Tech Support Forum banner
Status
Not open for further replies.

review logs of Virtumonde/Vundo infection

895 views 11 replies 1 participant last post by  fabbu  
#1 ·
Hi all,

My McAfee detected a Vtutu.dll trojan virus. McAfee's pop up advised that Vtutu is detected but cannot be removed.

I tried other alternatives to removes the virus (VundoFix 6.7.0.7, SpybotSD 1.3.012, FYI TeaTimer was disabled and Ad-Aware SE 6.2.0.206) SB found virtumonde but after every restart I receive a windows pop up indicating that c:windows/system32/vtutu.dll cannot be found. After checking in the system32 folder the vtutu.dll file is still present, to confirm that I have a virus I ran VundoFix one more time to removed the files, and after the restart it goes into a loop again, I see the windows pop up indicating Vtutu.dll cannot be found.

I decided to follow your tread: Users Self Help Malware Removal Guide, under: Virtumonde/Vundo Removal Instructions.

I will post the contents of C:\vundofix.txt and a set of logs from Deckard's System Scanner. I will also includ a HJT file

Thanks
 
#2 ·
VundoFix V6.7.7

Checking Java version...

Java version is 1.5.0.10

Scan started at 1:17:43 PM 19/01/2008

Listing files found while scanning....

C:\WINDOWS\system32\ututv.ini
C:\WINDOWS\system32\ututv.ini2
C:\WINDOWS\system32\vtutu.dll

Beginning removal...

Attempting to delete C:\WINDOWS\system32\ututv.ini
C:\WINDOWS\system32\ututv.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\ututv.ini2
C:\WINDOWS\system32\ututv.ini2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\vtutu.dll
C:\WINDOWS\system32\vtutu.dll Has been deleted!

Performing Repairs to the registry.
Done!
 
#3 ·
Deckard's System Scanner v20071014.68
Run by POUCHI on 2008-01-19 13:51:57
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

System Restore is disabled; attempting to re-enable...success.


-- Last 1 Restore Point(s) --
1: 2008-01-19 18:52:12 UTC - RP1 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.

Total Physical Memory: 511 MiB (512 MiB recommended).


-- HijackThis Clone ------------------------------------------------------------


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-01-19 13:56:05
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\Program Files\McAfee\MSC\mcmscsvc.exe
C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
C:\Program Files\McAfee\VirusScan\mcods.exe
C:\Program Files\McAfee\MSC\mcpromgr.exe
C:\Program Files\Common Files\McAfee\RedirSvc\RedirSvc.exe
C:\Program Files\McAfee\VirusScan\Mcshield.exe
C:\Program Files\McAfee\VirusScan\mcsysmon.exe
C:\Program Files\McAfee\MPF\MpfSrv.exe
C:\Program Files\SiteAdvisor\6253\SAService.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Documents and Settings\POUCHI\Desktop\dss.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Windows Defender\MSASCui .exe
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2 .exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
F0 - win.ini: load=C:\WINDOWS\system32\vtutu.exe
F3 - REG:win.ini: Load=C:\WINDOWS\system32\userinit.exe,
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O2 - BHO: (no name) - {22E53967-D04B-4109-B305-C48FBBAED0C8} - C:\WINDOWS\system32\vtutu.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptcl.dll
O2 - BHO: {23239637-2ee3-c89b-ef04-9dcff5a2c46d} - {d64c2a5f-fcd9-40fe-b98c-3ee273693232} - C:\WINDOWS\system32\jvdxtssw.dll (file missing)
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [CapFax] C:\Program Files\Classic PhoneTools\CapFax.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -onlytray
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SoundMax] "C:\Program Files\Analog Devices\SoundMAX\SMax4.exe" /tray
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EA Downloader\Core.exe" -silent
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Startup: Motorola Phone Tools.lnk = ?
O4 - Global Startup: InterVideo WinCinema Manager.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Panda ActiveScan - {653D93AF-C741-4e5e-8C1B-59BA43F93E16} - http://www.pandasoftware.com/activescan (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O18 - Protocol: lid - {5C135180-9973-46D9-ABF4-148267CBB8BF} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.0.0812.00.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.0.0812.00.dll
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O20 - Winlogon Notify: khfgebx - C:\WINDOWS\system32\khfgebx.dll (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\EmProxy\emproxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\Program Files\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\Program Files\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\RedirSvc\RedirSvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\Mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MpfSrv.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6253\SAService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe


--
End of file - 8752 bytes

-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R2 EIO - c:\windows\system32\drivers\eio.sys <Not Verified; ASUSTeK Computer Inc.; ASUS Kernel Mode Driver for NT>
R3 SAA7146n (TT DVB-PCI driver (SAA7146n)) - c:\windows\system32\drivers\saa7146n.sys <Not Verified; TechnoTrend AG; TT-DVBsat PCI>
R3 TTLOOPHE (Virtual DVB-S/-C/-T Network Adapter Driver) - c:\windows\system32\drivers\ttloophe.sys <Not Verified; TechnoTrend AG; TT-DVB PCI cards>
R3 usbsermpt (Motorola USB Modem Driver for MPT) - c:\windows\system32\drivers\usbsermpt.sys <Not Verified; Microsoft Corporation; Microsoft(R) Windows (R) 2000 Operating System>

S3 giveio - c:\windows\system32\giveio.sys
S3 mohfilt - c:\windows\system32\drivers\mohfilt.sys <Not Verified; Intel Corporation; Creatix V.9X data fax modem>


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

All services whitelisted.


-- Device Manager: Disabled ----------------------------------------------------

No disabled devices found.


-- Scheduled Tasks -------------------------------------------------------------

2008-01-19 13:48:22 330 --ah----- C:\WINDOWS\Tasks\MP Scheduled Scan.job
2008-01-15 02:40:50 352 --a------ C:\WINDOWS\Tasks\McDefragTask.job
2007-12-01 01:00:06 354 --a------ C:\WINDOWS\Tasks\McQcTask.job


-- Files created between 2007-12-19 and 2008-01-19 -----------------------------

2008-01-19 13:52:02 391 --ahs---- C:\WINDOWS\system32\ututv.ini2
2008-01-19 13:51:55 344576 --a------ C:\WINDOWS\system32\vtutu.dll
2008-01-17 20:59:39 0 d-------- C:\WINDOWS\system32\ActiveScan
2008-01-12 16:09:54 0 d-------- C:\VundoFix Backups
2008-01-12 16:09:39 132608 --a------ C:\Program Files\VundoFix.exe <Not Verified; Atribune.org; VundoFix>
2008-01-07 19:28:39 0 d-------- C:\Documents and Settings\Administrator\Application Data\Mozilla
2008-01-07 19:00:57 0 dr------- C:\Documents and Settings\Administrator\Favorites
2008-01-07 19:00:55 0 dr-h----- C:\Documents and Settings\Administrator\Recent
2008-01-07 19:00:55 0 d-------- C:\Documents and Settings\Administrator\Desktop
2008-01-07 19:00:11 0 d-------- C:\Documents and Settings\Administrator\Application Data
2008-01-07 19:00:11 0 d-------- C:\Documents and Settings\Administrator\Application Data\Microsoft
2008-01-07 19:00:05 0 d--h----- C:\Documents and Settings\Administrator\Templates
2008-01-07 19:00:04 0 d-------- C:\Documents and Settings\Administrator\Start Menu
2008-01-07 19:00:01 524288 --ah----- C:\Documents and Settings\Administrator\ntuser.dat
2008-01-07 19:00:01 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
2008-01-07 19:00:01 0 d--hs---- C:\Documents and Settings\Administrator\Cookies
2008-01-04 21:33:36 0 d-------- C:\Program Files\ProcessExplorer
2007-12-30 10:13:55 0 dr-h----- C:\Documents and Settings\POUCHI\Application Data\SecuROM
2007-12-27 20:23:50 0 d-------- C:\Program Files\RitzDVB


