Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

C:\Windows\System32\drivers\ESQULivowxinkvxtrwvipcceiyeeyipcswylp.sys


  • Please log in to reply
11 replies to this topic

#1 curundu

curundu

  • Members
  • 41 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Houston Texas
  • Local time:12:47 PM

Posted 26 September 2009 - 04:39 PM

Here are the files compiled from scans I have run per instructions from Boopme. I have a Rootkit that needs to be deleted.

Thanks for any help.


DDS (Ver_09-09-24.01) - NTFSx86
Run by Dave at 16:23:06.12 on Sat 09/26/2009
Internet Explorer: 8.0.6001.18813 BrowserJavaVersion: 1.6.0_13
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.958.377 [GMT -5:00]

SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\SYSTEM32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Program Files\Tall Emu\Online Armor\OAcat.exe
C:\Program Files\Tall Emu\Online Armor\oasrv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\SYSTEM32\taskeng.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\SYSTEM32\taskeng.exe
C:\Windows\SYSTEM32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Tall Emu\Online Armor\oaui.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Tall Emu\Online Armor\OAhlp.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Secunia\PSI\psi.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Opera\opera.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Dave\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://yahoo.sbc.com/dsl
uSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
mStart Page = hxxp://www.google.com
mDefault_Page_URL = hxxp://www.google.com
mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: H - No File
mURLSearchHooks: H - No File
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: {C7768536-96F8-4001-B1A2-90EE21279187} - No File
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [@OnlineArmor GUI] "c:\program files\tall emu\online armor\oaui.exe"
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mPolicies-explorer: EnableShellExecuteHooks = 1 (0x1)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - c:\program files\yahoo!\messenger\YahooMessenger.exe
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
Trusted Zone: turbotax.com
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} - hxxps://amaccess.amec.com/dana-cached/sc/JuniperSetupClient.cab
TCP: NameServer = 85.255.112.91,85.255.112.85
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
AppInit_DLLs: c:\progra~1\google\google~2\goec62~1.dll,c:\progra~1\google\google~2\GOEC62~1.DLL
SEH: OA Shell Helper: {4f07da45-8170-4859-9b5f-037ef2970034} - c:\progra~1\tallem~1\online~1\oaevent.dll

============= SERVICES / DRIVERS ===============

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-9-12 114768]
R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [2009-8-6 200784]
R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [2009-8-6 24656]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-9-12 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2009-9-12 53328]
R2 IntuitUpdateService;Intuit Update Service;c:\program files\common files\intuit\update service\IntuitUpdateService.exe [2008-10-10 13088]
R2 OAcat;Online Armor Helper Service;c:\program files\tall emu\online armor\oacat.exe [2009-8-6 362184]
R2 SvcOnlineArmor;Online Armor;c:\program files\tall emu\online armor\oasrv.exe [2009-8-6 3142344]
R3 OAnet;OnlineArmor Service;c:\windows\system32\drivers\OAnet.sys [2009-8-6 30800]
S2 gupdate1c9a76390e978f;Google Update Service (gupdate1c9a76390e978f);c:\program files\google\update\GoogleUpdate.exe [2009-3-17 133104]
S3 cpuz129;cpuz129;c:\program files\pc wizard 2008\pcwiz32.sys [2009-1-5 9600]
S3 GoogleDesktopManager-092308-165331;Google Desktop Manager 5.8.809.23506;c:\program files\google\google desktop search\GoogleDesktop.exe [2007-5-25 30192]
S3 rootrepeal1;rootrepeal1;c:\windows\system32\drivers\rootrepeal1.sys [2009-9-24 34816]
S3 rootrepeal2;rootrepeal2;c:\windows\system32\drivers\rootrepeal2.sys [2009-9-24 34816]
S3 rootrepeal3;rootrepeal3;c:\windows\system32\drivers\rootrepeal3.sys [2009-9-24 34816]
S4 nvrd32;NVIDIA nForce RAID Driver;c:\windows\system32\drivers\nvrd32.sys [2007-5-25 131368]

=============== Created Last 30 ================

2009-09-25 12:30 <DIR> --d----- c:\program files\Sophos
2009-09-20 14:24 <DIR> --d----- c:\users\dave\appdata\roaming\SUPERAntiSpyware.com
2009-09-20 14:24 <DIR> --d----- c:\program files\SUPERAntiSpyware
2009-09-20 14:24 <DIR> --d----- c:\program files\common files\Wise Installation Wizard
2009-09-19 22:48 <DIR> --d----- c:\programdata\Spybot - Search & Destroy
2009-09-19 22:48 <DIR> --d----- c:\program files\Spybot - Search & Destroy
2009-09-19 22:48 <DIR> --d----- c:\progra~2\Spybot - Search & Destroy
2009-08-29 14:59 <DIR> --d----- c:\program files\PC Drivers HeadQuarters
2009-08-29 14:30 <DIR> --d----- c:\program files\Trend Micro

