Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

Please help

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

Please help

Unread postby bluefalcon888 » March 28th, 2008, 12:31 am

Can you help me please

I am getting System Alerts :Trojan-Spy.Win32@mx

:Trojan TJ/BZ

:PSW.x_vir

Thanks
Bluefalcon888
bluefalcon888
Active Member
 
Posts: 14
Joined: March 27th, 2008, 10:49 pm
Advertisement
Register to Remove

Re: Please help

Unread postby Shaba » March 31st, 2008, 6:39 am

Hi bluefalcon888

Click here to download HJTInstall.exe
  • Save HJTInstall.exe to your desktop.
  • Doubleclick on the HJTInstall.exe icon on your desktop.
  • By default it will install to C:\Program Files\Trend Micro\HijackThis .
  • Click on Install.
  • It will create a HijackThis icon on the desktop.
  • Once installed, it will launch Hijackthis.
  • Click on the Do a system scan and save a logfile button. It will scan and the log should open in notepad.
  • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
  • Come back here to this thread and Paste the log in your next reply.
  • DO NOT use the AnalyseThis button, its findings are dangerous if misinterpreted.
  • DO NOT have Hijackthis fix anything yet. Most of what it finds will be harmless or even required.
User avatar
Shaba
Admin/Teacher Emeritus
 
Posts: 26974
Joined: March 24th, 2006, 4:42 am
Location: Finland

Re: Please help

Unread postby bluefalcon888 » March 31st, 2008, 3:57 pm

Hi MRU
Thanks for your help
This is what I copied

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:54:15 AM, on 1/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgfws8.exe
C:\WINDOWS\system32\lkcitdl.exe
C:\WINDOWS\system32\lkads.exe
C:\WINDOWS\system32\lktsrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\National Instruments\MAX\nimxs.exe
C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
C:\WINDOWS\system32\nisvcloc.exe
C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\UTSCSI.EXE
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\WINDOWS\System32\keyhook.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\Program Files\Elaborate Bytes\DVD Region Killer\RegKillTray.exe
C:\WINDOWS\System\Inst.exe
C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\WDBtnMgr.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\VoipStunt.com\VoipStunt\VoipStunt.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Dynalink\DYWUK54\Installer\WINXP\DYWUK54 Wireless Client Utility.exe
C:\Program Files\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe
C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
C:\Program Files\RALINK\RT2500 USB Wireless LAN Card\Installer\WINXP\RaConfig2500.exe
C:\WINDOWS\system32\sistray.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Program Files\Webshots\webshots.scr
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\WINDOWS\system32\hpoipm07.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Willem\Desktop\HiJackThis.exe
C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/def ... earch.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL (file missing)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
R3 - URLSearchHook: Applian Media Toolbar - {0c3bf3a6-1f4f-458d-809f-a526443db045} - C:\Program Files\Applian_Media\tbApp0.dll
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL (file missing)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL (file missing)
O2 - BHO: Applian Media Toolbar - {0c3bf3a6-1f4f-458d-809f-a526443db045} - C:\Program Files\Applian_Media\tbApp0.dll
O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Need2Find Bar BHO - {4D1C4E81-A32A-416b-BCDB-33B3EF3617D3} - C:\Program Files\Need2Find\bar\1.bin\ND2FNBAR.DLL (file missing)
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: (no name) - {6860A44B-5D3E-433D-A7B5-D517F810D0E7} - C:\Program Files\NetProject\sbmdl.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-nz\msntb.dll
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O2 - BHO: TBSB08131 - {BEF0D9FA-0BC4-4CE3-812D-63642A7E2590} - C:\Program Files\IEToolbar\Power Search Tool\power_search_tool_3au.dll
O2 - BHO: e404 helper - {DF47DD37-AC11-4A93-8E16-2B2364AF0897} - C:\Program Files\Helper\1206478486.dll (file missing)
O3 - Toolbar: xtramsn - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-nz\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: Need2Find Bar - {4D1C4E89-A32A-416b-BCDB-33B3EF3617D3} - C:\Program Files\Need2Find\bar\1.bin\ND2FNBAR.DLL (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Webshots Toolbar - {C17590D2-ECB4-4b15-8820-F58798DCC118} - C:\Program Files\Webshots\WSToolbar4IE.dll
O3 - Toolbar: Applian Media Toolbar - {0c3bf3a6-1f4f-458d-809f-a526443db045} - C:\Program Files\Applian_Media\tbApp0.dll
O3 - Toolbar: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\System32\keyhook.exe
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [ALnD2g] C:\WINDOWS\ifwhol.exe
O4 - HKLM\..\Run: [Vmxehrhy] C:\Program Files\Iiyyi\Tovfa.exe
O4 - HKLM\..\Run: [Á³#  L"h'þ9Óœð3rÅWC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\ifwhol.exe
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\Run: [RegKillElbyCheck] "C:\Program Files\Elaborate Bytes\DVD Region Killer\ElbyCheck.exe" /L RegKill
O4 - HKLM\..\Run: [RegKillTray] "C:\Program Files\Elaborate Bytes\DVD Region Killer\RegKillTray.exe"
O4 - HKLM\..\Run: [Inst] C:\WINDOWS\System\Inst.exe install
O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
O4 - HKLM\..\Run: [CmUsbSound] RunDll32 cmcnfgu.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "E:\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [VoipStunt] "C:\Program Files\VoipStunt.com\VoipStunt\VoipStunt.exe" -nosplash -minimized
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [12Voip] "C:\Program Files\12Voip.com\12Voip\12Voip.exe" -nosplash -minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKLM\..\Policies\Explorer\Run: [some] C:\Program Files\NetProject\scit.exe
O4 - HKLM\..\Policies\Explorer\Run: [start] C:\Program Files\NetProject\sbmntr.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: DYWUK54 Wireless Client Utility.lnk = C:\Program Files\Dynalink\DYWUK54\Installer\WINXP\DYWUK54 Wireless Client Utility.exe
O4 - Global Startup: HPAiODevice(hp psc 700 series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe
O4 - Global Startup: LUMIX Simple Viewer.lnk = ?
O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
O4 - Global Startup: RaConfig2500.lnk = C:\Program Files\RALINK\RT2500 USB Wireless LAN Card\Installer\WINXP\RaConfig2500.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.h ... xdm119YYNZ
O8 - Extra context menu item: &Webshots Photo Search - res://C:\Program Files\Webshots\WSToolbar4IE.dll/MENUSEARCH.HTM
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Download All by FlashGet - C:\PROGRA~1\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\PROGRA~1\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.iefixgate.com/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.iefixgate.com/redirect.php (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/file ... _en_US.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/fu ... .0.8-2.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installer ... taller.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMe ... loader.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgfws8.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Lookout Citadel Server (LkCitadelServer) - National Instruments, Inc. - C:\WINDOWS\system32\lkcitdl.exe
O23 - Service: National Instruments PSP Server Locator (lkClassAds) - National Instruments, Inc. - C:\WINDOWS\system32\lkads.exe
O23 - Service: National Instruments Time Synchronization (lkTimeSync) - National Instruments, Inc. - C:\WINDOWS\system32\lktsrv.exe
O23 - Service: NI Configuration Manager (mxssvr) - National Instruments Corporation - C:\Program Files\National Instruments\MAX\nimxs.exe
O23 - Service: National Instruments Domain Service (NIDomainService) - National Instruments, Inc. - C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
O23 - Service: NILM License Manager - Macrovision Corporation - C:\Program Files\National Instruments\Shared\License Manager\Bin\lmgrd.exe
O23 - Service: NI Service Locator (niSvcLoc) - National Instruments Corp. - C:\WINDOWS\system32\nisvcloc.exe
O23 - Service: National Instruments Variable Engine (NITaggerService) - National Instruments, Inc. - C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: CLCV0 (UTSCSI) - Unknown owner - C:\WINDOWS\system32\UTSCSI.EXE

--
End of file - 16614 bytes
bluefalcon888
Active Member
 
Posts: 14
Joined: March 27th, 2008, 10:49 pm

Re: Please help

Unread postby Shaba » April 1st, 2008, 7:46 am

Hi

Download SmitfraudFix (by S!Ri) to your Desktop.
http://siri.urz.free.fr/Fix/SmitfraudFix.exe

Double-click SmitfraudFix.exe
Select option #1 - Search by typing 1 and press Enter
This program will scan large amounts of files on your computer for known patterns so please be patient while it works. When it is done, the results of the scan will be displayed and it will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.

IMPORTANT: Do NOT run any other options until you are asked to do so!

**If the tool fails to launch from the Desktop, please move SmitfraudFix.exe directly to the root of the system drive (usually C:), and launch from there.
User avatar
Shaba
Admin/Teacher Emeritus
 
Posts: 26974
Joined: March 24th, 2006, 4:42 am
Location: Finland

Re: Please help

Unread postby bluefalcon888 » April 2nd, 2008, 12:19 am

Hi, This is the smithfraud logfile
Thanks

SmitFraudFix v2.309

Scan done at 17:16:03.68, Wed 02/04/2008
Run from C:\Documents and Settings\Willem\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» Process

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgfws8.exe
C:\WINDOWS\system32\lkcitdl.exe
C:\WINDOWS\system32\lkads.exe
C:\WINDOWS\system32\lktsrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\National Instruments\MAX\nimxs.exe
C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
C:\WINDOWS\system32\nisvcloc.exe
C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\UTSCSI.EXE
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\WINDOWS\System32\keyhook.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\Program Files\Elaborate Bytes\DVD Region Killer\RegKillTray.exe
C:\WINDOWS\System\Inst.exe
C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\WINDOWS\system32\WDBtnMgr.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\VoipStunt.com\VoipStunt\VoipStunt.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Dynalink\DYWUK54\Installer\WINXP\DYWUK54 Wireless Client Utility.exe
C:\Program Files\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe
C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
C:\Program Files\RALINK\RT2500 USB Wireless LAN Card\Installer\WINXP\RaConfig2500.exe
C:\WINDOWS\system32\sistray.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Program Files\Webshots\webshots.scr
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\WINDOWS\system32\hpoipm07.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\cmd.exe

»»»»»»»»»»»»»»»»»»»»»»»» hosts


»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Willem


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Willem\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu

C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url FOUND !
C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Willem\FAVORI~1

C:\DOCUME~1\Willem\FAVORI~1\Online Security Test.url FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

C:\Program Files\Helper\ FOUND !
C:\Program Files\NetProject\ FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"


»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
!!!Attention, following keys are not inevitably infected!!!

IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» VACFix
!!!Attention, following keys are not inevitably infected!!!

VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="avgrsstx.dll"
"LoadAppInit_DLLs"=dword:00000001


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Rustock



»»»»»»»»»»»»»»»»»»»»»»»» DNS

Description: RT2500 USB Wireless LAN Card - Packet Scheduler Miniport
DNS Server Search Order: 192.168.1.1

HKLM\SYSTEM\CCS\Services\Tcpip\..\{BD7EC19E-8C87-4D23-8E3C-E45D53936A81}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{BD7EC19E-8C87-4D23-8E3C-E45D53936A81}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{BD7EC19E-8C87-4D23-8E3C-E45D53936A81}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1


»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End
bluefalcon888
Active Member
 
Posts: 14
Joined: March 27th, 2008, 10:49 pm

Re: Please help

Unread postby Shaba » April 2nd, 2008, 5:07 am

Hi

Please print out or copy these instructions/tutorial to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.

Download and scan with SUPERAntiSpyware Free for Home Users
  • Double-click SUPERAntiSpyware.exe and use the default settings for installation.
  • An icon will be created on your desktop. Double-click that icon to launch the program.
  • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here.)
______________________________

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
______________________________

Double-click on SmitfraudFix.exe
Select option #2 - Clean by typing 2 and press Enter.
Wait for the tool to complete and disk cleanup to finish.
You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.
The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. Reboot in Safe Mode.

The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.
______________________________

Navigate to C:\Windows\Temp
Click Edit, click Select All, press the DELETE key, and then click Yes to confirm that you want to send all the items to the Recycle Bin.

Navigate to C:\Documents and Settings\(EVERY LISTED USER)\Local Settings\Temp
Click Edit, click Select All, press the DELETE key, and then click Yes to confirm that you want to send all the items to the Recycle Bin.

Clean out your Temporary Internet files. Proceed like this:

Quit Internet Explorer, all browsers and quit any instances of Windows Explorer.

For Internet Explorer 7
  • Click Start, click Control Panel, and then double-click Internet Options.
  • On the General tab, click Delete... under Browsing History.
  • Next to Temporary Internet Files, click Delete files, and then click OK.
  • Next to Cookies, click Delete cookies, and then click OK.
  • Next to History, click Delete history, and then click OK.
  • Click the Close button.
  • Click OK.
For Internet Explorer 4.x - 6.x
  • Click Start, click Control Panel, and then double-click Internet Options.
  • On the General tab, click Delete Files under Temporary Internet Files.
  • In the Delete Files dialog box, tick the Delete all offline content check box, and then click OK.
  • On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
  • Click on the Programs tab then click the Reset Web Settings button. Click Apply then OK.
  • Click OK.
For Netscape 4.x and Up
  • Click Edit from the Netscape menubar.
  • Click Preferences... from the Edit menu.
  • Expand the Advanced menu by clicking the triangle sign.
  • Click Cache.
  • Click both the Clear Memory Cache and the Clear Disk Cache buttons.
For Mozilla 1.x and Up
  • Click Edit from the Mozilla menubar.
  • Click Preferences... from the Edit menu.
  • Expand the Advanced menu by clicking the plus sign.
  • Click Cache.
  • Click the Clear Cache button.
For Opera
  • Click File from the Opera menubar.
  • Click Preferences... from the File menu.
  • Click the History and Cache menu.
  • Click the two Clear buttons next to Typed in addresses and Visited addresses (history) and click the Empty now button to clear the Disk cache.
  • Click Ok to close the Preferences menu.
Next Click Start, click Control Panel and then double-click Display. Click on the Desktop tab, then click the Customize Desktop button. Click on the Web tab. Under Web Pages you should see a checked entry called Security info or something similar. If it is there, select that entry and click the Delete button. Click Ok then Apply and Ok.

