Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Trojan Horse Clicker.fr And Raze Spyware Wallpaper


  • Please log in to reply
9 replies to this topic

#1 mattybbbbb

mattybbbbb

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:09:44 AM

Posted 03 July 2006 - 11:13 AM

Hello. I have my AVG report that a trojan horse "Clicker.FR" has been spotted and then when I try to heal it or move it to the vault, it tells me that I don't have access to do so. I have run Windows defender, HighJack this, Spy Hunter, and Spy Doctor but they are all the freeware versions and once they scan and find all the problems, they ask me to buy the real product to remove them. I don't want to purchase something if I don't know it will work. Also, at some point my desktop wallpaper was replaced with a RazeSpyware ad that wont allow me to right-click for my properties anymore. Can anyone help me? Here is my log from highJack this:

Logfile of HijackThis v1.99.1
Scan saved at 10:47:30 AM, on 7/3/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\PROGRA~1\NTS\ENTERN~1\app\pppoeservice.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\ZONELABS\vsmon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Winamp\winampa.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_FATIAIA.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\PROGRA~1\NTS\ENTERN~1\app\EnterNet.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Documents and Settings\Elizabeth Bruni\Local Settings\Temp\HijackThis.exe

R3 - URLSearchHook: (no name) - {E9BFFB8A-3E89-B62F-946C-BB44606BDA69} - lpt.dll (file missing)
O1 - Hosts: localhost 127.0.0.1
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINNT\system32\{DE7DABC7-5CF7-42F5-8BB9-0BDA781C8478}.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINNT\system32\{DE7DABC7-5CF7-42F5-8BB9-0BDA781C8478}.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [EPSON Stylus Photo R220 Series] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_FATIAIA.EXE /P30 "EPSON Stylus Photo R220 Series" /O6 "USB001" /M "Stylus Photo R220"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [$EnterNet] C:\PROGRA~1\NTS\ENTERN~1\app\EnterNet.exe -AutoStart
O4 - HKLM\..\Run: [sbin] TRPT.exe
O4 - HKLM\..\Run: [SpyElim] Brong32.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SpyHunter] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exe
O4 - HKLM\..\Run: [bqrcr.exe] C:\WINNT\system32\bqrcr.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [EPSON Stylus Photo R220 Series] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_FATIAIA.EXE /P30 "EPSON Stylus Photo R220 Series" /M "Stylus Photo R220" /EF "HKCU"
O4 - HKCU\..\Run: [KillAndClean] "C:\Program Files\KillAndClean\KillAndClean.exe"
O4 - HKCU\..\Run: [vxdman] gabber.exe
O4 - HKCU\..\Run: [sysconf16] JAguAr.exe
O4 - HKCU\..\Run: [browsebar] BoundRec.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{162B2BCB-07BC-4C85-8898-DB2C653AE800}: NameServer = 85.255.115.18,85.255.112.168
O17 - HKLM\System\CCS\Services\Tcpip\..\{CAE7A449-5C19-411A-9DEF-5B5EFC7B7910}: NameServer = 85.255.115.18,85.255.112.168
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.18 85.255.112.168
O17 - HKLM\System\CS1\Services\Tcpip\..\{162B2BCB-07BC-4C85-8898-DB2C653AE800}: NameServer = 85.255.115.18,85.255.112.168
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.115.18 85.255.112.168
O17 - HKLM\System\CS2\Services\Tcpip\..\{162B2BCB-07BC-4C85-8898-DB2C653AE800}: NameServer = 85.255.115.18,85.255.112.168
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.115.18 85.255.112.168
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Dmntsmt - VERITAS Software Corp. - (no file)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PPPoE Service (PPPoEService) - Unknown owner - C:\PROGRA~1\NTS\ENTERN~1\app\pppoeservice.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZONELABS\vsmon.exe

Thanks,
Matthew

BC AdBot (Login to Remove)

 


m

#2 Guest_Cretemonster_*

Guest_Cretemonster_*

  • Guests
  • OFFLINE
  •  

Posted 05 July 2006 - 03:20 PM

Hi Matthew and Welcome to the Bleeping Computer!


Hi tempest and Welcome to the Bleeping Computer!


First download ewido anti-spyware from HERE and save that file to your desktop.
This is a 30 day trial of the program
  • Once you have downloaded ewido anti-spyware, locate the icon on the desktop and double-click it to launch the set up program.
  • Once the setup is complete you will need run ewido and update the definition files.
  • On the main screen select the icon "Update" then select the "Update now" link.
    • Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close ewido anti-spyware, Do Not run a scan just yet, we will shortly.


Please download FixWareout from one of these sites:
http://downloads.subratam.org/Fixwareout.exe
http://www.bleepingcomputer.com/files/lonny/Fixwareout.exe
  • Save it to your desktop and run it. Click Next, then Install, make sure "Run fixit" is checked and click Finish.
  • The fix will begin; follow the prompts.
  • You will be asked to reboot your computer,Reboot into SAFE MODE(Tap F8 when restarting)
  • Your system may take longer than usual to load; this is normal.
  • Once the desktop loads-> Open HijackThis-> Click "Do a System Scan Only" and put a check by these but DO NOT hit the Fix Checked button yet

    R3 - URLSearchHook: (no name) - {E9BFFB8A-3E89-B62F-946C-BB44606BDA69} - lpt.dll (file missing)

    O1 - Hosts: localhost 127.0.0.1

    O2 - BHO: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINNT\system32\{DE7DABC7-5CF7-42F5-8BB9-0BDA781C8478}.dll

    O4 - HKLM\..\Run: [sbin] TRPT.exe

    O4 - HKLM\..\Run: [SpyElim] Brong32.exe

    O4 - HKLM\..\Run: [bqrcr.exe] C:\WINNT\system32\bqrcr.exe

    O4 - HKCU\..\Run: [vxdman] gabber.exe

    O4 - HKCU\..\Run: [sysconf16] JAguAr.exe

    O4 - HKCU\..\Run: [browsebar] BoundRec.exe

    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm

    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm

    O17 - HKLM\System\CCS\Services\Tcpip\..\{162B2BCB-07BC-4C85-8898-DB2C653AE800}: NameServer = 85.255.115.18,85.255.112.168

    O17 - HKLM\System\CCS\Services\Tcpip\..\{CAE7A449-5C19-411A-9DEF-5B5EFC7B7910}: NameServer = 85.255.115.18,85.255.112.168

    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.18 85.255.112.168

    O17 - HKLM\System\CS1\Services\Tcpip\..\{162B2BCB-07BC-4C85-8898-DB2C653AE800}: NameServer = 85.255.115.18,85.255.112.168

    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.115.18 85.255.112.168

    O17 - HKLM\System\CS2\Services\Tcpip\..\{162B2BCB-07BC-4C85-8898-DB2C653AE800}: NameServer = 85.255.115.18,85.255.112.168

    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.115.18 85.255.112.168

    O23 - Service: Dmntsmt - VERITAS Software Corp. - (no file)

    Now Make sure ALL WINDOWS and BROWSERS are CLOSED and hit the Fix Checked Button
  • Lauch ewido-anti-spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
  • ewido will now begin the scanning process, be patient this may take a little time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all actions"
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
  • Close out Ewido Anti-Spyware.
IMPORTANT: Do not open any other windows or programs while ewido is scanning, it may interfere with the scanning proccess.


Click Start, and then click Search.
Click All files and folders.
In the "All or part of the file name" box, type:

rasphone.pbk

Verify that "Look in" is set to "Local Hard Drives" or to (C:).
Click "More advanced options."
Check "Search system folders."
Check "Search subfolders."
Click Search.
Click Find Now or Search Now.

If you find rasphone.pbk file, right-click the file, and then click "Open With."
Deselect the "Always use this program to open this program" check box.
Scroll through the list of programs and double-click Notepad.
When the file opens, delete the entries below:

IpDnsAddress = 85.255.115.18
IpDns2Address = 85.255.112.168
IpNameAssign = 2



Restart the computer back into Normal Mode.


Now open the Control Panel-> In the windows control panel. If you are using Windows XP's Category View, select the Network and Internet Connections category otherwise double click on Network Connections. Then right click on your default connection, usually local area connection for cable and dsl, and left click on properties. Click the Networking tab. Double-click on the Internet Protocol (TCP/IP) item and select the radio dial that says Obtain DNS servers automatically

Press OK twice to get out of the properties screen and reboot if it asks.
That option might not be avaiable one some systems.


