Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

System-Restore infection - can't boot


  • This topic is locked This topic is locked
35 replies to this topic

#1 84xads

84xads

  • Members
  • 36 posts
  • OFFLINE
  •  
  • Local time:05:26 AM

Posted 10 November 2011 - 02:40 PM

Yesterday got an Windows Restore Virus. I followed the instructions and thought I got it off with malwarebytes until this morning it appeared again. The computer populated with the same problem as before.

I restarted the computer in an attempt to get into safe mode with networking, but I get a black screen with a blinking underscore line at the top.

I am making this post from another computer...

Thanks in advance!

BC AdBot (Login to Remove)

 


#2 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,700 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:07:26 AM

Posted 12 November 2011 - 01:17 PM

:welcome:

Which operating system is installed?

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#3 84xads

84xads
  • Topic Starter

  • Members
  • 36 posts
  • OFFLINE
  •  
  • Local time:05:26 AM

Posted 15 November 2011 - 10:14 AM

My OS is Windows 7 Ultimate

#4 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,700 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:07:26 AM

Posted 15 November 2011 - 03:44 PM

For x32 (x86) bit systems download Farbar Recovery Scan Tool and save it to a flash drive.
For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Click on Repair your computer menu item.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.
On the System Recovery Options menu you will get the following options:

Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt

  • Select Command Prompt
  • In the command window type in notepad and press Enter.
  • The notepad opens. Under File menu select Open.
  • Select "Computer" and find your flash drive letter and close the notepad.
  • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
    Note: Replace letter e with the drive letter of your flash drive.
  • The tool will start to run.
  • When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the flash drive. Please copy and paste it to your reply.

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#5 84xads

84xads
  • Topic Starter

  • Members
  • 36 posts
  • OFFLINE
  •  
  • Local time:05:26 AM

Posted 15 November 2011 - 04:02 PM

Scan result of Farbars's Recovery Tool (FRST written by farbar) Version 2.2.7
Ran by SYSTEM at 2011-11-15 14:55:25
Running from H:\
Windows 7 Ultimate (X64) OS Language: English(US)
The current controlset is ControlSet001

========================== Registry (Whitelisted) =============

HKLM\...\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe [153136 2007-03-01] (Nero AG)
HKLM\...\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [1836328 2007-09-20] (Nero AG)
HKLM\...\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin [611712 2011-03-22] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe_ID0ENQBO] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE [378224 2008-08-15] (Adobe Systems Incorporated)
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [141608 2010-07-21] (Apple Inc.)
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2010-08-10] (Apple Inc.)
HKLM\...\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe [x]
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [249064 2010-10-29] (Sun Microsystems, Inc.)
HKLM\...\Run: [NgTUiSAcmhn.exe] C:\ProgramData\NgTUiSAcmhn.exe [423768 2011-11-09] ()
HKLM\...\Run: [ISTray] "C:\Program Files\PC Tools Security\pctsGui.exe" /hideGUI [1600984 2011-07-07] (PC Tools)
HKLM\...\Run: [ZwwkkUUVrlOtx0y8234A] C:\Windows\system32\AV Security 2012v121.exe [1676800 2011-11-10] ()
HKU\Editing\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe" [202024 2007-09-20] (Nero AG)
HKU\Editing\...\Run: [cdloader] "C:\Users\Editing\AppData\Roaming\mjusbsp\cdloader2.exe" MAGICJACK [50592 2011-08-23] (magicJack L.P.)
HKU\Editing\...\Run: [AdobeBridge] [x]
HKU\Editing\...\Run: [Google Update] "C:\Users\Editing\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2010-08-24] (Google Inc.)
HKU\Editing\...\Run: [Dyyno Launcher] "C:\Program Files\Dyyno\Dyyno Broadcaster\dyyno_launcher.exe" 30100 30101 30102 30103 30104 [2155872 2010-08-11] ()
HKU\Editing\...\Run: [4X9VYU9VUVZY9J1BQLSKXBLCRU] C:\sym.bin\D5D97B2020C.exe /q [197120 2010-11-20] (Symantec Corporation)
HKLM-x32\...\Winlogon: [Userinit]
HKLM-x32\...\Winlogon: [Shell] [x x] ()
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254

==================== Services (Whitelisted) ======

3 Adobe Version Cue CS4; "C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe" -win32service [288112 2011-03-22] (Adobe Systems Incorporated)
3 ADVService; "C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe" [25704 2010-03-04] (Amazon.com)
2 Apple Mobile Device; "C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe" [144176 2010-06-10] (Apple Inc.)
2 bgsvcgen; "C:\Windows\system32\bgsvcgen.exe" [145504 2007-06-15] (B.H.A Corporation)
2 Bonjour Service; "C:\Program Files\Bonjour\mDNSResponder.exe" [345376 2010-05-18] (Apple Inc.)
2 Dyyno Launcher; C:\Program Files\Dyyno\Dyyno Broadcaster\launcherd.exe [410976 2010-08-11] ()
3 EhttpSrv; "C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe" [20680 2009-03-19] (ESET)
2 ekrn; "C:\Program Files\ESET\ESET Smart Security\ekrn.exe" [731840 2009-03-19] (ESET)
3 FLEXnet Licensing Service; "C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe" [655624 2010-05-15] (Acresso Software Inc.)
3 FontCache3.0.0.0; C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [42856 2009-06-10] (Microsoft Corporation)
2 gupdate; C:\Program Files\Google\Update\GoogleUpdate.exe /svc [136176 2010-08-24] (Google Inc.)
3 gupdatem; C:\Program Files\Google\Update\GoogleUpdate.exe /medsvc [136176 2010-08-24] (Google Inc.)
3 IDriverT; "C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe" [69632 2005-11-13] (Macrovision Corporation)
3 idsvc; "C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe" [878416 2010-11-04] (Microsoft Corporation)
2 Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [853288 2007-09-20] (Nero AG)
4 NetMsmqActivator; "C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe" -NetMsmqActivator [128848 2010-11-04] (Microsoft Corporation)
4 NetPipeActivator; C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [128848 2010-11-04] (Microsoft Corporation)
4 NetTcpActivator; C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [128848 2010-11-04] (Microsoft Corporation)
4 NetTcpPortSharing; C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [128848 2010-11-04] (Microsoft Corporation)
3 NMIndexingService; "C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe" [382248 2007-09-20] (Nero AG)
2 NMSAccessU; C:\Program Files\CDBurnerXP\NMSAccessU.exe [71096 2009-09-05] ()
2 RapiMgr; C:\Windows\WindowsMobile\rapimgr.dll [183688 2007-05-31] (Microsoft Corporation)
2 sdAuxService; C:\Program Files\PC Tools Security\pctsAuxs.exe [371472 2011-02-18] (PC Tools)
2 sdCoreService; C:\Program Files\PC Tools Security\pctsSvc.exe [1117144 2011-04-06] (PC Tools)
2 szserver; "C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe" [67024 2011-11-04] (iS3, Inc.)
2 TeamViewer6; C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe [2280312 2011-04-15] (TeamViewer GmbH)
2 TVersityMediaServer; "C:\Users\Editing\AppData\Local\TVersity\Media Server\MediaServer.exe" [856064 2010-02-25] ()
2 VisualWebRipper; "C:\Program Files\Visual Web Ripper\WebRipperService.exe" [12288 2011-05-16] (Sequentum)
2 WcesComm; C:\Windows\WindowsMobile\wcescomm.dll [379784 2007-05-31] (Microsoft Corporation)
2 .EsetTrialReset; C:\Program Files\ESET\ESET Smart Security\Shahed.exe /s [x]
3 aspnet_state; C:\Windows\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [x]

========================== Drivers (Whitelisted) =============

2 adfs; C:\Windows\System32\Drivers\adfs.sys [73312 2011-03-22] (Adobe Systems, Inc.)
3 b06bdrv; C:\Windows\System32\drivers\bxvbdx.sys [430080 2009-07-13] (Broadcom Corporation)
3 b57nd60x; C:\Windows\System32\DRIVERS\b57nd60x.sys [229888 2009-07-13] (Broadcom Corporation)
1 cdrbsdrv; C:\Windows\System32\Drivers\cdrbsdrv.sys [33408 2006-02-20] (B.H.A Corporation)
3 E1G60; C:\Windows\System32\DRIVERS\E1G60I32.sys [118784 2009-07-13] (Intel Corporation)
3 eamon; C:\Windows\System32\DRIVERS\eamon.sys [113960 2009-03-19] (ESET)
3 ebdrv; C:\Windows\System32\drivers\evbdx.sys [3100160 2009-07-13] (Broadcom Corporation)
2 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [107256 2009-03-19] (ESET)
2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [131976 2009-03-19] (ESET)
3 Epfwndis; C:\Windows\System32\DRIVERS\Epfwndis.sys [33096 2009-03-19] (ESET)
2 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [38240 2009-03-19] (ESET)
3 ioatdma; C:\Windows\System32\Drivers\qd26032.sys [37504 2008-01-17] (Intel Corporation)
3 ioatdma1; C:\Windows\System32\Drivers\qd16032.sys [36480 2008-01-17] (Intel Corporation)
0 is3srv; C:\Windows\System32\drivers\is3srv.sys [61328 2011-09-26] (iS3 Inc.)
3 iSSetup; C:\Windows\System32\DRIVERS\iSSetup.sys [106512 2009-08-04] (Intel Corporation)
3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [5810 2004-08-13] ()
3 O2MDRDR; C:\Windows\System32\DRIVERS\o2media.sys [47448 2009-07-26] (O2Micro )
3 O2SDRDR; C:\Windows\System32\DRIVERS\o2sd.sys [44064 2009-07-26] (O2Micro)
0 PCTCore; C:\Windows\System32\drivers\PCTCore.sys [263888 2011-07-11] (PC Tools)
0 pctDS; C:\Windows\System32\drivers\pctDS.sys [338880 2010-07-16] (PC Tools)
0 pctEFA; C:\Windows\System32\drivers\pctEFA.sys [656320 2010-07-16] (PC Tools)
1 PCTSD; C:\Windows\System32\Drivers\PCTSD.sys [233976 2011-03-10] (PC Tools)
0 PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [44608 2008-02-06] (Sonic Solutions)
3 rimmptsk; C:\Windows\System32\DRIVERS\rimmptsk.sys [48128 2009-06-25] (REDC)
3 rimspci; C:\Windows\System32\DRIVERS\rimspe86.sys [47104 2009-07-01] (REDC)
3 rimsptsk; C:\Windows\System32\DRIVERS\rimsptsk.sys [44544 2009-06-25] (REDC)
3 risdpcie; C:\Windows\System32\DRIVERS\risdpe86.sys [49152 2009-06-30] (REDC)
3 rismxdp; C:\Windows\System32\DRIVERS\rixdptsk.sys [38400 2009-06-25] (REDC)
3 rixdpcie; C:\Windows\System32\DRIVERS\rixdpe86.sys [38400 2009-07-04] (REDC)
3 RTL8167; C:\Windows\System32\DRIVERS\Rt86win7.sys [275048 2010-06-23] (Realtek )
3 RTSTOR; C:\Windows\System32\drivers\RTSTOR.SYS [65024 2009-05-12] (Realtek Semiconductor Corp.)
0 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2010-05-06] (Duplex Secure Ltd.)
3 StarOpen; C:\Windows\System32\Drivers\StarOpen.sys [7168 2009-09-28] ()
0 szkg5; C:\Windows\System32\DRIVERS\szkg.sys [61328 2011-09-26] (iS3 Inc.)
0 szkgfs; C:\Windows\System32\drivers\szkgfs.sys [59080 2011-08-16] (iS3, Inc.)
3 tbhsd; C:\Windows\System32\drivers\tbhsd.sys [37920 2010-05-25] (RapidSolution Software AG)
1 vpcnfltr; C:\Windows\System32\DRIVERS\vpcnfltr.sys [48128 2010-11-20] ()
3 wsvad_driver; C:\Windows\System32\drivers\VirtualAudio.sys [16896 2008-11-03] (Wondershare)
3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\mbamswissarmy.sys [x]
3 Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [x]
3 tsusbhub; C:\Windows\System32\drivers\tsusbhub.sys [x]
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
3 VMAUDIO; C:\Windows\System32\drivers\vmaudio.sys [x]
3 vmci; C:\Windows\System32\DRIVERS\vmci.sys [x]