==================== Find3M ====================

2009-09-26 15:23 31,776 a------- c:\programdata\nvModes.dat
2009-09-26 15:23 31,776 a------- c:\progra~2\nvModes.dat
2009-09-24 20:28 34,816 a------- c:\windows\system32\drivers\rootrepeal3.sys
2009-09-24 20:23 34,816 a------- c:\windows\system32\drivers\rootrepeal2.sys
2009-09-24 20:22 34,816 a------- c:\windows\system32\drivers\rootrepeal1.sys
2009-09-18 16:57 6,518 a------- c:\users\dave\appdata\roaming\wklnhst.dat
2009-09-17 20:38 86,016 a------- c:\windows\inf\infstrng.dat
2009-09-17 20:38 86,016 a------- c:\windows\inf\infstor.dat
2009-09-17 20:38 51,200 a------- c:\windows\inf\infpub.dat
2009-09-17 20:37 665,600 a------- c:\windows\inf\drvindex.dat
2009-08-28 07:39 28,672 a------- c:\windows\system32\Apphlpdm.dll
2009-08-28 07:39 173,056 a------- c:\windows\apppatch\AcXtrnal.dll
2009-08-28 07:38 2,153,984 a------- c:\windows\apppatch\AcGenral.dll
2009-08-28 07:38 541,696 a------- c:\windows\apppatch\AcLayers.dll
2009-08-28 07:38 459,776 a------- c:\windows\apppatch\AcSpecfc.dll
2009-08-28 05:15 4,240,384 a------- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-17 11:05 53,328 a------- c:\windows\system32\drivers\aswMonFlt.sys
2009-08-14 12:07 897,608 a------- c:\windows\system32\drivers\tcpip.sys
2009-08-14 11:29 104,960 a------- c:\windows\system32\netiohlp.dll
2009-08-14 11:29 17,920 a------- c:\windows\system32\netevent.dll
2009-08-14 09:16 17,920 a------- c:\windows\system32\ROUTE.EXE
2009-08-14 09:16 9,728 a------- c:\windows\system32\TCPSVCS.EXE
2009-08-14 09:16 11,264 a------- c:\windows\system32\MRINFO.EXE
2009-08-14 09:16 27,136 a------- c:\windows\system32\NETSTAT.EXE
2009-08-14 09:16 19,968 a------- c:\windows\system32\ARP.EXE
2009-08-14 09:16 10,240 a------- c:\windows\system32\finger.exe
2009-08-14 09:16 8,704 a------- c:\windows\system32\HOSTNAME.EXE
2009-07-21 16:52 915,456 a------- c:\windows\system32\wininet.dll
2009-07-21 16:47 109,056 a------- c:\windows\system32\iesysprep.dll
2009-07-21 16:47 71,680 a------- c:\windows\system32\iesetup.dll
2009-07-21 15:13 133,632 a------- c:\windows\system32\ieUnatt.exe
2009-07-17 09:35 71,680 a------- c:\windows\system32\atl.dll
2009-07-14 08:00 313,344 a------- c:\windows\system32\wmpdxm.dll
2009-07-14 07:59 4,096 a------- c:\windows\system32\dxmasf.dll
2009-07-14 07:58 7,680 a------- c:\windows\system32\spwmp.dll
2009-07-14 05:59 8,147,456 a------- c:\windows\system32\wmploc.DLL
2009-07-11 14:32 513,024 a------- c:\windows\system32\wlansvc.dll
2009-07-11 14:32 302,592 a------- c:\windows\system32\wlansec.dll
2009-07-11 14:32 293,376 a------- c:\windows\system32\wlanmsm.dll
2009-07-11 14:29 127,488 a------- c:\windows\system32\L2SecHC.dll
2008-09-21 10:37 56 a---h--- c:\programdata\ezsidmv.dat
2008-09-21 10:37 56 a---h--- c:\progra~2\ezsidmv.dat
2008-09-21 01:18 174 a--sh--- c:\program files\desktop.ini
2008-01-27 13:21 2,908,307 a------- c:\users\dave\SimpleDBudget105Setup.exe
2008-01-25 21:31 6,219,320 a------- c:\users\dave\picasaweb-current-setup.exe
2008-01-25 16:41 16,897,771 a------- c:\users\dave\pfc.exe
2008-01-19 21:43 23,405,072 a------- c:\users\dave\AdbeRdr811_en_US.exe
2006-11-02 07:42 287,440 a------- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 07:42 287,440 a------- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 07:42 30,674 a------- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 07:42 30,674 a------- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 04:20 287,440 a------- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 04:20 287,440 a------- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 04:20 30,674 a------- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 04:20 30,674 a------- c:\windows\inf\perflib\0000\perfc.dat
2009-05-28 16:04 16,384 a--sh--- c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\history\history.ie5\index.dat
2009-05-28 16:04 32,768 a--sh--- c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2009-05-28 16:04 16,384 a--sh--- c:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\cookies\index.dat
2009-06-17 18:06 245,760 a--sh--- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\ietldcache\index.dat
2007-05-25 16:52 8,192 a--sh--- c:\windows\users\default\NTUSER.DAT

============= FINISH: 16:28:29.54 ===============

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-09-24.01)

Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume3
Install Date: 5/25/2007 9:01:04 AM
System Uptime: 9/26/2009 3:23:04 PM (1 hours ago)

Motherboard: Dell Inc | |
Processor: AMD Athlon™ 64 X2 Dual Core Processor 3600+ | Socket M2 | 1800/1000mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 288 GiB total, 242.197 GiB free.
D: is FIXED (NTFS) - 10 GiB total, 6.365 GiB free.
E: is CDROM ()
F: is Removable
G: is Removable
H: is Removable
I: is Removable

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP982: 9/17/2009 8:11:57 PM - Windows Vista™ Service Pack 2
RP984: 9/19/2009 9:50:53 PM - Windows Update
RP986: 9/20/2009 12:38:07 PM - Scheduled Checkpoint
RP988: 9/20/2009 2:24:43 PM - Installed SUPERAntiSpyware Free Edition
RP990: 9/21/2009 2:59:47 PM - Windows Update
RP992: 9/23/2009 7:03:50 PM - Scheduled Checkpoint
RP994: 9/24/2009 9:23:56 AM - Scheduled Checkpoint
RP996: 9/24/2009 1:48:40 PM - Windows Update
RP998: 9/25/2009 1:52:20 PM - Scheduled Checkpoint
RP1000: 9/26/2009 4:00:33 PM - Scheduled Checkpoint

==== Installed Programs ======================


3D Ultra Pinball Thrillride
a-squared Free 4.5
Access Drivers
Adobe Flash Player 10 Plugin
AlfaHD
AnswerWorks 4.0 Runtime - English
AnswerWorks 5.0 English Runtime
Ask Toolbar
AT&T Yahoo! Applications
AutoCAD 2000
AutoCAD 2000 Migration Assistance
AutoVIP
avast! Antivirus
Bookworm Adventures Deluxe 1.0
Bookworm Deluxe 1.03
Bullzip PDF Printer 4.0.0.545
Caricature Studio Green 3.6
CCleaner (remove only)
Chuzzle Deluxe 1.0
Conexant D850 PCI V.92 Modem
CreditFederal.com Personal Finance Center
Dell Resource CD
Dell System Customization Wizard
DellSupport
Digital Line Detect
Diner Dash - Flo on the Go
DivX Codec
DivX Content Uploader
DivX Converter
DivX Player
DivX Web Player
Driver Detective
EarthLink Setup Files
Finding Nemo: Nemo's Underwater World of Fun Special Edition
Games, Music, & Photos Launcher
Glary Registry Repair 3.1.0.800
Google Desktop
Google Earth
Google Toolbar for Internet Explorer
Google Update Helper
Google Updater
GPL Ghostscript Lite 8.61
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Indeo® software
Internet Service Offers Launcher
J2SE Runtime Environment 5.0 Update 6
Java™ 6 Update 13
Java™ 6 Update 4
Java™ 6 Update 5
Java™ 6 Update 7
Java™ SE Runtime Environment 6
Juniper Networks Setup Client
Lernout & Hauspie TruVoice for Microsoft Agent
Microsoft .NET Framework 3.5 SP1
Microsoft Flight Simulator X
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
Microsoft XML Parser
Modem Diagnostic Tool
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB941833)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 Parser and SDK
Netflix Movie Viewer
NetWaiting
NVIDIA Drivers
Online Armor 3.5
OpenOffice.org 3.0
Opera 9.64
PC Wizard 2008.1.871
Picasa 3
Product Documentation Launcher
RCA SMV Video Converter
RealPlayer
RegCure 1.3.0.2
Roxio Creator Audio
Roxio Creator BDAV Plugin
Roxio Creator Copy
Roxio Creator Data
Roxio Creator DE
Roxio Creator Tools
Roxio Drag-to-Disc
Roxio Express Labeler
Roxio MyDVD DE
Roxio Update Manager
SBC Yahoo! DSL Home Networking Installer
SigmaTel Audio
SimpleD Budget
Skype™ 4.0
Sonic Activation Module
Sophos Anti-Rootkit 1.5.0
SpongeBob SquarePants - Battle for Bikini Bottom DEMO
TurboTax 2008
TurboTax 2008 WinPerFedFormset
TurboTax 2008 WinPerProgramHelp
TurboTax 2008 WinPerReleaseEngine
TurboTax 2008 WinPerTaxSupport
TurboTax 2008 WinPerUserEducation
TurboTax 2008 wrapper
TurboTax Basic 2007
Ultimate Pinball Extreme
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
User's Guides
Windows Media Player Firefox Plugin
Yahoo! Browser Services