Next Go start run type cmd and hit OK
type
ipconfig /flushdns
then hit enter, type exit hit enter
(that space between g and / is needed)


Please have the PC Scanned here:
Panda Active Scan

You will need to be using Internet Explorer for the Scan to work

Save the Report it generates

Post back with a fresh HijackThis log and the reports from Ewido and Panda along with report.txt from Fix WareOut.

Edited by Cretemonster, 05 July 2006 - 03:21 PM.


#3 mattybbbbb

mattybbbbb
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  

Posted 05 July 2006 - 07:43 PM

Thank you so much for replying . I am still at work, but I will follow your instructions when I get home. Thanks again.

#4 mattybbbbb

mattybbbbb
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:09:44 AM

Posted 12 July 2006 - 01:29 PM

For some reason my computer wont let me start in safe mode. Could this be a virus? I start up and when it prompts me, I hit F8 and then it skips directly to Windows 2000. I have held it from the begining of the start-up with no success, also. I have never had this problem before. I can enter my BIOS but nothing else. Is there something that I can do?

#5 Guest_Cretemonster_*

Guest_Cretemonster_*

  • Guests
  • OFFLINE
  •  

Posted 12 July 2006 - 02:14 PM

Just follow the directions in normal mode,we will deal with safe mode in a bit.

Most likely,the virus is injected into some critical windows processes and will have to be cleaned before a normal trip to safe mode occurs.

#6 mattybbbbb

mattybbbbb
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:09:44 AM

Posted 12 July 2006 - 05:57 PM

Thanks. I will when I get home. Last night I continued with the instructions in normal mode and ran FixWareout. It said that one file could not be removed and it prompted me to email someone(I am sorry that I don't have the info with me as our home computer seems to not want to send emails right now) immediately. I have the logs from highjack this, Ewido, and FixWareout. I will post those when I get home. The rasphone.pbk file is on my computer , but when I opened it with notepad, it was blank. That is where I stopped last night.

#7 mattybbbbb

mattybbbbb
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  

Posted 14 July 2006 - 09:03 AM

Here is the FixWareOut log:

Fixwareout ver 1.003
Last edited 07/1/2006
Post this report in the forums please

Reg Entries that were deleted
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
2812620D3916-3EE9-5584-5D0A-2AB13AE6{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
1DFED2A3FFE4-9199-2FC4-CE5B-A2AE98EC{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
FA5AB5FDB1E3-077A-3034-0ECF-43D46209{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
06FF310A0DB7-FCE8-E2B4-5811-DC44A11C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
91F8A1C96788-A489-7804-A152-38A935DA{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
F59F59B5FB92-5538-75C4-F3EE-94DA401D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
6D2B26D9FA7C-75BA-CD64-65CF-A6BDBFFA{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
DA5294210AC3-F818-77B4-36F1-ACCC543B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
373670CB7B7A-5998-6C64-B968-4D075DBF{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
DE2E779ED188-44E8-C134-8F49-68F29E9A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
A5011391AB10-2168-C674-5A93-60197BB5{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
1BEC37D3CCE2-8418-A964-BA5F-1ABD0053{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
ABB52CAE1487-AFBA-5D04-7CD5-4E50A253{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
3C220342C21C-10BA-8AF4-D968-E9EEB673{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
7448A668BDAE-79FA-1024-FF1F-8C868F76{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
CC0C15AEB4F6-C27B-7154-7718-DD001665{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
2AB14AD395BA-CA2B-0B84-A340-3223FBD9{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
B741E5F6E6E8-BC1A-2564-5D8A-B4D02BFC{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
BB03D8E8B913-23DB-6244-1FE1-9E942635{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
4FDC90947E20-0A79-AA14-B472-A632B7B8{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
C479BCDEAB7A-B34B-94B4-02FB-5713126A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
D5C67AC0DCCA-6CF8-CF54-53F7-E7E2329D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
E0146D944897-84E9-3364-AF41-5BA5E78D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
42B31A98114B-9D6A-5014-988F-91AE2F40{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
6588D75ECC3F-1BB8-6D14-6A50-83B918C7{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
6207E61D1478-724B-3AB4-FD15-FD9F79B2{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
B4AE4DB2B294-E4EB-3744-897F-CD967FBB{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
1EC1AC5DAAA5-434A-8C84-2CA6-770F2A9C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
8BA74E59421F-2BEB-0D54-D4CF-515CC354{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
6937774CDA27-4DFA-3114-3BFB-399D0541{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
F08E3FB08E56-3908-64F4-CD28-AD7C735E{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
CA9C7C4A170B-B02B-0824-99FB-DCE1B63C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
A0B9E381F8C1-178B-E464-E473-9676C575{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
C367E26E0806-5899-8624-84E4-A8B4BA96{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
69D1ED405B7E-FA7B-7944-D224-0498646E{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
D481FD337099-81A8-5834-FD60-9EDFB45A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
77BC5C6B253A-4CE9-4624-45CF-AE10AB24{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
5F855A47D3ED-4AD9-C604-F527-CAD8D2D2{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
66B3326CF550-A8AA-5974-1ED4-D220FB10{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
B5D1A134C456-C4A9-EC74-9486-5BF122AC{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
245B2CC653EB-71E8-8014-4B81-75826050{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
2F289D01BE21-BD3A-BF14-5C6C-92E38F82{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
5D948AA0F667-8DAA-7474-A079-363E6222{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
267B83804A8E-F17B-E884-E92A-AD9B9BC6{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
C7EF216E5173-9A2A-6BF4-4DD5-E1CE8D82{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
0C802169CB29-BC9B-9644-3D28-480B4757{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
7E1AE13A187B-F829-3644-3505-7E6B2C59{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
3466E315C4B6-D489-1284-4E28-B28C8F61{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
E0877A327B9D-C0AB-6D64-3D42-479EB777{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
D2AACB5E4C79-A439-7F64-02DB-F89AAEB8{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
784ADD15EA88-98A8-3274-0409-874B742F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
14B06C04862E-73CB-E494-8542-4A7ACD0C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
8557DD88CC96-8868-1694-F9FD-16272DCA{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
A023A57B3763-8218-1BD4-B796-456FB36E{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
6FAE51683CE5-8FAA-12D4-BE2E-2CDD70A4{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
5C3501F54761-922A-88B4-CD60-C251FB76{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
C0DEE9FD8C90-9FF9-6F74-2984-02A81E06{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
A44320D7AB6A-093B-E824-6540-4975A06D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
9B5ED69F556A-E889-C5F4-8A76-A413A030{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
9ACAF231AADC-CC1B-11B4-D8E9-C0370527{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
BA4ADD4130C4-3F5A-0904-8ECB-954B6528{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
5A8E5EE83949-1A48-92C4-AE9A-A1818C0B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
0F33B3283C87-1009-F9F4-27C3-8BDF170D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
CF7FFD006A02-3D58-F054-C8D4-3351BB8A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
3D128993B561-5A5B-F844-7033-E6BBD0D1{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
B5C76006EF17-F3AB-FB54-077F-E6B855D1{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
BD3379DBCBBA-8B88-8744-FD07-C1A69CB2{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
77B465DB071C-378A-EC64-03CE-161EED62{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
274BA469B30E-EAA8-9854-AF03-FDFEBFAD{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
B19E26AE5D74-E28A-5614-4DA0-6D6D1EF5{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
9BDF7E51A569-B278-0E04-961F-2651CE9E{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
3B185849BADE-97E8-7EF4-B220-45D2B830{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
668AE7227B96-2FE8-ECE4-F5EB-44133E07{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
C9EAD94BF268-1D8A-2634-EE05-F2F582EE{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
60E5BF9B2C29-477B-BA54-8D8C-4AB351E3{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
6802A22CDDB7-49DA-7F94-7CBE-9E914DE2{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
F4E79BA43B5B-69BA-97C4-668D-A5E608C7{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
8D3A21A959EE-3BC8-C544-1680-3487A77D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
937CC404E7BA-BEBA-F604-1B78-D05A8248{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
F8A1D8396C0D-5AC9-A934-D201-57D1B697{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
79F823280642-3D48-C024-C812-0191F8AF{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
703DC39CE92D-86DA-D8F4-A501-A3EDFE26{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
8AE94B4E4F4E-014A-DE54-9A85-C5344D47{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
15E524DA2BC7-0D8A-F2F4-FB0B-2AE14970{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
32706FF85536-D078-DA74-C509-551DC4FA{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
2531CE2C8FD0-E7CA-5DA4-5ADD-E75FBA22{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
AAED267BB2D7-6548-E0B4-EABF-F63D0BD0{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
37D85B8E9F4E-0B79-2454-E11B-326B57E8{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
7A069DAE05EC-4F58-91B4-80BD-59A32F1D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
4509DC0B2054-384A-8814-84C3-55396C50{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
5476EB8392E4-6399-E484-FF15-C772718B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
C1A0ED759C57-9149-0B64-4432-957F84C1{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
82CD1EA529B3-0DDA-BED4-64BD-FAB10DB3{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
85DA5F5231EA-191A-66E4-1748-7E6B5B78{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
3CC6A8DC97E2-C0FA-3524-BBB0-DC20EA98{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
AC7AB24E27A3-398A-BF44-DCF7-85341ECB{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
6AE7B4E25810-9208-35A4-889F-B0DA9B6F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
8A09A45BE2D8-4A08-FD74-F2C7-41D07BD6{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
B8BF29039489-6E18-2A64-B927-9BFB6AF5{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
2157777B239A-34E9-A0D4-080E-91F86EC9{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
74EFCF8C249D-1E18-8284-C500-6FBC09A8{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
E36768B539C6-0038-2AC4-8199-62BAD9A7{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
9A5C8060C0C0-0A1A-E8B4-0D5E-6AC8C32A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
612A98E2BE52-DEEA-C864-796C-30F6CCC8{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
74AA3CA03DB6-3A6A-EF44-F1E6-30F210F3{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
A0A41F497EF9-E0DA-3BA4-E0DE-7C3F63FF{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
855639EFEC01-AFD9-3654-DB31-B7EA9BA1{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
297B29DDF3E6-6D79-DF14-B86A-EE45BF64{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
C2830DEDCB83-1BFB-1FD4-8356-5D5D52E3{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
6C8864F17210-C668-D904-77A5-A7408327{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
908ACEFAD6BB-E3EB-6C84-6348-730C9083{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
66E1D5DC2A87-C01B-2F74-3BD2-14E5BCB7{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
FA7DBF78F60D-9B0B-B1D4-F401-C6E39687{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
F63F892D688D-5D48-9924-FF68-8DCE5374{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
E4B8912EC32B-69DB-5F24-00ED-8223F0D5{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
E4ECA14C395F-28DB-05A4-9CDB-5BA4F69C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
163DFA3C4264-59DA-34A4-348D-32713763{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
A7111227FB34-72DA-5F54-8FC8-D6943901{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
97A8C0E8557E-1D9B-0314-3E2C-0DC2E5A3{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
6BB0656AA93E-7F1A-1384-72C0-5E2E2C41{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
65E7D925C722-522A-6934-0663-8C8CB39A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
C65A77AA0A96-B67B-DD44-5803-0598F7B7{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
C536975A9128-8E98-AB84-CFD0-B02D838C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
5B08D4263BA4-89D9-DE84-C465-416E13ED{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
AAA744BB6452-6068-FA54-BE58-2DC7F7D5{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
3A5B0171E7F4-049B-67E4-3928-85ED8993{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
C94DECC333B8-3309-6214-6F08-CA851142{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
4DF058D27525-3EDA-1F74-5182-23A18186{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
6155B06A40DC-95CB-E554-0FF9-298B8EAA{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
58AE58B1453E-61AA-3164-E1C7-D6BDC21D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
4549CF4BC662-530A-BD34-4F72-15EEAAB8{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
D9AF31D9977F-B58A-A2F4-52F8-DA5D2980{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
F68802EEF01E-3F6A-EC24-E697-21AF3C6A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
91A6892FEEAD-4D68-93E4-FC19-8C755D35{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
7DDBDB7A4036-9939-0744-2EE5-3C0EC36F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
5DA2155AA471-C408-9C44-A08D-564496BC{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
68FF8C34C2B9-2C2B-48F4-AD3E-2BA37D07{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
7B99586903B3-C83B-15D4-6028-F51686E9{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
5BAFE01B7CC9-22CA-7084-FD98-777871CE{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
4A16B024AFA1-82FA-A1C4-03BB-BD6128B2{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
212F5C173518-8459-A4B4-7A56-39C38007{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
59C56BFE08E4-EA8A-3D04-BB36-FF771AD0{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
AE919AE3C5CE-D65A-2A34-AEB0-724AA4C2{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
98D3A19B23D6-6C4A-B9D4-69FF-7469264C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
F492C1A9D60F-15CB-E224-BB83-2EE34303{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
B2D969D5FC42-C8FB-5A54-B2EC-873F0532{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
1648273A5E16-6A58-25D4-8431-E0B78BAB{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
83B0A9CD39BA-63FB-78D4-65E4-37311E8D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
AC3D443AB55C-B76A-54F4-F214-85EEF49A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
9E4FBD5827F2-E479-0464-24D0-D5C87FB8{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
486A6D21E561-6028-0344-DE9D-95EF42E5{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
81874227BACC-4039-E1F4-6BF3-6CA9EB97{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
0F7C196D230F-65F9-6134-FF3C-7AB7A990{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
29A565501A0D-AF7A-0BC4-C653-7F1C5B01{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
53D072DA0D30-BCB9-4184-1D4C-AAE3BC02{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
A1E0A0777993-38A9-2FB4-3A28-44173E51{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
39A6457F807F-E19A-1354-F700-6A3BE274{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
C7A574D5D486-D72A-F934-2BCE-EF494719{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
5AF5E45A9F8E-5F2A-7D14-0A5F-5AB7668E{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
BF238BD9CDD7-7BF9-A074-F044-5CE37A99{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
4E2D2AD84C8E-683B-1DA4-3DE2-39739E2F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
7C71D79E3566-A1B8-9C44-BFD2-5384DD72{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
135A7A4222BA-6F8B-14F4-A2E2-D31BDD2F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
846536CA7083-9879-DE74-2350-0CFCC090{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
6B3F1C47A177-5CA9-6154-F0FB-AE96EDDE{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
ACEE240C165A-2C1B-19B4-31E3-6A8FB0A8{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
8A81CB196895-8A0B-8084-0430-3B3B178B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
FF6C92EC8070-D7CA-BDE4-78B3-73882DC4{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\aovmd
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
9F1DF45D257B-1ABB-1344-5519-5B8C2E6A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
D60A3ED2A1BA-40EA-C1A4-0977-999AE4A0{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
4A77C2F5BD32-0D28-0804-07CD-F936A17F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
25B6C4DD2F31-FA78-9F94-C593-2B1A00CD{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
31F8B2A0F36E-F92B-1A94-D725-0F89BE76{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
9041EC2FE1D0-2389-6494-D0EB-A3815A98{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
B56A23B469D6-6E9A-8B44-BBDB-AC956784{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
72587C37D041-D098-01A4-D711-5A74E822{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
29A8274DFEFA-26FA-43F4-5A4D-F2FB4D9A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
5899598258D5-4FB9-45B4-ACC5-32BBEC43{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
E0D19122E955-297A-05F4-A9AB-EA876809{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\xedocne
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\gib_ogol
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\repiwoh
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\llun
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\23plhps
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\mgcppp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\tesvaf
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\nlcalik
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\swen
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\ogol
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\eno
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\eerht
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\ruof
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\evif
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\ypszr
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\putesprpgd
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\lavinraCputeS
...

Microsoft ® Windows Script Host Version 5.6
Random Runs removed from HKLM
"dmvoa.exe"=-
...

