Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected with: Sorry, we couldn't find http://ad.yieldmanager.com/st%3Fad_type. Here are some related websites:


  • This topic is locked This topic is locked
35 replies to this topic

#1 mrboyertown

mrboyertown

  • Members
  • 36 posts
  • OFFLINE
  •  
  • Local time:10:48 AM

Posted 30 March 2009 - 07:06 PM

When I am on the iternet I get this message when i am on yahoo or walmart websites. As soon as I go to these websites i immediately and automatically get redirected to a google search results page (google is my home page) and on the top of the page the message Sorry, we couldn't find <http://ad.yieldmanager.com/st%3Fad_type>. Here are some related websites: is always there. I've run spybot search and destroy, ad-aware, and symantec anti-virus with all recent updates and they can't find anything. I've also tried running the search all files and folders option to try and find any folders with yieldmanager in it but have come up with nothing. Please help.....it is driving me crazy. And if you have any suggestions to any other anti-virus or spyware software I should be running along with what I already have, to keep this problem from happening again would be greatly appreciated. Thank you. Here are my logs from DDS: I also have downloaded the hi-jack this program, so if you want me to run that just let me know.

DDS (Ver_09-03-16.01) - NTFSx86
Run by Mark Richards at 19:39:55.42 on Mon 03/30/2009
Internet Explorer: 7.0.5730.11
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1415 [GMT -4:00]

AV: McAfee VirusScan *On-access scanning enabled* (Updated)
AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated)
FW: *disabled*

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\GEARSec.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\MotorolaDAP.exe
C:\Program Files\Norton Ghost\Agent\VProSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe
C:\Program Files\Common Files\AOL\1170410798\ee\AOLSoftware.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
C:\Program Files\Norton Ghost\Agent\GhostTray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Mark Richards\My Documents\HiJack This Program\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Mark Richards\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/ig/dell?hl=en&client=dell-inc&channel=us
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.comcast.net/toolbar2.0/search/
uDefault_Page_URL = hxxp://www.google.com/ig/dell?hl=en&client=dell-inc&channel=us
uWindow Title = Microsoft Internet Explorer presented by Comcast
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mWindow Title = Microsoft Internet Explorer presented by Comcast
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.comcast.net/toolbar2.0/search/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Comcast Toolbar: {4e7bd74f-2b8d-469e-93be-be2df4d9ae29} - c:\progra~1\comcas~1\COMCAS~1.DLL
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar2.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
TB: Comcast Toolbar: {4e7bd74f-2b8d-469e-93be-be2df4d9ae29} - c:\progra~1\comcas~1\COMCAS~1.DLL
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar2.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [updateMgr] "c:\program files\adobe\acrobat 7.0\acrobat\AdobeUpdateManager.exe" AcPro7_0_8 -reboot 1
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [DMXLauncher] c:\program files\dell\media experience\DMXLauncher.exe
mRun: [RealTray] c:\program files\real\realplayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [MimBoot] c:\progra~1\musicm~1\musicm~3\mimboot.exe
mRun: [MMTray] "c:\program files\musicmatch\musicmatch jukebox\mm_tray.exe"
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [<NO NAME>]
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [Corel Photo Downloader] c:\program files\corel\corel photo album 6\MediaDetect.exe
mRun: [MSKDetectorExe] c:\program files\mcafee\spamkiller\MSKDetct.exe /uninstall
mRun: [vptray] c:\progra~1\symant~1\VPTray.exe
mRun: [Acrobat Assistant 7.0] "c:\program files\adobe\acrobat 7.0\distillr\Acrotray.exe"
mRun: [tgcmd] c:\program files\support.com\bin\tgcmd.exe /server /startmonitor /deaf
mRun: [HostManager] c:\program files\common files\aol\1170410798\ee\AOLSoftware.exe
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Norton Ghost 10.0] "c:\program files\norton ghost\agent\GhostTray.exe"
StartupFolder: c:\docume~1\markri~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\markri~1\startm~1\programs\startup\regist~1.lnk - c:\program files\ubisoft\blazing angels squadrons of wwii\RegistrationReminder.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobea~1.lnk - c:\windows\installer\{ac76ba86-1033-0000-7760-100000000002}\SC_Acrobat.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\americ~1.lnk - c:\program files\america online 9.0\aoltray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe
IE: &Google Search
IE: &Translate English Word
IE: Backward Links
IE: Cached Snapshot of Page
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Similar Pages
IE: Translate Page into English
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: musicmatch.com\online
DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} - hxxps://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
Handler: intu-help-qb1 - {9B0F96C7-2E4B-433e-ABF3-043BA1B54AE3} - c:\program files\intuit\quickbooks 2005\HelpAsyncPluggableProtocol.dll
Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - c:\windows\system32\mscoree.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
AppInit_DLLs: c:\progra~1\google\google~1\GOEC62~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-3-7 64160]
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);c:\windows\system32\drivers\sfsync03.sys [2005-12-6 35328]
R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2005-2-4 324232]
R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2005-2-4 53896]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2005-6-2 185968]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2005-6-2 161392]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-1-18 951632]
R2 MotorolaDAP;Motorola Digital Audio Player Manager;c:\windows\system32\MotorolaDAP.exe [2004-8-18 270336]
R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2005-6-23 1715904]
R2 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2009-3-26 822424]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090329.003\naveng.sys [2009-3-29 89104]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090329.003\navex15.sys [2009-3-29 876144]
S3 ccPwdSvc;Symantec Password Validation;c:\program files\common files\symantec shared\ccPwdSvc.exe [2005-6-2 83568]
S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2005-6-23 124608]

=============== Created Last 30 ================

2009-03-29 15:15 <DIR> --d----- c:\program files\CCleaner
2009-03-26 22:45 4,608 a------- c:\windows\system32\drivers\symlcbrd.sys
2009-03-26 22:42 4,588,454 a------- c:\program files\setup.exe
2009-03-26 22:42 <DIR> --d----- c:\program files\Support
2009-03-26 22:42 <DIR> --d----- c:\program files\Driver Validation
2009-03-26 22:01 <DIR> --d----- c:\windows\system32\appmgmt
2009-03-26 21:46 <DIR> --d----- c:\windows\LMI20C.tmp
2009-03-25 20:45 215,144 a----r-- c:\windows\patchw32.dll
2009-03-25 20:45 215,144 a----r-- c:\windows\pw32a0.dll
2009-03-21 16:46 410,984 a------- c:\windows\system32\deploytk.dll
2009-03-17 03:27 15,688 a------- c:\windows\system32\lsdelete.exe
2009-03-10 19:00 <DIR> --d----- c:\docume~1\markri~1\applic~1\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2009-03-07 07:41 64,160 a------- c:\windows\system32\drivers\Lbd.sys
2009-03-07 07:37 <DIR> -cd-h--- c:\docume~1\alluse~1\applic~1\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-03-03 19:09 54,156 a---h--- c:\windows\QTFont.qfn
2009-03-03 19:09 1,409 a------- c:\windows\QTFont.for

==================== Find3M ====================

2009-03-25 13:45 4,184 a--sh--- c:\windows\system32\KGyGaAvL.sys
2009-02-09 07:13 1,846,784 a------- c:\windows\system32\win32k.sys
2009-02-09 07:13 1,846,784 -------- c:\windows\system32\dllcache\win32k.sys
2009-01-16 22:35 3,594,752 a------- c:\windows\system32\dllcache\mshtml.dll
2005-11-16 17:32 35 a------- c:\program files\SCSSDist.ini
2005-09-09 19:55 7,155,864 a------- c:\program files\NGhost10.msi
2005-09-09 19:55 37,766,164 a------- c:\program files\Data1.cab
2007-11-22 14:47 56 -c-shr-- c:\windows\system32\7D62A8C65D.sys
2008-08-19 07:06 32,768 ac-sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008081920080820\index.dat

============= FINISH: 19:40:24.78 ===============

Attached Files


Edited by Orange Blossom, 30 March 2009 - 10:16 PM.
Deactivate link. ~ OB


BC AdBot (Login to Remove)

 


#2 suebaby41

suebaby41

    W.A.M. (Women Against Malware)


  • Malware Response Team
  • 6,248 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:South Carolina, USA
  • Local time:10:48 AM

Posted 08 April 2009 - 02:55 PM

Welcome to the BleepingComputer Forums.

Since it has been a few days since you scanned your computer with HijackThis, we will need a new HijackThis log. If you have not already downloaded Random's System Information Tool (RSIT), please download Random's System Information Tool (RSIT) by random/random which includes a HijackThis log and save it to your desktop. If you have RSIT already on your computer, please run it again.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Please post the contents of log.txt.
Thank you for your patience.

Please see Preparation Guide for use before posting about your potential Malware problem.

If you have already posted this log at another forum or if you decide to seek help at another forum, please let us know. There is a shortage of helpers and taking the time of two volunteer helpers means that someone else may not be helped.

Please post your HijackThis log as a reply to this thread and not as an attachment. I am always leery of opening attachments so I always request that HijackThis logs are to be posted as a reply to the thread. I do not think that you are attaching anything scary but others may do so.

While we are working on your HijackThis log, please:
  • Reply to this thread; do not start another!
  • Do not make any changes on your computer during the cleaning process or download/add programs on your computer unless instructed to do so.
  • Do not run any other tool until instructed to do so!
  • Let me know if any of the links do not work or if any of the tools do not work.
  • Tell me about problems or symptoms that occur during the fix.
  • Do not run any other programs or open any other windows while doing a fix.
  • Ask any questions that you have regarding the fix(es), the infection(s), the performance of your computer, etc.
Thanks.
You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)
Malware Removal University Masters Graduate

Posted Image
Join The Fight Against Malware
No reply within 5 days will result in your topic being closed. If you need more time, please let me know by posting in this topic so that your topic will not be closed.

#3 mrboyertown

mrboyertown
  • Topic Starter

  • Members
  • 36 posts
  • OFFLINE
  •  
  • Local time:10:48 AM

Posted 11 April 2009 - 09:57 AM

Hello and thanks for your willingness to help.
Let me give you an overview of what has been going on. As stated in my first post I have been having a browser redirect problem when going onto certain sites such as walmart, cnbc, etc.... I've had my computer for 3 years and do alot of browsing but have never had this problem up until a few days ago. Now I first posted my problem under this forum but had been waiting for over a week for a response and figured my post had been forgotten or just overlooked. I was really having a problem with the redirect issues (which seemed to be getting worse) and it was hard to go to any sites, so I then posted my problem on the "Am I infected and what do I do" forum, in which I received a prompt response. I downloaded and ran many programs, none of which seemed to help with the problem. Then I was instructed to download the MVPS hosts file and to remove the Search Assistant and URL Assistant programs from my computer (Which I did). I no longer seem to be experiencing the redirect problems but I just have a hard time understanding why removing these programs have totally fixed the problem. The reason being is because, these programs as I understand it, have been on the computer from the factory (its a dell computer) and the whole time I've had this computer (3yrs), and doing an awful lot of browsing in that time, I have never encountered the browser redirect problem. If by removing these programs (Search and URL assistant) have indeed completely fixed my problem, than that is great. But I would really like a second opinion, it would be greatly appreciated. My main concern is that I would like to do a complete backup of my hard drive because I have years worth of valuble information and pictures and what not on it and have never performed one as of yet. I do not want to do this though until I know for sure I have removed any and all problems that might jepordize my files. I would also like to have a clean and infection free restore point for any problems that may happen in the future. Your input would be greatly appreciated. Thank you.

I already had the HiJackThis program downloaded onto my computer. I then noticed you wanted me to download RSIT and use it. Is there a difference between these two programs? Should I have both downloaded or use just one? And if so which one should I keep? Anyway I used the RSIT program as you have instructed and here is the log from that:
(If you also need just the hijackthis log also please let me know.) SORRY FOR THE LONG POST

Logfile of random's system information tool 1.06 (written by random/random)
Run by Mark Richards at 2009-04-11 10:31:21
Microsoft Windows XP Professional Service Pack 3
System drive C: has 129 GB (73%) free of 176 GB
Total RAM: 2046 MB (71% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:31:28, on 4/11/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\GEARSec.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\MotorolaDAP.exe
C:\Program Files\Norton Ghost\Agent\VProSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\Program Files\Common Files\AOL\1170410798\ee\AOLSoftware.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Norton Ghost\Agent\GhostTray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Mark Richards\Desktop\RSIT.exe
C:\Documents and Settings\Mark Richards\My Documents\HiJack This Program\Mark Richards.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.comcast.net/toolbar2.0/search/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.comcast.net/toolbar2.0/search/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer presented by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [tgcmd] C:\Program Files\Support.com\bin\tgcmd.exe /server /startmonitor /deaf
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1170410798\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Norton Ghost 10.0] "C:\Program Files\Norton Ghost\Agent\GhostTray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" AcPro7_0_8 -reboot 1
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Registration .LNK = C:\Program Files\Ubisoft\Blazing Angels Squadrons of WWII\RegistrationReminder.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/as...abs/tgctlsr.cab
O18 - Protocol: intu-help-qb1 - {9B0F96C7-2E4B-433E-ABF3-043BA1B54AE3} - C:\Program Files\Intuit\QuickBooks 2005\HelpAsyncPluggableProtocol.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: Motorola Digital Audio Player Manager (MotorolaDAP) - Motorola Inc. - C:\WINDOWS\system32\MotorolaDAP.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton Ghost\Agent\VProSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

--
End of file - 13982 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29}]
Comcast Toolbar - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL [2006-11-14 1799680]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5CA3D70E-1895-11CF-8E15-001234567890}]
DriveLetterAccess - C:\WINDOWS\System32\DLA\DLASHX_W.DLL [2005-09-08 110652]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - c:\program files\google\googletoolbar2.dll [2007-01-19 2403392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2005-09-24 231160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-03-09 35840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-03-09 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2005-09-24 231160]
{4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - Comcast Toolbar - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL [2006-11-14 1799680]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar2.dll [2007-01-19 2403392]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2007-09-17 8491008]
"SigmatelSysTrayApp"=C:\WINDOWS\stsystra.exe [2005-03-22 339968]
"IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [2005-06-17 139264]
"DMXLauncher"=C:\Program Files\Dell\Media Experience\DMXLauncher.exe []
"RealTray"=C:\Program Files\Real\RealPlayer\RealPlay.exe [2006-06-13 26112]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2006-06-13 98304]
"ccApp"=C:\Program Files\Common Files\Symantec Shared\ccApp.exe [2005-06-02 48752]
"MimBoot"=C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe [2006-09-18 8192]
"MMTray"=C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe [2006-09-18 110592]
"ISUSPM Startup"=C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe [2005-06-10 249856]
"ISUSScheduler"=C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2005-06-10 81920]
""= []
"DLA"=C:\WINDOWS\System32\DLA\DLACTRLW.EXE [2005-09-08 122940]
"Google Desktop Search"=C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2006-06-13 169472]
"Corel Photo Downloader"=C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe [2006-02-09 106496]
"MSKDetectorExe"=C:\Program Files\McAfee\SpamKiller\MSKDetct.exe [2005-07-12 1117184]
"vptray"=C:\PROGRA~1\SYMANT~1\VPTray.exe [2005-06-23 85696]
"Acrobat Assistant 7.0"=C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe [2006-01-12 483328]
"tgcmd"=C:\Program Files\Support.com\bin\tgcmd.exe [2007-03-07 1773568]
"HostManager"=C:\Program Files\Common Files\AOL\1170410798\ee\AOLSoftware.exe [2007-10-08 41824]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
"Ad-Watch"=C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe [2009-03-07 515416]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]
"Norton Ghost 10.0"=C:\Program Files\Norton Ghost\Agent\GhostTray.exe [2005-09-09 1537648]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-03-09 148888]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
"updateMgr"=C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe [2006-03-30 313472]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2009-03-23 1830128]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-100000000002}\SC_Acrobat.exe
America Online 9.0 Tray Icon.lnk - C:\Program Files\America Online 9.0\aoltray.exe
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe

C:\Documents and Settings\Mark Richards\Start Menu\Programs\Startup
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
Registration .LNK - C:\Program Files\Ubisoft\Blazing Angels Squadrons of WWII\RegistrationReminder.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2008-12-22 356352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
C:\WINDOWS\system32\NavLogon.dll [2005-06-23 43712]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2008-09-06 241704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Microsoft Games\Halo\halo.exe"="C:\Program Files\Microsoft Games\Halo\halo.exe:*:Enabled:Halo"
"C:\Program Files\America Online 9.0\waol.exe"="C:\Program Files\America Online 9.0\waol.exe:*:Disabled:America Online 9.0"
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Disabled:AOL"
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe"="C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Disabled:AOL"
"C:\Program Files\Common Files\AOL\1170410798\ee\aolsoftware.exe"="C:\Program Files\Common Files\AOL\1170410798\ee\aolsoftware.exe:*:Disabled:AOL Services"
"C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Disabled:LimeWire"
"C:\StubInstaller.exe"="C:\StubInstaller.exe:*:Disabled:LimeWire swarmed installer"
"C:\WINDOWS\LMI75.tmp\lmi_rescue.exe"="C:\WINDOWS\LMI75.tmp\lmi_rescue.exe:*:Disabled:LogMeIn Rescue"
"C:\WINDOWS\LMI20C.tmp\lmi_rescue.exe"="C:\WINDOWS\LMI20C.tmp\lmi_rescue.exe:*:Disabled:LogMeIn Rescue"
"C:\Program Files\Microsoft Games\Combat Flight Simulator 3\cfs3.exe"="C:\Program Files\Microsoft Games\Combat Flight Simulator 3\cfs3.exe:*:Disabled:Microsoft® Combat Flight Simulator 3"
"C:\Documents and Settings\Mark Richards\Local Settings\Temp\7zS274.tmp\SymNRT.exe"="C:\Documents and Settings\Mark Richards\Local Settings\Temp\7zS274.tmp\SymNRT.exe:*:Disabled:Norton Removal Tool"
"C:\Novell\GroupWise\grpwise.exe"="C:\Novell\GroupWise\grpwise.exe:*:Disabled:Novell GroupWise"
"C:\Novell\GroupWise\notify.exe"="C:\Novell\GroupWise\notify.exe:*:Disabled:Novell Notify"
"C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE:*:Disabled:Outlook"
"C:\Program Files\Intuit\QuickBooks 2005\QBDBMgrN.exe"="C:\Program Files\Intuit\QuickBooks 2005\QBDBMgrN.exe:*:Disabled:QuickBooks 2008 Data Manager"
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe"="C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL"
"C:\Program Files\America Online 9.0\waol.exe"="C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2009-04-11 10:31:21 ----D---- C:\rsit
2009-04-06 21:22:05 ----D---- C:\hosts
2009-04-05 07:41:55 ----A---- C:\WINDOWS\system32\tmp.txt
2009-04-05 07:41:15 ----A---- C:\WINDOWS\system32\o4Patch.exe
2009-04-05 07:41:15 ----A---- C:\WINDOWS\system32\IEDFix.C.exe
2009-04-05 07:41:15 ----A---- C:\WINDOWS\system32\Agent.OMZ.Fix.exe
2009-04-05 07:41:13 ----A---- C:\WINDOWS\system32\SrchSTS.exe
2009-04-05 07:41:13 ----A---- C:\WINDOWS\system32\Process.exe
2009-04-04 21:04:26 ----A---- C:\WINDOWS\ntbtlog.txt
2009-04-04 16:41:26 ----D---- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2009-04-04 16:41:18 ----D---- C:\Program Files\SUPERAntiSpyware
2009-04-04 16:41:17 ----D---- C:\Documents and Settings\Mark Richards\Application Data\SUPERAntiSpyware.com
2009-04-04 16:39:56 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2009-04-04 11:31:57 ----D---- C:\Documents and Settings\Mark Richards\Application Data\Malwarebytes
2009-04-04 11:31:52 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-04-04 11:31:52 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-04-02 04:37:20 ----A---- C:\WINDOWS\system32\javaws.exe
2009-04-02 04:37:20 ----A---- C:\WINDOWS\system32\javaw.exe
2009-04-02 04:37:20 ----A---- C:\WINDOWS\system32\java.exe
2009-03-29 15:15:02 ----D---- C:\Program Files\CCleaner
2009-03-26 22:42:43 ----A---- C:\Program Files\SCSSDist.ini
2009-03-26 22:42:41 ----D---- C:\Program Files\Support
2009-03-26 22:42:41 ----D---- C:\Program Files\Driver Validation
2009-03-26 22:01:28 ----D---- C:\WINDOWS\system32\appmgmt
2009-03-26 21:46:18 ----D---- C:\WINDOWS\LMI20C.tmp
2009-03-25 20:45:46 ----RA---- C:\WINDOWS\patchw32.dll
2009-03-25 20:45:09 ----RA---- C:\WINDOWS\pw32a0.dll
2009-03-21 16:46:14 ----A---- C:\WINDOWS\system32\deploytk.dll
2009-03-17 03:27:38 ----A---- C:\WINDOWS\system32\lsdelete.exe

======List of files/folders modified in the last 1 months======

2009-04-11 10:31:10 ----D---- C:\WINDOWS\Prefetch
2009-04-11 07:49:40 ----D---- C:\WINDOWS\Temp
2009-04-11 07:19:53 ----A---- C:\WINDOWS\win.ini
2009-04-10 15:41:04 ----SHD---- C:\WINDOWS\Installer
2009-04-10 15:40:56 ----D---- C:\Program Files\Dell
2009-04-10 15:39:31 ----D---- C:\WINDOWS\system32\CatRoot2
2009-04-10 15:39:22 ----D---- C:\Program Files\Symantec AntiVirus
2009-04-10 15:38:44 ----A---- C:\WINDOWS\ModemLog_Conexant D850 56K V.9x DFVc Modem.txt
2009-04-10 15:37:22 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-04-10 15:37:07 ----D---- C:\WINDOWS\system32
2009-04-06 21:27:58 ----D---- C:\WINDOWS\system32\drivers
2009-04-06 17:44:56 ----D---- C:\WINDOWS
2009-04-06 03:00:24 ----HD---- C:\WINDOWS\inf
2009-04-06 03:00:24 ----D---- C:\WINDOWS\system32\CatRoot
2009-04-04 16:41:18 ----RD---- C:\Program Files
2009-04-04 16:39:56 ----D---- C:\Program Files\Common Files
2009-04-03 18:35:33 ----A---- C:\WINDOWS\WPCMAPI.INI
2009-04-02 04:37:19 ----D---- C:\Program Files\Java
2009-03-29 15:48:53 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-03-29 15:29:56 ----D---- C:\WINDOWS\Debug
2009-03-29 15:29:55 ----D---- C:\WINDOWS\Minidump
2009-03-26 22:45:35 ----D---- C:\Program Files\Norton Ghost
2009-03-26 22:44:52 ----D---- C:\Program Files\Common Files\Symantec Shared
2009-03-26 21:52:54 ----SHD---- C:\System Volume Information
2009-03-26 21:48:42 ----D---- C:\WINDOWS\Registration
2009-03-26 21:09:22 ----D---- C:\Documents and Settings\All Users\Application Data\Symantec
2009-03-25 21:00:21 ----D---- C:\WINDOWS\WinSxS
2009-03-25 20:58:10 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-03-17 10:32:23 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-03-14 07:24:04 ----RSHD---- C:\WINDOWS\system32\dllcache

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 DLACDBHM;DLACDBHM; C:\WINDOWS\System32\Drivers\DLACDBHM.SYS [2005-08-25 5628]
R1 DLARTL_N;DLARTL_N; C:\WINDOWS\System32\Drivers\DLARTL_N.SYS [2005-08-25 22684]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys []
R1 GearAspiWDM;GearAspiWDM; C:\WINDOWS\system32\drivers\GearAspiWDM.sys [2005-09-09 14408]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys []
R1 SAVRT;SAVRT; \??\C:\Program Files\Symantec AntiVirus\savrt.sys []
R1 SAVRTPEL;SAVRTPEL; \??\C:\Program Files\Symantec AntiVirus\Savrtpel.sys []
R1 SYMTDI;SYMTDI; C:\WINDOWS\System32\Drivers\SYMTDI.SYS [2005-04-22 267192]
R1 V2IMount;V2IMount; C:\WINDOWS\system32\drivers\V2IMount.sys [2005-09-09 56192]
R2 ASCTRM;ASCTRM; C:\WINDOWS\system32\drivers\ASCTRM.sys [2006-06-13 8552]
R2 DLABOIOM;DLABOIOM; C:\WINDOWS\System32\DLA\DLABOIOM.SYS [2005-09-08 25628]
R2 DLADResN;DLADResN; C:\WINDOWS\System32\DLA\DLADResN.SYS [2005-09-08 2496]
R2 DLAIFS_M;DLAIFS_M; C:\WINDOWS\System32\DLA\DLAIFS_M.SYS [2005-09-08 86524]
R2 DLAOPIOM;DLAOPIOM; C:\WINDOWS\System32\DLA\DLAOPIOM.SYS [2005-09-08 14684]
R2 DLAPoolM;DLAPoolM; C:\WINDOWS\System32\DLA\DLAPoolM.SYS [2005-09-08 6364]
R2 DLAUDF_M;DLAUDF_M; C:\WINDOWS\System32\DLA\DLAUDF_M.SYS [2005-09-08 87036]
R2 DLAUDFAM;DLAUDFAM; C:\WINDOWS\System32\DLA\DLAUDFAM.SYS [2005-09-08 94332]
R2 DRVNDDM;DRVNDDM; C:\WINDOWS\System32\Drivers\DRVNDDM.SYS [2005-08-12 40544]
R2 dsunidrv;DellSupport UniDriver; C:\WINDOWS\system32\DRIVERS\dsunidrv.sys [2007-02-25 5376]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2003-04-09 11043]
R2 symlcbrd;symlcbrd; \??\C:\WINDOWS\system32\drivers\symlcbrd.sys []
R3 e1express;Intel® PRO/1000 PCI Express Network Connection Driver; C:\WINDOWS\system32\DRIVERS\e1e5132.sys [2005-08-25 176128]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 HSF_DP;HSF_DP; C:\WINDOWS\system32\DRIVERS\HSF_DP.sys [2003-11-17 1042432]
R3 HSFHWBS2;HSFHWBS2; C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys [2003-11-17 212224]
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 NAVENG;NAVENG; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20090410.003\naveng.sys []
R3 NAVEX15;NAVEX15; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20090410.003\navex15.sys []
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2007-09-17 6853088]
R3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS []
R3 STHDA;SigmaTel High Definition Audio CODEC; C:\WINDOWS\system32\drivers\sthda.sys [2005-11-16 1047816]
R3 SymEvent;SymEvent; \??\C:\Program Files\Symantec\SYMEVENT.SYS []
R3 SYMREDRV;SYMREDRV; C:\WINDOWS\System32\Drivers\SYMREDRV.SYS [2005-04-22 17976]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 wanatw;WAN Miniport (ATW); C:\WINDOWS\system32\DRIVERS\wanatw4.sys [2003-01-10 33588]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2003-11-17 680704]
S3 bvrp_pci;bvrp_pci; C:\WINDOWS\system32\drivers\bvrp_pci.sys []
S3 DSproct;DSproct; \??\C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys []
S3 E100B;Intel® PRO Adapter Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2001-08-17 117760]
S3 EraserUtilDrv10910;EraserUtilDrv10910; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10910.sys []
S3 SPBBCDrv;SPBBCDrv; \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys []
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 agp440;Intel AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\agp440.sys [2008-04-13 42368]
S4 agpCPQ;Compaq AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\agpCPQ.sys [2008-04-13 44928]
S4 alim1541;ALI AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\alim1541.sys [2008-04-13 42752]
S4 amdagp;AMD AGP Bus Filter Driver; C:\WINDOWS\system32\DRIVERS\amdagp.sys [2008-04-13 43008]
S4 cbidf;cbidf; C:\WINDOWS\system32\DRIVERS\cbidf2k.sys [2001-08-17 13952]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\DRIVERS\intelide.sys [2008-04-13 5504]
S4 sisagp;SIS AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\sisagp.sys [2008-04-13 40960]
S4 viaagp;VIA AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\viaagp.sys [2008-04-13 42240]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AOL ACS;AOL Connectivity Service; C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe [2006-10-23 46640]
R2 ccEvtMgr;Symantec Event Manager; C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe [2005-06-02 185968]
R2 ccSetMgr;Symantec Settings Manager; C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe [2005-06-02 161392]
R2 DefWatch;Symantec AntiVirus Definition Watcher; C:\Program Files\Symantec AntiVirus\DefWatch.exe [2005-06-23 19648]
R2 GEARSecurity;GEARSecurity; C:\WINDOWS\System32\GEARSec.exe [2005-09-09 53248]
R2 IAANTMon;Intel® Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe [2005-06-17 86140]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-03-09 152984]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2009-03-14 951632]
R2 MotorolaDAP;Motorola Digital Audio Player Manager; C:\WINDOWS\system32\MotorolaDAP.exe [2004-08-18 270336]
R2 Norton Ghost;Norton Ghost; C:\Program Files\Norton Ghost\Agent\VProSvc.exe [2005-09-09 2066024]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2007-09-17 155716]
R2 QBCFMonitorService;QBCFMonitorService; C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe [2008-10-22 20480]
R2 Symantec AntiVirus;Symantec AntiVirus; C:\Program Files\Symantec AntiVirus\Rtvscan.exe [2005-06-23 1715904]
R2 Symantec Core LC;Symantec Core LC; C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe [2009-03-26 822424]
R2 WANMiniportService;WAN Miniport (ATW) Service; C:\WINDOWS\wanmpsvc.exe [2003-08-27 65536]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
S2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-13 267776]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2006-06-25 72704]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 ccPwdSvc;Symantec Password Validation; C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe [2005-06-02 83568]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 DSBrokerService;DSBrokerService; C:\Program Files\DellSupport\brkrsvc.exe [2007-03-07 76848]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-03-18 138168]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 LiveUpdate;LiveUpdate; C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE [2009-02-19 3220856]
S3 NetSvc;Intel NCS NetService; C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe [2004-11-19 147456]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 QBFCService;Intuit QuickBooks FCS; C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe [2007-05-24 61440]
S3 SavRoam;SAVRoam; C:\Program Files\Symantec AntiVirus\SavRoam.exe [2005-06-23 124608]
S3 SNDSrvc;Symantec Network Drivers Service; C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe [2005-04-22 206552]
S3 SPBBCSvc;Symantec SPBBCSvc; C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe [2005-03-30 992864]
S3 Symantec RemoteAssist;Symantec RemoteAssist; C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe [2008-01-29 394704]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S4 Automatic LiveUpdate Scheduler;Automatic LiveUpdate Scheduler; C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe [2009-02-19 238968]

-----------------EOF-----------------

Edited by mrboyertown, 11 April 2009 - 10:09 AM.