==== Event Viewer Messages From Past Week ========

9/25/2009 12:27:23 PM, Error: EventLog [6008] - The previous system shutdown at 12:25:22 PM on 9/25/2009 was unexpected.
9/20/2009 2:26:56 PM, Error: EventLog [6008] - The previous system shutdown at 2:24:51 PM on 9/20/2009 was unexpected.
9/19/2009 9:52:11 PM, Error: Microsoft-Windows-Service Pack Installer [8] - Service Pack installation failed with error code 0x800f0a0d.
9/19/2009 10:58:11 PM, Error: Service Control Manager [7038] - The SstpSvc service was unable to log on as NT Authority\LocalService with the currently configured password due to the following error: A specified logon session does not exist. It may already have been terminated. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
9/19/2009 10:58:11 PM, Error: Service Control Manager [7001] - The Remote Access Connection Manager service depends on the Secure Socket Tunneling Protocol Service service which failed to start because of the following error: The service did not start due to a logon failure.
9/19/2009 10:58:11 PM, Error: Service Control Manager [7000] - The Secure Socket Tunneling Protocol Service service failed to start due to the following error: The service did not start due to a logon failure.
9/19/2009 10:44:21 PM, Error: Service Control Manager [7023] - The Secure Socket Tunneling Protocol Service service terminated with the following error: The RPC server is unavailable.
9/19/2009 10:44:21 PM, Error: Service Control Manager [7001] - The Remote Access Connection Manager service depends on the Secure Socket Tunneling Protocol Service service which failed to start because of the following error: The service has not been started.
9/19/2009 10:44:21 PM, Error: Service Control Manager [7001] - The Remote Access Connection Manager service depends on the Secure Socket Tunneling Protocol Service service which failed to start because of the following error: The RPC server is unavailable.

==== End Of File ===========================
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-09-24.01)

Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume3
Install Date: 5/25/2007 9:01:04 AM
System Uptime: 9/26/2009 3:23:04 PM (1 hours ago)

Motherboard: Dell Inc | |
Processor: AMD Athlon™ 64 X2 Dual Core Processor 3600+ | Socket M2 | 1800/1000mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 288 GiB total, 242.197 GiB free.
D: is FIXED (NTFS) - 10 GiB total, 6.365 GiB free.
E: is CDROM ()
F: is Removable
G: is Removable
H: is Removable
I: is Removable

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP982: 9/17/2009 8:11:57 PM - Windows Vista™ Service Pack 2
RP984: 9/19/2009 9:50:53 PM - Windows Update
RP986: 9/20/2009 12:38:07 PM - Scheduled Checkpoint
RP988: 9/20/2009 2:24:43 PM - Installed SUPERAntiSpyware Free Edition
RP990: 9/21/2009 2:59:47 PM - Windows Update
RP992: 9/23/2009 7:03:50 PM - Scheduled Checkpoint
RP994: 9/24/2009 9:23:56 AM - Scheduled Checkpoint
RP996: 9/24/2009 1:48:40 PM - Windows Update
RP998: 9/25/2009 1:52:20 PM - Scheduled Checkpoint
RP1000: 9/26/2009 4:00:33 PM - Scheduled Checkpoint

==== Installed Programs ======================


3D Ultra Pinball Thrillride
a-squared Free 4.5
Access Drivers
Adobe Flash Player 10 Plugin
AlfaHD
AnswerWorks 4.0 Runtime - English
AnswerWorks 5.0 English Runtime
Ask Toolbar
AT&T Yahoo! Applications
AutoCAD 2000
AutoCAD 2000 Migration Assistance
AutoVIP
avast! Antivirus
Bookworm Adventures Deluxe 1.0
Bookworm Deluxe 1.03
Bullzip PDF Printer 4.0.0.545
Caricature Studio Green 3.6
CCleaner (remove only)
Chuzzle Deluxe 1.0
Conexant D850 PCI V.92 Modem
CreditFederal.com Personal Finance Center
Dell Resource CD
Dell System Customization Wizard
DellSupport
Digital Line Detect
Diner Dash - Flo on the Go
DivX Codec
DivX Content Uploader
DivX Converter
DivX Player
DivX Web Player
Driver Detective
EarthLink Setup Files
Finding Nemo: Nemo's Underwater World of Fun Special Edition
Games, Music, & Photos Launcher
Glary Registry Repair 3.1.0.800
Google Desktop
Google Earth
Google Toolbar for Internet Explorer
Google Update Helper
Google Updater
GPL Ghostscript Lite 8.61
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Indeo® software
Internet Service Offers Launcher
J2SE Runtime Environment 5.0 Update 6
Java™ 6 Update 13
Java™ 6 Update 4
Java™ 6 Update 5
Java™ 6 Update 7
Java™ SE Runtime Environment 6
Juniper Networks Setup Client
Lernout & Hauspie TruVoice for Microsoft Agent
Microsoft .NET Framework 3.5 SP1
Microsoft Flight Simulator X
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
Microsoft XML Parser
Modem Diagnostic Tool
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB941833)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 Parser and SDK
Netflix Movie Viewer
NetWaiting
NVIDIA Drivers
Online Armor 3.5
OpenOffice.org 3.0
Opera 9.64
PC Wizard 2008.1.871
Picasa 3
Product Documentation Launcher
RCA SMV Video Converter
RealPlayer
RegCure 1.3.0.2
Roxio Creator Audio
Roxio Creator BDAV Plugin
Roxio Creator Copy
Roxio Creator Data
Roxio Creator DE
Roxio Creator Tools
Roxio Drag-to-Disc
Roxio Express Labeler
Roxio MyDVD DE
Roxio Update Manager
SBC Yahoo! DSL Home Networking Installer
SigmaTel Audio
SimpleD Budget
Skype™ 4.0
Sonic Activation Module
Sophos Anti-Rootkit 1.5.0
SpongeBob SquarePants - Battle for Bikini Bottom DEMO
TurboTax 2008
TurboTax 2008 WinPerFedFormset
TurboTax 2008 WinPerProgramHelp
TurboTax 2008 WinPerReleaseEngine
TurboTax 2008 WinPerTaxSupport
TurboTax 2008 WinPerUserEducation
TurboTax 2008 wrapper
TurboTax Basic 2007
Ultimate Pinball Extreme
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
User's Guides
Windows Media Player Firefox Plugin
Yahoo! Browser Services

==== Event Viewer Messages From Past Week ========

9/25/2009 12:27:23 PM, Error: EventLog [6008] - The previous system shutdown at 12:25:22 PM on 9/25/2009 was unexpected.
9/20/2009 2:26:56 PM, Error: EventLog [6008] - The previous system shutdown at 2:24:51 PM on 9/20/2009 was unexpected.
9/19/2009 9:52:11 PM, Error: Microsoft-Windows-Service Pack Installer [8] - Service Pack installation failed with error code 0x800f0a0d.
9/19/2009 10:58:11 PM, Error: Service Control Manager [7038] - The SstpSvc service was unable to log on as NT Authority\LocalService with the currently configured password due to the following error: A specified logon session does not exist. It may already have been terminated. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
9/19/2009 10:58:11 PM, Error: Service Control Manager [7001] - The Remote Access Connection Manager service depends on the Secure Socket Tunneling Protocol Service service which failed to start because of the following error: The service did not start due to a logon failure.
9/19/2009 10:58:11 PM, Error: Service Control Manager [7000] - The Secure Socket Tunneling Protocol Service service failed to start due to the following error: The service did not start due to a logon failure.
9/19/2009 10:44:21 PM, Error: Service Control Manager [7023] - The Secure Socket Tunneling Protocol Service service terminated with the following error: The RPC server is unavailable.
9/19/2009 10:44:21 PM, Error: Service Control Manager [7001] - The Remote Access Connection Manager service depends on the Secure Socket Tunneling Protocol Service service which failed to start because of the following error: The service has not been started.
9/19/2009 10:44:21 PM, Error: Service Control Manager [7001] - The Remote Access Connection Manager service depends on the Secure Socket Tunneling Protocol Service service which failed to start because of the following error: The RPC server is unavailable.