-- Find3M Report ---------------------------------------------------------------

2008-01-19 13:52:11 0 d-------- C:\Program Files\Windows Defender
2008-01-19 13:42:05 0 d-------- C:\Documents and Settings\POUCHI\Application Data\SiteAdvisor
2008-01-19 12:51:10 0 d-------- C:\Program Files\Java
2008-01-18 01:37:10 0 d-------- C:\Program Files\McAfee
2008-01-12 13:49:26 276 --a------ C:\Program Files\FixVundo.log
2008-01-12 01:19:27 0 d-------- C:\Program Files\SiteAdvisor
2008-01-09 06:26:55 0 d-------- C:\Program Files\Classic PhoneTools
2008-01-04 21:31:21 1613990 --a------ C:\Program Files\ProcessExplorer.zip
2007-12-30 11:17:57 0 d-------- C:\Program Files\EA SPORTS
2007-12-28 09:31:21 0 d-------- C:\Program Files\RitzDVB (2)


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{22E53967-D04B-4109-B305-C48FBBAED0C8}]
19/01/2008 01:51 PM 344576 --a------ C:\WINDOWS\system32\vtutu.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d64c2a5f-fcd9-40fe-b98c-3ee273693232}]
C:\WINDOWS\system32\jvdxtssw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" []
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" []
"CapFax"="C:\Program Files\Classic PhoneTools\CapFax.EXE" []
"PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.exe" []
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [19/01/2008 11:21 AM]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6253\SiteAdv.exe" []
"KernelFaultCheck"="C:\WINDOWS\system32\dumprep 0 -k" []
"SoundMax"="C:\Program Files\Analog Devices\SoundMAX\SMax4.exe" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe" []

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EA Core"="C:\Program Files\Electronic Arts\EA Downloader\Core.exe" []
"PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [19/01/2008 11:21 AM]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t

C:\Documents and Settings\POUCHI\Start Menu\Programs\Startup\
Motorola Phone Tools.lnk - C:\Program Files\Motorola Phone Tools\mPhonetools.exe [18/08/2007 12:04:34 PM]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [29/12/2005 12:51:39 AM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\khfgebx]
khfgebx.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\vtutu

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Usnsvc usnsvc


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
AutoRun\command- F:\Autorun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ffcb1cbe-77e9-11da-b4fe-806d6172696f}]
AutoRun\command- F:\Autorun.exe




-- End of Deckard's System Scanner: finished at 2008-01-19 13:57:09 ------------
 

Attachments

#4 ·
Logfile of HijackThis v1.99.1
Scan saved at 2:09:08 PM, on 19/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\SiteAdvisor\6253\SAService.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Windows Defender\MSASCui .exe
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2 .exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
F3 - REG:win.ini: load=C:\WINDOWS\system32\vtutu.exe
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [CapFax] C:\Program Files\Classic PhoneTools\CapFax.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -onlytray
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SoundMax] "C:\Program Files\Analog Devices\SoundMAX\SMax4.exe" /tray
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EA Downloader\Core.exe" -silent
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - Startup: Motorola Phone Tools.lnk = C:\Program Files\Motorola Phone Tools\mPhonetools.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Panda ActiveScan - {653D93AF-C741-4e5e-8C1B-59BA43F93E16} - http://www.pandasoftware.com/activescan (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6253\SAService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
 
#6 ·
Hi all,

I performed:The 5 Steps before Posting a Log

STEP 1 : was checked, ok
STEP 2 : Running a online scan (pandasoftware) was unsuccessful, I reach at where it indicates to "Select a device to scan...", when trying to select My Computer, nothing happens..., but on the left bottom I see a triangle with a exclamation mark with "Error on paged"
STEP 3 : downloaded both programs mentioned with ZonedOut.
STEP 4 : I Update your Operating System, XP
STEP 5 : I read Preparing to Post your Log.

At this point I restarted windows, to give the PC a fresh start but I still got the pop up. Attached : Pop_up.Bmp


I follow once again the tread: Users Self Help Malware Removal Guide, under: Virtumonde/Vundo Removal Instructions.

I will post the contents of C:\vundofix.txt and a set of logs from Deckard's System Scanner. I will also include a HJT file

Thanks
 

Attachments

#7 ·
After performing steps 1 to 5, I rebooted the PC, I ran Spybot Sd, nothing was found , I could not run AdAware it would freeze, ran VundoFix nothing was found, here are the logs VundoFix.txt


VundoFix V6.7.7

Checking Java version...

Java version is 1.5.0.10

Scan started at 1:17:43 PM 19/01/2008

Listing files found while scanning....

C:\WINDOWS\system32\ututv.ini
C:\WINDOWS\system32\ututv.ini2
C:\WINDOWS\system32\vtutu.dll

Beginning removal...

Attempting to delete C:\WINDOWS\system32\ututv.ini
C:\WINDOWS\system32\ututv.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\ututv.ini2
C:\WINDOWS\system32\ututv.ini2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\vtutu.dll
C:\WINDOWS\system32\vtutu.dll Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.7.7

Checking Java version...

Java version is 1.5.0.10

Scan started at 10:49:34 PM 19/01/2008

Listing files found while scanning....

C:\WINDOWS\system32\ututv.ini
C:\WINDOWS\system32\ututv.ini2
C:\WINDOWS\system32\vtutu.dll

Beginning removal...

Attempting to delete C:\WINDOWS\system32\ututv.ini
C:\WINDOWS\system32\ututv.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\ututv.ini2
C:\WINDOWS\system32\ututv.ini2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\vtutu.dll
C:\WINDOWS\system32\vtutu.dll Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal...

VundoFix V6.7.7

Checking Java version...

Java version is 1.5.0.10

Scan started at 1:41:13 AM 20/01/2008

Listing files found while scanning....

No infected files were found.


Beginning removal...

VundoFix V6.7.7

Checking Java version...

Java version is 1.5.0.10

Scan started at 7:31:06 AM 20/01/2008

Listing files found while scanning....

No infected files were found.


Beginning removal...
 