========================== NetSvcs (Whitelisted) ===========

============ One Month Created Files and Folders ==============

2011-11-15 14:55 - 2011-11-15 14:55 - 0000000 ____D C:\FRST
2011-11-10 07:45 - 2011-11-10 07:45 - 1676800 ____A C:\Windows\System32\AV Security 2012v121.exe
2011-11-10 07:45 - 2011-11-10 07:45 - 0001829 ____A C:\AV Security 2012.lnk
2011-11-10 07:45 - 2011-11-10 07:45 - 0000000 ____D C:\AV Security 2012
2011-11-10 07:25 - 2011-11-10 07:25 - 0161576 ____A C:\Windows\Minidump\111011-38532-01.dmp
2011-11-09 20:52 - 2011-11-09 21:45 - 0000000 ___HD C:\Program Files\PC Tools Security
2011-11-09 20:52 - 2011-11-09 20:54 - 0000000 ___HD C:\Program Files\Common Files\PC Tools
2011-11-09 20:52 - 2011-11-09 20:53 - 1644120 ___AH C:\Windows\System32\Drivers\Cat.DB
2011-11-09 20:52 - 2011-07-11 10:06 - 0160576 ___AH (PC Tools) C:\Windows\System32\Drivers\PCTAppEvent.sys
2011-11-09 20:52 - 2011-07-11 10:02 - 0263888 ___AH (PC Tools) C:\Windows\System32\Drivers\PCTCore.sys
2011-11-09 20:52 - 2011-07-11 07:07 - 0070664 ___AH (PC Tools) C:\Windows\System32\Drivers\pctplsg.sys
2011-11-09 20:52 - 2011-07-11 07:05 - 0253096 ___AH (PC Tools) C:\Windows\System32\Drivers\pctgntdi.sys
2011-11-09 20:52 - 2011-07-11 07:05 - 0107352 ___AH (PC Tools) C:\Windows\System32\Drivers\pctwfpfilter.sys
2011-11-09 20:52 - 2011-03-10 07:08 - 0233976 ___AH (PC Tools) C:\Windows\System32\Drivers\PCTSD.sys
2011-11-09 20:52 - 2010-07-16 12:59 - 0656320 ___AH (PC Tools) C:\Windows\System32\Drivers\pctEFA.sys
2011-11-09 20:52 - 2010-07-16 12:59 - 0338880 ___AH (PC Tools) C:\Windows\System32\Drivers\pctDS.sys
2011-11-09 20:51 - 2011-11-09 20:52 - 0000000 ___HD C:\Users\All Users\PC Tools
2011-11-09 20:51 - 2011-11-09 20:52 - 0000000 ___HD C:\ProgramData\PC Tools
2011-11-09 20:51 - 2011-11-09 20:51 - 0512992 ___AH C:\Users\Editing\Desktop\PCTools_Safe_Install.exe
2011-11-09 20:31 - 2011-11-09 20:31 - 0337760 ___AH C:\Users\All Users\ojQXTFdFCXgLmn.exe
2011-11-09 20:31 - 2011-11-09 20:31 - 0337760 ___AH C:\ProgramData\ojQXTFdFCXgLmn.exe
2011-11-09 20:31 - 2011-11-09 20:31 - 0000657 ___AH C:\Users\Editing\Desktop\System Restore.lnk
2011-11-09 20:31 - 2011-11-09 20:31 - 0000432 ___AH C:\Users\All Users\ojQXTFdFCXgLmn
2011-11-09 20:31 - 2011-11-09 20:31 - 0000432 ___AH C:\ProgramData\ojQXTFdFCXgLmn
2011-11-09 20:31 - 2011-11-09 20:31 - 0000296 ___AH C:\Users\All Users\~ojQXTFdFCXgLmn
2011-11-09 20:31 - 2011-11-09 20:31 - 0000296 ___AH C:\ProgramData\~ojQXTFdFCXgLmn
2011-11-09 20:31 - 2011-11-09 20:31 - 0000216 ___AH C:\Users\All Users\~ojQXTFdFCXgLmnr
2011-11-09 20:31 - 2011-11-09 20:31 - 0000216 ___AH C:\ProgramData\~ojQXTFdFCXgLmnr
2011-11-09 14:49 - 2011-11-09 14:49 - 0000016 ___AH C:\Windows\System32\config\software.szfi
2011-11-09 13:37 - 2011-09-29 08:03 - 1290608 ___AH (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2011-11-09 13:37 - 2011-09-28 19:37 - 2341888 ___AH (Microsoft Corporation) C:\Windows\System32\win32k.sys
2011-11-09 13:31 - 2011-11-09 13:28 - 0423768 ___AH C:\Users\All Users\NgTUiSAcmhn.exe
2011-11-09 13:31 - 2011-11-09 13:28 - 0423768 ___AH C:\ProgramData\NgTUiSAcmhn.exe
2011-11-09 13:26 - 2011-10-11 13:19 - 0002503 ___AH C:\Users\Public\Desktop\Skype.lnk
2011-11-09 13:26 - 2011-05-27 11:25 - 0001120 ___AH C:\Users\Public\Desktop\TeamViewer 6.lnk
2011-11-09 13:26 - 2011-05-26 19:06 - 0000803 ___AH C:\Users\Public\Desktop\Opera.lnk
2011-11-09 13:26 - 2011-05-17 12:43 - 0002585 ___AH C:\Users\Public\Desktop\Visual Web Ripper.lnk
2011-11-09 13:26 - 2011-05-11 13:33 - 0001096 ___AH C:\Users\Public\Desktop\Mozilla Firefox.lnk
2011-11-09 13:26 - 2011-05-02 07:24 - 0002062 ___AH C:\Users\Public\Desktop\DivX Plus Converter.lnk
2011-11-09 13:26 - 2011-03-16 13:56 - 0001078 ___AH C:\Users\Public\Desktop\OpenOffice.org 3.3.lnk
2011-11-09 13:26 - 2011-02-26 21:51 - 0001076 ___AH C:\Users\Public\Desktop\Prism Video File Converter.lnk
2011-11-09 13:26 - 2010-12-08 11:38 - 0001082 ___AH C:\Users\Public\Desktop\DivX Plus Player.lnk
2011-11-09 13:26 - 2010-11-29 10:35 - 0001085 ___AH C:\Users\Public\Desktop\NCH Toolbox.lnk
2011-11-09 13:26 - 2010-11-29 10:14 - 0001080 ___AH C:\Users\Public\Desktop\Debut Video Capture Software.lnk
2011-11-09 13:26 - 2010-08-31 20:24 - 0002009 ___AH C:\Users\Public\Desktop\ADP Pro.lnk
2011-11-09 13:26 - 2010-08-28 17:42 - 0000901 ___AH C:\Users\Public\Desktop\Vimeo Uploader.lnk
2011-11-09 13:26 - 2010-08-26 04:50 - 0002479 ___AH C:\Users\Public\Desktop\Safari.lnk
2011-11-09 13:26 - 2010-08-26 04:49 - 0002429 ___AH C:\Users\Public\Desktop\iTunes.lnk
2011-11-09 13:26 - 2009-07-13 20:41 - 0000174 __ASH C:\Users\All Users\Start Menu\Programs\Startup\desktop.ini
2011-11-09 10:53 - 2011-11-09 10:53 - 0000000 ___HD C:\Users\Editing\AppData\Roaming\Malwarebytes
2011-11-09 10:53 - 2011-11-09 10:53 - 0000000 ___HD C:\Users\All Users\Malwarebytes
2011-11-09 10:53 - 2011-11-09 10:53 - 0000000 ___HD C:\ProgramData\Malwarebytes
2011-11-09 10:52 - 2011-11-09 10:53 - 0000000 ___HD C:\Program Files\Malwarebytes' Anti-Malware
2011-11-09 10:52 - 2011-11-09 10:52 - 9852544 ___AH (Malwarebytes Corporation ) C:\Users\Editing\Downloads\mbam-setup-1.51.2.1300.exe
2011-11-09 10:40 - 2011-11-10 07:25 - 430548008 ____A C:\Windows\MEMORY.DMP
2011-11-09 10:40 - 2011-11-09 10:40 - 0161576 ___AH C:\Windows\Minidump\110911-26130-01.dmp
2011-11-09 10:13 - 2011-11-09 10:13 - 0000036 ___RH C:\Windows\System32\Drivers\etc\hosts
2011-11-09 10:11 - 2011-11-10 04:19 - 0000000 ___HD C:\Users\All Users\STOPzilla!
2011-11-09 10:11 - 2011-11-10 04:19 - 0000000 ___HD C:\ProgramData\STOPzilla!
2011-11-09 10:11 - 2011-11-09 10:11 - 0000000 ___HD C:\Program Files\STOPzilla!
2011-11-09 10:11 - 2011-11-09 10:11 - 0000000 ___HD C:\Program Files\Common Files\iS3
2011-11-09 10:10 - 2011-11-10 07:40 - 0769766 ____A C:\Windows\System32\PerfStringBackup.TMP
2011-11-09 09:56 - 2011-11-09 09:59 - 0000448 ___AH C:\Users\All Users\QiTWKMe7r4NtRr
2011-11-09 09:56 - 2011-11-09 09:59 - 0000448 ___AH C:\ProgramData\QiTWKMe7r4NtRr
2011-11-09 09:56 - 2011-11-09 09:56 - 0000304 ___AH C:\Users\All Users\~QiTWKMe7r4NtRr
2011-11-09 09:56 - 2011-11-09 09:56 - 0000304 ___AH C:\ProgramData\~QiTWKMe7r4NtRr
2011-11-09 09:56 - 2011-11-09 09:56 - 0000224 ___AH C:\Users\All Users\~QiTWKMe7r4NtRrr
2011-11-09 09:56 - 2011-11-09 09:56 - 0000224 ___AH C:\ProgramData\~QiTWKMe7r4NtRrr
2011-11-04 22:47 - 2011-11-04 22:47 - 0738768 __RAH (iS3, Inc.) C:\Windows\System32\IS3Base5.dll
2011-11-04 22:47 - 2011-11-04 22:47 - 0546256 __RAH (iS3, Inc.) C:\Windows\System32\SZComp5.dll
2011-11-04 22:47 - 2011-11-04 22:47 - 0480720 __RAH (iS3, Inc.) C:\Windows\System32\SZBase5.dll
2011-11-04 22:47 - 2011-11-04 22:47 - 0456144 __RAH (iS3, Inc.) C:\Windows\System32\IS3DBA5.dll
2011-11-04 22:47 - 2011-11-04 22:47 - 0390608 __RAH (iS3, Inc.) C:\Windows\System32\IS3UI5.dll
2011-11-04 22:47 - 2011-11-04 22:47 - 0230864 __RAH (iS3, Inc.) C:\Windows\System32\IS3Win325.dll
2011-11-04 22:47 - 2011-11-04 22:47 - 0132560 __RAH (iS3, Inc.) C:\Windows\System32\IS3HTUI5.dll
2011-11-04 22:47 - 2011-11-04 22:47 - 0103888 __RAH (iS3, Inc.) C:\Windows\System32\IS3Inet5.dll
2011-11-04 22:47 - 2011-11-04 22:47 - 0099792 __RAH (iS3, Inc.) C:\Windows\System32\IS3Svc5.dll
2011-11-04 22:47 - 2011-11-04 22:47 - 0067024 __RAH (iS3, Inc.) C:\Windows\System32\IS3Hks5.dll
2011-11-04 22:47 - 2011-11-04 22:47 - 0028624 __RAH (iS3, Inc.) C:\Windows\System32\IS3XDat5.dll
2011-11-04 22:47 - 2011-11-04 22:47 - 0022992 __RAH (iS3, Inc.) C:\Windows\System32\SZIO5.dll
2011-11-02 08:39 - 2011-11-02 08:39 - 0032690 ___AH C:\Users\Editing\Downloads\msg0005.WAV
2011-10-31 08:53 - 2011-10-31 08:53 - 0137232 ___AH C:\Users\Editing\Documents\attuverse-1.pdf
2011-10-31 08:31 - 2011-10-31 08:31 - 0173323 ___AH C:\Users\Editing\Documents\attuverse.pdf
2011-10-28 05:51 - 2011-10-28 05:51 - 1034094 ___AH C:\Users\Editing\Downloads\iStock_000017871434Medium.jpg
2011-10-26 11:06 - 2011-10-26 11:06 - 0000000 ___HD C:\Users\Editing\Downloads\iPhoneTemplate
2011-10-26 10:55 - 2011-10-26 15:06 - 399537702 ___AH C:\Users\Editing\Downloads\studio2CityRightAnimated.mov
2011-10-26 10:49 - 2011-10-26 15:05 - 485018267 ___AH C:\Users\Editing\Downloads\studio2CityLoop.mov
2011-10-26 10:38 - 2011-10-26 10:40 - 248970046 ___AH C:\Users\Editing\Downloads\iPhoneTemplate.zip
2011-10-19 14:26 - 2011-10-19 14:26 - 0545542 ___AH C:\Users\Editing\Downloads\Vistaprint_Car_Door_Magnets-Large.zip
2011-10-19 14:26 - 2011-10-19 14:26 - 0000000 ___HD C:\Users\Editing\Downloads\Vistaprint_Car_Door_Magnets-Large