Empty the Recycle Bin by right-clicking the Recycle Bin icon on your Desktop, and then clicking Empty Recycle Bin.
______________________________

  • Open SUPERAntiSpyware.
  • Under "Configuration and Preferences", click the Preferences button.
  • Click the Scanning Control tab.
  • Under Scanner Options make sure the following are checked (leave all others unchecked):
    • Close browsers before scanning.
    • Scan for tracking cookies.
    • Terminate memory threats before quarantining.
  • Click the "Close" button to leave the control center screen.
  • Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
  • On the left, make sure you check C:\Fixed Drive.
  • On the right, under "Complete Scan", choose Perform Complete Scan.
  • Click "Next" to start the scan. Please be patient while it scans your computer.
  • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
  • Make sure everything has a checkmark next to it and click "Next".
  • A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
  • If asked if you want to reboot, click "Yes".
  • To retrieve the removal information after reboot, launch SUPERAntispyware again.
    • Click Preferences, then click the Statistics/Logs tab.
    • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    • If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    • Please copy and paste the Scan Log results in your next reply.
  • Click Close to exit the program.
______________________________

Please post:
  1. c:\rapport.txt
  2. SUPERAntiSpyware log
  3. A new HijackThis log
You may need several replies to post the requested logs, otherwise they might get cut off.
User avatar
Shaba
Admin/Teacher Emeritus
 
Posts: 26974
Joined: March 24th, 2006, 4:42 am
Location: Finland

Re: Please help

Unread postby bluefalcon888 » April 2nd, 2008, 3:45 pm

Hi MRU

Thank You for your help!!

I am busy doing what you suggested, I have a question for you

I have been using the following spyware scanner
"C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Aware2007.exe"

What is your opinion of this package compared to Superantispyware

Shall I use only Superantispyware or both?

I have also installed the free AVG 7.0 virus scan package since my infection

Regards
Bluefalcon888
bluefalcon888
Active Member
 
Posts: 14
Joined: March 27th, 2008, 10:49 pm

Re: Please help

Unread postby Shaba » April 3rd, 2008, 3:33 am

Hi

I personally think that Superantispyware is much better than Ad-Aware 2007.

Both will work fine.
User avatar
Shaba
Admin/Teacher Emeritus
 
Posts: 26974
Joined: March 24th, 2006, 4:42 am
Location: Finland

Re: Please help

Unread postby bluefalcon888 » April 3rd, 2008, 4:08 am

Hi MRU

I logged a rapport file but somehow it got lost

I could not get to C:\Documents ad settings\Everyuser\Localsettings......
It is the local settings I could not locate
I was in explorer when I tried this and some how I could not see the "local settings" file

I did manage to get the last two

Thanks again for your help!
Bluefalcon888



SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 04/03/2008 at 09:04 AM

Application Version : 4.0.1154

Core Rules Database Version : 3429
Trace Rules Database Version: 1404

Scan type : Quick Scan
Total Scan Time : 00:32:04

Memory items scanned : 575
Memory threats detected : 1
Registry items scanned : 458
Registry threats detected : 126
File items scanned : 9414
File threats detected : 795

Adware.MyWebSearch
C:\PROGRA~1\MYWEBS~1\BAR\1.BIN\MWSOEMON.EXE
C:\PROGRA~1\MYWEBS~1\BAR\1.BIN\MWSOEMON.EXE
[MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\BAR\1.BIN\MWSOEMON.EXE
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00A6FAF1-072E-44cf-8957-5838F569A31D}
HKCR\CLSID\{00A6FAF1-072E-44CF-8957-5838F569A31D}
HKCR\CLSID\{00A6FAF1-072E-44CF-8957-5838F569A31D}
HKCR\CLSID\{00A6FAF1-072E-44CF-8957-5838F569A31D}\InprocServer32
HKCR\CLSID\{00A6FAF1-072E-44CF-8957-5838F569A31D}\InprocServer32#ThreadingModel
HKCR\CLSID\{00A6FAF1-072E-44CF-8957-5838F569A31D}\Programmable
C:\PROGRAM FILES\MYWEBSEARCH\SRCHASTT\1.BIN\MWSSRCAS.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
HKCR\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
HKCR\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
HKCR\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}\InprocServer32
HKCR\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}\InprocServer32#ThreadingModel
HKCR\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}\Programmable
HKCR\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}\TypeLib
C:\PROGRAM FILES\MYWEBSEARCH\BAR\1.BIN\MWSBAR.DLL
HKU\S-1-5-21-299502267-1580436667-1801674531-1004\Software\Microsoft\Internet Explorer\URLSearchHooks#{00A6FAF6-072E-44cf-8957-5838F569A31D}
HKCR\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D}
HKCR\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D}
HKCR\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D}\InprocServer32
HKCR\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D}\InprocServer32#ThreadingModel
HKCR\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D}\Programmable
HKCR\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
HKCR\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}\InprocServer32
HKCR\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}\InprocServer32#ThreadingModel
HKCR\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}\Programmable
HKCR\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}\TypeLib
C:\PROGRAM FILES\MYWEBSEARCH\BAR\1.BIN\MWSOEMON.EXE
C:\DOCUMENTS AND SETTINGS\ALL USERS\START MENU\PROGRAMS\STARTUP\MYWEBSEARCH EMAIL PLUGIN.LNK
C:\DOCUMENTS AND SETTINGS\ANJA\START MENU\PROGRAMS\STARTUP\MYWEBSEARCH EMAIL PLUGIN.LNK
C:\WINDOWS\Prefetch\MWSOEMON.EXE-22AAA5A1.pf

Unclassified.Unknown Origin
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4D1C4E81-A32A-416b-BCDB-33B3EF3617D3}
HKCR\CLSID\{4D1C4E81-A32A-416B-BCDB-33B3EF3617D3}
HKCR\CLSID\{4D1C4E81-A32A-416B-BCDB-33B3EF3617D3}
HKCR\CLSID\{4D1C4E81-A32A-416B-BCDB-33B3EF3617D3}\InprocServer32
HKCR\CLSID\{4D1C4E81-A32A-416B-BCDB-33B3EF3617D3}\InprocServer32#ThreadingModel
HKCR\CLSID\{4D1C4E81-A32A-416B-BCDB-33B3EF3617D3}\Programmable
HKCR\CLSID\{4D1C4E81-A32A-416B-BCDB-33B3EF3617D3}\TypeLib
C:\PROGRAM FILES\NEED2FIND\BAR\1.BIN\ND2FNBAR.DLL
HKLM\Software\Microsoft\Internet Explorer\Toolbar#{4D1C4E89-A32A-416b-BCDB-33B3EF3617D3}
HKCR\CLSID\{4D1C4E89-A32A-416B-BCDB-33B3EF3617D3}
HKCR\CLSID\{4D1C4E89-A32A-416b-BCDB-33B3EF3617D3}
HKCR\CLSID\{4D1C4E89-A32A-416b-BCDB-33B3EF3617D3}\InprocServer32
HKCR\CLSID\{4D1C4E89-A32A-416b-BCDB-33B3EF3617D3}\InprocServer32#ThreadingModel
HKCR\CLSID\{4D1C4E89-A32A-416b-BCDB-33B3EF3617D3}\Programmable
HKCR\CLSID\{4D1C4E89-A32A-416b-BCDB-33B3EF3617D3}\TypeLib
HKCR\TypeLib\{4D1C4E80-A32A-416b-BCDB-33B3EF3617D3}
HKCR\TypeLib\{4D1C4E80-A32A-416b-BCDB-33B3EF3617D3}\1.0
HKCR\TypeLib\{4D1C4E80-A32A-416b-BCDB-33B3EF3617D3}\1.0\0
HKCR\TypeLib\{4D1C4E80-A32A-416b-BCDB-33B3EF3617D3}\1.0\0\win32
HKCR\TypeLib\{4D1C4E80-A32A-416b-BCDB-33B3EF3617D3}\1.0\FLAGS
HKCR\TypeLib\{4D1C4E80-A32A-416b-BCDB-33B3EF3617D3}\1.0\HELPDIR

Trojan.Media-Codec/V4
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6860A44B-5D3E-433D-A7B5-D517F810D0E7}
HKCR\CLSID\{6860A44B-5D3E-433D-A7B5-D517F810D0E7}
HKCR\CLSID\{6860A44B-5D3E-433D-A7B5-D517F810D0E7}#xxx
HKCR\CLSID\{6860A44B-5D3E-433D-A7B5-D517F810D0E7}\InprocServer32
HKCR\CLSID\{6860A44B-5D3E-433D-A7B5-D517F810D0E7}\InprocServer32#ThreadingModel
C:\PROGRAM FILES\NETPROJECT\SBMDL.DLL
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#some [ C:\Program Files\NetProject\scit.exe ]
HKCR\videoPl.chl
HKCR\videoPl.chl\CLSID

Adware.E404 Helper/Variant-A
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DF47DD37-AC11-4A93-8E16-2B2364AF0897}
HKCR\CLSID\{DF47DD37-AC11-4A93-8E16-2B2364AF0897}
HKCR\CLSID\{DF47DD37-AC11-4A93-8E16-2B2364AF0897}
HKCR\CLSID\{DF47DD37-AC11-4A93-8E16-2B2364AF0897}\InprocServer32
HKCR\CLSID\{DF47DD37-AC11-4A93-8E16-2B2364AF0897}\InprocServer32#ThreadingModel
HKCR\CLSID\{DF47DD37-AC11-4A93-8E16-2B2364AF0897}\ProgID
HKCR\CLSID\{DF47DD37-AC11-4A93-8E16-2B2364AF0897}\Programmable
HKCR\CLSID\{DF47DD37-AC11-4A93-8E16-2B2364AF0897}\TypeLib
HKCR\CLSID\{DF47DD37-AC11-4A93-8E16-2B2364AF0897}\VersionIndependentProgID
C:\PROGRAM FILES\HELPER\1206478486.DLL

Trojan.Smitfraud Variant/IE Anti-Spyware
HKLM\Software\Microsoft\Internet Explorer\Extensions\{9034A523-D068-4BE8-A284-9DF278BE776E}