==== End Of File ===========================

Sophos Anti-Rootkit Version 1.5.0 © 2009 Sophos Plc
Started logging on 9/25/2009 at 12:31:34 PM
User "Dave" on computer "DAVE-PC"
Windows version 6.0 SP 1.0 Service Pack 1 build 6001 SM=0x300 PT=0x1 Win32
Info: Starting process scan.
Info: Starting registry scan.
Hidden: registry item \HKEY_LOCAL_MACHINE\SOFTWARE\ESQUL
Hidden: registry item \HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ESQULserv.sys
Hidden: registry item \HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ESQULserv.sys
Hidden: registry item \HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\ESQULserv.sys
Hidden: registry item \HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\ESQULserv.sys
Hidden: registry item \HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Services\ESQULserv.sys
Hidden: registry item \HKEY_LOCAL_MACHINE\SYSTEM\ControlSet006\Services\ESQULserv.sys
Hidden: registry item \HKEY_LOCAL_MACHINE\SYSTEM\ControlSet007\Services\ESQULserv.sys
Hidden: registry item \HKEY_LOCAL_MACHINE\SYSTEM\ControlSet008\Services\ESQULserv.sys
Hidden: registry item \HKEY_LOCAL_MACHINE\SYSTEM\ControlSet009\Services\ESQULserv.sys
Hidden: registry item \HKEY_LOCAL_MACHINE\SYSTEM\ControlSet010\Services\ESQULserv.sys
Hidden: registry item \HKEY_LOCAL_MACHINE\SYSTEM\ControlSet011\Services\ESQULserv.sys
Hidden: registry item \HKEY_LOCAL_MACHINE\SYSTEM\ControlSet012\Services\ESQULserv.sys
Hidden: registry item \HKEY_LOCAL_MACHINE\SYSTEM\ControlSet013\Services\ESQULserv.sys
Hidden: registry item \HKEY_LOCAL_MACHINE\SYSTEM\ControlSet014\Services\ESQULserv.sys
Hidden: registry item \HKEY_LOCAL_MACHINE\SYSTEM\ControlSet015\Services\ESQULserv.sys
Hidden: registry item \HKEY_LOCAL_MACHINE\SYSTEM\ControlSet016\Services\ESQULserv.sys
Hidden: registry item \HKEY_LOCAL_MACHINE\SYSTEM\ControlSet017\Services\ESQULserv.sys
Hidden: registry item \HKEY_LOCAL_MACHINE\SYSTEM\ControlSet018\Services\ESQULserv.sys
Hidden: registry item \HKEY_LOCAL_MACHINE\SYSTEM\ControlSet019\Services\ESQULserv.sys
Hidden: registry item \HKEY_LOCAL_MACHINE\SYSTEM\ControlSet020\Services\ESQULserv.sys
Hidden: registry item \HKEY_LOCAL_MACHINE\SYSTEM\ControlSet021\Services\ESQULserv.sys
Hidden: registry item \HKEY_LOCAL_MACHINE\SYSTEM\ControlSet022\Services\ESQULserv.sys
Hidden: registry item \HKEY_LOCAL_MACHINE\SYSTEM\ControlSet023\Services\ESQULserv.sys
Info: Starting disk scan of C: (NTFS).
Hidden: file C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F89LFDDU\AAABh1gMAAAAAAAIAAwAAAAAAuBpXgSIBAAAAAQAAADZlMDUwMTkwLTcxYWUtMTFkZS1iNGUzLT
AwMWIyNDkzNjQyMgBUAAAAAAA=ibBOAA==,,http%3A%2F%2Fipodtouchtopsite[1].com%2F,;ord=1247710485
Hidden: file C:\Program Files\SUPERAntiSpyware\Plugins\sab_wab.dll
Hidden: file C:\Program Files\SUPERAntiSpyware\SASCTXMN.DLL
Hidden: file C:\Windows\System32\drivers\ESQULivowxinkvxtrwvipcceiyeeyipcswylp.sys
Hidden: file C:\Windows\System32\ESQULfpixfoatwqpreqtneajeykvpoulshqxr.dll
Hidden: file C:\Windows\System32\ESQULfujwnvxobueivtmipdcdvymdwmxpjnid.dll
Hidden: file C:\Windows\System32\ESQULzcounter
Info: Starting disk scan of D: (NTFS).
Stopped logging on 9/25/2009 at 13:25:04 PM

BC AdBot (Login to Remove)

 


#2 SifuMike

SifuMike

    malware expert


  • Staff Emeritus
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:10:47 AM

Posted 01 October 2009 - 04:51 PM

Hello curundu,

You have a nasty rootkit on this computer. :(

Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
  • If you are using Firefox, make sure that your download settings are as follows:
    • Tools->Options->Main tab
    • Set to "Always ask me where to Save the files".
  • During the download, rename Combofix to Combo-Fix as follows:

    Posted Image

    Posted Image

  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    -----------------------------------------------------------

    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      -----------------------------------------------------------

    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

    -----------------------------------------------------------

  • Double click on combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the "C:\Combo-Fix.txt" .
**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**


Note: ComboFix may reset a number of Internet Explorer's settings, including making it the default browser.
Note: Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security.

Please do not install any new programs or update anything unless told to do so while we are fixing your problem.
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#3 curundu

curundu
  • Topic Starter

  • Members
  • 41 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Houston Texas
  • Local time:12:47 PM

Posted 01 October 2009 - 10:26 PM

Here is the report per your instructions.

Thank you,
Curundu


ComboFix 09-10-01.01 - Dave 10/01/2009 22:06.1.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.958.86 [GMT -5:00]
Running from: c:\users\Dave\Desktop\Combo-Fix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-1400113804-1914402855-3429530994-500
c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500
c:\$recycle.bin\S-1-5-21-76515569-653846985-77406772-500
c:\program files\AlfaHD
c:\program files\AlfaHD\Uninstall.exe
c:\users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AlfaHD
c:\windows\Installer\10b8dc3.msi
c:\windows\patch.exe
c:\windows\System32\drivers\ESQULivowxinkvxtrwvipcceiyeeyipcswylp.sys
c:\windows\System32\ESQULfpixfoatwqpreqtneajeykvpoulshqxr.dll
c:\windows\system32\ESQULfujwnvxobueivtmipdcdvymdwmxpjnid.dll
c:\windows\system32\ESQULzcounter

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_ESQULserv.sys
-------\Legacy_ESQULserv.sys
-------\Service_ESQULserv.sys


((((((((((((((((((((((((( Files Created from 2009-09-02 to 2009-10-02 )))))))))))))))))))))))))))))))
.