PLEASE NOTE, There WILL be LEGIT FILES LISTED. IF YOU ARE UNSURE OF WHAT IT
IS LEAVE THEM ALONE.
Example ipsec6.exe is legitimate

Search by size and names...
* csr.exe C:\WINNT\System32\CSFJO.EXE

Misc files
* thequicklink C:\WINNT\System32\EDJBW.DLL

Checking for older varients covered by the Rem3 tool


Search five digit cs, dm and jb files
This WILL/CAN also list Legit Files, Submit them at Virustotal
C:\WINNT\SYSTEM32\CSFJO.EXE 51,251 2006-07-01
C:\WINNT\SYSTEM32\DMVOA.EXE 44,128 2003-06-19
C:\WINNT\SYSTEM32\DMWQD.EXE 44,128 2003-06-19
Other suspects
Directory of C:\WINNT\system32
{908678AE-BA9A-4F50-A792-559E22191D0E}.exe
{34CEBB23-5CCA-4B54-9BF4-5D8528959985}.exe
{A9D4BF2F-D4A5-4F34-AF62-AFEFD4728A92}.exe
{228E47A5-117D-4A10-890D-140D73C78527}.exe
{487659CA-BDBB-44B8-A9E6-6D964B32A65B}.exe
{89A5183A-BE0D-4946-9832-0D1EF2CE1409}.exe
{67EB98F0-527D-49A1-B29F-E63F0A2B8F13}.exe
{DC00A1B2-395C-49F9-87AF-13F2DD4C6B52}.exe
{F71A639F-DC70-4080-82D0-23DB5F2C77A4}.exe
{0A4EA999-7790-4A1C-AE04-AB1A2DE3A06D}.exe
{A6E2C8B5-9155-4431-BBA1-B752D54FD1F9}.exe
{4CD28837-3B87-4EDB-AC7D-0708CE29C6FF}.exe
{8A0BF8A6-3E13-4B91-B1C2-A561C042EECA}.exe
{EDDE69EA-BF0F-4516-9AC5-771A74C1F3B6}.exe
{090CCFC0-0532-47ED-9789-3807AC635648}.exe
{F2E93793-2ED3-4AD1-B386-E8C48DA2D2E4}.exe
{99A73EC5-440F-470A-9FB7-7DDC9DB832FB}.exe
{E8667BA5-F5A0-41D7-A2F5-E8F9A54E5FA5}.exe
{917494FE-ECB2-439F-A27D-684D5D475A7C}.exe
{472EB3A6-007F-4531-A91E-F708F7546A93}.exe
{15E37144-82A3-4BF2-9A83-3997770A0E1A}.exe
{20CB3EAA-C4D1-4814-9BCB-03D0AD270D35}.exe
{10B5C1F7-356C-4CB0-A7FA-D0A105565A92}.exe
{099A7BA7-C3FF-4316-9F56-F032D691C7F0}.exe
{79BE9AC6-3FB6-4F1E-9304-CCAB72247818}.exe
{5E24FE59-D9ED-4430-8206-165E12D6A684}.exe
{8BF78C5D-0D42-4640-974E-2F7285DBF4E9}.exe
{A94FEE58-412F-4F45-A67B-C55BA344D3CA}.exe
{D8E11373-4E56-4D87-BF36-AB93DC9A0B38}.exe
{BAB87B0E-1348-4D52-85A6-61E5A3728461}.exe
{2350F378-CE2B-45A5-BF8C-24CF5D969D2B}.exe
{30343EE2-38BB-422E-BC51-F06D9A1C294F}.exe
{C4629647-FF96-4D9B-A4C6-6D32B91A3D89}.exe
{2C4AA427-0BEA-43A2-A56D-EC5C3EA919EA}.exe
{0DA177FF-63BB-40D3-A8AE-4E80EFB65C95}.exe
{70083C93-65A7-4B4A-9548-815371C5F212}.exe
{2B8216DB-BB30-4C1A-AF28-1AFA420B61A4}.exe
{EC178777-89DF-4807-AC22-9CC7B10EFAB5}.exe
{9E68615F-8206-4D51-B38C-3B30968599B7}.exe
{70D73AB2-E3DA-4F84-B2C2-9B2C43C8FF86}.exe
{CB694465-D80A-44C9-804C-174AA5512AD5}.exe
{F63CE0C3-5EE2-4470-9399-6304A7BDBDD7}.exe
{53D557C8-91CF-4E39-86D4-DAEEF2986A19}.exe
{A6C3FA12-796E-42CE-A6F3-E10FEE20886F}.exe
{0892D5AD-8F25-4F2A-A85B-F7799D13FA9D}.exe
{8BAAEE51-27F4-43DB-A035-266CB4FC9454}.exe
{D12CDB6D-7C1E-4613-AA16-E3541B85EA85}.exe
{AAE8B892-9FF0-455E-BC59-CD04A60B5516}.exe
{68181A32-2815-47F1-ADE3-52572D850FD4}.exe
{241158AC-80F6-4126-9033-8B333CCED49C}.exe
{3998DE58-8293-4E76-B940-4F7E1710B5A3}.exe
{5D7F7CD2-85EB-45AF-8606-2546BB447AAA}.exe
{DE31E614-564C-48ED-9D98-4AB3624D80B5}.exe
{C838D20B-0DFC-48BA-89E8-8219A579635C}.exe
{7B7F8950-3085-44DD-B76B-69A0AA77A56C}.exe
{A93BC8C8-3660-4396-A225-227C529D7E56}.exe
{14C2E2E5-0C27-4831-A1F7-E39AA6560BB6}.exe
{3A5E2CD0-C2E3-4130-B9D1-E7558E0C8A79}.exe
{1093496D-8CF8-45F5-AD27-43BF7221117A}.exe
{36731723-D843-4A43-AD95-4624C3AFD361}.exe
{C96F4AB5-BDC9-4A50-BD82-F593C41ACE4E}.exe
{5D0F3228-DE00-42F5-BD96-B23CE2198B4E}.exe
{4735ECD8-86FF-4299-84D5-D886D298F36F}.exe
{78693E6C-104F-4D1B-B0B9-D06F87FBD7AF}.exe
{7BCB5E41-2DB3-47F2-B10C-78A2CD5D1E66}.exe
{3809C037-8436-48C6-BE3E-BB6DAFECA809}.exe
{7238047A-5A77-409D-866C-01271F4688C6}.exe
{3E25D5D5-6538-4DF1-BFB1-38BCDED0382C}.exe
{46FB54EE-A68B-41FD-97D6-6E3FDD92B792}.exe
{1AB9AE7B-13BD-4563-9DFA-10CEFE936558}.exe
{FF36F3C7-ED0E-4AB3-AD0E-9FE794F14A0A}.exe
{3F012F03-6E1F-44FE-A6A3-6BD30AC3AA47}.exe
{8CCC6F03-C697-468C-AEED-25EB2E89A216}.exe
{A23C8CA6-E5D0-4B8E-A1A0-0C0C0608C5A9}.exe
{7A9DAB26-9918-4CA2-8300-6C935B86763E}.exe
{8A90CBF6-005C-4828-81E1-D942C8FCFE47}.exe
{9CE68F19-E080-4D0A-9E43-A932B7777512}.exe
{5FA6BFB9-729B-46A2-81E6-98493092FB8B}.exe
{6DB70D14-7C2F-47DF-80A4-8D2EB54A90A8}.exe
{F6B9AD0B-F988-4A53-8029-01852E4B7EA6}.exe
{BCE14358-7FCD-44FB-A893-3A72E42BA7CA}.exe
{89AE02CD-0BBB-4253-AF0C-2E79CD8A6CC3}.exe
{87B5B6E7-8471-4E66-A191-AE1325F5AD58}.exe
{3BD01BAF-DB46-4DEB-ADD0-3B925AE1DC28}.exe
{1C48F759-2344-46B0-9419-75C957DE0A1C}.exe
{B817277C-51FF-484E-9936-4E2938BE6745}.exe
{05C69355-3C48-4188-A483-4502B0CD9054}.exe
{D1F23A95-DB08-4B19-85F4-CE50EAD960A7}.exe
{8E75B623-B11E-4542-97B0-E4F9E8B58D73}.exe
{0DB0D36F-FBAE-4B0E-8456-7D2BB762DEAA}.exe
{22ABF57E-DDA5-4AD5-AC7E-0DF8C2EC1352}.exe
{AF4CD155-905C-47AD-870D-63558FF60723}.exe
{07941EA2-B0BF-4F2F-A8D0-7CB2AD425E51}.exe
{74D4435C-58A9-45ED-A410-E4F4E4B49EA8}.exe
{62EFDE3A-105A-4F8D-AD68-D29EC93CD307}.exe
{FA8F1910-218C-420C-84D3-246082328F97}.exe
{796B1D75-102D-439A-9CA5-D0C6938D1A8F}.exe
{8428A50D-87B1-406F-ABEB-AB7E404CC739}.exe
{D77A7843-0861-445C-8CB3-EE959A12A3D8}.exe
{7C806E5A-D866-4C79-AB96-B5B34AB97E4F}.exe
{2ED419E9-EBC7-49F7-AD94-7BDDC22A2086}.exe
{3E153BA4-C8D8-45AB-B774-92C2B9FB5E06}.exe
{EE285F2F-50EE-4362-A8D1-862FB49DAE9C}.exe
{70E33144-BE5F-4ECE-8EF2-69B7227EA866}.exe
{038B2D54-022B-4FE7-8E79-EDAB948581B3}.exe
{E9EC1562-F169-40E0-872B-965A15E7FDB9}.exe
{5FE1D6D6-0AD4-4165-A82E-47D5EA62E91B}.exe
{DAFBEFDF-30FA-4589-8AAE-E03B964AB472}.exe
{26DEE161-EC30-46CE-A873-C170BD564B77}.exe
{2BC96A1C-70DF-4478-88B8-ABBCBD9733DB}.exe
{1D558B6E-F770-45BF-BA3F-71FE60067C5B}.exe
{1D0DBB6E-3307-448F-B5A5-165B399821D3}.exe
{A8BB1533-4D8C-450F-85D3-20A600DFF7FC}.exe
{D071FDB8-3C72-4F9F-9001-78C3823B33F0}.exe
{B0C8181A-A9EA-4C29-84A1-94938EE5E8A5}.exe
{8256B459-BCE8-4090-A5F3-4C0314DDA4AB}.exe
{7250730C-9E8D-4B11-B1CC-CDAA132FACA9}.exe
{030A314A-67A8-4F5C-988E-A655F96DE5B9}.exe
{D60A5794-0456-428E-B390-A6BA7D02344A}.exe
{60E18A20-4892-47F6-9FF9-09C8DF9EED0C}.exe
{67BF152C-06DC-4B88-A229-16745F1053C5}.exe
{4A07DDC2-E2EB-4D21-AAF8-5EC38615EAF6}.exe
{E63BF654-697B-4DB1-8128-3673B75A320A}.exe
{ACD27261-DF9F-4961-8688-69CC88DD7558}.exe
{C0DCA7A4-2458-494E-BC37-E26840C60B41}.exe
{F247B478-9040-4723-8A89-88AE51DDA487}.exe
{8BEAA98F-BD20-46F7-934A-97C4E5BCAA2D}.exe
{777BE974-24D3-46D6-BA0C-D9B723A7780E}.exe
{16F8C82B-82E4-4821-984D-6B4C513E6643}.exe
{95C2B6E7-5053-4463-928F-B781A31EA1E7}.exe
{7574B084-82D3-4469-B9CB-92BC961208C0}.exe
{28D8EC1E-5DD4-4FB6-A2A9-3715E612FE7C}.exe
{6CB9B9DA-A29E-488E-B71F-E8A40838B762}.exe
{2226E363-970A-4747-AAD8-766F0AA849D5}.exe
{28F83E29-C6C5-41FB-A3DB-12EB10D982F2}.exe
{05062857-18B4-4108-8E17-BE356CC2B542}.exe
{CA221FB5-6849-47CE-9A4C-654C431A1D5B}.exe
{01BF022D-4DE1-4795-AA8A-055FC6233B66}.exe
{E9FF166C-8E07-42B0-93CE-8FF14B4F192D}.exe
{774015C5-2FA4-4246-BB11-2E36B4E7100C}.exe
{7A02C497-8E37-462F-B5A6-CAE5602F19E8}.exe
{55C60DAD-9909-4392-A2D9-EBA98F259BC2}.exe
{EF60EFFF-D1F6-45FE-885A-0DB76E4616F3}.exe
{E1A62CFE-2CB0-416C-8020-94B4EFB9E6ED}.exe
{A2D2BDFC-066B-4D08-902E-B95BCE53DF56}.exe

And here is an error report generated when running fixwareout:
An unexpected error has occurred at procedure:
modMain_FixOther1Item(sItem=O1 - Hosts: localhost 127.0.0.1)
Error #75 - Path/File access error

Please email me at merijn@spywareinfo.com, reporting the following:
* What you were trying to fix when the error occurred, if applicable
* How you can reproduce the error
* A complete HijackThis scan log, if possible

Windows version: Windows NT 5.00.2195
MSIE version: 6.0.2800.1106
HijackThis version: 1.99.1

This message has been copied to your clipboard.
Click OK to continue the rest of the scan.



My computer is running so slow that most of the time, it freezes up. I ran highjack this and tried to save the report, but it wouldn't do it. Is there anything that I can do?

#8 mattybbbbb

mattybbbbb
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:09:44 AM

Posted 14 July 2006 - 09:03 AM

Here is the FixWareOut log:

Fixwareout ver 1.003
Last edited 07/1/2006
Post this report in the forums please

Reg Entries that were deleted
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
2812620D3916-3EE9-5584-5D0A-2AB13AE6{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
1DFED2A3FFE4-9199-2FC4-CE5B-A2AE98EC{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
FA5AB5FDB1E3-077A-3034-0ECF-43D46209{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
06FF310A0DB7-FCE8-E2B4-5811-DC44A11C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
91F8A1C96788-A489-7804-A152-38A935DA{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
F59F59B5FB92-5538-75C4-F3EE-94DA401D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
6D2B26D9FA7C-75BA-CD64-65CF-A6BDBFFA{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
DA5294210AC3-F818-77B4-36F1-ACCC543B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
373670CB7B7A-5998-6C64-B968-4D075DBF{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
DE2E779ED188-44E8-C134-8F49-68F29E9A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
A5011391AB10-2168-C674-5A93-60197BB5{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
1BEC37D3CCE2-8418-A964-BA5F-1ABD0053{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
ABB52CAE1487-AFBA-5D04-7CD5-4E50A253{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
3C220342C21C-10BA-8AF4-D968-E9EEB673{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
7448A668BDAE-79FA-1024-FF1F-8C868F76{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
CC0C15AEB4F6-C27B-7154-7718-DD001665{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
2AB14AD395BA-CA2B-0B84-A340-3223FBD9{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
B741E5F6E6E8-BC1A-2564-5D8A-B4D02BFC{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
BB03D8E8B913-23DB-6244-1FE1-9E942635{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
4FDC90947E20-0A79-AA14-B472-A632B7B8{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
C479BCDEAB7A-B34B-94B4-02FB-5713126A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
D5C67AC0DCCA-6CF8-CF54-53F7-E7E2329D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
E0146D944897-84E9-3364-AF41-5BA5E78D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
42B31A98114B-9D6A-5014-988F-91AE2F40{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
6588D75ECC3F-1BB8-6D14-6A50-83B918C7{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
6207E61D1478-724B-3AB4-FD15-FD9F79B2{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
B4AE4DB2B294-E4EB-3744-897F-CD967FBB{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
1EC1AC5DAAA5-434A-8C84-2CA6-770F2A9C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
8BA74E59421F-2BEB-0D54-D4CF-515CC354{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
6937774CDA27-4DFA-3114-3BFB-399D0541{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
F08E3FB08E56-3908-64F4-CD28-AD7C735E{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
CA9C7C4A170B-B02B-0824-99FB-DCE1B63C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
A0B9E381F8C1-178B-E464-E473-9676C575{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
C367E26E0806-5899-8624-84E4-A8B4BA96{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
69D1ED405B7E-FA7B-7944-D224-0498646E{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
D481FD337099-81A8-5834-FD60-9EDFB45A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
77BC5C6B253A-4CE9-4624-45CF-AE10AB24{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
5F855A47D3ED-4AD9-C604-F527-CAD8D2D2{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
66B3326CF550-A8AA-5974-1ED4-D220FB10{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
B5D1A134C456-C4A9-EC74-9486-5BF122AC{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
245B2CC653EB-71E8-8014-4B81-75826050{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
2F289D01BE21-BD3A-BF14-5C6C-92E38F82{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
5D948AA0F667-8DAA-7474-A079-363E6222{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
267B83804A8E-F17B-E884-E92A-AD9B9BC6{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
C7EF216E5173-9A2A-6BF4-4DD5-E1CE8D82{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
0C802169CB29-BC9B-9644-3D28-480B4757{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
7E1AE13A187B-F829-3644-3505-7E6B2C59{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
3466E315C4B6-D489-1284-4E28-B28C8F61{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
E0877A327B9D-C0AB-6D64-3D42-479EB777{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
D2AACB5E4C79-A439-7F64-02DB-F89AAEB8{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
784ADD15EA88-98A8-3274-0409-874B742F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
14B06C04862E-73CB-E494-8542-4A7ACD0C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
8557DD88CC96-8868-1694-F9FD-16272DCA{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
A023A57B3763-8218-1BD4-B796-456FB36E{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
6FAE51683CE5-8FAA-12D4-BE2E-2CDD70A4{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
5C3501F54761-922A-88B4-CD60-C251FB76{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
C0DEE9FD8C90-9FF9-6F74-2984-02A81E06{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
A44320D7AB6A-093B-E824-6540-4975A06D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
9B5ED69F556A-E889-C5F4-8A76-A413A030{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
9ACAF231AADC-CC1B-11B4-D8E9-C0370527{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
BA4ADD4130C4-3F5A-0904-8ECB-954B6528{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
5A8E5EE83949-1A48-92C4-AE9A-A1818C0B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
0F33B3283C87-1009-F9F4-27C3-8BDF170D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
CF7FFD006A02-3D58-F054-C8D4-3351BB8A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
3D128993B561-5A5B-F844-7033-E6BBD0D1{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
B5C76006EF17-F3AB-FB54-077F-E6B855D1{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
BD3379DBCBBA-8B88-8744-FD07-C1A69CB2{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
77B465DB071C-378A-EC64-03CE-161EED62{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
274BA469B30E-EAA8-9854-AF03-FDFEBFAD{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
B19E26AE5D74-E28A-5614-4DA0-6D6D1EF5{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
9BDF7E51A569-B278-0E04-961F-2651CE9E{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
3B185849BADE-97E8-7EF4-B220-45D2B830{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
668AE7227B96-2FE8-ECE4-F5EB-44133E07{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
C9EAD94BF268-1D8A-2634-EE05-F2F582EE{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
60E5BF9B2C29-477B-BA54-8D8C-4AB351E3{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
6802A22CDDB7-49DA-7F94-7CBE-9E914DE2{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
F4E79BA43B5B-69BA-97C4-668D-A5E608C7{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
8D3A21A959EE-3BC8-C544-1680-3487A77D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
937CC404E7BA-BEBA-F604-1B78-D05A8248{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
F8A1D8396C0D-5AC9-A934-D201-57D1B697{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
79F823280642-3D48-C024-C812-0191F8AF{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
703DC39CE92D-86DA-D8F4-A501-A3EDFE26{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
8AE94B4E4F4E-014A-DE54-9A85-C5344D47{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
15E524DA2BC7-0D8A-F2F4-FB0B-2AE14970{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
32706FF85536-D078-DA74-C509-551DC4FA{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
2531CE2C8FD0-E7CA-5DA4-5ADD-E75FBA22{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
AAED267BB2D7-6548-E0B4-EABF-F63D0BD0{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
37D85B8E9F4E-0B79-2454-E11B-326B57E8{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
7A069DAE05EC-4F58-91B4-80BD-59A32F1D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
4509DC0B2054-384A-8814-84C3-55396C50{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
5476EB8392E4-6399-E484-FF15-C772718B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
C1A0ED759C57-9149-0B64-4432-957F84C1{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
82CD1EA529B3-0DDA-BED4-64BD-FAB10DB3{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
85DA5F5231EA-191A-66E4-1748-7E6B5B78{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
3CC6A8DC97E2-C0FA-3524-BBB0-DC20EA98{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
AC7AB24E27A3-398A-BF44-DCF7-85341ECB{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
6AE7B4E25810-9208-35A4-889F-B0DA9B6F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
8A09A45BE2D8-4A08-FD74-F2C7-41D07BD6{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
B8BF29039489-6E18-2A64-B927-9BFB6AF5{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
2157777B239A-34E9-A0D4-080E-91F86EC9{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
74EFCF8C249D-1E18-8284-C500-6FBC09A8{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
E36768B539C6-0038-2AC4-8199-62BAD9A7{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
9A5C8060C0C0-0A1A-E8B4-0D5E-6AC8C32A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
612A98E2BE52-DEEA-C864-796C-30F6CCC8{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
74AA3CA03DB6-3A6A-EF44-F1E6-30F210F3{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
A0A41F497EF9-E0DA-3BA4-E0DE-7C3F63FF{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
855639EFEC01-AFD9-3654-DB31-B7EA9BA1{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
297B29DDF3E6-6D79-DF14-B86A-EE45BF64{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
C2830DEDCB83-1BFB-1FD4-8356-5D5D52E3{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
6C8864F17210-C668-D904-77A5-A7408327{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
908ACEFAD6BB-E3EB-6C84-6348-730C9083{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
66E1D5DC2A87-C01B-2F74-3BD2-14E5BCB7{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
FA7DBF78F60D-9B0B-B1D4-F401-C6E39687{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
F63F892D688D-5D48-9924-FF68-8DCE5374{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
E4B8912EC32B-69DB-5F24-00ED-8223F0D5{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
E4ECA14C395F-28DB-05A4-9CDB-5BA4F69C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
163DFA3C4264-59DA-34A4-348D-32713763{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
A7111227FB34-72DA-5F54-8FC8-D6943901{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
97A8C0E8557E-1D9B-0314-3E2C-0DC2E5A3{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
6BB0656AA93E-7F1A-1384-72C0-5E2E2C41{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
65E7D925C722-522A-6934-0663-8C8CB39A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
C65A77AA0A96-B67B-DD44-5803-0598F7B7{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
C536975A9128-8E98-AB84-CFD0-B02D838C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
5B08D4263BA4-89D9-DE84-C465-416E13ED{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
AAA744BB6452-6068-FA54-BE58-2DC7F7D5{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
3A5B0171E7F4-049B-67E4-3928-85ED8993{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
C94DECC333B8-3309-6214-6F08-CA851142{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
4DF058D27525-3EDA-1F74-5182-23A18186{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
6155B06A40DC-95CB-E554-0FF9-298B8EAA{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
58AE58B1453E-61AA-3164-E1C7-D6BDC21D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
4549CF4BC662-530A-BD34-4F72-15EEAAB8{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
D9AF31D9977F-B58A-A2F4-52F8-DA5D2980{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
F68802EEF01E-3F6A-EC24-E697-21AF3C6A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
91A6892FEEAD-4D68-93E4-FC19-8C755D35{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
7DDBDB7A4036-9939-0744-2EE5-3C0EC36F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
5DA2155AA471-C408-9C44-A08D-564496BC{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
68FF8C34C2B9-2C2B-48F4-AD3E-2BA37D07{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
7B99586903B3-C83B-15D4-6028-F51686E9{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
5BAFE01B7CC9-22CA-7084-FD98-777871CE{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
4A16B024AFA1-82FA-A1C4-03BB-BD6128B2{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
212F5C173518-8459-A4B4-7A56-39C38007{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
59C56BFE08E4-EA8A-3D04-BB36-FF771AD0{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
AE919AE3C5CE-D65A-2A34-AEB0-724AA4C2{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
98D3A19B23D6-6C4A-B9D4-69FF-7469264C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
F492C1A9D60F-15CB-E224-BB83-2EE34303{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
B2D969D5FC42-C8FB-5A54-B2EC-873F0532{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
1648273A5E16-6A58-25D4-8431-E0B78BAB{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
83B0A9CD39BA-63FB-78D4-65E4-37311E8D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
AC3D443AB55C-B76A-54F4-F214-85EEF49A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
9E4FBD5827F2-E479-0464-24D0-D5C87FB8{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
486A6D21E561-6028-0344-DE9D-95EF42E5{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
81874227BACC-4039-E1F4-6BF3-6CA9EB97{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
0F7C196D230F-65F9-6134-FF3C-7AB7A990{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
29A565501A0D-AF7A-0BC4-C653-7F1C5B01{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
53D072DA0D30-BCB9-4184-1D4C-AAE3BC02{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
A1E0A0777993-38A9-2FB4-3A28-44173E51{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
39A6457F807F-E19A-1354-F700-6A3BE274{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
C7A574D5D486-D72A-F934-2BCE-EF494719{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
5AF5E45A9F8E-5F2A-7D14-0A5F-5AB7668E{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
BF238BD9CDD7-7BF9-A074-F044-5CE37A99{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
4E2D2AD84C8E-683B-1DA4-3DE2-39739E2F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
7C71D79E3566-A1B8-9C44-BFD2-5384DD72{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
135A7A4222BA-6F8B-14F4-A2E2-D31BDD2F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
846536CA7083-9879-DE74-2350-0CFCC090{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
6B3F1C47A177-5CA9-6154-F0FB-AE96EDDE{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
ACEE240C165A-2C1B-19B4-31E3-6A8FB0A8{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
8A81CB196895-8A0B-8084-0430-3B3B178B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
FF6C92EC8070-D7CA-BDE4-78B3-73882DC4{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\aovmd
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
9F1DF45D257B-1ABB-1344-5519-5B8C2E6A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
D60A3ED2A1BA-40EA-C1A4-0977-999AE4A0{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
4A77C2F5BD32-0D28-0804-07CD-F936A17F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
25B6C4DD2F31-FA78-9F94-C593-2B1A00CD{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
31F8B2A0F36E-F92B-1A94-D725-0F89BE76{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
9041EC2FE1D0-2389-6494-D0EB-A3815A98{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
B56A23B469D6-6E9A-8B44-BBDB-AC956784{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
72587C37D041-D098-01A4-D711-5A74E822{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
29A8274DFEFA-26FA-43F4-5A4D-F2FB4D9A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
5899598258D5-4FB9-45B4-ACC5-32BBEC43{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}
E0D19122E955-297A-05F4-A9AB-EA876809{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\xedocne
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\gib_ogol
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\repiwoh
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\llun
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\23plhps
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\mgcppp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\tesvaf
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\nlcalik
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\swen
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\ogol
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\eno
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\eerht
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\ruof
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\evif
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\ypszr
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\putesprpgd
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\lavinraCputeS
...

Microsoft ® Windows Script Host Version 5.6
Random Runs removed from HKLM
"dmvoa.exe"=-
...

PLEASE NOTE, There WILL be LEGIT FILES LISTED. IF YOU ARE UNSURE OF WHAT IT
IS LEAVE THEM ALONE.
Example ipsec6.exe is legitimate

Search by size and names...
* csr.exe C:\WINNT\System32\CSFJO.EXE

Misc files
* thequicklink C:\WINNT\System32\EDJBW.DLL

Checking for older varients covered by the Rem3 tool


Search five digit cs, dm and jb files
This WILL/CAN also list Legit Files, Submit them at Virustotal
C:\WINNT\SYSTEM32\CSFJO.EXE 51,251 2006-07-01
C:\WINNT\SYSTEM32\DMVOA.EXE 44,128 2003-06-19
C:\WINNT\SYSTEM32\DMWQD.EXE 44,128 2003-06-19
Other suspects
Directory of C:\WINNT\system32
{908678AE-BA9A-4F50-A792-559E22191D0E}.exe
{34CEBB23-5CCA-4B54-9BF4-5D8528959985}.exe
{A9D4BF2F-D4A5-4F34-AF62-AFEFD4728A92}.exe
{228E47A5-117D-4A10-890D-140D73C78527}.exe
{487659CA-BDBB-44B8-A9E6-6D964B32A65B}.exe
{89A5183A-BE0D-4946-9832-0D1EF2CE1409}.exe
{67EB98F0-527D-49A1-B29F-E63F0A2B8F13}.exe
{DC00A1B2-395C-49F9-87AF-13F2DD4C6B52}.exe
{F71A639F-DC70-4080-82D0-23DB5F2C77A4}.exe
{0A4EA999-7790-4A1C-AE04-AB1A2DE3A06D}.exe
{A6E2C8B5-9155-4431-BBA1-B752D54FD1F9}.exe
{4CD28837-3B87-4EDB-AC7D-0708CE29C6FF}.exe
{8A0BF8A6-3E13-4B91-B1C2-A561C042EECA}.exe
{EDDE69EA-BF0F-4516-9AC5-771A74C1F3B6}.exe
{090CCFC0-0532-47ED-9789-3807AC635648}.exe
{F2E93793-2ED3-4AD1-B386-E8C48DA2D2E4}.exe
{99A73EC5-440F-470A-9FB7-7DDC9DB832FB}.exe
{E8667BA5-F5A0-41D7-A2F5-E8F9A54E5FA5}.exe
{917494FE-ECB2-439F-A27D-684D5D475A7C}.exe
{472EB3A6-007F-4531-A91E-F708F7546A93}.exe
{15E37144-82A3-4BF2-9A83-3997770A0E1A}.exe
{20CB3EAA-C4D1-4814-9BCB-03D0AD270D35}.exe
{10B5C1F7-356C-4CB0-A7FA-D0A105565A92}.exe
{099A7BA7-C3FF-4316-9F56-F032D691C7F0}.exe
{79BE9AC6-3FB6-4F1E-9304-CCAB72247818}.exe
{5E24FE59-D9ED-4430-8206-165E12D6A684}.exe
{8BF78C5D-0D42-4640-974E-2F7285DBF4E9}.exe
{A94FEE58-412F-4F45-A67B-C55BA344D3CA}.exe
{D8E11373-4E56-4D87-BF36-AB93DC9A0B38}.exe
{BAB87B0E-1348-4D52-85A6-61E5A3728461}.exe
{2350F378-CE2B-45A5-BF8C-24CF5D969D2B}.exe
{30343EE2-38BB-422E-BC51-F06D9A1C294F}.exe
{C4629647-FF96-4D9B-A4C6-6D32B91A3D89}.exe
{2C4AA427-0BEA-43A2-A56D-EC5C3EA919EA}.exe
{0DA177FF-63BB-40D3-A8AE-4E80EFB65C95}.exe
{70083C93-65A7-4B4A-9548-815371C5F212}.exe
{2B8216DB-BB30-4C1A-AF28-1AFA420B61A4}.exe
{EC178777-89DF-4807-AC22-9CC7B10EFAB5}.exe
{9E68615F-8206-4D51-B38C-3B30968599B7}.exe
{70D73AB2-E3DA-4F84-B2C2-9B2C43C8FF86}.exe
{CB694465-D80A-44C9-804C-174AA5512AD5}.exe
{F63CE0C3-5EE2-4470-9399-6304A7BDBDD7}.exe
{53D557C8-91CF-4E39-86D4-DAEEF2986A19}.exe
{A6C3FA12-796E-42CE-A6F3-E10FEE20886F}.exe
{0892D5AD-8F25-4F2A-A85B-F7799D13FA9D}.exe
{8BAAEE51-27F4-43DB-A035-266CB4FC9454}.exe
{D12CDB6D-7C1E-4613-AA16-E3541B85EA85}.exe
{AAE8B892-9FF0-455E-BC59-CD04A60B5516}.exe
{68181A32-2815-47F1-ADE3-52572D850FD4}.exe
{241158AC-80F6-4126-9033-8B333CCED49C}.exe
{3998DE58-8293-4E76-B940-4F7E1710B5A3}.exe
{5D7F7CD2-85EB-45AF-8606-2546BB447AAA}.exe
{DE31E614-564C-48ED-9D98-4AB3624D80B5}.exe
{C838D20B-0DFC-48BA-89E8-8219A579635C}.exe
{7B7F8950-3085-44DD-B76B-69A0AA77A56C}.exe
{A93BC8C8-3660-4396-A225-227C529D7E56}.exe
{14C2E2E5-0C27-4831-A1F7-E39AA6560BB6}.exe
{3A5E2CD0-C2E3-4130-B9D1-E7558E0C8A79}.exe
{1093496D-8CF8-45F5-AD27-43BF7221117A}.exe
{36731723-D843-4A43-AD95-4624C3AFD361}.exe
{C96F4AB5-BDC9-4A50-BD82-F593C41ACE4E}.exe
{5D0F3228-DE00-42F5-BD96-B23CE2198B4E}.exe
{4735ECD8-86FF-4299-84D5-D886D298F36F}.exe
{78693E6C-104F-4D1B-B0B9-D06F87FBD7AF}.exe
{7BCB5E41-2DB3-47F2-B10C-78A2CD5D1E66}.exe
{3809C037-8436-48C6-BE3E-BB6DAFECA809}.exe
{7238047A-5A77-409D-866C-01271F4688C6}.exe
{3E25D5D5-6538-4DF1-BFB1-38BCDED0382C}.exe
{46FB54EE-A68B-41FD-97D6-6E3FDD92B792}.exe
{1AB9AE7B-13BD-4563-9DFA-10CEFE936558}.exe
{FF36F3C7-ED0E-4AB3-AD0E-9FE794F14A0A}.exe
{3F012F03-6E1F-44FE-A6A3-6BD30AC3AA47}.exe
{8CCC6F03-C697-468C-AEED-25EB2E89A216}.exe
{A23C8CA6-E5D0-4B8E-A1A0-0C0C0608C5A9}.exe
{7A9DAB26-9918-4CA2-8300-6C935B86763E}.exe
{8A90CBF6-005C-4828-81E1-D942C8FCFE47}.exe
{9CE68F19-E080-4D0A-9E43-A932B7777512}.exe
{5FA6BFB9-729B-46A2-81E6-98493092FB8B}.exe
{6DB70D14-7C2F-47DF-80A4-8D2EB54A90A8}.exe
{F6B9AD0B-F988-4A53-8029-01852E4B7EA6}.exe
{BCE14358-7FCD-44FB-A893-3A72E42BA7CA}.exe
{89AE02CD-0BBB-4253-AF0C-2E79CD8A6CC3}.exe
{87B5B6E7-8471-4E66-A191-AE1325F5AD58}.exe
{3BD01BAF-DB46-4DEB-ADD0-3B925AE1DC28}.exe
{1C48F759-2344-46B0-9419-75C957DE0A1C}.exe
{B817277C-51FF-484E-9936-4E2938BE6745}.exe
{05C69355-3C48-4188-A483-4502B0CD9054}.exe
{D1F23A95-DB08-4B19-85F4-CE50EAD960A7}.exe
{8E75B623-B11E-4542-97B0-E4F9E8B58D73}.exe
{0DB0D36F-FBAE-4B0E-8456-7D2BB762DEAA}.exe
{22ABF57E-DDA5-4AD5-AC7E-0DF8C2EC1352}.exe
{AF4CD155-905C-47AD-870D-63558FF60723}.exe
{07941EA2-B0BF-4F2F-A8D0-7CB2AD425E51}.exe
{74D4435C-58A9-45ED-A410-E4F4E4B49EA8}.exe
{62EFDE3A-105A-4F8D-AD68-D29EC93CD307}.exe
{FA8F1910-218C-420C-84D3-246082328F97}.exe
{796B1D75-102D-439A-9CA5-D0C6938D1A8F}.exe
{8428A50D-87B1-406F-ABEB-AB7E404CC739}.exe
{D77A7843-0861-445C-8CB3-EE959A12A3D8}.exe
{7C806E5A-D866-4C79-AB96-B5B34AB97E4F}.exe
{2ED419E9-EBC7-49F7-AD94-7BDDC22A2086}.exe
{3E153BA4-C8D8-45AB-B774-92C2B9FB5E06}.exe
{EE285F2F-50EE-4362-A8D1-862FB49DAE9C}.exe
{70E33144-BE5F-4ECE-8EF2-69B7227EA866}.exe
{038B2D54-022B-4FE7-8E79-EDAB948581B3}.exe
{E9EC1562-F169-40E0-872B-965A15E7FDB9}.exe
{5FE1D6D6-0AD4-4165-A82E-47D5EA62E91B}.exe
{DAFBEFDF-30FA-4589-8AAE-E03B964AB472}.exe
{26DEE161-EC30-46CE-A873-C170BD564B77}.exe
{2BC96A1C-70DF-4478-88B8-ABBCBD9733DB}.exe
{1D558B6E-F770-45BF-BA3F-71FE60067C5B}.exe
{1D0DBB6E-3307-448F-B5A5-165B399821D3}.exe
{A8BB1533-4D8C-450F-85D3-20A600DFF7FC}.exe
{D071FDB8-3C72-4F9F-9001-78C3823B33F0}.exe
{B0C8181A-A9EA-4C29-84A1-94938EE5E8A5}.exe
{8256B459-BCE8-4090-A5F3-4C0314DDA4AB}.exe
{7250730C-9E8D-4B11-B1CC-CDAA132FACA9}.exe
{030A314A-67A8-4F5C-988E-A655F96DE5B9}.exe
{D60A5794-0456-428E-B390-A6BA7D02344A}.exe
{60E18A20-4892-47F6-9FF9-09C8DF9EED0C}.exe
{67BF152C-06DC-4B88-A229-16745F1053C5}.exe
{4A07DDC2-E2EB-4D21-AAF8-5EC38615EAF6}.exe
{E63BF654-697B-4DB1-8128-3673B75A320A}.exe
{ACD27261-DF9F-4961-8688-69CC88DD7558}.exe
{C0DCA7A4-2458-494E-BC37-E26840C60B41}.exe
{F247B478-9040-4723-8A89-88AE51DDA487}.exe
{8BEAA98F-BD20-46F7-934A-97C4E5BCAA2D}.exe
{777BE974-24D3-46D6-BA0C-D9B723A7780E}.exe
{16F8C82B-82E4-4821-984D-6B4C513E6643}.exe
{95C2B6E7-5053-4463-928F-B781A31EA1E7}.exe
{7574B084-82D3-4469-B9CB-92BC961208C0}.exe
{28D8EC1E-5DD4-4FB6-A2A9-3715E612FE7C}.exe
{6CB9B9DA-A29E-488E-B71F-E8A40838B762}.exe
{2226E363-970A-4747-AAD8-766F0AA849D5}.exe
{28F83E29-C6C5-41FB-A3DB-12EB10D982F2}.exe
{05062857-18B4-4108-8E17-BE356CC2B542}.exe
{CA221FB5-6849-47CE-9A4C-654C431A1D5B}.exe
{01BF022D-4DE1-4795-AA8A-055FC6233B66}.exe
{E9FF166C-8E07-42B0-93CE-8FF14B4F192D}.exe
{774015C5-2FA4-4246-BB11-2E36B4E7100C}.exe
{7A02C497-8E37-462F-B5A6-CAE5602F19E8}.exe
{55C60DAD-9909-4392-A2D9-EBA98F259BC2}.exe
{EF60EFFF-D1F6-45FE-885A-0DB76E4616F3}.exe
{E1A62CFE-2CB0-416C-8020-94B4EFB9E6ED}.exe
{A2D2BDFC-066B-4D08-902E-B95BCE53DF56}.exe

And here is an error report generated when running fixwareout:
An unexpected error has occurred at procedure:
modMain_FixOther1Item(sItem=O1 - Hosts: localhost 127.0.0.1)
Error #75 - Path/File access error

Please email me at merijn@spywareinfo.com, reporting the following:
* What you were trying to fix when the error occurred, if applicable
* How you can reproduce the error
* A complete HijackThis scan log, if possible

Windows version: Windows NT 5.00.2195
MSIE version: 6.0.2800.1106
HijackThis version: 1.99.1

This message has been copied to your clipboard.
Click OK to continue the rest of the scan.



My computer is running so slow that most of the time, it freezes up. I ran highjack this and tried to save the report, but it wouldn't do it. Is there anything that I can do?

#9 mattybbbbb

mattybbbbb
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:09:44 AM

Posted 14 July 2006 - 09:06 AM

Also, Panda Scan won't finish the scan. It gets pretty close to finishing and then it freezes. It takes about 24 hours to scan "My Computer" with it. My CPU is always at 100% in my task manager. Anything that I can do about that?

#10 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,388 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:09:44 AM

Posted 23 August 2006 - 10:40 AM

I am very sorry the helper who was working on this log has not responded. I have no idea why they have not done so. Do you still require help?




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users