Adware.Tracking Cookie
C:\Documents and Settings\Willem\Cookies\willem@www.porn[1].txt
C:\Documents and Settings\Willem\Cookies\willem@yadro[3].txt
C:\Documents and Settings\Willem\Cookies\willem@doubleclick[4].txt
C:\Documents and Settings\Willem\Cookies\willem@www.burstnet[4].txt
C:\Documents and Settings\Willem\Cookies\willem@adrevolver[5].txt
C:\Documents and Settings\Willem\Cookies\willem@atdmt[7].txt
C:\Documents and Settings\Willem\Cookies\willem@burstnet[4].txt
C:\Documents and Settings\Willem\Cookies\willem@nextag[1].txt
C:\Documents and Settings\Willem\Cookies\willem@FISTING[3].txt
C:\Documents and Settings\Willem\Cookies\willem@tribalfusion[7].txt
C:\Documents and Settings\Willem\Cookies\willem@keywordmax[1].txt
C:\Documents and Settings\Willem\Cookies\willem@ad.yieldmanager[6].txt
C:\Documents and Settings\Willem\Cookies\willem@rotabanner2.rian[3].txt
C:\Documents and Settings\Willem\Cookies\willem@30468[1].txt
C:\Documents and Settings\Willem\Cookies\willem@ads.cnn[4].txt
C:\Documents and Settings\Willem\Cookies\willem@advancedcleaner[2].txt
C:\Documents and Settings\Willem\Cookies\willem@casalemedia[3].txt
C:\Documents and Settings\Willem\Cookies\willem@tracking.foxnews[2].txt
C:\Documents and Settings\Willem\Cookies\willem@spylog[1].txt
C:\Documents and Settings\Willem\Cookies\willem@www.antispyshield[1].txt
C:\Documents and Settings\Willem\Cookies\willem@revsci[5].txt
C:\Documents and Settings\Willem\Cookies\willem@media.adrevolver[1].txt
C:\Documents and Settings\Willem\Cookies\willem@statcounter[7].txt
C:\Documents and Settings\Willem\Cookies\willem@ads.telegraph.co[1].txt
C:\Documents and Settings\Willem\Cookies\willem@fastclick[5].txt
C:\Documents and Settings\Willem\Cookies\willem@advertising[3].txt
C:\Documents and Settings\Willem\Cookies\willem@virusranger[2].txt
C:\Documents and Settings\Willem\Cookies\willem@ehg-fxcm.hitbox[2].txt
C:\Documents and Settings\Willem\Cookies\willem@adinterax[5].txt
C:\Documents and Settings\Willem\Cookies\willem@ads.ookla[3].txt
C:\Documents and Settings\Willem\Cookies\willem@bluestreak[2].txt
C:\Documents and Settings\Willem\Cookies\willem@cgi-bin[10].txt
C:\Documents and Settings\Willem\Cookies\willem@www.winspykiller[1].txt
C:\Documents and Settings\Willem\Cookies\willem@list[3].txt
C:\Documents and Settings\Willem\Cookies\willem@hitbox[3].txt
C:\Documents and Settings\Willem\Cookies\willem@adtech[4].txt
C:\Documents and Settings\Willem\Cookies\willem@tacoda[1].txt
C:\Documents and Settings\Willem\Cookies\willem@winspycontrol[1].txt
C:\Documents and Settings\Willem\Cookies\willem@rambler[2].txt
C:\Documents and Settings\Willem\Cookies\willem@apmebf[6].txt
C:\Documents and Settings\Willem\Cookies\willem@porn[2].txt
C:\Documents and Settings\Willem\Cookies\willem@cgi-bin[8].txt
C:\Documents and Settings\Willem\Cookies\willem@mediaplex[2].txt
C:\Documents and Settings\Willem\Cookies\willem@winpcdoctor[2].txt
C:\Documents and Settings\Willem\Cookies\willem@www.ezytrack[2].txt
C:\Documents and Settings\Anja\Cookies\anja@winantivirus[1].txt
C:\Documents and Settings\Anja\Cookies\anja@try.screensavers[1].txt
C:\Documents and Settings\Anja\Cookies\anja@ads.hi5[1].txt
C:\Documents and Settings\Anja\Cookies\anja@screensavers[1].txt
C:\Documents and Settings\Anja\Cookies\anja@tribalfusion[2].txt
C:\Documents and Settings\Anja\Cookies\anja@www.screensavers[2].txt
C:\Documents and Settings\Anja\Cookies\anja@burstnet[1].txt
C:\Documents and Settings\Anja\Cookies\anja@www.halstats[1].txt
C:\Documents and Settings\Anja\Cookies\anja@cpvfeed[2].txt
C:\Documents and Settings\Anja\Cookies\anja@i.screensavers[2].txt
C:\Documents and Settings\Anja\Cookies\anja@a.websponsors[2].txt
C:\Documents and Settings\Anja\Cookies\anja@ads.cnn[1].txt
C:\Documents and Settings\Anja\Cookies\anja@ads.monster[1].txt
C:\Documents and Settings\Anja\Cookies\anja@adopt.hotbar[1].txt
C:\Documents and Settings\Anja\Cookies\anja@surfaccuracy[1].txt
C:\Documents and Settings\Anja\Cookies\anja@hotbar[2].txt
C:\Documents and Settings\Anja\Cookies\anja@adultcheck[1].txt
C:\Documents and Settings\Anja\Cookies\anja@atlas.fixionmedia[1].txt
C:\Documents and Settings\Anja\Cookies\anja@media.licenseacquisition[2].txt
C:\Documents and Settings\Anja\Cookies\anja@www.burstbeacon[1].txt
C:\Documents and Settings\Anja\Cookies\anja@chordfind[1].txt
C:\Documents and Settings\Anja\Cookies\anja@mediaonenetwork[2].txt
C:\Documents and Settings\Anja\Cookies\anja@ads.xtra.co[1].txt
C:\Documents and Settings\Anja\Cookies\anja@belnk[1].txt
C:\Documents and Settings\Anja\Cookies\anja@ads.xtramsn.co[1].txt
C:\Documents and Settings\Anja\Cookies\anja@click.cashengines[1].txt
C:\Documents and Settings\Anja\Cookies\anja@dist.belnk[2].txt
C:\Documents and Settings\Anja\Cookies\anja@kanoodle[2].txt
C:\Documents and Settings\Anja\Cookies\anja@mywebsearch[1].txt
C:\Documents and Settings\Anja\Cookies\anja@nextag[2].txt
C:\Documents and Settings\Anja\Cookies\anja@optimost[1].txt
C:\Documents and Settings\Anja\Cookies\anja@toplist[1].txt
C:\Documents and Settings\Anja\Cookies\anja@superstats[1].txt
C:\Documents and Settings\Anja\Cookies\anja@track.houseoftravel.co[1].txt
C:\Documents and Settings\Anja\Cookies\anja@www.starware[1].txt
C:\Documents and Settings\Anja\Cookies\anja@www.winantivirus[1].txt
C:\Documents and Settings\Erna\Cookies\erna@ads.monster[1].txt
C:\Documents and Settings\Erna\Cookies\erna@acvs.mediaonenetwork[2].txt
C:\Documents and Settings\Erna\Cookies\erna@mywebsearch[1].txt
C:\Documents and Settings\Erna\Cookies\erna@ads.xtramsn.co[1].txt
C:\Documents and Settings\Erna\Cookies\erna@mediaonenetwork[1].txt
C:\Documents and Settings\Nadja\Cookies\nadja@www.screensavers[1].txt
C:\Documents and Settings\Nadja\Cookies\nadja@acvs.mediaonenetwork[1].txt
C:\Documents and Settings\Nadja\Cookies\nadja@ads.thestar[1].txt
C:\Documents and Settings\Nadja\Cookies\nadja@xiti[1].txt
C:\Documents and Settings\Nadja\Cookies\nadja@atwola[2].txt
C:\Documents and Settings\Nadja\Cookies\nadja@i.screensavers[2].txt
C:\Documents and Settings\Nadja\Cookies\nadja@tracker.mediatracker.co[2].txt
C:\Documents and Settings\Nadja\Cookies\nadja@cpvfeed[1].txt
C:\Documents and Settings\Nadja\Cookies\nadja@winantispyware[2].txt
C:\Documents and Settings\Nadja\Cookies\nadja@paypopup[2].txt
C:\Documents and Settings\Nadja\Cookies\nadja@belnk[1].txt
C:\Documents and Settings\Nadja\Cookies\nadja@www.winfixer[2].txt
C:\Documents and Settings\Nadja\Cookies\nadja@adknowledge[2].txt
C:\Documents and Settings\Nadja\Cookies\nadja@winfixer[1].txt
C:\Documents and Settings\Nadja\Cookies\nadja@server.cpmstar[2].txt
C:\Documents and Settings\Nadja\Cookies\nadja@track.houseoftravel.co[1].txt
C:\Documents and Settings\Nadja\Cookies\nadja@ads.xtra.co[1].txt
C:\Documents and Settings\Nadja\Cookies\nadja@dist.belnk[2].txt
C:\Documents and Settings\Nadja\Cookies\nadja@ads.xtramsn.co[1].txt
C:\Documents and Settings\Nadja\Cookies\nadja@adopt.hbmediapro[2].txt
C:\Documents and Settings\Nadja\Cookies\nadja@ads.mediaturf[1].txt
C:\Documents and Settings\Nadja\Cookies\nadja@ads.monster[2].txt
C:\Documents and Settings\Nadja\Cookies\nadja@hypertracker[1].txt
C:\Documents and Settings\Nadja\Cookies\nadja@mediaonenetwork[1].txt
C:\Documents and Settings\Nadja\Cookies\nadja@mywebsearch[2].txt
C:\Documents and Settings\Thalia\Cookies\thalia@burstnet[1].txt
C:\Documents and Settings\Thalia\Cookies\thalia@kanoodle[1].txt
C:\Documents and Settings\Thalia\Cookies\thalia@surfaccuracy[1].txt
C:\Documents and Settings\Thalia\Cookies\thalia@cpvfeed[2].txt
C:\Documents and Settings\Thalia\Cookies\thalia@bs.serving-sys[1].txt
C:\Documents and Settings\Thalia\Cookies\thalia@interclick[1].txt
C:\Documents and Settings\Thalia\Cookies\thalia@adopt.hbmediapro[2].txt
C:\Documents and Settings\Thalia\Cookies\thalia@ads.joetec[1].txt
C:\Documents and Settings\Thalia\Cookies\thalia@www.macromedia[2].txt
C:\Documents and Settings\Thalia\Cookies\thalia@mediaonenetwork[2].txt
C:\Documents and Settings\Thalia\Cookies\thalia@banner.50starscasino[2].txt
C:\Documents and Settings\Thalia\Cookies\thalia@www.winfixer[2].txt
C:\Documents and Settings\Thalia\Cookies\thalia@www.screensavers[2].txt
C:\Documents and Settings\Thalia\Cookies\thalia@h.starware[1].txt
C:\Documents and Settings\Thalia\Cookies\thalia@hurricanedigitalmedia[2].txt
C:\Documents and Settings\Thalia\Cookies\thalia@www.findarticles[2].txt
C:\Documents and Settings\Thalia\Cookies\thalia@hypertracker[2].txt
C:\Documents and Settings\Thalia\Cookies\thalia@tracker.mediatracker.co[1].txt
C:\Documents and Settings\Thalia\Cookies\thalia@azjmp[2].txt
C:\Documents and Settings\Thalia\Cookies\thalia@mediaframe[1].txt
C:\Documents and Settings\Thalia\Cookies\thalia@a.websponsors[2].txt
C:\Documents and Settings\Thalia\Cookies\thalia@winfixer[1].txt
C:\Documents and Settings\Thalia\Cookies\thalia@paypopup[1].txt
C:\Documents and Settings\Thalia\Cookies\thalia@clickbank[1].txt
C:\Documents and Settings\Thalia\Cookies\thalia@i.screensavers[2].txt
C:\Documents and Settings\Thalia\Cookies\thalia@dist.belnk[2].txt
C:\Documents and Settings\Thalia\Cookies\thalia@ads.xtramsn.co[1].txt
C:\Documents and Settings\Thalia\Cookies\thalia@exitexchange[2].txt
C:\Documents and Settings\Thalia\Cookies\thalia@ads.xtra.co[1].txt
C:\Documents and Settings\Thalia\Cookies\thalia@belnk[1].txt
C:\Documents and Settings\Thalia\Cookies\thalia@click.cashengines[1].txt
C:\Documents and Settings\Thalia\Cookies\thalia@clicks.smartbizsearch[1].txt
C:\Documents and Settings\Thalia\Cookies\thalia@mywebsearch[1].txt
C:\Documents and Settings\Thalia\Cookies\thalia@www.tabfind[1].txt
C:\Documents and Settings\Willem\Local Settings\Temp\Cookies\willem@ads.cnn[1].txt

Adware.HBHelper
HKCR\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}
HKCR\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}\InprocServer32
HKCR\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}\InprocServer32#ThreadingModel
HKCR\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}\ProgID
HKCR\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}\TypeLib
HKCR\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}\VersionIndependentProgID

Adware.Surf Accuracy
C:\Program Files\SurfAccuracy\License.lnk
C:\Program Files\SurfAccuracy\SAcc.cfg
C:\Program Files\SurfAccuracy
HKLM\Software\SAcc
HKLM\Software\SAcc#accid
HKLM\Software\SAcc#subaccid
HKLM\Software\SAcc#Version
HKLM\Software\SAcc#InstallDate
HKLM\Software\SAcc#DbgInfo
HKLM\Software\SAcc#CfgReloadAttempts
HKLM\Software\SAcc#CfgReload
HKLM\Software\SAcc#SAData
HKLM\Software\SAcc#Counter
HKLM\Software\SAcc#NextInvoke
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SAcc
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SAcc#DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SAcc#UninstallString

Adware.Starware
C:\Documents and Settings\All Users\Application Data\Starware\buttons\games.bmp
C:\Documents and Settings\All Users\Application Data\Starware\buttons\gamesA.bmp
C:\Documents and Settings\All Users\Application Data\Starware\buttons\screensaver.bmp
C:\Documents and Settings\All Users\Application Data\Starware\buttons\screensaverA.bmp
C:\Documents and Settings\All Users\Application Data\Starware\buttons
C:\Documents and Settings\All Users\Application Data\Starware\contexts\error.xml
C:\Documents and Settings\All Users\Application Data\Starware\contexts\related.xml
C:\Documents and Settings\All Users\Application Data\Starware\contexts\travel.xml
C:\Documents and Settings\All Users\Application Data\Starware\contexts\Travel.xml.backup
C:\Documents and Settings\All Users\Application Data\Starware\contexts
C:\Documents and Settings\All Users\Application Data\Starware\SimpleUpdate\ProductMessagingConfig.xml
C:\Documents and Settings\All Users\Application Data\Starware\SimpleUpdate\ProductMessagingConfig.xml.backup
C:\Documents and Settings\All Users\Application Data\Starware\SimpleUpdate\SimpleUpdateConfig.xml
C:\Documents and Settings\All Users\Application Data\Starware\SimpleUpdate\SimpleUpdateConfig.xml.backup
C:\Documents and Settings\All Users\Application Data\Starware\SimpleUpdate\TimerManagerConfig.xml
C:\Documents and Settings\All Users\Application Data\Starware\SimpleUpdate\TimerManagerConfig.xml.backup
C:\Documents and Settings\All Users\Application Data\Starware\SimpleUpdate
C:\Documents and Settings\All Users\Application Data\Starware

Adware.IST/YourSiteBar
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ysbactivex.dll
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ysbactivex.dll#.Owner
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ysbactivex.dll#{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs#C:\WINDOWS\Downloaded Program Files\ysbactivex.dll [  ]

Trojan.Security Toolbar
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.url
C:\Documents and Settings\All Users\Start Menu\Security Troubleshooting.url

Adware.IST/ISTBar (Slotch Bar)
HKU\S-1-5-21-299502267-1580436667-1801674531-1004\Software\Microsoft\Internet Explorer\Main#BandRest
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main#BandRest

Browser Hijacker.Deskbar
HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}
HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\ProxyStubClsid
HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\ProxyStubClsid32
HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\TypeLib
HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\TypeLib#Version
HKCR\Interface\{9EBB289A-2D7B-465B-825F-1530B813E95A}
HKCR\Interface\{9EBB289A-2D7B-465B-825F-1530B813E95A}\ProxyStubClsid
HKCR\Interface\{9EBB289A-2D7B-465B-825F-1530B813E95A}\ProxyStubClsid32
HKCR\Interface\{9EBB289A-2D7B-465B-825F-1530B813E95A}\TypeLib
HKCR\Interface\{9EBB289A-2D7B-465B-825F-1530B813E95A}\TypeLib#Version
HKCR\Interface\{CD5C92AE-97B0-4BC3-BA65-BA0308D543BF}
HKCR\Interface\{CD5C92AE-97B0-4BC3-BA65-BA0308D543BF}\ProxyStubClsid
HKCR\Interface\{CD5C92AE-97B0-4BC3-BA65-BA0308D543BF}\ProxyStubClsid32
HKCR\Interface\{CD5C92AE-97B0-4BC3-BA65-BA0308D543BF}\TypeLib
HKCR\Interface\{CD5C92AE-97B0-4BC3-BA65-BA0308D543BF}\TypeLib#Version