2009-09-27 05:10 . 2009-09-27 05:13 -------- d-----w- c:\users\Dave\AppData\Roaming\Notepad++
2009-09-27 05:10 . 2009-09-27 05:13 -------- d-----w- c:\program files\Notepad++
2009-09-25 17:30 . 2009-09-25 17:30 -------- d-----w- c:\program files\Sophos
2009-09-25 01:28 . 2009-09-25 01:28 34816 ----a-w- c:\windows\system32\drivers\rootrepeal3.sys
2009-09-25 01:23 . 2009-09-25 01:23 34816 ----a-w- c:\windows\system32\drivers\rootrepeal2.sys
2009-09-25 01:22 . 2009-09-25 01:22 34816 ----a-w- c:\windows\system32\drivers\rootrepeal1.sys
2009-09-20 19:24 . 2009-09-20 19:24 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-09-20 19:24 . 2009-09-20 19:24 -------- d-----w- c:\users\Dave\AppData\Roaming\SUPERAntiSpyware.com
2009-09-20 19:24 . 2009-09-20 19:24 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-09-20 03:48 . 2009-09-20 03:57 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-09-20 03:48 . 2009-09-20 03:56 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-09-17 23:15 . 2009-09-17 23:15 -------- d-----w- c:\windows\system32\EventProviders
2009-09-12 15:38 . 2009-08-17 16:04 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-09-12 15:38 . 2009-08-17 16:04 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-09-12 15:38 . 2009-08-17 16:02 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-09-12 15:38 . 2009-08-17 16:05 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-09-12 15:38 . 2009-08-17 16:05 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-09-12 15:37 . 2009-08-17 16:10 1279456 ----a-w- c:\windows\system32\aswBoot.exe
2009-09-12 15:37 . 2009-08-17 16:05 53328 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2009-09-12 15:37 . 2009-09-12 15:37 -------- d-----w- c:\program files\Alwil Software
2009-09-10 00:43 . 2009-06-15 15:24 175104 ----a-w- c:\windows\system32\wdigest.dll
2009-09-10 00:43 . 2009-06-15 15:23 1256448 ----a-w- c:\windows\system32\lsasrv.dll
2009-09-10 00:43 . 2009-06-15 15:22 213504 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-10 00:43 . 2009-06-15 15:21 499712 ----a-w- c:\windows\system32\kerberos.dll
2009-09-10 00:43 . 2009-06-15 18:20 439896 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-09-10 00:43 . 2009-06-15 15:24 270848 ----a-w- c:\windows\system32\schannel.dll
2009-09-10 00:43 . 2009-06-15 15:24 72704 ----a-w- c:\windows\system32\secur32.dll
2009-09-10 00:43 . 2009-06-15 12:57 9728 ----a-w- c:\windows\system32\lsass.exe
2009-09-02 21:45 . 2009-08-28 12:39 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-09-02 21:45 . 2009-08-28 10:15 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-02 03:16 . 2009-05-14 23:54 31776 ----a-w- c:\programdata\nvModes.dat
2009-10-02 02:47 . 2009-08-29 19:38 -------- d-----w- c:\program files\Opera
2009-10-01 22:49 . 2009-07-23 23:11 -------- d-----w- c:\users\Dave\AppData\Roaming\GlarySoft
2009-10-01 15:40 . 2007-07-14 03:02 -------- d-----w- c:\programdata\Google Updater
2009-09-20 03:40 . 2009-07-24 00:23 -------- d-----w- c:\programdata\Malwarebytes
2009-09-18 21:57 . 2007-06-26 01:11 6518 ----a-w- c:\users\Dave\AppData\Roaming\wklnhst.dat
2009-09-09 13:36 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-09-04 01:47 . 2009-03-17 20:45 -------- d-----w- c:\users\Dave\AppData\Roaming\Uniblue
2009-08-30 14:12 . 2009-08-06 23:12 -------- d-----w- c:\program files\a-squared Free
2009-08-29 19:59 . 2009-08-29 19:59 -------- d-----w- c:\program files\PC Drivers HeadQuarters
2009-08-29 19:30 . 2009-08-29 19:30 -------- d-----w- c:\program files\Trend Micro
2009-08-25 23:56 . 2008-09-21 15:30 -------- d-----w- c:\users\Dave\AppData\Roaming\Skype
2009-08-25 23:36 . 2008-09-21 15:37 -------- d-----w- c:\users\Dave\AppData\Roaming\skypePM
2009-08-14 17:07 . 2009-09-08 21:16 897608 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-08-14 16:29 . 2009-09-08 21:16 104960 ----a-w- c:\windows\system32\netiohlp.dll
2009-08-14 16:29 . 2009-09-08 21:16 17920 ----a-w- c:\windows\system32\netevent.dll
2009-08-14 14:16 . 2009-09-08 21:16 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-08-14 14:16 . 2009-09-08 21:16 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-08-14 14:16 . 2009-09-08 21:16 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-08-14 14:16 . 2009-09-08 21:16 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-08-14 14:16 . 2009-09-08 21:16 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-08-14 14:16 . 2009-09-08 21:16 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-08-14 14:16 . 2009-09-08 21:16 10240 ----a-w- c:\windows\system32\finger.exe
2009-07-27 02:43 . 2009-07-27 01:39 14 ----a-w- c:\windows\system32\settings.dat
2009-07-21 21:52 . 2009-08-06 23:27 915456 ----a-w- c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-08-06 23:27 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-08-06 23:27 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-08-06 23:27 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-07-17 14:35 . 2009-08-25 23:51 71680 ----a-w- c:\windows\system32\atl.dll
2009-07-14 13:00 . 2009-08-25 23:49 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-14 12:59 . 2009-08-25 23:49 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-07-14 12:58 . 2009-08-25 23:49 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-07-14 10:59 . 2009-08-25 23:49 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-07-11 19:32 . 2009-09-08 21:16 293376 ----a-w- c:\windows\system32\wlanmsm.dll
2009-07-11 19:32 . 2009-09-08 21:16 513024 ----a-w- c:\windows\system32\wlansvc.dll
2009-07-11 19:32 . 2009-09-08 21:16 302592 ----a-w- c:\windows\system32\wlansec.dll
2009-07-11 19:29 . 2009-09-08 21:16 127488 ----a-w- c:\windows\system32\L2SecHC.dll
2009-05-14 00:23 . 2008-08-13 21:46 122880 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2007-05-25 21:52 . 2007-05-25 21:51 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rootrepeal.sys]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Digital Line Detect.lnk]
backup=c:\windows\pss\Digital Line Detect.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^Users^Dave^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 2.4.lnk]
backup=c:\windows\pss\OpenOffice.org 2.4.lnk.Startup
backupExtension=.Startup

[HKLM\~\startupfolder\C:^Users^Dave^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.0.lnk]
backup=c:\windows\pss\OpenOffice.org 3.0.lnk.Startup
backupExtension=.Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E6TaskPanel
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SBC Yahoo! Connection Manager