============ 3 Months Modified Files and Folders =============

2011-11-15 14:55 - 2011-11-15 14:55 - 0000000 ____D C:\FRST
2011-11-10 07:46 - 2011-07-13 07:58 - 0604770 ___AH C:\Windows\ntbtlog.txt
2011-11-10 07:45 - 2011-11-10 07:45 - 1676800 ____A C:\Windows\System32\AV Security 2012v121.exe
2011-11-10 07:45 - 2011-11-10 07:45 - 0001829 ____A C:\AV Security 2012.lnk
2011-11-10 07:45 - 2011-11-10 07:45 - 0000000 ____D C:\AV Security 2012
2011-11-10 07:45 - 2011-05-25 15:12 - 0000000 ___HD C:\sym.bin
2011-11-10 07:40 - 2011-11-09 10:10 - 0769766 ____A C:\Windows\System32\PerfStringBackup.TMP
2011-11-10 07:25 - 2011-11-10 07:25 - 0161576 ____A C:\Windows\Minidump\111011-38532-01.dmp
2011-11-10 07:25 - 2011-11-09 10:40 - 430548008 ____A C:\Windows\MEMORY.DMP
2011-11-10 07:25 - 2011-02-03 06:58 - 0000000 ___HD C:\Windows\Minidump
2011-11-10 04:19 - 2011-11-09 10:11 - 0000000 ___HD C:\Users\All Users\STOPzilla!
2011-11-10 04:19 - 2011-11-09 10:11 - 0000000 ___HD C:\ProgramData\STOPzilla!
2011-11-10 03:52 - 2010-08-24 11:17 - 0000916 ___AH C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1069887610-648576151-850243678-1005UA.job
2011-11-10 03:47 - 2010-08-29 17:12 - 0000888 ___AH C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2011-11-10 02:20 - 2010-05-06 16:21 - 1988080 ___AH C:\Windows\WindowsUpdate.log
2011-11-09 21:52 - 2010-08-24 11:17 - 0000864 ___AH C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1069887610-648576151-850243678-1005Core.job
2011-11-09 21:45 - 2011-11-09 20:52 - 0000000 ___HD C:\Program Files\PC Tools Security
2011-11-09 21:34 - 2009-07-13 20:34 - 0016848 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2011-11-09 21:34 - 2009-07-13 20:34 - 0016848 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2011-11-09 21:27 - 2010-08-29 17:12 - 0000884 ___AH C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2011-11-09 21:27 - 2010-05-16 10:28 - 0000675 ___AH C:\Windows\System32\TVersityMediaServer.log
2011-11-09 21:27 - 2009-07-13 20:53 - 0000006 ___AH C:\Windows\Tasks\SA.DAT
2011-11-09 21:27 - 2009-07-13 20:39 - 0053325 ___AH C:\Windows\setupact.log
2011-11-09 21:05 - 2009-07-13 20:53 - 0032656 ___AH C:\Windows\Tasks\SCHEDLGU.TXT
2011-11-09 20:54 - 2011-11-09 20:52 - 0000000 ___HD C:\Program Files\Common Files\PC Tools
2011-11-09 20:53 - 2011-11-09 20:52 - 1644120 ___AH C:\Windows\System32\Drivers\Cat.DB
2011-11-09 20:52 - 2011-11-09 20:51 - 0000000 ___HD C:\Users\All Users\PC Tools
2011-11-09 20:52 - 2011-11-09 20:51 - 0000000 ___HD C:\ProgramData\PC Tools
2011-11-09 20:51 - 2011-11-09 20:51 - 0512992 ___AH C:\Users\Editing\Desktop\PCTools_Safe_Install.exe
2011-11-09 20:50 - 2010-07-24 06:19 - 0000999 ___AH C:\Users\Editing\Desktop\magicJack.lnk
2011-11-09 20:50 - 2010-05-07 09:10 - 0000000 ___HD C:\Users\Editing\AppData\Roaming\mjusbsp
2011-11-09 20:49 - 2009-07-13 20:33 - 2228960 ___AH C:\Windows\System32\FNTCACHE.DAT
2011-11-09 20:48 - 2009-07-13 18:37 - 0000000 ___HD C:\Program Files\Common Files\System
2011-11-09 20:45 - 2009-11-09 03:30 - 50295240 ___AH (Microsoft Corporation) C:\Windows\System32\MRT.exe
2011-11-09 20:31 - 2011-11-09 20:31 - 0337760 ___AH C:\Users\All Users\ojQXTFdFCXgLmn.exe
2011-11-09 20:31 - 2011-11-09 20:31 - 0337760 ___AH C:\ProgramData\ojQXTFdFCXgLmn.exe
2011-11-09 20:31 - 2011-11-09 20:31 - 0000657 ___AH C:\Users\Editing\Desktop\System Restore.lnk
2011-11-09 20:31 - 2011-11-09 20:31 - 0000432 ___AH C:\Users\All Users\ojQXTFdFCXgLmn
2011-11-09 20:31 - 2011-11-09 20:31 - 0000432 ___AH C:\ProgramData\ojQXTFdFCXgLmn
2011-11-09 20:31 - 2011-11-09 20:31 - 0000296 ___AH C:\Users\All Users\~ojQXTFdFCXgLmn
2011-11-09 20:31 - 2011-11-09 20:31 - 0000296 ___AH C:\ProgramData\~ojQXTFdFCXgLmn
2011-11-09 20:31 - 2011-11-09 20:31 - 0000216 ___AH C:\Users\All Users\~ojQXTFdFCXgLmnr
2011-11-09 20:31 - 2011-11-09 20:31 - 0000216 ___AH C:\ProgramData\~ojQXTFdFCXgLmnr
2011-11-09 20:27 - 2011-10-11 10:58 - 0000000 __RHD C:\Users\Editing\Dropbox
2011-11-09 20:27 - 2011-10-11 10:57 - 0000000 ___HD C:\Users\Editing\AppData\Roaming\Dropbox
2011-11-09 20:27 - 2010-05-16 10:40 - 0005144 ___AH C:\Windows\System32\tversity.cookies
2011-11-09 20:27 - 2009-11-09 02:45 - 0282456 ___AH C:\Windows\PFRO.log
2011-11-09 14:49 - 2011-11-09 14:49 - 0000016 ___AH C:\Windows\System32\config\software.szfi
2011-11-09 13:28 - 2011-11-09 13:31 - 0423768 ___AH C:\Users\All Users\NgTUiSAcmhn.exe
2011-11-09 13:28 - 2011-11-09 13:31 - 0423768 ___AH C:\ProgramData\NgTUiSAcmhn.exe
2011-11-09 12:21 - 2009-07-13 18:37 - 0000000 ___HD C:\Windows\PLA
2011-11-09 10:53 - 2011-11-09 10:53 - 0000000 ___HD C:\Users\Editing\AppData\Roaming\Malwarebytes
2011-11-09 10:53 - 2011-11-09 10:53 - 0000000 ___HD C:\Users\All Users\Malwarebytes
2011-11-09 10:53 - 2011-11-09 10:53 - 0000000 ___HD C:\ProgramData\Malwarebytes
2011-11-09 10:53 - 2011-11-09 10:52 - 0000000 ___HD C:\Program Files\Malwarebytes' Anti-Malware
2011-11-09 10:52 - 2011-11-09 10:52 - 9852544 ___AH (Malwarebytes Corporation ) C:\Users\Editing\Downloads\mbam-setup-1.51.2.1300.exe
2011-11-09 10:41 - 2011-10-11 10:57 - 0001230 ___AH C:\Users\Editing\Start Menu\Programs\Startup\Dropbox.lnk
2011-11-09 10:41 - 2011-10-11 10:57 - 0001230 ___AH C:\Users\Editing\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
2011-11-09 10:40 - 2011-11-09 10:40 - 0161576 ___AH C:\Windows\Minidump\110911-26130-01.dmp
2011-11-09 10:13 - 2011-11-09 10:13 - 0000036 ___RH C:\Windows\System32\Drivers\etc\hosts
2011-11-09 10:11 - 2011-11-09 10:11 - 0000000 ___HD C:\Program Files\STOPzilla!
2011-11-09 10:11 - 2011-11-09 10:11 - 0000000 ___HD C:\Program Files\Common Files\iS3
2011-11-09 09:59 - 2011-11-09 09:56 - 0000448 ___AH C:\Users\All Users\QiTWKMe7r4NtRr
2011-11-09 09:59 - 2011-11-09 09:56 - 0000448 ___AH C:\ProgramData\QiTWKMe7r4NtRr
2011-11-09 09:57 - 2009-11-08 13:05 - 0750608 ___AH C:\Windows\System32\PerfStringBackup.INI
2011-11-09 09:56 - 2011-11-09 09:56 - 0000304 ___AH C:\Users\All Users\~QiTWKMe7r4NtRr
2011-11-09 09:56 - 2011-11-09 09:56 - 0000304 ___AH C:\ProgramData\~QiTWKMe7r4NtRr
2011-11-09 09:56 - 2011-11-09 09:56 - 0000224 ___AH C:\Users\All Users\~QiTWKMe7r4NtRrr
2011-11-09 09:56 - 2011-11-09 09:56 - 0000224 ___AH C:\ProgramData\~QiTWKMe7r4NtRrr
2011-11-04 22:47 - 2011-11-04 22:47 - 0738768 __RAH (iS3, Inc.) C:\Windows\System32\IS3Base5.dll
2011-11-04 22:47 - 2011-11-04 22:47 - 0546256 __RAH (iS3, Inc.) C:\Windows\System32\SZComp5.dll
2011-11-04 22:47 - 2011-11-04 22:47 - 0480720 __RAH (iS3, Inc.) C:\Windows\System32\SZBase5.dll
2011-11-04 22:47 - 2011-11-04 22:47 - 0456144 __RAH (iS3, Inc.) C:\Windows\System32\IS3DBA5.dll
2011-11-04 22:47 - 2011-11-04 22:47 - 0390608 __RAH (iS3, Inc.) C:\Windows\System32\IS3UI5.dll
2011-11-04 22:47 - 2011-11-04 22:47 - 0230864 __RAH (iS3, Inc.) C:\Windows\System32\IS3Win325.dll
2011-11-04 22:47 - 2011-11-04 22:47 - 0132560 __RAH (iS3, Inc.) C:\Windows\System32\IS3HTUI5.dll
2011-11-04 22:47 - 2011-11-04 22:47 - 0103888 __RAH (iS3, Inc.) C:\Windows\System32\IS3Inet5.dll
2011-11-04 22:47 - 2011-11-04 22:47 - 0099792 __RAH (iS3, Inc.) C:\Windows\System32\IS3Svc5.dll
2011-11-04 22:47 - 2011-11-04 22:47 - 0067024 __RAH (iS3, Inc.) C:\Windows\System32\IS3Hks5.dll
2011-11-04 22:47 - 2011-11-04 22:47 - 0028624 __RAH (iS3, Inc.) C:\Windows\System32\IS3XDat5.dll
2011-11-04 22:47 - 2011-11-04 22:47 - 0022992 __RAH (iS3, Inc.) C:\Windows\System32\SZIO5.dll
2011-11-03 11:59 - 2010-06-11 17:20 - 0000000 ___HD C:\Users\Editing\AppData\Roaming\FileZilla
2011-11-02 08:39 - 2011-11-02 08:39 - 0032690 ___AH C:\Users\Editing\Downloads\msg0005.WAV
2011-10-31 08:53 - 2011-10-31 08:53 - 0137232 ___AH C:\Users\Editing\Documents\attuverse-1.pdf
2011-10-31 08:31 - 2011-10-31 08:31 - 0173323 ___AH C:\Users\Editing\Documents\attuverse.pdf
2011-10-31 07:10 - 2010-09-03 08:10 - 0000219 ___AH C:\Windows\System32\lsprst7.tgz
2011-10-31 07:10 - 2010-09-03 08:10 - 0000205 ___AH C:\Windows\System32\lsprst7.dll
2011-10-31 07:10 - 2010-09-03 08:10 - 0000087 ___AH C:\Windows\System32\ssprs.tgz
2011-10-31 07:10 - 2010-09-03 08:10 - 0000073 ___AH C:\Windows\System32\ssprs.dll
2011-10-31 07:10 - 2010-09-03 08:10 - 0000021 ___AH C:\Windows\SurCode.INI
2011-10-29 16:57 - 2010-05-16 10:35 - 0000069 ___AH C:\Windows\NeroDigital.ini
2011-10-29 08:49 - 2011-06-17 04:56 - 0414368 ___AH (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2011-10-28 18:53 - 2010-08-24 11:17 - 0002409 ___AH C:\Users\Editing\Desktop\Google Chrome.lnk
2011-10-28 05:51 - 2011-10-28 05:51 - 1034094 ___AH C:\Users\Editing\Downloads\iStock_000017871434Medium.jpg
2011-10-27 18:09 - 2009-11-08 13:37 - 0000000 ___HD C:\Program Files\Mozilla Firefox
2011-10-26 15:06 - 2011-10-26 10:55 - 399537702 ___AH C:\Users\Editing\Downloads\studio2CityRightAnimated.mov
2011-10-26 15:05 - 2011-10-26 10:49 - 485018267 ___AH C:\Users\Editing\Downloads\studio2CityLoop.mov
2011-10-26 11:06 - 2011-10-26 11:06 - 0000000 ___HD C:\Users\Editing\Downloads\iPhoneTemplate
2011-10-26 11:04 - 2010-05-15 10:37 - 0000000 ___HD C:\Users\Editing\Documents\Adobe
2011-10-26 10:40 - 2011-10-26 10:38 - 248970046 ___AH C:\Users\Editing\Downloads\iPhoneTemplate.zip
2011-10-19 14:26 - 2011-10-19 14:26 - 0545542 ___AH C:\Users\Editing\Downloads\Vistaprint_Car_Door_Magnets-Large.zip
2011-10-19 14:26 - 2011-10-19 14:26 - 0000000 ___HD C:\Users\Editing\Downloads\Vistaprint_Car_Door_Magnets-Large
2011-10-14 00:21 - 2010-12-16 11:32 - 0000000 ___HD C:\Program Files\Microsoft Silverlight
2011-10-11 13:22 - 2010-08-12 05:47 - 0000000 ___HD C:\Users\Editing\AppData\Roaming\Skype
2011-10-11 13:19 - 2011-11-09 13:26 - 0002503 ___AH C:\Users\Public\Desktop\Skype.lnk
2011-10-11 13:19 - 2010-08-12 05:46 - 0000000 __RHD C:\Program Files\Skype
2011-10-11 13:19 - 2010-08-12 05:46 - 0000000 ___HD C:\Users\All Users\Skype
2011-10-11 13:19 - 2010-08-12 05:46 - 0000000 ___HD C:\ProgramData\Skype
2011-10-11 13:18 - 2010-08-12 05:47 - 0000000 ___HD C:\Users\Editing\AppData\Roaming\skypePM
2011-10-11 10:58 - 2011-10-11 10:58 - 0001043 ___AH C:\Users\Editing\Desktop\Dropbox.lnk
2011-10-11 10:58 - 2010-05-06 16:34 - 0000000 ___HD C:\users\Editing
2011-10-11 10:57 - 2011-10-11 10:57 - 16215808 ___AH (Dropbox, Inc.) C:\Users\Editing\Downloads\Dropbox 1.1.45.exe
2011-10-11 10:03 - 2011-10-11 10:03 - 0173466 ___AH C:\Users\Editing\Documents\Sugarsave - text club flyer.pdf
2011-10-11 10:03 - 2011-10-11 08:53 - 0183971 ___AH C:\Users\Editing\Documents\Sugarsave - text club flyer.docx
2011-10-11 09:00 - 2011-10-11 09:00 - 0306544 ___AH C:\Users\Editing\Documents\Sugarsave - local coupon program flyer.pdf
2011-10-11 08:53 - 2011-10-11 08:53 - 0320640 ___AH C:\Users\Editing\Documents\Sugarsave - local coupon program flyer.docx
2011-10-05 10:59 - 2011-10-05 09:44 - 0000000 ___HD C:\Program Files\SophieSew
2011-10-05 09:44 - 2011-10-05 09:44 - 4530015 ___AH (Carlos Mandell, Inc. ) C:\Users\Editing\Downloads\SophieSew_SetUp_1_13B42.exe
2011-10-01 06:21 - 2011-10-01 06:21 - 0023325 ___AH C:\Users\Editing\Documents\Bruce Thompson's Resume 0410bc.pdf
2011-09-29 08:03 - 2011-11-09 13:37 - 1290608 ___AH (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2011-09-28 19:37 - 2011-11-09 13:37 - 2341888 ___AH (Microsoft Corporation) C:\Windows\System32\win32k.sys
2011-09-26 10:21 - 2011-09-26 10:21 - 0061328 __RAH (iS3 Inc.) C:\Windows\System32\Drivers\SZKG.sys
2011-09-26 10:21 - 2011-09-26 10:21 - 0061328 __RAH (iS3 Inc.) C:\Windows\System32\Drivers\is3srv.sys
2011-09-22 06:44 - 2011-09-22 06:44 - 5869972 ___AH C:\Users\Editing\Downloads\CMS Career Orientation Comp Plan1.WMA
2011-09-22 05:39 - 2011-09-22 05:39 - 10854580 ___AH C:\Users\Editing\Downloads\CMS Career Orientation Overview1.WMA
2011-09-20 08:44 - 2011-09-20 08:44 - 0567413 ___AH C:\Users\Editing\Downloads\photo.JPG
2011-09-16 03:27 - 2009-07-13 18:37 - 0000000 ____D C:\Windows\rescache
2011-08-31 18:36 - 2011-10-14 00:03 - 12275200 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2011-08-31 18:35 - 2011-10-14 00:03 - 1798144 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2011-08-31 18:33 - 2011-10-14 00:03 - 9704960 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2011-08-31 18:28 - 2011-10-14 00:03 - 1126912 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2011-08-31 18:28 - 2011-10-14 00:03 - 1102848 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2011-08-31 18:27 - 2011-10-14 00:03 - 0231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2011-08-31 18:26 - 2011-10-14 00:03 - 0065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2011-08-31 18:24 - 2011-10-14 00:03 - 0716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2011-08-31 18:23 - 2011-10-14 00:03 - 1791488 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2011-08-31 18:23 - 2011-10-14 00:03 - 0072704 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2011-08-31 18:22 - 2011-10-14 00:03 - 2382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2011-08-31 18:21 - 2011-10-14 00:03 - 0176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2011-08-31 17:42 - 2011-08-31 16:57 - 3882604 ___AH C:\Users\Editing\Documents\f1099msc-4a.pdf
2011-08-31 16:37 - 2011-08-31 16:46 - 0073293 ___AH C:\Users\Editing\Documents\f1099msc.pdf
2011-08-26 20:26 - 2011-10-13 01:04 - 0571904 ____A (Microsoft Corporation) C:\Windows\System32\oleaut32.dll
2011-08-26 20:26 - 2011-10-13 01:04 - 0233472 ____A (Microsoft Corporation) C:\Windows\System32\oleacc.dll
2011-08-20 00:18 - 2010-07-16 17:07 - 0000000 ___HD C:\Users\Editing\AppData\Local\Visual Web Ripper