#8 ·
next it was requested to run DSS, I see the main.txt but cannot find the extra.txt file, I checked in the folder that was created for DSS, Deckard and System scan, in it there was only main.txt , I got an extra.txt file when I first ran DSS. I don't understand ??? here the main.txt

Deckard's System Scanner v20071014.68
Run by POUCHI on 2008-01-20 12:12:48
Computer is in Normal Mode.
--------------------------------------------------------------------------------

Total Physical Memory: 511 MiB (512 MiB recommended).


-- HijackThis (run as POUCHI.exe) ----------------------------------------------

Unable to find log (file not found); running clone.
-- HijackThis Clone ------------------------------------------------------------


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-01-20 12:13:50
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\Program Files\McAfee\MSC\mcmscsvc.exe
C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
C:\Program Files\McAfee\VirusScan\mcods.exe
C:\Program Files\McAfee\MSC\mcpromgr.exe
C:\Program Files\Common Files\McAfee\RedirSvc\RedirSvc.exe
C:\Program Files\McAfee\VirusScan\Mcshield.exe
C:\Program Files\McAfee\VirusScan\mcsysmon.exe
C:\Program Files\McAfee\MPF\MpfSrv.exe
C:\Program Files\SiteAdvisor\6253\SAService.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\McAfee\MSC\mcupdmgr.exe
C:\Documents and Settings\POUCHI\Desktop\dss.exe
C:\Program Files\HijackThis\POUCHI.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptcl.dll
O2 - BHO: {23239637-2ee3-c89b-ef04-9dcff5a2c46d} - {d64c2a5f-fcd9-40fe-b98c-3ee273693232} - C:\WINDOWS\system32\jvdxtssw.dll (file missing)
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [CapFax] C:\Program Files\Classic PhoneTools\CapFax.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -onlytray
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
O4 - HKLM\..\Run: [SoundMax] "C:\Program Files\Analog Devices\SoundMAX\SMax4.exe" /tray
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EA Downloader\Core.exe" -silent
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Startup: Motorola Phone Tools.lnk = ?
O4 - Global Startup: InterVideo WinCinema Manager.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Panda ActiveScan - {653D93AF-C741-4e5e-8C1B-59BA43F93E16} - http://www.pandasoftware.com/activescan (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/win...soft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1200797860062
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O18 - Protocol: lid - {5C135180-9973-46D9-ABF4-148267CBB8BF} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.0.0812.00.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.0.0812.00.dll
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O20 - Winlogon Notify: khfgebx - C:\WINDOWS\system32\khfgebx.dll (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\EmProxy\emproxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\Program Files\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\Program Files\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\RedirSvc\RedirSvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\Mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MpfSrv.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6253\SAService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe


--
End of file - 8143 bytes

-- Files created between 2007-12-20 and 2008-01-20 -----------------------------

2008-01-19 23:37:06 24576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe <Not Verified; Atribune.org; Vundofix Service>
2008-01-19 20:06:57 0 d-------- C:\Program Files\ZonedOut
2008-01-19 19:19:12 118784 --a------ C:\WINDOWS\system32\MSSTDFMT.DLL <Not Verified; Microsoft Corporation; MSSTDFMT Object Library>
2008-01-19 19:19:10 0 d-------- C:\Program Files\SpywareBlaster
2008-01-17 20:59:39 0 d-------- C:\WINDOWS\system32\ActiveScan
2008-01-12 16:09:54 0 d-------- C:\VundoFix Backups
2008-01-12 16:09:39 132608 --a------ C:\Program Files\VundoFix.exe <Not Verified; Atribune.org; VundoFix>
2008-01-07 19:28:39 0 d-------- C:\Documents and Settings\Administrator\Application Data\Mozilla
2008-01-07 19:00:57 0 dr------- C:\Documents and Settings\Administrator\Favorites
2008-01-07 19:00:55 0 dr-h----- C:\Documents and Settings\Administrator\Recent
2008-01-07 19:00:55 0 d-------- C:\Documents and Settings\Administrator\Desktop
2008-01-07 19:00:11 0 d-------- C:\Documents and Settings\Administrator\Application Data
2008-01-07 19:00:11 0 d-------- C:\Documents and Settings\Administrator\Application Data\Microsoft
2008-01-07 19:00:05 0 d--h----- C:\Documents and Settings\Administrator\Templates
2008-01-07 19:00:04 0 d-------- C:\Documents and Settings\Administrator\Start Menu
2008-01-07 19:00:01 524288 --ah----- C:\Documents and Settings\Administrator\ntuser.dat
2008-01-07 19:00:01 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
2008-01-07 19:00:01 0 d--hs---- C:\Documents and Settings\Administrator\Cookies
2008-01-04 21:33:36 0 d-------- C:\Program Files\ProcessExplorer
2007-12-30 10:13:55 0 dr-h----- C:\Documents and Settings\POUCHI\Application Data\SecuROM
2007-12-27 20:23:50 0 d-------- C:\Program Files\RitzDVB


-- Find3M Report ---------------------------------------------------------------

2008-01-20 06:26:18 0 d-------- C:\Program Files\Windows Defender
2008-01-20 00:06:48 0 d-------- C:\Documents and Settings\POUCHI\Application Data\SiteAdvisor
2008-01-19 20:12:15 0 d-------- C:\Program Files\RitzDVB (2)
2008-01-19 20:02:42 240904 --a------ C:\Program Files\ZonedOut.zip
2008-01-19 12:51:10 0 d-------- C:\Program Files\Java
2008-01-18 01:37:10 0 d-------- C:\Program Files\McAfee
2008-01-12 13:49:26 276 --a------ C:\Program Files\FixVundo.log
2008-01-12 01:19:27 0 d-------- C:\Program Files\SiteAdvisor
2008-01-09 06:26:55 0 d-------- C:\Program Files\Classic PhoneTools
2008-01-04 21:31:21 1613990 --a------ C:\Program Files\ProcessExplorer.zip
2007-12-30 11:17:57 0 d-------- C:\Program Files\EA SPORTS


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d64c2a5f-fcd9-40fe-b98c-3ee273693232}]
C:\WINDOWS\system32\jvdxtssw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" []
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" []
"CapFax"="C:\Program Files\Classic PhoneTools\CapFax.EXE" []
"PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.exe" []
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" []
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6253\SiteAdv.exe" []
"SoundMax"="C:\Program Files\Analog Devices\SoundMAX\SMax4.exe" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe" []

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EA Core"="C:\Program Files\Electronic Arts\EA Downloader\Core.exe" []
"PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" []

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t

C:\Documents and Settings\POUCHI\Start Menu\Programs\Startup\
Motorola Phone Tools.lnk - C:\Program Files\Motorola Phone Tools\mPhonetools.exe [18/08/2007 12:04:34 PM]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [29/12/2005 12:51:39 AM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\khfgebx]
khfgebx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Usnsvc usnsvc


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
AutoRun\command- F:\Autorun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ffcb1cbe-77e9-11da-b4fe-806d6172696f}]
AutoRun\command- F:\Autorun.exe




-- End of Deckard's System Scanner: finished at 2008-01-20 12:15:25 ------------
 
#9 ·
here the HTJ:

Logfile of HijackThis v1.99.1
Scan saved at 12:19:36 PM, on 20/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\SiteAdvisor\6253\SAService.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
C:\PROGRA~1\HIJACK~1\POUCHI.exe
C:\WINDOWS\notepad.exe
C:\WINDOWS\system32\NOTEPAD.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: {23239637-2ee3-c89b-ef04-9dcff5a2c46d} - {d64c2a5f-fcd9-40fe-b98c-3ee273693232} - C:\WINDOWS\system32\jvdxtssw.dll (file missing)
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [CapFax] C:\Program Files\Classic PhoneTools\CapFax.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -onlytray
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
O4 - HKLM\..\Run: [SoundMax] "C:\Program Files\Analog Devices\SoundMAX\SMax4.exe" /tray
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EA Downloader\Core.exe" -silent
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - Startup: Motorola Phone Tools.lnk = C:\Program Files\Motorola Phone Tools\mPhonetools.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Panda ActiveScan - {653D93AF-C741-4e5e-8C1B-59BA43F93E16} - http://www.pandasoftware.com/activescan (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/win...soft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1200797860062
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O20 - Winlogon Notify: khfgebx - khfgebx.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6253\SAService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
 
#10 ·
I managed to perform a online scan with Kaspersky, here are the results,


-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Sunday, January 20, 2008 4:28:09 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 20/01/2008
Kaspersky Anti-Virus database records: 525024
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
F:\

Scan Statistics:
Total number of scanned objects: 85711
Number of viruses found: 2
Number of infected objects: 57
Number of suspicious objects: 0
Duration of the scan process: 00:56:55

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\McAfee\MNA\NAData Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MPF\data\log.edb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MPF\data\logout.edb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MPF\data\tempIpRules.xdb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\Events.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\{9D13E68C-6F8C-4C6F-8F85-84045E306B45}.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\{D327EDAC-021F-44CD-9444-72F547029F73}.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\McUsers.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Data\TFR1.tmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Logs\OAS.Log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0040f6cdae9d37ed2bb3eb844530c029_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0063ecd3930eb2ff0a7f5a0f0039ae83_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\015688fca3521202858878b10a567b43_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0183cf1621c8e930ef038393fa990546_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\01a4cf0da6dfcf78a153de59c66d3929_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\022607a1edce71835a9f8a2925f673fd_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0245e4b05e3293e5a2926a1c6b7640a8_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\02e599b865a93f290140de301df24cc9_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\03f65e5196dd84ef9dea5e0e4f412df0_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\044b150d349194d050b917e182870b5e_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\045a86dff8d686f97c2b49f1005098ee_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\04a84daecf715c84e25375778590b907_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0710edf56dc2d568448f7ab96808d895_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\092dd4812c17c74edd7aae551563ccf9_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\096037d9d2e6fea7c1ef062fbc48e178_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0a93831a5ef467033d03b10dd316e998_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0af04509691e34838bdca241867a0b0b_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0b0384fb9dd743052c722e27e9c9abdb_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0be96e6cf99a46b071a8fdda92ebacf7_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0c661883e2be7b9104278895d04b3a38_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0de903e83de24908073d046bc2e4753d_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0e01d642ff63ad9857faf2b272b97635_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0e129f38ace3976af420ae65ae4540b4_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0e12b93658f1c00d2f2d51bd77d83450_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0f6986c74ef8cebab0627c36453c0cd1_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0fb31982eec2f24c8e7ac4569d3a8033_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\10b0530b593f622278d77004930bdc2b_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\11b746fb2aca45bd0988fba2ff71106d_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1347a954acc1581c522e879f8a84295e_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\134f364ef8f4f70db7fc62594ab1f343_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\143e9784f346db4f4d43f1e5860ffdd8_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\15558d7d56abd0f9fa1211a75d1917c0_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\15f8d0e77bef0beb4d0f2ed01549d8ea_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\162a0296ba32d7a7f6183bfe0d9645eb_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\16eb49c8f76178e8320e060ce23735ce_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\17465fa8d2fb9981488491d40098e4c6_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\175e5f17464634d4574c4d0f3e07640c_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\18ba7beb029203d5710fe77541725827_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\198301a0c2548aefaa97f90f66c73cd4_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1a69f24dfa8318cc2007d7f6a002fea9_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1c485a309ed2b44d06c5fff4bd1522ed_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1f9048097f090b672c04293c407068d5_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\20787df31cd7ae1bfe09b65aa7f1645d_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\20dfc8c4ed9bfb51a6258a964b643063_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\20f4ffc7f138d7b86d95eee2c497ec03_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2197b2fe613b98a19683e25998a9dc62_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\238817bcb70e7f077cddd9ab511eee13_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\275d05b7ac08689338a31d6bf3dd9110_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2900d2e7e8020734183621e8e83b9160_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2a0c56d01ca68c4d803d7038fd2d8bcc_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2a3b05c4194a1bbf268d4ae04a716760_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2ac59ec18a82caa2cac738e80fa51af1_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2c4b1c0b5bfd8c7d593dd113d723381a_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2d2572e091ce1427af49ce522b0e644e_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2db9d12d8f05765179de0261ce4f6c36_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2f02c2a58aa54701e8ecb3fbf7f49a96_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2f52c3b0521b66cadaa07db5ec6af967_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\30d78ffe66534b8a78c79beab275c713_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\31983b8c81499887ea1719c60bc00e6a_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3276229835fefe1abe65ea5fceeebc82_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\328d672ace4e1e1840546786cd8fb25e_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3390c57f65f43f79eedf4bbd8d3d2e70_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\33c5c4cfe8630c5235e36fe2c234c5ba_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3513dd738131f32f9bd48005e31b30ca_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\364618e3b06c432bc82f4ce21da759ae_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\380ea0813b95c9d6cd6ed58fd44f6a78_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\38cfaa235880035f4611b4d8882dca5b_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\39249aa65370f1ccce7c04550f992e0a_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3990344348bb7db06ab01517b6d700ab_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\39abb81009b5facfd7c443adc57b1b1e_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3b5325b979f2736219dfb31b23fcbab0_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3ea494e2680c5106f68d4d0ff6291df2_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3f7f8aadf34746ad2fedaae83ecfd212_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\40f7e2c3dbdd4816a2f5aea076918c9e_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\414f8fabe525ed9bc557dd14d17a8dda_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\418a298a456116ca025c8bb934c78bd8_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\41ea1d9424f56cca4d58c5b68fe2d247_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\42dcfdf65c0b06168590466505f81a20_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\43cab2b94fcc68baaa48acfd39ff0410_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4471459e2ac1465c867965a370fe713d_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\44bf5444bf387b11b605597406c9d25f_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\45e8ee3fe7de1137e7d53dcb6a7abc46_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\45fba8cc8eb9c9e6ec1b1f718498549d_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\476d2bdbfb1a1cef414ca1377b4e6561_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\47ba96a6e816d2c1c142ae458efaee39_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\48498c865a37c355f0da1523046efb2b_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\487483f512ab773666f20db2814eeb69_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\487727588c568f6caf04e3154eb9c3c6_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4983e6d66b94acfdf647c23c55740944_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4a9a4ce42aa1bcfeca1af6294b91dcbc_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4b7863ec615af8b37f75c3e6b15378ab_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4c49a69a750634ac81a0aadc76638ff9_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4c68c194c65b20a5fb0fb872aff8c27c_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4c9c95e746eea575f016beed59439558_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4cdf1858095a47396462f33c9a2af29d_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4d95eb5a4213e55b1c20447fe767d2d6_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4e64b1225514ce1a2dd8b8344900906d_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4e82b2a017d751764f5cb96809e22f3f_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4eea66334d16d7ab1089f0e96311085a_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\502db573c873dd348b1b3e697688413a_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\504d4823fb6c58f8cdb533059099a7f3_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\50922264842f18777c4f0d4913038358_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\50cfdc6b6be60130c235749d2abd87b3_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\50db215009497aa907f0c0ac848b576d_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\51ab85088d49718dd5ff94aee75a312a_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\52217682ead1319fb42c24d5de735209_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\53df68b22e871eb61c257da6951055ee_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\53f3fb27e51d35f86b11a8acab3529f9_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\56212e8205865b043d993bbabf10e60d_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\562c939ce25465a7bb3b6d3c8f646d26_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5783124af8da1e549e77738479930fa7_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\58e8697dd3f9dc51d527e0d60830e294_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\599a852631105f9cb4059a3090d346e4_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\59a3584ab1acd67210aa0c99b6851256_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5a054a647848888df200b25874d620de_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5a10908d7cb6b9bc721684156358de7c_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5bf97577ead4388c3f78cb8fc7d1ce83_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5cf7cce29ab04953343c90131c3f8891_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5d7381878a89858584a6dd2f85c1ee13_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5da445d368779742252fdb9d6677c264_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5f06943d86c70730e6705cce455584c2_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5f1228ab73f88049877f74a80f8979af_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5f3a1fb0e5c95c0bd4326b576f715c8a_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5fb20fa688fdcecdafe58353a57e6e1f_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5fccb557e1d788b264270e6a8e5cb5f2_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6059cbac5617bababb33e6f7095e3888_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\60df159b29708ba207e30859ec922a16_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\612b017e1ba31e64f92bc9442dcb773e_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\63dcf29b27eb587a15889d492ba796ed_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\63f27782e756e60e6c7f0ce6490b8990_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\655ac319d5a2765969e887f87c36aca5_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\666503bb2e6069be80324b7048e00172_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\676049232defe7b935039e7e32d45222_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\681f54873a241f4775b11b0b2f92e7a0_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6861b54ebe265b5db1499133a67affcb_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\692e1b1ae66b51da35d5ef2fd382e395_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6aa099535cdfecb1c64c11dec31ab5fa_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6aa57f0b84f141db3f0b1342494fcb60_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6ba395225a662c4b59925100118c6442_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6bf67b3ce99afb24452367cd1671f3a5_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6cb5896490f71faee7f50620246abf1f_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6d8452da6cfb7bb30a9d33d6de14b776_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6e19c63472674b8fac9a6201505ab592_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6ec4d53a924dfe8ffcf38a4162cdaad8_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6efaecaf3cabdfb91d585fcd2502afbd_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6f63de5f46501da0251aa7720b51b287_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6fcd18f660aa2bdc3c85adef37aeda3f_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6ffeada821bcd206af2f043199a75292_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\70653012cdaa93744f66e95780314c84_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\711b1fdbd8af1450a3ad0edbb42e3b50_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\71814d06a7942fca49a961d731aa18fb_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\730d43339559226ef83e757dd0113666_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\745ee96c18cdb45381ed7bb11d0bec91_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\74797c8acd11441349c613cf6008a6c9_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\74f91d63bba5be2ef42d811cab535de9_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\75be314af232709dd766b18bd8780767_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\785d10c2e5a901ff8badce6a29c48613_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\795c1813784400089c97358d034c858d_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7a08adf5bfa09021253fc146885ceb00_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7bac60173a6f34c9b53c66b161b6dff1_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7cf4de9a251fe3c29c096cbc99ce9c29_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7d2de36df81e158d1b02a8c3d6c5d3ae_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7d421dfe39039c0e01cded626aba1c48_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7dedec3d3568e7445ca37e4aa2b182ed_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7eb1b7402ead2f2bab2fef977953a99b_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7f50bd596477f3f1a277c8ecdd164f61_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7f6483b808915e74a289ac6424dcdf32_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8049190cd81a830cd6640513ca62e83c_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\809b277df44e1e5a4375f00745538224_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\81d4cad18e97f0021d6ebfefe8724cbd_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8286ba2d034ef0e62f950424c7bbb918_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\83d1d45225d8c984e4f1f9408df31f52_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\842cd820b7504510463218c30e189ba9_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8493b86e405cffa8d07656597ee8c85c_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\849756d24ec28889d823f6bacace9010_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\84c56735a04b4b7de50725540b93f700_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\84fa3c53b49000afd099d8b63eb0a5ac_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\856f055d3b895e3ea5c73bbcaa6d2f22_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\85c402acb6283f0d9093f107bd54701a_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8660261959eae09cf93271b7a39ef540_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8693bda0ca8482833e57b8b2ebf98f2e_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\872d04517310017e9051188c09746f5b_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8734bf93a3db4f5ae97ade3d715c6b81_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\886657f1f117a0dd8d310e1869f42100_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\88b226f8f31c839f0b340e4192c5731d_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\89234abbaa128a8d48a92e0d1070ef55_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\89ab32c76f5d09de2de87c0693874b01_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8a9309e597b2a0679f8d4d21c1cff605_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8ac4850754a43c87cf58a49ba8df6f5f_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8affefdd0729f0f6332cb817e89e566d_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8be7ae0249a26bfdea951c4e6b872d16_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8c95b2210832177a608889ceefef78e0_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8d416802845f1632c7a01f73a88f08ba_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8e7d0529ca32d5c7a1c560c31e2cd200_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8e7e70406318da449c6ed7d953a49290_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8f38d644c07f0fcc21d6d236080c79e8_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8fc2ce09790ae258e10d6a937fd91a6d_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\93f68549e94abcf33f3879a45efa2cf3_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\94143fbd0e81b68124b68a5d2860ddc7_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\960ab095b09f8546ec03a70a4f7bd5ed_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9655d75119e725af16e4d462a02f80f1_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\96bf32abee148ca93f111c1731bebd47_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9720341cef969f2c440d785e735fdd83_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9747d051a9f796e1e3bbc62a6dd01844_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\983ff43f3b9ab12f36655d18020bebbb_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\986963737760560c980fc400b7a7b8c0_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\98a23dab775f5544c94bc32ebea3b186_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\98be74bb3b1db336ae46cd139326538c_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\98caf370bef1a13023eebb13fb226cd5_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\990870bbe37813059d3171fff33e5394_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\99b5c9b71562a6f9b96c6e2c7607baaf_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\99fe8d805022163ced6007ecb222f925_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9a6851b2c800c50f841d44a2f56defef_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9aa9b5f651d561036b5e4d087ef3c869_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9ada07e55d36982b2bd1078cb1a988cd_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9b95d8a0c1911db604293979613e17f0_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9c6c4c490a5fcee9d39d9f460d7bbfcc_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9c75845ed453d29ed8b288cbd522e583_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9cc050a26239bf755b1e4caa928d151c_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9d86bf2e13896fed259d33ef20554ca7_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9d8f9fdd6d3eb7ef5422adeb3f275ac2_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9df178dab7d8b1d2d87b2793d95940b8_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9e370642c0e8e42421c985bee2aa44cd_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9ebbbbc2a2f6ae78124e244d25c903d8_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9fbec597696aee06f34d18e7ffac3fe9_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9ffa9321558f9e7a459b92f900923c6e_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a0dfe05e5137ad2a978a02ef5a1c1657_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a1beec3cd09087df1d2fe360a2125b5b_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a1d75c73b790dec2fde99fdb530f7e38_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a23539a77d8598251e59bea392c76f1a_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a374d420365502c04df007923f6fe017_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a4eac1c749a73857b9168b012340115b_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a4ed06c741a53670327f65cff227c105_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a6a7905664a8cacbaece5d6468398583_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a6fb1d22dfb171250eefc059bba0279d_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a75b34e8d4bf9757d03d6af23062ecc9_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a785019eac8b3ab1de122bfce28f8536_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a83a7a276b5a6b564d743b13b3e4107a_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a95879b157766a99b10866be1dda7995_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ac4fdf86924708f903378a88cf515844_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ac5c3b96071dd94f6c86dc16fd7700d0_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ae219bf456e522f41afab365460da9ba_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ae226578e03c4182f24b6c658b21cd33_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ae97b76d0c6dc1b28235247cce360aac_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b0bb43896be724b1c4344436bcd2371b_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b11b809e086e078b620721acdf5b60f1_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b12f671df0ce66299b324dbe881a08a4_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b1a3fa90e48e1ba52bbba90d1e2a5eba_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b1dd1e0a5d85c05aa29c4273263181fb_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b216405b8294c8c30061ea56e3387c53_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b3924b64213b67a1d93af34d8b7dae68_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b546a0758aee5891e8891a0f3855fe0f_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b65e6145e88ce2af49554b5be6ace450_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b70820a2d611846655d103f671dfabb7_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b720668c0ffeb7dd73e8354882bc2e9d_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b86a98d28d7701abb6e3d525a0083af2_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b90d3ab16e680386b3757f8f0ae2d9a4_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b9300eeb67727c6dc04447e12187ef15_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b933639547179eef67320fae2d88a7bf_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ba7e627017da1d49e369cdf025e67155_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ba8858060cf59d32c9b1e80099e4efec_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bc2ad4f6a0d32f9884d27f45ad7510ee_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bc705ad6a2f4e80b13cee577b19f7345_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bcbab8932ac53aa742ef5a9fcc937c11_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bdbb613f01570ecd4e7daa8da378dde0_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bdd8557a2f8bac6963f865df8becae9f_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bdff7477e2f1d3e091e706ae7eb529bf_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bea056b3bccef320fb5dc4fe7f21e9f2_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c06dc501b14ac85f6a052a9e787716b9_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c0bb762b3c2f3a9a5a14f70aef8599e2_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c1b3c94a3ce239dfe8efbf6386cc6ff4_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c1d7a36417f85680fbf2bab51db41ffa_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c37610b3f1fe20ab0326038f347b84f5_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c3d1b34efb217e9499f0788de1584f83_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c44eff08c5c5bb558000dea67dddb309_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c4b37e1ab32b3325444a8c9707a4bddb_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c547843d94675e142c4b7987d46319bf_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c659fa69d807df055d061472cd24cf0d_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c6a737fde6d5647332e81c93602021b4_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c7519f4b8c6383271be61af075c9d2cf_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c7be49531126304aa880801e1b82b16d_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c7f590cb7ccb8ffea22d1517b9fc7135_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c80249b39d5a7b49e8a39519a7945c3b_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c8cd90d34cc84ab01ea91b2fbaf2730f_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ca9b062a03d5f0962fbb7419b2077af6_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cc7d8dd172e041d6fde905173b35a9ff_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cc84b4a3622399829fbc78660632455d_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cd1d1eb337cdcfc1ce7296faf7cf5845_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cdafcd6ed89ae59289710fb850c2c17d_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ce512323557c2f928ca8567db4973c88_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d00e9a9db83a985d3114365f01dc5fd7_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d1352883c3b61deb1e370d28bdc37238_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d1cf47f1e2d4b33003a2410aa2a3cc29_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d53013c53cbc74f91565a4ab6f8a7fac_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d58b498eef454ec0422728540796a968_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d6d0e0601ee70d60691cdfc080dbe4f0_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d88984e9e3201c0afca0b5ebcdd41a67_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d9df7f6c38a6675d264e595b3754b3b1_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\da91b9e45ceb25b2373f1647121829d8_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\da95e567902f2f0c91d74fe0f74478a6_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\daa72c3bf27680c75778b360aad154e4_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dca6fe6e975f72098988836624ca92c2_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dd9822a4f3377f95f682211c8e5ce518_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ddc751ad569e2fb626ac4fe27228242e_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ddd0763b610d2afc191f913755315dd1_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\de4a9d87d3a1e27cabec1b83ee11e40d_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\de4d6f538370e28dc0a81718d1ce19ff_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\df1a7e6838d3539f7806e324b7fc78dd_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\df1f285b4df98fc3ef3e45f1c3a7cbfc_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e09837b64f62806b26e9d7f11f19ba32_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e1103bdb9b37d5eb345870d5ec204911_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e2eeeaed1a1073da2682d5f544ce25c0_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e309ed9e3cec0fea75a7f10810f84a43_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e3ade316921d5f5d1df67aeb1042bde0_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e3e953b20ba66259580f72472173ab45_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e449c440d15657eafbeb8fdc6e316da0_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e4a980b1e43cfda5a6eb8524be0f09ce_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e61a9d3da929b21dccc5e88cd06c092a_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e63c5cb07cd96c20c3d85a6837eaaea8_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e6b04a7af02a68c80acfa63d7c00f9be_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e6b99f90601322409ed866198ca8f81c_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e6d8ff732f365e2d8f6fdae6682cacd3_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e7a8c535586ff7a73f879619430dd34f_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e7e96ec4bc1fa6762dbc517099648316_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e82d34971596b293c1c9a8a8b9202530_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e88b2420b76d19ec3aac55ab8f2a1c73_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e88bceff7afecc3863e5ca08c11bbe25_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e8c18f13a823364a734a199106c14e01_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e92eb4bd66146e818f48512ba597984f_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e9caf07edf3b0cfe6e5cea2efccfecdb_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ea0c13fdf92813bf56b8068cc4083310_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ea1fcd004835d965c4aa98be13955ccf_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ea254ed0e1c8ef0e9689e3e7a8f14f2b_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ea31243e34b6f9e7e31801165725d5c4_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ea43ad1d4e6c6ea986cb11d087b9e731_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ea5febb79f0f40704942c8d4bd070b31_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\eaa9ea11af12ff1f399b97633dbbe152_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\eaeebc025ed37dd794c3a81b45bfd52f_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\eba4d9410838652f950d3983998b51bb_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ec5d115b6693423bcaebe9f169fe9d7e_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ec83c83188f228ab8d2b41b30f0974cf_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ed4fd335d0e8e657f84175872ee11bb1_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\edf18d083931b171ae6bebe122cd0848_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ee97da1df31e42fd304769372be8ae56_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f003fc84b607782a03b1d266bcc95a83_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f0f8c300204d2b078ee03c9fe031a871_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f2def6ac81f30f76aeda7cd455e62b83_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f383582cb949fa90964372413eb3d6e8_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f3c2cf92fb06eab277e1349b634721fd_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f3c45e659b36deca616bddcae5c592af_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f3ef27e5f9529ab84413dd56ec415a8e_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f537c5d14b6d9a56965983d890081e00_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f63a9ebee90c7a2727ceb1c5bc9e6eff_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f7319648395a068dff0955828792a3d2_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f74c973e4c22fef36de095d0df5051d8_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f758e59f1ea94ccb6fea552b4e053a7c_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f7813b818ffb3f4b50029634e857f8fb_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f78a5037c9c351bce8db35bc35e37a36_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f857da1118e5a2f0c2963e77cdb05003_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f93fe98b44277fd82a72041480b0fdc1_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fb38d89690c184dbcd3e4e2ff062f60a_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fbd50a2d8a6b93091b56e010faeb3db2_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fc182054378b702c424a6b239f8dbc0a_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fc242e8ac5737d51fbdf2028454e5897_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fc292ba130a7e051cdefb58ba4a75fbd_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fc70ec4bc4beec9eab93aafd83a1f053_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fc7aa526fcd748d9bd813602b0fcff27_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fcf1fafa0669c6a4bcf8a5054e0b6516_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fd0cd4991862bb3c7594c6773c36b38d_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fd3239e1c2dab86e6eedc4ec7585dd48_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fe27821c35e596a5ed9d0c6d7c0890b6_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\feacf0365612c9ff4f890ff996048e7e_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\febaa81343efe2e57f64dace9f3b91a4_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fed8af1c50f4eb67fefe6dff5dca5ea7_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\feec7beb98a20378a7318ab0f7b71df0_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ff7b910e1a69dbfded9cf8b9f86da85d_803ab22f-8287-47c6-b2d7-ad61d1ebd876 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-12102006-003830.log Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\POUCHI\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\POUCHI\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\POUCHI\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\POUCHI\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\POUCHI\Local Settings\Temp\~DF5F75.tmp Object is locked skipped
C:\Documents and Settings\POUCHI\Local Settings\Temp\~DFAB39.tmp Object is locked skipped
C:\Documents and Settings\POUCHI\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\POUCHI\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\POUCHI\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\POUCHI\ntuser.dat.LOG Object is locked skipped
C:\QooBox\Quarantine\C\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\Windows Defender\MSASCui.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\vtutu.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.dih skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\vtutu.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\RECYCLER\S-1-5-21-1659004503-1645522239-725345543-1004\Dc2\backup\DOCUME~1\POUCHI\LOCALS~1\Temp\RCX10.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\RECYCLER\S-1-5-21-1659004503-1645522239-725345543-1004\Dc2\backup\DOCUME~1\POUCHI\LOCALS~1\Temp\RCX11.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\RECYCLER\S-1-5-21-1659004503-1645522239-725345543-1004\Dc2\backup\DOCUME~1\POUCHI\LOCALS~1\Temp\RCX12.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\RECYCLER\S-1-5-21-1659004503-1645522239-725345543-1004\Dc2\backup\DOCUME~1\POUCHI\LOCALS~1\Temp\RCX13.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\RECYCLER\S-1-5-21-1659004503-1645522239-725345543-1004\Dc2\backup\DOCUME~1\POUCHI\LOCALS~1\Temp\RCX13B4.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\RECYCLER\S-1-5-21-1659004503-1645522239-725345543-1004\Dc2\backup\DOCUME~1\POUCHI\LOCALS~1\Temp\RCX13B7.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\RECYCLER\S-1-5-21-1659004503-1645522239-725345543-1004\Dc2\backup\DOCUME~1\POUCHI\LOCALS~1\Temp\RCX14.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\RECYCLER\S-1-5-21-1659004503-1645522239-725345543-1004\Dc2\backup\DOCUME~1\POUCHI\LOCALS~1\Temp\RCX15.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\RECYCLER\S-1-5-21-1659004503-1645522239-725345543-1004\Dc2\backup\DOCUME~1\POUCHI\LOCALS~1\Temp\RCX16.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\RECYCLER\S-1-5-21-1659004503-1645522239-725345543-1004\Dc2\backup\DOCUME~1\POUCHI\LOCALS~1\Temp\RCX1A.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\RECYCLER\S-1-5-21-1659004503-1645522239-725345543-1004\Dc2\backup\DOCUME~1\POUCHI\LOCALS~1\Temp\RCX1D.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\RECYCLER\S-1-5-21-1659004503-1645522239-725345543-1004\Dc2\backup\DOCUME~1\POUCHI\LOCALS~1\Temp\RCX27.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\RECYCLER\S-1-5-21-1659004503-1645522239-725345543-1004\Dc2\backup\DOCUME~1\POUCHI\LOCALS~1\Temp\RCX2A.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\RECYCLER\S-1-5-21-1659004503-1645522239-725345543-1004\Dc2\backup\DOCUME~1\POUCHI\LOCALS~1\Temp\RCX2D.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\RECYCLER\S-1-5-21-1659004503-1645522239-725345543-1004\Dc2\backup\DOCUME~1\POUCHI\LOCALS~1\Temp\RCX31.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\RECYCLER\S-1-5-21-1659004503-1645522239-725345543-1004\Dc2\backup\DOCUME~1\POUCHI\LOCALS~1\Temp\RCX33.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\RECYCLER\S-1-5-21-1659004503-1645522239-725345543-1004\Dc2\backup\DOCUME~1\POUCHI\LOCALS~1\Temp\RCX45.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\RECYCLER\S-1-5-21-1659004503-1645522239-725345543-1004\Dc2\backup\DOCUME~1\POUCHI\LOCALS~1\Temp\RCX5.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\RECYCLER\S-1-5-21-1659004503-1645522239-725345543-1004\Dc2\backup\DOCUME~1\POUCHI\LOCALS~1\Temp\RCX51.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\RECYCLER\S-1-5-21-1659004503-1645522239-725345543-1004\Dc2\backup\DOCUME~1\POUCHI\LOCALS~1\Temp\RCX6.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\RECYCLER\S-1-5-21-1659004503-1645522239-725345543-1004\Dc2\backup\DOCUME~1\POUCHI\LOCALS~1\Temp\RCX63.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\RECYCLER\S-1-5-21-1659004503-1645522239-725345543-1004\Dc2\backup\DOCUME~1\POUCHI\LOCALS~1\Temp\RCX6F.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\RECYCLER\S-1-5-21-1659004503-1645522239-725345543-1004\Dc2\backup\DOCUME~1\POUCHI\LOCALS~1\Temp\RCX7.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\RECYCLER\S-1-5-21-1659004503-1645522239-725345543-1004\Dc2\backup\DOCUME~1\POUCHI\LOCALS~1\Temp\RCX7F.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\RECYCLER\S-1-5-21-1659004503-1645522239-725345543-1004\Dc2\backup\DOCUME~1\POUCHI\LOCALS~1\Temp\RCX8.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\RECYCLER\S-1-5-21-1659004503-1645522239-725345543-1004\Dc2\backup\DOCUME~1\POUCHI\LOCALS~1\Temp\RCX80.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\RECYCLER\S-1-5-21-1659004503-1645522239-725345543-1004\Dc2\backup\DOCUME~1\POUCHI\LOCALS~1\Temp\RCX81.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\RECYCLER\S-1-5-21-1659004503-1645522239-725345543-1004\Dc2\backup\DOCUME~1\POUCHI\LOCALS~1\Temp\RCX83.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\RECYCLER\S-1-5-21-1659004503-1645522239-725345543-1004\Dc2\backup\DOCUME~1\POUCHI\LOCALS~1\Temp\RCX8D.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\RECYCLER\S-1-5-21-1659004503-1645522239-725345543-1004\Dc2\backup\DOCUME~1\POUCHI\LOCALS~1\Temp\RCX9.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\RECYCLER\S-1-5-21-1659004503-1645522239-725345543-1004\Dc2\backup\DOCUME~1\POUCHI\LOCALS~1\Temp\RCX92.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\RECYCLER\S-1-5-21-1659004503-1645522239-725345543-1004\Dc2\backup\DOCUME~1\POUCHI\LOCALS~1\Temp\RCXA.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\RECYCLER\S-1-5-21-1659004503-1645522239-725345543-1004\Dc2\backup\DOCUME~1\POUCHI\LOCALS~1\Temp\RCXAB.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\RECYCLER\S-1-5-21-1659004503-1645522239-725345543-1004\Dc2\backup\DOCUME~1\POUCHI\LOCALS~1\Temp\RCXBC.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\RECYCLER\S-1-5-21-1659004503-1645522239-725345543-1004\Dc2\backup\DOCUME~1\POUCHI\LOCALS~1\Temp\RCXC1.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\RECYCLER\S-1-5-21-1659004503-1645522239-725345543-1004\Dc2\backup\DOCUME~1\POUCHI\LOCALS~1\Temp\RCXEA1.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\RECYCLER\S-1-5-21-1659004503-1645522239-725345543-1004\Dc2\backup\DOCUME~1\POUCHI\LOCALS~1\Temp\RCXEC1.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{9CE4383C-6DE3-476B-B2CA-E1F24A9A2990}\RP1\A0000001.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{9CE4383C-6DE3-476B-B2CA-E1F24A9A2990}\RP1\A0000025.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{9CE4383C-6DE3-476B-B2CA-E1F24A9A2990}\RP2\A0000034.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{9CE4383C-6DE3-476B-B2CA-E1F24A9A2990}\RP2\A0000035.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{9CE4383C-6DE3-476B-B2CA-E1F24A9A2990}\RP2\A0000040.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{9CE4383C-6DE3-476B-B2CA-E1F24A9A2990}\RP2\A0000041.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{9CE4383C-6DE3-476B-B2CA-E1F24A9A2990}\RP2\A0000054.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.dih skipped
C:\System Volume Information\_restore{9CE4383C-6DE3-476B-B2CA-E1F24A9A2990}\RP2\A0000075.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{9CE4383C-6DE3-476B-B2CA-E1F24A9A2990}\RP2\A0000076.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{9CE4383C-6DE3-476B-B2CA-E1F24A9A2990}\RP3\A0000079.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{9CE4383C-6DE3-476B-B2CA-E1F24A9A2990}\RP3\A0000080.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{9CE4383C-6DE3-476B-B2CA-E1F24A9A2990}\RP4\A0000083.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{9CE4383C-6DE3-476B-B2CA-E1F24A9A2990}\RP4\A0000084.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.dih skipped
C:\System Volume Information\_restore{9CE4383C-6DE3-476B-B2CA-E1F24A9A2990}\RP4\A0000087.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{9CE4383C-6DE3-476B-B2CA-E1F24A9A2990}\RP4\A0000088.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{9CE4383C-6DE3-476B-B2CA-E1F24A9A2990}\RP5\change.log Object is locked skipped
C:\VundoFix Backups\vtutu.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.dih skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\ModemLog_Motorola USB Modem #2.txt Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{F94DDDDC-C076-408E-B5CA-B3A909BCA282}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\mcafee_bwdBChb3b0uokLH Object is locked skipped
C:\WINDOWS\Temp\mcafee_fuFkt6MU7gygb5j Object is locked skipped
C:\WINDOWS\Temp\mcafee_XVR0E4RRaFlccu7 Object is locked skipped
C:\WINDOWS\Temp\mcmsc_1zmBD3IDvmDKVHv Object is locked skipped
C:\WINDOWS\Temp\mcmsc_7JhSD4CTliP0O8b Object is locked skipped
C:\WINDOWS\Temp\mcmsc_chx9Sw9lpsox5ml Object is locked skipped
C:\WINDOWS\Temp\mcmsc_gg54CNUpOvCAZOw Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

Scan process completed.
 
#11 ·
here is hjt:

Logfile of HijackThis v1.99.1
Scan saved at 4:41:51 PM, on 20/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\SiteAdvisor\6253\SAService.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Motorola Phone Tools\mPhonetools.exe
c:\program files\mcafee\msc\mcuimgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: {23239637-2ee3-c89b-ef04-9dcff5a2c46d} - {d64c2a5f-fcd9-40fe-b98c-3ee273693232} - C:\WINDOWS\system32\jvdxtssw.dll (file missing)
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [CapFax] C:\Program Files\Classic PhoneTools\CapFax.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -onlytray
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
O4 - HKLM\..\Run: [SoundMax] "C:\Program Files\Analog Devices\SoundMAX\SMax4.exe" /tray
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EA Downloader\Core.exe" -silent
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Panda ActiveScan - {653D93AF-C741-4e5e-8C1B-59BA43F93E16} - http://www.pandasoftware.com/activescan (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/win...soft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1200797860062
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{61D1EE99-7F63-4B30-901C-A1196CF77FE1}: NameServer = 207.181.101.4 207.181.101.5
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O20 - Winlogon Notify: khfgebx - khfgebx.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6253\SAService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
 
#12 ·
Since I performed the 5 step required, my PC seems to run better and no more pop ups that would indicating it cannot locate a specific .dll file. I can assume that the vundo virus is no longer infecting my PC.

But what I would like is if a specialist tech can overlook my log's and symptoms, and analyze if anything else need to be looked at and corrected.


I am ready to provide you almost any report you need.

Please advise,

Thanks
 
Status
Not open for further replies.
You have insufficient privileges to reply here.