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [9/12/2009 10:38 AM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [9/12/2009 10:38 AM 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [9/12/2009 10:37 AM 53328]
R2 IntuitUpdateService;Intuit Update Service;c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe [10/10/2008 6:45 AM 13088]
S2 gupdate1c9a76390e978f;Google Update Service (gupdate1c9a76390e978f);c:\program files\Google\Update\GoogleUpdate.exe [3/17/2009 7:46 PM 133104]
S3 cpuz129;cpuz129;c:\program files\PC Wizard 2008\pcwiz32.sys [1/5/2009 9:13 PM 9600]
S3 GoogleDesktopManager-092308-165331;Google Desktop Manager 5.8.809.23506;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [5/25/2007 9:20 AM 30192]
S3 rootrepeal1;rootrepeal1;c:\windows\System32\drivers\rootrepeal1.sys [9/24/2009 8:22 PM 34816]
S3 rootrepeal2;rootrepeal2;c:\windows\System32\drivers\rootrepeal2.sys [9/24/2009 8:23 PM 34816]
S3 rootrepeal3;rootrepeal3;c:\windows\System32\drivers\rootrepeal3.sys [9/24/2009 8:28 PM 34816]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-10-02 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-07-14 15:37]

2009-10-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-18 00:46]

2009-10-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-18 00:46]

2009-09-28 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2007-06-25 18:08]

2009-09-28 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2007-06-25 18:08]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://yahoo.sbc.com/dsl
mStart Page = hxxp://www.google.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
Trusted Zone: turbotax.com
DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} - hxxps://amaccess.amec.com/dana-cached/sc/JuniperSetupClient.cab
.
- - - - ORPHANS REMOVED - - - -

URLSearchHooks-CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
ShellExecuteHooks-{4F07DA45-8170-4859-9B5F-037EF2970034} - (no file)
Notify-avldr - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-01 22:17
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\1F04.tmp"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'Explorer.exe'(2224)
c:\program files\Roxio\Drag-to-Disc\Shellex.dll
c:\windows\system32\DLAAPI_W.DLL
c:\program files\Roxio\Drag-to-Disc\ShellRes.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\nvvsvc.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\nvvsvc.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\a-squared Free\a2service.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
c:\windows\System32\drivers\XAudio.exe
c:\windows\System32\WUDFHost.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
c:\program files\Secunia\PSI\psi.exe
c:\program files\Alwil Software\Avast4\ashDisp.exe
c:\program files\Windows Media Player\wmpnscfg.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Completion time: 2009-10-02 22:21 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-02 03:21

Pre-Run: 255,500,726,272 bytes free
Post-Run: 255,230,750,720 bytes free

228 --- E O F --- 2009-09-28 13:48

#4 SifuMike

SifuMike

    malware expert


  • Staff Emeritus
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:10:47 AM

Posted 02 October 2009 - 12:18 AM

Hi curundu,


Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
  • Please download Java Version 6 Update 16
  • Click the "Free Java Download" button.
  • Click "Free Java Download" again
  • Save the file jxpiinstall.exe to your desktop
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
    Examples of older versions in Add or Remove Programs:
    J2SE Runtime Environment 5.0 Update 6
    Java 6 Update 13
    Java 6 Update 4
    Java 6 Update 5
    Java 6 Update 7
    Java SE Runtime Environment 6

  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jxpiinstall.exe to install the newest version.
**********************

Download Security Check by screen317 from here or here.
Save it to your Desktop.
Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
A Notepad document should open automatically called checkup.txt.
Please post the contents of that document.

**********************

While TeaTimer and Windows Defender are excellent tools for the prevention of spyware, they can sometimes prevent some things from being fixed.

Please disable TeaTimer and Windows Defender for now until you are clean. TeaTimer and Windows Defender can be re-activated once your log is clean.

* Open Spybot Search & Destroy.
* In the Mode menu click "Advanced mode" if not already selected.
* Choose "Yes" at the Warning prompt.
* Expand the "Tools" menu.
* Click "Resident".
* Uncheck the "Resident "TeaTimer" (Protection of overall system settings) active." box.
* In the File menu click "Exit" to exit Spybot Search & Destroy.

To disable Windows Defender:
Open Windows Defender.
Click on Tools, General Settings.
Scroll down and uncheck Turn on real-time protection (recommended).
After you uncheck this, click on the Save button and close Windows Defender.


Note: If you already have Malwarebytes' Anti-Malware, then update, run it, then do a "Perform Full Scan"

Please download Malwarebytes' Anti-Malware from one of these places:
http://download.cnet.com/Malwarebytes-Anti...&tag=button
http://www.majorgeeks.com/Malwarebytes_Ant...ware_d5756.html
http://www.besttechie.net/mbam/mbam-setup.exe

Double Click mbam-setup.exe to install the application.

* Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select "Perform Full Scan", then click Scan.
* The scan may take some time to finish,so please be patient.
* When the scan is complete, click OK, then Show Results to view the results.
* Make sure that everything is checked, and click Remove Selected.
* When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
* The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
* Copy&Paste the entire MBAM report (even if it does not find anything) in your next reply along with a fresh HijackThis log.

Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.

**********************

Please do a scan with Kaspersky Online Scanner. Please note: Kaspersky requires Java Runtime Environment (JRE) be installed before scanning for malware, as ActiveX is no longer being used.)

If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.
  • Open the Kaspersky WebScanner
    page.
  • Click on the Kaspersky Online Scanner button on the main page.
  • The program will launch and fill in the Information section on the left.
  • Read the "Requirements and Limitations" then press the Posted Image button.
  • The program will begin downloading the latest program and definition files. It may take a while so please be patient and let it finish.
  • Once the files have been downloaded, click on the Posted Image ...button.
    In the scan settings make sure the following are selected:
    • Detect malicious programs of the following categories:
      Viruses, Worms, Trojan Horses, Rootkits
      Spyware, Adware, Dialers and other potentially dangerous programs
    • Scan compound files (doesn't apply to the File scan area):
      Archives
      Mail databases
      By default the above items should already be checked.
    • Click the Posted Image button, if you made any changes.
  • Now under the Scan section on the left:

    Select My Computer
  • The program will now start and scan your system. This will run for a while, be patient and let it finish.
  • Once the scan is complete, click on View scan report
  • Now, click on the Save Report as button.
  • In the drop down box labeled Files of type change the type to Text file.
  • Save the file to your desktop.
  • Copy and paste that information in your next post even if it finds nothing.
You can refer to this animation by sundavis if needed.

Edited by SifuMike, 02 October 2009 - 12:32 AM.

If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#5 curundu

curundu
  • Topic Starter

  • Members
  • 41 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Houston Texas
  • Local time:12:47 PM

Posted 11 October 2009 - 01:18 PM

Sorry I took so long to reply. I could not run the Kaspersky Webscanner as its disabled for now, according to their site. When it was offering the Online Snanner option I was told My Java was out of date, even though I had downloaded the latest version. Java told me I had the latest version when I tried to download it, so I couldn't run Kaspersky when it was availble.
I applied the other reports. I hope they are helpful. On another note, Internet Exployer is now working fine. I haven't downloaded Firefox yet, unless you say its OK.