Adware.Zango Toolbar/Hb
HKCR\Wallpaper.WallpaperManager
HKCR\Wallpaper.WallpaperManager\CLSID
HKCR\Wallpaper.WallpaperManager\CurVer
HKCR\Wallpaper.WallpaperManager.1
HKCR\Wallpaper.WallpaperManager.1\CLSID
HKCR\CLSID\{8109FD3D-D891-4F80-8339-50A4913ACE6F}
HKCR\CLSID\{8109FD3D-D891-4F80-8339-50A4913ACE6F}\InprocServer32
HKCR\CLSID\{8109FD3D-D891-4F80-8339-50A4913ACE6F}\InprocServer32#ThreadingModel
HKCR\CLSID\{8109FD3D-D891-4F80-8339-50A4913ACE6F}\ProgID
HKCR\CLSID\{8109FD3D-D891-4F80-8339-50A4913ACE6F}\Programmable
HKCR\CLSID\{8109FD3D-D891-4F80-8339-50A4913ACE6F}\TypeLib
HKCR\CLSID\{8109FD3D-D891-4F80-8339-50A4913ACE6F}\VersionIndependentProgID
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\IESkins
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoOI\dynamic
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoOI\static
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoOI
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoOL\dynamic
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoOL\static
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoOL
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\1.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\1007589.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\1029191.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\1035655.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\1055531.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\1065003.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\1070527.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\1102507.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\1177361.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\119420.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\1219027.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\1325092.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\1325321.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\1383612.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\1387231.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\1387424.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\1400989.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\1401724.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\1414116.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\1733178.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\1769922.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\1823498.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\1866203.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\221540.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\232117.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\2359662.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\2396354.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\2634378.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\27529.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\2756664.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\2787043.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\2883915.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\2885069.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\3251993.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\333590.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\3340762.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\3345633.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\3442551.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\3448677.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\3708680.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\3852296.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\3855415.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\3859864.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\3864475.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\398142.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\416852.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\520358.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\54150.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\559163.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\600583.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\602043.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\618281.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\682775.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\733368.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\737654.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\761357.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\799546.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\805478.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\819382.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\886051.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\912087.sdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\ASPL1.dat
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\domains.txt
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\hstat
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\1000025183
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\1000037585
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\1000047763
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\1000048226
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\1000048404
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\100905
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\10807
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\11213
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\11312
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\11431
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\11891
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\118964
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\127887
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\13035
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\13546
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\13562
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\13611
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\13617
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\13785
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\1458
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\14899
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\1491
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\15032
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\15040
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\15907
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\159328
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\16173
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\17025
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\17040
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\17409
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\17656
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\17974
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\18019
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\180320
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\18191
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\184591
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\18721
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\19050
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\19650
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\20187
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\2021
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\202699
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\20357
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\20478
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\20517
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\205324
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\20768
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\20869
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\20963
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\21060
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\216543
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\218943
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\22094
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\22254
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\22257
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\22265
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\223385
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\22389
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\224412
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\22657
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\227417
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\22915
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\23066
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\23607
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\23757
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\23901
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\23923
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\242233
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\24341
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\25032
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\25043
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\25047
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\251492
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\25424
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\25469
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\25509
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\257182
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\258537
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\25933
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\26134
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\26185
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\26340
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\26664
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\26994
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\270795
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\27414
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\274447
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\27503
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\27942
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\28147
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\28185
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\282887
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\28383
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\288733
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\289716
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\29115
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\29138
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\29139
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\29479
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\29509
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\30431
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\30987
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\32276
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\32614
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\32622
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\32634
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\32883
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\32980
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\33069
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\33265
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\33912
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\34123
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\34186
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\34481
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\35000
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\35047
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\351786
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\35522
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\35644
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\356660
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\35902
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\35904
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\36079
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\361427
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\367116
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\36719
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\3677
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\37135
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\371665
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\37834
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\380172
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\38868
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\39689
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\398331
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\398397
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\39850
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\39897
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\401332
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\41215
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\4124
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\4142
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\41499
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\41641
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\41858
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\41929
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\41999
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\422734
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\42688
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\427075
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\42915
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\43184
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\4382
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\439286
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\43979
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\44228
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\44293
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\44323
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\44458
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\44769
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\4487
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\44878
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\44957
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\450210
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\45833
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\463749
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\46415
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\468327
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\469131
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\47371
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\482315
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\486721
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\4967
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\49821
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\49923
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\50905
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\50939
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\51666
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\51824
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\52335
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\52625
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\526532
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\531510
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\53481
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\5358
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\53813
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\53933
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\540999
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\541369
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\54189
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\544105
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\54473
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\54579
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\54908
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\549635
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\552210
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\5567
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\55778
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\56133
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\561893
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\564073
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\565392
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\565974
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\56815
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\569859
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\57137
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\572023
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\575586
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\578907
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\579123
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\579718
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\58197
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\58804
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\59221
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\59234
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\59243
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\594416
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\59844
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\59905
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\59913
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\602675
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\61167
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\61168
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\61670
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\61678
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\61682
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\61795
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\61837
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\62019
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\622354
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\6275
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\6292
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\63143
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\63264
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\636407
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\63770
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\63806
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\638331
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\64402
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\644411
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\64517
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\6468
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\64781
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\6501
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\65429
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\6546
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\6556
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\6558
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\655883
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\6559
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\6561
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\65762
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\65965
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\6635
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\664683
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\66836
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\66855
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\668564
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\67491
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\676
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\67733
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\68016
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\68102
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\6873
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\69308
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\69322
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\69325
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\69940
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\702277
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\702617
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\702649
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\702684
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\702685
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\702691
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\702707
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\702713
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\70650
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\71149
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\71340
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\71542
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\72010
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\72873
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\72889
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\72932
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\7295
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\73415
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\73670
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\737665
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\738022
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\73804
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\73811
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\741544
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\74398
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\744617
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\744873
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\744919
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\745029
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\745144
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\745146
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\745220
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\745256
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\745272
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\745326
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\745331
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\745340
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\745348
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\745556
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\745865
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\747828
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\7482
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\75098
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\751209
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\751222
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\7518
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\7521
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\753009
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\7652
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\78600
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\79079
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\79246
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\79257
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\79805
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\80193
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\80644
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\80670
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\81010
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\81830
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\82155
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\82180
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\82223
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\82385
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\82646
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\82959
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\83634
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\83706
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\83743
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\85381
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\85522
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\85701
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\86140
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\87002
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\87215
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\87385
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\87594
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\87908
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\88609
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\89153
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\89200
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\89673
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\89764
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\89936
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\90154
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\90300
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\90358
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\90371
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\90375
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\90389
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\90415
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\91925
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\93110
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\93279
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\93574
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\93575
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\93899
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\93921
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\93934
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\93958
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\93997
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\94400
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\94407
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\95319
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\95325
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\95610
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\95678
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\95692
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\95701
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\95704
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\95825
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\95849
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\9695
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\96961
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\97498
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\97499
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\97546
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\97741
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\97801
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\9836
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\9875
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\99392
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\99658
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\ustat\3503.dat
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\ustat
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\btntrans.idx
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\btntrans1.dat
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\buttondir.txt
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\components.cdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\default.cdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_511745-514279.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_bidzC_ZT_IE-ca.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_bidzC_ZT_IE-us.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_categorize.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_comparison.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_explorer-Mails.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_explorer-people.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_favorites.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_Games.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_Hide.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_hotbarcom.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_Hotmail.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_hsskin.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_jemster.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_jemsterie.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_jemsteruk.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_jobsearch.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_Mails.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_MobileSidewalk.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_MobileSW-US.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_new.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_premium.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_reun.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_ringtones.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_SearchBoxTrapper.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_searchfor.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_searchgo.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_weather.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_yellowpages.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\d_icons_buttons_1000.res
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\d_icons_buttons_2000.res
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\d_icons_buttons_3000.res
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\d_icons_buttons_bar.res
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\d_icons_buttons_bbar1.res
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\d_icons_buttons_logos.res
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\d_icons_buttons_other.res
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\email-def-511724-548964.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\email-def-511724-9595.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\email-t1-bg.res
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\icons2.res
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\keywords.idx
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\keywords1.dat
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\layout.cdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\linkpathlegal.txt
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\progress.res
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\sales_buttons.res
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\s_icons_buttons.res
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\t2_bg.res
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\theweb.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\top7.cdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Top7_theweb.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\tsd_bg.res
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\zango.res
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\btntrans.idx
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\btntrans1.dat
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\buttondir.txt
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\components.cdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\default.cdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\Default_511745-514279.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\Default_bidzC_ZT_IE-ca.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\Default_bidzC_ZT_IE-us.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\Default_categorize.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\Default_comparison.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\Default_explorer-Mails.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\Default_explorer-people.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\Default_favorites.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\Default_Games.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\Default_Hide.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\Default_hotbarcom.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\Default_Hotmail.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\Default_hsskin.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\Default_jemster.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\Default_jemsterie.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\Default_jemsteruk.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\Default_jobsearch.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\Default_Mails.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\Default_MobileSidewalk.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\Default_MobileSW-US.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\Default_new.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\Default_premium.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\Default_reun.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\Default_ringtones.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\Default_SearchBoxTrapper.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\Default_searchfor.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\Default_searchgo.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\Default_weather.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\Default_yellowpages.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\d_icons_buttons_1000.res
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\d_icons_buttons_2000.res
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\d_icons_buttons_3000.res
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\d_icons_buttons_bar.res
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\d_icons_buttons_bbar1.res
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\d_icons_buttons_logos.res
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\d_icons_buttons_other.res
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\email-def-511724-548964.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\email-def-511724-9595.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\email-t1-bg.res
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\icons2.res
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\keywords.idx
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\keywords1.dat
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\layout.cdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\linkpathlegal.txt
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\progress.res
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\sales_buttons.res
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\s_icons_buttons.res
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\t2_bg.res
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\theweb.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\top7.cdf
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\Top7_theweb.mnu
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\tsd_bg.res
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2\zango.res
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\BtnTrans.xip
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\BtnTrans1.xip
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\buttondir.xip
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\default.xip
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\d_icons_buttons_1000.xip
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\d_icons_buttons_2000.xip
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\d_icons_buttons_3000.xip
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\d_icons_buttons_bar.xip
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\d_icons_buttons_bbar1.xip
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\d_icons_buttons_logos.xip
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\d_icons_buttons_other.xip
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\email-t1-bg.xip
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\icons2.xip
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\keywords.xip
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\keywords1.xip
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\layout.xip
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\linkpathlegal.xip
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\progress.xip
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\sales_buttons.xip
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\samplegroups2.txt
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\samplegroups2.xip
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\s_icons_buttons.xip
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\t2_bg.xip
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\top7.xip
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\tsd_bg.xip
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\zango.xip
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0\ZangoToolbar
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\v3.0
C:\Documents and Settings\Willem\Application Data\ZangoToolbar\zbar.log
C:\Documents and Settings\Willem\Application Data\ZangoToolbar

Trojan.DNSChanger-Codec
HKCR\CLSID\E404.e404mgr
HKCR\CLSID\E404.e404mgr#UserId

Malware.SpyLocked
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Safety Alert
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Safety Alert#DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Safety Alert#UninstallString

Adware.E404 Helper/Hij
HKCR\E404.e404mgr
HKCR\E404.e404mgr\CLSID
HKCR\E404.e404mgr\CurVer
HKCR\E404.e404mgr.1
HKCR\E404.e404mgr.1\CLSID

Rogue.VirusHeat
C:\DOCUMENTS AND SETTINGS\WILLEM\LOCAL SETTINGS\TEMP\BR857.EXE

Trojan.FakeAlert-Gen/Variant
C:\WINDOWS\SYSTEM32\SOZCTUE.DLL





Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:55:37 PM, on 3/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\WINDOWS\System32\keyhook.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Elaborate Bytes\DVD Region Killer\RegKillTray.exe
C:\WINDOWS\System\Inst.exe
C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\WDBtnMgr.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\VoipStunt.com\VoipStunt\VoipStunt.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgfws8.exe
C:\WINDOWS\system32\lkcitdl.exe
C:\Program Files\Dynalink\DYWUK54\Installer\WINXP\DYWUK54 Wireless Client Utility.exe
C:\WINDOWS\system32\lkads.exe
C:\WINDOWS\system32\lktsrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\National Instruments\MAX\nimxs.exe
C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
C:\WINDOWS\system32\nisvcloc.exe
C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\UTSCSI.EXE
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
C:\Program Files\RALINK\RT2500 USB Wireless LAN Card\Installer\WINXP\RaConfig2500.exe
C:\WINDOWS\system32\sistray.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Program Files\Webshots\webshots.scr
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\WINDOWS\system32\hpoipm07.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Documents and Settings\Willem\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
R3 - URLSearchHook: Applian Media Toolbar - {0c3bf3a6-1f4f-458d-809f-a526443db045} - C:\Program Files\Applian_Media\tbApp0.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Applian Media Toolbar - {0c3bf3a6-1f4f-458d-809f-a526443db045} - C:\Program Files\Applian_Media\tbApp0.dll
O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-nz\msntb.dll
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O2 - BHO: TBSB08131 - {BEF0D9FA-0BC4-4CE3-812D-63642A7E2590} - C:\Program Files\IEToolbar\Power Search Tool\power_search_tool_3au.dll
O3 - Toolbar: xtramsn - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-nz\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Webshots Toolbar - {C17590D2-ECB4-4b15-8820-F58798DCC118} - C:\Program Files\Webshots\WSToolbar4IE.dll
O3 - Toolbar: Applian Media Toolbar - {0c3bf3a6-1f4f-458d-809f-a526443db045} - C:\Program Files\Applian_Media\tbApp0.dll
O3 - Toolbar: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\System32\keyhook.exe
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [ALnD2g] C:\WINDOWS\ifwhol.exe
O4 - HKLM\..\Run: [Vmxehrhy] C:\Program Files\Iiyyi\Tovfa.exe
O4 - HKLM\..\Run: [Á³#  L"h'þ9Óœð3rÅWC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\ifwhol.exe
O4 - HKLM\..\Run: [RegKillElbyCheck] "C:\Program Files\Elaborate Bytes\DVD Region Killer\ElbyCheck.exe" /L RegKill
O4 - HKLM\..\Run: [RegKillTray] "C:\Program Files\Elaborate Bytes\DVD Region Killer\RegKillTray.exe"
O4 - HKLM\..\Run: [Inst] C:\WINDOWS\System\Inst.exe install
O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
O4 - HKLM\..\Run: [CmUsbSound] RunDll32 cmcnfgu.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "E:\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [VoipStunt] "C:\Program Files\VoipStunt.com\VoipStunt\VoipStunt.exe" -nosplash -minimized
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [12Voip] "C:\Program Files\12Voip.com\12Voip\12Voip.exe" -nosplash -minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: DYWUK54 Wireless Client Utility.lnk = C:\Program Files\Dynalink\DYWUK54\Installer\WINXP\DYWUK54 Wireless Client Utility.exe
O4 - Global Startup: HPAiODevice(hp psc 700 series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe
O4 - Global Startup: LUMIX Simple Viewer.lnk = ?
O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
O4 - Global Startup: RaConfig2500.lnk = C:\Program Files\RALINK\RT2500 USB Wireless LAN Card\Installer\WINXP\RaConfig2500.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.h ... xdm119YYNZ
O8 - Extra context menu item: &Webshots Photo Search - res://C:\Program Files\Webshots\WSToolbar4IE.dll/MENUSEARCH.HTM
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Download All by FlashGet - C:\PROGRA~1\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\PROGRA~1\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/file ... _en_US.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/fu ... .0.8-2.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installer ... taller.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMe ... loader.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgfws8.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Lookout Citadel Server (LkCitadelServer) - National Instruments, Inc. - C:\WINDOWS\system32\lkcitdl.exe
O23 - Service: National Instruments PSP Server Locator (lkClassAds) - National Instruments, Inc. - C:\WINDOWS\system32\lkads.exe
O23 - Service: National Instruments Time Synchronization (lkTimeSync) - National Instruments, Inc. - C:\WINDOWS\system32\lktsrv.exe
O23 - Service: NI Configuration Manager (mxssvr) - National Instruments Corporation - C:\Program Files\National Instruments\MAX\nimxs.exe
O23 - Service: National Instruments Domain Service (NIDomainService) - National Instruments, Inc. - C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
O23 - Service: NILM License Manager - Macrovision Corporation - C:\Program Files\National Instruments\Shared\License Manager\Bin\lmgrd.exe
O23 - Service: NI Service Locator (niSvcLoc) - National Instruments Corp. - C:\WINDOWS\system32\nisvcloc.exe
O23 - Service: National Instruments Variable Engine (NITaggerService) - National Instruments, Inc. - C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: CLCV0 (UTSCSI) - Unknown owner - C:\WINDOWS\system32\UTSCSI.EXE

--
End of file - 14848 bytes
bluefalcon888
Active Member
 
Posts: 14
Joined: March 27th, 2008, 10:49 pm

Re: Please help

Unread postby Shaba » April 3rd, 2008, 5:05 am

Hi

Much better :)

Create own folder for HijackThis to desktop and move it into that folder.