========================= Known DLLs (Whitelisted) ============

C:\Windows\SysWOW64\clbcatq.dll is missing
C:\Windows\SysWOW64\ole32.dll is missing
C:\Windows\SysWOW64\advapi32.dll is missing
C:\Windows\SysWOW64\COMDLG32.dll is missing
C:\Windows\SysWOW64\gdi32.dll is missing
C:\Windows\SysWOW64\IERTUTIL.dll is missing
C:\Windows\SysWOW64\IMAGEHLP.dll is missing
C:\Windows\SysWOW64\IMM32.dll is missing
C:\Windows\SysWOW64\kernel32.dll is missing
C:\Windows\SysWOW64\LPK.dll is missing
C:\Windows\SysWOW64\MSCTF.dll is missing
C:\Windows\SysWOW64\MSVCRT.dll is missing
C:\Windows\SysWOW64\NORMALIZ.dll is missing
C:\Windows\SysWOW64\NSI.dll is missing
C:\Windows\SysWOW64\OLEAUT32.dll is missing
C:\Windows\SysWOW64\PSAPI.dll is missing
C:\Windows\SysWOW64\rpcrt4.dll is missing
C:\Windows\SysWOW64\sechost.dll is missing
C:\Windows\SysWOW64\Setupapi.dll is missing
C:\Windows\SysWOW64\SHELL32.dll is missing
C:\Windows\SysWOW64\SHLWAPI.dll is missing
C:\Windows\SysWOW64\URLMON.dll is missing
C:\Windows\SysWOW64\user32.dll is missing
C:\Windows\SysWOW64\USP10.dll is missing
C:\Windows\SysWOW64\WININET.dll is missing
C:\Windows\SysWOW64\WLDAP32.dll is missing
C:\Windows\SysWOW64\WS2_32.dll is missing
C:\Windows\SysWOW64\DifxApi.dll is missing

========================= Bamital & volsnap Check ============

C:\Windows\System32\winlogon.exe
[2011-05-25 15:12] - [2010-11-20 04:17] - 0286720 ____A (Microsoft Corporation) 6D13E1406F50C66E2A95D97F22C47560

C:\Windows\System32\wininit.exe
[2009-07-13 15:36] - [2009-07-13 17:14] - 0096256 ____A (Microsoft Corporation) B5C5DCAD3899512020D135600129D665

C:\Windows\explorer.exe
[2011-04-27 16:54] - [2011-02-24 21:30] - 2616320 ____A (Microsoft Corporation) 8B88EBBB05A0E56B7DCC708498C02B3E

C:\Windows\System32\Drivers\volsnap.sys
[2011-05-25 15:12] - [2010-11-20 04:30] - 0245632 ____A (Microsoft Corporation) F497F67932C6FA693D7DE2780631CFE7


========================= Memory info ======================

Percentage of memory in use: 8%
Total physical RAM: 12279.12 MB
Available physical RAM: 11293.7 MB
Total Pagefile: 12277.27 MB
Available Pagefile: 11285.98 MB
Total Virtual: 8192 MB
Available Virtual: 8191.89 MB

======================= Partitions =========================

1 Drive c: () (Fixed) (Total:139.64 GB) (Free:25.75 GB) NTFS
2 Drive d: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS
3 Drive f: (CD_ROM) (CDROM) (Total:0.19 GB) (Free:0 GB) CDFS
4 Drive g: (U3 System) (CDROM) (Total:0.01 GB) (Free:0 GB) CDFS
5 Drive h: () (Removable) (Total:1.9 GB) (Free:1.74 GB) FAT
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
7 Drive y: (Storage) (Fixed) (Total:931.5 GB) (Free:846.05 GB) NTFS

==========================================================

Last Boot: 2011-11-09 16:48

======================= End Of Log ==========================

#6 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,700 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:07:26 AM

Posted 15 November 2011 - 04:30 PM

Wow. That computer was hit hard. We have Registry entries and files missing.

Download MBRFix from here.

Save and extract its contents to the working computer's desktop. There are three files in the MBRFix folder. From these, only copy the MBRFix64.exe to the USB drive.

Also download the enclosed file and save it in the USB drive.

Insert the USB drive into the ailing computer.

Now please enter System Recovery Options and run FRST64 as you did before, except that this time around, press the Fix button just once and wait.

The tool will make a log on the flashdrive (Fixlog.txt). It will also create a file labeled MBRDUMP.txt. Copy and Paste the contents of the Fixlog.txt in your next reply, but attach the MBRDUMP.txt as it is a hex file.