Much Thanks,
Curundu




Results of screen317's Security Check version 0.99.0
Windows Vista Service Pack 2 (UAC is enabled)
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Enabled!
avast! Antivirus
a-squared Free 4.5
WMIC entry does not exist for antivirus; attempting automatic update.
avast! updated!
``````````````````````````````
Anti-malware/Other Utilities Check:

Secunia PSI
Sophos Anti-Rootkit 1.5.0
CCleaner (remove only)
Java™ 6 Update 16
Adobe Flash Player 10
Adobe Reader 9.1
``````````````````````````````
Process Check:
objlist.exe by Laurent

Windows Defender MSASCui.exe
``````````````````````````````
DNS Vulnerability Check:

GREAT! (Not vulnerable to DNS cache poisoning)

`````````End of Log```````````


Malwarebytes' Anti-Malware 1.41
Database version: 2902
Windows 6.0.6002 Service Pack 2

10/3/2009 6:06:43 PM
mbam-log-2009-10-03 (18-06-43).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 286637
Time elapsed: 1 hour(s), 5 minute(s), 46 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Qoobox\Quarantine\C\Program Files\AlfaHD\Uninstall.exe.vir (Trojan.DNSChanger) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\Windows\System32\ESQULfpixfoatwqpreqtneajeykvpoulshqxr.dll.vir (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\install.exe (Trojan.Agent) -> Quarantined and deleted successfully.

#6 SifuMike

SifuMike

    malware expert


  • Staff Emeritus
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:10:47 AM

Posted 11 October 2009 - 01:25 PM

Hello curundu,

I haven't downloaded Firefox yet, unless you say its OK


You can download Firefox if you want. :(


Lets run an F-Secure online scan for Viruses, Spyware and RootKits:
Go to http://support.f-secure.com/enu/home/ols.shtml

Notes:
This scan will only work with Internet Explorer
You must have administrator rights to run this scan
This scan can take several hours, so please be patient

Scroll to the bottom of the page and click the Start scanning button. A window will pop up.
Allow the Active X control to be installed on your computer, then click the Accept button
Click Full System Scan and allow the components to download and the scan to complete.
If malware is found, check Submit samples to F-Secure then select Automatic cleaning
When cleaning has finitished, click Show report (this will open an Internet Explorer window containing the report)
Highlight and Copy (CTRL + C) the complete report, and Paste (CTRL + V) in a new reply to this post


If Automatic cleaning with Submit samples hangs, click Cancel, then New Scan
When the cleaning option is presented, Uncheck Submit samples to F-Secure
Click Automatic cleaning
When cleaning has finitished, click Show report (this will open an Internet Explorer window containing the report)
Highlight and Copy (CTRL + C) the complete report, and Paste (CTRL + V) in a new reply to this post
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#7 curundu

curundu
  • Topic Starter

  • Members
  • 41 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Houston Texas
  • Local time:12:47 PM

Posted 16 October 2009 - 06:38 AM

Here is the report from F-Secure. Thank you for your help. Can you suggest what anti-virus and anti-malware programs I should have on my computer from now on?
I'm going to see how much of a donation I can make.
Thanks again,
Curundu


Scanning Report
Friday, October 16, 2009 18:01:55 - 04:24:37
Computer name: DAVE-PC
Scanning type: Scan system for malware, spyware and rootkits
Target: C:\ D:\


--------------------------------------------------------------------------------

No malware found

--------------------------------------------------------------------------------

Statistics
Scanned:
Files: 2824301
System: 4219
Not scanned: 237
Actions:
Disinfected: 0
Renamed: 0
Deleted: 0
Not cleaned: 0
Submitted: 0
Files not scanned:
C:\PAGEFILE.SYS
C:\WINDOWS\SYSTEM32\CONFIG\COMPONENTS
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT
C:\WINDOWS\SYSTEM32\CONFIG\SAM
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE
C:\WINDOWS\SYSTEM32\CONFIG\REGBACK\COMPONENTS
C:\WINDOWS\SYSTEM32\CONFIG\REGBACK\DEFAULT
C:\WINDOWS\SYSTEM32\CONFIG\REGBACK\SOFTWARE
C:\WINDOWS\SYSTEM32\CONFIG\REGBACK\SAM
C:\WINDOWS\SYSTEM32\CONFIG\REGBACK\SYSTEM
C:\WINDOWS\SYSTEM32\CONFIG\REGBACK\SECURITY
C:\WINDOWS\SYSTEM32\CATROOT2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\CATDB
C:\WINDOWS\SYSTEM32\CATROOT2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\CATDB
C:\USERS\DAVE\LOCAL SETTINGS\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9
C:\USERS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F
C:\USERS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETR
C:\USERS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOW
C:\USERS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA
C:\USERS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA
C:\USERS\DAVE\APPDATA\LOCAL\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\USERS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B
C:\USERS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5
C:\USERS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRA
C:\USERS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS
C:\USERS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\
C:\USERS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\
C:\USERS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\
C:\USERS\ALL USERS\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\USERS\ALL USERS\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\USERS\ALL USERS\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\USERS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\USERS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\USERS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\USERS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\USERS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\USERS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\USERS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\USERS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\USERS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\USERS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\USERS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\USERS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\USERS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\USERS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\USERS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\USERS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\USERS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\USERS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\USERS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\USERS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\USERS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\USERS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E
C:\USERS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-29
C:\USERS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F2934
C:\USERS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6
C:\USERS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHI
C:\USERS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT
C:\USERS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATI
C:\SYSTEM VOLUME INFORMATION\MOUNTPOINTMANAGERREMOTEDATABASE
C:\SYSTEM VOLUME INFORMATION\{664BB336-B99B-11DE-8598-001AA03F14B3}{3808876B-C176-4E48-B7AE-04046E6CC752}
C:\SYSTEM VOLUME INFORMATION\{871BB909-B27B-11DE-8679-001AA03F14B3}{3808876B-C176-4E48-B7AE-04046E6CC752}
C:\SYSTEM VOLUME INFORMATION\{C4F06318-B064-11DE-B5BC-001AA03F14B3}{3808876B-C176-4E48-B7AE-04046E6CC752}
C:\SYSTEM VOLUME INFORMATION\{E101C91B-B8DC-11DE-9B8B-001AA03F14B3}{3808876B-C176-4E48-B7AE-04046E6CC752}
C:\SYSTEM VOLUME INFORMATION\{EF4C38A0-B1AA-11DE-AD35-001AA03F14B3}{3808876B-C176-4E48-B7AE-04046E6CC752}
C:\PROGRAMDATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\PROGRAMDATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\PROGRAMDATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\PROGRAMDATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\PROGRAMDATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\PROGRAMDATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\PROGRAMDATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\PROGRAMDATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\PROGRAMDATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\PROGRAMDATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\PROGRAMDATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\PROGRAMDATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\PROGRAMDATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\PROGRAMDATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\PROGRAMDATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\PROGRAMDATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\PROGRAMDATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\PROGRAMDATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\PROGRAMDATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\PROGRAMDATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\PROGRAMDATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\PROGRAMDATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\PROGRAMDATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\PROGRAMDATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\PROGRAMDATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF
C:\PROGRAMDATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4
C:\PROGRAMDATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DE
C:\PROGRAMDATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3
C:\PROGRAMDATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKE
C:\PROGRAMDATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRY
C:\PROGRAMDATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION D
C:\PROGRAMDATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION D
C:\DOCUMENTS AND SETTINGS\DAVE\LOCAL SETTINGS\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9
C:\DOCUMENTS AND SETTINGS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F
C:\DOCUMENTS AND SETTINGS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETR
C:\DOCUMENTS AND SETTINGS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOW
C:\DOCUMENTS AND SETTINGS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA
C:\DOCUMENTS AND SETTINGS\DAVE\LOCAL SETTINGS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA
C:\DOCUMENTS AND SETTINGS\DAVE\APPDATA\LOCAL\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\APPDATA\LOCAL\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B993EC444}
C:\DOCUMENTS AND SETTINGS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5D3-4F37-A8E4-5C9B
C:\DOCUMENTS AND SETTINGS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3ABC3641-F5
C:\DOCUMENTS AND SETTINGS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRA
C:\DOCUMENTS AND SETTINGS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS
C:\DOCUMENTS AND SETTINGS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\
C:\DOCUMENTS AND SETTINGS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\
C:\DOCUMENTS AND SETTINGS\DAVE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\
C:\DOCUMENTS AND SETTINGS\ALL USERS\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E6FFF04B2
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-2936-4E06-96EE-983E
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F293432DEA_A48341C2-29
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6B7B3E7E0EDF9F2934
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\90BD3F79F6
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHI
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATI

--------------------------------------------------------------------------------

Options
Scanning engines:
Scanning options:
Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB LNK WSF {* PDF ZL? XML XXX ANI AVB BAT CMD JOB LSP MAP MHT MIF PHP POT SWF WMF NWS TAR
Use advanced heuristics

#8 SifuMike

SifuMike

    malware expert


  • Staff Emeritus
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:10:47 AM

Posted 16 October 2009 - 12:41 PM

Hi curundu,

F-Secure looks good.

I think we have you clean. :(

How is the computer running?

If all is OK, then we will do the program clean up.

Can you suggest what anti-virus and anti-malware programs I should have on my computer from now on?


You had nasty rootkit on this computer and no antivirus will protect you from them.
Your are currently running AVAST antivirus, and that is one of the three free antivirus that are highly recommended.

If you wish to try another, the free

Avast or
AntiVir or
AVG antivirus

Products from all three vendors received the Virus Bulletin's VB100% award and certification for virus detection from ICSA Labs.

Never install more than one antivirus scanner or firewall on your system! Several together can give you problems and decrease the reliability of it seriously!

You should also update and run Malwarebytes weekly.

Edited by SifuMike, 16 October 2009 - 12:41 PM.

If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#9 curundu

curundu
  • Topic Starter

  • Members
  • 41 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Houston Texas
  • Local time:12:47 PM

Posted 17 October 2009 - 12:05 AM

SifuMike,
Thanks so much for your help. The PC runs nicely. Its nice having a healthy PC. This forum is the best managed one I have ever visited.

I read where I could run a Defrag from the DosPrompt and tried it. Seemed to work pretty good. Any thoughts on that?

I think I'll stick with Avast and MalwareBytes. Can they both run at the same time, or are they automatically running in the background? What about Windows Defender? Its set to scan at 2am at which time my PC is typically turned off. What should I do with Windows Defender?

Have you ever heard of Secunia Personal Software Inspector? Just today it said my programs were up to date. Now it says 8 programs are insecure/end-of-life and exposing my PC to security issues. It would seem like I have to constantly be updating programs, and typically I never gets alerts to update from most programs.

On another note. My wife likes Internet Explorer (default browser), my 8 year old daughter likes Opera Browser, and I like Firefox. Oh well.

Thanks again from little Hempstead Texas.

#10 SifuMike

SifuMike

    malware expert


  • Staff Emeritus
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:10:47 AM

Posted 17 October 2009 - 12:54 AM

Hi curundu,

Your very welcome. :(

Uninstall ComboFix, go to to Start > Run & type in Combo-Fix /u
Make sure there's a space between Combo-fix and /
Then hit enter.

This will uninstall Combofix, delete any of its related folders and files (Qoobox
VundoFix Backups, Avenger, _OTM3), reset your clock settings, hide file extensions, hide the system/hidden files and resets System Restore again.


Please read and follow
How did I get infected?, With steps so it does not happen again!
as well as
How to prevent Malware' by miekiemoes

If you want to improve speed/system performance after malware removal, take a look here.


I read where I could run a Defrag from the DosPrompt and tried it. Seemed to work pretty good. Any thoughts on that

Thats a good way to run it. To make it run faster you should make sure your temp files are deleted.
CCleaner is a good temp file clean.

Another defrag program (free) you can use is Defragger.


I think I'll stick with Avast and MalwareBytes. Can they both run at the same time, or are they automatically running in the background?


Thats a good choice. Avast runs in the background. Malwarebytes runs on demand (not in the background). You can have Avast running in background while Malwarebytes is running.

What about Windows Defender? Its set to scan at 2am at which time my PC is typically turned off. What should I do with Windows Defender?


I assume you mean that the computer is not on the internet at 2am.
You need to have the computer turned on and running for it to scan. I would set it to scan in the daytime.

Have you ever heard of Secunia Personal Software Inspector?



Yes, I use it. :(

Just today it said my programs were up to date. Now it says 8 programs are insecure/end-of-life and exposing my PC to security issues. It would seem like I have to constantly be updating programs, and typically I never gets alerts to update from most program


Most programs do not tell you they are out of date or need updating. Either you search the programs site for updates (like Adobe Acrobat) or use a program like Secunia Personal Software Inspector to look for updates automaticaly.

On another note. My wife likes Internet Explorer (default browser), my 8 year old daughter likes Opera Browser, and I like Firefox. Oh well

.
Actually, it is a good thing to have multiple browsers on a computer. If malware disables one of them then you have a back up broswer. :)
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#11 curundu

curundu
  • Topic Starter

  • Members
  • 41 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Houston Texas
  • Local time:12:47 PM

Posted 22 October 2009 - 06:01 PM

I can't for the life of me find Combo-Fix to uninstall it. The icon is there and I can start it but its not in the list of programs in the Control Panel. I tried the method you suggested but Vista said it could not find it.
I still don't understand the windows architecture of Vista. It really sucks. When would be a good time to buy Windows 7?

Later,
Curundu

#12 SifuMike

SifuMike

    malware expert


  • Staff Emeritus
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:10:47 AM

Posted 22 October 2009 - 06:18 PM

Hi curundu,

We will get rid of it anther way. :(

Delete Combo-Fix from your desktop
Delete this folder: C:\Qoobox

Please download OTC and save it to desktop.
Double-click OTC.exe.
Click the CleanUp! button.
Select Yes when the "Begin cleanup Process?" prompt appears.
If you are prompted to Reboot during the cleanup, select Yes.
The tool will delete itself once it finishes, if not delete it by yourself.

Note: If you receive a warning from your firewall or other security programs regarding OTC attempting to contact the internet, please allow it to do so.


I still don't understand the windows architecture of Vista. It really sucks. When would be a good time to buy Windows 7?


It is just released today. I would wait a month or so before buying it, so they get the bugs out of it. If your a college student then you can get it for $29.99
http://www.bleepingcomputer.com/forums/t/260220/2999-windows-7-home-premium-upgrade-for-college-students/
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users