#4 mrboyertown

mrboyertown
  • Topic Starter

  • Members
  • 36 posts
  • OFFLINE
  •  
  • Local time:10:48 AM

Posted 11 April 2009 - 10:10 AM

I did run the Hijackthis and RSIT and dont know which log is for what program so here is the other log also:

info.txt logfile of random's system information tool 1.06 2009-04-11 10:31:31

======Uninstall list======

-->"C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
-->C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu
-->C:\WINDOWS\system32\\MSIEXEC.EXE /x {075473F5-846A-448B-BCB3-104AA1760205}
-->C:\WINDOWS\system32\\MSIEXEC.EXE /x {1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
-->C:\WINDOWS\system32\\MSIEXEC.EXE /x {AB708C9B-97C8-4AC9-899B-DBF226AC9382}
-->C:\WINDOWS\system32\\MSIEXEC.EXE /x {B12665F4-4E93-4AB4-B7FC-37053B524629}
-->MsiExec.exe /I{403EF592-953B-4794-BCEF-ECAB835C2095}
-->MsiExec.exe /I{8ED4E82B-8CEA-40DE-826C-37AC7B941F81}
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Acrobat.com-->MsiExec.exe /X{287ECFA4-719A-2143-A09B-D6A12DE54E40}
Ad-Aware-->"C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}\Ad-AwareAE.exe" REMOVE=TRUE MODIFY=FALSE
Ad-Aware-->C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}\Ad-AwareAE.exe
Adobe Acrobat 7.0.8 Professional-->msiexec /I {AC76BA86-1033-0000-7760-100000000002}
Adobe AIR-->c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{A2BCA9F1-566C-4805-97D1-7FDC93386723}
Adobe Bridge 1.0-->MsiExec.exe /I{B74D4E10-6884-0000-0000-000000000103}
Adobe Common File Installer-->MsiExec.exe /I{8EDBA74D-0686-4C99-BFDD-F894678E5B39}
Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Help Center 1.0-->MsiExec.exe /I{E9787678-1033-0000-8E67-000000000001}
Adobe Photoshop CS2-->msiexec /I {236BB7C4-4419-42FD-0409-1E257A25E34D}
Adobe Reader 9.1-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A91000000001}
Adobe Stock Photos 1.0-->MsiExec.exe /I{BC467935-A9A5-4D0F-BD89-94F36CDF0524}
AOL Coach Version 1.0(Build:20040229.1 en)-->C:\Program Files\Common Files\aolshare\Coach\AolCInUn.exe
AOL Uninstaller (Choose which Products to Remove)-->C:\Program Files\Common Files\AOL\uninstaller.exe
CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
Comcast High-Speed Internet Install Wizard-->C:\Program Files\support.com\uninstall\chsi_uninstaller.exe
Comcast Toolbar-->C:\Program Files\comcasttoolbar\uninstall.exe -uninstall -prompt
Conexant D850 56K V.9x DFVc Modem-->C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200F14F1\HXFSETUP.EXE -U -Idel200fk.inf
Corel Photo Album 6-->MsiExec.exe /X{8A9B8148-DDD7-448F-BD6C-358386D32354}
Critical Update for Windows Media Player 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
Dell CinePlayer-->MsiExec.exe /I{43CAC9A1-1993-4F65-9096-7C9AFC2BBF54}
Dell Digital Jukebox Driver-->C:\Program Files\Dell\Digital Jukebox Drivers\DrvUnins.exe /s
Dell Driver Reset Tool-->MsiExec.exe /I{5905F42D-3F5F-4916-ADA6-94A3646AEE76}
Dell Laser Printer 1110 Software Uninstall-->C:\Program Files\DELL\Dell Laser Printer 1110\Install\Maininst.exe /Uninstall
DellSupport-->MsiExec.exe /X{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}
Desktop Doctor-->"C:\Program Files\Support.com\providerComcast\Uninstall.exe" /c "Remove Desktop Doctor?"
Digital Content Portal-->MsiExec.exe /I{B702CCCE-3176-4DBF-B932-D1B8F402F330}
Digital Line Detect-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E646DCF0-5A68-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanelAnyText
EarthLink setup files-->MsiExec.exe /X{728278A1-0BB7-45E4-AC5E-91D7C0FD1EDE}
GameSpy Arcade-->C:\PROGRA~1\GAMESP~1\UNWISE.EXE C:\PROGRA~1\GAMESP~1\INSTALL.LOG
Google Desktop-->C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe -uninstall
Google Toolbar for Internet Explorer-->regsvr32 /u /s "c:\program files\google\googletoolbar2.dll"
GroupWise Internet Browser Mail Integration-->C:\Novell\GroupWise\gwmailto.exe /uninstall
GroupWise Tip of the Day C3PO-->C:\Novell\GroupWise\gwtip.exe /uninstall
GroupWise-->MsiExec.exe /I{00C7099C-891A-47E0-A454-2249979595BA}
High Definition Audio Driver Package - KB835221-->C:\WINDOWS\$NtUninstallKB835221WXP$\spuninst\spuninst.exe
HijackThis 2.0.2-->"C:\Documents and Settings\Mark Richards\My Documents\HiJack This Program\HijackThis.exe" /uninstall
Hotfix for Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Format SDK (KB902344)-->"C:\WINDOWS\$NtUninstallKB902344$\spuninst\spuninst.exe"
Hotfix for Windows Media Format SDK (KB910998)-->"C:\WINDOWS\$NtUninstallKB910998$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Intel Matrix Storage Manager-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}\setup.exe" -l0409 -INTELUNINST
Intel® PRO Network Connections Drivers-->Prounstl.exe
Intel® PROSet for Wired Connections-->MsiExec.exe /I{4CEA6811-DFAD-4892-828D-49941FE3B779}
J2SE Runtime Environment 5.0 Update 10-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150100}
J2SE Runtime Environment 5.0 Update 11-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150110}
J2SE Runtime Environment 5.0 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150070}
J2SE Runtime Environment 5.0 Update 9-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150090}
Java 2 Runtime Environment, SE v1.4.2_03-->MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142030}
Java™ 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
Java™ 6 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
Java™ 6 Update 3-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java™ 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Java™ SE Runtime Environment 6 Update 1-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
Learn2 Player (Uninstall Only)-->C:\Program Files\Learn2.com\StRunner\stuninst.exe
LimeWire 4.12.6-->"C:\Program Files\LimeWire\uninstall.exe"
LiveReg (Symantec Corporation)-->C:\Program Files\Common Files\Symantec Shared\LiveReg\VcSetup.exe /REMOVE
LiveUpdate (Symantec Corporation)-->MsiExec.exe /x {E80F62FF-5D3C-4A19-8409-9721F2928206} /l*v "C:\Documents and Settings\All Users\Application Data\LuUninstall.LiveUpdate"
LiveUpdate (Symantec Corporation)-->MsiExec.exe /X{E80F62FF-5D3C-4A19-8409-9721F2928206}
Macromedia Flash Player-->MsiExec.exe /X{0456ebd7-5f67-4ab6-852e-63781e3f389c}
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
MCU-->MsiExec.exe /I{D2988E9B-C73F-422C-AD4B-A66EBE257120}
Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
Microsoft Combat Flight Simulator 3.1-->"C:\Program Files\Microsoft Games\Combat Flight Simulator 3\UNINSTAL.EXE" /runtemp /addremove
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Halo-->"C:\Program Files\Microsoft Games\Halo\UNINSTAL.EXE" /runtemp /addremove
Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office Professional Edition 2003-->MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
Microsoft Plus! Digital Media Edition Installer-->MsiExec.exe /X{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}
Microsoft Plus! Photo Story 2 LE-->MsiExec.exe /X{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Modem Helper-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F142D56-3326-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanel
Motorola Music Manager-->MsiExec.exe /X{C753D59A-E796-4470-A641-83ED3EF42544}
MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 Parser and SDK-->MsiExec.exe /I{716E0306-8318-4364-8B8F-0CC4E9376BAC}
Musicmatch for Windows Media Player-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E93E5EF6-D361-481E-849D-F16EF5C78EBC}\setup.exe" -l0x9 remove
Musicmatch® Jukebox-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{85D3CC30-8859-481A-9654-FD9B74310BEF}\setup.exe" -l0x9 -uninst
NetWaiting-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3F92ABBB-6BBF-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanelAnyText
Norton Ghost 10.0-->MsiExec.exe /X{32F720F5-2D0D-4245-A2B0-9EB3CECF8101}
NVIDIA Drivers-->C:\WINDOWS\system32\nvudisp.exe UninstallGUI
Qualxserve Service Agreement-->MsiExec.exe /X{0F756CD9-4A1E-409B-B101-601DDC4C03AA}
Quick Resize-->MsiExec.exe /I{22DD7ADB-989A-49AF-AEB8-2B82533FF494}
QuickBooks Simple Start 2008-->msiexec.exe /I {8ED4E82B-8CEA-40DE-826C-37AC7B941F81} UNIQUE_NAME="atomlimited" QBFULLNAME="QuickBooks Simple Start 2008" ADDREMOVE=1
QuickTime-->C:\WINDOWS\unvise32qt.exe C:\WINDOWS\system32\QuickTime\Uninstall.log
RealPlayer Basic-->C:\Program Files\Common Files\Real\Update\\rnuninst.exe RealNetworks|RealPlayer|6.0
Roxio DLA-->MsiExec.exe /I{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
Roxio MyDVD LE-->MsiExec.exe /I{21657574-BD54-48A2-9450-EB03B2C7FC29}
Roxio RecordNow Audio-->MsiExec.exe /I{AB708C9B-97C8-4AC9-899B-DBF226AC9382}
Roxio RecordNow Copy-->MsiExec.exe /I{B12665F4-4E93-4AB4-B7FC-37053B524629}
Roxio RecordNow Data-->MsiExec.exe /I{075473F5-846A-448B-BCB3-104AA1760205}
Security Update for Step By Step Interactive Training (KB898458)-->"C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
Security Update for Step By Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB928090)-->"C:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB929969)-->"C:\WINDOWS\ie7updates\KB929969\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB931768)-->"C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB933566)-->"C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB937143)-->"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB939653)-->"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player 10 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP10$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
SimCity 4 Deluxe-->C:\Program Files\Maxis\SimCity 4 Deluxe\EAUninstall.exe
Sonic Activation Module-->MsiExec.exe /I{5B6BE547-21E2-49CA-B2E2-6A5F470593B1}
Sonic Update Manager-->MsiExec.exe /I{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
Spybot - Search & Destroy 1.5.2.20-->"C:\WINDOWS\unins000.exe"
Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins001.exe"
SUPERAntiSpyware Free Edition-->MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
SupportSoft Assisted Service-->MsiExec.exe /I{5A3F6A80-7913-475E-8B96-477A952CFA43}
Symantec AntiVirus-->MsiExec.exe /I{3248E093-5288-4CA9-B3AB-11A675FEA1F9}
Symantec KB-DocID:2003093015493306-->MsiExec.exe /I{08C5815C-2C6E-44f8-8748-0E61BC9AFB68}
Symantec Technical Support Web Controls-->MsiExec.exe /X{20C53FA2-4307-4671-A93F-9463B29DFCF1}
Update for Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Update for Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
Update for Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
Viewpoint Media Player-->C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
Visual C++ 2008 x86 Runtime - (v9.0.30729)-->MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27}
Visual C++ 2008 x86 Runtime - v9.0.30729.01-->C:\WINDOWS\system32\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT=""
WebCyberCoach 3.2 Dell-->"C:\Program Files\WebCyberCoach\b_Dell\WCC_Wipe.exe" "WebCyberCoach ext\wtrb" /inf "engine.inf,RealUninstallSection,,4" /infcfg "enginecf.inf,RealUninstallSection,,4"
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 10 Hotfix - KB895316-->"C:\WINDOWS\$NtUninstallKB895316$\spuninst\spuninst.exe"
Windows Media Player 10-->MsiExec.exe /I{33BB4982-DC52-4886-A03B-F4C5C80BEE89}
Windows Media Player 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
WordPerfect Office 12-->MsiExec.exe /I{AF19F291-F22F-4798-9662-525305AE9E48}

======Hosts File======

127.0.0.1 localhost
127.0.0.1 ad.a8.net
127.0.0.1 asy.a8ww.net
127.0.0.1 acezip.net #[SiteAdvisor.acezip.net]
127.0.0.1 www.acezip.net #[Win32/Adware.180Solutions]
127.0.0.1 phpadsnew.abac.com
127.0.0.1 a.abnad.net
127.0.0.1 b.abnad.net
127.0.0.1 c.abnad.net #[eTrust.Tracking.Cookie]
127.0.0.1 d.abnad.net

======Security center information======

AV: McAfee VirusScan
AV: Symantec AntiVirus Corporate Edition
FW: (disabled)

======System event log======

Computer Name: MARK
Event Code: 59
Message: Resolve Partial Assembly failed for Microsoft.VC80.MFCLOC.
Reference error message: The referenced assembly is not installed on your system.
.

Record Number: 42526
Source Name: SideBySide
Time Written: 20090220111742.000000-300
Event Type: error
User:

Computer Name: MARK
Event Code: 32
Message: Dependent Assembly Microsoft.VC80.MFCLOC could not be found and Last Error was The referenced assembly is not installed on your system.


Record Number: 42525
Source Name: SideBySide
Time Written: 20090220111742.000000-300
Event Type: error
User:

Computer Name: MARK
Event Code: 59
Message: Generate Activation Context failed for C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\MFC80.DLL.
Reference error message: The operation completed successfully.
.

Record Number: 42524
Source Name: SideBySide
Time Written: 20090220111742.000000-300
Event Type: error
User:

Computer Name: MARK
Event Code: 59
Message: Resolve Partial Assembly failed for Microsoft.VC80.MFCLOC.
Reference error message: The referenced assembly is not installed on your system.
.

Record Number: 42523
Source Name: SideBySide
Time Written: 20090220111742.000000-300
Event Type: error
User:

Computer Name: MARK
Event Code: 32
Message: Dependent Assembly Microsoft.VC80.MFCLOC could not be found and Last Error was The referenced assembly is not installed on your system.


Record Number: 42522
Source Name: SideBySide
Time Written: 20090220111741.000000-300
Event Type: error
User:

=====Application event log=====

Computer Name: MARK
Event Code: 1001
Message: Fault bucket 419857259.

Record Number: 17664
Source Name: Application Error
Time Written: 20090325210205.000000-240
Event Type: error
User:

Computer Name: MARK
Event Code: 1001
Message: Detection of product '{32F720F5-2D0D-4245-A2B0-9EB3CECF8101}', feature 'Console' failed during request for component '{EEE2295C-E02C-4CA0-A700-1BF3AFA60DDC}'

Record Number: 17663
Source Name: MsiInstaller
Time Written: 20090325210202.000000-240
Event Type: warning
User: MARK\Mark Richards

Computer Name: MARK
Event Code: 1000
Message: Faulting application VProSvc.exe, version 10.0.3.20387, faulting module VProObj.dll, version 10.0.0.8079, fault address 0x0017270a.

Record Number: 17662
Source Name: Application Error
Time Written: 20090325210201.000000-240
Event Type: error
User:

Computer Name: MARK
Event Code: 1000
Message: Faulting application VProSvc.exe, version 10.0.3.20387, faulting module VProObj.dll, version 10.0.0.8079, fault address 0x0017270a.

Record Number: 17659
Source Name: Application Error
Time Written: 20090325204944.000000-240
Event Type: error
User:

Computer Name: MARK
Event Code: 1015
Message: Failed to connect to server. Error: 0x800401F0

Record Number: 17653
Source Name: MsiInstaller
Time Written: 20090325204509.000000-240
Event Type: warning
User: MARK\Mark Richards

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Adobe\AGL;C:\Program Files\Common Files\Intuit\QBPOSSDKRuntime
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 6 Stepping 4, GenuineIntel
"PROCESSOR_REVISION"=0604
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"SonicCentral"=C:\Program Files\Common Files\Sonic Shared\Sonic Central\

-----------------EOF-----------------

Edited by mrboyertown, 11 April 2009 - 10:12 AM.


#5 suebaby41

suebaby41

    W.A.M. (Women Against Malware)


  • Malware Response Team
  • 6,248 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:South Carolina, USA
  • Local time:10:48 AM

Posted 12 April 2009 - 11:01 AM

The item(s) below indicate(s) you have installed .

"C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Disabled:LimeWire"
"C:\StubInstaller.exe"="C:\StubInstaller.exe:*:Disabled:LimeWire swarmed installer"


Since the nature of P2P programs are counter productive to restoring your PC to a healthy state, I ask that you remove P2P file sharing programs prior to my providing you with malware removal assistance. Even the safest P2P file sharing programs that do not contain bundled spyware, still expose you to risks because of the very nature of the P2P file sharing process. By default, most P2P file sharing programs are configured to automatically launch at startup. They are also configured to allow other P2P users on the same network open access to a shared directory on your computer.

The people who design and distribute malware will use any method to infect personal computers to make use of their stored data or machine power for further propagation of the malware files. A popular method is the use of file-sharing tools as a tremendous amount of prospective victims can be reached through it. Many very malicious worms and trojans, such as the Storm Worm, target and spread across P2P files sharing networks because of their known vulnerabilities.
To remove the P2P program:
  • Click Start > Control Panel.
  • In Control Panel, double-click Add or Remove Programs.
  • In Add or Remove Programs, highlight , click Remove.
  • Close the Add or Remove Programs and the Control Panel windows.
  • Using Windows Explorer (Windows key+e), search for the folder. If the program folder is still there, select/highlight . DELETE it. (File > Delete.) If Windows is not installed on the C drive, replace C:\ with the appropriate drive letter.
  • Close Windows Explorer.
There is a Video showing how to uninstall a program (Grinler) detailing how to add or remove program in Windows for those who find a visual aid appealing. NOTE: Take care when answering any questions posed by an uninstaller. Some questions may be worded to deceive you into keeping the program.

I am not asking you to do remove the P2P program(s) without giving you good reasons for doing so.
  • P2P programs form a direct conduit on to your computer.
  • P2P security measures are easily circumvented.
  • Some P2P programs will share everything on the computer with anyone by default. If your P2P program is not configured correctly, you may be sharing more files than you realize.
  • There have been cases where people's passwords, address books and other personal, private, and financial details have been exposed to the file sharing network by a badly configured program.
  • P2P programs have always been a target of malware writers. There are more Viruses, Worms and Trojans being distributed with the downloaded files.
  • P2P programs connected to a network can be used to spread malware, share private documents, or use the file server to both store and forward malware.
  • Many of the files in P2P networks are copyrighted and legal action could result.
  • Pedophiles can use P2P communities to distribute child porn materials or attempt to make contact with children.
  • This article from InfoWorld, Seattle Man Arrested For P To P ID Theft, illustrates perfectly the dangers of a poorly configured P2P program.
  • Many of the programs come bundled with other unwanted programs, but even the ones free of any bundled software are not safe to use.
  • When you use them, you are downloading software from an unknown source directly onto your computer bypassing your Firewall and Anti-Virus software. Many of these Downloads are being targeted to carry infections.
For more information, please read Malware Removal Forum's Policy regarding P2P programs. P2P (peer to peer) file sharing programs must be removed.

References for the risk of these programs are:If you continue to use P2P programs, you will probably get infected again.

Please uninstall all P2P programs and post a new HijackThis log.
You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)
Malware Removal University Masters Graduate

Posted Image
Join The Fight Against Malware
No reply within 5 days will result in your topic being closed. If you need more time, please let me know by posting in this topic so that your topic will not be closed.

#6 suebaby41

suebaby41

    W.A.M. (Women Against Malware)


  • Malware Response Team
  • 6,248 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:South Carolina, USA
  • Local time:10:48 AM

Posted 12 April 2009 - 12:38 PM

Step 1
  • Please download GooredFix , making sure that you save this file to your Desktop.
  • Double-click GooredFix.exe on your Desktop (Note: If you are using Vista, right-click GooredFix and select Run As Administrator...).
  • Select Option#1 - Find Goored (no fix), by typing 1 and pressing Enter.
  • A logfile should popup shortly. Please post the log in your next reply.

You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)
Malware Removal University Masters Graduate

Posted Image
Join The Fight Against Malware
No reply within 5 days will result in your topic being closed. If you need more time, please let me know by posting in this topic so that your topic will not be closed.

#7 mrboyertown

mrboyertown
  • Topic Starter

  • Members
  • 36 posts
  • OFFLINE
  •  
  • Local time:10:48 AM

Posted 12 April 2009 - 08:50 PM

Okay did as you requested.....removed limewire and ran gooredfix and here is my log:

GooredFix v1.92 by jpshortstuff
Log created at 21:49 on 12/04/2009 running Option #1 (Mark Richards)
Firefox version [Unable to determine]

=====Suspect Goored Entries=====

=====Dumping Registry Values=====

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"jqs@sun.com"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff"


Ready for your next instructions. And Thanks again for helping me.

#8 suebaby41

suebaby41

    W.A.M. (Women Against Malware)


  • Malware Response Team
  • 6,248 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:South Carolina, USA
  • Local time:10:48 AM

Posted 14 April 2009 - 07:28 PM

Please post a new HijackThis log. Thanks.
You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)
Malware Removal University Masters Graduate

Posted Image
Join The Fight Against Malware
No reply within 5 days will result in your topic being closed. If you need more time, please let me know by posting in this topic so that your topic will not be closed.

#9 mrboyertown

mrboyertown
  • Topic Starter

  • Members
  • 36 posts
  • OFFLINE
  •  
  • Local time:10:48 AM

Posted 14 April 2009 - 09:29 PM

Here is my new Hijackthis Log:

Logfile of random's system information tool 1.06 (written by random/random)
Run by Mark Richards at 2009-04-14 22:28:05
Microsoft Windows XP Professional Service Pack 3
System drive C: has 128 GB (73%) free of 176 GB
Total RAM: 2046 MB (67% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:28:16, on 4/14/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\GEARSec.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\MotorolaDAP.exe
C:\Program Files\Norton Ghost\Agent\VProSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
C:\Program Files\Common Files\AOL\1170410798\ee\AOLSoftware.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\Norton Ghost\Agent\GhostTray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Documents and Settings\Mark Richards\Desktop\RSIT.exe
C:\Documents and Settings\Mark Richards\My Documents\HiJack This Program\Mark Richards.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.comcast.net/toolbar2.0/search/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.comcast.net/toolbar2.0/search/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer presented by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [tgcmd] C:\Program Files\Support.com\bin\tgcmd.exe /server /startmonitor /deaf
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1170410798\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Norton Ghost 10.0] "C:\Program Files\Norton Ghost\Agent\GhostTray.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" AcPro7_0_8 -reboot 1
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Registration .LNK = C:\Program Files\Ubisoft\Blazing Angels Squadrons of WWII\RegistrationReminder.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/as...abs/tgctlsr.cab
O18 - Protocol: intu-help-qb1 - {9B0F96C7-2E4B-433E-ABF3-043BA1B54AE3} - C:\Program Files\Intuit\QuickBooks 2005\HelpAsyncPluggableProtocol.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: Motorola Digital Audio Player Manager (MotorolaDAP) - Motorola Inc. - C:\WINDOWS\system32\MotorolaDAP.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton Ghost\Agent\VProSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

--
End of file - 13802 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29}]
Comcast Toolbar - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL [2006-11-14 1799680]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5CA3D70E-1895-11CF-8E15-001234567890}]
DriveLetterAccess - C:\WINDOWS\System32\DLA\DLASHX_W.DLL [2005-09-08 110652]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - c:\program files\google\googletoolbar2.dll [2007-01-19 2403392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2005-09-24 231160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-03-09 35840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-03-09 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2005-09-24 231160]
{4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - Comcast Toolbar - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL [2006-11-14 1799680]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar2.dll [2007-01-19 2403392]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2007-09-17 8491008]
"SigmatelSysTrayApp"=C:\WINDOWS\stsystra.exe [2005-03-22 339968]
"IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [2005-06-17 139264]
"DMXLauncher"=C:\Program Files\Dell\Media Experience\DMXLauncher.exe []
"RealTray"=C:\Program Files\Real\RealPlayer\RealPlay.exe [2006-06-13 26112]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2006-06-13 98304]
"ccApp"=C:\Program Files\Common Files\Symantec Shared\ccApp.exe [2005-06-02 48752]
"MimBoot"=C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe [2006-09-18 8192]
"MMTray"=C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe [2006-09-18 110592]
"ISUSPM Startup"=C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe [2005-06-10 249856]
"ISUSScheduler"=C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2005-06-10 81920]
""= []
"DLA"=C:\WINDOWS\System32\DLA\DLACTRLW.EXE [2005-09-08 122940]
"Google Desktop Search"=C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2006-06-13 169472]
"Corel Photo Downloader"=C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe [2006-02-09 106496]
"MSKDetectorExe"=C:\Program Files\McAfee\SpamKiller\MSKDetct.exe [2005-07-12 1117184]
"vptray"=C:\PROGRA~1\SYMANT~1\VPTray.exe [2005-06-23 85696]
"Acrobat Assistant 7.0"=C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe [2006-01-12 483328]
"tgcmd"=C:\Program Files\Support.com\bin\tgcmd.exe [2007-03-07 1773568]
"HostManager"=C:\Program Files\Common Files\AOL\1170410798\ee\AOLSoftware.exe [2007-10-08 41824]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
"Ad-Watch"=C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe [2009-03-07 515416]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-03-09 148888]
"Norton Ghost 10.0"=C:\Program Files\Norton Ghost\Agent\GhostTray.exe [2005-09-09 1537648]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
"updateMgr"=C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe [2006-03-30 313472]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2009-03-23 1830128]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-100000000002}\SC_Acrobat.exe
America Online 9.0 Tray Icon.lnk - C:\Program Files\America Online 9.0\aoltray.exe
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe

C:\Documents and Settings\Mark Richards\Start Menu\Programs\Startup
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
Registration .LNK - C:\Program Files\Ubisoft\Blazing Angels Squadrons of WWII\RegistrationReminder.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2008-12-22 356352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
C:\WINDOWS\system32\NavLogon.dll [2005-06-23 43712]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2008-09-06 241704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Microsoft Games\Halo\halo.exe"="C:\Program Files\Microsoft Games\Halo\halo.exe:*:Enabled:Halo"
"C:\Program Files\America Online 9.0\waol.exe"="C:\Program Files\America Online 9.0\waol.exe:*:Disabled:America Online 9.0"
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Disabled:AOL"
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe"="C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Disabled:AOL"
"C:\Program Files\Common Files\AOL\1170410798\ee\aolsoftware.exe"="C:\Program Files\Common Files\AOL\1170410798\ee\aolsoftware.exe:*:Disabled:AOL Services"
"C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Disabled:LimeWire"
"C:\StubInstaller.exe"="C:\StubInstaller.exe:*:Disabled:LimeWire swarmed installer"
"C:\WINDOWS\LMI75.tmp\lmi_rescue.exe"="C:\WINDOWS\LMI75.tmp\lmi_rescue.exe:*:Disabled:LogMeIn Rescue"
"C:\WINDOWS\LMI20C.tmp\lmi_rescue.exe"="C:\WINDOWS\LMI20C.tmp\lmi_rescue.exe:*:Disabled:LogMeIn Rescue"
"C:\Program Files\Microsoft Games\Combat Flight Simulator 3\cfs3.exe"="C:\Program Files\Microsoft Games\Combat Flight Simulator 3\cfs3.exe:*:Disabled:Microsoft® Combat Flight Simulator 3"
"C:\Documents and Settings\Mark Richards\Local Settings\Temp\7zS274.tmp\SymNRT.exe"="C:\Documents and Settings\Mark Richards\Local Settings\Temp\7zS274.tmp\SymNRT.exe:*:Disabled:Norton Removal Tool"
"C:\Novell\GroupWise\grpwise.exe"="C:\Novell\GroupWise\grpwise.exe:*:Disabled:Novell GroupWise"
"C:\Novell\GroupWise\notify.exe"="C:\Novell\GroupWise\notify.exe:*:Disabled:Novell Notify"
"C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE:*:Disabled:Outlook"
"C:\Program Files\Intuit\QuickBooks 2005\QBDBMgrN.exe"="C:\Program Files\Intuit\QuickBooks 2005\QBDBMgrN.exe:*:Disabled:QuickBooks 2008 Data Manager"
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\LMI3B.tmp\lmi_rescue.exe"="C:\WINDOWS\LMI3B.tmp\lmi_rescue.exe:*:Disabled:LogMeIn Rescue"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe"="C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL"
"C:\Program Files\America Online 9.0\waol.exe"="C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2009-04-14 21:17:38 ----A---- C:\Program Files\setup.exe
2009-04-14 20:02:13 ----D---- C:\WINDOWS\LMI3B.tmp
2009-04-11 10:31:21 ----D---- C:\rsit
2009-04-06 21:22:05 ----D---- C:\hosts
2009-04-05 07:41:55 ----A---- C:\WINDOWS\system32\tmp.txt
2009-04-05 07:41:15 ----A---- C:\WINDOWS\system32\o4Patch.exe
2009-04-05 07:41:15 ----A---- C:\WINDOWS\system32\IEDFix.C.exe
2009-04-05 07:41:15 ----A---- C:\WINDOWS\system32\Agent.OMZ.Fix.exe
2009-04-05 07:41:13 ----A---- C:\WINDOWS\system32\SrchSTS.exe
2009-04-05 07:41:13 ----A---- C:\WINDOWS\system32\Process.exe
2009-04-04 21:04:26 ----A---- C:\WINDOWS\ntbtlog.txt
2009-04-04 16:41:26 ----D---- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2009-04-04 16:41:18 ----D---- C:\Program Files\SUPERAntiSpyware
2009-04-04 16:41:17 ----D---- C:\Documents and Settings\Mark Richards\Application Data\SUPERAntiSpyware.com
2009-04-04 16:39:56 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2009-04-04 11:31:57 ----D---- C:\Documents and Settings\Mark Richards\Application Data\Malwarebytes
2009-04-04 11:31:52 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-04-04 11:31:52 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-04-02 04:37:20 ----A---- C:\WINDOWS\system32\javaws.exe
2009-04-02 04:37:20 ----A---- C:\WINDOWS\system32\javaw.exe
2009-04-02 04:37:20 ----A---- C:\WINDOWS\system32\java.exe
2009-03-29 15:15:02 ----D---- C:\Program Files\CCleaner
2009-03-26 22:42:43 ----A---- C:\Program Files\SCSSDist.ini
2009-03-26 22:42:41 ----D---- C:\Program Files\Support
2009-03-26 22:42:41 ----D---- C:\Program Files\Driver Validation
2009-03-26 22:01:28 ----D---- C:\WINDOWS\system32\appmgmt
2009-03-26 21:46:18 ----D---- C:\WINDOWS\LMI20C.tmp
2009-03-25 20:45:46 ----RA---- C:\WINDOWS\patchw32.dll
2009-03-25 20:45:09 ----RA---- C:\WINDOWS\pw32a0.dll
2009-03-21 16:46:14 ----A---- C:\WINDOWS\system32\deploytk.dll
2009-03-17 03:27:38 ----A---- C:\WINDOWS\system32\lsdelete.exe

