bb292c335f2627bc18632_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\30eeecfcbea108aa7ae2f215f728e30c_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\316bffad5a0f7c3b3cb4245c12b73e11_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3260e7a3e26c55062d4cc99f79dec155_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\339fbac8da2ffafa2bec7ca9a5f6ccbb_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\33af28e0c2c60576fcf2996340781540_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\33ba5da382ad6cab26257df6524e12fa_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\34164460cb451c057acecf61c52ff8ee_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\346f8c60719b18864cfc7378d27de627_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\34913510d4e146964244037b2874c168_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\355531bf132feacefda2aa404899ff8e_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\358d01b77a804c4f5ff44cafe14f8adc_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\360569407543689b47f89503024d6194_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\36312d1fca8e62a66a0029ef9255fce0_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\363c36c4e3fe24c5656e8b9505459a8b_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\36ad5e343dc3f18829ffbe8c4b64d925_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\36aebb0314f01c51ccc42b9c461f7d5a_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\378ab726ee85e77ad2dd4f08926215c5_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\378f8b6179bdd397b4d475b1ea02ab51_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\37cb2f07dcbd433062ec0477b0afde07_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\37d0f1813fa9ca141e20bbbb459770dd_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\37d6d898de56cb68c84ea6ef860388a5_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\384c44dab241ccd9d1db491f40cf8d41_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3861c32627775be4c2c621eabe7d880a_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\388c0f43d1dbc1b0f073da950debf759_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\390b87c29b5f805a62002dfaabaca984_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\39218f2c04cd8599d258c6456f5ee796_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\396858761906e84966fba14fd6bf726d_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3993c25a9220be3c6a3c3e8bb572de1b_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3ae05e525b42eb2703501dca178187d8_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3be2502cfbdbd244a60358ae104527c7_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3bf1b5839d97a797bb739168018a689e_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3c3b42e76eb2cae665f72ff8a0655a48_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3d159442e37bb54c1eafa42069a1f1de_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3e01f5a5238f7e43b8666b9153866e90_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3e09ccf97a8703e88f26e0d062982622_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3edb0192e11728206ae0c11dbee66ec1_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3f0ec27e931865b82614d8f9bebe4ae5_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3f8ff87d14bfa44a01f97308f619815d_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3f9d4386ebb8180c4274e0d0f2d47c3c_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3fa4e22a8905373b727b91ae1dfa27ca_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3fe5caff48c36795f55f2c406a0ab342_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3fec1ed66e687a3c1d08445afd43f3d1_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3ff224d3a1f52f9a1bfd1a3162e12dfc_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4080ed7ad8cbae63b8794dfeef1bd322_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\419faa683fd216d1c11becb7eeb72a1f_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4259a6776d67053285febf02f02fa89c_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\42b7b002edc6a7033f9724da53052bd0_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\44eb129fe5f188629c6abc312597cedd_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\44ff3d39d6131ed238123de7709bab8a_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\450d6d870579fb3bc088c91cf2d05ddd_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4545c3de2ba574da72fe424fd3f85cf4_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\457135d6f755a80c6e17058dca64e68c_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\457d7184ad23be744f3598302447d018_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\45930e238df8453bc994dcdb2a9276f7_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\45be7f9eaf2bf547807d57451d097b7c_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\45f42ff2223ee6ed0b4603b2ca2fe93d_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\46480a0ab2f89da1d17ddb0fb395dcd2_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\467914ad2d61b234bb271b5660e78bed_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\470d27ff3cfbe2356b237e075c525574_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\47c80e630259dba469e1988ed60e125f_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4841cb554b3e649822e4d5b77faf4eb1_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\489ad8673292066b364076dfcb76a3d6_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\48a6c7648c3b48a5e0a4bf1490296d10_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\491a960f7badb12a894ec7056b464e18_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\492dc41d7d1cbb4a102616f6d2610791_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4994b9d324b9708f0cc927fb92f8712b_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4a37fd033dc664ecd4fcdde914dd0881_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4a47155e10d03b51b0dd2da8d378e89d_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4ac5a0122cedc184e1badbdf3481da5d_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4af51f64f7d5947b9a3f36a8df6a6bae_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4b76bfd3756852c5d4a74f8bd8d62610_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4bf10dee34f93310b445f6ebf98005a0_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4c662a7c95679f0262ad97c86ac2f62f_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4c9fbedbc5ee9e1be5754cf87bb7a7a6_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4cb3b90be4506ec57541e56a1092add0_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4d7f9cf1142932eaa70a6e72c2c5f444_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4db29fabf8c3990253818546b85f2729_