Open HijackThis, click do a system scan only and checkmark these:

R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O4 - HKLM\..\Run: [ALnD2g] C:\WINDOWS\ifwhol.exe
O4 - HKLM\..\Run: [Vmxehrhy] C:\Program Files\Iiyyi\Tovfa.exe
O4 - HKLM\..\Run: [Á³# L"h'þ9Óœð3rÅWC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\ifwhol.exe
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -


Close all windows including browser and press fix checked.

Reboot.

Delete these if present:

C:\WINDOWS\ifwhol.exe
C:\Program Files\Iiyyi

Empty Recycle Bin.Please click this link-->Jotti

Copy/paste the first file on the list into the white Upload a file box and click Submit/Send (depends on which one you are using Jotti or VirusTotal).

C:\Program Files\IEToolbar\Power Search Tool\power_search_tool_3au.dll

Please post back the results of the scan in your next post.

If Jotti is busy, try the same at Virustotal: http://www.virustotal.com/

Post:

- a fresh HijackThis log
- jotti/virustotal results
User avatar
Shaba
Admin/Teacher Emeritus
 
Posts: 26974
Joined: March 24th, 2006, 4:42 am
Location: Finland

Re: Please help

Unread postby bluefalcon888 » April 3rd, 2008, 11:44 pm

Hi MRU

These are the jotti results

Scan taken on 04 Apr 2008 03:37:52 (GMT)
A-Squared Found nothing
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
CPsecure Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found nothing
Fortinet Found nothing
Ikarus Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found nothing
Rising Antivirus Found nothing
Sophos Antivirus Found nothing
VirusBuster Found nothing
VBA32 Found nothing


Hijackthis log


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:42:48 PM, on 4/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgfws8.exe
C:\WINDOWS\system32\lkcitdl.exe
C:\WINDOWS\system32\lkads.exe
C:\WINDOWS\system32\lktsrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\National Instruments\MAX\nimxs.exe
C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
C:\WINDOWS\system32\nisvcloc.exe
C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\UTSCSI.EXE
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\WINDOWS\System32\keyhook.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Elaborate Bytes\DVD Region Killer\RegKillTray.exe
C:\WINDOWS\System\Inst.exe
C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\WDBtnMgr.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\VoipStunt.com\VoipStunt\VoipStunt.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Dynalink\DYWUK54\Installer\WINXP\DYWUK54 Wireless Client Utility.exe
C:\Program Files\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe
C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\WINDOWS\system32\hpoipm07.exe
C:\Program Files\RALINK\RT2500 USB Wireless LAN Card\Installer\WINXP\RaConfig2500.exe
C:\WINDOWS\system32\sistray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Program Files\Webshots\webshots.scr
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Program Files\Media Player Classic\mplayerc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\Willem\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Applian Media Toolbar - {0c3bf3a6-1f4f-458d-809f-a526443db045} - C:\Program Files\Applian_Media\tbApp0.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Applian Media Toolbar - {0c3bf3a6-1f4f-458d-809f-a526443db045} - C:\Program Files\Applian_Media\tbApp0.dll
O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-nz\msntb.dll
O2 - BHO: TBSB08131 - {BEF0D9FA-0BC4-4CE3-812D-63642A7E2590} - C:\Program Files\IEToolbar\Power Search Tool\power_search_tool_3au.dll
O3 - Toolbar: xtramsn - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-nz\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Webshots Toolbar - {C17590D2-ECB4-4b15-8820-F58798DCC118} - C:\Program Files\Webshots\WSToolbar4IE.dll
O3 - Toolbar: Applian Media Toolbar - {0c3bf3a6-1f4f-458d-809f-a526443db045} - C:\Program Files\Applian_Media\tbApp0.dll
O3 - Toolbar: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\System32\keyhook.exe
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [RegKillElbyCheck] "C:\Program Files\Elaborate Bytes\DVD Region Killer\ElbyCheck.exe" /L RegKill
O4 - HKLM\..\Run: [RegKillTray] "C:\Program Files\Elaborate Bytes\DVD Region Killer\RegKillTray.exe"
O4 - HKLM\..\Run: [Inst] C:\WINDOWS\System\Inst.exe install
O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
O4 - HKLM\..\Run: [CmUsbSound] RunDll32 cmcnfgu.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "E:\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [VoipStunt] "C:\Program Files\VoipStunt.com\VoipStunt\VoipStunt.exe" -nosplash -minimized
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [12Voip] "C:\Program Files\12Voip.com\12Voip\12Voip.exe" -nosplash -minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: DYWUK54 Wireless Client Utility.lnk = C:\Program Files\Dynalink\DYWUK54\Installer\WINXP\DYWUK54 Wireless Client Utility.exe
O4 - Global Startup: HPAiODevice(hp psc 700 series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe
O4 - Global Startup: LUMIX Simple Viewer.lnk = ?
O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
O4 - Global Startup: RaConfig2500.lnk = C:\Program Files\RALINK\RT2500 USB Wireless LAN Card\Installer\WINXP\RaConfig2500.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.h ... xdm119YYNZ
O8 - Extra context menu item: &Webshots Photo Search - res://C:\Program Files\Webshots\WSToolbar4IE.dll/MENUSEARCH.HTM
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Download All by FlashGet - C:\PROGRA~1\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\PROGRA~1\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/file ... _en_US.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/fu ... .0.8-2.cab
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installer ... taller.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMe ... loader.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgfws8.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Lookout Citadel Server (LkCitadelServer) - National Instruments, Inc. - C:\WINDOWS\system32\lkcitdl.exe
O23 - Service: National Instruments PSP Server Locator (lkClassAds) - National Instruments, Inc. - C:\WINDOWS\system32\lkads.exe
O23 - Service: National Instruments Time Synchronization (lkTimeSync) - National Instruments, Inc. - C:\WINDOWS\system32\lktsrv.exe
O23 - Service: NI Configuration Manager (mxssvr) - National Instruments Corporation - C:\Program Files\National Instruments\MAX\nimxs.exe
O23 - Service: National Instruments Domain Service (NIDomainService) - National Instruments, Inc. - C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
O23 - Service: NILM License Manager - Macrovision Corporation - C:\Program Files\National Instruments\Shared\License Manager\Bin\lmgrd.exe
O23 - Service: NI Service Locator (niSvcLoc) - National Instruments Corp. - C:\WINDOWS\system32\nisvcloc.exe
O23 - Service: National Instruments Variable Engine (NITaggerService) - National Instruments, Inc. - C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: CLCV0 (UTSCSI) - Unknown owner - C:\WINDOWS\system32\UTSCSI.EXE

--
End of file - 14396 bytes
bluefalcon888
Active Member
 
Posts: 14
Joined: March 27th, 2008, 10:49 pm

Re: Please help

Unread postby Shaba » April 4th, 2008, 4:04 am

Hi

HijackThis is still directly in Desktop:

C:\Documents and Settings\Willem\Desktop\HiJackThis.exe

It should be like this:

C:\Documents and Settings\Willem\Desktop\HijackThis\HiJackThis.exe

Please correct it.

After that:

Open HijackThis, click do a system scan only and checkmark these:

O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/fu ... .0.8-2.cab
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installer ... taller.cab

Close all windows including browser and press fix checked.

Reboot.

Please do an online scan with Kaspersky Online Scanner. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:

    o Scan using the following Anti-Virus database:

    + Extended (If available otherwise Standard)

    o Scan Options:

    + Scan Archives
    + Scan Mail Bases

  • Click OK
  • Now under select a target to scan select My Computer
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Please do not use your computer while the scan is running. Once the scan is complete it will display if your system has been infected.
  • Click the Save Report As... button (see red arrow below)
    Image
  • In the Save as... prompt, select Desktop
  • In the File name box, name the file KasScan-ddmmyy (or similar)
  • In the Save as type prompt, select Text file (see below)
    Image
  • Now click on the Save as Text button
  • Savethe file to your desktop.
  • Copy and paste that information in your next post.

Note: This scanner will work with Internet Explorer Only! Keep ALL other programs closed during the scan

Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the license, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.

Post:

- a fresh HijackThis log
- kaspersky report
User avatar
Shaba
Admin/Teacher Emeritus
 
Posts: 26974
Joined: March 24th, 2006, 4:42 am
Location: Finland

Re: Please help

Unread postby bluefalcon888 » April 5th, 2008, 3:34 am

Hi MRU

It looks like I will never get rid of this infestation!!
I wonder how one can keep your PC free from this?
Thanks for your help once again!
Here are the reports
Regards
Bluefalco888

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:29:32 PM, on 5/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgfws8.exe
C:\WINDOWS\system32\lkcitdl.exe
C:\WINDOWS\system32\lkads.exe
C:\WINDOWS\system32\lktsrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\National Instruments\MAX\nimxs.exe
C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
C:\WINDOWS\system32\nisvcloc.exe
C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\UTSCSI.EXE
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\WINDOWS\System32\keyhook.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Elaborate Bytes\DVD Region Killer\RegKillTray.exe
C:\WINDOWS\System\Inst.exe
C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\WDBtnMgr.exe
E:\Reader\Reader_sl.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\VoipStunt.com\VoipStunt\VoipStunt.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Dynalink\DYWUK54\Installer\WINXP\DYWUK54 Wireless Client Utility.exe
C:\Program Files\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe
C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\hpoipm07.exe
C:\Program Files\RALINK\RT2500 USB Wireless LAN Card\Installer\WINXP\RaConfig2500.exe
C:\WINDOWS\system32\sistray.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Program Files\Webshots\webshots.scr
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Documents and Settings\Willem\Desktop\Hijackthis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Applian Media Toolbar - {0c3bf3a6-1f4f-458d-809f-a526443db045} - C:\Program Files\Applian_Media\tbApp0.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Applian Media Toolbar - {0c3bf3a6-1f4f-458d-809f-a526443db045} - C:\Program Files\Applian_Media\tbApp0.dll
O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-nz\msntb.dll
O2 - BHO: TBSB08131 - {BEF0D9FA-0BC4-4CE3-812D-63642A7E2590} - C:\Program Files\IEToolbar\Power Search Tool\power_search_tool_3au.dll
O3 - Toolbar: xtramsn - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-nz\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Webshots Toolbar - {C17590D2-ECB4-4b15-8820-F58798DCC118} - C:\Program Files\Webshots\WSToolbar4IE.dll
O3 - Toolbar: Applian Media Toolbar - {0c3bf3a6-1f4f-458d-809f-a526443db045} - C:\Program Files\Applian_Media\tbApp0.dll
O3 - Toolbar: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\System32\keyhook.exe
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [RegKillElbyCheck] "C:\Program Files\Elaborate Bytes\DVD Region Killer\ElbyCheck.exe" /L RegKill
O4 - HKLM\..\Run: [RegKillTray] "C:\Program Files\Elaborate Bytes\DVD Region Killer\RegKillTray.exe"
O4 - HKLM\..\Run: [Inst] C:\WINDOWS\System\Inst.exe install
O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
O4 - HKLM\..\Run: [CmUsbSound] RunDll32 cmcnfgu.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "E:\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [VoipStunt] "C:\Program Files\VoipStunt.com\VoipStunt\VoipStunt.exe" -nosplash -minimized
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [12Voip] "C:\Program Files\12Voip.com\12Voip\12Voip.exe" -nosplash -minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: DYWUK54 Wireless Client Utility.lnk = C:\Program Files\Dynalink\DYWUK54\Installer\WINXP\DYWUK54 Wireless Client Utility.exe
O4 - Global Startup: HPAiODevice(hp psc 700 series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe
O4 - Global Startup: LUMIX Simple Viewer.lnk = ?
O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
O4 - Global Startup: RaConfig2500.lnk = C:\Program Files\RALINK\RT2500 USB Wireless LAN Card\Installer\WINXP\RaConfig2500.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.h ... xdm119YYNZ
O8 - Extra context menu item: &Webshots Photo Search - res://C:\Program Files\Webshots\WSToolbar4IE.dll/MENUSEARCH.HTM
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Download All by FlashGet - C:\PROGRA~1\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\PROGRA~1\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/file ... _en_US.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/ka ... nicode.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMe ... loader.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgfws8.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lookout Citadel Server (LkCitadelServer) - National Instruments, Inc. - C:\WINDOWS\system32\lkcitdl.exe
O23 - Service: National Instruments PSP Server Locator (lkClassAds) - National Instruments, Inc. - C:\WINDOWS\system32\lkads.exe
O23 - Service: National Instruments Time Synchronization (lkTimeSync) - National Instruments, Inc. - C:\WINDOWS\system32\lktsrv.exe
O23 - Service: NI Configuration Manager (mxssvr) - National Instruments Corporation - C:\Program Files\National Instruments\MAX\nimxs.exe
O23 - Service: National Instruments Domain Service (NIDomainService) - National Instruments, Inc. - C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
O23 - Service: NILM License Manager - Macrovision Corporation - C:\Program Files\National Instruments\Shared\License Manager\Bin\lmgrd.exe
O23 - Service: NI Service Locator (niSvcLoc) - National Instruments Corp. - C:\WINDOWS\system32\nisvcloc.exe
O23 - Service: National Instruments Variable Engine (NITaggerService) - National Instruments, Inc. - C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: CLCV0 (UTSCSI) - Unknown owner - C:\WINDOWS\system32\UTSCSI.EXE