======List of files/folders modified in the last 1 months======

2009-04-14 22:28:13 ----D---- C:\WINDOWS\Prefetch
2009-04-14 21:45:06 ----D---- C:\WINDOWS
2009-04-14 21:31:46 ----D---- C:\WINDOWS\Temp
2009-04-14 21:28:07 ----D---- C:\WINDOWS\system32\CatRoot2
2009-04-14 21:27:34 ----D---- C:\Program Files\Symantec AntiVirus
2009-04-14 21:26:51 ----A---- C:\WINDOWS\ModemLog_Conexant D850 56K V.9x DFVc Modem.txt
2009-04-14 21:25:22 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-04-14 21:24:29 ----D---- C:\WINDOWS\system32\drivers
2009-04-14 21:24:28 ----D---- C:\Program Files\Norton Ghost
2009-04-14 21:21:02 ----SHD---- C:\WINDOWS\Installer
2009-04-14 21:20:53 ----D---- C:\Program Files\Common Files\Symantec Shared
2009-04-14 21:20:49 ----D---- C:\WINDOWS\system32
2009-04-14 21:17:38 ----RD---- C:\Program Files
2009-04-14 19:24:56 ----D---- C:\WINDOWS\system32\NtmsData
2009-04-11 20:06:17 ----A---- C:\WINDOWS\win.ini
2009-04-10 15:40:56 ----D---- C:\Program Files\Dell
2009-04-06 03:00:24 ----HD---- C:\WINDOWS\inf
2009-04-06 03:00:24 ----D---- C:\WINDOWS\system32\CatRoot
2009-04-04 16:39:56 ----D---- C:\Program Files\Common Files
2009-04-03 18:35:33 ----A---- C:\WINDOWS\WPCMAPI.INI
2009-04-02 04:37:19 ----D---- C:\Program Files\Java
2009-03-29 15:48:53 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-03-29 15:29:56 ----D---- C:\WINDOWS\Debug
2009-03-29 15:29:55 ----D---- C:\WINDOWS\Minidump
2009-03-26 21:52:54 ----SHD---- C:\System Volume Information
2009-03-26 21:48:42 ----D---- C:\WINDOWS\Registration
2009-03-26 21:09:22 ----D---- C:\Documents and Settings\All Users\Application Data\Symantec
2009-03-25 21:00:21 ----D---- C:\WINDOWS\WinSxS
2009-03-25 20:58:10 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-03-17 10:32:23 ----D---- C:\Program Files\Spybot - Search & Destroy

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 DLACDBHM;DLACDBHM; C:\WINDOWS\System32\Drivers\DLACDBHM.SYS [2005-08-25 5628]
R1 DLARTL_N;DLARTL_N; C:\WINDOWS\System32\Drivers\DLARTL_N.SYS [2005-08-25 22684]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys []
R1 GearAspiWDM;GearAspiWDM; C:\WINDOWS\system32\drivers\GearAspiWDM.sys [2005-09-09 14408]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys []
R1 SAVRT;SAVRT; \??\C:\Program Files\Symantec AntiVirus\savrt.sys []
R1 SAVRTPEL;SAVRTPEL; \??\C:\Program Files\Symantec AntiVirus\Savrtpel.sys []
R1 SYMTDI;SYMTDI; C:\WINDOWS\System32\Drivers\SYMTDI.SYS [2005-04-22 267192]
R1 V2IMount;V2IMount; C:\WINDOWS\system32\drivers\V2IMount.sys [2005-09-09 56192]
R2 ASCTRM;ASCTRM; C:\WINDOWS\system32\drivers\ASCTRM.sys [2006-06-13 8552]
R2 DLABOIOM;DLABOIOM; C:\WINDOWS\System32\DLA\DLABOIOM.SYS [2005-09-08 25628]
R2 DLADResN;DLADResN; C:\WINDOWS\System32\DLA\DLADResN.SYS [2005-09-08 2496]
R2 DLAIFS_M;DLAIFS_M; C:\WINDOWS\System32\DLA\DLAIFS_M.SYS [2005-09-08 86524]
R2 DLAOPIOM;DLAOPIOM; C:\WINDOWS\System32\DLA\DLAOPIOM.SYS [2005-09-08 14684]
R2 DLAPoolM;DLAPoolM; C:\WINDOWS\System32\DLA\DLAPoolM.SYS [2005-09-08 6364]
R2 DLAUDF_M;DLAUDF_M; C:\WINDOWS\System32\DLA\DLAUDF_M.SYS [2005-09-08 87036]
R2 DLAUDFAM;DLAUDFAM; C:\WINDOWS\System32\DLA\DLAUDFAM.SYS [2005-09-08 94332]
R2 DRVNDDM;DRVNDDM; C:\WINDOWS\System32\Drivers\DRVNDDM.SYS [2005-08-12 40544]
R2 dsunidrv;DellSupport UniDriver; C:\WINDOWS\system32\DRIVERS\dsunidrv.sys [2007-02-25 5376]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2003-04-09 11043]
R2 symlcbrd;symlcbrd; \??\C:\WINDOWS\system32\drivers\symlcbrd.sys []
R3 e1express;Intel® PRO/1000 PCI Express Network Connection Driver; C:\WINDOWS\system32\DRIVERS\e1e5132.sys [2005-08-25 176128]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 HSF_DP;HSF_DP; C:\WINDOWS\system32\DRIVERS\HSF_DP.sys [2003-11-17 1042432]
R3 HSFHWBS2;HSFHWBS2; C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys [2003-11-17 212224]
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 NAVENG;NAVENG; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20090410.003\naveng.sys []
R3 NAVEX15;NAVEX15; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20090410.003\navex15.sys []
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2007-09-17 6853088]
R3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS []
R3 STHDA;SigmaTel High Definition Audio CODEC; C:\WINDOWS\system32\drivers\sthda.sys [2005-11-16 1047816]
R3 SymEvent;SymEvent; \??\C:\Program Files\Symantec\SYMEVENT.SYS []
R3 SYMREDRV;SYMREDRV; C:\WINDOWS\System32\Drivers\SYMREDRV.SYS [2005-04-22 17976]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 wanatw;WAN Miniport (ATW); C:\WINDOWS\system32\DRIVERS\wanatw4.sys [2003-01-10 33588]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2003-11-17 680704]
S3 bvrp_pci;bvrp_pci; C:\WINDOWS\system32\drivers\bvrp_pci.sys []
S3 DSproct;DSproct; \??\C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys []
S3 E100B;Intel® PRO Adapter Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2001-08-17 117760]
S3 EraserUtilDrv10910;EraserUtilDrv10910; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10910.sys []
S3 SPBBCDrv;SPBBCDrv; \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys []
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 agp440;Intel AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\agp440.sys [2008-04-13 42368]
S4 agpCPQ;Compaq AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\agpCPQ.sys [2008-04-13 44928]
S4 alim1541;ALI AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\alim1541.sys [2008-04-13 42752]
S4 amdagp;AMD AGP Bus Filter Driver; C:\WINDOWS\system32\DRIVERS\amdagp.sys [2008-04-13 43008]
S4 cbidf;cbidf; C:\WINDOWS\system32\DRIVERS\cbidf2k.sys [2001-08-17 13952]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\DRIVERS\intelide.sys [2008-04-13 5504]
S4 sisagp;SIS AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\sisagp.sys [2008-04-13 40960]
S4 viaagp;VIA AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\viaagp.sys [2008-04-13 42240]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AOL ACS;AOL Connectivity Service; C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe [2006-10-23 46640]
R2 ccEvtMgr;Symantec Event Manager; C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe [2005-06-02 185968]
R2 ccSetMgr;Symantec Settings Manager; C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe [2005-06-02 161392]
R2 DefWatch;Symantec AntiVirus Definition Watcher; C:\Program Files\Symantec AntiVirus\DefWatch.exe [2005-06-23 19648]
R2 GEARSecurity;GEARSecurity; C:\WINDOWS\System32\GEARSec.exe [2005-09-09 53248]
R2 IAANTMon;Intel® Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe [2005-06-17 86140]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-03-09 152984]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2009-03-14 951632]
R2 MotorolaDAP;Motorola Digital Audio Player Manager; C:\WINDOWS\system32\MotorolaDAP.exe [2004-08-18 270336]
R2 Norton Ghost;Norton Ghost; C:\Program Files\Norton Ghost\Agent\VProSvc.exe [2005-09-09 2066024]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2007-09-17 155716]
R2 QBCFMonitorService;QBCFMonitorService; C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe [2008-10-22 20480]
R2 Symantec AntiVirus;Symantec AntiVirus; C:\Program Files\Symantec AntiVirus\Rtvscan.exe [2005-06-23 1715904]
R2 Symantec Core LC;Symantec Core LC; C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe [2009-04-14 822424]
R2 WANMiniportService;WAN Miniport (ATW) Service; C:\WINDOWS\wanmpsvc.exe [2003-08-27 65536]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
S2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-13 267776]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2006-06-25 72704]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 ccPwdSvc;Symantec Password Validation; C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe [2005-06-02 83568]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 DSBrokerService;DSBrokerService; C:\Program Files\DellSupport\brkrsvc.exe [2007-03-07 76848]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-03-18 138168]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 LiveUpdate;LiveUpdate; C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE [2009-02-19 3220856]
S3 NetSvc;Intel NCS NetService; C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe [2004-11-19 147456]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 QBFCService;Intuit QuickBooks FCS; C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe [2007-05-24 61440]
S3 SavRoam;SAVRoam; C:\Program Files\Symantec AntiVirus\SavRoam.exe [2005-06-23 124608]
S3 SNDSrvc;Symantec Network Drivers Service; C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe [2005-04-22 206552]
S3 SPBBCSvc;Symantec SPBBCSvc; C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe [2005-03-30 992864]
S3 Symantec RemoteAssist;Symantec RemoteAssist; C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe [2008-01-29 394704]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S4 Automatic LiveUpdate Scheduler;Automatic LiveUpdate Scheduler; C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe [2009-02-19 238968]

-----------------EOF-----------------

Ready for my next instructions.

#10 mrboyertown

mrboyertown
  • Topic Starter

  • Members
  • 36 posts
  • OFFLINE
  •  
  • Local time:10:48 AM

Posted 15 April 2009 - 03:53 AM

Another weird thing that is going on with my computer that I wanted to tell you about is that, when I either turn on my computer or restart it, while the programs for windows are loading onto my desktop, a windows installer dialog box appears that says "preparing to install...." then without me doing anything it disappears within a couple of moments. It never use to do this until I started having my original problem. I dont know if this has anything to do with my original problem or if it's something completely different.

#11 suebaby41

suebaby41

    W.A.M. (Women Against Malware)


  • Malware Response Team
  • 6,248 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:South Carolina, USA
  • Local time:10:48 AM

Posted 15 April 2009 - 04:36 PM

NOTE: If for some reason you are unable to complete a step(s), skip that step and continue with the rest of the steps. Please describe your problem with the step in your next reply.

Step 1

You may want to print this page. Make sure to work through the fixes in the order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes.

Step 2

Let’s run ATF-Cleaner to ensure no malware is hiding in temporary folders and for general computer cleanup to free space on your computer.
  • Please download the ATF-Cleaner by Atribune.
  • Double-click ATF-Cleaner.exe to run the program.
  • Check the boxes to the left of:
    • Windows Temp
    • Current User Temp
    • All Users Temp
    • Temporary Internet Files
    • Prefetch (Windows XP) only
    • Java Cache
  • The rest are optional - if you want to remove them all, check Select All.
  • Click the Empty Selected button.
  • When you get the Done Cleaning message, click OK.
  • Follow the same steps for Firefox or Opera. You have the option of checking No if you want to save your passwords.
  • Click Exit on the Main menu to close the program.
Step 3

In Normal Mode, run an online malware check from at least two and preferably three (one may catch something that another one may not) of the following sites
BitDefender
Kaspersky Online Virus Scanner
McAfee FreeScan
Panda's ActiveScan
Trend Micro™ HouseCall
Windows Live Safety Center Free Online Scan
WindowSecurity.com TrojanScan
When you have completed the scans, if you get a report of files that cannot be cleaned / deleted, make a note of the file location of anything that cannot be cleaned / deleted. Please edit the log(s) and remove:
  • items listed as "Object is locked skipped"
  • items reported that are in a quarantine folder
Please post the edited list in your next reply.

Step 4

I recommend using Spyware Blaster.
  • Please download SpywareBlaster and save it to your desktop.
  • Double click on it to install the program.
  • Follow the prompts and choose the default locations when installing the program.
  • When the program is installed, it will place an icon on your desktop.
  • Double click on the SpywareBlaster icon and you will be presented with a brief tutorial. On the first page of this tutorial, you will see some of the SpywareBlaster features
  • Click on the Next button to proceed to the second page of the tutorial.
  • If you want to purchase the software, then you should select Automatic Updating. If you do not plan on purchasing the software, then you should select the option for Manual Updating. Press the Next button.
  • At the next screen, click Finish.
  • At the next screen, Protection Status, click Enable All Protection.
  • Click Download Latest Protection Updates. This will ensure that SpywareBlaster has the latest definitions so that it can protect your browser more efficiently. You should update SpywareBlaster regularly, as much as every few days, in order to provide the best protection. Each time you update, be sure to click Enable All Protection.
Step 5

Malwarebytes' Anti-Malware is FREEWARE, however you may upgrade to the PRO version which contains realtime protection, scheduled scanning and updating.
  • Please download Malwarebytes Anti-Malware (MBAM). Alternate download link
  • Double-click on Download_mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Click Finish.
  • MBAM will automatically start and you will be asked to update the program before performing scan. If an update is found, the program will automatically update itself.
  • Press the OK button to close that box and continue. If you encounter any problems while downloading the updates, manually download them from the Malware Bytes Web site. Scroll down the page until you see Latest Database; click Download from GT500.org
  • Double-click on mbam-rules.exe to install.
  • On the Scanner tab, make sure the Perform Quick Scan option is selected.
  • Click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and Scan in progress will show at the top. It may take some time to complete; please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully.
  • At the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
  • Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.
Step 6

Check your computer with anti-rootkit applications. I recommend avast! antirootkit or Trend Micro RootkitBuster.

Step 7

Check to see if you have insecure applications with
Secunia Software Inspector. Secunia Software Inspector:
  • Detects insecure versions of common/popular programs installed on your computer.
  • Verifies that all Microsoft patches are applied.
  • Assists you in updating, patching, and protecting your computer.
  • Activates additional security features in Sun Java.
  • Runs through your browser. No installation or download is required.
Step 8

Optional Fixes is the name that we use for fixes for unnecessary programs that load during startup and run in the background. These programs are not required to start automatically as you can start them manually if you need them. You would be removing the program from your startup but you would not be removing the program itself.

Your computer may be sluggish due to the many programs loading during startup and running in the background that are not necessary. Windows has a facility for starting programs at startup time. Some of these programs are required for your computer and the applications installed on it to run correctly. A good example of such a program is a virus-checking application that must always run, constantly checking for and isolating or removing files with viruses. Other such programs are not strictly required, or are optional. In some cases, you can gain significant performance enhancements by disabling the automatic startup of these programs. In many cases, the functionality offered by the programs is still available by starting the programs manually by, for example, starting the program from the Windows Start->Programs menu. Media players and instant messaging programs often fall into this category. In fact, it is common for many modern software applications, when installed, to add programs at startup that add items to the system tray or shortcut (context) menus in Windows Explorer to provide quick access to the features and functions of these applications. While they may be useful, they do increase boot time and consume system resources. It is advised that you disable these programs so that they do not take up necessary resources or slow the boot time.

Other than ScanRegistry, SystemTray, StateMgr, antivirus program entries, and firewall program entries, very few others need to load and run.

Read the articles below to see if it applies to your computer problem with being slow to respond.
Slow_Computer_Check_here_first_it_may_not_be_malware.
Help! My computer is slow!
50 Tips for a Super Fast PC
4 Ways to Speed Up Your Computer's Performance
It's not always malware: How to fix the top 10 Internet Explorer issues

If you decide that you want to stop the Optional Fixes in your startup, let me know and I will give you a list with instructions. You would be removing the program from your startup but you would not be removing the program itself.

Step 9

Please run HijackThis in Normal Mode and post:
  • the list of file names and locations for any files that cannot be cleaned / deleted that were reported after you completed the online scans.
  • the log from MalwareBytes
  • a new HijackThis log
Please advise me of any problems you still have.
You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)
Malware Removal University Masters Graduate

Posted Image
Join The Fight Against Malware
No reply within 5 days will result in your topic being closed. If you need more time, please let me know by posting in this topic so that your topic will not be closed.

#12 mrboyertown

mrboyertown
  • Topic Starter

  • Members
  • 36 posts
  • OFFLINE
  •  
  • Local time:10:48 AM

Posted 19 April 2009 - 01:59 PM

Sorry it has taken so long for me to get back to you. I've been a little busy. Anyway I followed are your steps and have some questions regarding what the scans found and whether I should be fixing these things or not.

Here is the log from panda security. Just wondereing what I should do with what this program has found. Since you have to pay to have activescan 2.0 disinfect these files, how do I do it manually? Do I just search for the files that are in the log and delete them myself? And do I even have to delete these files?
ANALYSIS: 2009-04-18 06:37:52
PROTECTIONS: 2
MALWARE: 4
SUSPECTS: 1
;***********************************************************************************************************************************************************************************
PROTECTIONS
Description Version Active Updated
;===================================================================================================================================================================================
McAfee VirusScan Yes Yes
Symantec AntiVirus Corporate Edition 10.0.1.1000 Yes Yes
;===================================================================================================================================================================================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===================================================================================================================================================================================
00139059 Cookie/Traffic Marketplace TrackingCookie No 0 Yes No C:\Documents and Settings\Mark Richards\Cookies\mark_richards@trafficmp[1].txt
00167642 Cookie/Com.com TrackingCookie No 0 Yes No C:\Documents and Settings\Mark Richards\Cookies\mark_richards@com[1].txt
00484705 Application/IEDefender HackTools No 0 Yes No C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073250.exe
00484705 Application/IEDefender HackTools No 0 Yes No C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1024\A0073989.exe
00484705 Application/IEDefender HackTools No 0 Yes No C:\WINDOWS\system32\IEDFix.C.exe
01048936 Generic Malware Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1025\A0074174.dll
01048936 Generic Malware Virus/Trojan No 0 Yes No C:\Program Files\GameSpy Arcade\Services\_common\PortraitLoader.dll
;===================================================================================================================================================================================
SUSPECTS
Sent Location R
;===================================================================================================================================================================================
No C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1023\A0073778.exe[²èÇ]
;===================================================================================================================================================================================
VULNERABILITIES
Id Severity Description R
;===================================================================================================================================================================================
;===================================================================================================================================================================================


Then I ran avast antiroot kit software and here is the log for it. Should I be manually deleting these files also? They are a bunch of system restore files and I dont know if it is okay to delete these files or not. (And if I should delete these files, do I just search for them using the search tool and delete?)
avast! Antirootkit, version 0.9.6
Scan started: Saturday, April 18, 2009 7:19:23

File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1000\A0072231.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1001\A0072241.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1001\A0072244.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1001\A0072246.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1001\A0072247.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1001\A0072249.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1001\A0072250.SYS **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1001\A0072252.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1001\A0072253.SYS **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1001\A0072255.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1001\A0072261.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1001\A0072270.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1001\A0072476.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1001\A0072477.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1001\A0072482.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1002\A0072530.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1003\A0072574.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1003\A0072578.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1004\A0072630.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1004\A0072634.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072688.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072689.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072690.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072691.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072692.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072693.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072694.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072695.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072696.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072697.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072698.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072699.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072700.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072701.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072702.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072703.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072704.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072705.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072706.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072707.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072708.cpl **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072709.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072710.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072711.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072712.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072713.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072714.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072715.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072716.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072717.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072718.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072719.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072720.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072721.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072722.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072723.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072724.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072725.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072726.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072727.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072728.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072729.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072730.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072731.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072732.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072733.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072734.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072735.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072736.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072737.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072738.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072739.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072740.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072741.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072742.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072743.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072744.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072745.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072746.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072747.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072748.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072749.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072750.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072751.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072752.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072753.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072754.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072755.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072756.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072757.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072758.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072759.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072760.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072761.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072762.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072763.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072764.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072765.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072766.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072767.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072768.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072769.cpl **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072771.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072772.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072773.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072774.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072775.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072785.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1006\A0072789.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1007\A0072834.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1007\A0072838.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1007\A0072872.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1007\A0072874.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1007\A0072875.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1007\A0072877.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1007\A0072878.SYS **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1007\A0072880.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1007\A0072881.SYS **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1007\A0072883.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1008\A0072910.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1008\A0072917.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1008\A0072918.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1008\A0072925.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1009\A0072940.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1009\A0072943.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1009\A0072948.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1009\A0072956.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1009\A0072960.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1010\A0072987.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1010\A0072991.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1010\A0072999.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1010\A0073006.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1011\A0073032.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1011\A0073036.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1011\A0073043.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1011\A0073048.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1011\A0073049.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1011\A0073050.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1011\A0073051.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1011\A0073052.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1011\A0073053.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1011\A0073057.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1011\A0073067.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1011\A0073069.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1011\A0073078.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1011\A0073082.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1012\A0073088.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1012\A0073092.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1012\A0073097.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1012\A0073102.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1012\A0073132.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1013\A0073136.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1013\A0073140.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1013\A0073145.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1013\A0073146.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1013\A0073151.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1013\A0073152.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1013\A0073159.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1013\A0073164.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1013\A0073166.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073169.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073191.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073195.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073200.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073223.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073228.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073233.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073236.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073237.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073238.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073239.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073241.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073242.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073243.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073244.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073246.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073247.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073248.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073249.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073250.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073251.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073252.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073253.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073254.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073255.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073256.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073257.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073259.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073260.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073261.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073262.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073263.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073264.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073265.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073266.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073267.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073268.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073269.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073270.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073271.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073272.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073273.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073277.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1014\A0073281.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1015\A0073291.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1015\A0073293.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1015\A0073294.SYS **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1015\A0073296.SYS **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1015\A0073297.SYS **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1015\A0073298.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1015\A0073299.SYS **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1015\A0073301.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1015\A0073307.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1015\A0073309.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1015\A0073310.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1015\A0073312.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1015\A0073313.SYS **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1015\A0073315.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1015\A0073316.SYS **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1015\A0073318.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1015\A0073324.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1015\A0073344.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1016\A0073371.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1016\A0073380.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1016\A0073384.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1016\A0073389.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1017\A0073402.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1017\A0073405.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1017\A0073406.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1017\A0073407.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1017\A0073409.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1017\A0073414.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1017\A0073415.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1017\A0073417.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1017\A0073422.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1017\A0073424.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1017\A0073427.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1017\A0073431.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1017\A0073438.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1018\A0073454.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1018\A0073456.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1018\A0073460.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1018\A0073465.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1019\A0073477.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1019\A0073478.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1019\A0073479.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1019\A0073480.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1019\A0073481.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1019\A0073482.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1019\A0073483.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1019\A0073484.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1019\A0073485.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073487.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073488.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073489.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073490.EXE **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073491.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073492.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073493.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073494.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073495.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073496.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073497.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073498.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073499.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073500.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073501.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073502.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073503.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073504.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073505.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073506.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073507.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073508.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073509.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073510.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073511.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073512.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073513.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073514.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073515.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073516.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073517.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073519.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073520.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073521.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073522.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073523.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073524.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073525.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073526.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073527.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073528.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073529.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073530.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073531.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073534.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073535.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073536.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073537.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073538.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073539.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073540.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073541.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073542.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073543.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073544.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073545.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073546.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073547.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073548.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073549.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073550.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073551.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073552.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073553.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073554.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073555.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073556.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073557.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073558.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073559.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073560.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073561.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073562.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073563.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073564.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073565.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073566.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073567.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073568.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073570.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073571.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073572.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073573.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073575.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073576.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073577.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073578.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073579.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073580.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073582.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073583.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073585.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073586.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073587.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073588.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073594.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073595.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073596.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073597.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073598.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073603.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073604.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073612.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073617.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073618.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073619.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073620.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073621.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073622.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073623.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073624.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073625.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073626.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073627.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073628.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073629.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073630.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073631.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073632.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073633.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073634.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073635.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073636.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073637.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073640.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073641.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073642.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073643.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073644.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073645.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\A0073646.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1021\A0073650.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1021\A0073653.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1021\A0073660.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1021\A0073664.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1021\A0073665.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1021\A0073673.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1021\A0073681.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1021\A0073682.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1021\A0073683.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1021\A0073687.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1021\A0073692.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1021\A0073697.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1021\A0073699.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1021\A0073700.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1021\A0073702.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1021\A0073703.SYS **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1021\A0073705.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1021\A0073706.SYS **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1021\A0073708.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1021\A0073717.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1021\A0073723.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1021\A0073730.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1021\A0073732.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1022\A0073765.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1023\A0073778.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1023\A0073781.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1023\A0073782.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1023\A0073783.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1023\A0073784.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1023\A0073785.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1023\A0073786.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1023\A0073787.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1023\A0073788.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1023\A0073789.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1023\A0073790.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1023\A0073791.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1023\A0073792.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1023\A0073793.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1023\A0073794.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1023\A0073795.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1023\A0073796.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1023\A0073797.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1023\A0073798.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1023\A0073799.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1023\A0073800.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1023\A0073801.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1023\A0073802.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1023\A0073803.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1023\A0073804.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1024\A0073915.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1024\A0073956.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1024\A0073961.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1024\A0073989.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1024\A0073996.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1024\A0073998.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1025\A0074017.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1025\A0074019.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1025\A0074020.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1025\A0074022.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1025\A0074023.SYS **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1025\A0074025.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1025\A0074026.SYS **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1025\A0074028.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1025\A0074034.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1025\A0074036.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1025\A0074037.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1025\A0074038.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1025\A0074041.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1025\A0074042.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1025\A0074043.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1025\A0074044.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1025\A0074045.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1025\A0074174.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1025\A0074175.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1025\A0074194.EXE **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1025\A0074198.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP921\A0067567.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP921\A0067605.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP921\A0067609.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP922\A0067620.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP922\A0067622.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP922\A0067626.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP923\A0067644.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP923\A0067648.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP923\A0067652.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP924\A0067800.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP924\A0067804.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP924\A0067808.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP925\A0067829.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP925\A0067831.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP925\A0067832.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP925\A0067834.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP925\A0067835.SYS **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP925\A0067837.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP925\A0067838.SYS **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP925\A0067840.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP925\A0067846.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP925\A0067849.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP925\A0067855.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP926\A0067870.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP926\A0068852.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP926\A0068856.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP927\A0068893.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP927\A0068894.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP927\A0068898.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP927\A0068899.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP927\A0068902.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP927\A0068903.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP927\A0068906.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP927\A0068907.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP927\A0068910.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP927\A0068911.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP927\A0068914.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP927\A0068915.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP927\A0068918.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP927\A0068919.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP927\A0068922.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP927\A0068923.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP927\A0068926.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP927\A0068927.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP927\A0068930.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP927\A0068931.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP927\A0068934.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP927\A0068935.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP927\A0068938.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP927\A0068939.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP927\A0068942.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP927\A0068943.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP927\A0068946.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP927\A0068947.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP927\A0068950.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP927\A0068951.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP927\A0068954.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP927\A0068958.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP927\A0068986.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP927\A0068998.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP928\A0069011.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP928\A0069012.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP928\A0069020.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP929\A0069026.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP929\A0069027.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP929\A0069031.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP930\A0069039.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP930\A0069040.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP930\A0069044.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP931\A0069058.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP931\A0069062.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP931\A0069066.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP932\A0069129.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP932\A0069131.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP932\A0069132.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP932\A0069134.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP932\A0069135.SYS **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP932\A0069137.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP932\A0069138.SYS **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP932\A0069140.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP932\A0069146.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP932\A0069147.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP932\A0069148.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP932\A0069149.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP932\A0069150.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP932\A0069151.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP932\A0069152.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP933\A0069161.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP934\A0069177.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP934\A0069179.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP934\A0069183.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP935\A0069197.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP935\A0069199.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP935\A0069203.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP936\A0069213.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP936\A0069215.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP936\A0069223.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP937\A0069229.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP937\A0069231.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP937\A0069235.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP938\A0069293.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP938\A0069297.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP938\A0069301.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP938\A0069310.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP938\A0069312.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP938\A0069313.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP938\A0069315.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP938\A0069316.SYS **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP938\A0069318.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP938\A0069319.SYS **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP938\A0069321.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP939\A0069327.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP940\A0069337.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP941\A0069369.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP941\A0069373.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP942\A0069393.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP942\A0069395.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP942\A0069399.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP943\A0069410.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP943\A0069414.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP943\A0069423.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP943\A0069424.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP943\A0069425.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP944\A0069430.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP945\A0069490.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP945\A0069510.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP945\A0069524.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP945\A0069530.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP945\A0069532.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP945\A0069533.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP945\A0069535.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP945\A0069536.SYS **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP945\A0069538.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP945\A0069539.SYS **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP945\A0069541.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP946\A0069549.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP947\A0069565.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP947\A0069574.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP947\A0069578.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP948\A0069584.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP948\A0069594.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP948\A0069598.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP949\A0069627.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP949\A0069628.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP949\A0069632.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP950\A0069644.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP950\A0069645.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP950\A0069649.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP951\A0069662.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP951\A0069663.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP951\A0069667.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP952\A0069679.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP952\A0069681.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP952\A0069682.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP952\A0069684.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP952\A0069685.SYS **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP952\A0069687.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP952\A0069688.SYS **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP952\A0069690.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP952\A0069696.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP952\A0069697.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP953\A0069700.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP954\A0069711.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP954\A0069717.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP954\A0069721.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP955\A0069740.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP955\A0069742.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP955\A0069746.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP956\A0069759.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP957\A0069764.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP957\A0069773.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP958\A0069796.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP958\A0069800.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP959\A0069823.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP959\A0069824.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP959\A0069828.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP960\A0069851.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP960\A0069863.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP960\A0069867.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP960\A0069881.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP960\A0069883.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP960\A0069884.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP960\A0069886.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP960\A0069887.SYS **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP960\A0069889.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP960\A0069890.SYS **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP960\A0069892.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP960\A0069898.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP961\A0069926.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP962\A0069936.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP963\A0069938.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP964\A0069944.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP964\A0069947.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP964\A0069951.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP965\A0069978.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP965\A0069982.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP966\A0070022.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP967\A0070036.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP967\A0070040.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP967\A0070051.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP967\A0070053.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP967\A0070054.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP967\A0070056.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP967\A0070057.SYS **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP967\A0070059.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP967\A0070060.SYS **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP967\A0070062.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP967\A0070068.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP968\A0070084.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP968\A0070085.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP968\A0070089.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP968\A0070097.new **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP968\A0070098.new **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP968\A0070099.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP968\A0070100.old **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP968\A0070101.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP968\A0070102.old **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP968\A0070103.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP968\A0070114.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP968\A0070115.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP968\A0070116.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP968\A0070117.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP968\A0070118.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP968\A0070119.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP968\A0070120.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP968\A0070121.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP968\A0070122.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP968\A0070123.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP968\A0070124.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP968\A0070125.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP968\A0070126.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP968\A0070127.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP968\A0070128.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP968\A0070129.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP968\A0070130.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP968\A0070131.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP968\A0070132.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP968\A0070133.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP968\A0070134.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP968\A0070135.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP968\A0070136.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP968\A0070137.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP968\A0070138.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP968\A0070139.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP968\A0070140.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP968\A0070141.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP968\A0070142.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP968\A0070143.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP968\A0070149.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP969\A0070173.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP969\A0070177.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP970\A0070204.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP971\A0070224.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP971\A0070228.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP972\A0070262.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP972\A0070266.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070306.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070308.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070309.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070310.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070311.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070312.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070313.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070314.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070315.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070316.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070317.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070318.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070319.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070320.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070321.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070322.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070323.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070324.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070325.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070326.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070327.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070328.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070329.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070330.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070331.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070332.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070333.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070334.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070335.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070336.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070337.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070338.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070339.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070343.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070346.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070353.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070354.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070355.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070356.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070357.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070358.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070360.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070361.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070362.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070379.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070380.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070381.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP973\A0070382.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070418.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070419.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070420.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070421.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070426.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070429.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070459.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070461.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070462.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070463.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070464.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070465.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070466.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070467.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070469.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070470.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070471.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070472.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070474.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070475.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070476.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070477.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070479.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070480.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070481.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070483.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070484.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070539.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070540.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070541.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070542.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070543.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070544.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070545.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070546.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070547.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070548.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070549.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070550.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070551.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070552.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070553.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070556.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070557.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP974\A0070558.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP975\A0070587.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP975\A0070597.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP976\A0070633.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP976\A0070638.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP976\A0070639.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP976\A0070640.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP976\A0070641.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP976\A0070642.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP976\A0070643.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP976\A0070644.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP976\A0070645.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP976\A0070646.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP976\A0070647.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP976\A0070648.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP976\A0070649.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP976\A0070650.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP976\A0070651.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP976\A0070652.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP976\A0070653.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP976\A0070654.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP976\A0070655.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP976\A0070656.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP976\A0070657.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP976\A0070658.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP976\A0070659.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP976\A0070660.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070665.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070667.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070671.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070873.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070874.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070875.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070876.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070877.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070878.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070879.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070880.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070881.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070882.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070883.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070884.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070885.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070886.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070887.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070888.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070889.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070890.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070891.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070892.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070893.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070894.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070895.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070896.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070897.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070898.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070899.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070900.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070901.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070902.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070903.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070904.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070905.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070906.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070907.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070908.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070909.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070910.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070911.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070912.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070913.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070914.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070915.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070916.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070917.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070918.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070919.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070920.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070921.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070922.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070923.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070924.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070925.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070926.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070927.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070928.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070929.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070930.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070931.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070932.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070933.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070934.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070935.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070936.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070937.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070938.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070939.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070940.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070941.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070942.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070943.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070944.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070945.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070946.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070947.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070948.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070949.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070950.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070951.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070952.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070953.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070954.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070955.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070956.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070957.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070958.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070959.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070960.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070961.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070962.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070963.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070964.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070965.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070966.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070967.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070968.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070969.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070970.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070971.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070972.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070973.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070974.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070975.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070976.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070977.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070978.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070979.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070980.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070981.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070982.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070983.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070984.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070985.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070986.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070987.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070988.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070989.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070990.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070991.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070992.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070993.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070994.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070995.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070996.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070997.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070998.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0070999.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071000.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071001.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071002.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071003.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071004.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071005.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071006.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071007.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071008.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071009.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071010.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071011.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071012.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071013.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071014.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071015.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071016.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071017.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071018.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071019.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071020.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071021.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071022.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071023.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071024.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071025.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071026.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071027.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071028.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071029.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071030.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071031.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071032.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071033.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071034.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071035.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071036.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071037.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071038.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071039.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071040.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071041.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071042.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071043.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071044.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071045.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071046.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071047.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071048.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071049.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071050.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071051.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071052.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071053.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071054.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071055.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071056.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071057.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071058.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071059.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071060.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071061.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071062.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071063.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071064.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071065.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071066.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071067.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071068.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071069.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071070.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071071.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071072.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071073.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071074.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071075.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071076.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071077.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071078.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071079.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071080.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071081.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071082.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071083.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071084.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071085.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071086.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071087.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071088.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071089.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071090.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071091.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071092.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071093.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071094.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071095.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071096.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071097.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071098.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071099.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071100.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071101.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071102.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP977\A0071106.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP978\A0071132.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP978\A0071136.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP978\A0071154.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP978\A0071156.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP978\A0071157.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP978\A0071159.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP978\A0071160.SYS **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP978\A0071162.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP978\A0071163.SYS **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP978\A0071165.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP979\A0071186.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP979\A0071188.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP979\A0071189.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP979\A0071243.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP979\A0071246.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP979\A0071250.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP980\A0071270.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP981\A0071296.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP981\A0071300.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP982\A0071327.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP982\A0071329.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP982\A0071330.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP982\A0071332.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP982\A0071333.SYS **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP982\A0071335.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP982\A0071336.SYS **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP982\A0071338.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP982\A0071344.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP982\A0071347.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP982\A0071348.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP982\A0071349.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP982\A0071352.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP982\A0071353.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP982\A0071354.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP982\A0071407.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP982\A0071410.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP982\A0071411.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP982\A0071412.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP982\A0071413.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP982\A0071414.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP982\A0071415.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP982\A0071416.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP982\A0071417.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP982\A0071418.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP982\A0071419.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP982\A0071420.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP982\A0071431.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP982\A0071436.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP982\A0071440.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP983\A0071468.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP983\A0071472.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP984\A0071498.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP984\A0071502.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP985\A0071539.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP985\A0071543.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP985\A0071555.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP985\A0071557.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP985\A0071558.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP985\A0071560.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP985\A0071561.SYS **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP985\A0071563.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP985\A0071564.SYS **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP985\A0071566.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP986\A0071588.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP986\A0071597.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP986\A0071601.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP987\A0071612.cpl **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP987\A0071613.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP987\A0071614.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP987\A0071615.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP987\A0071621.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP988\A0071641.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP988\A0071646.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP988\A0071650.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP990\A0071698.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP990\A0071702.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP990\A0071716.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP990\A0071717.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP990\A0071718.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071738.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071742.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071761.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071763.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071764.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071766.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071767.SYS **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071769.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071770.SYS **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071772.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071778.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071784.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071785.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071786.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071787.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071788.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071789.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071790.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071791.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071792.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071793.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071794.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071795.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071796.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071797.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071798.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071799.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071800.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071801.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071802.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071803.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071804.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071805.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071806.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071807.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071808.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071809.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071810.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071811.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071812.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071813.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071814.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071815.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071816.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071817.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071818.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071819.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071820.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071821.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071822.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071823.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071824.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071825.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071826.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071827.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071828.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071829.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071830.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071831.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071832.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071833.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071834.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071835.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071836.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071837.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071838.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071839.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071840.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071841.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071842.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071844.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071845.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071846.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP991\A0071847.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP992\A0071850.EXE **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP992\A0071851.EXE **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP992\A0071852.EXE **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP992\A0071853.EXE **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP992\A0071854.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP992\A0071855.EXE **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP992\A0071857.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP992\A0071859.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP992\A0071860.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP992\A0071861.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP992\A0071862.EXE **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP992\A0071863.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP992\A0071864.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP992\A0071865.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP992\A0071866.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP992\A0071867.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP992\A0071868.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP992\A0071869.CPL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP992\A0071870.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP992\A0071871.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP992\A0071872.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP992\A0071873.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP992\A0071874.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP992\A0071875.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP992\A0071878.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP992\A0071879.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP992\A0071880.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP992\A0071881.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP992\A0071882.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP992\A0071883.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP992\A0071884.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP992\snapshot\MFEX-1.DAT **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP992\snapshot\MFEX-2.DAT **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP992\snapshot\MFEX-3.DAT **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP992\snapshot\MFEX-4.DAT **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP992\snapshot\MFEX-5.DAT **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP992\snapshot\MFEX-6.DAT **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP992\snapshot\MFEX-7.DAT **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP993\A0071888.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP993\A0071889.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP993\A0071890.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP993\A0071891.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP993\A0071892.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP993\A0071893.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP993\A0071894.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP993\A0071895.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP993\A0071896.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP993\A0071897.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP993\A0071898.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP993\A0071902.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP993\A0071909.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP993\A0071910.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP993\A0071911.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP993\A0071912.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP993\A0071913.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP993\A0071914.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP993\A0071915.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP993\snapshot\MFEX-1.DAT **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP993\snapshot\MFEX-2.DAT **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP993\snapshot\MFEX-3.DAT **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP993\snapshot\MFEX-4.DAT **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP993\snapshot\MFEX-5.DAT **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP993\snapshot\MFEX-6.DAT **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP993\snapshot\MFEX-7.DAT **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP994\A0071933.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP994\A0071937.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP995\A0071963.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP995\A0071968.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP995\A0071978.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP995\A0071979.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP995\A0071980.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP995\A0071981.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP995\A0071982.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP995\A0071983.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP995\A0071984.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP996\A0071988.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP996\A0071990.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP996\A0071992.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP996\A0071993.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP996\A0071994.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP996\A0071995.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP996\A0071996.EXE **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP996\A0072002.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP996\A0072004.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP996\A0072005.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP996\A0072006.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP996\A0072007.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP996\A0072008.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP996\A0072009.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP996\A0072010.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072015.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072016.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072017.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072018.EXE **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072019.EXE **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072020.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072021.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072022.EXE **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072023.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072024.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072025.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072026.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072027.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072028.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072029.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072030.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072031.EXE **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072032.EXE **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072033.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072034.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072035.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072036.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072037.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072038.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072039.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072040.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072041.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072043.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072044.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072045.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072046.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072048.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072049.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072050.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072051.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072052.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072053.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072054.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072055.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072056.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072057.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072058.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072059.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072060.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072061.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072062.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072063.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072064.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072065.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072066.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072067.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072068.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072069.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072070.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072071.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072072.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072073.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072075.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072076.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072077.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072078.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072080.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072081.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072082.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072083.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072084.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072086.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072087.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072093.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072094.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072095.EXE **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072096.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072097.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072098.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072099.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072100.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072105.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072106.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072107.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072108.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072109.rbf **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072123.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072129.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072130.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072131.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072132.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072133.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072134.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP997\A0072135.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP998\A0072139.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP998\A0072142.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP998\A0072151.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP998\A0072152.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP998\A0072158.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP999\A0072175.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP999\A0072179.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP999\A0072180.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP999\A0072181.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP999\A0072182.exe **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP999\A0072183.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP999\A0072187.dll **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP999\A0072197.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP999\A0072199.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP999\A0072200.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP999\A0072202.sys **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP999\A0072203.SYS **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP999\A0072205.DLL **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP999\A0072206.SYS **HIDDEN**
File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP999\A0072208.DLL **HIDDEN**

Scan finished: Saturday, April 18, 2009 7:39:20
Hidden files found: 1420
Hidden registry items found: 0
Hidden processes found: 0
Hidden services found: 0
Hidden boot sectors found: 0


----------

Then I also ran the Trend Micro Rootkit Buster program which found nothing? Thats why Im not sure if I should be deleting what AVAST ANTIROOT has found or not? Heres the log from Trend Micro:
+----------------------------------------------------
| Trend Micro RootkitBuster
| Module version: 2.52.0.1013
+----------------------------------------------------


--== Dump Hidden MBR and Hidden File on C:\ ==--
No hidden files found.


--== Dump Hidden Registry Value on HKLM ==--
No hidden registry entries found.


--== Dump Hidden Process ==--
No hidden processes found.

--== Dump Hidden Driver ==--
No hidden drivers found.

Regarding Step #8 I would like to recieve the instructions on how to use optional fixes to remove the programs that are automatically starting in Windows that do not have to be there. It would be greatly appreciated.

Here is my latest MalwareBytes log:

Malwarebytes' Anti-Malware 1.36
Database version: 2009
Windows 5.1.2600 Service Pack 3

4/19/2009 12:21:52 PM
mbam-log-2009-04-19 (12-21-52).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 180583
Time elapsed: 53 minute(s), 11 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


And here is my latest hijackthis log: (What is the difference from using RSIT.exe and HijackThis?.....Do I need to keep the RSIT.exe file I have saved on my desktop?)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:52:41, on 4/19/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\Common Files\AOL\1170410798\ee\AOLSoftware.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\GEARSec.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Norton Ghost\Agent\GhostTray.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\MotorolaDAP.exe
C:\Program Files\Norton Ghost\Agent\VProSvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Documents and Settings\Mark Richards\Local Settings\Temporary Internet Files\Content.IE5\ZM7YTDZA\aswar[1].exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Mark Richards\My Documents\HiJack This Program\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.comcast.net/toolbar2.0/search/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.comcast.net/toolbar2.0/search/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer presented by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [tgcmd] C:\Program Files\Support.com\bin\tgcmd.exe /server /startmonitor /deaf
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1170410798\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Norton Ghost 10.0] "C:\Program Files\Norton Ghost\Agent\GhostTray.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" AcPro7_0_8 -reboot 1
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Registration .LNK = C:\Program Files\Ubisoft\Blazing Angels Squadrons of WWII\RegistrationReminder.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/as...abs/tgctlsr.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase5483.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O18 - Protocol: intu-help-qb1 - {9B0F96C7-2E4B-433E-ABF3-043BA1B54AE3} - C:\Program Files\Intuit\QuickBooks 2005\HelpAsyncPluggableProtocol.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: Motorola Digital Audio Player Manager (MotorolaDAP) - Motorola Inc. - C:\WINDOWS\system32\MotorolaDAP.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton Ghost\Agent\VProSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

--
End of file - 14785 bytes

#13 suebaby41

suebaby41

    W.A.M. (Women Against Malware)


  • Malware Response Team
  • 6,248 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:South Carolina, USA
  • Local time:10:48 AM

Posted 20 April 2009 - 12:14 PM

I was diagnosed Friday with Trigger thumb which is a condition in which my thumb catches in a bent position. My thumb straightens with a snap — like a trigger being pulled and released. It can cause my finger to become locked in a bent position. It is very painful. I am wearing a brace on my left hand.

I can still type and plan to continue working your log. Please be patient as it does slow me down.
You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)
Malware Removal University Masters Graduate

Posted Image
Join The Fight Against Malware
No reply within 5 days will result in your topic being closed. If you need more time, please let me know by posting in this topic so that your topic will not be closed.

#14 suebaby41

suebaby41

    W.A.M. (Women Against Malware)


  • Malware Response Team
  • 6,248 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:South Carolina, USA
  • Local time:10:48 AM

Posted 20 April 2009 - 03:06 PM

Here is the log from panda security. Just wondereing what I should do with what this program has found. Since you have to pay to have activescan 2.0 disinfect these files, how do I do it manually? Do I just search for the files that are in the log and delete them myself? And do I even have to delete these files?
Then I ran avast antiroot kit software and here is the log for it. Should I be manually deleting these files also? They are a bunch of system restore files and I dont know if it is okay to delete these files or not. (And if I should delete these files, do I just search for them using the search tool and delete?)

Do not pay for anything. Online scans are used to identify the location of the malware.

The System Volume Information folder is a hidden system folder that the System Restore tool uses to store its information and restore points. There is a System Volume Information folder on every partition on your computer. When we get your computer cleaned, we will disable and enable System Restore which will delete all files in the System Volume Information folder.

Regarding Step #8 I would like to recieve the instructions on how to use optional fixes to remove the programs that are automatically starting in Windows that do not have to be there. It would be greatly appreciated.

By fixing the "Optional Fixes", you will remove the program from your startup but you will not remove the program itself. Note the large number of startup items. This adversely affects the bootup time and computer speed with this large amount of unnecessary programs loading at startup and then running in the background.

Please run HijackThis and click Scan. Place checks next to the HijackThis entries that are Optional Fixes that you have chosen to remove from your startup list.

NvCpl.dll,NvStartup initializes the clock and memory settings on nVidia based graphics cards. Enable if you overclock your card. This program is not required to start automatically as you can start it manually if you need it. It is advised that you disable this program so that it does not take up necessary resources. It may be worthwhile to fix it with HijackThis. Item(s) to fix in HijackThis:

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

stsystra.exe (Sigmatel Audio sound card) process can be removed to free up resources without compromising system performance. SigmatelSysTrayApp is the system tray program for the Sigmatel Audio sound card. Often found on Dell computers. This is a valid program but it is not required to run on startup. This program is not required to start automatically as you can start it manually if you need it. It is advised that you disable this program so that it does not take up necessary resources. Many users have reported this process slows their boot time. It may be worthwhile to fix it with HijackThis. Item(s) to fix in HijackThis:

O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe

iaanotif.exe (Intel® Application Accelerator) process can be removed to free up resources without compromising system performance. iaanotif.exe is the IAA Event Monitor User Notification Tool - part of - "a performance software package for desktop PCs using select Intel® chipsets" that "replaces the ATA drivers that come with Windows with drivers optimized for desktop and mobile PCs." If you use the RAID version, it's required to notify you if a RAID 1 disk has failed. Whether or not you need to run this program on startup must be decided by you. If you feel that you want this program starting automatically so that you have it available as needed, then do not disable it. This program is not required to start automatically as you can start it manually if you need it. It is advised that you disable this program so that it does not take up necessary resources. Many users have reported this process slows their boot time. It may be worthwhile to fix it with HijackThis. Item(s) to fix in HijackThis:

O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe

DMXLauncher.exe (Dell's Media Experience) process can be removed to free up resources without compromising system performance. It is part of Dell's Media Experience, a multimedia suite which offers the user functionality to organise and play music and digital video files. Whether or not you need to run this program on startup must be decided by you. If you feel that you want this program starting automatically so that you have it available as needed, then do not disable it. This program is not required to start automatically as you can start it manually if you need it. It is advised that you disable this program so that it does not take up necessary resources. Many users have reported this process slows their boot time. It may be worthwhile to fix it with HijackThis. Item(s) to fix in HijackThis:

O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe

realplay.exe (RealPlayer) process can be removed to free up resources without compromising system performance. realplay.exe is the main process belonging to Real Networks, Real Player which allows the playing of various video files such as MPEG and AVI. This process also installs a system tray icon onto your system tray bar. This program is a non-essential system process, and is installed for ease of use. The program is not required to start automatically as you can start it manually if you need it. If you start RealPlayer manually, it adds itself back to the start-up list. You can stop this from happening by right-clicking on the tray icon and disabling StartCenter via PreferencesThis. It is advised that you disable this program so that it does not take up necessary resources. Many users have reported this process slows their boot time. It may be worthwhile to fix it with HijackThis. Item(s) to fix in HijackThis:

O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER

You have QuickTime running at Startup. This is QuickTime's system tray icon and not necessary for the program to function properly. It is considered to be a resource hog. You can fix this with HijackThis, but you will need to change the setting in QuickTime Player itself to keep it from resetting itself. To Remove The QuickTime Icon From System Tray:
  • Right-click the icon and select QuickTime Preferences.
  • Select Advanced tab (farthest to right)
  • Locate the option Install QuickTime icon in system tray in the Tray Icon area near the bottom and uncheck the box next to it.
  • Exit the Preferences by selecting OK.
  • This should remove the icon from your tray and it should not be there the next time you restart your computer.
Item(s) to fix in HijackThis:

O4 ‑ HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" ‑atboottime

mimboot.exe (Musicmatch Jukebox) process can be removed to free up resources without compromising system performance. Starts Musicmatch_Jukebox at bootup - can be started manually. This is a valid program but it is not required to start automatically as you can start it manually if you need it. It is advised that you disable this program so that it does not take up necessary resources. Many users have reported this process slows their boot time. It may be worthwhile to fix it with HijackThis. Item(s) to fix in HijackThis:

O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe

mm_tray.exe process can be removed to free up resources without compromising system performance. mm_tray.exe is the tray bar process for MusicMatch Jukebox which organizes and plays music media such as MP3. It gives the user easy access to the MusicMatch Jukebox application and settings. This is a non-essential process. Disabling or enabling it is down to user preference. This program is not required to start automatically as you can start it manually if you need it. It is advised that you disable this program so that it does not take up necessary resources. Many users have reported this process slows their boot time. It may be worthwhile to fix it with HijackThis. Item(s) to fix in HijackThis:

O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe

ISUSPM Startup ISUSPM.exe ( InstallShield Update Service Scheduler) process can be removed to free up resources without compromising system performance. It automatically searches for and performs any updates to the software so you’re always working with the most current version. This program is not required to start automatically as you can start it manually if you need it. It is advised that you disable this program so that it does not take up necessary resources. Many users have reported this process slows their boot time. It may be worthwhile to fix it with HijackThis. Item(s) to fix in HijackThis:

O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup

issch.exe ISUSScheduler ( InstallShield Update Service Scheduler) process can be removed to free up resources without compromising system performance. It automatically searches for and performs any updates to the software so you’re always working with the most current version. This program is not required to start automatically as you can start it manually if you need it. It is advised that you disable this program so that it does not take up necessary resources. Many users have reported this process slows their boot time. It may be worthwhile to fix it with HijackThis. Item(s) to fix in HijackThis:

O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

GoogleDesktop.exe (Google Desktop Search) process can be removed to free up resources without compromising system performance. Google Desktop Search - "a desktop search application that provides full text search over your email, computer files, chats, and the web pages you've viewed. By making your computer searchable, Google Desktop Search puts your information easily within your reach and frees you from having to manually organize your files, emails, and bookmarks". This program is not required to start automatically as you can start it manually if you need it. It is advised that you disable this program so that it does not take up necessary resources. Many users have reported this process slows their boot time. It may be worthwhile to fix it with HijackThis. Item(s) to fix in HijackThis:

O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup

You have AcroTray.exerunning at Startup. AcroTray.exe is the Acrobat Assistant used when you print your documents to a PDF. While converting documents to a PDF this process should not be removed. This is a non-essential process. You will still be able to start it manually if you need it. You can fix this with HijackThis. Item(s) to fix in HijackThis:

O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"

AOLSoftware.exe (AOL Online) process can be removed to free up resources without compromising system performance. Added by AOL Online. When run, this program starts the AOL tray icon. The tray icon gives end-user's Internet connectivity status, the ability to launch a standalone dialer similar to Windows DUN and access to AOL diagnostic data. The numbers in the path may change depending on the version of AOL that is installed. This is a valid program but it is not required to run on startup. This program is not required to start automatically as you can start it manually if you need it. It is advised that you disable this program so that it does not take up necessary resources. Many users have reported this process slows their boot time. It may be worthwhile to fix it with HijackThis. Item(s) to fix in HijackThis:
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1170410798\ee\AOLSoftware.exe

You have reader_sl.exe running at Startup. This is a process associated with the Adobe Reader. It is used to decrease the load time for the reader when a PDF document is selected. This is a non-essential process. You will still be able to start it manually if you need it. You can fix this with HijackThis. Item(s) to fix in HijackThis:

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

You have jusched.exe running at Startup. It checks with Sun's Java updates site to see if newer Java versions are available. This program is not required to start automatically. You can do this manually by visiting http://java.sun.com or just run the Java Plug-In Control Panel. It is advised that you disable this program so that it does not take up necessary resources. It may be worthwhile to fix it with HijackThis. Item(s) to fix in HijackThis:

O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

msmsgs.exe (MSN Messenger Internet chat tool) is the main process relating to the MSN Messenger Internet chat tool installed by default on most Windows computers. The Windows Messenger (IM, MSN Messenger) from Microsoft provides Online Chat and Instant Messaging. If you don't use Windows Messenger, you can
  • Rename the "Messenger" folder.
  • Uninstall, Stop, Disable or Remove "Windows Messenger (IM, MSN Messenger)".
A tray bar is also installed alongside this process for easy access to its features which include Internet chat, file sharing and audio/video conferencing. This is a non-essential process. Disabling or enabling it is down to user preference. process can be removed to free up resources without compromising system performance. This program is not required to start automatically as you can start it manually if you need it. It is advised that you disable this program so that it does not take up necessary resources. Many users have reported this process slows their boot time. It may be worthwhile to fix it with HijackThis. Item(s) to fix in HijackThis:

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

You have Adobe Gamma Loader.exe running at Startup. Adobe Gamma Loader.exe is installed alongside Adobe Creative Studio products and allows the color calibration of your video output device. This is a non-essential process. You will still be able to start it manually if you need it. You can fix this with HijackThis. Item(s) to fix in HijackThis:

O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

RegistrationReminder.exe (various games) process can be removed to free up resources without compromising system performance. The process RegistrationReminder MFC Application belongs to the software RegistrationReminder Application or RegistrationReminder.exe by unknown. RegistrationReminder.exe is located in a subfolder of "C:\Program Files". This is a valid program but it is not required to start automatically as you can start it manually if you need it. It is advised that you disable this program so that it does not take up necessary resources. Many users have reported this process slows their boot time. It may be worthwhile to fix it with HijackThis. Item(s) to fix in HijackThis:

O4 - Startup: Registration .LNK = C:\Program Files\Ubisoft\Blazing Angels Squadrons of WWII\RegistrationReminder.exe

Acrobat_sl.exe (Adobe Acrobat Speed Launcher) process can be removed to free up resources without compromising system performance. This is a valid program but it is not required to start automatically as you can start it manually if you need it.

When you install Acrobat, the Speed Launcher program is installed into your computer’s Common Startup group. The Speed Launcher shortens the time needed to start Acrobat.
Although this is not recommended, you can disable Speed Launcher by dragging its icon out of the Startup folder.
Note: If you have both Acrobat and Reader installed on the same system, two Speed Launcher icons appear in the Startup folder. If you want to disable Speed Launcher, remove both Speed Launcher icons from the Startup folder.

It is advised that you disable this program so that it does not take up necessary resources. Many users have reported this process slows their boot time. It may be worthwhile to fix it with HijackThis. Item(s) to fix in HijackThis:

O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?

aoltray.exe (America Online *.* Tray Icon) process can be removed to free up resources without compromising system performance. aoltray.exe puts AOL icon in System Tray (*.* denotes version if present). Connect to AOL via the desktop shortcut or Start -> Programs. This program is not required to start automatically as you can start it manually if you need it. It is advised that you disable this program so that it does not take up necessary resources. Many users have reported this process slows their boot time. It may be worthwhile to fix it with HijackThis. Item(s) to fix in HijackThis:

O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe

DLG.exe (Digital Line Detect.Ink) process can be removed to free up resources without compromising system performance. It detects whether your are plugged into a digital telephone line and displays the information graphically. Installed by Dell (and maybe others) and is included with all Connexant V.92 and Broadcom modems. This program is not required to start automatically as you can start it manually if you need it. It is advised that you disable this program so that it does not take up necessary resources. Many users have reported this process slows their boot time. It may be worthwhile to fix it with HijackThis. Item(s) to fix in HijackThis:

O4 - Global Startup: Digital Line Detect.lnk = ?

qbupdate.exe (Quickbooks Update Agent) process can be removed to free up resources without compromising system performance. Associated with Intuit's Quickbooks but not required. Possibly to do with the payroll update service but you're prompted to check for updates when appropriate whether this is running or not This program is not required to start automatically as you can start it manually if you need it. It is advised that you disable this program so that it does not take up necessary resources. Many users have reported this process slows their boot time. It may be worthwhile to fix it with HijackThis. Item(s) to fix in HijackThis:

O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe

GoogleUpdaterService.exe (Google Updater) process can be removed to free up resources without compromising system performance. Used to update Google programs such as Google Toolbar. This is a valid program but it is not required to start automatically as you can start it manually if you need it. It is advised that you disable this program so that it does not take up necessary resources. To change the service to Disabled.
  • Right-click on My Computer and choose Manage.
  • Expand the Services and Applications section and click on Services.
  • On the right-side of the screen, find the entry for Google Updater Service and double-click on it.
  • Change the Startup Type: to Disabled.
  • Hit the OK button and close the Computer Management screen.
Many users have reported this process slows their boot time. It may be worthwhile to fix it with HijackThis. Item(s) to fix in HijackThis:

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

IDriverT.exe (InstallShield- InstallDriver Table Manager) process can be removed to free up resources without compromising system performance. idrivert.exe is a process which belongs to the InstallShield product installation service which should only appear when you are installing a new piece of software. This program is not required to start automatically as you can start it manually if you need it. To change to Manual:
  • Right-click on My Computer and choose Manage.
  • Expand the Services and Applications section and click on Services.
  • On the right-side of the screen, find the entry for InstallDriver Table Manager and double-click on it.
  • Change the Startup Type: to Manual.
  • Hit the OK button and close the Computer Management screen.
Many users have reported this process slows their boot time. It may be worthwhile to fix it with HijackThis. Item(s) to fix in HijackThis:

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe

Close all browsers and other windows except for HijackThis, and click Fix Checked to have HijackThis fix the entries you checked.

And here is my latest hijackthis log
: (What is the difference from using RSIT.exe and HijackThis?.....Do I need to keep the RSIT.exe file I have saved on my desktop?)

You can delete RSIT.exe.
You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)
Malware Removal University Masters Graduate

Posted Image
Join The Fight Against Malware
No reply within 5 days will result in your topic being closed. If you need more time, please let me know by posting in this topic so that your topic will not be closed.

#15 mrboyertown

mrboyertown
  • Topic Starter

  • Members
  • 36 posts
  • OFFLINE
  •  
  • Local time:10:48 AM

Posted 20 April 2009 - 07:45 PM

Thanks for the reply,...sorry to hear about your diagnosis. I ran HijackThis and removed some of the startup programs that you had suggested. Now Im ready for my next instructions. I also wanted to let you know that when I start up my computuer when Windows is loading up a Windows Dialoag box appears - Windows Installer......Preparing to Install - pops up for a few seconds then disappears on its own. Its been doing this since about the time I first started having my problems. Got rid of the browser redirect problem but the windows installer dialog box still appears every time Windows is booting up. Anyway, Im ready for my next instructions. Also ran my latest HijackThis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:33:18, on 4/20/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\GEARSec.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\MotorolaDAP.exe
C:\Program Files\Norton Ghost\Agent\VProSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Norton Ghost\Agent\GhostTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\Program Files\Common Files\AOL\1170410798\ee\aolsoftware.exe
C:\Documents and Settings\Mark Richards\My Documents\HiJack This Program\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.comcast.net/toolbar2.0/search/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.comcast.net/toolbar2.0/search/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer presented by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [tgcmd] C:\Program Files\Support.com\bin\tgcmd.exe /server /startmonitor /deaf
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Norton Ghost 10.0] "C:\Program Files\Norton Ghost\Agent\GhostTray.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" AcPro7_0_8 -reboot 1
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Registration .LNK = C:\Program Files\Ubisoft\Blazing Angels Squadrons of WWII\RegistrationReminder.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/as...abs/tgctlsr.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase5483.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O18 - Protocol: intu-help-qb1 - {9B0F96C7-2E4B-433E-ABF3-043BA1B54AE3} - C:\Program Files\Intuit\QuickBooks 2005\HelpAsyncPluggableProtocol.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: Motorola Digital Audio Player Manager (MotorolaDAP) - Motorola Inc. - C:\WINDOWS\system32\MotorolaDAP.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton Ghost\Agent\VProSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

--
End of file - 12508 bytes




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users