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4dc317628d7887138df578ebb4405fd9_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4df7800f23f62a742999a0929a132965_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4ef64a55477c0e3d32ab56d3cc70b043_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4eff19d112d0547d2bac9803768cf960_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4f8c80c16252f3b0c4dbf5d7c4ce4c79_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4fb07927224e9171878775c637eb6be3_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\500c639e4bd413496b09f1b5a5818185_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\51dd6627eb059323cb319b3df513db1a_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\52935c8f64a422e4784bebecd3856923_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\52bcee15019d5e79f81e826dc540bc07_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5395919091572ff40b02e9d94c0a2150_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\53d07d83faae76dfbf0b871f98ea230e_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\53d9bee8530a88d6e8841dfc24884e33_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\542170b4ef54d3166487a257e7f7f920_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5481ae7589857b540c125b41e5d65b6b_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\557065d80d16de7c06a1e3be680c4861_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\56511056a66b0461dbabea04ef3ec125_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5705d2a77dc98888656799239986a6c0_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5749ac6f47d2e7f6881217ae90dbb4cd_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\58085fbd85ac1d5165744351e67da0ce_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\59132c63e540d7bbaf727d78b632079e_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\59376c263628a4536423f9f614f0565f_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\59527e8015edd0b343aa688623e95163_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\599284988aeec146f8e8e123c3d83c37_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5a52e67d6fc52cf2ecb886cf9266e4b7_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5a8d1d8308b23045532c770fc593770d_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5ad15979801ef70281a2622bc01c5453_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5ada06fdeced6bbb18f366fe460282b6_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5b79bcc5222f0ea49974848ad4b05348_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5c27282c6d680a327ab34e3aeeacb230_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5cafd001c2f25209ac69abdd7ce71a75_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5cbdec61545fabe1a62e123260357861_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5d2c4975f073b17c5af47a71e7766774_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5e7270611bf436da057539aa15517526_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5e83d4ab1e786dcae4d5ed72040ce194_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5f967c09de1927f70a586709904829c6_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\60024683f6e98654785bf90e9403c7a7_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\60485291e0796ef7cef58efc7d70fd0d_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6196d78d59233cc7f37826af62a19982_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\61c9088f8c689f9ea3e03b73d47de35f_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\61eabffa19d2a5ebda10eaea9eef7f69_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\624800a2dab78d059ab88ae71e806f36_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\628930dd9b466385b81862c313dce195_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\62b0bee73545474402f435119fa7b929_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\62e7a55245a6c6726424ef4b21dba4b0_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6327d249e4c96ebb4994ab252318ccde_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\63cf742879052b1ce8d13450693883eb_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6428d3f6ae36e0d3068d3c6621c7442d_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\649413f1ff9fcbc7598531d8e87e3445_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6522442d1c1ad611b1b7ffde68fd1218_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\655c7440b41ac5d7baaf509f8712ca94_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\65d036364fcefc3c463518a4512eddd6_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\66a72ea02cbea4a371a2cfbc941fae24_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\677ff273dcdf1a847815b7e47e6a8084_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\67ff9aa7baf523bec39ba4a68dbc6f3f_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6801e26c3d6f6ec52049ab19a1340472_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\689849b1e43624432d3b87362c763005_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\68d5c4842a3845151901a8618d3c738e_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\68eca8ce44a60916f1fc6bac4f6056f4_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\69d9b6a754ee20e9b0c22bd3e09a5c21_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6a5e09692d08b0453038aaeb84b52c16_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6ab3104c2987b5602fd74c21d932d4af_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6ae21d8e6fb563c45e4f3637f786e596_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6bb0b06c3864c3784d1903feae21fc43_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6c03eaa6b3073c7b5c36e981929e66ab_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6c9502326212c3cc88b71c0f4b9a9769_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6cc81741e8e6b730b686ff91373203f7_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6d616ec2b8144f7f26273c6d261189bd_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6e3307bc3068083c786edd479b7aba25_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6ed7a26bda0e9a9528b88808792c0df4_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6f34e12c8a63cc3fe9bcc8e30bb9fc4a_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6f72532ec7d83e49321ba432a8a023d5_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6ffa058b5f05d76cda7af85a56f073d6_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\70300a012aa766017ec4b8c5d7fcbe91_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7045cf022f7d9aa36163de0553d52169_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\707191ee3281d954b08dfee41d63e25a_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\71b48183ce237ca26326907e64146907_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\71fef123b8267f765f9e1af7712e4379_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7237a4c6ebfeb09d4643705c5037ceef_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\72667cf3f694f667d8b54f82dfa1eaac_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\72dfb985c7fc13f8716845a15414e7e9_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\73b33acfe1fde5e03ad4092b6da76469_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\745f499f3a94399f2e83ca53053cc14e_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\749b6331e8efb5ac2f4874ccee0727c4_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\74d86a33dd410e55deb397506057e5e2_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\753fd1fe436ead4e45a7669b8ae7ca1d_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\75510903ebb3fe5e94a41306132f171f_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7604d8279ed66f463c68a2f2ef613a04_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\764d30415194f94e3e1156cf92fbf817_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\76c5ae9d5ed51873a56632be8e9c48dd_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\76ea28daf2472abf327527f2da1f17b1_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\773c7d7dd700759036ea57fd20955d8a_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\775d81436fbf321e1f70d1bdc4d83636_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7b7d9cbd228d23c6334842fa4b60b453_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7bfc8ab36d27a0d92827701a76a02033_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7c3bb48b1c129a41e1571488353b265b_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7c6d3ca4b13d89372adb03f2ab320c3c_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7cd5c14d7c281aa16eddb056cbc2ee9f_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7e97ac8ceee55fd711a50aaa29806313_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7f258e72df553dc58a479ac46f57ad9d_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\81776992bae9fcc40731a31d1b7c7bb8_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8189140b145602fa232586b3a9438b9f_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8189621b8db8b3c12879a2ea30e18eed_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\81f8ce557135e414f0a516f453193e49_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\83531b42025f202b00b7388e6752ab43_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\836b734792861d3d89818c7ab16ae9e2_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\839049d72f6a79a4120510fae2049b0f_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\845fc12d5eb17da5c5e61a1b322a6e2b_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\86022824227bcf63da5c846af79858da_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\86b70fd44eaea4d95239d59e7a8272b0_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\873aa24c16b83ac06d345b2a6605cb54_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8790d6b37e936a5c4b80a03db9aac342_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\87eacd6e659937191148b1ae8026b005_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\890817a0a83b31caf4a0e6264cbf5c56_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8917cae7c7f3d9e67052194f87277539_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\89854484f576cf630f0dcac54e2d8ad3_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8986de08d17ec67ad5c67694cdedaf14_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\899616399fd46ee35077bccd35b22c86_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\89c00abbfb12b1f8d15b743cbd1f946b_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\89fa887b751250f421bdd764e9559cd2_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8a61b0e288e546895803ac8cd4b17561_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8a91febb2a146b41e4139358ad2a555a_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8b84dfbadee4be6d6e7dfb70b57e6476_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8bb66e127a1b661379c75929e1378391_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8be7fee7e8179cff8c2c1ff1a1f7c622_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8c191880ea70db23ca7f76aa9b32700d_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8c7a4d4db99d3b3caf024122d315c69b_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8d1d45edeca2db023651889aefbb10ff_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8db993ff759d6d72af8228f3d5f7ce48_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8dc4a61fb4bad45a605bb0c056b1b164_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8e0ee97740aef58bc234d3faaeadea7d_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8ef0fabd38359eacbffd6fa651862638_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8f6ec4139b98a9c71a6ee6e92b06ed3c_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\909b0bd9d81819e34912e06316669f3f_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\916649f2e930a721fbdac6477802af2e_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\927d77ba54b025133c8da97ce66badb4_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\935fc95b022b01967605977a0400452f_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\938152f7c4de2baededfbf8ec0567af1_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\93ef1098dfe184cfc5977afb8cf1e244_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9432e7222bb4fe90b9410a76c5900d65_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\94a2a3f2e5caccbfd055f5e305e94b9d_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\94db11f467fc23b48f79091faf849374_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\94e3be38c6276ffec7a05b138fcda59f_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\954430af900a178d5529231c26bd2daf_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\96e4009707b191feb2799019c7a6ba9e_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\990f1ee4af13241208ea46fc92bb520f_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\99bf86366323c4ae4e5800a5ad434498_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9aa77f9f1fbcc8e3399a751015b69812_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9af70645122efbc161d4a8b458ba499a_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9b0fa34931ca6d2b69d636b44c4c4f6d_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9d4b51cd12eb28ae67ccb773049f69e0_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9dd5576a8596a3d9fe73d78e98d4c6f6_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9e39fefbe10aae109aa736024313905f_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9e7247d9f8adf734ef9409cffb205ea8_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a0753ade6e4429b3148dbc53074066b4_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a08a7482a2ed91e8580485256e6030f1_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a0b6c8ee842494072fbd8548b545b848_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a11559bbc80ab0fd09620105b248f981_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a167a15faefa7d4948f149f2ebaea515_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a25820c447e3865690adea328b88d6c8_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a28491d1c2d499170b3c3d1a2c15bdc9_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a2bf2477874099333619b6a19cc0a2d2_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a37d0984e3f85c0cd703303c19b821e1_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a437ff50454010ee39ac174061341489_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a4ba4ad6ea338ded019bb682e6991fde_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a5af1cf8597bd8ea9827e5c522d5734e_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a5d0b7897dcb46fb88519602217f1a3d_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a67c5129bbb739c7c63593e96fe68a9a_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a69173dfbb24ae6210d7cafa2d424616_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a6d032535d3b465e60df36de55c13623_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a7e8d30488f48c10d5894492933961dc_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a8bf92115b468db9d6313c9d59438ea8_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a931de178afcd94fa3e80ae364a691fd_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a94277ff5947976a0b2d16caaabf9a85_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a99690eeffd38b65c965ae245e6a5244_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a9c6ac84541dd186b09719c93b983c92_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\aac934194a67272c8beb6a936a8936b5_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ab83fbd821726fb3fccb7c7fa44f9f06_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ad0339566c707207e32c38f05d26f40d_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ad7512c2d210a87a086e8ff6ca76fca5_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\adbf4fab0f3c26cc844d998cbdaf8314_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\adfbc41c037db393500d817e398f59d1_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\af3e46e9164488bcbd239c139950af9e_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\afc8935f5210aaf82914275373af7a75_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b03ca51ec4ecd20fecb62722f21de614_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b076c44a4ca5c937b45cdfe6cce0630a_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b091c12d985b31fc3ce081fe910bd1e6_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b0b9bedc9c1e7c491a1b5a4adfe7dcd0_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b1ba2234f0506cdf668e28b89acf9ac1_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b2871a7208ae8de3683b0a49669e60d8_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b2ce1176fdcd5afc4c496548a229b080_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b2d11a5ffa8833c1321d3f860ec73a63_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b2f4a0ba34d992dbe4cf6438eea6a176_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b382e7b9b39ce5548218bdceee3cf535_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b38bb5842ca5d3d4f4580a9824d05788_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b3f1f246dfe7862ef3bc687fe8a41a04_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b3f3fb0355174f6f45dabc5d59f6e86f_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b46d78a011fbf7270314671d189d44dc_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b4be9cd76b3ee3459a69d95728507be6_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b5270df57e37b9eaa7f5e0a0749a6de2_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b6629ac42f28a26cf623602ee2a4d4b5_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b7352ef27ad19808ad90f354a987c72f_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b84afcbbca0dea2281ebd942838813f0_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b8afbbbbdef84109244c12f8f49fb257_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b9e8dc75fcef62c2fd9e1b373255fb50_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\baa6e79a57c5766c9100b1112072df25_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\babf07ffdd01d4e6f726f252a72dfd9e_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\baf52ebf949caa3ad28110adc1e14038_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bd39bc6a3d8926da578f03a748c27cb8_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bd492898fb6c95d2736a65a5c096187b_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\be68359f1605086c142a8414cb636302_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\be88551648252c829b8a4d6e32c1cebb_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\be8fc4397b024b5a0f1edccbb059dce6_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bea29e8ed7ead3d39d59c251d44a6c46_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bedbd90ec2f9c194035c662e195771c0_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bf9ea3b460c904849aaeded23e0f1e2f_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bfcf9884d5743ba1ccba3917bdf53754_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c03fa7f883ebef8c277855d0a397b720_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c06d01900fb0de3f170a304f889556ee_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c071ddb74f624b5c80d0ce031a7ce33b_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c0ed3c42f9b280e735f539f350765bea_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c175659a91992203b54e3df7fc9e060a_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c1d2e23be5f98bd04ccc3a80cbe65cf3_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c23ee48c77794bab6ebfbeaa5c9c8072_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c32eb2f283fbd9af1302ddb1a00e686c_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c3cf85f3101a303c08cf84f442419c6f_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c44957161d61870029c6e39527aa7933_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c48b5d00a96c5a67f87919696a786986_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c4a996d1b6f1b7a38d35b74fc3998cb6_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c52ae3177e19fbe92bd70de6587f9bd6_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c5d14682e83119da6c8d0595e380c9f2_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c60d3fe0ebbc0927c821a5032bd6efe7_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c631ce10d36c17179b73362b69d2c71c_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c66f639e1accf3a0abb35e58a55c2714_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c68082b870201b21358bbb1076261f94_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c6c196770b9247c46bc3b1978374b9bc_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c6d0b578f6e15db66ec718e9c7dfc713_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c71962f73f4e3867604b3c9bd3d6ae4b_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c731fca43f333b88278c0e8b8d85f144_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c852df0c0d01ed2e05200f289d309296_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c8644ad9658988a9381c4d57a250b49c_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c8b923fbf9ab2ee040d3507ceda42180_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c8df484afde97bd0857778b45b208912_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c964c700aba901f232b3daac88ec8471_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cb4a75739f397aa8bfb930316d9953d0_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ccb21d3d67fdbf769e98113307d0a47e_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cd03faf37e3f5d96fcda9fa5334d458b_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ce0a4a88654c2140caeb8118aa5a4d2c_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ce9c6fe279a83df68f0e3ee82b28d376_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ceb6b1f33e4234c160d921de049c463c_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cebd6052e012423f807e8b6d5000db39_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cedf04e62e4889ea58382b2bd8e3faa5_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cfbb9b95dfd6a772a242c060127d609c_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cff3cf6b91d7533cb7629363a542082d_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d0e4a7cb43fade438014c96918750444_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d149c3b1ce8d70de486be63682adcc38_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d1cb21d7c903a018dbf7a43d511b9781_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d1d5e37cc252018eb78d13c28a6df3ae_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d2db9885cbe5c9a23e2e03034d938193_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d338c0a801f69d3e7e2bee7945f31690_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d34a51ad2d47de85b08588d1dc862007_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d3659108cbd37c58067d993a5d2e0d86_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d444d6e54b798d4782f60a070f985a7a_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d4546320f0fb53725b79738960a6a9e6_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d4f180e3276ba16d020c4013fd316af6_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d57fe6bca3affeed3bb1dea8546f1650_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d59bc920091d94a6abcc8cb436bb51bb_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d5a40941be807e694b7de3789d524bbe_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d6734cd06b715aff65c0f90f48d9b357_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d6b20741f0f43836b13355c2505b871f_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d6f941db605bbc3cb1c738bec97dbb0e_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d7163e014af81f45032a97335e72d8c3_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d723e05af0f371c69b9afea7f960d96e_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d77c2ced4d40ec5d82598743323f1cc6_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d78703e95c985be492670cababced417_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d9304cb34ca1494fa75b2b7139015987_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d9e2779085ba18a8af9bd63eb5597fac_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dab1bc4057cb8ba01fe8c87b0545e3d0_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dacfb458f3f13a8cc1c58cfb16f1a9a3_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\db5aa7f34d54fdf59899a0940cdf1e13_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dbc8ff4face7facb92047f770a54d688_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dc592d4672f6ae7efd417cbc6654277f_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dc8b4193786e71b1593b7aa6047f88c5_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dd653c54e53095ad60140ab64dcbd065_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dd7abf088b19aead436d18e3614ce861_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dece048e4722bf46f6e174d3b6a752ba_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\df0eff8f16ee90de70a1aa60c8721f5b_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e0400f390a052468cb6a01db30ae950c_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e0bc1f461c9c32e79e07a644e758ce11_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e17fd468810bc6f38c66193f94fb6843_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e1d4340bb36ce72d76bf7531c49b3632_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e1e8a9cca85b798ae3f05d58345b8ab6_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e212dae135aa3f9565305d68503aa6c7_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e2bedda94e4d66faf71f3f57e7ae50dc_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e32a2cea6a9cccf3ca5f0dac3acf1689_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e36b7f32d633382b3a4c5cd82187ed15_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e3763fe10c8348c338f5ba9e6850e1e7_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e406734781daf7180dbb3bb9de777295_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e52efd1b3d251b55523e8ba6c4fb525c_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e5f3d54531d6d9857507e242c4cbfbe7_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e61922b285c78e9aa6e8ec38d2b3f290_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e6766b3aac929de3b5cdac70a56bb85f_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e7008523623effd4ecc3cfd535742e29_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e84c743b7181698f83df2b03175516d2_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e87cbeb548b3a2f74ceb064a72d0322a_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e924382f4e395035916d0c51bbab6265_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e9ee4ec46ebb9a8e8f08f325e7a03206_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ea0488390eadc183c91d92f9d5bbc6d3_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ea0ea6692a1f458902216185d7ea603b_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ea89dc81cfc4dccb48d780ec5a1e4714_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ea9f7764682dc6f4a57533989fbfe06d_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\eb05acf3976836ce5df0eb0f4b95b6a7_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ec6b4557b3763339b77535a11649f3a6_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ed6608f0fc17d1b1c083234b6578a95e_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ed77a78f240a90dd919209c883007b2e_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ef960b2e9f242d3b4b20d888fb2a09ca_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f1b20f56386639f86ea3ed8260d1d576_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f1cf626bd325a1da14cc356ec769e4de_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f21216f674e0fb762194da38ef2e1ca1_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f243c4c3f4157561868e47fd9f6ef71a_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f2f7ddb5591d6ec4c4e4b3f5363ccb9c_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f372e2cf16e2c33f86300729b29cbb5d_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f3931df0578be30884ae7fa93ba17ea7_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f3cf8199471d9a6131e9d38d36bd153a_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f5113e9db9fa4dd6f8dbc8f241b5a6e1_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f5247ec3420fb37740370162430667e9_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f60be97b3f9aee7874e0c02ccd358aab_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f628a0ad14ec1146b2dea31908fff9d8_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f62d755fc081bf5b0f2965aea10332ec_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f6dcd23d57e428d90c27424fc9bf622f_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f713be3a96b96c30e70a2be2273841ac_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f79e2ccf781d3895f1280f0c96ba3bce_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f8b74919a14ebab018220344c3dd5bce_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f8bf334b4cfad7aee5207ee94509fb96_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f8d469587d3d94da446a8a40ce94d04a_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f9f08a63b3441d073930cfc5b5ca1dcf_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fa4e7db0c1726baafacacb230da66d65_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fa8e1340200052877f70d2cc54119d37_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\faaa0b5c6c3a396e01ed0d59eb1931c8_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fab1ce8af13d36c90d135a397a4df50c_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fb505475b7f32c5216956d4583897e2a_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fbff3b96fced73168c5aff5d108a1f79_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fc7539cbb92862906dfdfde7e6ac182c_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fcb58dc5beaf104f1a1a530696f39947_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fcd9a7b74765451ecf8952c16beb4bfe_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fdd56df5d93e899eb7aafe0ef2b25586_a63f4c78-ad07-4aea-b3e2-1b6e00760530 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\sentinel\2.1\gwhashs.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\F3BROVLY.DLL.bac_a03076 Infected: not-a-virus:AdTool.Win32.MyWebSearch.at skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\F3HISTSW.DLL.bac_a03076 Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\F3HTMLMU.DLL.bac_a03076 Infected: not-a-virus:AdTool.Win32.MyWebSearch.l skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\F3HTTPCT.DLL.bac_a03076 Infected: not-a-virus:AdTool.Win32.MyWebSearch.af skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\F3PSSAVR.SCR.bac_a03076 Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\F3RESTUB.DLL.bac_a03076 Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\F3SCHMON.EXE.bac_a03076 Infected: not-a-virus:AdTool.Win32.MyWebSearch.a skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\F3WPHOOK.DLL.bac_a03076 Infected: not-a-virus:AdTool.Win32.MyWebSearch.bh skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\M3IDLE.DLL.bac_a03076 Infected: not-a-virus:AdTool.Win32.MyWebSearch.ax skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\M3MSG.DLL.bac_a03076 Infected: not-a-virus:AdTool.Win32.MyWebSearch.at skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\M3OUTLCN.DLL.bac_a03076 Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\MWSOEMON.EXE.bac_a03076 Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\MWSOESTB.DLL.bac_a03076 Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\riched20.dll.bac_a03076 Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WinNB58.dll.bac_a03076 Infected: not-a-virus:AdWare.Win32.Mirar.a skipped
C:\Documents and Settings\Owner\Application Data\TELUS\eProtect Advisor\client_gateway.log Object is locked skipped
C:\Documents and Settings\Owner\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\by5y4t71.Default User\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\by5y4t71.Default User\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\by5y4t71.Default User\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\by5y4t71.Default User\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\History\History.IE5\MSHist012007102620071027\index.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Owner\ntuser.dat Object is locked skipped
C:\Documents and Settings\Owner\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Panda Software\Panda Antivirus 2007\cace2423dfb97c58fe7dd9f120557063PSK_NAMES Object is locked skipped
C:\Program Files\Panda Software\Panda Antivirus 2007\cace2423dfb97c58fe7dd9f120557063PSK_NAMES2 Object is locked skipped
C:\Program Files\TELUS eCare\SmartBridge\AlertFilter.log Object is locked skipped
C:\Program Files\TELUS eCare\SmartBridge\log\httpclient.log Object is locked skipped
C:\Program Files\TELUS eCare\SmartBridge\SmartBridge.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{C39EB662-9398-4523-B9ED-4E390A792B3A}\RP556\A0103261.exe/data0001.bin Infected: not-a-virus:Client-IRC.Win32.mIRC.617 skipped
C:\System Volume Information\_restore{C39EB662-9398-4523-B9ED-4E390A792B3A}\RP556\A0103261.exe mIRC: infected - 1 skipped
C:\System Volume Information\_restore{C39EB662-9398-4523-B9ED-4E390A792B3A}\RP599\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb Object is locked skipped
C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log Object is locked skipped
C:\WINDOWS\SoftwareDistribution\DataStore\Logs\tmp.edb Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{37DB3035-D8A2-4483-BC46-582F3B8F3B94}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb Object is locked skipped
C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.

#12 SifuMike

SifuMike

    malware expert


  • Staff Emeritus
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:01:38 AM

Posted 26 October 2007 - 02:35 PM

Hi mummsie39,


The Kaspersky scan looks clean. Everything it found was in your System Restore folder or in your housecall quarentined folder, so nothing to worry about. :thumbsup:

We will be reseting the System Restore folder shortly and that will clean it.

I have a very small memory I beleive it is 1.81GHZ 192MB RAM I plan on upgrading it very soon

.

You need at least 512 MB of memory for Windows XP. RAM is the cheapest way to improve the speed. If you decide to upgrade to Vista, then you will far more memory.

There were four accounts but we have since deleted two leaving two. Also the Java doesn't work for my games anymore on either browser on IE I get a message that Java is found not working and on Mozilla I get as far as the games main page the Java console opens and then closes Mozilla.


Go to Test Your ActiveX Installation
http://pcpitstop.com/testax.asp

What does the Java error message say?

I would uninstall you Java and download and install it again. I am thinking it is not installing completely or you Activex is not set properly.

Did you uninstall all the old Java on your computer?



Uninstall ComboFix, go to to Start > Run & type in ComboFix /u
Make sure there's a space between Combofix and /
Then hit enter.

This will uninstall Combofix, delete its related folders and files, reset your clock settings, hide file extensions, hide the system/hidden files and resets System Restore again.

Please read and follow How did I get infected?, With steps so it does not happen again!
as well as
How to prevent Malware' by miekiemoes


If you want to improve speed/system performance after malware removal, take a look here.
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#13 SifuMike

SifuMike

    malware expert


  • Staff Emeritus
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:01:38 AM

Posted 01 November 2007 - 11:22 PM

Since your problem appears to be resolved, this thread will now be closed. If you need this topic reopened, please contact me or a member of the HJT Team and we will reopen it for you. Include the address of this thread in your request. If you should have a new issue, please start a new topic. This applies only to the original topic starter. Everyone else please begin a New Topic.
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users