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#7 84xads

84xads
  • Topic Starter

  • Members
  • 36 posts
  • OFFLINE
  •  
  • Local time:05:26 AM

Posted 15 November 2011 - 05:29 PM

FRST did not create a MBRDUMp.txt file, but here is the fixlog.txt




Fix result of Farbars's Recovery Tool (FRST written by farbar Version 2.2.7)
Ran by SYSTEM at 2011-11-15 16:22:46 R:1
Running from H:\

==============================================

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Windows Mobile Device Center Value deleted successfully.
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\NgTUiSAcmhn.exe Value deleted successfully.
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ZwwkkUUVrlOtx0y8234A Value deleted successfully.
HKEY_USERS\Editing\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge Value deleted successfully.
C:\Windows\System32\AV Security 2012v121.exe moved successfully.
C:\AV Security 2012.lnk moved successfully.
C:\AV Security 2012 moved successfully.
C:\Users\All Users\ojQXTFdFCXgLmn.exe moved successfully.
C:\ProgramData\ojQXTFdFCXgLmn.exe not found.
C:\Users\Editing\Desktop\System Restore.lnk moved successfully.
C:\Users\All Users\ojQXTFdFCXgLmn moved successfully.
C:\ProgramData\ojQXTFdFCXgLmn not found.
C:\Users\All Users\~ojQXTFdFCXgLmn moved successfully.
C:\ProgramData\~ojQXTFdFCXgLmn not found.
C:\Users\All Users\~ojQXTFdFCXgLmnr moved successfully.
C:\ProgramData\~ojQXTFdFCXgLmnr not found.
C:\Users\All Users\QiTWKMe7r4NtRr moved successfully.
C:\ProgramData\QiTWKMe7r4NtRr not found.
C:\Users\All Users\~QiTWKMe7r4NtRr moved successfully.
C:\ProgramData\~QiTWKMe7r4NtRr not found.
C:\Users\All Users\~QiTWKMe7r4NtRrr moved successfully.
C:\ProgramData\~QiTWKMe7r4NtRrr not found.
C:\Windows\ntbtlog.txt moved successfully.
C:\Windows\System32\AV Security 2012v121.exe not found.
C:\AV Security 2012.lnk not found.
C:\AV Security 2012 not found.
C:\Users\All Users\ojQXTFdFCXgLmn.exe not found.
C:\ProgramData\ojQXTFdFCXgLmn.exe not found.
C:\Users\Editing\Desktop\System Restore.lnk not found.
C:\Users\All Users\ojQXTFdFCXgLmn not found.
C:\ProgramData\ojQXTFdFCXgLmn not found.
C:\Users\All Users\~ojQXTFdFCXgLmn not found.
C:\ProgramData\~ojQXTFdFCXgLmn not found.
C:\Users\All Users\~ojQXTFdFCXgLmnr not found.
C:\ProgramData\~ojQXTFdFCXgLmnr not found.
C:\Users\All Users\QiTWKMe7r4NtRr not found.
C:\ProgramData\QiTWKMe7r4NtRr not found.
C:\Users\All Users\~QiTWKMe7r4NtRr not found.
C:\ProgramData\~QiTWKMe7r4NtRr not found.
C:\Users\All Users\~QiTWKMe7r4NtRrr not found.
C:\ProgramData\~QiTWKMe7r4NtRrr not found.
DEFAULT hive was successfully copied to System32\config\HiveBackup
DEFAULT hive was successfully restored from registry back up.
SAM hive was successfully copied to System32\config\HiveBackup
SAM hive was successfully restored from registry back up.
SECURITY hive was successfully copied to System32\config\HiveBackup
SECURITY hive was successfully restored from registry back up.
SOFTWARE hive was successfully copied to System32\config\HiveBackup
SOFTWARE hive was successfully restored from registry back up.
SYSTEM hive was successfully copied to System32\config\HiveBackup
SYSTEM hive was successfully restored from registry back up.
C:\MBRFix64 /drive 0 savembr H:\MBRDUMP.txt not found.

==== End of Fixlog ====

#8 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,700 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:07:26 AM

Posted 15 November 2011 - 06:17 PM

My fault. Had a syntax error in the fix.

Download the enclosed file and save it in the USB drive, overwriting the existing one.

Insert the USB drive into the ailing computer.

Now please enter System Recovery Options and run FRST64 as you did before, except that this time around, press the Fix button just once and wait.

The tool will make a log on the flashdrive (Fixlog.txt). It will also create a file labeled MBRDUMP.txt. Copy and Paste the contents of the Fixlog.txt in your next reply, but attach the MBRDUMP.txt as it is a hex file.

Edited by JSntgRvr, 15 November 2011 - 06:21 PM.

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#9 84xads

84xads
  • Topic Starter

  • Members
  • 36 posts
  • OFFLINE
  •  
  • Local time:05:26 AM

Posted 15 November 2011 - 06:50 PM

Fix result of Farbars's Recovery Tool (FRST written by farbar Version 2.2.7)
Ran by SYSTEM at 2011-11-15 17:48:01 R:2
Running from H:\

==============================================


========= H:\MBRFix64 /drive 0 savembr H:\MBRDUMP.txt =========


========= End of CMD: =========


==== End of Fixlog ====

Attached Files



#10 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,700 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:07:26 AM

Posted 15 November 2011 - 07:05 PM

The MBR is infected.

Download the enclosed file and save it in the USB drive, overwriting the existing one.

Insert the USB drive into the ailing computer.

Now please enter System Recovery Options and run FRST64 as you did before, except that this time around, press the Fix button just once and wait. It will take a while as it will be removing the hidden file attribute to every file and folder in the drive, except for those with a System attribute. Be patient.

The tool will make a log on the flashdrive (Fixlog.txt). Copy and Paste the contents of the Fixlog.txt in your next reply.

If successful, attempt to boot in Normal Mode. If able to do so, run Combofix as follows:

Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
  • Please, never rename Combofix unless instructed.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    -----------------------------------------------------------

    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link or this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      If AVG or CA Internet Security Suite is installed, you must remove these programs before using Combofix. If any of these applications will not uninstall, it is first recommended to uninstall it with AppRemover by Opswat. http://www.appremover.com/supported-applications. Do not use AppRemover on Norton

      -----------------------------------------------------------

    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

    -----------------------------------------------------------

  • Double click on combofix.exe & follow the prompts.
  • Install the Recovery Console if prompted.
  • When finished, it will produce a report for you.
  • Please post the "C:\ComboFix.txt" .
**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

Note: ComboFix may reset a number of Internet Explorer's settings, including making it the default browser.
Note: Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security.

Please do not install any new programs or update anything (always allow your antivirus/antispyware to update) unless told to do so while we are fixing your problem. If combofix alerts to a new version and offers to update, please let it. It is essential we always use the latest version.

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#11 84xads

84xads
  • Topic Starter

  • Members
  • 36 posts
  • OFFLINE
  •  
  • Local time:05:26 AM

Posted 15 November 2011 - 08:35 PM

I ran the Fix but can't boot in Normal mode...my fixlog.txt is too large to upload. I'll see if I can break it up over separate posts.


Fix result of Farbars's Recovery Tool (FRST written by farbar Version 2.2.7)
Ran by SYSTEM at 2011-11-15 18:19:29 R:3
Running from H:\