--
End of file - 13839 bytes



-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Saturday, April 05, 2008 8:21:58 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 5/04/2008
Kaspersky Anti-Virus database records: 682641
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\
F:\

Scan Statistics:
Total number of scanned objects: 319950
Number of viruses found: 24
Number of infected objects: 82
Number of suspicious objects: 0
Duration of the scan process: 03:35:49

Infected Object Name / Virus Name / Last Action
C:\ASmithfruad\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\ASmithfruad\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\ASmithfruad\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\ASmithfruad\SmitfraudFix.exe RarSFX: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\avg8\AvgAm\avgam.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgam.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgcore.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgcore.log.1 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avglng.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgns.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgrs.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgsched.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgui.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgwd.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgwdsvc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\commonpriv.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\commonpub.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\00b3f014d40c5056b77d15df966d67ba_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\01ec5b1f10af285e659663d79861d8a4_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\020f52542255284ca25c51449c17f88e_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0239d8294af5cbe8d7dbc9bb92113c44_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0428521c5a38e581aafe8bfd794e6776_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\048f3cd99b89244167724a5396b3f397_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\05013ec8e540bc7ff2be0971ec6b72fc_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0627b593928f3f3a7df4cb378c9071bf_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\069fd422d698d2e0254b180ec93f1ccb_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\087ce7c8bc6c4c12fe88f97e07bf0720_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\090525ec2d45b80a08b6b76c8587de7f_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\096958267b2a0ceaf5740e056a935891_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0a8289b0a88ddb7e4dc469cc126de52a_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0d9fb3f3009f3b8dc1a5b56d4c63bed0_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0df5715a428ab7972dd5f3ead57a7116_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\11b2cb5d810739e09ce7227645a77d9c_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\123483f3395840c7a08c855ca538818e_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\136f10336d68547aab3e5d8f98db875d_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\137fb1e46af2001341a4e72cebc78a23_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1410ceeb8b7e8ddcb2837c15c6adef4f_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\14f8e62aeff86edbff17c30b5bec0c0e_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\153b1ba888a6fc667d8d8293a00ad0b6_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\15433768fcf8ded86dc710784083944c_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1543567b6a459857083862fc9e46bc94_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\16743d65f34627b5c864032217426b88_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\168dd58f8596bcb1457bf97af5e73837_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\178175c1a867766e5ff5a6a9a2a98307_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\17e4d0c536c4d9a351a65b9bf90ff2b5_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1898ca3882e1b880e7e049f28fb23285_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\18ea52793168174e3e97697821ac9835_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\18f0886c1844dcf43c90946096ffcf7f_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\18f6ae22c66a33481395124d2c0ae560_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1a0094facb593424e64c932d5232a2c0_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1aada20bfadd6371043242cb6b7dc2de_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1c76424ce3bdbab18b74b1b4afe88239_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1f0ae0bf12c10bd708f87970f49d5ba9_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1f63ea5ae4df0c7cfebe5406cfed9bea_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2335803801a58d6b06af6864caa20edb_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\239e8adea649886d283fd5cfd6f6f790_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\24575f280a3c38af807509cff663ba11_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2559341ed1877964fbd599d3f73ff4c9_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2626ee7efbf61f5775d844ce3f8d66cd_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\26933182861b9ec193b3541cf75eeb05_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\269c147021156e4054bf0f2effc5e2d4_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\26a8816b0da6554b73ba3fd64d42f40f_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\26edb5cd9ee4361b83f5e07e00a9d337_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\270d26c2998d560956019c87e829940a_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\27c3144a8a47a4fa637f926363a6ae82_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\281628410114636272349b1a29eb23b3_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2939fe126af684f92e74e4e1b6a00add_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2a835aee345803e9a93e2cdea917cef6_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2adc89fe52911f10a07ccd83992541f0_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2b44aa8776106097036e9c65ae98a77c_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2b47f4c12b1b592b089d8b45d354a8b3_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2c42ddf5feee4850faf4e11a079965ab_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2c7f91af03ee8b8b8ac5399384f9c53d_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2c93d7791eebb1d1d0438c073e4c91a5_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2c9846336bef4ad056d2a22566538c9f_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2d60eb62b5fa5f25fad6304f34e37244_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2e8388b65882edabda9b79d6e3e014c8_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2e84dce3b70661fa6902ea947871c64b_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2ebdaf62beecd798641546846ed2f3c0_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2fda5a150e5a2aa41bf75eaf051b4387_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\302104d9ce49c612a8c562e22d5d416f_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3086a9508bcfd6880b3c324d0e845308_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\30ec52c5ff849c0c950086b2d85c613c_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3203ef5af2c9252435a929f0adaaed67_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3246a5e7a977144fc791280f2098c22d_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\32c14ff67cd55d512913ac2a00aeb2d6_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\32c6e5ead507bbc804d1daa9ad4fabb0_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\331e0c148d9eca7a2336cddc10cf3ba5_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\355b629642f89b1d23cced45ca30b9b2_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\372354f1419f71dc1426963f1d8661f5_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\37f3636e32bbb99cb7c26a95457f744a_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\380d1fcf29e7b05555f079d3abe66638_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\389d49e06001b1b13ba875bbe63acbeb_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\39481070d6ecc6a6c14db73addedcb19_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\39792dea29d559092237d361bbe1633d_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\39f11c063474d6e5d51e327d8c8e5198_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3a45a09cba379a3d95614e0bab37046d_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3bd064a82250cac91f93c647cc8aa9bc_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3d58b6db0bd98c7dd55f1f246c956dfe_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3d69aa03fd50e472eeacec1dd06afc05_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3e336f851e4efd37366d0a2c489293ae_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3e6d257eae76c4b3c94546033a3c2fa4_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3eb42083f5e96dd75784373ea5c4e304_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3ec311f152c1c5783dd84c9fca8c1442_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3fb079281434df5f0fd9934172f94bc2_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4226a26004c381dc76ea9f6f96b084f8_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\42e682ccbebd0c0266f452eb479e3b8e_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4381a43077f56872e56567cfa637776e_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\43821d899122ed2e79a18937dd5e8560_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\441f1976cead891e61c04f3492a469b2_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\44a4655c94470ae28e3287c621811929_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\44ad0ccea047448d2cb832d1a7413a18_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4539b6ae54134695193091c27065b4c8_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4546aaec3235a0a356252c896414c4f9_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\454706d3f6c53c0f704d556153b7f5a1_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\456334bc52183b4036a94aa3de530be8_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\45862915382fea12ad0f31f01a94cd81_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\465040e5ea0eaaabf0decc54bdd06963_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\47131317d59aaebfebfc9d72d55f460e_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4860d05aeaf7dcd0775b2d888a9d7227_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\48d7dec242c30c2f72d92496ecaf9179_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\48ffb21d54e4f07d37e37550a9c50495_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4c50c7147574abef78f90a50d8a3456c_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4c5fadf40e3bbc32dd6d1fead34d6d8b_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4cee06ced189895306a250444f0d04d5_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4cf0a7db8095182959d29c46ef3a589b_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4d05dc726b72e44f818a7c2efae0170d_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4d3f48bd01d7a45942b7638f1795f504_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4d9c918f7b1135ffa70042bf68d7e278_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4e88dedec2ed5efe1fbc84f637c74ba4_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4f5c2c53a6894b90a97c722d9b44d675_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4f769224d58377fa75b3248acb993c74_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4fbf6a48205a7c53edd762d303f6eed0_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4fbfe4437ea9c4b0ab2061b47b50089c_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\506538a783d98d30eded769d8f3f6c28_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\50fd35ef866046a5ae3484d215e4b19e_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\522ab72287b0cbbbab385b893519f288_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\52718634300428992133244165fda9b9_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\52ea2c5a452370e6abd20013fc3fce7c_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\538ea4d51db1981ff64db2a52e1f5d49_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\53f288cdc2808650b27596accca6efa2_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\54fc73df3054186f4b867c056f4818b0_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\550362ff5e618b37f4daa8046cd0cc63_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5558b841d060840e012400dec1edb9d3_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\55735c937e043b9c90df3f21e17ee7a2_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\55784127f4e78a43f35f8c5ed772f0f6_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\55bdda262ab0c47bc2302f4308086826_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\574965c46029235a80d4790546f1947b_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\57ed6297c5d9567f5826450e2f0714ae_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\58a1a75861cdf9089a854ad80e6bde06_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\58a6bf4331e03a2a0886eea51942763f_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\58ed96f1cf9606b0008b142119224ae7_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\59be6ba82b4c5ce41bea0b793cbb6e55_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5aa279d6d932a053180a71e0b0971319_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5b5117d020a2bd658180b713bf87f0fd_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5b96216a359b186533a7ca927c4c479a_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5be1b5af1c4e7bc021156b573ad01d5b_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5c09da21c489be61d24eb2e4abd5e500_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5c1f8591ca4516d124ae7e697e04646d_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5dc97411e2d237cdc5a545b93537dbf5_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5e73bc144b2ef178c02fd7d7af3c8d90_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5e86f2e8a0173941a47e981e5eae26ea_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5eae51046fc0582fbca5b6ab20ddbc34_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\60e2fb9dbfd9ea41c554b23641464a0c_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6152920329e2f93edc61ea25f3b02c4b_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\616139fa9a65e686e0c2d4c258015e15_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\630d5d0dccde8eb624aceacfeb3a2e25_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\631510e11edd9199fbfb189b2e11bf58_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\631cf5486ac76648b56a0a5750d915db_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\63be6649f616fd523ea6594b429cbdee_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\63e0d90634411f35acd1c3a5c5665eaa_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\650b9593c59a88ff10584ad11fbb3e75_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\65336262d7f76a8c5abd8802f34c6bde_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\66ab55a1da5c5b55d22029f3439d20a0_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\66c8eeedb9de00bd01d27fff2fb1785d_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\66eb9fd3518d7e2c04441746483ddaf9_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\67c483fa80dd8541ba4151d4591862d1_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\67ca983d97c2ab99c068662705458b03_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\67d86c98d2be09f59943dc0fde8b1eae_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\68470c15e8c03945cd61fe891269ba14_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6851193d7904ad40cc77e1b875ca5ad0_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\687e49df522d440d25447d75b587f7aa_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\69fb70105dcf49b8775efaab1efd194f_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6b2c735e796f2c31adb53df72fbd84f4_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6b944e2686cc5884abff70122fb51e72_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6c5f82ae0edd575e10222251a21e21a1_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6d5cc03a88fd9537e3c97670f202653d_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6db2cec5e1d9be04b4ec5ebe1bb3be60_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6dcb29aa5832c946198646467e7d3b7b_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6e268ed4504944967cdc414f876a8d96_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6f1fd5de9362118267c3aa44c012fcd7_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6f76b3e6e8adffcc2bcda032200d03fd_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\702fc725018a01029bf030d8fc21f5f5_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\716965da2b4f80487fc996e4fe9a8f20_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\718af88d237930c38cab324b422b73e7_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\719340e1458bade8c4feb385199470cb_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\719cb3feaa3906ad77833aee02e9a1a0_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7233da119552d3d1ca6671b78c196b33_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7242c1d6fb02f005e88e1c00f16b139c_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\724f61fd27d79f14670106dfefcdc24b_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\72b431fdfc19c73e44a1fd47b9c5c59e_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\731c31d26eeddba07a12e0dcb0172168_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7337e3c3d155ddb743c5199c33a6dd67_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\73580f4b6cdc8057373bfbd3109802c4_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\73a36d4fd7016edf8fc963ba26ae75c4_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\74959ac0242a6e31d6a294af9fe8ed51_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\74c3d70a7d9cc0a0d5ce6c3e9666dd5c_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\754f07cc6bff4f3ab5235cffc3a75e17_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\77e49dc4ab66984bef45c0a6421d0fcc_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7997ca1b7939d5e9b21f25615e5f0843_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7a2e8b933ff2e0ece58eef2578ca70b6_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7ad5b9349d9de6add6f8abd66c298725_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7b06addfa3321e8276856d7fd1c5fe43_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7b40276fe2f66ef2ba3194ad2fc8ade7_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7c94bee293bddef49a33499d9df3dee3_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7cc54b3b9c25afa66e538b3b32ab12ec_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7cf532803c44a2a7ce9f00119fda5c87_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7cf5bdeafce9b9141b8959455d083c2e_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7dada6a12ce09add50b64673eace1242_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7f41ae59124bb9e6f09c1240097b6f26_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\80a0bcb8a392ffcfa266450a9a0b9c69_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\80acf129c28dee7694a9881f4ba8655c_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\80b4a6ead5c40b91ebceaf9acd2c24b7_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\80ea5e9b505200790548baa878e0dea2_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8175fd4f978a01adb2cb989198953c3a_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\81e14927df3710262552d855a69e8a07_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8223f5eaa554dde8a645d05993ed8323_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\825f5a8e25d661d87054a481a2fa5ca9_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8265e6da58339b65631b9e178cded049_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\826cbae15a80d3569feccb5f975a13b1_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\829b33b9dde392ee5210993cb52be03f_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\837e3c18d5728622e8bb2e758c749086_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\83e2dcb138280bb8f6e59e2dc6dff07e_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\847ffb422158122839f8c2f88a47274e_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\850eddc19a0e54016c660452f358d109_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8521826a5b059111b36e46e56fd27acf_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\875312d6bc875aa82aa3ca45af88a553_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8934768fc95991baeaebff636288d7f0_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8a6d5748960ee038fbe531f6abe1611e_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8bf9bf40d699c618825c9af9378b9423_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8c465805a734736cd732253a76e05038_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8c653e762c62e39c717cc746ecb91f50_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8ce52890bef775f4e96c83b537ca8941_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8cef7bfcb086970ab59aa51751392021_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8d3dd8335d741589b755bc213da46dde_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8d489aa41c7fa979f2c26ba6a189463a_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8df320c323047f8fd4ffd90bd15bf96a_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9055598f21eb25aa69e4d072276ef771_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\90561abf27c744d8c5896642a8612c94_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9057d78d3cbb2193f6714663e3db0c8f_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9150262d3c3fa4d2198bc589b7f950ac_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\91b2c405666723f945550386366dfb46_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\91bf8bade6ea293690ef7845cc3ad544_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\929d34af543b747a59fe8864fcd3ceb9_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\94b7a64fce2895cc7b414cc4b25a1bdd_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\94e86fd72778057a411bfde45e093aff_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9531e58f9a5450cac015995a74d1f92d_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\96adafcbfa440563716f62dd03d884df_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\96f92d6a18ef8aa203c0768128228e31_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\971ed59920e71b545fc56c1a0a8dd74e_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9730ae38b8fc53910abc08023f36595c_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9740fc4d5b8fa44babd2f8319fb44efe_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\977a68dcd9ce424719fd6a2afbe20ed7_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\97d0dd25626c6be37ea8615b3ad510a7_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\981a0765ac4fe31b0305ad2b2525f364_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\991b4ac1f8ab6c8ef2bb5f02de9b777d_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\99506738d5b122ec2ebbc2cfe7cfa4e0_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\996bc5f48b590c226ce6e90790dbcae2_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9a0a420cfd9eeffb3737dee74e7eb4a0_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9a3684e95ce2be63aeba12b54526dbdb_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9a9655ea2d8fdcbe9d5e853de91b4345_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9ae9c38c27ced632999f8a0f7159db9d_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9b0d073f06dca0a50c7a82342e996254_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9b19e559a4db0763e4436674b1b8f5de_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9b771cd67215254580fa1fd413c413f2_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9bf563d6eb18e625cea3b01e244c7052_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9c0a848b8d379a8551a0854d10c7b0c0_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9c839604b531836aec75ca151e62e5d3_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9cb4efd2e7590fbe5187b7572231d733_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9cd66e86331968481f3f0387512411a5_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9d0aeb9b96e41fa35af3a00d69676151_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9d11ee02bb881187b0c713d05e77cc7d_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9ebb2e9c9008b787d8a9ab2a1dbbf1d6_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9f4a0d7dec28b739135240b692af3a8a_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9f4ff398655b3d9f489bff69e54d4764_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9f7567d9672122c2f2af64ab04f93f48_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9fdbf4ac37dc12d4ead24f8bb0349e92_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9fe76cc5ec70e7f528747ddb3e830576_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a09b0f1f47cc4ff0bfc43aa337668d14_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a0fc1274ee1f1235edb702eff3550c5e_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a1260944e5d0350b6db659766487fb1f_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a18d7e9c5390f05bbea2179a655c12c6_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a2c13249b9eb21562d6db095695bed86_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a3f15a9d6943ef495258fe85846d0336_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a427141000a74d6af6550c7806b03428_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a449c6045109120403544f79ce35f452_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a5b0dafc59a803256c7396b49b6b6c68_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a5f1e2501853f48a2d6079f63c072f11_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a608910a7190b58d6def30ccd5aa3154_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a68748d390ea97f3525462fad03ccc7e_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a688c7485a6e2993ceb0ab172c2ce7b9_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a6e3cae49d4180e90ebfec7018c8e7f0_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a7184a9a6c25536bbdf057769099137c_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a7935b39cd8c84cc1bc73ebd54dae417_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a7ad8e679d0091af54d9b2f02db14f66_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a7bbb7bddab0a76dd31f0aa74bfb8c24_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a99ebce3b0dbd8be4b8b4c517c246aa0_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\aa703c2afa0cc0f057735c5d8b56ffa1_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\aa8e5b77f800990861d21a567a4ae6a0_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\aa9099c9cd53cdf88d99317c389ad9df_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ac0c1b470a87f8f4819fd8f4ce075779_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\acaf3bf8f58d60585859e8f094f10808_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ad587c60a338af7f438aa3c9b4f5af89_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ada55ab08838f92ea2ac760c831bf8cf_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\adae938be6c68a1af10f2149f0dc653d_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\aea395ee1466faf7b6aeaa3494d7c85a_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\af055dc94fec077aafd888618878229d_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b0d1c6e705e2086557f3ed22eab1ea97_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b0e6398075950c04c90f32f63e792574_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b20220bb18e689287cdfcbfc926373d2_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b2a087c5fefcb603ae82686b5d7ae2f1_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b51185b0f83b09645621ccdb1569d45b_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b51a0680c371a9fead352452ab3d5245_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b5e1f09cbcf46ebe90d179e87e326e9d_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b5f2c2c73b648d33ed6adb2762ca586c_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b66b291b181c7284c19d927ed72baed2_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b686e46c803e33b9878f4a5ef23bc8fa_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b731b0bb061ea454f5249dbd3e96e723_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b740d64311031506f1ee2fa6440cd5c9_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b7e2cf3c1ef6ef0f3a6dbbf4592c5530_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b89758a13d79ad2f97d626753e62f409_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b962e186b5c12eca9567700a1732a239_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ba3af0773bc7d8ca1369d4917f46a444_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bb710257abce1712f348edcdf6bcd6a1_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bbd0e6df8f585ff6556b1e18eb04cde5_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bcba210deee9d81a1b6bbd34c04cbf38_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bd1446585fd2d4c497227b0c4900b541_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bd869f7322e49f10bc6ac8f02d01d214_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bd951a1fff1322214f49303a4f3233ad_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bf4d6f49ce1a3d336fa4245aed56c667_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bfa5ac7b981488ffc48cf61e76e76c8a_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c0079e07ea6861cb8e38706a917ee4ca_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c00c27dcc637848b13b6089705fe868b_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c01ff1bec41839d4e015168910a91566_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c083ff542a0f1ffdb15075375dc8a344_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c1e121f1e0e2ce5213af94985e572dc5_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c1fc9b4c706c1a3596855db3cd747f1b_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c245efa59a63f10cf1a43da76b716867_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c2be146ca8c43ee04b96f47cc4554569_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c452398d1b8a0a758f3b6e037d0d5e98_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c4820bbbf5466c8b3e0961b97bf1ca6b_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c53385b303a4a664f6e50074dabfe4d5_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c56a2ee8d9b5d1756897279493c5245c_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c7c3ed1e028b5459d3eb4cf35a3bffb7_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c90f0baab66d5b26ee7aa2c7f4ebe8a7_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ca00d6beaac28e63424437130b774ef4_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cab411c4cbbad523b84c9481a1e2bbd6_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cac71aeeb17045a0aad941813de17430_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cc6379715f264c1663e5752a4cd9feb4_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ce05c0731e3cdaaf9288764e04ad8df4_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ce226e41e98fc11fb1ac05799578cef6_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ce96a45c5953ab11924615346f8649bf_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ceb6431e2073165a54a84de2cf5bbd74_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cf181822ec6d3efb5c8cc79d3d66d268_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cf4afeac1bad8167024d6f5492567924_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cff30fdbd5b18fd8898d1bce96b4e520_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d0d09d7bc87c3574c8cdcdf9ea8c6af6_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d10cea2e39001854a155f86b9aaa4be4_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d123b943ad7412fafdecfb7b7a08973d_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d13ec3660333d1b915202c3fb166f80b_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d17782feab85603f538743be72bdde7f_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d1928ff76c5bf837c38d78c3ff71b928_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d2d8239edd94cd826d3a4b9fe9a16643_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d3a5b1d94f552c86cd11baee98683fd4_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d3b81f53a54ddd68bc10bf8c0769aa46_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d3eb772744bf9ca787554c98d05bbd42_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d5199ef29fa75a92c7ed0ad11aee2ca9_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d5e8cdcb62f4221a30566155fa53c2bd_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d658f5a65e92ba96cb7c9fe61e7dfb19_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d7be16e61a803608e0855d9d67939681_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d8449d6fc9e2061a405ac628b9b99988_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d857bbf1fafa66b6592e97945bdba188_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d8663ecc6efb3ba0218ac4adc99696f5_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d95ca65526f0a350c93f371982815005_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d9a62a8651b3e1d351edfcd547e4569a_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d9e2bcd8489f5130e94f91d183202d49_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\da023980731aca0ef9d3e8bfff48f2bc_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\da94bb5b1325f9e29fc53b89c22933e1_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\daa32eb4fd314550f843049b11c0bdb1_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\daf2c403521b98486f1477d953821cb3_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\daf8f90f198856df908fee1c82fb73ee_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dc7635e8bedf4844a0c39cb1eb55b08f_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dcc7376f6b29a5d9fe78802e028d27aa_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dcc7c30165550a0127e9a19c5d90a236_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ddb5f2f164acaedce388c5843795b34a_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\de1bf1bfc18684abbfe7c50556d39e46_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dfd084bfff29ea0adbd6f9228d8e92e6_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e118670205758d92e92fe32d211411b6_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e134ad8346ab1709696173fa5105dd09_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e1ce76990969f7d6317f7dcf9475a10c_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e33e68aec527d6b918981315c43f5aca_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e35ff862634e2aafe72932a2721ac147_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e51f9d48a07bf4a1b16dba52149269b6_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e5c8e454829b4198c67e050cea56af67_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e5fe3659e3eb339033e5f73b2360decc_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e6c1bf55b034e932027b0c5f1bff7660_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e747a2fcbf428e700137f4b7d8bb6911_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e80432397c4e384d5841444a53662f08_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e857808a63a3094567375cd10df77521_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e86417564ebeaa2dc3e638c89821d7fe_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e86c0de6fb95b70758745e669a95929d_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e8e3d623b5533fc8f1304c7a16f423e2_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e8e43a734e565d593527abb9bf40682b_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e9a0371319d1af8a3424ede6f61a349b_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e9b5bbc16f464b61d7b2223160cb9096_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ebbff4513e5723d9cb25db8c3dd0c6bb_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ec654b44707375ef76b22ef468b3ee6d_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ed7b031497ce52239408676c8764532a_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\eedc2b1a2cfe75a73fd449f12004107a_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ef1f9dfca59afb1a2625f6ca16825161_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ef63667fad3695e08456b9726fd50a12_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f2b2a34586a98c98087399cfb40959e7_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f2b722bc0f6a96e2e7365cc080d9ac2f_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f2bcf5aa6caa49c74b83f2868db3737d_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f400219863604cc25b253ee55fd16362_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f40d348c7b85a80c11d89f587f015601_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f4686448af5397146b14255a84d22eff_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f4d110bd19b2126dcd3c61078d1457dc_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f54085f4b660de001308013dd55cf329_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f57278ed4fa8a849d0744eabcc0a607c_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f6021215d02357eb3bef900df6f1fd36_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f653c452e434259acb1e173fed7d26b6_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f6606a937cc97247058043aa459d3466_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f6e43dfacdcafe8294863c1b74a4c24d_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f73d109c638f6190dcdcfa3550debcf7_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f8914b8123b639ad22551fb7b890bafe_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f8baa0e07585fb8a126830ef9674e089_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f8da95e2d97938aa46e73d2a0c84f0d1_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f9799dba8e0f7bc9f371510cca8c66ac_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f9c1619160d3a9ace216f7aa1baf2212_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fa441a8af6d16aee20513bc74d8d1a3e_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\faa2c64bddc41c513d802d0685c5b1d2_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fab27e78a1c69abeecc4e6a2ba1d7305_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fac7b2ef8fcc31cfe1e01e4c60b8b5dc_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fb179c6a274ddea9db3288ebe5e7d2dc_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fb269eb57e2d786082473f33a636ef8d_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fc5673e3219670378262a4266ea6af8e_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fc659279164be89cb10f8b3ea18dfd31_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fd3840496d7fcbf051d347834751558b_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ffd52da15ff44fcd8a57380254a0f909_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fff715528c5cddd733df7c5eadcab7ed_85a0d38b-dae4-4520-b295-c31fb3678210 Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Thalia\Local Settings\Temporary Internet Files\Content.IE5\IJKL456P\mww_setup[1].exe/data0007 Infected: not-a-virus:FraudTool.Win32.MalwareWipe.q skipped
C:\Documents and Settings\Thalia\Local Settings\Temporary Internet Files\Content.IE5\IJKL456P\mww_setup[1].exe NSIS: infected - 1 skipped
C:\Documents and Settings\Thalia\Local Settings\Temporary Internet Files\Content.IE5\IX7ST8VQ\send_car_int[1].htm Infected: Exploit.HTML.CodeBaseExec skipped
C:\Documents and Settings\Willem\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\AppLogs\SUPERANTISPYWARE-4-5-2008( 13-50-17 ).LOG Object is locked skipped
C:\Documents and Settings\Willem\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Willem\Desktop\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Willem\Desktop\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Willem\Desktop\SmitfraudFix.exe RarSFX: infected - 2 skipped
C:\Documents and Settings\Willem\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Willem\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Willem\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Willem\Local Settings\History\History.IE5\MSHist012008040520080406\index.dat Object is locked skipped
C:\Documents and Settings\Willem\Local Settings\Temp\Perflib_Perfdata_7d4.dat Object is locked skipped
C:\Documents and Settings\Willem\Local Settings\Temp\~DF1166.tmp Object is locked skipped
C:\Documents and Settings\Willem\Local Settings\Temp\~DFCC74.tmp Object is locked skipped
C:\Documents and Settings\Willem\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Willem\Local Settings\Temporary Internet Files\Content.IE5\KLQNOBQV\securitypills[1].htm Infected: not-virus:Hoax.HTML.Secureinvites.a skipped
C:\Documents and Settings\Willem\Local Settings\Temporary Internet Files\Content.IE5\KLQNOBQV\securitypills[2].htm Infected: not-virus:Hoax.HTML.Secureinvites.a skipped
C:\Documents and Settings\Willem\My Documents\mp3 to cd\freeripmp3.exe/file40 Infected: not-a-virus:AdTool.Win32.MyWebSearch.br skipped
C:\Documents and Settings\Willem\My Documents\mp3 to cd\freeripmp3.exe Inno: infected - 1 skipped
C:\Documents and Settings\Willem\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Willem\NTUSER.DAT.LOG Object is locked skipped
C:\Program Files\MalwareWar 7.3\MalwareWar 7.3.exe Infected: not-a-virus:FraudTool.Win32.MalwareWipe.q skipped
C:\Program Files\MSN Messenger\riched20.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\Program Files\MyWebSearch\bar\1.bin\F3CJPEG.DLL Infected: not-a-virus:AdWare.Win32.FunWeb.d skipped
C:\Program Files\MyWebSearch\bar\1.bin\F3HISTSW.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\Program Files\MyWebSearch\bar\1.bin\F3PSSAVR.SCR Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\Program Files\MyWebSearch\bar\1.bin\F3RESTUB.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\Program Files\MyWebSearch\bar\1.bin\F3SCRCTR.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.l skipped
C:\Program Files\MyWebSearch\bar\1.bin\F3WPHOOK.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bh skipped
C:\Program Files\MyWebSearch\bar\1.bin\M3OUTLCN.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\Program Files\National Instruments\MAX\Data\config3.mxd Object is locked skipped
C:\Program Files\National Instruments\MAX\Data\config3.mxs Object is locked skipped
C:\RECYCLER\NPROTECT\00000245 Object is locked skipped
C:\RECYCLER\NPROTECT\00000246 Object is locked skipped
C:\RECYCLER\NPROTECT\00000493 Object is locked skipped
C:\RECYCLER\NPROTECT\00000494 Object is locked skipped
C:\RECYCLER\NPROTECT\00000565 Object is locked skipped
C:\RECYCLER\NPROTECT\00000566 Object is locked skipped
C:\RECYCLER\NPROTECT\00000639 Object is locked skipped
C:\RECYCLER\NPROTECT\00000640 Object is locked skipped
C:\RECYCLER\NPROTECT\00000895 Object is locked skipped
C:\RECYCLER\NPROTECT\00000896 Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{C4E0C875-AD2B-4F6C-97E6-1490228598DC}\RP963\A0213233.dll Object is locked skipped
C:\System Volume Information\_restore{C4E0C875-AD2B-4F6C-97E6-1490228598DC}\RP963\A0213299.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{C4E0C875-AD2B-4F6C-97E6-1490228598DC}\RP965\A0213639.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\System Volume Information\_restore{C4E0C875-AD2B-4F6C-97E6-1490228598DC}\RP968\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\f3PSSavr.scr Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
E:\download old2\Downloads old\NEW (D)\INTERNET DL OLD\Internet downloads\marinefree.exe/WISE0030.BIN/data0001.cab/Save.exe Infected: not-a-virus:AdWare.Win32.SaveNow.ae skipped
E:\download old2\Downloads old\NEW (D)\INTERNET DL OLD\Internet downloads\marinefree.exe/WISE0030.BIN/data0001.cab/SaveUninst.exe Infected: not-a-virus:AdWare.Win32.SaveNow.af skipped
E:\download old2\Downloads old\NEW (D)\INTERNET DL OLD\Internet downloads\marinefree.exe/WISE0030.BIN/data0001.cab Infected: not-a-virus:AdWare.Win32.SaveNow.af skipped
E:\download old2\Downloads old\NEW (D)\INTERNET DL OLD\Internet downloads\marinefree.exe/WISE0030.BIN/data0002.cab/Uninst.exe Infected: not-a-virus:AdWare.Win32.SaveNow.v skipped
E:\download old2\Downloads old\NEW (D)\INTERNET DL OLD\Internet downloads\marinefree.exe/WISE0030.BIN/data0002.cab Infected: not-a-virus:AdWare.Win32.SaveNow.v skipped
E:\download old2\Downloads old\NEW (D)\INTERNET DL OLD\Internet downloads\marinefree.exe/WISE0030.BIN Infected: not-a-virus:AdWare.Win32.SaveNow.v skipped
E:\download old2\Downloads old\NEW (D)\INTERNET DL OLD\Internet downloads\marinefree.exe/WISE0031.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
E:\download old2\Downloads old\NEW (D)\INTERNET DL OLD\Internet downloads\marinefree.exe WiseSFX: infected - 7 skipped
E:\download old2\Downloads old\NEW (D)\INTERNET DL OLD\Internet downloads\Morpheus30.exe/WISE0013.BIN/WISE0012.BIN Infected: not-a-virus:AdWare.Win32.WurldMedia.c skipped
E:\download old2\Downloads old\NEW (D)\INTERNET DL OLD\Internet downloads\Morpheus30.exe/WISE0013.BIN/WISE0014.BIN Infected: not-a-virus:AdWare.Win32.WurldMedia.b skipped
E:\download old2\Downloads old\NEW (D)\INTERNET DL OLD\Internet downloads\Morpheus30.exe/WISE0013.BIN Infected: not-a-virus:AdWare.Win32.WurldMedia.b skipped
E:\download old2\Downloads old\NEW (D)\INTERNET DL OLD\Internet downloads\Morpheus30.exe/WISE0014.BIN Infected: not-a-virus:AdWare.Win32.MyWay.o skipped
E:\download old2\Downloads old\NEW (D)\INTERNET DL OLD\Internet downloads\Morpheus30.exe WiseSFX: infected - 4 skipped
E:\download old2\Downloads old\NEW (D)\marinefree.exe/WISE0084.BIN/data0001.cab/VVSN.exe Infected: not-a-virus:AdWare.Win32.SaveNow.z skipped
E:\download old2\Downloads old\NEW (D)\marinefree.exe/WISE0084.BIN/data0001.cab Infected: not-a-virus:AdWare.Win32.SaveNow.z skipped
E:\download old2\Downloads old\NEW (D)\marinefree.exe/WISE0084.BIN Infected: not-a-virus:AdWare.Win32.SaveNow.z skipped
E:\download old2\Downloads old\NEW (D)\marinefree.exe/WISE0087.BIN/data0001.cab/VVSN.exe Infected: not-a-virus:AdWare.Win32.SaveNow.z skipped
E:\download old2\Downloads old\NEW (D)\marinefree.exe/WISE0087.BIN/data0001.cab Infected: not-a-virus:AdWare.Win32.SaveNow.z skipped
E:\download old2\Downloads old\NEW (D)\marinefree.exe/WISE0087.BIN Infected: not-a-virus:AdWare.Win32.SaveNow.z skipped
E:\download old2\Downloads old\NEW (D)\marinefree.exe/WISE0088.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
E:\download old2\Downloads old\NEW (D)\marinefree.exe/WISE0089.BIN/data.rar/WhAgent.exe Infected: not-a-virus:AdWare.Win32.WebHancer skipped
E:\download old2\Downloads old\NEW (D)\marinefree.exe/WISE0089.BIN/data.rar/whInstaller.exe Infected: not-a-virus:AdWare.Win32.WebHancer skipped
E:\download old2\Downloads old\NEW (D)\marinefree.exe/WISE0089.BIN/data.rar/WhSurvey.exe Infected: not-a-virus:AdWare.Win32.WebHancer skipped
E:\download old2\Downloads old\NEW (D)\marinefree.exe/WISE0089.BIN/data.rar/Webhdll.dll Infected: not-a-virus:AdWare.Win32.WebHancer skipped
E:\download old2\Downloads old\NEW (D)\marinefree.exe/WISE0089.BIN/data.rar/whiehlpr.dll Infected: not-a-virus:AdWare.Win32.WebHancer skipped
E:\download old2\Downloads old\NEW (D)\marinefree.exe/WISE0089.BIN/data.rar Infected: not-a-virus:AdWare.Win32.WebHancer skipped
E:\download old2\Downloads old\NEW (D)\marinefree.exe/WISE0089.BIN Infected: not-a-virus:AdWare.Win32.WebHancer skipped
E:\download old2\Downloads old\NEW (D)\marinefree.exe/WISE0090.BIN Infected: not-a-virus:Server-Proxy.Win32.MarketScore.h skipped
E:\download old2\Downloads old\NEW (D)\marinefree.exe/WISE0091.BIN Infected: not-a-virus:Server-Proxy.Win32.MarketScore.i skipped
E:\download old2\Downloads old\NEW (D)\marinefree.exe WiseSFX: infected - 16 skipped
E:\download old2\Downloads old\NEW (D)\marinefree.exe WiseSFXDropper: infected - 16 skipped
E:\download old2\My Download Files\frogbender.exe/data0001/regwebh.dll Infected: not-a-virus:AdWare.Win32.WebHancer.16 skipped
E:\download old2\My Download Files\frogbender.exe/data0001/wbhshare.dll Infected: not-a-virus:AdWare.Win32.WebHancer.16 skipped
E:\download old2\My Download Files\frogbender.exe/data0001/webhdll.dll Infected: not-a-virus:AdWare.Win32.WebHancer.16 skipped
E:\download old2\My Download Files\frogbender.exe/data0001/whAgent.exe Infected: not-a-virus:AdWare.Win32.WebHancer.16 skipped
E:\download old2\My Download Files\frogbender.exe/data0001/whiedc.dll Infected: not-a-virus:AdWare.Win32.WebHancer.16 skipped
E:\download old2\My Download Files\frogbender.exe/data0001/whiehlpr.dll Infected: not-a-virus:AdWare.Win32.WebHancer.16 skipped
E:\download old2\My Download Files\frogbender.exe/data0001/whieshm.dll Infected: not-a-virus:AdWare.Win32.WebHancer.16 skipped
E:\download old2\My Download Files\frogbender.exe/data0001/whInstaller.exe Infected: not-a-virus:AdWare.Win32.WebHancer.16 skipped
E:\download old2\My Download Files\frogbender.exe/data0001 Infected: not-a-virus:AdWare.Win32.WebHancer.16 skipped
E:\download old2\My Download Files\frogbender.exe Inno: infected - 9 skipped
E:\Downloads may 2006\Downloads Jan 2006\blubstersetup250.exe/WISE0012.BIN Infected: not-a-virus:AdWare.Win32.MyWay.ac skipped
E:\Downloads may 2006\Downloads Jan 2006\blubstersetup250.exe/WISE0013.BIN/data0142 Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
E:\Downloads may 2006\Downloads Jan 2006\blubstersetup250.exe/WISE0013.BIN Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
E:\Downloads may 2006\Downloads Jan 2006\blubstersetup250.exe/WISE0014.BIN/data.rar/WhAgent.exe Infected: not-a-virus:AdWare.Win32.WebHancer skipped
E:\Downloads may 2006\Downloads Jan 2006\blubstersetup250.exe/WISE0014.BIN/data.rar/whInstaller.exe Infected: not-a-virus:AdWare.Win32.WebHancer skipped
E:\Downloads may 2006\Downloads Jan 2006\blubstersetup250.exe/WISE0014.BIN/data.rar/WhSurvey.exe Infected: not-a-virus:AdWare.Win32.WebHancer skipped
E:\Downloads may 2006\Downloads Jan 2006\blubstersetup250.exe/WISE0014.BIN/data.rar/Webhdll.dll Infected: not-a-virus:AdWare.Win32.WebHancer skipped
E:\Downloads may 2006\Downloads Jan 2006\blubstersetup250.exe/WISE0014.BIN/data.rar/whiehlpr.dll Infected: not-a-virus:AdWare.Win32.WebHancer skipped
E:\Downloads may 2006\Downloads Jan 2006\blubstersetup250.exe/WISE0014.BIN/data.rar Infected: not-a-virus:AdWare.Win32.WebHancer skipped
E:\Downloads may 2006\Downloads Jan 2006\blubstersetup250.exe/WISE0014.BIN Infected: not-a-virus:AdWare.Win32.WebHancer skipped
E:\Downloads may 2006\Downloads Jan 2006\blubstersetup250.exe/WISE0015.BIN/cd_clint.dll Infected: not-a-virus:AdWare.Win32.Cydoor skipped
E:\Downloads may 2006\Downloads Jan 2006\blubstersetup250.exe/WISE0015.BIN/cd_htm.dll Infected: not-a-virus:AdWare.Win32.Cydoor skipped
E:\Downloads may 2006\Downloads Jan 2006\blubstersetup250.exe/WISE0015.BIN Infected: not-a-virus:AdWare.Win32.Cydoor skipped
E:\Downloads may 2006\Downloads Jan 2006\blubstersetup250.exe WiseSFX: infected - 13 skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