==============================================


========= Attrib -h c:\*.* /S /D =========

Not resetting system file - C:\$Recycle.Bin\S-1-5-21-1069887610-648576151-850243678-1005\$RGTP7R3\desktop.ini
Not resetting system file - C:\$Recycle.Bin\S-1-5-21-1069887610-648576151-850243678-1005\$RQ6SDF6\desktop.ini
Not resetting system file - C:\$Recycle.Bin\S-1-5-21-1069887610-648576151-850243678-1005\desktop.ini
Not resetting system file - C:\$Recycle.Bin\S-1-5-21-1069887610-648576151-850243678-501\desktop.ini
Not resetting system file - C:\$Recycle.Bin\S-1-5-21-1069887610-648576151-850243678-1005
Not resetting system file - C:\$Recycle.Bin\S-1-5-21-1069887610-648576151-850243678-501
Not resetting system file - C:\Program Files\ACD Systems\ACDSee Pro\3.0\AlbumGenerator\Thumbs.db
Not resetting system file - C:\Program Files\Adobe\Adobe Extension Manager CS4\ReadMe\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Cool Extras\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Plug-ins\Extensions\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Plug-ins\Illustrator Filters\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Plug-ins\Illustrator Formats\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Plug-ins\Photoshop Effects\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Plug-ins\Photoshop Filters\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Plug-ins\Photoshop Formats\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Plug-ins\Text Filters\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Plug-ins\Tools\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Plug-ins\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Presets\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Read Me\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Scripting\Documentation\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\JavaScript\AutoCAD\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\JavaScript\Datasets\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\JavaScript\FXG\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\JavaScript\Glyphs\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\JavaScript\Gradients\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\JavaScript\Miscellaneous\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\JavaScript\MultiArtboards\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\JavaScript\Swatches\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\JavaScript\Working With Paths\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\JavaScript\Working With Symbols\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\JavaScript\Working With Text\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\JavaScript\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\AutoCAD\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\CalendarSample\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\Collect for Output\sample\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\Collect for Output\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\ColorWheel\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\ContactSheet\images\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\ContactSheet\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\CycleGraph\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\Export Flash Animation\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\Glyphs\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\Gradients\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\Miscellaneous\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\MultiArtboards\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\Sierpinski\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\Swatches\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\Web Gallery\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\Working with Datasets\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\Working with Path Points\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\Working With Symbols\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\Working with Tagged Art\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\Working With Text\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\desktop.ini
Not resetting system file - C:\Program Files\Adobe\Adobe Illustrator CS4\Scripting\desktop.ini
Not resetting system file - C:\Program Files\Common Files\ACD Systems\borders\textures\Thumbs.db
Not resetting system file - C:\Program Files\Common Files\microsoft shared\Stationery\Desktop.ini
Not resetting system file - C:\Program Files\Microsoft Games\Chess\desktop.ini
Not resetting system file - C:\Program Files\Microsoft Games\FreeCell\desktop.ini
Not resetting system file - C:\Program Files\Microsoft Games\Hearts\desktop.ini
Not resetting system file - C:\Program Files\Microsoft Games\Mahjong\desktop.ini
Not resetting system file - C:\Program Files\Microsoft Games\Purble Place\desktop.ini
Not resetting system file - C:\Program Files\Microsoft Games\Solitaire\desktop.ini
Not resetting system file - C:\Program Files\Microsoft Games\SpiderSolitaire\desktop.ini
Not resetting system file - C:\Program Files\UltraISO\backup
Not resetting system file - C:\Program Files\Windows Mail\WinMail.exe
Not resetting system file - C:\Program Files\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Extension Manager CS4\ReadMe\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Cool Extras\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Plug-ins\Extensions\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Plug-ins\Illustrator Filters\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Plug-ins\Illustrator Formats\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Plug-ins\Photoshop Effects\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Plug-ins\Photoshop Filters\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Plug-ins\Photoshop Formats\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Plug-ins\Text Filters\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Plug-ins\Tools\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Plug-ins\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Presets\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Read Me\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Scripting\Documentation\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\JavaScript\AutoCAD\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\JavaScript\Datasets\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\JavaScript\FXG\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\JavaScript\Glyphs\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\JavaScript\Gradients\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\JavaScript\Miscellaneous\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\JavaScript\MultiArtboards\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\JavaScript\Swatches\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\JavaScript\Working With Paths\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\JavaScript\Working With Symbols\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\JavaScript\Working With Text\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\JavaScript\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\AutoCAD\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\CalendarSample\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\Collect for Output\sample\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\Collect for Output\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\ColorWheel\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\ContactSheet\images\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\ContactSheet\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\CycleGraph\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\Export Flash Animation\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\Glyphs\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\Gradients\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\Miscellaneous\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\MultiArtboards\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\Sierpinski\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\Swatches\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\Web Gallery\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\Working with Datasets\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\Working with Path Points\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\Working With Symbols\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\Working with Tagged Art\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\Working With Text\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\Visual Basic\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Scripting\Sample Scripts\desktop.ini
Not resetting system file - C:\Program Files (x86)\Adobe\Adobe Illustrator CS4\Scripting\desktop.ini
Not resetting system file - C:\Program Files (x86)\Common Files\microsoft shared\Stationery\Desktop.ini
Not resetting system file - C:\Program Files (x86)\CyberLink\PowerDVD\Product.Id
Not resetting system file - C:\Program Files (x86)\Windows Mail\WinMail.exe
Not resetting system file - C:\Program Files (x86)\desktop.ini
Not resetting system file - C:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_CValidator.H1D
Not resetting system file - C:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MKWD_AssetId.H1W
Not resetting system file - C:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MKWD_BestBet.H1W
Not resetting system file - C:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MTOC_help.H1H
Not resetting system file - C:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MValidator.H1D
Not resetting system file - C:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MValidator.Lck
Not resetting system file - C:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help{9DAA54E8-CD95-4107-8E7F-BA3F24732D95}.H1Q
Not resetting system file - C:\ProgramData\Microsoft\Crypto\Keys\111f1076540215d8eac27e3480a140f0_ee7e024f-2431-4352-b104-3ef11701e54d
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\024973121aa8de831992cc6ff58a05cb_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\026ad28fee0e3057ecc1169cfe8fd094_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\02824be4d0169133f62504e04613fc00_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\03c9fba1be8af62b4bed344bd75f7a9d_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\0544efc04480ac91f44e0003bc8e74ce_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\062f08cbd7c8ca3c3dbd37c04a9c3697_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\07ac20e7ca1544d6de72b62027138d1b_ee7e024f-2431-4352-b104-3ef11701e54d
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\07eb217be261d5e8f5e7a86a8573f957_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\0ae572a30725394c0fe89f418d9ecad9_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\0b1b767000e0beffea2d6347d0322185_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\0b652fee9f149fe5cb9c9476abedf921_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\0ba3e0f3f3151897e41753b90049c21f_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\0f0ad02a534993ff323c5fb7c29324c8_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\101f15e4eabdf94ec5ac62c0d20d69f6_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\137c2522718b63d99ff13d086c237672_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\13af81527d330ca8eaa440ac441e57a5_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1489168690cb92189782a76130ea95f0_ee7e024f-2431-4352-b104-3ef11701e54d
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\149a95f66f97926d46186872dd140af5_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\172a5d40abc02f42264572f93f030e15_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\17f2889d8b3801a9295b866e0595047e_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\18bedf06fa314a66e2cec196e6fb7747_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1cabaa60a78b3ee80512eadeba41dc01_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1d17a584ac4790fd9204af9a2b532de5_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1d49c0e94bc71a0ff5bdc0d657b6e2a2_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1fd2fc6e8a4ab541b72c671fe2adb5ec_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\21002542309313fd8c1aa27902b03197_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\239119931bc69a58a73917c1d7d3c545_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\24d6adc0f1f7f60bebd7b70c6bd4ea1c_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2679d19b38106bebfd1d3793d74fe75e_ee7e024f-2431-4352-b104-3ef11701e54d
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\28166b877c6c2cf95bc989c4fcbd6d42_ee7e024f-2431-4352-b104-3ef11701e54d
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\28d060774ebbbef2eaa6d97327ad963f_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\29f7289f15e7a5e0ba68712dc753a41b_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2b3d3e236e6a2bd1371479ec38fe6e48_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2bae2be4c2063a73f86807cf97aa75aa_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2e5900bee909c2c234a1feb474e444ae_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2ff15160333c1e8689ec4dcdadc01fc9_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\33e78e65fcca5b7d795e4473ff8e2947_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\352a1092e3cd0fed65f7eb770e4a7728_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\374cad7869d110d252b8c8681e7c02f2_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\377620de22656a0c363579f6bd9e6cf8_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\37f822ae4cffdc48506e1a144d4562e2_ee7e024f-2431-4352-b104-3ef11701e54d
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\38f5319c0af41000be25210d919a3df5_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\39fefb42dfd01a90d37dc73a01635955_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3bc16aff374de350d64f1f259db9d037_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\409f0351d1022a05a878af40f51c7cfa_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\43452f764f108b481a5d9a82082dc4e7_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\45cde4aef74f5b8d7d3b6813c01f4103_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4b882c1840172acb33978945f7fd24f9_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4bdc7c85f8dd9561786a1bf0b1d64cf8_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\547bcf06dc309838005de0d84205fe62_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5488b49411ed5b74bf94863bb303f966_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5679a202ebdee729c00b8d3f1a989928_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\568943849c3dcab69a04095e961f67a9_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\58225e44c87616c32329d29b233318ad_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\59be0df8ba657281c53cc74113f1fe5d_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\59ddc55e9276b1ffb8490724a0b04ff7_ee7e024f-2431-4352-b104-3ef11701e54d
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\59de45a1026dc795d5fb878ee748e626_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5a07520ea333a70484f27e166dca924b_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5aa39941f7e8b52f3f4b9e20fee5f40a_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5dfb336e43c6b7f9e19b7b1d534724df_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\60441755d82ad0339aae473e64d9db6c_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\606632123643aa93732bc2c6bca6d510_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\606c6e549c9dceb4bc4b3a946bfa58ea_ee7e024f-2431-4352-b104-3ef11701e54d
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\62ccdb71e5a0a9bb8414a33de13babfc_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\632a6ea8f322106f4178dc10dfe6d39c_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6a602ac655beaeb81b7785952c41dd5b_ee7e024f-2431-4352-b104-3ef11701e54d
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6cb3f9d14c7ca8457f3f4c8661dd7fb0_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7358b9561b7099bbb40ef85219c3dcbf_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\73b997fbfb3beb62cbbd642ca853b3db_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\746bc2ee54d1c7ca37da9d6ce22bb2f4_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7824ce10328b9a593e22ff4d6af63787_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7c10d8753a05fea82c41ec43299b2491_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7fb92b499a0a3e30ade893d3a025ffda_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8103f2baac771eef1905c1dec44ee62f_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8176d7a3823ef2ce971ef88512474750_ee7e024f-2431-4352-b104-3ef11701e54d
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\85adb3f6841f918b294d21e7b6c3d17c_ee7e024f-2431-4352-b104-3ef11701e54d
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\89cbe48bfa44fe72b0afad741de99a76_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8a2983f680c06d44dc846d3a85715d59_ee7e024f-2431-4352-b104-3ef11701e54d
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8a4366ada72a95c8a25d8fa824fc27a8_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8be7904eb532ba92ec4f0e62864247f4_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8e01b9c95d54305f29b842fc9616acfd_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8ef5825d82b61c5d79f623428c3018bc_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\95a151e3850cc540df8c9f863dc2d1a3_ee7e024f-2431-4352-b104-3ef11701e54d
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\976c8cb2dce7c4fef96b45aa11a5c179_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9e120d838ffa74a8bf426b721eda6262_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9ed27f199566de19dd27fe32103535c1_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9f101e6974da6dae35c5099599c4e777_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a35a0ffbbe37d3d10124930c76a8c0a1_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a44e753e2a3f43c849eaea1851bbc3f1_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a61e75ffef06c65003dd593e5601fde0_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a6f20be52ad41d977f080324102fa4d6_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a91a4479c38e892b37004395fea7ad34_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\aa873b3464d826bdf2a1943953ffa8fa_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\aabd85a7e804f87cc67e7ab79742ecf1_ee7e024f-2431-4352-b104-3ef11701e54d
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\acab233ed89ca0efa33d52d153a0f208_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ae0622dabf948616a808fbbcebb584f1_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\aec1120f1fe15586b27488db1443f0de_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\aedd6d6236ee9808da3a954d997afe61_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b155d94e58190064cea033a11a334fea_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b38a586dedfa31839ff74b449305f815_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b5866f6cd59e927c4e7f5f94b77fbb3d_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\bc692958ff4755e00e6f3275f3ddaf03_ee7e024f-2431-4352-b104-3ef11701e54d
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\bd644ec75286548324d66d49c3a7e1ea_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\bf2222c280e4794996c329a8bdb1a4ef_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\bf307cd727dca9b5fe13a97c96ed2e48_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c05f7f1c27821103c9e18ea5bf2da69f_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c18de722864b166e7ab81c6c9f9e8e3a_ee7e024f-2431-4352-b104-3ef11701e54d
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c3c54966ad173664646d3059b879185b_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c95de68e9ac46f3beac48c494e669ef2_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\cd9350120d40bed3870974891ce7723d_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\cf509f9851c489d76eaca119f4a0be09_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d0e719ca7638c20c117b81654a116831_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d141a9d5c900d4535129b980960b6481_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d1b121f8754843afedbb572892fe33f6_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d2fd63ed240d032b43a273d1f06bf9a1_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d4a2ee2f7d5feb3560f54fac0ae913d6_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\da1c310b30dac6fbb0921ec8ed43a07d_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\db4b7e6e612b56541202f1d1795fc574_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\db7a5c2b9687cbc2b7418c340a66c271_ee7e024f-2431-4352-b104-3ef11701e54d
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ddd7b3fff5a1a636f1ee79a5e50f2780_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e2a9675709d80e95507247ea174972e5_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e3a25ca37b69b1bd18a05db994900c8a_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e54b07d65fd932efb4057008df087768_ee7e024f-2431-4352-b104-3ef11701e54d
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e587c6775f790345cc3bb395f858972b_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ea953e500e5e45d19f6ef4b0e6bd6c80_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\eb2bae432fdad7ab9b2ca57eaf8b898f_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ed184063cf105a5cc169e2db3e30818c_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ee0d7e79fd8a7c8019ca41bd7534fa25_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ee8012831c66f676a364b8ecf080ad19_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ef8a7448b588c959e9f1d336e25bfd45_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f0394560491cf88d9f63a19572cb5947_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f1c32bf9fbe41577bff001001d8d4c1a_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f686aace6942fb7f7ceb231212eef4a4_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fc1e3851f429ea606d6ff1e01a5229f1_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fc89010cdaf22be6b911837a37e56d2d_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fc9af1bef626ce73816bed125ba43ec6_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fddf046a3d84c2d92a91cc46f86e77b0_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fe4004f79aa4cbb3e2a39b79f78224da_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5d91c0b736f4f8dbdd317cf8a037fced_ee7e024f-2431-4352-b104-3ef11701e54d
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\6b29ae44e85efac3c72ff4d1865d73f1_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\83aa4cc77f591dfc2374580bbd95f6ba_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\d42cc0c3858a58db2db37658219e6400_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18
Not resetting system file - C:\ProgramData\Microsoft\Crypto\Keys
Not resetting system file - C:\ProgramData\Microsoft\DRM\Server
Not resetting system file - C:\ProgramData\Microsoft\PlayReady\Cache\S-1-5-21-1069887610-648576151-850243678-1005\MSPRindiv01.key
Not resetting system file - C:\ProgramData\Microsoft\PlayReady\Cache\indiv01.bla
Not resetting system file - C:\ProgramData\Microsoft\PlayReady\Cache\indiv01.key
Not resetting system file - C:\ProgramData\Microsoft\PlayReady\Cache\indiv01.tmp
Not resetting system file - C:\ProgramData\Microsoft\PlayReady\Cache
Not resetting system file - C:\ProgramData\Microsoft\Windows\DRM\Cache\Indiv_SID_S-1-5-18\Indiv01.key
Not resetting system file - C:\ProgramData\Microsoft\Windows\DRM\Cache\Indiv_SID_S-1-5-20\Indiv01.key
Not resetting system file - C:\ProgramData\Microsoft\Windows\DRM\Cache\Indiv_SID_S-1-5-21-1069887610-648576151-850243678-1005\Indiv01.key
Not resetting system file - C:\ProgramData\Microsoft\Windows\DRM\Cache\Indiv01.bla
Not resetting system file - C:\ProgramData\Microsoft\Windows\DRM\Cache\Indiv01.key
Not resetting system file - C:\ProgramData\Microsoft\Windows\DRM\Cache\Indiv01.tmp
Not resetting system file - C:\ProgramData\Microsoft\Windows\DRM\blackbox.bin
Not resetting system file - C:\ProgramData\Microsoft\Windows\DRM\Cache
Not resetting system file - C:\ProgramData\Microsoft\Windows\DRM\drmstore.hds
Not resetting system file - C:\ProgramData\Microsoft\Windows\DRM\DRMv1.bak
Not resetting system file - C:\ProgramData\Microsoft\Windows\DRM\DRMv1.key
Not resetting system file - C:\ProgramData\Microsoft\Windows\DRM\IndivBox.key
Not resetting system file - C:\ProgramData\Microsoft\Windows\DRM\v2ksndv.bla
Not resetting system file - C:\ProgramData\Microsoft\Windows\DRM\v3ks.bla
Not resetting system file - C:\ProgramData\Microsoft\Windows\DRM\v3ks.sec
Not resetting system file - C:\ProgramData\Microsoft\Windows\Ringtones\desktop.ini
Not resetting system file - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Desktop.ini
Not resetting system file - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Desktop.ini
Not resetting system file - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\Desktop.ini
Not resetting system file - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\desktop.ini
Not resetting system file - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini
Not resetting system file - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini
Not resetting system file - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Desktop.ini
Not resetting system file - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini
Not resetting system file - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
Not resetting system file - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Virtual PC\desktop.ini
Not resetting system file - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini
Not resetting system file - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice.org 3.3
Not resetting system file - C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini
Not resetting system file - C:\ProgramData\Microsoft\Windows\AIT
Not resetting system file - C:\ProgramData\Microsoft\Windows\DRM
Not resetting system file - C:\ProgramData\Norton\symdata.xml
Not resetting system file - C:\ProgramData\Symantec\symdata.xml
Not resetting system file - C:\ProgramData\TechSmith\Camtasia Studio\Library\Target_Blue_Title\Thumbs.db
Not resetting system file - C:\ProgramData\Documents
Not resetting system file - C:\ProgramData\Microsoft
Not resetting system file - C:\Recovery\215ff935-7884-11de-bc5b-80dfd9bad690\boot.sdi
Not resetting system file - C:\Recovery\215ff935-7884-11de-bc5b-80dfd9bad690\Winre.wim
Not resetting system file - C:\Recovery\215ff935-7884-11de-bc5b-80dfd9bad690
Not resetting system file - C:\Sandbox\Editing\DefaultBox\desktop.ini
Not resetting system file - C:\Sandbox\Editing\DefaultBox\RegHive.LOG1
Not resetting system file - C:\Sandbox\Editing\DefaultBox\RegHive.LOG2
Not resetting system file - C:\Sandbox\Editing\DefaultBox\RegHive{fe9cf9a5-8e56-11df-9d03-00248c44f7fb}.TM.blf
Not resetting system file - C:\Sandbox\Editing\DefaultBox\RegHive{fe9cf9a5-8e56-11df-9d03-00248c44f7fb}.TMContainer00000000000000000001.regtrans-ms
Not resetting system file - C:\Sandbox\Editing\DefaultBox\RegHive{fe9cf9a5-8e56-11df-9d03-00248c44f7fb}.TMContainer00000000000000000002.regtrans-ms
Not resetting system file - C:\Sandbox\Editing\desktop.ini
Not resetting system file - C:\Sandbox\desktop.ini
Not resetting system file - C:\System Volume Information\SPP\OnlineMetadataCache\{ab79e1f8-0bd2-4b1a-8ef6-029fcfb38bfd}_OnDiskSnapshotProp
Not resetting system file - C:\System Volume Information\SPP\SppGroupCache\{AB79E1F8-0BD2-4B1A-8EF6-029FCFB38BFD}_DriverPackageInfo
Not resetting system file - C:\System Volume Information\SPP\SppGroupCache\{AB79E1F8-0BD2-4B1A-8EF6-029FCFB38BFD}_WindowsUpdateInfo
Not resetting system file - C:\System Volume Information\SPP\OnlineMetadataCache
Not resetting system file - C:\System Volume Information\SPP\SppCbsHiveStore
Not resetting system file - C:\System Volume Information\SPP\SppGroupCache
Not resetting system file - C:\System Volume Information\MountPointManagerRemoteDatabase
Not resetting system file - C:\System Volume Information\pctEfaData
Not resetting system file - C:\System Volume Information\SPP
Not resetting system file - C:\System Volume Information\Syscache.hve.LOG1
Not resetting system file - C:\System Volume Information\Syscache.hve.LOG2
Not resetting system file - C:\System Volume Information\tracking.log
Not resetting system file - C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}
Not resetting system file - C:\System Volume Information\{8dc67662-0b5c-11e1-8fb4-00248c44f7fb}{3808876b-c176-4e48-b7ae-04046e6cc752}
Not resetting system file - C:\Users\All Users\Microsoft\Assistance\Client\1.0\en-US\Help_CValidator.H1D
Not resetting system file - C:\Users\All Users\Microsoft\Assistance\Client\1.0\en-US\Help_MKWD_AssetId.H1W
Not resetting system file - C:\Users\All Users\Microsoft\Assistance\Client\1.0\en-US\Help_MKWD_BestBet.H1W
Not resetting system file - C:\Users\All Users\Microsoft\Assistance\Client\1.0\en-US\Help_MTOC_help.H1H
Not resetting system file - C:\Users\All Users\Microsoft\Assistance\Client\1.0\en-US\Help_MValidator.H1D
Not resetting system file - C:\Users\All Users\Microsoft\Assistance\Client\1.0\en-US\Help_MValidator.Lck
Not resetting system file - C:\Users\All Users\Microsoft\Assistance\Client\1.0\en-US\Help{9DAA54E8-CD95-4107-8E7F-BA3F24732D95}.H1Q
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\Keys\111f1076540215d8eac27e3480a140f0_ee7e024f-2431-4352-b104-3ef11701e54d
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\024973121aa8de831992cc6ff58a05cb_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\026ad28fee0e3057ecc1169cfe8fd094_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\02824be4d0169133f62504e04613fc00_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\03c9fba1be8af62b4bed344bd75f7a9d_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\0544efc04480ac91f44e0003bc8e74ce_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\062f08cbd7c8ca3c3dbd37c04a9c3697_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\07ac20e7ca1544d6de72b62027138d1b_ee7e024f-2431-4352-b104-3ef11701e54d
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\07eb217be261d5e8f5e7a86a8573f957_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\0ae572a30725394c0fe89f418d9ecad9_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\0b1b767000e0beffea2d6347d0322185_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\0b652fee9f149fe5cb9c9476abedf921_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\0ba3e0f3f3151897e41753b90049c21f_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\0f0ad02a534993ff323c5fb7c29324c8_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\101f15e4eabdf94ec5ac62c0d20d69f6_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\137c2522718b63d99ff13d086c237672_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\13af81527d330ca8eaa440ac441e57a5_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\1489168690cb92189782a76130ea95f0_ee7e024f-2431-4352-b104-3ef11701e54d
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\149a95f66f97926d46186872dd140af5_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\172a5d40abc02f42264572f93f030e15_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\17f2889d8b3801a9295b866e0595047e_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\18bedf06fa314a66e2cec196e6fb7747_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\1cabaa60a78b3ee80512eadeba41dc01_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\1d17a584ac4790fd9204af9a2b532de5_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\1d49c0e94bc71a0ff5bdc0d657b6e2a2_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\1fd2fc6e8a4ab541b72c671fe2adb5ec_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\21002542309313fd8c1aa27902b03197_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\239119931bc69a58a73917c1d7d3c545_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\24d6adc0f1f7f60bebd7b70c6bd4ea1c_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\2679d19b38106bebfd1d3793d74fe75e_ee7e024f-2431-4352-b104-3ef11701e54d
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\28166b877c6c2cf95bc989c4fcbd6d42_ee7e024f-2431-4352-b104-3ef11701e54d
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\28d060774ebbbef2eaa6d97327ad963f_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\29f7289f15e7a5e0ba68712dc753a41b_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\2b3d3e236e6a2bd1371479ec38fe6e48_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\2bae2be4c2063a73f86807cf97aa75aa_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\2e5900bee909c2c234a1feb474e444ae_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\2ff15160333c1e8689ec4dcdadc01fc9_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\33e78e65fcca5b7d795e4473ff8e2947_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\352a1092e3cd0fed65f7eb770e4a7728_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\374cad7869d110d252b8c8681e7c02f2_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\377620de22656a0c363579f6bd9e6cf8_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\37f822ae4cffdc48506e1a144d4562e2_ee7e024f-2431-4352-b104-3ef11701e54d
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\38f5319c0af41000be25210d919a3df5_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\39fefb42dfd01a90d37dc73a01635955_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\3bc16aff374de350d64f1f259db9d037_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\409f0351d1022a05a878af40f51c7cfa_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\43452f764f108b481a5d9a82082dc4e7_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\45cde4aef74f5b8d7d3b6813c01f4103_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\4b882c1840172acb33978945f7fd24f9_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\4bdc7c85f8dd9561786a1bf0b1d64cf8_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\547bcf06dc309838005de0d84205fe62_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\5488b49411ed5b74bf94863bb303f966_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\5679a202ebdee729c00b8d3f1a989928_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\568943849c3dcab69a04095e961f67a9_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\58225e44c87616c32329d29b233318ad_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\59be0df8ba657281c53cc74113f1fe5d_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\59ddc55e9276b1ffb8490724a0b04ff7_ee7e024f-2431-4352-b104-3ef11701e54d
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\59de45a1026dc795d5fb878ee748e626_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\5a07520ea333a70484f27e166dca924b_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\5aa39941f7e8b52f3f4b9e20fee5f40a_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\5dfb336e43c6b7f9e19b7b1d534724df_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\60441755d82ad0339aae473e64d9db6c_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\606632123643aa93732bc2c6bca6d510_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\606c6e549c9dceb4bc4b3a946bfa58ea_ee7e024f-2431-4352-b104-3ef11701e54d
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\62ccdb71e5a0a9bb8414a33de13babfc_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\632a6ea8f322106f4178dc10dfe6d39c_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\6a602ac655beaeb81b7785952c41dd5b_ee7e024f-2431-4352-b104-3ef11701e54d
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\6cb3f9d14c7ca8457f3f4c8661dd7fb0_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\7358b9561b7099bbb40ef85219c3dcbf_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\73b997fbfb3beb62cbbd642ca853b3db_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\746bc2ee54d1c7ca37da9d6ce22bb2f4_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\7824ce10328b9a593e22ff4d6af63787_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\7c10d8753a05fea82c41ec43299b2491_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\7fb92b499a0a3e30ade893d3a025ffda_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\8103f2baac771eef1905c1dec44ee62f_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\8176d7a3823ef2ce971ef88512474750_ee7e024f-2431-4352-b104-3ef11701e54d
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\85adb3f6841f918b294d21e7b6c3d17c_ee7e024f-2431-4352-b104-3ef11701e54d
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\89cbe48bfa44fe72b0afad741de99a76_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\8a2983f680c06d44dc846d3a85715d59_ee7e024f-2431-4352-b104-3ef11701e54d
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\8a4366ada72a95c8a25d8fa824fc27a8_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\8be7904eb532ba92ec4f0e62864247f4_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\8e01b9c95d54305f29b842fc9616acfd_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\8ef5825d82b61c5d79f623428c3018bc_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\95a151e3850cc540df8c9f863dc2d1a3_ee7e024f-2431-4352-b104-3ef11701e54d
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\976c8cb2dce7c4fef96b45aa11a5c179_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\9e120d838ffa74a8bf426b721eda6262_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\9ed27f199566de19dd27fe32103535c1_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\9f101e6974da6dae35c5099599c4e777_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\a35a0ffbbe37d3d10124930c76a8c0a1_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\a44e753e2a3f43c849eaea1851bbc3f1_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\a61e75ffef06c65003dd593e5601fde0_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\a6f20be52ad41d977f080324102fa4d6_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\a91a4479c38e892b37004395fea7ad34_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\aa873b3464d826bdf2a1943953ffa8fa_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\aabd85a7e804f87cc67e7ab79742ecf1_ee7e024f-2431-4352-b104-3ef11701e54d
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\acab233ed89ca0efa33d52d153a0f208_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\ae0622dabf948616a808fbbcebb584f1_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\aec1120f1fe15586b27488db1443f0de_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\aedd6d6236ee9808da3a954d997afe61_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\b155d94e58190064cea033a11a334fea_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\b38a586dedfa31839ff74b449305f815_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\b5866f6cd59e927c4e7f5f94b77fbb3d_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\bc692958ff4755e00e6f3275f3ddaf03_ee7e024f-2431-4352-b104-3ef11701e54d
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\bd644ec75286548324d66d49c3a7e1ea_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\bf2222c280e4794996c329a8bdb1a4ef_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\bf307cd727dca9b5fe13a97c96ed2e48_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\c05f7f1c27821103c9e18ea5bf2da69f_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\c18de722864b166e7ab81c6c9f9e8e3a_ee7e024f-2431-4352-b104-3ef11701e54d
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\c3c54966ad173664646d3059b879185b_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\c95de68e9ac46f3beac48c494e669ef2_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\cd9350120d40bed3870974891ce7723d_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\cf509f9851c489d76eaca119f4a0be09_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\d0e719ca7638c20c117b81654a116831_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\d141a9d5c900d4535129b980960b6481_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\d1b121f8754843afedbb572892fe33f6_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\d2fd63ed240d032b43a273d1f06bf9a1_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\d4a2ee2f7d5feb3560f54fac0ae913d6_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\da1c310b30dac6fbb0921ec8ed43a07d_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\db4b7e6e612b56541202f1d1795fc574_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\db7a5c2b9687cbc2b7418c340a66c271_ee7e024f-2431-4352-b104-3ef11701e54d
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\ddd7b3fff5a1a636f1ee79a5e50f2780_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\e2a9675709d80e95507247ea174972e5_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\e3a25ca37b69b1bd18a05db994900c8a_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\e54b07d65fd932efb4057008df087768_ee7e024f-2431-4352-b104-3ef11701e54d
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\e587c6775f790345cc3bb395f858972b_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\ea953e500e5e45d19f6ef4b0e6bd6c80_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\eb2bae432fdad7ab9b2ca57eaf8b898f_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\ed184063cf105a5cc169e2db3e30818c_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\ee0d7e79fd8a7c8019ca41bd7534fa25_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\ee8012831c66f676a364b8ecf080ad19_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\ef8a7448b588c959e9f1d336e25bfd45_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\f0394560491cf88d9f63a19572cb5947_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\f1c32bf9fbe41577bff001001d8d4c1a_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\f686aace6942fb7f7ceb231212eef4a4_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\fc1e3851f429ea606d6ff1e01a5229f1_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\fc89010cdaf22be6b911837a37e56d2d_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\fc9af1bef626ce73816bed125ba43ec6_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\fddf046a3d84c2d92a91cc46f86e77b0_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\fe4004f79aa4cbb3e2a39b79f78224da_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\S-1-5-18\5d91c0b736f4f8dbdd317cf8a037fced_ee7e024f-2431-4352-b104-3ef11701e54d
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\S-1-5-18\6b29ae44e85efac3c72ff4d1865d73f1_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\S-1-5-18\83aa4cc77f591dfc2374580bbd95f6ba_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\S-1-5-18\d42cc0c3858a58db2db37658219e6400_21ac8353-ec3a-49b6-b62f-c4a955f3f6c9
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\RSA\S-1-5-18
Not resetting system file - C:\Users\All Users\Microsoft\Crypto\Keys
Not resetting system file - C:\Users\All Users\Microsoft\DRM\Server
Not resetting system file - C:\Users\All Users\Microsoft\PlayReady\Cache\S-1-5-21-1069887610-648576151-850243678-1005\MSPRindiv01.key
Not resetting system file - C:\Users\All Users\Microsoft\PlayReady\Cache\indiv01.bla
Not resetting system file - C:\Users\All Users\Microsoft\PlayReady\Cache\indiv01.key
Not resetting system file - C:\Users\All Users\Microsoft\PlayReady\Cache\indiv01.tmp
Not resetting system file - C:\Users\All Users\Microsoft\PlayReady\Cache
Not resetting system file - C:\Users\All Users\Microsoft\Windows\DRM\Cache\Indiv_SID_S-1-5-18\Indiv01.key
Not resetting system file - C:\Users\All Users\Microsoft\Windows\DRM\Cache\Indiv_SID_S-1-5-20\Indiv01.key
Not resetting system file - C:\Users\All Users\Microsoft\Windows\DRM\Cache\Indiv_SID_S-1-5-21-1069887610-648576151-850243678-1005\Indiv01.key
Not resetting system file - C:\Users\All Users\Microsoft\Windows\DRM\Cache\Indiv01.bla
Not resetting system file - C:\Users\All Users\Microsoft\Windows\DRM\Cache\Indiv01.key
Not resetting system file - C:\Users\All Users\Microsoft\Windows\DRM\Cache\Indiv01.tmp
Not resetting system file - C:\Users\All Users\Microsoft\Windows\DRM\blackbox.bin
Not resetting system file - C:\Users\All Users\Microsoft\Windows\DRM\Cache
Not resetting system file - C:\Users\All Users\Microsoft\Windows\DRM\drmstore.hds
Not resetting system file - C:\Users\All Users\Microsoft\Windows\DRM\DRMv1.bak
Not resetting system file - C:\Users\All Users\Microsoft\Windows\DRM\DRMv1.key
Not resetting system file - C:\Users\All Users\Microsoft\Windows\DRM\IndivBox.key
Not resetting system file - C:\Users\All Users\Microsoft\Windows\DRM\v2ksndv.bla
Not resetting system file - C:\Users\All Users\Microsoft\Windows\DRM\v3ks.bla
Not resetting system file - C:\Users\All Users\Microsoft\Windows\DRM\v3ks.sec
Not resetting system file - C:\Users\All Users\Microsoft\Windows\Ringtones\desktop.ini
Not resetting system file - C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Desktop.ini
Not resetting system file - C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Desktop.ini
Not resetting system file - C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\Desktop.ini
Not resetting system file - C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\desktop.ini
Not resetting system file - C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini
Not resetting system file - C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini
Not resetting system file - C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Games\Desktop.ini
Not resetting system file - C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini
Not resetting system file - C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
Not resetting system file - C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Windows Virtual PC\desktop.ini
Not resetting system file - C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\desktop.ini
Not resetting system file - C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\OpenOffice.org 3.3
Not resetting system file - C:\Users\All Users\Microsoft\Windows\Start Menu\desktop.ini
Not resetting system file - C:\Users\All Users\Microsoft\Windows\AIT
Not resetting system file - C:\Users\All Users\Microsoft\Windows\DRM
Not resetting system file - C:\Users\All Users\Norton\symdata.xml
Not resetting system file - C:\Users\All Users\Symantec\symdata.xml
Not resetting system file - C:\Users\All Users\TechSmith\Camtasia Studio\Library\Target_Blue_Title\Thumbs.db
Not resetting system file - C:\Users\All Users\Documents
Not resetting system file - C:\Users\All Users\Microsoft
Not resetting system file - C:\Users\Default\AppData\Local\Microsoft\Windows\History\History.IE5\desktop.ini
Not resetting system file - C:\Users\Default\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
Not resetting system file - C:\Users\Default\AppData\Local\Microsoft\Windows\History\desktop.ini
Not resetting system file - C:\Users\Default\AppData\Local\Microsoft\Windows\History\History.IE5
Not resetting system file - C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3QBK2W2T\desktop.ini
Not resetting system file - C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DU1TK9P1\desktop.ini
Not resetting system file - C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G0GHDEEE\desktop.ini
Not resetting system file - C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HJKGHJJ1\desktop.ini
Not resetting system file - C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3QBK2W2T
Not resetting system file - C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\desktop.ini
Not resetting system file - C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DU1TK9P1
Not resetting system file - C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G0GHDEEE
Not resetting system file - C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HJKGHJJ1
Not resetting system file - C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
Not resetting system file - C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5
Not resetting system file - C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\desktop.ini
Not resetting system file - C:\Users\Default\AppData\Local\Microsoft\Windows\History
Not resetting system file - C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files
Not resetting system file - C:\Users\Default\AppData\Local\History
Not resetting system file - C:\Users\Default\AppData\Local\Temporary Internet Files
Not resetting system file - C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
Not resetting system file - C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
Not resetting system file - C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\Desktop.ini
Not resetting system file - C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Desktop.ini
Not resetting system file - C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Desktop.ini
Not resetting system file - C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini
Not resetting system file - C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini
Not resetting system file - C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies
Not resetting system file - C:\Users\Default\AppData\Roaming\Microsoft
Not resetting system file - C:\Users\Default\Cookies
Not resetting system file - C:\Users\Default\NTUSER.DAT
Not resetting system file - C:\Users\Default\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf
Not resetting system file - C:\Users\Default\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms
Not resetting system file - C:\Users\Default\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms
Not resetting system file - C:\Users\Editing\AppData\Local\Microsoft\Credentials\D68760F1A93DB29C1B0575751FD8E701
Not resetting system file - C:\Users\Editing\AppData\Local\Microsoft\Credentials\DFBE70A7E5CC19A398EBF1B96859CE5D
Not resetting system file - C:\Users\Editing\AppData\Local\Microsoft\ehome\ehthumbs_vista.db

#12 84xads

84xads
  • Topic Starter

  • Members
  • 36 posts
  • OFFLINE
  •  
  • Local time:05:26 AM

Posted 15 November 2011 - 08:37 PM

Let me know if you want everything in the middle - this txt file was over 2 megs

Not resetting system file - C:\Windows.old\Windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_6.1.7100.0_uk-ua_f0269cf5eaead952\uk-UA_BitLockerToGo.exe.mui
Not resetting system file - C:\Windows.old\Windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_6.1.7100.0_zh-cn_25a3d84ca3f18525\zh-CN_BitLockerToGo.exe.mui
Not resetting system file - C:\Windows.old\Windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_6.1.7100.0_zh-tw_29a015a2a1626195\zh-TW_BitLockerToGo.exe.mui
Not resetting system file - C:\Windows.old\Windows\winsxs\x86_microsoft-windows-s..ccessagent-binaries_31bf3856ad364e35_6.1.7100.0_none_4f235739c9769b50\autorun.inf
Not resetting system file - C:\Windows.old\Windows\winsxs\x86_microsoft-windows-s..ccessagent-binaries_31bf3856ad364e35_6.1.7100.0_none_4f235739c9769b50\BitLockerToGo.exe
Not resetting system file - C:\Windows.old\Windows\winsxs\x86_microsoft-windows-s..ccessagent-binaries_31bf3856ad364e35_6.1.7100.0_none_4f235739c9769b50\Read Me.url
Not resetting system file - C:\Windows.old\Windows\assembly
Not resetting system file - C:\Windows.old\Windows\BitLockerDiscoveryVolumeContents
Not resetting system file - C:\Windows.old\Windows\bootstat.dat
Not resetting system file - C:\Windows.old\Windows\Fonts
Not resetting system file - C:\Windows.old\Windows\Installer
Not resetting system file - C:\Windows.old\Windows\Media
Not resetting system file - C:\Windows.old\$Recycle.Bin
Not resetting system file - C:\Windows.old\Recovery
Not resetting system file - C:\$Recycle.Bin
Not resetting system file - C:\ntuser.dat.LOG1
Not resetting system file - C:\ntuser.dat.LOG2
Not resetting system file - C:\ntuser.dat{0240620e-9e32-11de-b76d-00248c44f7fb}.TM.blf
Not resetting system file - C:\ntuser.dat{0240620e-9e32-11de-b76d-00248c44f7fb}.TMContainer00000000000000000001.regtrans-ms
Not resetting system file - C:\ntuser.dat{0240620e-9e32-11de-b76d-00248c44f7fb}.TMContainer00000000000000000002.regtrans-ms
Not resetting system file - C:\pagefile.sys
Not resetting system file - C:\Recovery
Not resetting system file - C:\System Volume Information

========= End of CMD: =========


========= bootrec /FixMbr =========

˙ūT

========= End of CMD: =========


========= bcdedit /set {default} winpe no =========

The boot configuration data store could not be opened.
The system cannot find the file specified.

========= End of CMD: =========


=========== Control: ===========

The boot configuration data store could not be opened.
The system cannot find the file specified.

==== End of Control: ====

==== End of Fixlog ====

#13 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,700 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:07:26 AM

Posted 15 November 2011 - 10:08 PM

Seems that the MBR is refusing to unlock. Lets try MBRFix along the normal Windows commands.

Download the enclosed file and save it in the USB drive, overwriting the existing one.

Insert the USB drive into the ailing computer.

Now please enter System Recovery Options and run FRST64 as you did before, except that this time around, press the Fix button just once and wait.

The tool will make a log on the flashdrive (Fixlog.txt). ]. Copy and Paste the contents of the Fixlog.txt in your next reply.

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#14 84xads

84xads
  • Topic Starter

  • Members
  • 36 posts
  • OFFLINE
  •  
  • Local time:05:26 AM

Posted 15 November 2011 - 11:46 PM

Fix result of Farbars's Recovery Tool (FRST written by farbar Version 2.2.7)
Ran by SYSTEM at 2011-11-15 22:43:39 R:4
Running from H:\

==============================================


========= CMD: H:\MBRFix64 /drive 0 fixmbr /win7 =========

'CMD:' is not recognized as an internal or external command,
operable program or batch file.

========= End of CMD: =========


========= bootrec /FixMbr =========

˙ūT

========= End of CMD: =========


========= bcdedit /set {default} winpe no =========

The boot configuration data store could not be opened.
The system cannot find the file specified.

========= End of CMD: =========


=========== Control: ===========

The boot configuration data store could not be opened.
The system cannot find the file specified.

==== End of Control: ====

==== End of Fixlog ====

#15 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,700 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:07:26 AM

Posted 16 November 2011 - 12:13 AM

Sorry. Another syntax error

Download the enclosed file and save it in the USB drive, overwriting the existing one.

Insert the USB drive into the ailing computer.

Now please enter System Recovery Options and run FRST64 as you did before, except that this time around, press the Fix button just once and wait.

The tool will make a log on the flash drive (Fixlog.txt). Copy and Paste the contents of the Fixlog.txt in your next reply.

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users