Scan process completed.
bluefalcon888
Active Member
 
Posts: 14
Joined: March 27th, 2008, 10:49 pm

Re: Please help

Unread postby Shaba » April 5th, 2008, 4:47 am

Hi

Uninstall via add/remove programs:

MyWebSearch or similar

Open HijackThis, click do a system scan only and checkmark these:

O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.h ... xdm119YYNZ


Close all windows including browser and press fix checked.

Reboot.

Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    Code: Select all
    C:\Documents and Settings\Thalia\Local Settings\Temporary Internet Files\Content.IE5\IJKL456P\mww_setup[1].exe 
    C:\Documents and Settings\Thalia\Local Settings\Temporary Internet Files\Content.IE5\IX7ST8VQ\send_car_int[1].htm 
    C:\Documents and Settings\Willem\Local Settings\Temporary Internet Files\Content.IE5\KLQNOBQV\securitypills[1].htm 
    C:\Documents and Settings\Willem\Local Settings\Temporary Internet Files\Content.IE5\KLQNOBQV\securitypills[2].htm 
    C:\Documents and Settings\Willem\My Documents\mp3 to cd\freeripmp3.exe
    C:\Documents and Settings\Willem\My Documents\mp3 to cd\freeripmp3.exe 
    C:\Program Files\MalwareWar 7.3
    C:\Program Files\MSN Messenger
    C:\Program Files\MyWebSearch
    C:\WINDOWS\system32\f3PSSavr.scr 
    E:\download old2\Downloads old\NEW (D)\INTERNET DL OLD\Internet downloads\marinefree.exe
    E:\download old2\Downloads old\NEW (D)\INTERNET DL OLD\Internet downloads\Morpheus30.exe
    E:\download old2\Downloads old\NEW (D)\marinefree.exe
    E:\download old2\My Download Files\frogbender.exe
    E:\Downloads may 2006\Downloads Jan 2006\blubstersetup250.exe
    

  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the light blue bar) and choose Paste.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt2
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post along with a fresh HijackThis log.
User avatar
Shaba
Admin/Teacher Emeritus
 
Posts: 26974
Joined: March 24th, 2006, 4:42 am
Location: Finland

Re: Please help

Unread postby bluefalcon888 » April 7th, 2008, 4:19 pm

Hi MRU

Have you received my reply to your last post?

Regards
Bluefalcon888
bluefalcon888
Active Member
 
Posts: 14
Joined: March 27th, 2008, 10:49 pm
Advertisement
Register to Remove

Next

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 205 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware