kohu Posted October 3, 2007 Report Share Posted October 3, 2007 (edited) My problems, Popups and my desktop dissapearing on me. Also sometimes a new window will popup whenI'm browsing the internet and open a lot of tabs. Also AVG is picking up a thing called downloader.tinyid or something that I can't seem to get rid off. Not fun... Heres the logEdit: Just wanted to say I love that you guys do this! Saved my life before so here I am Logfile of HijackThis v1.99.1Scan saved at 6:24:53 PM, on 10/2/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16512)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exec:\Program Files\Common Files\Symantec Shared\ccSetMgr.exec:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exeC:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exec:\Program Files\Common Files\Symantec Shared\ccProxy.exeC:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exec:\Program Files\Norton AntiVirus\navapsvc.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\M-Audio Uno\UnoInst.exeC:\Program Files\Viewpoint\Common\ViewpointService.exeC:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exeC:\WINDOWS\system32\lxcrcoms.exeC:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\iPod\bin\iPodService.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\system32\wscntfy.exeC:\Program Files\Java\jre1.6.0_02\bin\jusched.exeC:\windows\system\hpsysdrv.exeC:\Program Files\HP\hpcoretech\hpcmpmgr.exeC:\WINDOWS\System32\hphmon05.exeC:\WINDOWS\system32\VTTimer.exeC:\Program Files\Common Files\Symantec Shared\ccApp.exeC:\WINDOWS\AGRSMMSG.exeC:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exeC:\Program Files\HP\HP Software Update\HPWuSchd2.exeC:\HP\KBD\KBD.EXEC:\Program Files\Lexmark 2400 Series\lxcrmon.exeC:\Program Files\Lexmark 2400 Series\ezprint.exeC:\Program Files\iTunes\iTunesHelper.exeC:\windows\system32\lrdsrngo.exeC:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exeC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\WINDOWS\Cyb2k.exeC:\Program Files\Messenger\msmsgs.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exeC:\Program Files\HP\Digital Imaging\bin\hpqtra08.exeC:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXEC:\Program Files\WiFiConnector\NintendoWFCReg.exeC:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exeC:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exeC:\Program Files\Internet Explorer\iexplore.exeC:\WINDOWS\explorer.exeC:\Documents and Settings\Pete's\My Documents\highjackthis\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktopR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhostO3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dllO3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dllO3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dllO3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dllO3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - c:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dllO4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exeO4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exeO4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exeO4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXEO4 - HKLM\..\Run: [VTTimer] VTTimer.exeO4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"O4 - HKLM\..\Run: [updateManager] "c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /rO4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exeO4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exeO4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exeO4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exeO4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXEO4 - HKLM\..\Run: [lxcrmon.exe] "C:\Program Files\Lexmark 2400 Series\lxcrmon.exe"O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2400 Series\ezprint.exe"O4 - HKLM\..\Run: [LXCRCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll,_RunDLLEntry@16O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"O4 - HKLM\..\Run: [{08-8B-BF-FC-ZN}] C:\windows\system32\lrdsrngo.exe CHD003O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimizedO4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osbootO4 - HKLM\..\Run: [spyHunter] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exeO4 - HKLM\..\Run: [ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exeO4 - HKLM\..\Run: [C2K] C:\WINDOWS\Cyb2k.exeO4 - HKLM\..\Run: [searchIndexer] rundll32.exe "C:\WINDOWS\system32\jhmekjhc.dll",sitypnowO4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /backgroundO4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - HKCU\..\Run: [backupNotify] c:\Program Files\HP\Digital Imaging\bin\backupnotify.exeO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - Startup: PowerReg Scheduler V3.exeO4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\lrdsrngo.exeO4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exeO4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXEO4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exeO4 - Global Startup: Run Nintendo Wi-Fi USB Connector Registration Tool.lnk = C:\Program Files\WiFiConnector\NintendoWFCReg.exeO4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exeO8 - Extra context menu item: Download all links using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htmO8 - Extra context menu item: Download all videos using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htmO8 - Extra context menu item: Download link using &BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htmO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000O8 - Extra context menu item: Open in New &Window (PopOops) - C:\WINDOWS\Web\PopOops.htmO8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimageO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)O9 - Extra button: Panda ActiveScan - {653D93AF-C741-4e5e-8C1B-59BA43F93E16} - http://www.pandasoftware.com/activescan (file missing)O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLLO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO11 - Options group: [iNTERNATIONAL] International*O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dllO15 - Trusted Zone: *.stumbleupon.comO16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cabO16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cabO16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cabO16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cabO16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1187204501375O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cabO16 - DPF: {A954AFC3-3A26-44C2-A126-2B61C09F8FC9} (SNRecovery Control) - http://www.cybersitter.com/recovery/ocx/SerialRecovery.ocxO16 - DPF: {C52439A0-2693-4E40-B141-9F9AD5257241} (Lexmark eDiagnostics Class) - https://ediagnostics.lexmark.com/serval.cabO16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cabO21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dllO23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeO23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exeO23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exeO23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exeO23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exeO23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeO23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exeO23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exeO23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeO23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\endhwnev.exe (file missing)O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exeO23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exeO23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exeO23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXEO23 - Service: lxcr_device - - C:\WINDOWS\system32\lxcrcoms.exeO23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exeO23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exeO23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exeO23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exeO23 - Service: Uno Installer (UnoInstallerService) - Unknown owner - C:\Program Files\M-Audio Uno\UnoInst.exeO23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exeO23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe Edited October 3, 2007 by Kohu Link to post Share on other sites
Andro1d Posted October 3, 2007 Report Share Posted October 3, 2007 Hello and Welcome to Best Techie. I am MoNsTeReNeRgY22 and I will be assisting you with your malware problem today. Please do the following in the exact order they are posted, and ask any questions you may have before proceeding.Step 1First do you recoginse the following site?stumbleupon.comStep 2Please download VundoFix.exe to your desktopDouble-click VundoFix.exe to run it.Click the Scan for Vundo button.Once it's done scanning, click the Remove Vundo button.You will receive a prompt asking if you want to remove the files, click YESOnce you click yes, your desktop will go blank as it starts removing Vundo.When completed, it will prompt that it will reboot your computer, click OK.Please post the contents of C:\vundofix.txt and a new HiJackThis log in a reply to this thread.Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears upon rebooting.Step 3I need you to rename Hijackthis because I suspect that you may have the Vundo infection that can hide some entries in your log.Please go to the folder where you saved Hijackthis.exe:< C:\Documents and Settings\Pete's\My Documents\highjackthis\HijackThis.exe >Right-click on it, then select Rename.Please rename it to energy.exeThen double-click energy.exe to scan and then post the new logfile.Step 4Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to infect your system. Please follow these steps to remove older version Java components and update:Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.Scroll down to where it says "Java Runtime Environment (JRE)6 Update 3...allows end-users to run Java applications".Click the "Download" button to the right.Read the License Agreement and then check the box that says: "Accept License Agreement". The page will refresh.Click on the link to download Windows Offline Installation and save the file to your desktop.Close any programs you may have running - especially your web browser.Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.Click the Remove or Change/Remove button.Repeat as many times as necessary to remove each Java versions.Reboot your computer once all Java components are removed.Then from your desktop double-click on jre-6u3-windows-i586-p.exe to install the newest version.Step 5Please post the following in your next replyInfo on the site in questionvundofix.txtRenamed HJT Lof Link to post Share on other sites
kohu Posted October 4, 2007 Author Report Share Posted October 4, 2007 Yes, I do know of Stumbleupon, Is it something to be concerned about? I download the toolbar a while ago.I didn't get a logfile for vundo fix, but I do know that it couldn't delete a file called xxyyywt.dll if I recal. I tried to delete it on startup but it didn't work.heres my new HJT logLogfile of HijackThis v1.99.1Scan saved at 7:01:04 PM, on 10/3/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16512)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exec:\Program Files\Common Files\Symantec Shared\ccSetMgr.exec:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exeC:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exec:\Program Files\Common Files\Symantec Shared\ccProxy.exeC:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exec:\Program Files\Norton AntiVirus\navapsvc.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\M-Audio Uno\UnoInst.exeC:\Program Files\Viewpoint\Common\ViewpointService.exeC:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\wscntfy.exeC:\WINDOWS\System32\svchost.exeC:\windows\system\hpsysdrv.exeC:\Program Files\HP\hpcoretech\hpcmpmgr.exeC:\WINDOWS\System32\hphmon05.exeC:\WINDOWS\system32\VTTimer.exeC:\Program Files\Common Files\Symantec Shared\ccApp.exeC:\WINDOWS\AGRSMMSG.exeC:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exeC:\Program Files\HP\HP Software Update\HPWuSchd2.exeC:\HP\KBD\KBD.EXEC:\Program Files\Lexmark 2400 Series\lxcrmon.exeC:\Program Files\Lexmark 2400 Series\ezprint.exeC:\Program Files\iTunes\iTunesHelper.exeC:\windows\system32\lrdsrngo.exeC:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exeC:\WINDOWS\system32\lxcrcoms.exeC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\Program Files\Messenger\msmsgs.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exeC:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exeC:\Program Files\HP\Digital Imaging\bin\hpqtra08.exeC:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXEC:\Program Files\WiFiConnector\NintendoWFCReg.exeC:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exeC:\Program Files\iPod\bin\iPodService.exeC:\WINDOWS\system32\msiexec.exeC:\Documents and Settings\Pete's\My Documents\highjackthis\energy.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktopR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhostO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocxO2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dllO2 - BHO: StumbleUpon Launcher - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dllO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dllO2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dllO2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - c:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dllO2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dllO2 - BHO: (no name) - {B62F5B2F-FB3C-45BC-97BF-9EBE1A61AED4} - C:\WINDOWS\system32\awvtr.dll (file missing)O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dllO3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dllO3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dllO3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dllO3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dllO3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - c:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dllO4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exeO4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exeO4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exeO4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXEO4 - HKLM\..\Run: [VTTimer] VTTimer.exeO4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"O4 - HKLM\..\Run: [updateManager] "c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /rO4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exeO4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exeO4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exeO4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exeO4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXEO4 - HKLM\..\Run: [lxcrmon.exe] "C:\Program Files\Lexmark 2400 Series\lxcrmon.exe"O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2400 Series\ezprint.exe"O4 - HKLM\..\Run: [LXCRCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll,_RunDLLEntry@16O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"O4 - HKLM\..\Run: [{08-8B-BF-FC-ZN}] C:\windows\system32\lrdsrngo.exe CHD003O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimizedO4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osbootO4 - HKLM\..\Run: [spyHunter] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exeO4 - HKLM\..\Run: [ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exeO4 - HKLM\..\Run: [C2K] C:\WINDOWS\Cyb2k.exeO4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /backgroundO4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - HKCU\..\Run: [backupNotify] c:\Program Files\HP\Digital Imaging\bin\backupnotify.exeO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - Startup: PowerReg Scheduler V3.exeO4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\lrdsrngo.exeO4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exeO4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXEO4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exeO4 - Global Startup: Run Nintendo Wi-Fi USB Connector Registration Tool.lnk = C:\Program Files\WiFiConnector\NintendoWFCReg.exeO4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exeO8 - Extra context menu item: Download all links using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htmO8 - Extra context menu item: Download all videos using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htmO8 - Extra context menu item: Download link using &BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htmO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000O8 - Extra context menu item: Open in New &Window (PopOops) - C:\WINDOWS\Web\PopOops.htmO8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimageO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dllO9 - Extra button: Panda ActiveScan - {653D93AF-C741-4e5e-8C1B-59BA43F93E16} - http://www.pandasoftware.com/activescan (file missing)O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLLO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO11 - Options group: [iNTERNATIONAL] International*O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dllO15 - Trusted Zone: *.stumbleupon.comO16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cabO16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cabO16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cabO16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cabO16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cabO16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1187204501375O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cabO16 - DPF: {A954AFC3-3A26-44C2-A126-2B61C09F8FC9} (SNRecovery Control) - http://www.cybersitter.com/recovery/ocx/SerialRecovery.ocxO16 - DPF: {C52439A0-2693-4E40-B141-9F9AD5257241} (Lexmark eDiagnostics Class) - https://ediagnostics.lexmark.com/serval.cabO16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cabO20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dllO20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dllO21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dllO23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeO23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exeO23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exeO23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exeO23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exeO23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeO23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exeO23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exeO23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeO23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\endhwnev.exe (file missing)O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exeO23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exeO23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exeO23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXEO23 - Service: lxcr_device - - C:\WINDOWS\system32\lxcrcoms.exeO23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exeO23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exeO23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exeO23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exeO23 - Service: Uno Installer (UnoInstallerService) - Unknown owner - C:\Program Files\M-Audio Uno\UnoInst.exeO23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exeO23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exeOh, and I hope I got the new Java right. I think it installed correctly. Link to post Share on other sites
Andro1d Posted October 4, 2007 Report Share Posted October 4, 2007 (edited) No, I just have been seeing that a lot lately in logs and can't seem to find much info about it. Just wanted to make sure taht you added it, not some random program or piece of malware.Can you see if the log is located here?C:\vundofix.txtAlso please do the followingDownload Deckard's System Scanner (DSS) to your Desktop.Close all applications and windows.Double-click on DSS.exe to run it, and follow the prompts.When it has finished, dss will open two Notepads main.txt and extra.txt -- please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.Extra Note: When running DSS, some firewalls may warn that sigcheck.exe is trying to access the internet - please ensure that you allow sigcheck.exe permission to do so. Also, it may happen that your Antivirus flags DSS as suspicious. Please allow the Deckard's System Scanner to run and don't let your Antivirus delete it. (In this case, it may be better to temporary disable your Antivirus) Edited October 4, 2007 by MoNsTeReNeRgY22 Link to post Share on other sites
kohu Posted October 4, 2007 Author Report Share Posted October 4, 2007 (edited) Aha! Heres the vundofix log!VundoFix V6.5.6Checking Java version...Java version is 1.4.2.3Old versions of java are exploitable and should be removed.Scan started at 3:38:25 PM 7/25/2007Listing files found while scanning....No infected files were found.VundoFix V6.5.9Checking Java version...Java version is 1.4.2.3Old versions of java are exploitable and should be removed.Scan started at 5:27:42 PM 10/3/2007Listing files found while scanning....C:\windows\system32\acyveqdm.iniC:\windows\system32\aggvaorn.dllC:\windows\system32\aglsjgsq.dllC:\windows\system32\ahadrepr.dllC:\windows\system32\akvxhcfv.dllC:\windows\system32\aorvyaqt.iniC:\WINDOWS\system32\awvtr.dllC:\windows\system32\ayldidqg.iniC:\windows\system32\ayxnnfgr.iniC:\windows\system32\bbvckdpp.iniC:\windows\system32\binqsyqw.dllC:\windows\system32\bjyufmfi.iniC:\windows\system32\bqyyrevi.iniC:\windows\system32\btjdryrr.dllC:\windows\system32\bybtpite.dllC:\windows\system32\bydrafbu.iniC:\windows\system32\ceownxft.dllC:\windows\system32\chjkemhj.iniC:\windows\system32\clnlelfd.dllC:\WINDOWS\system32\coxsgffg.dllC:\windows\system32\cqqmhnwr.iniC:\windows\system32\dcpgmlpy.dllC:\windows\system32\dflelnlc.iniC:\windows\system32\difpuoew.dllC:\windows\system32\dlbudeas.dllC:\windows\system32\dmxejgoi.iniC:\windows\system32\dpyhlpxv.dllC:\windows\system32\drdlommt.dllC:\windows\system32\drnjxljn.iniC:\windows\system32\drqsfxvm.iniC:\windows\system32\eervjfyx.dllC:\windows\system32\ejmvqbyv.dllC:\windows\system32\ekpgbiyn.iniC:\windows\system32\embxsohx.iniC:\windows\system32\emlvkxij.dllC:\windows\system32\ensjjknj.dllC:\windows\system32\eqfftdqr.dllC:\windows\system32\etiptbyb.iniC:\windows\system32\evdrcnft.iniC:\windows\system32\eysxdeyr.dllC:\windows\system32\fcaminff.dllC:\windows\system32\fcxqoiex.iniC:\windows\system32\fdxxnelg.iniC:\windows\system32\ffnimacf.iniC:\windows\system32\ffrwohdj.iniC:\windows\system32\fhssyspr.iniC:\windows\system32\fnlkgupm.iniC:\windows\system32\frxqypvp.iniC:\windows\system32\fsxfysss.dllC:\windows\system32\ftbuikuj.dllC:\windows\system32\fvuielst.dllC:\windows\system32\ghlorpmp.dllC:\windows\system32\glenxxdf.dllC:\windows\system32\gnipaxix.dllC:\windows\system32\gqdidlya.dllC:\windows\system32\hfyhwwlu.iniC:\windows\system32\hngoeehn.dllC:\windows\system32\hsmyuiym.iniC:\windows\system32\hvwvedpq.dllC:\windows\system32\ifmfuyjb.dllC:\windows\system32\ihyeawiu.dllC:\windows\system32\iogjexmd.dllC:\windows\system32\iveryyqb.dllC:\windows\system32\ixxvtvxm.iniC:\windows\system32\jdhowrff.dllC:\windows\system32\jewafmsx.iniC:\windows\system32\jhmekjhc.dllC:\windows\system32\jixkvlme.iniC:\windows\system32\jjjdcrep.iniC:\windows\system32\jnkjjsne.iniC:\windows\system32\jolwnndo.dllC:\windows\system32\jqeppbjx.dllC:\windows\system32\jukiubtf.iniC:\windows\system32\kbacmjbo.dllC:\windows\system32\kjhpmtkw.dllC:\windows\system32\kjshanat.iniC:\windows\system32\kttgkakl.dllC:\windows\system32\kuvqdujv.dllC:\windows\system32\kvkwlncr.dllC:\windows\system32\ldmvlcns.iniC:\windows\system32\lhwrkdbt.dllC:\windows\system32\lkakgttk.iniC:\windows\system32\lkemsolv.dllC:\WINDOWS\system32\lubphvcu.dllC:\windows\system32\luunjajp.iniC:\windows\system32\mdqevyca.dllC:\windows\system32\mgavwain.dllC:\windows\system32\mitsenpn.iniC:\windows\system32\mjglnelx.iniC:\windows\system32\mpugklnf.dllC:\windows\system32\mqkwdqns.dllC:\windows\system32\mrohsivq.iniC:\windows\system32\mvxfsqrd.dllC:\windows\system32\mxvtvxxi.dllC:\windows\system32\myafaokt.iniC:\windows\system32\myiuymsh.dllC:\windows\system32\nbuyciep.dllC:\WINDOWS\system32\nbytahug.dllC:\windows\system32\ncirjmkv.dllC:\windows\system32\nhatropy.iniC:\windows\system32\nheeognh.iniC:\windows\system32\nhntmorq.iniC:\windows\system32\niawvagm.iniC:\windows\system32\njlxjnrd.dllC:\windows\system32\nkjwaavh.exeC:\windows\system32\npnestim.dllC:\windows\system32\nqmvsnfq.iniC:\windows\system32\nroavgga.iniC:\windows\system32\nyibgpke.dllC:\windows\system32\objmcabk.iniC:\windows\system32\odnnwloj.iniC:\windows\system32\ohlpxlws.dllC:\windows\system32\onwsiivp.iniC:\windows\system32\ooufpkwr.iniC:\windows\system32\ouinjiqr.dllC:\windows\system32\pbbniabv.dllC:\windows\system32\peicyubn.iniC:\windows\system32\percdjjj.dllC:\windows\system32\piomrlyu.iniC:\windows\system32\pjajnuul.dllC:\windows\system32\pjvbrogt.dllC:\windows\system32\pluwwilv.dllC:\windows\system32\pmprolhg.iniC:\windows\system32\ppdkcvbb.dllC:\windows\system32\pviiswno.dllC:\windows\system32\pvpyqxrf.dllC:\windows\system32\pxjjjaax.dllC:\windows\system32\qbqvocnq.dllC:\windows\system32\qesahwmq.iniC:\windows\system32\qfnsvmqn.dllC:\windows\system32\qmwhaseq.dllC:\windows\system32\qncovqbq.iniC:\windows\system32\qpdevwvh.iniC:\windows\system32\qromtnhn.dllC:\windows\system32\qsgjslga.iniC:\windows\system32\qubdmgps.dllC:\windows\system32\qvishorm.dllC:\windows\system32\rcnlwkvk.iniC:\windows\system32\rcrwxhvs.dllC:\windows\system32\rgfnnxya.dllC:\windows\system32\rooksxis.dllC:\windows\system32\rperdaha.iniC:\windows\system32\rpsysshf.dllC:\windows\system32\rqdtffqe.iniC:\windows\system32\rqijniuo.iniC:\windows\system32\rryrdjtb.iniC:\WINDOWS\system32\rtvwa.bak1C:\WINDOWS\system32\rtvwa.bak2C:\WINDOWS\system32\rtvwa.iniC:\WINDOWS\system32\rtvwa.ini2C:\WINDOWS\system32\rtvwa.tmpC:\windows\system32\rwkpfuoo.dllC:\windows\system32\rwnhmqqc.dllC:\windows\system32\ryedxsye.iniC:\windows\system32\saedubld.iniC:\windows\system32\saqlwdcw.iniC:\windows\system32\sarkjvou.iniC:\windows\system32\sgmrvvjt.iniC:\windows\system32\sixskoor.iniC:\windows\system32\snclvmdl.dllC:\windows\system32\snqdwkqm.iniC:\windows\system32\spgmdbuq.iniC:\windows\system32\sssyfxsf.iniC:\windows\system32\svhxwrcr.iniC:\windows\system32\swlxplho.iniC:\windows\system32\tanahsjk.dllC:\windows\system32\tbdkrwhl.iniC:\windows\system32\tfncrdve.dllC:\windows\system32\tgorbvjp.iniC:\windows\system32\tjvvrmgs.dllC:\windows\system32\tkoafaym.dllC:\windows\system32\tmmoldrd.iniC:\windows\system32\tqayvroa.dllC:\windows\system32\tsleiuvf.iniC:\windows\system32\ubfardyb.dllC:\windows\system32\ucqqimax.iniC:\windows\system32\ucvhpbul.iniC:\windows\system32\ucwikttu.dllC:\windows\system32\uiwaeyhi.iniC:\windows\system32\ulwwhyfh.dllC:\windows\system32\uovjkras.dllC:\windows\system32\uqyqipfy.iniC:\windows\system32\uttkiwcu.iniC:\windows\system32\uylrmoip.dllC:\windows\system32\vbainbbp.iniC:\windows\system32\vfchxvka.iniC:\windows\system32\vjudqvuk.iniC:\windows\system32\vkmjricn.iniC:\windows\system32\vliwwulp.iniC:\windows\system32\vlosmekl.iniC:\windows\system32\vxplhypd.iniC:\windows\system32\vybqvmje.iniC:\windows\system32\wcdwlqas.dllC:\windows\system32\weoupfid.iniC:\windows\system32\wktmphjk.iniC:\windows\system32\wqysqnib.iniC:\windows\system32\wxuorxgx.dllC:\windows\system32\wytgnygy.iniC:\windows\system32\xaajjjxp.iniC:\windows\system32\xamiqqcu.dllC:\windows\system32\xeioqxcf.dllC:\windows\system32\xgxrouxw.iniC:\windows\system32\xhosxbme.dllC:\windows\system32\xixaping.iniC:\windows\system32\xjbppeqj.iniC:\windows\system32\xlenlgjm.dllC:\windows\system32\xmcnmmmx.iniC:\windows\system32\xmmmncmx.dllC:\windows\system32\xsmfawej.dllC:\WINDOWS\system32\xxyyywt.dllC:\windows\system32\xyfjvree.iniC:\windows\system32\yfpiqyqu.dllC:\windows\system32\ygyngtyw.dllC:\windows\system32\yplmgpcd.iniC:\windows\system32\yportahn.dllBeginning removal... Attempting to delete C:\windows\system32\acyveqdm.iniC:\windows\system32\acyveqdm.ini Has been deleted! Attempting to delete C:\windows\system32\aggvaorn.dllC:\windows\system32\aggvaorn.dll Has been deleted! Attempting to delete C:\windows\system32\aglsjgsq.dllC:\windows\system32\aglsjgsq.dll Has been deleted! Attempting to delete C:\windows\system32\ahadrepr.dllC:\windows\system32\ahadrepr.dll Has been deleted! Attempting to delete C:\windows\system32\akvxhcfv.dllC:\windows\system32\akvxhcfv.dll Has been deleted! Attempting to delete C:\windows\system32\aorvyaqt.iniC:\windows\system32\aorvyaqt.ini Has been deleted! Attempting to delete C:\WINDOWS\system32\awvtr.dllC:\WINDOWS\system32\awvtr.dll Could not be deleted. Attempting to delete C:\windows\system32\ayldidqg.iniC:\windows\system32\ayldidqg.ini Has been deleted! Attempting to delete C:\windows\system32\ayxnnfgr.iniC:\windows\system32\ayxnnfgr.ini Has been deleted! Attempting to delete C:\windows\system32\bbvckdpp.iniC:\windows\system32\bbvckdpp.ini Has been deleted! Attempting to delete C:\windows\system32\binqsyqw.dllC:\windows\system32\binqsyqw.dll Has been deleted! Attempting to delete C:\windows\system32\bjyufmfi.iniC:\windows\system32\bjyufmfi.ini Has been deleted! Attempting to delete C:\windows\system32\bqyyrevi.iniC:\windows\system32\bqyyrevi.ini Has been deleted! Attempting to delete C:\windows\system32\btjdryrr.dllC:\windows\system32\btjdryrr.dll Has been deleted! Attempting to delete C:\windows\system32\bybtpite.dllC:\windows\system32\bybtpite.dll Has been deleted! Attempting to delete C:\windows\system32\bydrafbu.iniC:\windows\system32\bydrafbu.ini Has been deleted! Attempting to delete C:\windows\system32\ceownxft.dllC:\windows\system32\ceownxft.dll Has been deleted! Attempting to delete C:\windows\system32\chjkemhj.iniC:\windows\system32\chjkemhj.ini Has been deleted! Attempting to delete C:\windows\system32\clnlelfd.dllC:\windows\system32\clnlelfd.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\coxsgffg.dllC:\WINDOWS\system32\coxsgffg.dll Has been deleted! Attempting to delete C:\windows\system32\cqqmhnwr.iniC:\windows\system32\cqqmhnwr.ini Has been deleted! Attempting to delete C:\windows\system32\dcpgmlpy.dllC:\windows\system32\dcpgmlpy.dll Has been deleted! Attempting to delete C:\windows\system32\dflelnlc.iniC:\windows\system32\dflelnlc.ini Has been deleted! Attempting to delete C:\windows\system32\difpuoew.dllC:\windows\system32\difpuoew.dll Has been deleted! Attempting to delete C:\windows\system32\dlbudeas.dllC:\windows\system32\dlbudeas.dll Has been deleted! Attempting to delete C:\windows\system32\dmxejgoi.iniC:\windows\system32\dmxejgoi.ini Has been deleted! Attempting to delete C:\windows\system32\dpyhlpxv.dllC:\windows\system32\dpyhlpxv.dll Has been deleted! Attempting to delete C:\windows\system32\drdlommt.dllC:\windows\system32\drdlommt.dll Has been deleted! Attempting to delete C:\windows\system32\drnjxljn.iniC:\windows\system32\drnjxljn.ini Has been deleted! Attempting to delete C:\windows\system32\drqsfxvm.iniC:\windows\system32\drqsfxvm.ini Has been deleted! Attempting to delete C:\windows\system32\eervjfyx.dllC:\windows\system32\eervjfyx.dll Has been deleted! Attempting to delete C:\windows\system32\ejmvqbyv.dllC:\windows\system32\ejmvqbyv.dll Has been deleted! Attempting to delete C:\windows\system32\ekpgbiyn.iniC:\windows\system32\ekpgbiyn.ini Has been deleted! Attempting to delete C:\windows\system32\embxsohx.iniC:\windows\system32\embxsohx.ini Has been deleted! Attempting to delete C:\windows\system32\emlvkxij.dllC:\windows\system32\emlvkxij.dll Has been deleted! Attempting to delete C:\windows\system32\ensjjknj.dllC:\windows\system32\ensjjknj.dll Has been deleted! Attempting to delete C:\windows\system32\eqfftdqr.dllC:\windows\system32\eqfftdqr.dll Has been deleted! Attempting to delete C:\windows\system32\etiptbyb.iniC:\windows\system32\etiptbyb.ini Has been deleted! Attempting to delete C:\windows\system32\evdrcnft.iniC:\windows\system32\evdrcnft.ini Has been deleted! Attempting to delete C:\windows\system32\eysxdeyr.dllC:\windows\system32\eysxdeyr.dll Has been deleted! Attempting to delete C:\windows\system32\fcaminff.dllC:\windows\system32\fcaminff.dll Has been deleted! Attempting to delete C:\windows\system32\fcxqoiex.iniC:\windows\system32\fcxqoiex.ini Has been deleted! Attempting to delete C:\windows\system32\fdxxnelg.iniC:\windows\system32\fdxxnelg.ini Has been deleted! Attempting to delete C:\windows\system32\ffnimacf.iniC:\windows\system32\ffnimacf.ini Has been deleted! Attempting to delete C:\windows\system32\ffrwohdj.iniC:\windows\system32\ffrwohdj.ini Has been deleted! Attempting to delete C:\windows\system32\fhssyspr.iniC:\windows\system32\fhssyspr.ini Has been deleted! Attempting to delete C:\windows\system32\fnlkgupm.iniC:\windows\system32\fnlkgupm.ini Has been deleted! Attempting to delete C:\windows\system32\frxqypvp.iniC:\windows\system32\frxqypvp.ini Has been deleted! Attempting to delete C:\windows\system32\fsxfysss.dllC:\windows\system32\fsxfysss.dll Has been deleted! Attempting to delete C:\windows\system32\ftbuikuj.dllC:\windows\system32\ftbuikuj.dll Has been deleted! Attempting to delete C:\windows\system32\fvuielst.dllC:\windows\system32\fvuielst.dll Has been deleted! Attempting to delete C:\windows\system32\ghlorpmp.dllC:\windows\system32\ghlorpmp.dll Has been deleted! Attempting to delete C:\windows\system32\glenxxdf.dllC:\windows\system32\glenxxdf.dll Has been deleted! Attempting to delete C:\windows\system32\gnipaxix.dllC:\windows\system32\gnipaxix.dll Has been deleted! Attempting to delete C:\windows\system32\gqdidlya.dllC:\windows\system32\gqdidlya.dll Has been deleted! Attempting to delete C:\windows\system32\hfyhwwlu.iniC:\windows\system32\hfyhwwlu.ini Has been deleted! Attempting to delete C:\windows\system32\hngoeehn.dllC:\windows\system32\hngoeehn.dll Has been deleted! Attempting to delete C:\windows\system32\hsmyuiym.iniC:\windows\system32\hsmyuiym.ini Has been deleted! Attempting to delete C:\windows\system32\hvwvedpq.dllC:\windows\system32\hvwvedpq.dll Has been deleted! Attempting to delete C:\windows\system32\ifmfuyjb.dllC:\windows\system32\ifmfuyjb.dll Has been deleted! Attempting to delete C:\windows\system32\ihyeawiu.dllC:\windows\system32\ihyeawiu.dll Has been deleted! Attempting to delete C:\windows\system32\iogjexmd.dllC:\windows\system32\iogjexmd.dll Has been deleted! Attempting to delete C:\windows\system32\iveryyqb.dllC:\windows\system32\iveryyqb.dll Has been deleted! Attempting to delete C:\windows\system32\ixxvtvxm.iniC:\windows\system32\ixxvtvxm.ini Has been deleted! Attempting to delete C:\windows\system32\jdhowrff.dllC:\windows\system32\jdhowrff.dll Has been deleted! Attempting to delete C:\windows\system32\jewafmsx.iniC:\windows\system32\jewafmsx.ini Has been deleted! Attempting to delete C:\windows\system32\jhmekjhc.dllC:\windows\system32\jhmekjhc.dll Has been deleted! Attempting to delete C:\windows\system32\jixkvlme.iniC:\windows\system32\jixkvlme.ini Has been deleted! Attempting to delete C:\windows\system32\jjjdcrep.iniC:\windows\system32\jjjdcrep.ini Has been deleted! Attempting to delete C:\windows\system32\jnkjjsne.iniC:\windows\system32\jnkjjsne.ini Has been deleted! Attempting to delete C:\windows\system32\jolwnndo.dllC:\windows\system32\jolwnndo.dll Has been deleted! Attempting to delete C:\windows\system32\jqeppbjx.dllC:\windows\system32\jqeppbjx.dll Has been deleted! Attempting to delete C:\windows\system32\jukiubtf.iniC:\windows\system32\jukiubtf.ini Has been deleted! Attempting to delete C:\windows\system32\kbacmjbo.dllC:\windows\system32\kbacmjbo.dll Has been deleted! Attempting to delete C:\windows\system32\kjhpmtkw.dllC:\windows\system32\kjhpmtkw.dll Has been deleted! Attempting to delete C:\windows\system32\kjshanat.iniC:\windows\system32\kjshanat.ini Has been deleted! Attempting to delete C:\windows\system32\kttgkakl.dllC:\windows\system32\kttgkakl.dll Has been deleted! Attempting to delete C:\windows\system32\kuvqdujv.dllC:\windows\system32\kuvqdujv.dll Has been deleted! Attempting to delete C:\windows\system32\kvkwlncr.dllC:\windows\system32\kvkwlncr.dll Has been deleted! Attempting to delete C:\windows\system32\ldmvlcns.iniC:\windows\system32\ldmvlcns.ini Has been deleted! Attempting to delete C:\windows\system32\lhwrkdbt.dllC:\windows\system32\lhwrkdbt.dll Has been deleted! Attempting to delete C:\windows\system32\lkakgttk.iniC:\windows\system32\lkakgttk.ini Has been deleted! Attempting to delete C:\windows\system32\lkemsolv.dllC:\windows\system32\lkemsolv.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\lubphvcu.dllC:\WINDOWS\system32\lubphvcu.dll Could not be deleted. Attempting to delete C:\windows\system32\luunjajp.iniC:\windows\system32\luunjajp.ini Has been deleted! Attempting to delete C:\windows\system32\mdqevyca.dllC:\windows\system32\mdqevyca.dll Has been deleted! Attempting to delete C:\windows\system32\mgavwain.dllC:\windows\system32\mgavwain.dll Has been deleted! Attempting to delete C:\windows\system32\mitsenpn.iniC:\windows\system32\mitsenpn.ini Has been deleted! Attempting to delete C:\windows\system32\mjglnelx.iniC:\windows\system32\mjglnelx.ini Has been deleted! Attempting to delete C:\windows\system32\mpugklnf.dllC:\windows\system32\mpugklnf.dll Has been deleted! Attempting to delete C:\windows\system32\mqkwdqns.dllC:\windows\system32\mqkwdqns.dll Has been deleted! Attempting to delete C:\windows\system32\mrohsivq.iniC:\windows\system32\mrohsivq.ini Has been deleted! Attempting to delete C:\windows\system32\mvxfsqrd.dllC:\windows\system32\mvxfsqrd.dll Has been deleted! Attempting to delete C:\windows\system32\mxvtvxxi.dllC:\windows\system32\mxvtvxxi.dll Has been deleted! Attempting to delete C:\windows\system32\myafaokt.iniC:\windows\system32\myafaokt.ini Has been deleted! Attempting to delete C:\windows\system32\myiuymsh.dllC:\windows\system32\myiuymsh.dll Has been deleted! Attempting to delete C:\windows\system32\nbuyciep.dllC:\windows\system32\nbuyciep.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\nbytahug.dllC:\WINDOWS\system32\nbytahug.dll Could not be deleted. Attempting to delete C:\windows\system32\ncirjmkv.dllC:\windows\system32\ncirjmkv.dll Has been deleted! Attempting to delete C:\windows\system32\nhatropy.iniC:\windows\system32\nhatropy.ini Has been deleted! Attempting to delete C:\windows\system32\nheeognh.iniC:\windows\system32\nheeognh.ini Has been deleted! Attempting to delete C:\windows\system32\nhntmorq.iniC:\windows\system32\nhntmorq.ini Has been deleted! Attempting to delete C:\windows\system32\niawvagm.iniC:\windows\system32\niawvagm.ini Has been deleted! Attempting to delete C:\windows\system32\njlxjnrd.dllC:\windows\system32\njlxjnrd.dll Has been deleted! Attempting to delete C:\windows\system32\nkjwaavh.exeC:\windows\system32\nkjwaavh.exe Has been deleted! Attempting to delete C:\windows\system32\npnestim.dllC:\windows\system32\npnestim.dll Has been deleted! Attempting to delete C:\windows\system32\nqmvsnfq.iniC:\windows\system32\nqmvsnfq.ini Has been deleted! Attempting to delete C:\windows\system32\nroavgga.iniC:\windows\system32\nroavgga.ini Has been deleted! Attempting to delete C:\windows\system32\nyibgpke.dllC:\windows\system32\nyibgpke.dll Has been deleted! Attempting to delete C:\windows\system32\objmcabk.iniC:\windows\system32\objmcabk.ini Has been deleted! Attempting to delete C:\windows\system32\odnnwloj.iniC:\windows\system32\odnnwloj.ini Has been deleted! Attempting to delete C:\windows\system32\ohlpxlws.dllC:\windows\system32\ohlpxlws.dll Has been deleted! Attempting to delete C:\windows\system32\onwsiivp.iniC:\windows\system32\onwsiivp.ini Has been deleted! Attempting to delete C:\windows\system32\ooufpkwr.iniC:\windows\system32\ooufpkwr.ini Has been deleted! Attempting to delete C:\windows\system32\ouinjiqr.dllC:\windows\system32\ouinjiqr.dll Has been deleted! Attempting to delete C:\windows\system32\pbbniabv.dllC:\windows\system32\pbbniabv.dll Has been deleted! Attempting to delete C:\windows\system32\peicyubn.iniC:\windows\system32\peicyubn.ini Has been deleted! Attempting to delete C:\windows\system32\percdjjj.dllC:\windows\system32\percdjjj.dll Has been deleted! Attempting to delete C:\windows\system32\piomrlyu.iniC:\windows\system32\piomrlyu.ini Has been deleted! Attempting to delete C:\windows\system32\pjajnuul.dllC:\windows\system32\pjajnuul.dll Has been deleted! Attempting to delete C:\windows\system32\pjvbrogt.dllC:\windows\system32\pjvbrogt.dll Has been deleted! Attempting to delete C:\windows\system32\pluwwilv.dllC:\windows\system32\pluwwilv.dll Has been deleted! Attempting to delete C:\windows\system32\pmprolhg.iniC:\windows\system32\pmprolhg.ini Has been deleted! Attempting to delete C:\windows\system32\ppdkcvbb.dllC:\windows\system32\ppdkcvbb.dll Has been deleted! Attempting to delete C:\windows\system32\pviiswno.dllC:\windows\system32\pviiswno.dll Has been deleted! Attempting to delete C:\windows\system32\pvpyqxrf.dllC:\windows\system32\pvpyqxrf.dll Has been deleted! Attempting to delete C:\windows\system32\pxjjjaax.dllC:\windows\system32\pxjjjaax.dll Has been deleted! Attempting to delete C:\windows\system32\qbqvocnq.dllC:\windows\system32\qbqvocnq.dll Has been deleted! Attempting to delete C:\windows\system32\qesahwmq.iniC:\windows\system32\qesahwmq.ini Has been deleted! Attempting to delete C:\windows\system32\qfnsvmqn.dllC:\windows\system32\qfnsvmqn.dll Has been deleted! Attempting to delete C:\windows\system32\qmwhaseq.dllC:\windows\system32\qmwhaseq.dll Has been deleted! Attempting to delete C:\windows\system32\qncovqbq.iniC:\windows\system32\qncovqbq.ini Has been deleted! Attempting to delete C:\windows\system32\qpdevwvh.iniC:\windows\system32\qpdevwvh.ini Has been deleted! Attempting to delete C:\windows\system32\qromtnhn.dllC:\windows\system32\qromtnhn.dll Has been deleted! Attempting to delete C:\windows\system32\qsgjslga.iniC:\windows\system32\qsgjslga.ini Has been deleted! Attempting to delete C:\windows\system32\qubdmgps.dllC:\windows\system32\qubdmgps.dll Has been deleted! Attempting to delete C:\windows\system32\qvishorm.dllC:\windows\system32\qvishorm.dll Has been deleted! Attempting to delete C:\windows\system32\rcnlwkvk.iniC:\windows\system32\rcnlwkvk.ini Has been deleted! Attempting to delete C:\windows\system32\rcrwxhvs.dllC:\windows\system32\rcrwxhvs.dll Has been deleted! Attempting to delete C:\windows\system32\rgfnnxya.dllC:\windows\system32\rgfnnxya.dll Has been deleted! Attempting to delete C:\windows\system32\rooksxis.dllC:\windows\system32\rooksxis.dll Has been deleted! Attempting to delete C:\windows\system32\rperdaha.iniC:\windows\system32\rperdaha.ini Has been deleted! Attempting to delete C:\windows\system32\rpsysshf.dllC:\windows\system32\rpsysshf.dll Has been deleted! Attempting to delete C:\windows\system32\rqdtffqe.iniC:\windows\system32\rqdtffqe.ini Has been deleted! Attempting to delete C:\windows\system32\rqijniuo.iniC:\windows\system32\rqijniuo.ini Has been deleted! Attempting to delete C:\windows\system32\rryrdjtb.iniC:\windows\system32\rryrdjtb.ini Has been deleted! Attempting to delete C:\WINDOWS\system32\rtvwa.bak1C:\WINDOWS\system32\rtvwa.bak1 Has been deleted! Attempting to delete C:\WINDOWS\system32\rtvwa.bak2C:\WINDOWS\system32\rtvwa.bak2 Has been deleted! Attempting to delete C:\WINDOWS\system32\rtvwa.iniC:\WINDOWS\system32\rtvwa.ini Has been deleted! Attempting to delete C:\WINDOWS\system32\rtvwa.ini2C:\WINDOWS\system32\rtvwa.ini2 Has been deleted! Attempting to delete C:\WINDOWS\system32\rtvwa.tmpC:\WINDOWS\system32\rtvwa.tmp Has been deleted! Attempting to delete C:\windows\system32\rwkpfuoo.dllC:\windows\system32\rwkpfuoo.dll Has been deleted! Attempting to delete C:\windows\system32\rwnhmqqc.dllC:\windows\system32\rwnhmqqc.dll Has been deleted! Attempting to delete C:\windows\system32\ryedxsye.iniC:\windows\system32\ryedxsye.ini Has been deleted! Attempting to delete C:\windows\system32\saedubld.iniC:\windows\system32\saedubld.ini Has been deleted! Attempting to delete C:\windows\system32\saqlwdcw.iniC:\windows\system32\saqlwdcw.ini Has been deleted! Attempting to delete C:\windows\system32\sarkjvou.iniC:\windows\system32\sarkjvou.ini Has been deleted! Attempting to delete C:\windows\system32\sgmrvvjt.iniC:\windows\system32\sgmrvvjt.ini Has been deleted! Attempting to delete C:\windows\system32\sixskoor.iniC:\windows\system32\sixskoor.ini Has been deleted! Attempting to delete C:\windows\system32\snclvmdl.dllC:\windows\system32\snclvmdl.dll Has been deleted! Attempting to delete C:\windows\system32\snqdwkqm.iniC:\windows\system32\snqdwkqm.ini Has been deleted! Attempting to delete C:\windows\system32\spgmdbuq.iniC:\windows\system32\spgmdbuq.ini Has been deleted! Attempting to delete C:\windows\system32\sssyfxsf.iniC:\windows\system32\sssyfxsf.ini Has been deleted! Attempting to delete C:\windows\system32\svhxwrcr.iniC:\windows\system32\svhxwrcr.ini Has been deleted! Attempting to delete C:\windows\system32\swlxplho.iniC:\windows\system32\swlxplho.ini Has been deleted! Attempting to delete C:\windows\system32\tanahsjk.dllC:\windows\system32\tanahsjk.dll Has been deleted! Attempting to delete C:\windows\system32\tbdkrwhl.iniC:\windows\system32\tbdkrwhl.ini Has been deleted! Attempting to delete C:\windows\system32\tfncrdve.dllC:\windows\system32\tfncrdve.dll Has been deleted! Attempting to delete C:\windows\system32\tgorbvjp.iniC:\windows\system32\tgorbvjp.ini Has been deleted! Attempting to delete C:\windows\system32\tjvvrmgs.dllC:\windows\system32\tjvvrmgs.dll Has been deleted! Attempting to delete C:\windows\system32\tkoafaym.dllC:\windows\system32\tkoafaym.dll Has been deleted! Attempting to delete C:\windows\system32\tmmoldrd.iniC:\windows\system32\tmmoldrd.ini Has been deleted! Attempting to delete C:\windows\system32\tqayvroa.dllC:\windows\system32\tqayvroa.dll Has been deleted! Attempting to delete C:\windows\system32\tsleiuvf.iniC:\windows\system32\tsleiuvf.ini Has been deleted! Attempting to delete C:\windows\system32\ubfardyb.dllC:\windows\system32\ubfardyb.dll Has been deleted! Attempting to delete C:\windows\system32\ucqqimax.iniC:\windows\system32\ucqqimax.ini Has been deleted! Attempting to delete C:\windows\system32\ucvhpbul.iniC:\windows\system32\ucvhpbul.ini Has been deleted! Attempting to delete C:\windows\system32\ucwikttu.dllC:\windows\system32\ucwikttu.dll Has been deleted! Attempting to delete C:\windows\system32\uiwaeyhi.iniC:\windows\system32\uiwaeyhi.ini Has been deleted! Attempting to delete C:\windows\system32\ulwwhyfh.dllC:\windows\system32\ulwwhyfh.dll Has been deleted! Attempting to delete C:\windows\system32\uovjkras.dllC:\windows\system32\uovjkras.dll Has been deleted! Attempting to delete C:\windows\system32\uqyqipfy.iniC:\windows\system32\uqyqipfy.ini Has been deleted! Attempting to delete C:\windows\system32\uttkiwcu.iniC:\windows\system32\uttkiwcu.ini Has been deleted! Attempting to delete C:\windows\system32\uylrmoip.dllC:\windows\system32\uylrmoip.dll Has been deleted! Attempting to delete C:\windows\system32\vbainbbp.iniC:\windows\system32\vbainbbp.ini Has been deleted! Attempting to delete C:\windows\system32\vfchxvka.iniC:\windows\system32\vfchxvka.ini Has been deleted! Attempting to delete C:\windows\system32\vjudqvuk.iniC:\windows\system32\vjudqvuk.ini Has been deleted! Attempting to delete C:\windows\system32\vkmjricn.iniC:\windows\system32\vkmjricn.ini Has been deleted! Attempting to delete C:\windows\system32\vliwwulp.iniC:\windows\system32\vliwwulp.ini Has been deleted! Attempting to delete C:\windows\system32\vlosmekl.iniC:\windows\system32\vlosmekl.ini Has been deleted! Attempting to delete C:\windows\system32\vxplhypd.iniC:\windows\system32\vxplhypd.ini Has been deleted! Attempting to delete C:\windows\system32\vybqvmje.iniC:\windows\system32\vybqvmje.ini Has been deleted! Attempting to delete C:\windows\system32\wcdwlqas.dllC:\windows\system32\wcdwlqas.dll Has been deleted! Attempting to delete C:\windows\system32\weoupfid.iniC:\windows\system32\weoupfid.ini Has been deleted! Attempting to delete C:\windows\system32\wktmphjk.iniC:\windows\system32\wktmphjk.ini Has been deleted! Attempting to delete C:\windows\system32\wqysqnib.iniC:\windows\system32\wqysqnib.ini Has been deleted! Attempting to delete C:\windows\system32\wxuorxgx.dllC:\windows\system32\wxuorxgx.dll Has been deleted! Attempting to delete C:\windows\system32\wytgnygy.iniC:\windows\system32\wytgnygy.ini Has been deleted! Attempting to delete C:\windows\system32\xaajjjxp.iniC:\windows\system32\xaajjjxp.ini Has been deleted! Attempting to delete C:\windows\system32\xamiqqcu.dllC:\windows\system32\xamiqqcu.dll Has been deleted! Attempting to delete C:\windows\system32\xeioqxcf.dllC:\windows\system32\xeioqxcf.dll Has been deleted! Attempting to delete C:\windows\system32\xgxrouxw.iniC:\windows\system32\xgxrouxw.ini Has been deleted! Attempting to delete C:\windows\system32\xhosxbme.dllC:\windows\system32\xhosxbme.dll Has been deleted! Attempting to delete C:\windows\system32\xixaping.iniC:\windows\system32\xixaping.ini Has been deleted! Attempting to delete C:\windows\system32\xjbppeqj.iniC:\windows\system32\xjbppeqj.ini Has been deleted! Attempting to delete C:\windows\system32\xlenlgjm.dllC:\windows\system32\xlenlgjm.dll Has been deleted! Attempting to delete C:\windows\system32\xmcnmmmx.iniC:\windows\system32\xmcnmmmx.ini Has been deleted! Attempting to delete C:\windows\system32\xmmmncmx.dllC:\windows\system32\xmmmncmx.dll Has been deleted! Attempting to delete C:\windows\system32\xsmfawej.dllC:\windows\system32\xsmfawej.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\xxyyywt.dllC:\WINDOWS\system32\xxyyywt.dll Could not be deleted. Attempting to delete C:\windows\system32\xyfjvree.iniC:\windows\system32\xyfjvree.ini Has been deleted! Attempting to delete C:\windows\system32\yfpiqyqu.dllC:\windows\system32\yfpiqyqu.dll Has been deleted! Attempting to delete C:\windows\system32\ygyngtyw.dllC:\windows\system32\ygyngtyw.dll Has been deleted! Attempting to delete C:\windows\system32\yplmgpcd.iniC:\windows\system32\yplmgpcd.ini Has been deleted! Attempting to delete C:\windows\system32\yportahn.dllC:\windows\system32\yportahn.dll Has been deleted!Performing Repairs to the registry.Done!Beginning removal... Attempting to delete C:\WINDOWS\system32\awvtr.dllC:\WINDOWS\system32\awvtr.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\lubphvcu.dllC:\WINDOWS\system32\lubphvcu.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\nbytahug.dllC:\WINDOWS\system32\nbytahug.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\rtvwa.iniC:\WINDOWS\system32\rtvwa.ini Has been deleted! Attempting to delete C:\WINDOWS\system32\xxyyywt.dllC:\WINDOWS\system32\xxyyywt.dll Could not be deleted.Performing Repairs to the registry.Done! Edited October 4, 2007 by Kohu Link to post Share on other sites
kohu Posted October 4, 2007 Author Report Share Posted October 4, 2007 Heres the main.txt from DSSDeckard's System Scanner v20070905.67Run by Pete's on 2007-10-03 20:26:38Computer is in Normal Mode.---------------------------------------------------------------------------------- System Restore --------------------------------------------------------------Successfully created a Deckard's System Scanner Restore Point.-- Last 5 Restore Point(s) --124: 2007-10-04 03:26:51 UTC - RP225 - Deckard's System Scanner Restore Point123: 2007-10-04 02:00:20 UTC - RP224 - Installed Google Toolbar for Internet Explorer122: 2007-10-04 01:58:02 UTC - RP223 - Installed Java 6 Update 3121: 2007-10-04 01:55:52 UTC - RP222 - Removed Java 2 Runtime Environment, SE v1.4.2_03120: 2007-10-04 01:49:09 UTC - RP221 - System Checkpoint-- First Restore Point -- 1: 2007-07-07 03:22:38 UTC - RP102 - System CheckpointBacked up registry hives.Performed disk cleanup.-- HijackThis (run as Pete's.exe) ----------------------------------------------Logfile of HijackThis v1.99.1Scan saved at 8:29:25 PM, on 10/3/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16512)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exec:\Program Files\Common Files\Symantec Shared\ccSetMgr.exec:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exeC:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exec:\Program Files\Common Files\Symantec Shared\ccProxy.exeC:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exec:\Program Files\Norton AntiVirus\navapsvc.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\M-Audio Uno\UnoInst.exeC:\Program Files\Viewpoint\Common\ViewpointService.exeC:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\wscntfy.exeC:\WINDOWS\System32\svchost.exeC:\windows\system\hpsysdrv.exeC:\Program Files\HP\hpcoretech\hpcmpmgr.exeC:\WINDOWS\System32\hphmon05.exeC:\WINDOWS\system32\VTTimer.exeC:\Program Files\Common Files\Symantec Shared\ccApp.exeC:\WINDOWS\AGRSMMSG.exeC:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exeC:\Program Files\HP\HP Software Update\HPWuSchd2.exeC:\HP\KBD\KBD.EXEC:\Program Files\Lexmark 2400 Series\lxcrmon.exeC:\Program Files\Lexmark 2400 Series\ezprint.exeC:\Program Files\iTunes\iTunesHelper.exeC:\windows\system32\lrdsrngo.exeC:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exeC:\WINDOWS\system32\lxcrcoms.exeC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\Program Files\Messenger\msmsgs.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exeC:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exeC:\Program Files\HP\Digital Imaging\bin\hpqtra08.exeC:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXEC:\Program Files\WiFiConnector\NintendoWFCReg.exeC:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exeC:\Program Files\iPod\bin\iPodService.exeC:\Program Files\Google\GoogleToolbarNotifier\1.2.911.3380\GoogleToolbarNotifier.exeC:\Documents and Settings\Pete's\Desktop\dss.exeC:\DOCUME~1\Pete's\MYDOCU~1\HIGHJA~1\Pete's.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktopR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhostO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocxO2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dllO2 - BHO: StumbleUpon Launcher - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dllO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dllO2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dllO2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - c:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dllO2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dllO2 - BHO: (no name) - {B62F5B2F-FB3C-45BC-97BF-9EBE1A61AED4} - C:\WINDOWS\system32\awvtr.dll (file missing)O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dllO3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dllO3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dllO3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dllO3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dllO3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - c:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dllO4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exeO4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exeO4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exeO4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXEO4 - HKLM\..\Run: [VTTimer] VTTimer.exeO4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"O4 - HKLM\..\Run: [updateManager] "c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /rO4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exeO4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exeO4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exeO4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exeO4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXEO4 - HKLM\..\Run: [lxcrmon.exe] "C:\Program Files\Lexmark 2400 Series\lxcrmon.exe"O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2400 Series\ezprint.exe"O4 - HKLM\..\Run: [LXCRCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll,_RunDLLEntry@16O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"O4 - HKLM\..\Run: [{08-8B-BF-FC-ZN}] C:\windows\system32\lrdsrngo.exe CHD003O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimizedO4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osbootO4 - HKLM\..\Run: [spyHunter] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exeO4 - HKLM\..\Run: [ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exeO4 - HKLM\..\Run: [C2K] C:\WINDOWS\Cyb2k.exeO4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /backgroundO4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - HKCU\..\Run: [backupNotify] c:\Program Files\HP\Digital Imaging\bin\backupnotify.exeO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.911.3380\GoogleToolbarNotifier.exeO4 - Startup: PowerReg Scheduler V3.exeO4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\lrdsrngo.exeO4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exeO4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXEO4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exeO4 - Global Startup: Run Nintendo Wi-Fi USB Connector Registration Tool.lnk = C:\Program Files\WiFiConnector\NintendoWFCReg.exeO4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exeO8 - Extra context menu item: Download all links using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htmO8 - Extra context menu item: Download all videos using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htmO8 - Extra context menu item: Download link using &BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htmO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000O8 - Extra context menu item: Open in New &Window (PopOops) - C:\WINDOWS\Web\PopOops.htmO8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimageO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dllO9 - Extra button: Panda ActiveScan - {653D93AF-C741-4e5e-8C1B-59BA43F93E16} - http://www.pandasoftware.com/activescan (file missing)O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLLO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO11 - Options group: [iNTERNATIONAL] International*O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dllO15 - Trusted Zone: *.stumbleupon.comO16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cabO16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cabO16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cabO16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cabO16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cabO16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1187204501375O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cabO16 - DPF: {A954AFC3-3A26-44C2-A126-2B61C09F8FC9} (SNRecovery Control) - http://www.cybersitter.com/recovery/ocx/SerialRecovery.ocxO16 - DPF: {C52439A0-2693-4E40-B141-9F9AD5257241} (Lexmark eDiagnostics Class) - https://ediagnostics.lexmark.com/serval.cabO16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cabO20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dllO20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dllO21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dllO23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeO23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exeO23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exeO23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exeO23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exeO23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeO23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exeO23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exeO23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeO23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\endhwnev.exe (file missing)O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exeO23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exeO23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exeO23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXEO23 - Service: lxcr_device - - C:\WINDOWS\system32\lxcrcoms.exeO23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exeO23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exeO23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exeO23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exeO23 - Service: Uno Installer (UnoInstallerService) - Unknown owner - C:\Program Files\M-Audio Uno\UnoInst.exeO23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exeO23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe-- HijackThis Fixed Entries (C:\DOCUME~1\Pete's\MYDOCU~1\HIGHJA~1\backups\) ----backup-20070726-153724-152 O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXEbackup-20070726-153724-372 O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)backup-20070726-153724-455 O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)-- File Associations -----------------------------------------------------------All associations okay.-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------R3 dsreader (MaxDrive Driver (dsreader.sys)) - c:\windows\system32\drivers\dsreader.sys <Not Verified; Thesycon GmbH, Germany; Universal USB Device Driver>R3 Eplpdx02 - c:\windows\system32\drivers\eplpdx02.sys <Not Verified; MK Systems CO., LTD.; MK Systems LPT I/O Driver for Windows2000>R3 Iviaspi (IVI ASPI Shell) - c:\windows\system32\drivers\iviaspi.sys <Not Verified; InterVideo, Inc.; InterVideo ASPI Shell>R3 Pfc (Padus ASPI Shell) - c:\windows\system32\drivers\pfc.sys <Not Verified; Padus, Inc.; Padus® ASPI Shell>S3 EVOLUSB (%EVOL_USB_SvcDesc%) - c:\windows\system32\drivers\evolusb.sys <Not Verified; Evolution Electronics Ltd.; Evolution USB MIDI Keyboard Interface>S3 ialm - c:\windows\system32\drivers\ialmnt5.sys <Not Verified; Intel Corporation; Intel Graphics Accelerator Drivers for Windows NT®>S3 pnicml - c:\docume~1\owner\locals~1\temp\pnicml.sys (file missing)S3 RT25USBAP (Nintendo Wi-Fi USB Connector Service) - c:\windows\system32\drivers\rt25usbap.sys <Not Verified; Ralink Technology Inc.; Ralink 802.11g Wireless USB Adapters>S3 samhid - c:\windows\system32\drivers\samhid.sysS3 USBIO (USBIO Driver (usbio.sys)) - c:\windows\system32\drivers\usbio.sys <Not Verified; Thesycon GmbH, Germany; Universal USB Device Driver>-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>R2 EPSONStatusAgent2 (EPSON Printer Status Agent2) - c:\program files\common files\epson\ebapi\sagent2.exe <Not Verified; SEIKO EPSON CORPORATION; EPSON Bidirectional Printer>R2 UnoInstallerService (Uno Installer) - c:\program files\m-audio uno\unoinst.exe <Not Verified; ; EvoUno USB Installer Service>R2 Viewpoint Manager Service - "c:\program files\viewpoint\common\viewpointservice.exe" <Not Verified; Viewpoint Corporation; Viewpoint Manager>S2 DomainService - c:\windows\system32\endhwnev.exe /service (file missing)S3 Imapi Helper - "c:\program files\alex feinman\iso recorder\imapihelper.exe" <Not Verified; Alex Feinman; ISO Recorder>-- Device Manager: Disabled ----------------------------------------------------Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}Description: 1394 Net AdapterDevice ID: V1394\NIC1394\78232CE01800Manufacturer: MicrosoftName: 1394 Net AdapterPNP Device ID: V1394\NIC1394\78232CE01800Service: NIC1394Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}Description: Nintendo Wi-Fi USB ConnectorDevice ID: USB\VID_0411&PID_008B00D0BF817B3Manufacturer: NintendoName: Nintendo Wi-Fi USB ConnectorPNP Device ID: USB\VID_0411&PID_008B00D0BF817B3Service: RT25USBAP-- Scheduled Tasks -------------------------------------------------------------2007-09-28 20:00:00 530 --a------ C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - Owner.job2007-09-14 15:16:34 532 --a------ C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - Pete's.job2007-09-07 21:40:03 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job-- Files created between 2007-09-03 and 2007-10-03 -----------------------------2007-10-03 19:00:24 0 d-------- C:\Documents and Settings\All Users\Application Data\Google2007-10-03 15:22:27 75328 --a------ C:\WINDOWS\system32\mktmaqqr.exe <Not Verified; ; DDC>2007-10-02 20:03:15 75328 --a------ C:\WINDOWS\system32\qnrdligo.exe <Not Verified; ; DDC>2007-10-02 19:37:17 75328 --a------ C:\WINDOWS\system32\vbedxlfp.exe <Not Verified; ; DDC>2007-10-02 18:19:16 75328 --a------ C:\WINDOWS\system32\ahviptds.exe <Not Verified; ; DDC>2007-10-02 18:09:04 75328 --a------ C:\WINDOWS\system32\xxnlcsrd.exe <Not Verified; ; DDC>2007-10-02 17:36:26 75328 --a------ C:\WINDOWS\system32\ndekpepp.exe <Not Verified; ; DDC>2007-10-02 16:16:13 75328 --a------ C:\WINDOWS\system32\eulumrfo.exe <Not Verified; ; DDC>2007-10-02 16:01:14 75328 --a------ C:\WINDOWS\system32\gstjwlkt.exe <Not Verified; ; DDC>2007-10-02 15:16:08 75328 --a------ C:\WINDOWS\system32\inmkcpar.exe <Not Verified; ; DDC>2007-10-01 20:46:58 75328 --a------ C:\WINDOWS\system32\jqhfuoni.exe <Not Verified; ; DDC>2007-10-01 19:08:22 75328 --a------ C:\WINDOWS\system32\nmxlnhnc.exe <Not Verified; ; DDC>2007-10-01 18:15:22 75328 --a------ C:\WINDOWS\system32\jnknllyr.exe <Not Verified; ; DDC>2007-10-01 18:14:13 75328 --a------ C:\WINDOWS\system32\mmaooktc.exe <Not Verified; ; DDC>2007-10-01 16:30:40 75328 --a------ C:\WINDOWS\system32\bsluyvwr.exe <Not Verified; ; DDC>2007-10-01 16:25:45 75328 --a------ C:\WINDOWS\system32\ntggmhid.exe <Not Verified; ; DDC>2007-10-01 15:34:59 75328 --a------ C:\WINDOWS\system32\nlmsodpx.exe <Not Verified; ; DDC>2007-10-01 15:16:06 75328 --a------ C:\WINDOWS\system32\gcwsbvlu.exe <Not Verified; ; DDC>2007-09-30 20:59:46 75328 --a------ C:\WINDOWS\system32\nytijdmq.exe <Not Verified; ; DDC>2007-09-30 20:46:09 75328 --a------ C:\WINDOWS\system32\pkwfiwiu.exe <Not Verified; ; DDC>2007-09-30 20:16:39 75328 --a------ C:\WINDOWS\system32\mftjvkml.exe <Not Verified; ; DDC>2007-09-30 19:31:43 75328 --a------ C:\WINDOWS\system32\vkpgfubx.exe <Not Verified; ; DDC>2007-09-30 18:58:26 75328 --a------ C:\WINDOWS\system32\clshtinn.exe <Not Verified; ; DDC>2007-09-30 18:36:07 75328 --a------ C:\WINDOWS\system32\vkvxdctr.exe <Not Verified; ; DDC>2007-09-30 18:30:23 75328 --a------ C:\WINDOWS\system32\nlgtiqni.exe <Not Verified; ; DDC>2007-09-30 17:59:50 75328 --a------ C:\WINDOWS\system32\exjqctyt.exe <Not Verified; ; DDC>2007-09-30 17:55:42 75328 --a------ C:\WINDOWS\system32\eyqkyona.exe <Not Verified; ; DDC>2007-09-30 17:34:19 75328 --a------ C:\WINDOWS\system32\dtgufwfa.exe <Not Verified; ; DDC>2007-09-30 16:16:59 75328 --a------ C:\WINDOWS\system32\qgrwbayc.exe <Not Verified; ; DDC>2007-09-30 15:59:22 75328 --a------ C:\WINDOWS\system32\iaumboxl.exe <Not Verified; ; DDC>2007-09-30 15:26:17 75328 --a------ C:\WINDOWS\system32\jhqryvml.exe <Not Verified; ; DDC>2007-09-30 15:20:39 75328 --a------ C:\WINDOWS\system32\swbrwtwe.exe <Not Verified; ; DDC>2007-09-30 15:18:30 75328 --a------ C:\WINDOWS\system32\bqlfceno.exe <Not Verified; ; DDC>2007-09-30 14:48:36 75328 --a------ C:\WINDOWS\system32\ujweeaqf.exe <Not Verified; ; DDC>2007-09-30 14:12:42 75328 --a------ C:\WINDOWS\system32\jqrqjknw.exe <Not Verified; ; DDC>2007-09-30 13:48:08 75328 --a------ C:\WINDOWS\system32\uyslucpl.exe <Not Verified; ; DDC>2007-09-30 13:40:12 75328 --a------ C:\WINDOWS\system32\luhijkbe.exe <Not Verified; ; DDC>2007-09-30 13:15:39 75328 --a------ C:\WINDOWS\system32\bnrgfcyy.exe <Not Verified; ; DDC>2007-09-30 13:10:55 75328 --a------ C:\WINDOWS\system32\yccdhise.exe <Not Verified; ; DDC>2007-09-30 12:55:19 75328 --a------ C:\WINDOWS\system32\jbbqigeg.exe <Not Verified; ; DDC>2007-09-30 12:49:42 75328 --a------ C:\WINDOWS\system32\hkasakfa.exe <Not Verified; ; DDC>2007-09-30 12:06:31 75328 --a------ C:\WINDOWS\system32\brjchwdp.exe <Not Verified; ; DDC>2007-09-30 11:57:51 75328 --a------ C:\WINDOWS\system32\ofgjvyml.exe <Not Verified; ; DDC>2007-09-30 11:56:37 75328 --a------ C:\WINDOWS\system32\tsmqyvox.exe <Not Verified; ; DDC>2007-09-30 11:08:16 75328 --a------ C:\WINDOWS\system32\ljqsrqve.exe <Not Verified; ; DDC>2007-09-30 10:57:47 75328 --a------ C:\WINDOWS\system32\auojsluu.exe <Not Verified; ; DDC>2007-09-30 10:19:36 75328 --a------ C:\WINDOWS\system32\svoxxjaj.exe <Not Verified; ; DDC>2007-09-30 08:28:19 75328 --a------ C:\WINDOWS\system32\irgjxtbq.exe <Not Verified; ; DDC>2007-09-30 08:26:25 75328 --a------ C:\WINDOWS\system32\wmtehaik.exe <Not Verified; ; DDC>2007-09-29 21:34:08 75328 --a------ C:\WINDOWS\system32\dmeaxavy.exe <Not Verified; ; DDC>2007-09-29 21:14:15 75328 --a------ C:\WINDOWS\system32\xbnkugnj.exe <Not Verified; ; DDC>2007-09-29 20:27:59 75328 --a------ C:\WINDOWS\system32\rplckioe.exe <Not Verified; ; DDC>2007-09-29 20:14:07 75328 --a------ C:\WINDOWS\system32\tmiocnua.exe <Not Verified; ; DDC>2007-09-29 19:54:32 0 d-------- C:\New Folder <NEWFOL~1>2007-09-29 19:48:58 75328 --a------ C:\WINDOWS\system32\gwarlmjd.exe <Not Verified; ; DDC>2007-09-29 19:44:37 75328 --a------ C:\WINDOWS\system32\eerpwahc.exe <Not Verified; ; DDC>2007-09-29 19:32:22 75328 --a------ C:\WINDOWS\system32\elxnqvoj.exe <Not Verified; ; DDC>2007-09-29 19:15:58 75328 --a------ C:\WINDOWS\system32\ifilaykf.exe <Not Verified; ; DDC>2007-09-29 19:06:16 75328 --a------ C:\WINDOWS\system32\efijtflg.exe <Not Verified; ; DDC>2007-09-29 19:01:59 75328 --a------ C:\WINDOWS\system32\cytcdlhu.exe <Not Verified; ; DDC>2007-09-29 18:31:30 75328 --a------ C:\WINDOWS\system32\phuswosl.exe <Not Verified; ; DDC>2007-09-29 18:21:59 75328 --a------ C:\WINDOWS\system32\nxswlcth.exe <Not Verified; ; DDC>2007-09-29 17:33:30 75328 --a------ C:\WINDOWS\system32\rhuywycq.exe <Not Verified; ; DDC>2007-09-29 17:08:10 75328 --a------ C:\WINDOWS\system32\qdnqemek.exe <Not Verified; ; DDC>2007-09-29 16:26:46 75328 --a------ C:\WINDOWS\system32\ilgorkbs.exe <Not Verified; ; DDC>2007-09-29 16:24:32 75328 --a------ C:\WINDOWS\system32\mvwuhpyy.exe <Not Verified; ; DDC>2007-09-29 16:20:08 75328 --a------ C:\WINDOWS\system32\mnvqvxqd.exe <Not Verified; ; DDC>2007-09-29 15:06:19 75328 --a------ C:\WINDOWS\system32\morlxjsw.exe <Not Verified; ; DDC>2007-09-29 14:58:20 75328 --a------ C:\WINDOWS\system32\vmddfldq.exe <Not Verified; ; DDC>2007-09-29 14:28:11 75328 --a------ C:\WINDOWS\system32\yfgmjans.exe <Not Verified; ; DDC>2007-09-29 14:16:33 0 d-------- C:\Program Files\VOCALOID22007-09-29 14:13:28 200704 --a------ C:\WINDOWS\system32\libguide40.dll <Not Verified; Intel Corporation; Guide Run-time Library>2007-09-29 14:13:28 4874240 --a------ C:\WINDOWS\system32\DSE2_DFT.dll2007-09-29 13:43:05 75328 --a------ C:\WINDOWS\system32\lrkyepii.exe <Not Verified; ; DDC>2007-09-29 12:14:47 75328 --a------ C:\WINDOWS\system32\vybuqhef.exe <Not Verified; ; DDC>2007-09-29 12:04:48 0 d-------- C:\Program Files\Undisker2007-09-29 12:00:18 75328 --a------ C:\WINDOWS\system32\krovexcx.exe <Not Verified; ; DDC>2007-09-29 11:49:28 75328 --a------ C:\WINDOWS\system32\keelhdht.exe <Not Verified; ; DDC>2007-09-29 11:47:25 75328 --a------ C:\WINDOWS\system32\okkqwucj.exe <Not Verified; ; DDC>2007-09-29 11:41:39 75328 --a------ C:\WINDOWS\system32\wiqxdsji.exe <Not Verified; ; DDC>2007-09-29 11:38:16 75328 --a------ C:\WINDOWS\system32\jqgrwaju.exe <Not Verified; ; DDC>2007-09-29 11:33:34 75328 --a------ C:\WINDOWS\system32\dtieeaar.exe <Not Verified; ; DDC>2007-09-29 11:26:47 75328 --a------ C:\WINDOWS\system32\waysmhch.exe <Not Verified; ; DDC>2007-09-29 11:11:01 75328 --a------ C:\WINDOWS\system32\tvalsolt.exe <Not Verified; ; DDC>2007-09-29 11:05:10 0 d-------- C:\Program Files\Alex Feinman2007-09-29 10:46:29 0 d-------- C:\Program Files\LSoft Technologies2007-09-29 10:29:33 75328 --a------ C:\WINDOWS\system32\vgxulvfy.exe <Not Verified; ; DDC>2007-09-28 23:40:03 75328 --a------ C:\WINDOWS\system32\igorrulb.exe <Not Verified; ; DDC>2007-09-28 20:37:38 75328 --a------ C:\WINDOWS\system32\whkdomlt.exe <Not Verified; ; DDC>2007-09-28 20:21:35 75328 --a------ C:\WINDOWS\system32\piwknnky.exe <Not Verified; ; DDC>2007-09-28 19:04:25 75328 --a------ C:\WINDOWS\system32\jmeybmff.exe <Not Verified; ; DDC>2007-09-28 19:03:27 75328 --a------ C:\WINDOWS\system32\nytqlkjb.exe <Not Verified; ; DDC>2007-09-28 17:39:09 75328 --a------ C:\WINDOWS\system32\kagomquy.exe <Not Verified; ; DDC>2007-09-28 17:11:02 75328 --a------ C:\WINDOWS\system32\ffabrlrf.exe <Not Verified; ; DDC>2007-09-28 17:04:59 75328 --a------ C:\WINDOWS\system32\rdpdrmkd.exe <Not Verified; ; DDC>2007-09-28 16:58:07 75328 --a------ C:\WINDOWS\system32\jrhyrarb.exe <Not Verified; ; DDC>2007-09-28 16:20:40 75328 --a------ C:\WINDOWS\system32\eymbrmsr.exe <Not Verified; ; DDC>2007-09-28 16:15:28 75328 --a------ C:\WINDOWS\system32\myyuullp.exe <Not Verified; ; DDC>2007-09-28 16:07:14 75328 --a------ C:\WINDOWS\system32\ygepxnrr.exe <Not Verified; ; DDC>2007-09-28 15:49:17 75328 --a------ C:\WINDOWS\system32\jwfiwyxh.exe <Not Verified; ; DDC>2007-09-28 15:44:38 0 d-------- C:\Program Files\Steinberg2007-09-28 15:40:38 75328 --a------ C:\WINDOWS\system32\vvqsyiph.exe <Not Verified; ; DDC>2007-09-28 15:20:25 0 d-------- C:\Program Files\VOCALOID2007-09-28 06:04:48 75328 --a------ C:\WINDOWS\system32\xcradfwd.exe <Not Verified; ; DDC>2007-09-27 19:31:19 75328 --a------ C:\WINDOWS\system32\opwychlt.exe <Not Verified; ; DDC>2007-09-27 19:29:19 75328 --a------ C:\WINDOWS\system32\djnjbxwa.exe <Not Verified; ; DDC>2007-09-27 19:13:33 75328 --a------ C:\WINDOWS\system32\pholwlhi.exe <Not Verified; ; DDC>2007-09-25 09:24:13 75328 --a------ C:\WINDOWS\system32\nwyujmlo.exe <Not Verified; ; DDC>2007-09-24 15:13:30 75328 --a------ C:\WINDOWS\system32\apmsycwe.exe <Not Verified; ; DDC>2007-09-23 10:25:09 75328 --a------ C:\WINDOWS\system32\jhucgsqq.exe <Not Verified; ; DDC>2007-09-23 09:47:13 75328 --a------ C:\WINDOWS\system32\ycqtcafr.exe <Not Verified; ; DDC>2007-09-22 16:03:02 75328 --a------ C:\WINDOWS\system32\jkkvduqk.exe <Not Verified; ; DDC>2007-09-22 13:26:43 75328 --a------ C:\WINDOWS\system32\boxavbkc.exe <Not Verified; ; DDC>2007-09-22 12:38:59 75328 --a------ C:\WINDOWS\system32\aefwwuws.exe <Not Verified; ; DDC>2007-09-22 12:32:41 75328 --a------ C:\WINDOWS\system32\cctxiiuq.exe <Not Verified; ; DDC>2007-09-22 09:51:41 75328 --a------ C:\WINDOWS\system32\mvkfprvf.exe <Not Verified; ; DDC>2007-09-21 15:29:49 75328 --a------ C:\WINDOWS\system32\hipqwplj.exe <Not Verified; ; DDC>2007-09-21 15:20:10 75328 --a------ C:\WINDOWS\system32\qyykmltg.exe <Not Verified; ; DDC>2007-09-21 15:16:24 75328 --a------ C:\WINDOWS\system32\tmipuitg.exe <Not Verified; ; DDC>2007-09-20 20:46:18 0 d-------- C:\Program Files\Windows Media Connect 22007-09-20 20:41:12 0 d-------- C:\WINDOWS\system32\drivers\UMDF2007-09-20 15:15:23 75328 --a------ C:\WINDOWS\system32\vrdxyxpw.exe <Not Verified; ; DDC>2007-09-19 21:14:50 75328 --a------ C:\WINDOWS\system32\jcsnoxqh.exe <Not Verified; ; DDC>2007-09-18 20:08:33 75328 --a------ C:\WINDOWS\system32\mjnkdjaj.exe <Not Verified; ; DDC>2007-09-18 15:15:50 75328 --a------ C:\WINDOWS\system32\qodplpty.exe <Not Verified; ; DDC>2007-09-17 15:17:32 75328 --a------ C:\WINDOWS\system32\welcgytu.exe <Not Verified; ; DDC>2007-09-16 13:08:13 75328 --a------ C:\WINDOWS\system32\dcmgpqws.exe <Not Verified; ; DDC>2007-09-15 11:33:28 75328 --a------ C:\WINDOWS\system32\hviiscyv.exe <Not Verified; ; DDC>2007-09-15 09:32:44 75328 --a------ C:\WINDOWS\system32\arvgymlv.exe <Not Verified; ; DDC>2007-09-14 18:42:58 75328 --a------ C:\WINDOWS\system32\epxkwvnh.exe <Not Verified; ; DDC>2007-09-13 18:42:10 75328 --a------ C:\WINDOWS\system32\wvexemju.exe <Not Verified; ; DDC>2007-09-13 15:40:22 75328 --a------ C:\WINDOWS\system32\smnovfjs.exe <Not Verified; ; DDC>2007-09-13 15:17:57 75328 --a------ C:\WINDOWS\system32\hdktltgh.exe <Not Verified; ; DDC>2007-09-12 20:52:33 75328 --a------ C:\WINDOWS\system32\nbrjikvu.exe <Not Verified; ; DDC>2007-09-12 16:22:37 75328 --a------ C:\WINDOWS\system32\qdjmedpk.exe <Not Verified; ; DDC>2007-09-12 15:41:27 0 d-------- C:\dsgm_output12_9_2007_15-41-1872007-09-12 15:19:10 75328 --a------ C:\WINDOWS\system32\jtmgxxft.exe <Not Verified; ; DDC>2007-09-11 15:19:02 75328 --a------ C:\WINDOWS\system32\pjneskhn.exe <Not Verified; ; DDC>2007-09-10 15:22:28 75328 --a------ C:\WINDOWS\system32\evpifsox.exe <Not Verified; ; DDC>2007-09-09 12:15:04 75328 --a------ C:\WINDOWS\system32\ghtycdpm.exe <Not Verified; ; DDC>2007-09-09 11:28:53 75328 --a------ C:\WINDOWS\system32\ivtbgpno.exe <Not Verified; ; DDC>2007-09-09 10:26:08 75328 --a------ C:\WINDOWS\system32\piwvirvs.exe <Not Verified; ; DDC>2007-09-08 21:50:14 75328 --a------ C:\WINDOWS\system32\yiiudiot.exe <Not Verified; ; DDC>2007-09-08 13:53:13 75328 --a------ C:\WINDOWS\system32\ocytqrfr.exe <Not Verified; ; DDC>2007-09-08 12:48:07 75328 --a------ C:\WINDOWS\system32\ybkgdrqq.exe <Not Verified; ; DDC>2007-09-08 10:45:30 75328 --a------ C:\WINDOWS\system32\ghomkhnq.exe <Not Verified; ; DDC>2007-09-08 09:07:44 0 d-------- C:\Program Files\Norton Personal Firewall2007-09-08 09:02:44 75328 --a------ C:\WINDOWS\system32\jlnoinpq.exe <Not Verified; ; DDC>2007-09-07 16:08:15 75328 --a------ C:\WINDOWS\system32\jdsrouhr.exe <Not Verified; ; DDC>2007-09-07 15:19:55 75328 --a------ C:\WINDOWS\system32\ocxyahga.exe <Not Verified; ; DDC>2007-09-06 20:12:08 75328 --a------ C:\WINDOWS\system32\rhelayjj.exe <Not Verified; ; DDC>2007-09-06 19:32:47 75328 --a------ C:\WINDOWS\system32\slfugsrx.exe <Not Verified; ; DDC>2007-09-06 16:48:22 75328 --a------ C:\WINDOWS\system32\unxudbtl.exe <Not Verified; ; DDC>2007-09-06 15:27:17 75328 --a------ C:\WINDOWS\system32\jhbyyphq.exe <Not Verified; ; DDC>-- Find3M Report ---------------------------------------------------------------2007-10-03 19:34:19 0 d-------- C:\Documents and Settings\Pete's\Application Data\Google2007-10-03 19:00:24 0 d-------- C:\Program Files\Google2007-10-03 18:59:03 0 d-------- C:\Program Files\Java2007-10-03 17:39:35 0 d-------- C:\Program Files\Common Files\Symantec Shared2007-10-03 17:38:20 0 d-------- C:\Program Files\Common Files2007-10-02 18:18:46 0 d-------- C:\Program Files\Norton AntiVirus2007-10-02 18:18:10 0 d-------- C:\Program Files\M-Audio Uno2007-10-02 18:17:45 0 d-------- C:\Program Files\Lexmark 2400 Series2007-10-02 18:17:37 0 d-------- C:\Program Files\iTunes2007-10-02 18:17:18 0 d-------- C:\Program Files\Messenger2007-10-02 18:17:11 0 d-------- C:\Program Files\WiFiConnector2007-10-02 18:17:06 0 d-------- C:\Program Files\StumbleUpon2007-10-02 18:17:06 0 d-------- C:\Program Files\Lexmark Toolbar2007-10-02 16:00:06 28 --a------ C:\WINDOWS\liccyval.dat2007-09-30 16:32:37 0 d-------- C:\Documents and Settings\Pete's\Application Data\NetMedia Providers2007-09-29 14:53:40 0 d-------- C:\Program Files\lx_cats2007-09-29 14:20:17 0 d--h----- C:\Program Files\InstallShield Installation Information2007-09-29 13:36:15 0 d-------- C:\Documents and Settings\Pete's\Application Data\InstallShield2007-09-29 11:13:44 0 d-------- C:\Documents and Settings\Pete's\Application Data\uTorrent2007-09-29 10:37:38 0 d-------- C:\Program Files\MagicISO2007-09-28 15:52:58 2246 --a------ C:\WINDOWS\system32\wzfil.dll2007-09-28 15:52:56 6050 --a------ C:\WINDOWS\system32\wrestfil.dll2007-09-28 15:52:56 4162 --a------ C:\WINDOWS\system32\viofil.dll2007-09-28 15:52:56 5782 --a------ C:\WINDOWS\system32\vgamfil.dll2007-09-28 15:52:56 1656 --a------ C:\WINDOWS\system32\tapfil.dll2007-09-28 15:52:56 14712 --a------ C:\WINDOWS\system32\tafil.dll2007-09-28 15:52:56 6830 --a------ C:\WINDOWS\system32\swfil.dll2007-09-28 15:52:56 258 --a------ C:\WINDOWS\system32\srchout.dll2007-09-28 15:52:56 3444 --a------ C:\WINDOWS\system32\srchin.dll2007-09-28 15:52:56 540 --a------ C:\WINDOWS\system32\srchfrgn.dll2007-09-28 15:52:56 12266 --a------ C:\WINDOWS\system32\sporfil.dll2007-09-28 15:52:56 724 --a------ C:\WINDOWS\system32\spmfil.dll2007-09-28 15:52:56 592 --a------ C:\WINDOWS\system32\snetfil.dll2007-09-28 15:52:54 157916 --a------ C:\WINDOWS\system32\pxyfil.dll2007-09-28 15:52:54 12730 --a------ C:\WINDOWS\system32\psyfil.dll2007-09-28 15:52:54 16802 --a------ C:\WINDOWS\system32\popfil.dll2007-09-28 15:52:54 9634 --a------ C:\WINDOWS\system32\pkmon.dll2007-09-28 15:52:54 306 --a------ C:\WINDOWS\system32\picsfil.dll2007-09-28 15:52:54 22618 --a------ C:\WINDOWS\system32\perfil.dll2007-09-28 15:52:52 17488 --a------ C:\WINDOWS\system32\nvgamfil.dll2007-09-28 15:52:52 116 --a------ C:\WINDOWS\system32\nfil.dll2007-09-28 15:52:52 670 --a------ C:\WINDOWS\system32\mp3fil.dll2007-09-28 15:52:52 7778 --a------ C:\WINDOWS\system32\movfil.dll2007-09-28 15:52:52 34 --a------ C:\WINDOWS\system32\macfil.dll2007-09-28 15:52:52 3286 --a------ C:\WINDOWS\system32\lgwfil.dll2007-09-28 15:52:52 18 --a------ C:\WINDOWS\system32\lastupdate.dll2007-09-28 15:52:52 8652 --a------ C:\WINDOWS\system32\jbfil.dll2007-09-28 15:52:52 1100 --a------ C:\WINDOWS\system32\imgfil.dll2007-09-28 15:52:52 194 --a------ C:\WINDOWS\system32\igefil.dll2007-09-28 15:52:52 5180 --a------ C:\WINDOWS\system32\iawfil.dll2007-09-28 15:52:52 4442 --a------ C:\WINDOWS\system32\hatfil.dll2007-09-28 15:52:52 9796 --a------ C:\WINDOWS\system32\gnfil.dll2007-09-28 15:52:50 1482 --a------ C:\WINDOWS\system32\gdwfil.dll2007-09-28 15:52:50 13070 --a------ C:\WINDOWS\system32\gblfil.dll2007-09-28 15:52:50 1816 --a------ C:\WINDOWS\system32\fshrfil.dll2007-09-28 15:52:50 11338 --a------ C:\WINDOWS\system32\fmfil.dll2007-09-28 15:52:50 13154 --a------ C:\WINDOWS\system32\finfil.dll2007-09-28 15:52:50 12422 --a------ C:\WINDOWS\system32\entfil.dll2007-09-28 15:52:50 1830 --a------ C:\WINDOWS\system32\cultfil.dll2007-09-28 15:52:50 1790 --a------ C:\WINDOWS\system32\csnews.dll2007-09-28 15:52:50 10906 --a------ C:\WINDOWS\system32\chtfil.dll2007-09-28 15:52:50 400 --a------ C:\WINDOWS\system32\bsnlst.dll2007-09-28 15:52:50 100 --a------ C:\WINDOWS\system32\bnrfil.dll2007-09-28 15:52:48 7642 --a------ C:\WINDOWS\system32\auctfil.dll2007-09-28 15:52:48 88076 --a------ C:\WINDOWS\system32\adwfil.dll2007-09-20 20:17:00 0 d-------- C:\Program Files\AviSynth 2.52007-09-17 16:11:43 0 d-------- C:\Program Files\Common Files\InstallShield2007-09-08 09:06:45 0 d-------- C:\Program Files\Symantec2007-09-06 16:47:53 0 d-------- C:\Program Files\ImTOO2007-08-30 09:40:34 75328 --a------ C:\WINDOWS\system32\ggtlanbv.exe <Not Verified; ; DDC>2007-08-29 21:53:33 75328 --a------ C:\WINDOWS\system32\psaatulw.exe <Not Verified; ; DDC>2007-08-29 18:04:57 75328 --a------ C:\WINDOWS\system32\nbvvkwmv.exe <Not Verified; ; DDC>2007-08-29 16:42:22 75328 --a------ C:\WINDOWS\system32\jkmvqdvq.exe <Not Verified; ; DDC>2007-08-29 15:23:50 75328 --a------ C:\WINDOWS\system32\gftjimxs.exe <Not Verified; ; DDC>2007-08-29 10:58:58 75328 --a------ C:\WINDOWS\system32\miwlgref.exe <Not Verified; ; DDC>2007-08-29 10:24:18 75328 --a------ C:\WINDOWS\system32\ybtnyfoq.exe <Not Verified; ; DDC>2007-08-28 21:37:42 75328 --a------ C:\WINDOWS\system32\gctaebqn.exe <Not Verified; ; DDC>2007-08-28 19:52:52 75328 --a------ C:\WINDOWS\system32\tkdivwyj.exe <Not Verified; ; DDC>2007-08-28 19:49:19 75328 --a------ C:\WINDOWS\system32\orkjkxgb.exe <Not Verified; ; DDC>2007-08-28 19:22:52 75328 --a------ C:\WINDOWS\system32\bknruawb.exe <Not Verified; ; DDC>2007-08-28 16:26:46 75328 --a------ C:\WINDOWS\system32\hbdrbtnn.exe <Not Verified; ; DDC>2007-08-28 16:08:18 75328 --a------ C:\WINDOWS\system32\uffskdaf.exe <Not Verified; ; DDC>2007-08-28 13:12:31 75328 --a------ C:\WINDOWS\system32\ifjunyfo.exe <Not Verified; ; DDC>2007-08-28 11:27:35 75328 --a------ C:\WINDOWS\system32\xmpvefnn.exe <Not Verified; ; DDC>2007-08-27 15:45:35 0 d-------- C:\Program Files\Real2007-08-27 15:44:12 0 d-------- C:\Program Files\Windows Live2007-08-24 18:40:38 0 d-------- C:\Program Files\HP2007-08-24 16:52:11 0 d-------- C:\Documents and Settings\Pete's\Application Data\Macromedia2007-08-23 12:38:54 52766 --a------ C:\WINDOWS\system32\lrdsrngo.exe <Not Verified; ; Browser Driver>2007-08-20 12:50:18 0 d-------- C:\Program Files\Accursed Toys2007-08-19 15:54:07 0 d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.22007-08-19 15:04:54 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard2007-08-17 10:50:28 3648 --a------ C:\WINDOWS\system32\giisjvor.dll2007-08-15 10:30:30 75328 --a------ C:\WINDOWS\system32\nvhxjugb.exe <Not Verified; ; DDC>2007-08-15 10:13:41 52765 --a------ C:\WINDOWS\system32\lkdsrngm.exe <Not Verified; ; Browser Driver>2007-08-14 19:51:07 0 d-------- C:\Program Files\SpywareBlaster2007-08-14 19:26:53 934 --a------ C:\WINDOWS\system32\winpfz32.sys2007-08-14 13:56:50 0 d-------- C:\Program Files\LimeWire2007-08-14 08:32:34 52759 --a------ C:\WINDOWS\system32\lndsrngo.exe <Not Verified; ; Browser Driver>2007-08-13 21:11:55 52756 --a------ C:\WINDOWS\system32\dwdsrngt.exe <Not Verified; ; Browser Driver>2007-08-13 21:11:54 40183 ---hs---- C:\Program Files\Common Files\Yazzle1281OinUninstaller.exe2007-08-13 21:11:34 31254 -----n--- C:\WINDOWS\system32\xxyyywt.dll2007-08-13 19:02:00 0 d-------- C:\Program Files\iPod2007-08-13 18:02:08 0 d-------- C:\Program Files\QuickTime2007-08-13 18:00:19 0 d-------- C:\Program Files\Apple Software Update2007-08-13 17:59:42 0 d-------- C:\Program Files\Common Files\Apple2007-08-04 13:21:54 0 d-------- C:\Program Files\Lenogo iPod to PC Transfer2007-08-03 13:52:22 0 d-------- C:\Program Files\StepMania2007-08-01 09:31:18 9045 ---hs---- C:\WINDOWS\system32\hjkkj.bak22007-07-31 08:19:01 6506 ---hs---- C:\WINDOWS\system32\hjkkj.bak12007-07-26 09:27:47 1099004 --a------ C:\Documents and Settings\Pete's\Application Data\Install.dat2007-07-25 21:26:12 22907904 --a------ C:\ledbackground <LEDBAC~1>2007-07-25 08:22:55 1733912 ---hs---- C:\WINDOWS\system32\ijllm.bak22007-07-24 17:44:42 23 --a------ C:\Documents and Settings\Pete's\Application Data\Download.url2007-07-24 17:19:22 6466 ---hs---- C:\WINDOWS\system32\ijllm.bak12007-07-24 17:19:04 228960 --a------ C:\WINDOWS\system32\mllji.dll2007-07-24 17:13:49 31254 --a------ C:\WINDOWS\system32\iifcaay.dll-- Registry Dump ---------------------------------------------------------------*Note* empty entries & legit default entries are not shown[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B62F5B2F-FB3C-45BC-97BF-9EBE1A61AED4}] C:\WINDOWS\system32\awvtr.dll[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [05/07/1998 05:04 PM]"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [01/12/2005 02:54 PM]"HPHUPD05"="c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [08/21/2003 04:23 AM]"HPHmon05"="C:\WINDOWS\System32\hphmon05.exe" [08/21/2003 04:15 AM]"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [04/14/2004 01:43 PM]"VTTimer"="VTTimer.exe" [01/15/2004 09:33 PM C:\WINDOWS\system32\VTTimer.exe]"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [03/09/2006 11:47 AM]"UpdateManager"="c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [08/19/2003 02:01 AM]"AGRSMMSG"="AGRSMMSG.exe" [03/04/2005 12:01 PM C:\WINDOWS\AGRSMMSG.exe]"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [11/30/2004 10:10 PM]"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [02/11/2005 06:24 PM]"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [02/16/2005 11:11 PM]"KBD"="C:\HP\KBD\KBD.EXE" [02/02/2005 04:44 PM]"lxcrmon.exe"="C:\Program Files\Lexmark 2400 Series\lxcrmon.exe" [03/06/2006 01:48 PM]"EzPrint"="C:\Program Files\Lexmark 2400 Series\ezprint.exe" [02/07/2006 01:10 AM]"LXCRCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll" [02/24/2006 07:54 AM]"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [06/29/2007 06:24 AM]"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [07/31/2007 06:44 PM]"{08-8B-BF-FC-ZN}"="C:\windows\system32\lrdsrngo.exe" [08/23/2007 12:38 PM]"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [06/11/2007 02:25 AM]"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [08/25/2004 07:07 PM]"SpyHunter"="C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exe" []"Ink Monitor"="C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe" [10/16/2001 11:10 AM]"C2K"="C:\WINDOWS\Cyb2k.exe" [08/03/2004 10:47 AM]"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [09/25/2007 01:11 AM][HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [10/13/2004 09:24 AM]"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [06/29/2007 06:24 AM]"BackupNotify"="c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe" [01/09/2004 02:34 AM]"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 12:56 AM]"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.911.3380\GoogleToolbarNotifier.exe" [10/03/2007 07:00 PM]C:\Documents and Settings\Pete's\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe [2/3/2007 7:40:21 PM] TA_Start.lnk - C:\WINDOWS\system32\lrdsrngo.exe [8/23/2007 12:38:54 PM]C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe [1/2/2005 4:50:01 PM]EPSON Status Monitor 3 Environment Check 2.lnk - C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE [8/22/2004 12:45:32 PM]HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [9/16/2003 1:19:24 PM]Run Nintendo Wi-Fi USB Connector Registration Tool.lnk - C:\Program Files\WiFiConnector\NintendoWFCReg.exe [12/9/2006 7:08:41 PM]Updates from HP.lnk - C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe [4/1/2004 2:16:45 PM][HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]"DisableRegistryTools"=0 (0x0)"Wallpaper"=[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]"NoActiveDesktop"=0 (0x0)"ForceActiveDesktopOn"=0 (0x0)[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]@="Service"[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]@="Volume shadow copy"[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]AutoRun\command- D:\Info.exe folder.htt 480 480[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4d11b6a8-9432-11db-acf2-000d0bf817b3}]AutoRun\command- L:\setupSNK.exe-- Hosts -----------------------------------------------------------------------127.0.0.1 ad.a8.net127.0.0.1 asy.a8ww.net127.0.0.1 www.aaa-livedoor.net #[Trojan-PSW.Win32.Maran.ei]127.0.0.1 www.abcsearcher.com #[spamdexing][Microsoft.Strider]127.0.0.1 abc-search.info127.0.0.1 abloga.info #[spamdexing]127.0.0.1 www.abx4.com #[Adware.ABXToolbar]127.0.0.1 www.acezip.net #[Win32/Adware.180Solutions]127.0.0.1 phpadsnew.abac.com127.0.0.1 a.abnad.net16031 more entries in hosts file.-- End of Deckard's System Scanner: finished at 2007-10-03 20:31:20 ------------ Link to post Share on other sites
kohu Posted October 4, 2007 Author Report Share Posted October 4, 2007 And heres the extra.txt from DSSDeckard's System Scanner v20070905.67Extra logfile - please post this as an attachment with your post.---------------------------------------------------------------------------------- System Information ----------------------------------------------------------Microsoft Windows XP Home Edition (build 2600) SP 2.0Architecture: X86; Language: EnglishCPU 0: AMD Athlon XP 3200+Percentage of Memory in Use: 61%Physical Memory (total/avail): 511.48 MiB / 194.61 MiBPagefile Memory (total/avail): 1246.98 MiB / 861.57 MiBVirtual Memory (total/avail): 2047.88 MiB / 1962.48 MiBC: is Fixed (NTFS) - 144.25 GiB total, 61.21 GiB free. D: is Fixed (FAT32) - 4.79 GiB total, 0.62 GiB free. E: is CDROM (CDFS)F: is CDROM (CDFS)H: is Removable (No Media)I: is Removable (No Media)J: is Removable (No Media)K: is Removable (No Media)L: is Removable (No Media)\\.\PHYSICALDRIVE0 - ST3160021A - 149.05 GiB - 2 partitions \PARTITION0 - Unknown - 4.79 GiB - D: \PARTITION1 (bootable) - Installable File System - 144.25 GiB - C:\\.\PHYSICALDRIVE5 - Generic STORAGE DEVICE USB Device\\.\PHYSICALDRIVE2 - Generic USB CF Reader USB Device\\.\PHYSICALDRIVE4 - Generic USB MS Reader USB Device\\.\PHYSICALDRIVE1 - Generic USB SD Reader USB Device\\.\PHYSICALDRIVE3 - Generic USB SM Reader USB Device-- Security Center -------------------------------------------------------------AUOptions is scheduled to auto-install.Windows Internal Firewall is enabled.FW: Norton Personal Firewall v2004 (Symantec Corporation) DisabledAV: Norton AntiVirus v2004 (Symantec Corporation) Outdated[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019""C:\\Program Files\\Updates from HP\\137903\\Program\\BackWeb-137903.exe"="C:\\Program Files\\Updates from HP\\137903\\Program\\BackWeb-137903.exe:*:Disabled:BackWeb-137903""C:\\Program Files\\Kazaa Lite K++\\KazaaLite.kpp"="C:\\Program Files\\Kazaa Lite K++\\KazaaLite.kpp:*:Enabled:KazaaLite""C:\\Program Files\\Microsoft Games\\Zoo Tycoon 2\\zt.exe"="C:\\Program Files\\Microsoft Games\\Zoo Tycoon 2\\zt.exe:*:Enabled:Zoo Tycoon 2 Executable""C:\\WINDOWS\\system32\\lxcrcoms.exe"="C:\\WINDOWS\\system32\\lxcrcoms.exe:*:Enabled:Lexmark Communications System""C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"="C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe:*:Enabled:Sid Meier's Civilization 4""C:\\Program Files\\WiFiConnector\\NintendoWFCReg.exe"="C:\\Program Files\\WiFiConnector\\NintendoWFCReg.exe:*:Enabled:Nintendo Wi-Fi USB Connector""C:\\Program Files\\EA Games\\The Battle for Middle-earth \\game.dat"="C:\\Program Files\\EA Games\\The Battle for Middle-earth \\game.dat:*:Enabled:The Battle for Middle-earth ""C:\\WINDOWS\\Cyb2k.exe"="C:\\WINDOWS\\Cyb2k.exe:*:Disabled:CYBERsitter Control Panel""C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Disabled:eMule""C:\\Program Files\\MAIET\\Gunz\\GunzLauncher.exe"="C:\\Program Files\\MAIET\\Gunz\\GunzLauncher.exe:*:Enabled:GunzLauncher""C:\\Documents and Settings\\Pete's\\Desktop\\emu-rom\\7737_Win2DS0.5\\Win2DS.exe"="C:\\Documents and Settings\\Pete's\\Desktop\\emu-rom\\7737_Win2DS0.5\\Win2DS.exe:*:Enabled:Win2DS""C:\\Program Files\\BitComet\\BitComet.exe"="C:\\Program Files\\BitComet\\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client""C:\\Program Files\\uTorrent\\utorrent.exe"="C:\\Program Files\\uTorrent\\utorrent.exe:*:Enabled:µTorrent""C:\\Documents and Settings\\Pete's\\Desktop\\DSHobro\\DSHobro.exe"="C:\\Documents and Settings\\Pete's\\Desktop\\DSHobro\\DSHobro.exe:*:Enabled:DSHobro""C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes""C:\\WINDOWS\\system32\\fnnryqgn.exe"="C:\\WINDOWS\\system32\\fnn""C:\\WINDOWS\\system32\\endhwnev.exe"="C:\\WINDOWS\\system32\\end""C:\\Documents and Settings\\Pete's\\Desktop\\DS ROMS\\dshobro03\\Server.exe"="C:\\Documents and Settings\\Pete's\\Desktop\\DS ROMS\\dshobro03\\Server.exe:*:Enabled:Server"-- Environment Variables -------------------------------------------------------ALLUSERSPROFILE=C:\Documents and Settings\All UsersAPPDATA=C:\Documents and Settings\Pete's\Application DataCLASSPATH=.;C:\Program Files\Java\j2re1.4.2_03\lib\ext\QTJava.zipCLIENTNAME=ConsoleCOLLECTIONID=COL8143CommonProgramFiles=C:\Program Files\Common FilesCOMPUTERNAME=SHADOWComSpec=C:\WINDOWS\system32\cmd.exeDEVKITARM=/c/devkitPro/devkitARMDEVKITPPC=/c/devkitPro/devkitPPCDEVKITPRO=/c/devkitProDEVKITPSP=/c/devkitPro/devkitPSPFP_NO_HOST_CHECK=NOHMSERVER=https://h30083.www3.hp.com/wuss/servlet/WUSSServletHOMEDRIVE=C:HOMEPATH=\Documents and Settings\Pete'sITEMID=dj-22741-6LANG=1033LOGONSERVER=\\SHADOWNUMBER_OF_PROCESSORS=1OS=Windows_NTOSVER=winXPHPAPATH=c:/devkitPro/PAlib/Path=c:\devkitPro\msys\bin;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;c:\Python22;C:\Program Files\PC-Doctor for Windows\services;C:\Program Files\ATI Technologies\ATI Control Panel;C:\Program Files\QuickTime\QTSystem\PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSHPROCESSOR_ARCHITECTURE=x86PROCESSOR_IDENTIFIER=x86 Family 6 Model 10 Stepping 0, AuthenticAMDPROCESSOR_LEVEL=6PROCESSOR_REVISION=0a00ProgramFiles=C:\Program FilesPROMPT=$P$GQTJAVA=C:\Program Files\Java\j2re1.4.2_03\lib\ext\QTJava.zipSESSIONID=1098426280950wuws04-l1e1be92:ffbf4e2f8a:3c80SESSIONNAME=ConsoleSWUTVER=1.0.22.20030804SystemDrive=C:SystemRoot=C:\WINDOWSTEMP=C:\DOCUME~1\Pete's\LOCALS~1\TempTIMEOUT=0TMP=C:\DOCUME~1\Pete's\LOCALS~1\TempTOOLPATH=/c:\Program%20Files\HP\HP%20Software%20Update\install.htmUPDATEDIR=C:\DOCUME~1\Owner\LOCALS~1\Temp\rad0131D.tmpUSERDOMAIN=SHADOWUSERNAME=Pete'sUSERPROFILE=C:\Documents and Settings\Pete'sVERSION=3.0.2.97windir=C:\WINDOWS__COMPAT_LAYER=EnableNXShowUI -- User Profiles ---------------------------------------------------------------Owner (admin)Pete's (admin)Kid (new local, admin)Administrator (admin)-- Add/Remove Programs --------------------------------------------------------- --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0 --> C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{39DA87A1-0B26-4562-A70C-2A6147366E47}\Setup.exe" --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9F765BD0-B900-4EDE-A90B-61C8A9E95C42}\Setup.exe" --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BAD59025-5B73-4E12-B789-0028C5A573C2}\Setup.exe" --> c:\WINDOWS\System32\\MSIEXEC.EXE /I {09DA4F91-2A09-4232-AB8C-6BC740096DE3} REMOVE=UpdateMgrFeature --> c:\WINDOWS\System32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19} --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.infATI - Software Uninstall Utility --> C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exeATI Control Panel --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe" ATI DVD Decoder 2.2.0.0 --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{45D228AA-4284-467A-9DB6-942B92BFF656} /l1033 ATI Display Driver --> rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -cleanATI HYDRAVISION --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{083F79E4-6FE9-46FB-A6C6-4F8862742947}\setup.exe" ATI Multimedia Center 8.6.0.0 --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{B7DC0CAF-0D27-4ACE-8E34-8594C8D7C1DB} /l1033 AVG Anti-Spyware 7.5 --> C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Uninstall.exeAction Replay Code Manager --> "C:\Program Files\Datel\Action Replay Code Manager\unins000.exe"Active@ ISO Burner v 1.1 --> "C:\Program Files\LSoft Technologies\Active ISO Burner\UNWISE.EXE" "C:\Program Files\LSoft Technologies\Active ISO Burner\INSTALL.LOG"Adobe Acrobat - Reader 6.0.2 Update --> MsiExec.exe /I{AC76BA86-0000-0000-0000-6028747ADE01}Adobe Acrobat 4.0 --> C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Common Files\Adobe\Acrobat 4.0\NT\Uninst.isu" -c"C:\Program Files\Common Files\Adobe\Acrobat 4.0\NT\Uninst.dll"Adobe Acrobat 4.0, 5.0 --> C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.isu" -c"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.dll"Adobe ActiveShare 1.2 --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Adobe\ActiveShare\Uninst.isu"Adobe Atmosphere Player for Acrobat and Adobe Reader --> C:\WINDOWS\atmoUn.exeAdobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exeAdobe PhotoDeluxe Home Edition 4.0 --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Adobe\PhotoDeluxe Home Edition 4.0\Uninst.isu"Adobe Reader 6.0.1 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A00000000001}Advanced Batch Converter --> "C:\Program Files\Advanced Batch Converter\uninstall.exe"Age of Empires III --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{7B9CC60A-9B81-46A3-A953-76B6BF9EEC97} Agere Systems PCI Soft Modem --> agrsmdelApple Mobile Device Support --> MsiExec.exe /I{967D588C-9B96-40C9-A222-DCD6922563CA}Apple Software Update --> MsiExec.exe /I{492724FC-3B26-46B4-824F-3CE2722D9AA0}Audacity 1.2.6 --> "C:\Program Files\Audacity\unins000.exe"AviSynth 2 (remove only) --> "C:\Program Files\AviSynth 2.5\uninst.exe"AviSynth 2.5 --> "C:\Program Files\AviSynth 2.5\Uninstall.exe"Black & White® 2 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\110\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D9E52CD1-9DF1-4A8A-9BDC-1E5E53982F2B}\setup.exe" -l0x9 -removeonlyBlackhawk Striker from Hewlett-Packard Desktops (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\E28167F1-3F42-40C7-9119-1D5A97444F10\Uninstall.exe"Blasterball 2 from Hewlett-Packard Desktops (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\8C4E79CC-03E1-43AA-9910-9A5113F24603\Uninstall.exe"Bounce Symphony from Hewlett-Packard Desktops (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\D11F7128-8CBD-408B-8BF8-034604DEDD42\Uninstall.exe"CC_ccProxyMSI --> MsiExec.exe /I{A398F2DC-D706-4bb2-AC38-5532CD229D08}CC_ccStart --> MsiExec.exe /I{2357DF2D-4CF0-4BD7-826F-4EB396B3567E}Civilization III --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{2157961D-0507-44A8-BCF2-1EE2D439E8DF} Clever Batch Image Converter 1.8.18 alpha --> "C:\Program Files\Clever Batch Image Converter\unins000.exe"Crystal Maze from Hewlett-Packard Desktops (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\DAE7A92A-BAC7-42FA-AC62-53DEF1DC4292\Uninstall.exe"DAO --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{C88E49AA-41C5-4420-A08D-BE1B6C5A3A74} Darwinia Demo2 --> "C:\Program Files\DarwiniaDemo2\unins000.exe"DivX Player --> C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYERDivX Pro Trial --> C:\Program Files\DivX\DivXCodecUninstall.exe /CODECEPSON Printer Software --> C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /rEasy Graphic Converter 1.2 --> "C:\Program Files\Easy Graphic Converter\unins000.exe"Enhanced Multimedia Keyboard Solution --> C:\HP\KBD\Install.exe /uFLV Converter 3 --> C:\Program Files\ImTOO\FLV Converter 3\Uninstall.exeFive Card Frenzy from Hewlett-Packard Desktops (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\DA44615A-C243-46A4-8E47-184CFF33CD38\Uninstall.exe"Free WMA to MP3 Converter 1.16 --> "C:\Program Files\Free WMA to MP3 Converter\unins000.exe"G6 Save Converter v0.33 --> rundll32.exe dfshim.dll,ShArpMaintain G6 Save Converter v0.33.application, Culture=neutral, PublicKeyToken=7285edd9a976dba3, processorArchitecture=msilGGE909 PC Recoil Pad --> C:\PROGRA~1\GAMEEL~1\GGE909~1\UNWISE.EXE C:\PROGRA~1\GAMEEL~1\GGE909~1\INSTALL.LOGGdiplusUpgrade --> MsiExec.exe /I{5421155F-B033-49DB-9B33-8F80F233D4D5}Ghost Recon --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D89EF3B3-6F17-4665-B7A9-A4235A6DC787}\Setup.exe" Google Earth --> RunDll32 C:\DOCUME~1\Pete's\APPLIC~1\INSTAL~1\PROFES~1\RunTime\101\Intel32\Ctor.dll,LaunchSetup "C:\Documents and Settings\Pete's\Application Data\InstallShield Installation Information\{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}\setup.exe" -l0x9 -removeonlyGoogle Earth --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\101\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}\setup.exe" -l0x9 -removeonlyGoogle Toolbar for Internet Explorer --> MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}Google Toolbar for Internet Explorer --> regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"Google Video Player --> "C:\Pete'ss programs\Google\Google Video Player\Uninstall.exe"HP Image Zone 3.5 --> C:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.datHP Image Zone Plus 3.5 --> C:\Program Files\HP\Digital Imaging\{C6C44651-7C66-4b11-92E8-17565D3D22DD}\setup\hpzscr01.exe -datfile hpdscr01.datHP Instant Support --> C:\PROGRA~1\HPINST~1\UNWISE.EXE C:\PROGRA~1\HPINST~1\INSTALL.LOGHP PSC & OfficeJet 3.5 --> "C:\Program Files\HP\Digital Imaging\{0FABD3D7-3036-4e78-B29D-58957ADB0A12}\setup\hpzscr01.exe" -datfile hposcr03.datHP Photo & Imaging 3.5 - HP Devices --> C:\Program Files\HP\Digital Imaging\{15B9DC72-73F9-4d99-9E28-848D66DA8D99}\setup\hpzscr01.exe -datfile hpiscr01.datHP Software Update --> MsiExec.exe /X{15EE79F4-4ED1-4267-9B0F-351009325D7D}HP Update --> MsiExec.exe /X{8C6027FD-53DC-446D-BB75-CACD7028A134}HPIZ350 --> MsiExec.exe /X{F247869D-3643-4A9F-821B-3534145928E3}HijackThis 1.99.1 --> C:\Documents and Settings\Pete's\My Documents\highjackthis\HijackThis.exe /uninstallHotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"How To Master Excel 2000 --> C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\Uninst.isuISO Recorder --> MsiExec.exe /I{DFC6573E-124D-4026-BFA4-B433C9D3FF21}Impossible Creatures --> "C:\Program Files\Microsoft Games\Impossible Creatures\UNINSTAL.EXE" /runtemp /addremoveImpossible Creatures 1.0.1 --> MsiExec.exe /X{6B2B0D05-2B4A-4855-A47B-D69CD9E3CDD6}Ink Monitor --> C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe -UInterVideo WinDVD Creator 2 --> "C:\Program Files\InstallShield Installation Information\{2FCE4FC5-6930-40E7-A4F1-F862207424EF}\setup.exe" REMOVEALLInterVideo WinDVD Player --> "C:\Program Files\InstallShield Installation Information\{98E8A2EF-4EAE-43B8-A172-74842B764777}\setup.exe" REMOVEALLItsDeductible Express --> MsiExec.exe /X{36495C59-089C-49D1-BD15-9E5BD86DC9A1}Java 6 Update 2 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}Java 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}Kazaa Lite K++ v2.4.3 --> "C:\Program Files\Kazaa Lite K++\unins000.exe"Kazoo Player --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\LightWork Design\Kazoo Player\Uninst.isu"Lenogo iPod to PC Transfer v3.0 --> "C:\Program Files\Lenogo iPod to PC Transfer\unins000.exe"Lexmark 2400 Series --> C:\Program Files\Lexmark 2400 Series\Install\x86\Uninst.exeLexmark Toolbar --> regsvr32.exe /s /u "C:\Program Files\Lexmark Toolbar\toolband.dll"Line Adventures 1.0 --> "C:\Program Files\Line Adventures\unins000.exe"LiveReg (Symantec Corporation) --> C:\Program Files\Common Files\Symantec Shared\LiveReg\VcSetup.exe /REMOVELiveUpdate 3.0 (Symantec Corporation) --> "C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /ULords of the Realm III --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7C1EAF33-82AD-4A63-B56D-4739172714DF}\Setup.exe" -l0x9 M&Ms The Lost Formulas --> C:\Program Files\M&Ms The Lost Formulas\Unwise.exeMAIET entertainment - Gunz --> C:\Program Files\MAIET\Gunz\Uninstall.exeMAX DS Video Converter --> "C:\Program Files\Datel\MAX DS Video Converter\unins000.exe"MAX DS Video Converter --> "C:\Program Files\Datel\MAX DS Video Converter\unins000.exe"MSN Music Assistant --> rundll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\msninst.inf,UninstallMSRedist --> MsiExec.exe /I{FC37ABD0-2108-4beb-B010-1254E0662B5A}Magic ISO Maker v5.4 (build 0251) --> C:\PROGRA~1\MagicISO\UNWISE.EXE C:\PROGRA~1\MagicISO\INSTALL.LOGMall Tycoon 2 --> C:\WINDOWS\Mall Tycoon 2 Uninstaller.exeMemories Disc Creator 2.0 --> MsiExec.exe /X{2E132061-C78A-48D4-A899-1D13B9D189FA}Microsoft Calculator Plus --> MsiExec.exe /I{83073C45-3003-4671-9A86-243AAADD915A}Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"Microsoft Data Access Components KB870669 --> C:\WINDOWS\muninst.exe C:\WINDOWS\INF\KB870669.infMicrosoft Money 2004 --> MsiExec.exe /I{1D643CD7-4DD6-11D7-A4E0-000874180BB3}Microsoft Money 2004 System Pack --> MsiExec.exe /I{8C64E145-54BA-11D6-91B1-00500462BE80}Microsoft Office Professional Edition 2003 --> MsiExec.exe /I{91E30409-6000-11D3-8CFE-0150048383C9}Microsoft Plus! Digital Media Edition --> MsiExec.exe /I{C6A7AF96-4EB1-4AAE-8318-1AB393C64F88}Microsoft Text-to-Speech Engine 4.0 (English) --> RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\msTTS.inf, UninstallMicrosoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"Microsoft Works 7.0 --> MsiExec.exe /I{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}Mozilla Firefox (2.0.0.7) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exeNeed For Speed Hot Pursuit 2 --> C:\Program Files\EA Games\Need For Speed Hot Pursuit 2\EAUninstall.exeNintendo DS - GBA Max Drive --> "C:\Program Files\Datel\Nintendo DS - GBA Max Drive\unins000.exe"Nintendo Wi-Fi USB Connector Registration Tool --> C:\Program Files\WiFiConnector\SoftAPUninst.exeNorton AntiVirus 2004 (Symantec Corporation) --> C:\Program Files\Common Files\Symantec Shared\SymSetup\{C6F5B6CF-609C-428E-876F-CA83176C021B}.exe /XNorton AntiVirus 2004 --> MsiExec.exe /X{C6F5B6CF-609C-428E-876F-CA83176C021B}Norton AntiVirus Parent MSI --> MsiExec.exe /I{E5EE9939-259F-4DE2-8023-5C49E16A4F43}Norton Internet Security --> MsiExec.exe /I{12E2B9E9-05B1-407d-B0FD-B5F350535125}Norton Internet Security --> MsiExec.exe /I{48185814-A224-447a-81DA-71BD20580E1B}Norton Internet Security --> MsiExec.exe /I{526AD5DC-CFC4-4f2a-8442-C84CC91D6C7F}Norton Internet Security --> MsiExec.exe /I{88770EA7-9E8F-483C-ADDB-5F633691C036}Norton Internet Security --> MsiExec.exe /I{91AA4B1F-B918-4e0b-A304-F8D4EC5D7726}Norton Internet Security --> MsiExec.exe /I{C9D599E1-6B68-4a1f-8A4F-A1DB433DB1BF}Norton Internet Security --> MsiExec.exe /I{FC2C0536-583C-46c0-844A-62CECAE01F22}Norton Personal Firewall (Symantec Corporation) --> C:\Program Files\Common Files\Symantec Shared\SymSetup\{3BD0196C-6553-460c-A0C4-90D8AE5D60D2}.exe /XNorton Personal Firewall --> MsiExec.exe /I{3BD0196C-6553-460c-A0C4-90D8AE5D60D2}Norton WMI Update --> MsiExec.exe /X{1526D87C-A955-4FAB-BF18-697BA457E352}Orbital from Hewlett-Packard Desktops (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\62067F4C-84A9-45B9-8573-B90468B0A3EF\Uninstall.exe"Otto from Hewlett-Packard Desktops (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\BFBCBAE3-8293-4215-9C4F-C2402C118EDB\Uninstall.exe"Overball from Hewlett-Packard Desktops (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\6723E59E-322A-417A-8E03-27A61E18253C\Uninstall.exe"PC-Doctor for Windows --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1F7CCFA3-D926-4882-B2A5-A0217ED25597}\Setup.exe" PS2 --> C:\WINDOWS\system32\ps2.exe uninstallPaint.NET v3.08 --> MsiExec.exe /X{83B26E5D-1795-4DFE-9317-0FA0F3AAB568}Panda ActiveScan --> C:\WINDOWS\system32\ASUninst.exe Panda ActiveScanPcsx2 0.9.2 Watermoose --> "C:\Program Files\Pcsx2\unins000.exe"Photosmart 140,240,7200,7600,7700,7900 Series --> C:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\setup\hpzscr01.exe -datfile hphscr01.datPolar Bowler from Hewlett-Packard Desktops (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\36317AE4-57EC-4F3E-B828-009A3DD96BE8\Uninstall.exe"Pop-Up Stopper Free Edition --> C:\PROGRA~1\PANICW~1\POP-UP~1\UNWISE.EXE C:\PROGRA~1\PANICW~1\POP-UP~1\INSTALL.LOGProject64 1.6 --> MsiExec.exe /X{9559F7CA-5E34-4237-A2D9-D856464AD727}QuickTime --> MsiExec.exe /I{95A890AA-B3B1-44B6-9C18-A8F7AB3EE7FC}RealPlayer --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0RecordNow! --> MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19}Rhapsody Player Engine --> MsiExec.exe /I{8A62A068-3FD6-495A-9F66-26FE94F32EC9}Rhinoceros 3.0 Evaluation --> C:\PROGRA~1\RHINOC~1.0EV\System\Unwise.exe C:\PROGRA~1\RHINOC~1.0EV\System\Install.logRiva Producer Lite --> "C:\Program Files\Riva\Riva Producer Lite\unins000.exe"Roll --> C:\WINDOWS\UniFish3.exe C:\Program Files\Hasbro Interactive\RollerCoaster Tycoon\RollerCoaster Tycoon.logRoller Coaster Tycoon --> C:\PROGRA~1\INFOGR~2\ROLLER~1\UNWISE.EXE C:\PROGRA~1\INFOGR~2\ROLLER~1\INSTALL.LOGRollerCoaster Tycoon 2 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{72DF62BD-FF36-424E-AA5F-D89BAFF2C249}\Setup.exe" -l0x9 S3 S3Display --> vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Display'S3 S3Gamma2 --> vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Gamma2'S3 S3Info2 --> vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Info2'S3 S3Overlay --> vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Overlay'SC Ver 2.60 --> "C:\Program Files\SC\unins000.exe"Security Update for CAPICOM (KB931906) --> MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}Security Update for CAPICOM (KB931906) --> MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}Security Update for Step By Step Interactive Training (KB898458) --> "C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"Security Update for Step By Step Interactive Training (KB923723) --> "C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"Sid Meier's Civilization 4 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\110\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CFBCE791-2D53-4FCE-B3FB-D6E01F4112E8}\setup.exe" -l0x9 -removeonlySid Meier's Pirates! --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{1632FD86-1BA4-4FC4-8B25-A8C655D63F68} /l1033 Slyder from Hewlett-Packard Desktops (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\C2C3C2DB-7D8A-4E20-B527-E3149FAECC3A\Uninstall.exe"Smart Popup Blocker version 1.10 --> "C:\Program Files\SmartPopupBlocker\unins000.exe"Sonic Update Manager --> MsiExec.exe /I{09DA4F91-2A09-4232-AB8C-6BC740096DE3}Sony ACID Music Studio 6.0b --> MsiExec.exe /X{D4A823CA-D124-456E-9A98-71544A928897}SpongeBob SquarePants - The Movie --> RunDll32 C:\DOCUME~1\Pete's\APPLIC~1\INSTAL~1\PROFES~1\RunTime701\Intel32\Ctor.dll,LaunchSetup "C:\Documents and Settings\Pete's\Application Data\InstallShield Installation Information\{B98D958E-9E59-43B7-B47F-043D45D73EE6}\setup.exe" -l0x9 -uninst Spybot - Search & Destroy 1.4 --> "C:\Program Files\Spybot - Search & Destroy\unins000.exe"SpywareBlaster v3.5.1 --> "C:\Program Files\SpywareBlaster\unins000.exe"Street Atlas USA Deluxe --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3409AD65-7A2A-46D4-8F07-DB1508B9158D}\setup.exe" NoModeStumbleUpon IE Toolbar --> C:\Program Files\StumbleUpon\uninstall.exeThe Battle for Middle-earth --> C:\Program Files\EA GAMES\The Battle for Middle-earth \EAUninstall.exeThe Hobbit --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{023FFB0A-C5DB-4930-B3E4-D48266C21738} Toolkit View(HP) --> c:\Windows\HPTK\unhptkit.exeTotal Video Converter 3.01 --> "C:\Program Files\Total Video Converter\unins000.exe"Tradewinds from Hewlett-Packard Desktops (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\F5215F01-DFC0-475D-A910-6F1AF94E807E\Uninstall.exe"TurboTax 2005 --> C:\Program Files\TurboTax\Deluxe 2005\TaxUnst.EXE "C:\Program Files\TurboTax\Deluxe 2005\Uninstall.log" -NoGuiTurboTax Deluxe 2004 --> C:\Program Files\TurboTax\Deluxe 2004\TaxUnst.EXE "C:\Program Files\TurboTax\Deluxe 2004\Uninstall.log" -NoGuiTurboTax ItsDeductible 2005 --> MsiExec.exe /X{2E7595EC-4FB1-4E29-93D4-9083C8A9B107}UltraISO V7.25 ME --> "C:\Program Files\UltraISO\unins000.exe"UniChrome IGP Driver and Utilities --> C:\PROGRA~1\S3\S3\s3setvga.exe -s -fC:\PROGRA~1\S3\S3\S3.unsUno --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime91\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F8E28912-A7B8-488C-B259-33F9014B9D09}\setup.exe" -l0x9 Updates from HP --> C:\WINDOWS\BWUnin-6.2.3.66.exe -AppId 137903VIA Rhine-Family Fast Ethernet Adapter --> Rundll32.exe vuins32.dll,vuins32Ex $Rhine $VIAVOCALOID Editor V1.1.1.0 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B123B3B1-C2A0-47E7-AAAB-D1E2DBE259CB}\setup.exe" -l0x9 VOCALOID Expression DB (Miriam) --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{44F77FBE-828D-4B04-A02B-C70426F65C86}\setup.exe" -l0x9 VOCALOID Expression DB (Standard) --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9B89EB0D-68C3-4E5D-A705-CD8D37DABF50}\setup.exe" -l0x9 VOCALOID SKIN (Zero-G MIRIAM) --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8BBB3758-6759-4086-835B-1D665DBE979F}\setup.exe" -l0x9 VOCALOID VSTi V1.1.1.0 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FAC611DA-E445-4D7A-8311-7389C627FA32}\setup.exe" -l0x9 VOCALOID Voice DB (Miriam) --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{146303B2-EA46-4BFB-8054-FC75A0D0088B}\setup.exe" -l0x9 VOCALOID2 Editor V2.0.2.4J --> C:\Program Files\InstallShield Installation Information\{F1C1C21B-F56E-400B-B0B0-270D817889F3}\setup.exe -runfromtemp -l0x0009 -removeonlyVOCALOID2 Expression DB (Standard) --> C:\Program Files\InstallShield Installation Information\{B6588186-9657-486C-AEB1-F57D8E160F19}\setup.exe -runfromtemp -l0x0009 -removeonlyVOCALOID2 VSTi V2.0.2.0 --> C:\Program Files\InstallShield Installation Information\{A95FF0B9-5CFB-497E-8872-3A5F41AD9D4F}\setup.exe -runfromtemp -l0x0009 -removeonlyVOCALOID2 Voice DB (Miku) --> C:\Program Files\InstallShield Installation Information\{B4342A07-E2C7-4A8B-9145-CBDEE750BCE3}\setup.exe -runfromtemp -l0x0009 -removeonlyVideo to Audio Converter 3 --> C:\Program Files\ImTOO\Video to Audio Converter 3\Uninstall.exeViewpoint Manager (Remove Only) --> C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgrInstaller.exe /u /kVolvo Ocean Race 2005 --> "C:\Program Files\Virtual Spectator\Volvo Ocean Race 2005\unins000.exe"WexTech AnswerWorks --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EA2BEBD6-87B9-41E5-95AC-7E4C165A9475}\SETUP.EXE" -l0x9 -eliminateWhere Am I Dataset --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3A202CE5-2F2C-484F-B43E-523943D68E68}\setup.exe" NoModeWinISO 5.3 --> "C:\Program Files\WinISO\unins000.exe"Windows Live Sign-in Assistant --> MsiExec.exe /I{CB5EA99C-8A5B-49F2-9A1A-2EF78BE4DB41}Windows Live installer --> MsiExec.exe /X{7BC43F11-02C8-45FA-ABDC-E2F9FF31F825}Windows Media Encoder 9 Series --> MsiExec.exe /I{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}Windows Media Encoder 9 Series --> msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"Word Symphony from Hewlett-Packard Desktops (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\B8610D19-E576-4F91-8A2F-07898D9CA301\Uninstall.exe"Zoo Tycoon 2 --> "C:\Program Files\Microsoft Games\Zoo Tycoon 2\UNINSTAL.EXE" /runtemp /uninstallZoo Tycoon 2 Patch --> "C:\Program Files\Microsoft Games\Zoo Tycoon 2\UNINSTPA.EXE" /runtemp /uninstallccCommon --> MsiExec.exe /I{11D504D0-FF9D-423F-BF00-7E93FBB57EEA}devkitProUpdater 1.4.2 --> c:\devkitPro\uninst.exeiPod for Windows 2005-11-17 --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{8338BA06-E527-491B-9400-F51708FEE695} /l1033 iTunes --> MsiExec.exe /I{E0219810-16E4-437D-9165-93D7B22524F9}ips XP 1.11.2600 --> "C:\Program Files\ipsXP\unins000.exe"ips XP 1.11.2600 --> "C:\Program Files\ipsXP\unins000.exe"overland --> MsiExec.exe /I{766273C1-A39B-47EB-ACE8-DEBDD8094BCC}-- Application Event Log -------------------------------------------------------Event Record #/Type6800 / ErrorEvent Submitted/Written: 10/03/2007 06:19:53 PMEvent ID/Source: 1002 / Application HangEvent Description:Hanging application iexplore.exe, version 7.0.6000.16512, hang module hungapp, version 0.0.0.0, hang address 0x00000000.Event Record #/Type6799 / ErrorEvent Submitted/Written: 10/03/2007 06:19:27 PMEvent ID/Source: 1002 / Application HangEvent Description:Hanging application iexplore.exe, version 7.0.6000.16512, hang module hungapp, version 0.0.0.0, hang address 0x00000000.Event Record #/Type6798 / ErrorEvent Submitted/Written: 10/03/2007 06:19:17 PMEvent ID/Source: 1002 / Application HangEvent Description:Hanging application iexplore.exe, version 7.0.6000.16512, hang module hungapp, version 0.0.0.0, hang address 0x00000000.Event Record #/Type6797 / ErrorEvent Submitted/Written: 10/03/2007 06:18:36 PMEvent ID/Source: 1002 / Application HangEvent Description:Hanging application iexplore.exe, version 7.0.6000.16512, hang module hungapp, version 0.0.0.0, hang address 0x00000000.Event Record #/Type6772 / ErrorEvent Submitted/Written: 10/03/2007 05:31:47 PMEvent ID/Source: 1015 / WinlogonEvent Description:A critical system process, C:\WINDOWS\system32\lsass.exe, failed with status code 00000000. The machinemust now be restarted.-- Security Event Log ----------------------------------------------------------No Errors/Warnings found.-- System Event Log ------------------------------------------------------------Event Record #/Type14667 / ErrorEvent Submitted/Written: 10/03/2007 06:56:19 PMEvent ID/Source: 7023 / Service Control ManagerEvent Description:The Application Management service terminated with the following error: %%126Event Record #/Type14664 / ErrorEvent Submitted/Written: 10/03/2007 06:56:19 PMEvent ID/Source: 7023 / Service Control ManagerEvent Description:The Application Management service terminated with the following error: %%126Event Record #/Type14661 / ErrorEvent Submitted/Written: 10/03/2007 06:56:19 PMEvent ID/Source: 7023 / Service Control ManagerEvent Description:The Application Management service terminated with the following error: %%126Event Record #/Type14658 / ErrorEvent Submitted/Written: 10/03/2007 06:56:19 PMEvent ID/Source: 7023 / Service Control ManagerEvent Description:The Application Management service terminated with the following error: %%126Event Record #/Type14655 / ErrorEvent Submitted/Written: 10/03/2007 06:56:19 PMEvent ID/Source: 7023 / Service Control ManagerEvent Description:The Application Management service terminated with the following error: %%126-- End of Deckard's System Scanner: finished at 2007-10-03 20:31:20 ------------ Link to post Share on other sites
Andro1d Posted October 4, 2007 Report Share Posted October 4, 2007 (edited) Hello again,CLICK THIS TO LINK TO BE SURE YOU CAN VIEW HIDDEN FILESPlease go here:The Spy Killer ForumClick on "New Topic"Put your name, e-mail address, and this as the title: "C:\WINDOWS\system32\xxyyywt.dll".Put a link to this Geeks to Go topic in the description box.Then next to the file box, at the bottom, click the browse button, then navigate to this file:C:\WINDOWS\system32\xxyyywt.dll[*]Click Open.[*]Click Post.Thank you!!Let me know when you do this. Edited October 4, 2007 by MoNsTeReNeRgY22 Link to post Share on other sites
kohu Posted October 4, 2007 Author Report Share Posted October 4, 2007 (edited) oops, double post >.> Edited October 4, 2007 by Kohu Link to post Share on other sites
kohu Posted October 4, 2007 Author Report Share Posted October 4, 2007 Okay! I did it!. I didn't really understand step three, so I hope I did it right.heres the link if you need it. http://www.thespykiller.co.uk/index.php?topic=4985.0 Link to post Share on other sites
Andro1d Posted October 5, 2007 Report Share Posted October 5, 2007 Whoops, step 3 was a mistake on my part. I forgot to edit my speech Step 1Please download VundoFix.exe to your desktop (This is a newer version)Double-click VundoFix.exe to run it.Click the Scan for Vundo button.Once it's done scanning, click the Remove Vundo button.You will receive a prompt asking if you want to remove the files, click YESOnce you click yes, your desktop will go blank as it starts removing Vundo.When completed, it will prompt that it will reboot your computer, click OK.Please post the contents of C:\vundofix.txt and a new HiJackThis log in a reply to this thread.Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears upon rebooting.Step 2Download ComboFix from Here or Here to your Desktop.Double click combofix.exe and follow the prompts.When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply along with the vundofix.txtNote: Do not mouseclick combofix's window while its running. That may cause it to stall Link to post Share on other sites
kohu Posted October 5, 2007 Author Report Share Posted October 5, 2007 Heres the vundo log.VundoFix V6.5.6Checking Java version...Java version is 1.4.2.3Old versions of java are exploitable and should be removed.Scan started at 3:38:25 PM 7/25/2007Listing files found while scanning....No infected files were found.VundoFix V6.5.9Checking Java version...Java version is 1.4.2.3Old versions of java are exploitable and should be removed.Scan started at 5:27:42 PM 10/3/2007Listing files found while scanning....C:\windows\system32\acyveqdm.iniC:\windows\system32\aggvaorn.dllC:\windows\system32\aglsjgsq.dllC:\windows\system32\ahadrepr.dllC:\windows\system32\akvxhcfv.dllC:\windows\system32\aorvyaqt.iniC:\WINDOWS\system32\awvtr.dllC:\windows\system32\ayldidqg.iniC:\windows\system32\ayxnnfgr.iniC:\windows\system32\bbvckdpp.iniC:\windows\system32\binqsyqw.dllC:\windows\system32\bjyufmfi.iniC:\windows\system32\bqyyrevi.iniC:\windows\system32\btjdryrr.dllC:\windows\system32\bybtpite.dllC:\windows\system32\bydrafbu.iniC:\windows\system32\ceownxft.dllC:\windows\system32\chjkemhj.iniC:\windows\system32\clnlelfd.dllC:\WINDOWS\system32\coxsgffg.dllC:\windows\system32\cqqmhnwr.iniC:\windows\system32\dcpgmlpy.dllC:\windows\system32\dflelnlc.iniC:\windows\system32\difpuoew.dllC:\windows\system32\dlbudeas.dllC:\windows\system32\dmxejgoi.iniC:\windows\system32\dpyhlpxv.dllC:\windows\system32\drdlommt.dllC:\windows\system32\drnjxljn.iniC:\windows\system32\drqsfxvm.iniC:\windows\system32\eervjfyx.dllC:\windows\system32\ejmvqbyv.dllC:\windows\system32\ekpgbiyn.iniC:\windows\system32\embxsohx.iniC:\windows\system32\emlvkxij.dllC:\windows\system32\ensjjknj.dllC:\windows\system32\eqfftdqr.dllC:\windows\system32\etiptbyb.iniC:\windows\system32\evdrcnft.iniC:\windows\system32\eysxdeyr.dllC:\windows\system32\fcaminff.dllC:\windows\system32\fcxqoiex.iniC:\windows\system32\fdxxnelg.iniC:\windows\system32\ffnimacf.iniC:\windows\system32\ffrwohdj.iniC:\windows\system32\fhssyspr.iniC:\windows\system32\fnlkgupm.iniC:\windows\system32\frxqypvp.iniC:\windows\system32\fsxfysss.dllC:\windows\system32\ftbuikuj.dllC:\windows\system32\fvuielst.dllC:\windows\system32\ghlorpmp.dllC:\windows\system32\glenxxdf.dllC:\windows\system32\gnipaxix.dllC:\windows\system32\gqdidlya.dllC:\windows\system32\hfyhwwlu.iniC:\windows\system32\hngoeehn.dllC:\windows\system32\hsmyuiym.iniC:\windows\system32\hvwvedpq.dllC:\windows\system32\ifmfuyjb.dllC:\windows\system32\ihyeawiu.dllC:\windows\system32\iogjexmd.dllC:\windows\system32\iveryyqb.dllC:\windows\system32\ixxvtvxm.iniC:\windows\system32\jdhowrff.dllC:\windows\system32\jewafmsx.iniC:\windows\system32\jhmekjhc.dllC:\windows\system32\jixkvlme.iniC:\windows\system32\jjjdcrep.iniC:\windows\system32\jnkjjsne.iniC:\windows\system32\jolwnndo.dllC:\windows\system32\jqeppbjx.dllC:\windows\system32\jukiubtf.iniC:\windows\system32\kbacmjbo.dllC:\windows\system32\kjhpmtkw.dllC:\windows\system32\kjshanat.iniC:\windows\system32\kttgkakl.dllC:\windows\system32\kuvqdujv.dllC:\windows\system32\kvkwlncr.dllC:\windows\system32\ldmvlcns.iniC:\windows\system32\lhwrkdbt.dllC:\windows\system32\lkakgttk.iniC:\windows\system32\lkemsolv.dllC:\WINDOWS\system32\lubphvcu.dllC:\windows\system32\luunjajp.iniC:\windows\system32\mdqevyca.dllC:\windows\system32\mgavwain.dllC:\windows\system32\mitsenpn.iniC:\windows\system32\mjglnelx.iniC:\windows\system32\mpugklnf.dllC:\windows\system32\mqkwdqns.dllC:\windows\system32\mrohsivq.iniC:\windows\system32\mvxfsqrd.dllC:\windows\system32\mxvtvxxi.dllC:\windows\system32\myafaokt.iniC:\windows\system32\myiuymsh.dllC:\windows\system32\nbuyciep.dllC:\WINDOWS\system32\nbytahug.dllC:\windows\system32\ncirjmkv.dllC:\windows\system32\nhatropy.iniC:\windows\system32\nheeognh.iniC:\windows\system32\nhntmorq.iniC:\windows\system32\niawvagm.iniC:\windows\system32\njlxjnrd.dllC:\windows\system32\nkjwaavh.exeC:\windows\system32\npnestim.dllC:\windows\system32\nqmvsnfq.iniC:\windows\system32\nroavgga.iniC:\windows\system32\nyibgpke.dllC:\windows\system32\objmcabk.iniC:\windows\system32\odnnwloj.iniC:\windows\system32\ohlpxlws.dllC:\windows\system32\onwsiivp.iniC:\windows\system32\ooufpkwr.iniC:\windows\system32\ouinjiqr.dllC:\windows\system32\pbbniabv.dllC:\windows\system32\peicyubn.iniC:\windows\system32\percdjjj.dllC:\windows\system32\piomrlyu.iniC:\windows\system32\pjajnuul.dllC:\windows\system32\pjvbrogt.dllC:\windows\system32\pluwwilv.dllC:\windows\system32\pmprolhg.iniC:\windows\system32\ppdkcvbb.dllC:\windows\system32\pviiswno.dllC:\windows\system32\pvpyqxrf.dllC:\windows\system32\pxjjjaax.dllC:\windows\system32\qbqvocnq.dllC:\windows\system32\qesahwmq.iniC:\windows\system32\qfnsvmqn.dllC:\windows\system32\qmwhaseq.dllC:\windows\system32\qncovqbq.iniC:\windows\system32\qpdevwvh.iniC:\windows\system32\qromtnhn.dllC:\windows\system32\qsgjslga.iniC:\windows\system32\qubdmgps.dllC:\windows\system32\qvishorm.dllC:\windows\system32\rcnlwkvk.iniC:\windows\system32\rcrwxhvs.dllC:\windows\system32\rgfnnxya.dllC:\windows\system32\rooksxis.dllC:\windows\system32\rperdaha.iniC:\windows\system32\rpsysshf.dllC:\windows\system32\rqdtffqe.iniC:\windows\system32\rqijniuo.iniC:\windows\system32\rryrdjtb.iniC:\WINDOWS\system32\rtvwa.bak1C:\WINDOWS\system32\rtvwa.bak2C:\WINDOWS\system32\rtvwa.iniC:\WINDOWS\system32\rtvwa.ini2C:\WINDOWS\system32\rtvwa.tmpC:\windows\system32\rwkpfuoo.dllC:\windows\system32\rwnhmqqc.dllC:\windows\system32\ryedxsye.iniC:\windows\system32\saedubld.iniC:\windows\system32\saqlwdcw.iniC:\windows\system32\sarkjvou.iniC:\windows\system32\sgmrvvjt.iniC:\windows\system32\sixskoor.iniC:\windows\system32\snclvmdl.dllC:\windows\system32\snqdwkqm.iniC:\windows\system32\spgmdbuq.iniC:\windows\system32\sssyfxsf.iniC:\windows\system32\svhxwrcr.iniC:\windows\system32\swlxplho.iniC:\windows\system32\tanahsjk.dllC:\windows\system32\tbdkrwhl.iniC:\windows\system32\tfncrdve.dllC:\windows\system32\tgorbvjp.iniC:\windows\system32\tjvvrmgs.dllC:\windows\system32\tkoafaym.dllC:\windows\system32\tmmoldrd.iniC:\windows\system32\tqayvroa.dllC:\windows\system32\tsleiuvf.iniC:\windows\system32\ubfardyb.dllC:\windows\system32\ucqqimax.iniC:\windows\system32\ucvhpbul.iniC:\windows\system32\ucwikttu.dllC:\windows\system32\uiwaeyhi.iniC:\windows\system32\ulwwhyfh.dllC:\windows\system32\uovjkras.dllC:\windows\system32\uqyqipfy.iniC:\windows\system32\uttkiwcu.iniC:\windows\system32\uylrmoip.dllC:\windows\system32\vbainbbp.iniC:\windows\system32\vfchxvka.iniC:\windows\system32\vjudqvuk.iniC:\windows\system32\vkmjricn.iniC:\windows\system32\vliwwulp.iniC:\windows\system32\vlosmekl.iniC:\windows\system32\vxplhypd.iniC:\windows\system32\vybqvmje.iniC:\windows\system32\wcdwlqas.dllC:\windows\system32\weoupfid.iniC:\windows\system32\wktmphjk.iniC:\windows\system32\wqysqnib.iniC:\windows\system32\wxuorxgx.dllC:\windows\system32\wytgnygy.iniC:\windows\system32\xaajjjxp.iniC:\windows\system32\xamiqqcu.dllC:\windows\system32\xeioqxcf.dllC:\windows\system32\xgxrouxw.iniC:\windows\system32\xhosxbme.dllC:\windows\system32\xixaping.iniC:\windows\system32\xjbppeqj.iniC:\windows\system32\xlenlgjm.dllC:\windows\system32\xmcnmmmx.iniC:\windows\system32\xmmmncmx.dllC:\windows\system32\xsmfawej.dllC:\WINDOWS\system32\xxyyywt.dllC:\windows\system32\xyfjvree.iniC:\windows\system32\yfpiqyqu.dllC:\windows\system32\ygyngtyw.dllC:\windows\system32\yplmgpcd.iniC:\windows\system32\yportahn.dllBeginning removal... Attempting to delete C:\windows\system32\acyveqdm.iniC:\windows\system32\acyveqdm.ini Has been deleted! Attempting to delete C:\windows\system32\aggvaorn.dllC:\windows\system32\aggvaorn.dll Has been deleted! Attempting to delete C:\windows\system32\aglsjgsq.dllC:\windows\system32\aglsjgsq.dll Has been deleted! Attempting to delete C:\windows\system32\ahadrepr.dllC:\windows\system32\ahadrepr.dll Has been deleted! Attempting to delete C:\windows\system32\akvxhcfv.dllC:\windows\system32\akvxhcfv.dll Has been deleted! Attempting to delete C:\windows\system32\aorvyaqt.iniC:\windows\system32\aorvyaqt.ini Has been deleted! Attempting to delete C:\WINDOWS\system32\awvtr.dllC:\WINDOWS\system32\awvtr.dll Could not be deleted. Attempting to delete C:\windows\system32\ayldidqg.iniC:\windows\system32\ayldidqg.ini Has been deleted! Attempting to delete C:\windows\system32\ayxnnfgr.iniC:\windows\system32\ayxnnfgr.ini Has been deleted! Attempting to delete C:\windows\system32\bbvckdpp.iniC:\windows\system32\bbvckdpp.ini Has been deleted! Attempting to delete C:\windows\system32\binqsyqw.dllC:\windows\system32\binqsyqw.dll Has been deleted! Attempting to delete C:\windows\system32\bjyufmfi.iniC:\windows\system32\bjyufmfi.ini Has been deleted! Attempting to delete C:\windows\system32\bqyyrevi.iniC:\windows\system32\bqyyrevi.ini Has been deleted! Attempting to delete C:\windows\system32\btjdryrr.dllC:\windows\system32\btjdryrr.dll Has been deleted! Attempting to delete C:\windows\system32\bybtpite.dllC:\windows\system32\bybtpite.dll Has been deleted! Attempting to delete C:\windows\system32\bydrafbu.iniC:\windows\system32\bydrafbu.ini Has been deleted! Attempting to delete C:\windows\system32\ceownxft.dllC:\windows\system32\ceownxft.dll Has been deleted! Attempting to delete C:\windows\system32\chjkemhj.iniC:\windows\system32\chjkemhj.ini Has been deleted! Attempting to delete C:\windows\system32\clnlelfd.dllC:\windows\system32\clnlelfd.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\coxsgffg.dllC:\WINDOWS\system32\coxsgffg.dll Has been deleted! Attempting to delete C:\windows\system32\cqqmhnwr.iniC:\windows\system32\cqqmhnwr.ini Has been deleted! Attempting to delete C:\windows\system32\dcpgmlpy.dllC:\windows\system32\dcpgmlpy.dll Has been deleted! Attempting to delete C:\windows\system32\dflelnlc.iniC:\windows\system32\dflelnlc.ini Has been deleted! Attempting to delete C:\windows\system32\difpuoew.dllC:\windows\system32\difpuoew.dll Has been deleted! Attempting to delete C:\windows\system32\dlbudeas.dllC:\windows\system32\dlbudeas.dll Has been deleted! Attempting to delete C:\windows\system32\dmxejgoi.iniC:\windows\system32\dmxejgoi.ini Has been deleted! Attempting to delete C:\windows\system32\dpyhlpxv.dllC:\windows\system32\dpyhlpxv.dll Has been deleted! Attempting to delete C:\windows\system32\drdlommt.dllC:\windows\system32\drdlommt.dll Has been deleted! Attempting to delete C:\windows\system32\drnjxljn.iniC:\windows\system32\drnjxljn.ini Has been deleted! Attempting to delete C:\windows\system32\drqsfxvm.iniC:\windows\system32\drqsfxvm.ini Has been deleted! Attempting to delete C:\windows\system32\eervjfyx.dllC:\windows\system32\eervjfyx.dll Has been deleted! Attempting to delete C:\windows\system32\ejmvqbyv.dllC:\windows\system32\ejmvqbyv.dll Has been deleted! Attempting to delete C:\windows\system32\ekpgbiyn.iniC:\windows\system32\ekpgbiyn.ini Has been deleted! Attempting to delete C:\windows\system32\embxsohx.iniC:\windows\system32\embxsohx.ini Has been deleted! Attempting to delete C:\windows\system32\emlvkxij.dllC:\windows\system32\emlvkxij.dll Has been deleted! Attempting to delete C:\windows\system32\ensjjknj.dllC:\windows\system32\ensjjknj.dll Has been deleted! Attempting to delete C:\windows\system32\eqfftdqr.dllC:\windows\system32\eqfftdqr.dll Has been deleted! Attempting to delete C:\windows\system32\etiptbyb.iniC:\windows\system32\etiptbyb.ini Has been deleted! Attempting to delete C:\windows\system32\evdrcnft.iniC:\windows\system32\evdrcnft.ini Has been deleted! Attempting to delete C:\windows\system32\eysxdeyr.dllC:\windows\system32\eysxdeyr.dll Has been deleted! Attempting to delete C:\windows\system32\fcaminff.dllC:\windows\system32\fcaminff.dll Has been deleted! Attempting to delete C:\windows\system32\fcxqoiex.iniC:\windows\system32\fcxqoiex.ini Has been deleted! Attempting to delete C:\windows\system32\fdxxnelg.iniC:\windows\system32\fdxxnelg.ini Has been deleted! Attempting to delete C:\windows\system32\ffnimacf.iniC:\windows\system32\ffnimacf.ini Has been deleted! Attempting to delete C:\windows\system32\ffrwohdj.iniC:\windows\system32\ffrwohdj.ini Has been deleted! Attempting to delete C:\windows\system32\fhssyspr.iniC:\windows\system32\fhssyspr.ini Has been deleted! Attempting to delete C:\windows\system32\fnlkgupm.iniC:\windows\system32\fnlkgupm.ini Has been deleted! Attempting to delete C:\windows\system32\frxqypvp.iniC:\windows\system32\frxqypvp.ini Has been deleted! Attempting to delete C:\windows\system32\fsxfysss.dllC:\windows\system32\fsxfysss.dll Has been deleted! Attempting to delete C:\windows\system32\ftbuikuj.dllC:\windows\system32\ftbuikuj.dll Has been deleted! Attempting to delete C:\windows\system32\fvuielst.dllC:\windows\system32\fvuielst.dll Has been deleted! Attempting to delete C:\windows\system32\ghlorpmp.dllC:\windows\system32\ghlorpmp.dll Has been deleted! Attempting to delete C:\windows\system32\glenxxdf.dllC:\windows\system32\glenxxdf.dll Has been deleted! Attempting to delete C:\windows\system32\gnipaxix.dllC:\windows\system32\gnipaxix.dll Has been deleted! Attempting to delete C:\windows\system32\gqdidlya.dllC:\windows\system32\gqdidlya.dll Has been deleted! Attempting to delete C:\windows\system32\hfyhwwlu.iniC:\windows\system32\hfyhwwlu.ini Has been deleted! Attempting to delete C:\windows\system32\hngoeehn.dllC:\windows\system32\hngoeehn.dll Has been deleted! Attempting to delete C:\windows\system32\hsmyuiym.iniC:\windows\system32\hsmyuiym.ini Has been deleted! Attempting to delete C:\windows\system32\hvwvedpq.dllC:\windows\system32\hvwvedpq.dll Has been deleted! Attempting to delete C:\windows\system32\ifmfuyjb.dllC:\windows\system32\ifmfuyjb.dll Has been deleted! Attempting to delete C:\windows\system32\ihyeawiu.dllC:\windows\system32\ihyeawiu.dll Has been deleted! Attempting to delete C:\windows\system32\iogjexmd.dllC:\windows\system32\iogjexmd.dll Has been deleted! Attempting to delete C:\windows\system32\iveryyqb.dllC:\windows\system32\iveryyqb.dll Has been deleted! Attempting to delete C:\windows\system32\ixxvtvxm.iniC:\windows\system32\ixxvtvxm.ini Has been deleted! Attempting to delete C:\windows\system32\jdhowrff.dllC:\windows\system32\jdhowrff.dll Has been deleted! Attempting to delete C:\windows\system32\jewafmsx.iniC:\windows\system32\jewafmsx.ini Has been deleted! Attempting to delete C:\windows\system32\jhmekjhc.dllC:\windows\system32\jhmekjhc.dll Has been deleted! Attempting to delete C:\windows\system32\jixkvlme.iniC:\windows\system32\jixkvlme.ini Has been deleted! Attempting to delete C:\windows\system32\jjjdcrep.iniC:\windows\system32\jjjdcrep.ini Has been deleted! Attempting to delete C:\windows\system32\jnkjjsne.iniC:\windows\system32\jnkjjsne.ini Has been deleted! Attempting to delete C:\windows\system32\jolwnndo.dllC:\windows\system32\jolwnndo.dll Has been deleted! Attempting to delete C:\windows\system32\jqeppbjx.dllC:\windows\system32\jqeppbjx.dll Has been deleted! Attempting to delete C:\windows\system32\jukiubtf.iniC:\windows\system32\jukiubtf.ini Has been deleted! Attempting to delete C:\windows\system32\kbacmjbo.dllC:\windows\system32\kbacmjbo.dll Has been deleted! Attempting to delete C:\windows\system32\kjhpmtkw.dllC:\windows\system32\kjhpmtkw.dll Has been deleted! Attempting to delete C:\windows\system32\kjshanat.iniC:\windows\system32\kjshanat.ini Has been deleted! Attempting to delete C:\windows\system32\kttgkakl.dllC:\windows\system32\kttgkakl.dll Has been deleted! Attempting to delete C:\windows\system32\kuvqdujv.dllC:\windows\system32\kuvqdujv.dll Has been deleted! Attempting to delete C:\windows\system32\kvkwlncr.dllC:\windows\system32\kvkwlncr.dll Has been deleted! Attempting to delete C:\windows\system32\ldmvlcns.iniC:\windows\system32\ldmvlcns.ini Has been deleted! Attempting to delete C:\windows\system32\lhwrkdbt.dllC:\windows\system32\lhwrkdbt.dll Has been deleted! Attempting to delete C:\windows\system32\lkakgttk.iniC:\windows\system32\lkakgttk.ini Has been deleted! Attempting to delete C:\windows\system32\lkemsolv.dllC:\windows\system32\lkemsolv.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\lubphvcu.dllC:\WINDOWS\system32\lubphvcu.dll Could not be deleted. Attempting to delete C:\windows\system32\luunjajp.iniC:\windows\system32\luunjajp.ini Has been deleted! Attempting to delete C:\windows\system32\mdqevyca.dllC:\windows\system32\mdqevyca.dll Has been deleted! Attempting to delete C:\windows\system32\mgavwain.dllC:\windows\system32\mgavwain.dll Has been deleted! Attempting to delete C:\windows\system32\mitsenpn.iniC:\windows\system32\mitsenpn.ini Has been deleted! Attempting to delete C:\windows\system32\mjglnelx.iniC:\windows\system32\mjglnelx.ini Has been deleted! Attempting to delete C:\windows\system32\mpugklnf.dllC:\windows\system32\mpugklnf.dll Has been deleted! Attempting to delete C:\windows\system32\mqkwdqns.dllC:\windows\system32\mqkwdqns.dll Has been deleted! Attempting to delete C:\windows\system32\mrohsivq.iniC:\windows\system32\mrohsivq.ini Has been deleted! Attempting to delete C:\windows\system32\mvxfsqrd.dllC:\windows\system32\mvxfsqrd.dll Has been deleted! Attempting to delete C:\windows\system32\mxvtvxxi.dllC:\windows\system32\mxvtvxxi.dll Has been deleted! Attempting to delete C:\windows\system32\myafaokt.iniC:\windows\system32\myafaokt.ini Has been deleted! Attempting to delete C:\windows\system32\myiuymsh.dllC:\windows\system32\myiuymsh.dll Has been deleted! Attempting to delete C:\windows\system32\nbuyciep.dllC:\windows\system32\nbuyciep.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\nbytahug.dllC:\WINDOWS\system32\nbytahug.dll Could not be deleted. Attempting to delete C:\windows\system32\ncirjmkv.dllC:\windows\system32\ncirjmkv.dll Has been deleted! Attempting to delete C:\windows\system32\nhatropy.iniC:\windows\system32\nhatropy.ini Has been deleted! Attempting to delete C:\windows\system32\nheeognh.iniC:\windows\system32\nheeognh.ini Has been deleted! Attempting to delete C:\windows\system32\nhntmorq.iniC:\windows\system32\nhntmorq.ini Has been deleted! Attempting to delete C:\windows\system32\niawvagm.iniC:\windows\system32\niawvagm.ini Has been deleted! Attempting to delete C:\windows\system32\njlxjnrd.dllC:\windows\system32\njlxjnrd.dll Has been deleted! Attempting to delete C:\windows\system32\nkjwaavh.exeC:\windows\system32\nkjwaavh.exe Has been deleted! Attempting to delete C:\windows\system32\npnestim.dllC:\windows\system32\npnestim.dll Has been deleted! Attempting to delete C:\windows\system32\nqmvsnfq.iniC:\windows\system32\nqmvsnfq.ini Has been deleted! Attempting to delete C:\windows\system32\nroavgga.iniC:\windows\system32\nroavgga.ini Has been deleted! Attempting to delete C:\windows\system32\nyibgpke.dllC:\windows\system32\nyibgpke.dll Has been deleted! Attempting to delete C:\windows\system32\objmcabk.iniC:\windows\system32\objmcabk.ini Has been deleted! Attempting to delete C:\windows\system32\odnnwloj.iniC:\windows\system32\odnnwloj.ini Has been deleted! Attempting to delete C:\windows\system32\ohlpxlws.dllC:\windows\system32\ohlpxlws.dll Has been deleted! Attempting to delete C:\windows\system32\onwsiivp.iniC:\windows\system32\onwsiivp.ini Has been deleted! Attempting to delete C:\windows\system32\ooufpkwr.iniC:\windows\system32\ooufpkwr.ini Has been deleted! Attempting to delete C:\windows\system32\ouinjiqr.dllC:\windows\system32\ouinjiqr.dll Has been deleted! Attempting to delete C:\windows\system32\pbbniabv.dllC:\windows\system32\pbbniabv.dll Has been deleted! Attempting to delete C:\windows\system32\peicyubn.iniC:\windows\system32\peicyubn.ini Has been deleted! Attempting to delete C:\windows\system32\percdjjj.dllC:\windows\system32\percdjjj.dll Has been deleted! Attempting to delete C:\windows\system32\piomrlyu.iniC:\windows\system32\piomrlyu.ini Has been deleted! Attempting to delete C:\windows\system32\pjajnuul.dllC:\windows\system32\pjajnuul.dll Has been deleted! Attempting to delete C:\windows\system32\pjvbrogt.dllC:\windows\system32\pjvbrogt.dll Has been deleted! Attempting to delete C:\windows\system32\pluwwilv.dllC:\windows\system32\pluwwilv.dll Has been deleted! Attempting to delete C:\windows\system32\pmprolhg.iniC:\windows\system32\pmprolhg.ini Has been deleted! Attempting to delete C:\windows\system32\ppdkcvbb.dllC:\windows\system32\ppdkcvbb.dll Has been deleted! Attempting to delete C:\windows\system32\pviiswno.dllC:\windows\system32\pviiswno.dll Has been deleted! Attempting to delete C:\windows\system32\pvpyqxrf.dllC:\windows\system32\pvpyqxrf.dll Has been deleted! Attempting to delete C:\windows\system32\pxjjjaax.dllC:\windows\system32\pxjjjaax.dll Has been deleted! Attempting to delete C:\windows\system32\qbqvocnq.dllC:\windows\system32\qbqvocnq.dll Has been deleted! Attempting to delete C:\windows\system32\qesahwmq.iniC:\windows\system32\qesahwmq.ini Has been deleted! Attempting to delete C:\windows\system32\qfnsvmqn.dllC:\windows\system32\qfnsvmqn.dll Has been deleted! Attempting to delete C:\windows\system32\qmwhaseq.dllC:\windows\system32\qmwhaseq.dll Has been deleted! Attempting to delete C:\windows\system32\qncovqbq.iniC:\windows\system32\qncovqbq.ini Has been deleted! Attempting to delete C:\windows\system32\qpdevwvh.iniC:\windows\system32\qpdevwvh.ini Has been deleted! Attempting to delete C:\windows\system32\qromtnhn.dllC:\windows\system32\qromtnhn.dll Has been deleted! Attempting to delete C:\windows\system32\qsgjslga.iniC:\windows\system32\qsgjslga.ini Has been deleted! Attempting to delete C:\windows\system32\qubdmgps.dllC:\windows\system32\qubdmgps.dll Has been deleted! Attempting to delete C:\windows\system32\qvishorm.dllC:\windows\system32\qvishorm.dll Has been deleted! Attempting to delete C:\windows\system32\rcnlwkvk.iniC:\windows\system32\rcnlwkvk.ini Has been deleted! Attempting to delete C:\windows\system32\rcrwxhvs.dllC:\windows\system32\rcrwxhvs.dll Has been deleted! Attempting to delete C:\windows\system32\rgfnnxya.dllC:\windows\system32\rgfnnxya.dll Has been deleted! Attempting to delete C:\windows\system32\rooksxis.dllC:\windows\system32\rooksxis.dll Has been deleted! Attempting to delete C:\windows\system32\rperdaha.iniC:\windows\system32\rperdaha.ini Has been deleted! Attempting to delete C:\windows\system32\rpsysshf.dllC:\windows\system32\rpsysshf.dll Has been deleted! Attempting to delete C:\windows\system32\rqdtffqe.iniC:\windows\system32\rqdtffqe.ini Has been deleted! Attempting to delete C:\windows\system32\rqijniuo.iniC:\windows\system32\rqijniuo.ini Has been deleted! Attempting to delete C:\windows\system32\rryrdjtb.iniC:\windows\system32\rryrdjtb.ini Has been deleted! Attempting to delete C:\WINDOWS\system32\rtvwa.bak1C:\WINDOWS\system32\rtvwa.bak1 Has been deleted! Attempting to delete C:\WINDOWS\system32\rtvwa.bak2C:\WINDOWS\system32\rtvwa.bak2 Has been deleted! Attempting to delete C:\WINDOWS\system32\rtvwa.iniC:\WINDOWS\system32\rtvwa.ini Has been deleted! Attempting to delete C:\WINDOWS\system32\rtvwa.ini2C:\WINDOWS\system32\rtvwa.ini2 Has been deleted! Attempting to delete C:\WINDOWS\system32\rtvwa.tmpC:\WINDOWS\system32\rtvwa.tmp Has been deleted! Attempting to delete C:\windows\system32\rwkpfuoo.dllC:\windows\system32\rwkpfuoo.dll Has been deleted! Attempting to delete C:\windows\system32\rwnhmqqc.dllC:\windows\system32\rwnhmqqc.dll Has been deleted! Attempting to delete C:\windows\system32\ryedxsye.iniC:\windows\system32\ryedxsye.ini Has been deleted! Attempting to delete C:\windows\system32\saedubld.iniC:\windows\system32\saedubld.ini Has been deleted! Attempting to delete C:\windows\system32\saqlwdcw.iniC:\windows\system32\saqlwdcw.ini Has been deleted! Attempting to delete C:\windows\system32\sarkjvou.iniC:\windows\system32\sarkjvou.ini Has been deleted! Attempting to delete C:\windows\system32\sgmrvvjt.iniC:\windows\system32\sgmrvvjt.ini Has been deleted! Attempting to delete C:\windows\system32\sixskoor.iniC:\windows\system32\sixskoor.ini Has been deleted! Attempting to delete C:\windows\system32\snclvmdl.dllC:\windows\system32\snclvmdl.dll Has been deleted! Attempting to delete C:\windows\system32\snqdwkqm.iniC:\windows\system32\snqdwkqm.ini Has been deleted! Attempting to delete C:\windows\system32\spgmdbuq.iniC:\windows\system32\spgmdbuq.ini Has been deleted! Attempting to delete C:\windows\system32\sssyfxsf.iniC:\windows\system32\sssyfxsf.ini Has been deleted! Attempting to delete C:\windows\system32\svhxwrcr.iniC:\windows\system32\svhxwrcr.ini Has been deleted! Attempting to delete C:\windows\system32\swlxplho.iniC:\windows\system32\swlxplho.ini Has been deleted! Attempting to delete C:\windows\system32\tanahsjk.dllC:\windows\system32\tanahsjk.dll Has been deleted! Attempting to delete C:\windows\system32\tbdkrwhl.iniC:\windows\system32\tbdkrwhl.ini Has been deleted! Attempting to delete C:\windows\system32\tfncrdve.dllC:\windows\system32\tfncrdve.dll Has been deleted! Attempting to delete C:\windows\system32\tgorbvjp.iniC:\windows\system32\tgorbvjp.ini Has been deleted! Attempting to delete C:\windows\system32\tjvvrmgs.dllC:\windows\system32\tjvvrmgs.dll Has been deleted! Attempting to delete C:\windows\system32\tkoafaym.dllC:\windows\system32\tkoafaym.dll Has been deleted! Attempting to delete C:\windows\system32\tmmoldrd.iniC:\windows\system32\tmmoldrd.ini Has been deleted! Attempting to delete C:\windows\system32\tqayvroa.dllC:\windows\system32\tqayvroa.dll Has been deleted! Attempting to delete C:\windows\system32\tsleiuvf.iniC:\windows\system32\tsleiuvf.ini Has been deleted! Attempting to delete C:\windows\system32\ubfardyb.dllC:\windows\system32\ubfardyb.dll Has been deleted! Attempting to delete C:\windows\system32\ucqqimax.iniC:\windows\system32\ucqqimax.ini Has been deleted! Attempting to delete C:\windows\system32\ucvhpbul.iniC:\windows\system32\ucvhpbul.ini Has been deleted! Attempting to delete C:\windows\system32\ucwikttu.dllC:\windows\system32\ucwikttu.dll Has been deleted! Attempting to delete C:\windows\system32\uiwaeyhi.iniC:\windows\system32\uiwaeyhi.ini Has been deleted! Attempting to delete C:\windows\system32\ulwwhyfh.dllC:\windows\system32\ulwwhyfh.dll Has been deleted! Attempting to delete C:\windows\system32\uovjkras.dllC:\windows\system32\uovjkras.dll Has been deleted! Attempting to delete C:\windows\system32\uqyqipfy.iniC:\windows\system32\uqyqipfy.ini Has been deleted! Attempting to delete C:\windows\system32\uttkiwcu.iniC:\windows\system32\uttkiwcu.ini Has been deleted! Attempting to delete C:\windows\system32\uylrmoip.dllC:\windows\system32\uylrmoip.dll Has been deleted! Attempting to delete C:\windows\system32\vbainbbp.iniC:\windows\system32\vbainbbp.ini Has been deleted! Attempting to delete C:\windows\system32\vfchxvka.iniC:\windows\system32\vfchxvka.ini Has been deleted! Attempting to delete C:\windows\system32\vjudqvuk.iniC:\windows\system32\vjudqvuk.ini Has been deleted! Attempting to delete C:\windows\system32\vkmjricn.iniC:\windows\system32\vkmjricn.ini Has been deleted! Attempting to delete C:\windows\system32\vliwwulp.iniC:\windows\system32\vliwwulp.ini Has been deleted! Attempting to delete C:\windows\system32\vlosmekl.iniC:\windows\system32\vlosmekl.ini Has been deleted! Attempting to delete C:\windows\system32\vxplhypd.iniC:\windows\system32\vxplhypd.ini Has been deleted! Attempting to delete C:\windows\system32\vybqvmje.iniC:\windows\system32\vybqvmje.ini Has been deleted! Attempting to delete C:\windows\system32\wcdwlqas.dllC:\windows\system32\wcdwlqas.dll Has been deleted! Attempting to delete C:\windows\system32\weoupfid.iniC:\windows\system32\weoupfid.ini Has been deleted! Attempting to delete C:\windows\system32\wktmphjk.iniC:\windows\system32\wktmphjk.ini Has been deleted! Attempting to delete C:\windows\system32\wqysqnib.iniC:\windows\system32\wqysqnib.ini Has been deleted! Attempting to delete C:\windows\system32\wxuorxgx.dllC:\windows\system32\wxuorxgx.dll Has been deleted! Attempting to delete C:\windows\system32\wytgnygy.iniC:\windows\system32\wytgnygy.ini Has been deleted! Attempting to delete C:\windows\system32\xaajjjxp.iniC:\windows\system32\xaajjjxp.ini Has been deleted! Attempting to delete C:\windows\system32\xamiqqcu.dllC:\windows\system32\xamiqqcu.dll Has been deleted! Attempting to delete C:\windows\system32\xeioqxcf.dllC:\windows\system32\xeioqxcf.dll Has been deleted! Attempting to delete C:\windows\system32\xgxrouxw.iniC:\windows\system32\xgxrouxw.ini Has been deleted! Attempting to delete C:\windows\system32\xhosxbme.dllC:\windows\system32\xhosxbme.dll Has been deleted! Attempting to delete C:\windows\system32\xixaping.iniC:\windows\system32\xixaping.ini Has been deleted! Attempting to delete C:\windows\system32\xjbppeqj.iniC:\windows\system32\xjbppeqj.ini Has been deleted! Attempting to delete C:\windows\system32\xlenlgjm.dllC:\windows\system32\xlenlgjm.dll Has been deleted! Attempting to delete C:\windows\system32\xmcnmmmx.iniC:\windows\system32\xmcnmmmx.ini Has been deleted! Attempting to delete C:\windows\system32\xmmmncmx.dllC:\windows\system32\xmmmncmx.dll Has been deleted! Attempting to delete C:\windows\system32\xsmfawej.dllC:\windows\system32\xsmfawej.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\xxyyywt.dllC:\WINDOWS\system32\xxyyywt.dll Could not be deleted. Attempting to delete C:\windows\system32\xyfjvree.iniC:\windows\system32\xyfjvree.ini Has been deleted! Attempting to delete C:\windows\system32\yfpiqyqu.dllC:\windows\system32\yfpiqyqu.dll Has been deleted! Attempting to delete C:\windows\system32\ygyngtyw.dllC:\windows\system32\ygyngtyw.dll Has been deleted! Attempting to delete C:\windows\system32\yplmgpcd.iniC:\windows\system32\yplmgpcd.ini Has been deleted! Attempting to delete C:\windows\system32\yportahn.dllC:\windows\system32\yportahn.dll Has been deleted!Performing Repairs to the registry.Done!Beginning removal... Attempting to delete C:\WINDOWS\system32\awvtr.dllC:\WINDOWS\system32\awvtr.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\lubphvcu.dllC:\WINDOWS\system32\lubphvcu.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\nbytahug.dllC:\WINDOWS\system32\nbytahug.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\rtvwa.iniC:\WINDOWS\system32\rtvwa.ini Has been deleted! Attempting to delete C:\WINDOWS\system32\xxyyywt.dllC:\WINDOWS\system32\xxyyywt.dll Could not be deleted.Performing Repairs to the registry.Done!VundoFix V6.5.9Checking Java version...Java version is 1.4.2.3Old versions of java are exploitable and should be removed.Scan started at 6:44:09 PM 10/4/2007Listing files found while scanning....C:\windows\system32\xxyyywt.dllBeginning removal... Attempting to delete C:\windows\system32\xxyyywt.dllC:\windows\system32\xxyyywt.dll Has been deleted!Performing Repairs to the registry.Done! Link to post Share on other sites
kohu Posted October 5, 2007 Author Report Share Posted October 5, 2007 Heres the HJT log, starting the combofix now...Logfile of HijackThis v1.99.1Scan saved at 6:59:30 PM, on 10/4/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16512)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exec:\Program Files\Common Files\Symantec Shared\ccSetMgr.exec:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exeC:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exec:\Program Files\Common Files\Symantec Shared\ccProxy.exeC:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exec:\Program Files\Norton AntiVirus\navapsvc.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\M-Audio Uno\UnoInst.exeC:\Program Files\Viewpoint\Common\ViewpointService.exeC:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exeC:\windows\system\hpsysdrv.exeC:\Program Files\HP\hpcoretech\hpcmpmgr.exeC:\WINDOWS\System32\hphmon05.exeC:\WINDOWS\system32\VTTimer.exeC:\Program Files\Common Files\Symantec Shared\ccApp.exeC:\WINDOWS\AGRSMMSG.exeC:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exeC:\Program Files\HP\HP Software Update\HPWuSchd2.exeC:\HP\KBD\KBD.EXEC:\Program Files\Lexmark 2400 Series\lxcrmon.exeC:\Program Files\Lexmark 2400 Series\ezprint.exeC:\Program Files\iTunes\iTunesHelper.exeC:\windows\system32\lrdsrngo.exeC:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exeC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\WINDOWS\system32\wscntfy.exeC:\WINDOWS\system32\lxcrcoms.exeC:\WINDOWS\Cyb2k.exeC:\Program Files\Java\jre1.6.0_03\bin\jusched.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Messenger\msmsgs.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\Google\GoogleToolbarNotifier\1.2.911.3380\GoogleToolbarNotifier.exeC:\WINDOWS\system32\wuauclt.exeC:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exeC:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exeC:\Program Files\HP\Digital Imaging\bin\hpqtra08.exeC:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXEC:\Program Files\WiFiConnector\NintendoWFCReg.exeC:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exeC:\Program Files\iPod\bin\iPodService.exeC:\Documents and Settings\Pete's\My Documents\highjackthis\energy.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktopR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhostO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocxO2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dllO2 - BHO: StumbleUpon Launcher - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dllO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dllO2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dllO2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - c:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dllO2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dllO2 - BHO: (no name) - {B62F5B2F-FB3C-45BC-97BF-9EBE1A61AED4} - C:\WINDOWS\system32\awvtr.dll (file missing)O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dllO3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dllO3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dllO3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dllO3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dllO3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - c:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dllO4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exeO4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exeO4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exeO4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXEO4 - HKLM\..\Run: [VTTimer] VTTimer.exeO4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"O4 - HKLM\..\Run: [updateManager] "c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /rO4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exeO4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exeO4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exeO4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exeO4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXEO4 - HKLM\..\Run: [lxcrmon.exe] "C:\Program Files\Lexmark 2400 Series\lxcrmon.exe"O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2400 Series\ezprint.exe"O4 - HKLM\..\Run: [LXCRCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll,_RunDLLEntry@16O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"O4 - HKLM\..\Run: [{08-8B-BF-FC-ZN}] C:\windows\system32\lrdsrngo.exe CHD003O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimizedO4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osbootO4 - HKLM\..\Run: [spyHunter] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exeO4 - HKLM\..\Run: [ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exeO4 - HKLM\..\Run: [C2K] C:\WINDOWS\Cyb2k.exeO4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /backgroundO4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - HKCU\..\Run: [backupNotify] c:\Program Files\HP\Digital Imaging\bin\backupnotify.exeO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.911.3380\GoogleToolbarNotifier.exeO4 - Startup: PowerReg Scheduler V3.exeO4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\lrdsrngo.exeO4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exeO4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXEO4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exeO4 - Global Startup: Run Nintendo Wi-Fi USB Connector Registration Tool.lnk = C:\Program Files\WiFiConnector\NintendoWFCReg.exeO4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exeO8 - Extra context menu item: Download all links using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htmO8 - Extra context menu item: Download all videos using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htmO8 - Extra context menu item: Download link using &BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htmO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000O8 - Extra context menu item: Open in New &Window (PopOops) - C:\WINDOWS\Web\PopOops.htmO8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimageO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dllO9 - Extra button: Panda ActiveScan - {653D93AF-C741-4e5e-8C1B-59BA43F93E16} - http://www.pandasoftware.com/activescan (file missing)O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLLO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO11 - Options group: [iNTERNATIONAL] International*O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dllO15 - Trusted Zone: *.stumbleupon.comO16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cabO16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cabO16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cabO16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cabO16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cabO16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1187204501375O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cabO16 - DPF: {A954AFC3-3A26-44C2-A126-2B61C09F8FC9} (SNRecovery Control) - http://www.cybersitter.com/recovery/ocx/SerialRecovery.ocxO16 - DPF: {C52439A0-2693-4E40-B141-9F9AD5257241} (Lexmark eDiagnostics Class) - https://ediagnostics.lexmark.com/serval.cabO16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cabO20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dllO20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dllO21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dllO23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeO23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exeO23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exeO23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exeO23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exeO23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeO23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exeO23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exeO23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeO23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\endhwnev.exe (file missing)O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exeO23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exeO23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exeO23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXEO23 - Service: lxcr_device - - C:\WINDOWS\system32\lxcrcoms.exeO23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exeO23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exeO23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exeO23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exeO23 - Service: Uno Installer (UnoInstallerService) - Unknown owner - C:\Program Files\M-Audio Uno\UnoInst.exeO23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exeO23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe Link to post Share on other sites
Andro1d Posted October 5, 2007 Report Share Posted October 5, 2007 (edited) Just read your next post Edited October 5, 2007 by MoNsTeReNeRgY22 Link to post Share on other sites
kohu Posted October 5, 2007 Author Report Share Posted October 5, 2007 And heres the Combofix log! I guess it didn't like my supercard's .chtComboFix 07-10-04.6 - Pete's 2007-10-04 19:02:02.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.135 [GMT -7:00]Running from: C:\Documents and Settings\Pete's\Desktop\ComboFix.exe * Created a new restore point.((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))).C:\Documents and Settings\All Users\Application Data.\winantispyware 2007C:\Documents and Settings\All Users\Application Data.\winantispyware 2007\Data\AbbrC:\Documents and Settings\All Users\Application Data.\winantispyware 2007\Data\ProductCodeC:\Documents and Settings\All Users\Application Data\WinAntiSpyware 2007\Data\AbbrC:\Documents and Settings\All Users\Application Data\WinAntiSpyware 2007\Data\ProductCodeC:\Documents and Settings\Pete's\Application Data\install.datC:\Documents and Settings\Pete's\Application Data\WinAntiSpyware 2007C:\Documents and Settings\Pete's\Application Data\WinAntiSpyware 2007\Logs\update.logC:\Documents and Settings\Pete's\Favorites\Error Cleaner.urlC:\Documents and Settings\Pete's\Favorites\Privacy Protector.urlC:\Documents and Settings\Pete's\Favorites\Spyware&Malware Protection.urlC:\Documents and Settings\Pete's\Start Menu\Programs\Startup\ta_start.lnkC:\Program Files\alexa toolbarC:\Program Files\alexa toolbar\uninstall.exeC:\Program Files\Common Files\{30408~1C:\Program Files\Common Files\{30408~1\UnInstall.exeC:\Program Files\Common Files\{30408~2C:\Program Files\Common Files\{30408~2\UnInstall.exeC:\Program Files\Common Files\{40408~1C:\Program Files\Common Files\{40408~2C:\Program Files\Common Files\winantispyware 2007C:\Program Files\Common Files\winantispyware 2007\err.logC:\Program Files\Common Files\Yazzle1122OinUninstaller.exeC:\Program Files\Common Files\Yazzle1281OinUninstaller.exeC:\Program Files\ipwindowsC:\Program Files\ipwindows\Uninst.exeC:\Program Files\outerinfoC:\Program Files\outerinfo\Terms.rtfC:\Program Files\SCC:\Program Files\SC\cheat001.chtC:\Program Files\SC\cheat002.chtC:\Program Files\SC\cheat004.chtC:\Program Files\SC\cheat005.chtC:\Program Files\SC\cheat006.chtC:\Program Files\SC\cheat007.chtC:\Program Files\SC\cheat008.chtC:\Program Files\SC\cheat009.chtC:\Program Files\SC\cheat010.chtC:\Program Files\SC\cheat011.chtC:\Program Files\SC\cheat012.chtC:\Program Files\SC\cheat013.chtC:\Program Files\SC\cheat014.chtC:\Program Files\SC\cheat015.chtC:\Program Files\SC\cheat016.chtC:\Program Files\SC\cheat017.chtC:\Program Files\SC\cheat018.chtC:\Program Files\SC\cheat019.chtC:\Program Files\SC\cheat020.chtC:\Program Files\SC\cheat021.chtC:\Program Files\SC\cheat022.chtC:\Program Files\SC\cheat023.chtC:\Program Files\SC\cheat024.chtC:\Program Files\SC\cheat025.chtC:\Program Files\SC\cheat026.chtC:\Program Files\SC\cheat027.chtC:\Program Files\SC\cheat028.chtC:\Program Files\SC\cheat029.chtC:\Program Files\SC\cheat030.chtC:\Program Files\SC\cheat031.chtC:\Program Files\SC\cheat032.chtC:\Program Files\SC\cheat033.chtC:\Program Files\SC\cheat034.chtC:\Program Files\SC\cheat035.chtC:\Program Files\SC\cheat036.chtC:\Program Files\SC\cheat037.chtC:\Program Files\SC\cheat038.chtC:\Program Files\SC\cheat039.chtC:\Program Files\SC\cheat040.chtC:\Program Files\SC\cheat041.chtC:\Program Files\SC\cheat042.chtC:\Program Files\SC\cheat043.chtC:\Program Files\SC\cheat044.chtC:\Program Files\SC\cheat045.chtC:\Program Files\SC\cheat046.chtC:\Program Files\SC\cheat047.chtC:\Program Files\SC\cheat048.chtC:\Program Files\SC\cheat049.chtC:\Program Files\SC\cheat050.chtC:\Program Files\SC\cheat051.chtC:\Program Files\SC\cheat052.chtC:\Program Files\SC\cheat053.chtC:\Program Files\SC\cheat054.chtC:\Program Files\SC\cheat055.chtC:\Program Files\SC\cheat056.chtC:\Program Files\SC\cheat057.chtC:\Program Files\SC\cheat058.chtC:\Program Files\SC\cheat059.chtC:\Program Files\SC\cheat060.chtC:\Program Files\SC\cheat061.chtC:\Program Files\SC\cheat062.chtC:\Program Files\SC\cheat063.chtC:\Program Files\SC\cheat064.chtC:\Program Files\SC\cheat065.chtC:\Program Files\SC\cheat066.chtC:\Program Files\SC\cheat067.chtC:\Program Files\SC\cheat069.chtC:\Program Files\SC\cheat070.chtC:\Program Files\SC\cheat071.chtC:\Program Files\SC\cheat072.chtC:\Program Files\SC\cheat073.chtC:\Program Files\SC\cheat074.chtC:\Program Files\SC\cheat075.chtC:\Program Files\SC\cheat076.chtC:\Program Files\SC\cheat077.chtC:\Program Files\SC\cheat078.chtC:\Program Files\SC\cheat079.chtC:\Program Files\SC\cheat080.chtC:\Program Files\SC\cheat081.chtC:\Program Files\SC\cheat082.chtC:\Program Files\SC\cheat083.chtC:\Program Files\SC\cheat084.chtC:\Program Files\SC\cheat086.chtC:\Program Files\SC\cheat087.chtC:\Program Files\SC\cheat088.chtC:\Program Files\SC\cheat089.chtC:\Program Files\SC\cheat090.chtC:\Program Files\SC\cheat091.chtC:\Program Files\SC\cheat092.chtC:\Program Files\SC\cheat093.chtC:\Program Files\SC\cheat094.chtC:\Program Files\SC\cheat095.chtC:\Program Files\SC\cheat096.chtC:\Program Files\SC\cheat097.chtC:\Program Files\SC\cheat099.chtC:\Program Files\SC\cheat100.chtC:\Program Files\SC\cheat101.chtC:\Program Files\SC\cheat102.chtC:\Program Files\SC\cheat103.chtC:\Program Files\SC\cheat104.chtC:\Program Files\SC\cheat105.chtC:\Program Files\SC\cheat106.chtC:\Program Files\SC\cheat107.chtC:\Program Files\SC\cheat108.chtC:\Program Files\SC\cheat109.chtC:\Program Files\SC\cheat110.chtC:\Program Files\SC\cheat111.chtC:\Program Files\SC\cheat112.chtC:\Program Files\SC\cheat113.chtC:\Program Files\SC\cheat114.chtC:\Program Files\SC\cheat115.chtC:\Program Files\SC\cheat116.chtC:\Program Files\SC\cheat117.chtC:\Program Files\SC\cheat118.chtC:\Program Files\SC\cheat119.chtC:\Program Files\SC\cheat120.chtC:\Program Files\SC\cheat121.chtC:\Program Files\SC\cheat122.chtC:\Program Files\SC\cheat123.chtC:\Program Files\SC\cheat124.chtC:\Program Files\SC\cheat125.chtC:\Program Files\SC\cheat126.chtC:\Program Files\SC\cheat127.chtC:\Program Files\SC\cheat128.chtC:\Program Files\SC\cheat129.chtC:\Program Files\SC\cheat130.chtC:\Program Files\SC\cheat131.chtC:\Program Files\SC\cheat132.chtC:\Program Files\SC\cheat133.chtC:\Program Files\SC\cheat134.chtC:\Program Files\SC\cheat135.chtC:\Program Files\SC\cheat136.chtC:\Program Files\SC\cheat137.chtC:\Program Files\SC\cheat138.chtC:\Program Files\SC\cheat139.chtC:\Program Files\SC\cheat140.chtC:\Program Files\SC\cheat141.chtC:\Program Files\SC\cheat142.chtC:\Program Files\SC\cheat143.chtC:\Program Files\SC\cheat144.chtC:\Program Files\SC\cheat145.chtC:\Program Files\SC\cheat146.chtC:\Program Files\SC\cheat147.chtC:\Program Files\SC\cheat148.chtC:\Program Files\SC\cheat149.chtC:\Program Files\SC\cheat150.chtC:\Program Files\SC\cheat151.chtC:\Program Files\SC\cheat152.chtC:\Program Files\SC\cheat153.chtC:\Program Files\SC\cheat154.chtC:\Program Files\SC\cheat155.chtC:\Program Files\SC\cheat156.chtC:\Program Files\SC\cheat157.chtC:\Program Files\SC\cheat158.chtC:\Program Files\SC\cheat159.chtC:\Program Files\SC\cheat160.chtC:\Program Files\SC\cheat161.chtC:\Program Files\SC\cheat162.chtC:\Program Files\SC\cheat163.chtC:\Program Files\SC\cheat164.chtC:\Program Files\SC\cheat165.chtC:\Program Files\SC\cheat166.chtC:\Program Files\SC\cheat167.chtC:\Program Files\SC\cheat168.chtC:\Program Files\SC\cheat169.chtC:\Program Files\SC\cheat170.chtC:\Program Files\SC\cheat171.chtC:\Program Files\SC\cheat172.chtC:\Program Files\SC\cheat173.chtC:\Program Files\SC\cheat174.chtC:\Program Files\SC\cheat175.chtC:\Program Files\SC\cheat176.chtC:\Program Files\SC\cheat177.chtC:\Program Files\SC\cheat178.chtC:\Program Files\SC\cheat179.chtC:\Program Files\SC\cheat180.chtC:\Program Files\SC\cheat181.chtC:\Program Files\SC\cheat182.chtC:\Program Files\SC\cheat183.chtC:\Program Files\SC\cheat184.chtC:\Program Files\SC\cheat185.chtC:\Program Files\SC\cheat186.chtC:\Program Files\SC\cheat187.chtC:\Program Files\SC\cheat188.chtC:\Program Files\SC\cheat189.chtC:\Program Files\SC\cheat190.chtC:\Program Files\SC\cheat191.chtC:\Program Files\SC\cheat192.chtC:\Program Files\SC\cheat193.chtC:\Program Files\SC\cheat194.chtC:\Program Files\SC\cheat195.chtC:\Program Files\SC\cheat196.chtC:\Program Files\SC\cheat197.chtC:\Program Files\SC\cheat198.chtC:\Program Files\SC\cheat199.chtC:\Program Files\SC\cheat200.chtC:\Program Files\SC\cheat201.chtC:\Program Files\SC\cheat202.chtC:\Program Files\SC\cheat203.chtC:\Program Files\SC\cheat204.chtC:\Program Files\SC\cheat205.chtC:\Program Files\SC\cheat206.chtC:\Program Files\SC\cheat207.chtC:\Program Files\SC\cheat208.chtC:\Program Files\SC\cheat209.chtC:\Program Files\SC\cheat210.chtC:\Program Files\SC\cheat211.chtC:\Program Files\SC\cheat212.chtC:\Program Files\SC\cheat213.chtC:\Program Files\SC\cheat214.chtC:\Program Files\SC\cheat215.chtC:\Program Files\SC\cheat216.chtC:\Program Files\SC\cheat217.chtC:\Program Files\SC\cheat218.chtC:\Program Files\SC\cheat219.chtC:\Program Files\SC\cheat220.chtC:\Program Files\SC\cheat221.chtC:\Program Files\SC\cheat222.chtC:\Program Files\SC\cheat223.chtC:\Program Files\SC\cheat224.chtC:\Program Files\SC\cheat225.chtC:\Program Files\SC\cheat226.chtC:\Program Files\SC\cheat227.chtC:\Program Files\SC\cheat228.chtC:\Program Files\SC\cheat229.chtC:\Program Files\SC\cheat230.chtC:\Program Files\SC\cheat231.chtC:\Program Files\SC\cheat232.chtC:\Program Files\SC\cheat233.chtC:\Program Files\SC\cheat234.chtC:\Program Files\SC\cheat235.chtC:\Program Files\SC\cheat236.chtC:\Program Files\SC\cheat237.chtC:\Program Files\SC\cheat238.chtC:\Program Files\SC\cheat239.chtC:\Program Files\SC\cheat240.chtC:\Program Files\SC\cheat241.chtC:\Program Files\SC\cheat242.chtC:\Program Files\SC\cheat243.chtC:\Program Files\SC\cheat244.chtC:\Program Files\SC\cheat245.chtC:\Program Files\SC\cheat246.chtC:\Program Files\SC\cheat247.chtC:\Program Files\SC\cheat248.chtC:\Program Files\SC\cheat249.chtC:\Program Files\SC\cheat250.chtC:\Program Files\SC\cheat251.chtC:\Program Files\SC\cheat252.chtC:\Program Files\SC\cheat253.chtC:\Program Files\SC\cheat254.chtC:\Program Files\SC\cheat255.chtC:\Program Files\SC\cheat256.chtC:\Program Files\SC\cheat257.chtC:\Program Files\SC\cheat258.chtC:\Program Files\SC\cheat259.chtC:\Program Files\SC\cheat260.chtC:\Program Files\SC\cheat261.chtC:\Program Files\SC\cheat262.chtC:\Program Files\SC\cheat263.chtC:\Program Files\SC\cheat264.chtC:\Program Files\SC\cheat265.chtC:\Program Files\SC\cheat266.chtC:\Program Files\SC\cheat267.chtC:\Program Files\SC\cheat268.chtC:\Program Files\SC\cheat269.chtC:\Program Files\SC\cheat270.chtC:\Program Files\SC\cheat271.chtC:\Program Files\SC\cheat272.chtC:\Program Files\SC\cheat273.chtC:\Program Files\SC\cheat274.chtC:\Program Files\SC\cheat275.chtC:\Program Files\SC\cheat276.chtC:\Program Files\SC\cheat277.chtC:\Program Files\SC\cheat278.chtC:\Program Files\SC\cheat279.chtC:\Program Files\SC\cheat280.chtC:\Program Files\SC\cheat281.chtC:\Program Files\SC\cheat282.chtC:\Program Files\SC\cheat283.chtC:\Program Files\SC\cheat284.chtC:\Program Files\SC\cheat285.chtC:\Program Files\SC\cheat286.chtC:\Program Files\SC\cheat287.chtC:\Program Files\SC\cheat288.chtC:\Program Files\SC\cheat289.chtC:\Program Files\SC\cheat290.chtC:\Program Files\SC\cheat291.chtC:\Program Files\SC\cheat292.chtC:\Program Files\SC\cheat293.chtC:\Program Files\SC\cheat294.chtC:\Program Files\SC\cheat295.chtC:\Program Files\SC\cheat296.chtC:\Program Files\SC\cheat297.chtC:\Program Files\SC\cheat298.chtC:\Program Files\SC\cheat299.chtC:\Program Files\SC\cheat300.chtC:\Program Files\SC\cheat301.chtC:\Program Files\SC\cheat302.chtC:\Program Files\SC\cheat303.chtC:\Program Files\SC\cheat304.chtC:\Program Files\SC\cheat305.chtC:\Program Files\SC\cheat306.chtC:\Program Files\SC\cheat307.chtC:\Program Files\SC\cheat308.chtC:\Program Files\SC\cheat309.chtC:\Program Files\SC\cheat310.chtC:\Program Files\SC\cheat311.chtC:\Program Files\SC\cheat312.chtC:\Program Files\SC\cheat313.chtC:\Program Files\SC\cheat314.chtC:\Program Files\SC\cheat315.chtC:\Program Files\SC\cheat316.chtC:\Program Files\SC\cheat317.chtC:\Program Files\SC\cheat318.chtC:\Program Files\SC\cheat319.chtC:\Program Files\SC\cheat320.chtC:\Program Files\SC\cheat321.chtC:\Program Files\SC\cheat322.chtC:\Program Files\SC\cheat323.chtC:\Program Files\SC\cheat324.chtC:\Program Files\SC\cheat325.chtC:\Program Files\SC\cheat326.chtC:\Program Files\SC\cheat327.chtC:\Program Files\SC\cheat328.chtC:\Program Files\SC\cheat329.chtC:\Program Files\SC\cheat330.chtC:\Program Files\SC\cheat331.chtC:\Program Files\SC\cheat332.chtC:\Program Files\SC\cheat333.chtC:\Program Files\SC\cheat334.chtC:\Program Files\SC\cheat335.chtC:\Program Files\SC\cheat336.chtC:\Program Files\SC\cheat337.chtC:\Program Files\SC\cheat338.chtC:\Program Files\SC\cheat339.chtC:\Program Files\SC\cheat340.chtC:\Program Files\SC\cheat341.chtC:\Program Files\SC\cheat342.chtC:\Program Files\SC\cheat343.chtC:\Program Files\SC\cheat344.chtC:\Program Files\SC\cheat345.chtC:\Program Files\SC\cheat346.chtC:\Program Files\SC\cheat347.chtC:\Program Files\SC\cheat348.chtC:\Program Files\SC\cheat349.chtC:\Program Files\SC\cheat350.chtC:\Program Files\SC\cheat351.chtC:\Program Files\SC\cheat352.chtC:\Program Files\SC\cheat353.chtC:\Program Files\SC\cheat354.chtC:\Program Files\SC\cheat355.chtC:\Program Files\SC\cheat356.chtC:\Program Files\SC\cheat357.chtC:\Program Files\SC\cheat358.chtC:\Program Files\SC\cheat359.chtC:\Program Files\SC\cheat360.chtC:\Program Files\SC\cheat361.chtC:\Program Files\SC\cheat362.chtC:\Program Files\SC\cheat363.chtC:\Program Files\SC\cheat364.chtC:\Program Files\SC\cheat365.chtC:\Program Files\SC\cheat366.chtC:\Program Files\SC\cheat367.chtC:\Program Files\SC\cheat368.chtC:\Program Files\SC\cheat369.chtC:\Program Files\SC\cheat370.chtC:\Program Files\SC\cheat371.chtC:\Program Files\SC\cheat372.chtC:\Program Files\SC\cheat373.chtC:\Program Files\SC\cheat374.chtC:\Program Files\SC\cheat375.chtC:\Program Files\SC\cheat376.chtC:\Program Files\SC\cheat377.chtC:\Program Files\SC\cheat378.chtC:\Program Files\SC\cheat379.chtC:\Program Files\SC\cheat380.chtC:\Program Files\SC\cheat381.chtC:\Program Files\SC\cheat382.chtC:\Program Files\SC\cheat383.chtC:\Program Files\SC\cheat384.chtC:\Program Files\SC\cheat385.chtC:\Program Files\SC\cheat386.chtC:\Program Files\SC\cheat387.chtC:\Program Files\SC\cheat388.chtC:\Program Files\SC\cheat389.chtC:\Program Files\SC\cheat390.chtC:\Program Files\SC\cheat391.chtC:\Program Files\SC\cheat392.chtC:\Program Files\SC\cheat393.chtC:\Program Files\SC\cheat394.chtC:\Program Files\SC\cheat395.chtC:\Program Files\SC\cheat396.chtC:\Program Files\SC\cheat397.chtC:\Program Files\SC\cheat398.chtC:\Program Files\SC\cheat399.chtC:\Program Files\SC\cheat400.chtC:\Program Files\SC\cheat401.chtC:\Program Files\SC\cheat402.chtC:\Program Files\SC\cheat403.chtC:\Program Files\SC\cheat404.chtC:\Program Files\SC\cheat405.chtC:\Program Files\SC\cheat406.chtC:\Program Files\SC\cheat407.chtC:\Program Files\SC\cheat408.chtC:\Program Files\SC\cheat409.chtC:\Program Files\SC\cheat410.chtC:\Program Files\SC\cheat411.chtC:\Program Files\SC\cheat412.chtC:\Program Files\SC\cheat413.chtC:\Program Files\SC\cheat414.chtC:\Program Files\SC\cheat415.chtC:\Program Files\SC\cheat416.chtC:\Program Files\SC\cheat417.chtC:\Program Files\SC\cheat418.chtC:\Program Files\SC\cheat419.chtC:\Program Files\SC\cheat420.chtC:\Program Files\SC\cheat421.chtC:\Program Files\SC\cheat422.chtC:\Program Files\SC\cheat423.chtC:\Program Files\SC\cheat424.chtC:\Program Files\SC\cheat425.chtC:\Program Files\SC\cheat426.chtC:\Program Files\SC\cheat427.chtC:\Program Files\SC\cheat428.chtC:\Program Files\SC\cheat429.chtC:\Program Files\SC\cheat430.chtC:\Program Files\SC\cheat431.chtC:\Program Files\SC\cheat432.chtC:\Program Files\SC\cheat433.chtC:\Program Files\SC\cheat434.chtC:\Program Files\SC\cheat435.chtC:\Program Files\SC\cheat436.chtC:\Program Files\SC\cheat437.chtC:\Program Files\SC\cheat438.chtC:\Program Files\SC\cheat439.chtC:\Program Files\SC\cheat440.chtC:\Program Files\SC\cheat441.chtC:\Program Files\SC\cheat442.chtC:\Program Files\SC\cheat443.chtC:\Program Files\SC\cheat444.chtC:\Program Files\SC\cheat445.chtC:\Program Files\SC\cheat446.chtC:\Program Files\SC\cheat447.chtC:\Program Files\SC\cheat448.chtC:\Program Files\SC\cheat449.chtC:\Program Files\SC\cheat450.chtC:\Program Files\SC\cheat451.chtC:\Program Files\SC\cheat452.chtC:\Program Files\SC\cheat453.chtC:\Program Files\SC\cheat454.chtC:\Program Files\SC\cheat455.chtC:\Program Files\SC\cheat456.chtC:\Program Files\SC\cheat457.chtC:\Program Files\SC\cheat458.chtC:\Program Files\SC\cheat459.chtC:\Program Files\SC\cheat460.chtC:\Program Files\SC\cheat461.chtC:\Program Files\SC\cheat462.chtC:\Program Files\SC\cheat463.chtC:\Program Files\SC\cheat464.chtC:\Program Files\SC\cheat465.chtC:\Program Files\SC\cheat466.chtC:\Program Files\SC\cheat467.chtC:\Program Files\SC\cheat468.chtC:\Program Files\SC\cheat469.chtC:\Program Files\SC\cheat470.chtC:\Program Files\SC\cheat471.chtC:\Program Files\SC\cheat472.chtC:\Program Files\SC\cheat473.chtC:\Program Files\SC\cheat474.chtC:\Program Files\SC\cheat475.chtC:\Program Files\SC\cheat476.chtC:\Program Files\SC\cheat477.chtC:\Program Files\SC\cheat478.chtC:\Program Files\SC\cheat479.chtC:\Program Files\SC\cheat480.chtC:\Program Files\SC\cheat481.chtC:\Program Files\SC\cheat482.chtC:\Program Files\SC\cheat483.chtC:\Program Files\SC\cheat484.chtC:\Program Files\SC\cheat485.chtC:\Program Files\SC\cheat486.chtC:\Program Files\SC\cheat487.chtC:\Program Files\SC\cheat488.chtC:\Program Files\SC\cheat489.chtC:\Program Files\SC\cheat490.chtC:\Program Files\SC\cheat491.chtC:\Program Files\SC\cheat492.chtC:\Program Files\SC\cheat493.chtC:\Program Files\SC\cheat494.chtC:\Program Files\SC\cheat495.chtC:\Program Files\SC\cheat496.chtC:\Program Files\SC\cheat497.chtC:\Program Files\SC\cheat498.chtC:\Program Files\SC\cheat499.chtC:\Program Files\SC\cheat500.chtC:\Program Files\SC\cheat501.chtC:\Program Files\SC\cheat502.chtC:\Program Files\SC\cheat503.chtC:\Program Files\SC\cheat504.chtC:\Program Files\SC\cheat505.chtC:\Program Files\SC\cheat506.chtC:\Program Files\SC\cheat507.chtC:\Program Files\SC\cheat508.chtC:\Program Files\SC\cheat509.chtC:\Program Files\SC\cheat510.chtC:\Program Files\SC\cheat511.chtC:\Program Files\SC\cheat512.chtC:\Program Files\SC\cheat513.chtC:\Program Files\SC\cheat514.chtC:\Program Files\SC\cheat515.chtC:\Program Files\SC\cheat516.chtC:\Program Files\SC\cheat517.chtC:\Program Files\SC\cheat518.chtC:\Program Files\SC\cheat519.chtC:\Program Files\SC\cheat520.chtC:\Program Files\SC\cheat521.chtC:\Program Files\SC\cheat522.chtC:\Program Files\SC\cheat523.chtC:\Program Files\SC\cheat524.chtC:\Program Files\SC\cheat525.chtC:\Program Files\SC\cheat526.chtC:\Program Files\SC\cheat527.chtC:\Program Files\SC\cheat528.chtC:\Program Files\SC\cheat529.chtC:\Program Files\SC\cheat530.chtC:\Program Files\SC\cheat532.chtC:\Program Files\SC\cheat533.chtC:\Program Files\SC\cheat534.chtC:\Program Files\SC\cheat535.chtC:\Program Files\SC\cheat536.chtC:\Program Files\SC\cheat537.chtC:\Program Files\SC\cheat538.chtC:\Program Files\SC\cheat539.chtC:\Program Files\SC\cheat540.chtC:\Program Files\SC\cheat541.chtC:\Program Files\SC\cheat542.chtC:\Program Files\SC\cheat543.chtC:\Program Files\SC\cheat544.chtC:\Program Files\SC\cheat545.chtC:\Program Files\SC\cheat547.chtC:\Program Files\SC\cheat548.chtC:\Program Files\SC\cheat549.chtC:\Program Files\SC\cheat550.chtC:\Program Files\SC\cheat551.chtC:\Program Files\SC\cheat553.chtC:\Program Files\SC\cheat554.chtC:\Program Files\SC\cheat555.chtC:\Program Files\SC\cheat556.chtC:\Program Files\SC\cheat557.chtC:\Program Files\SC\cheat558.chtC:\Program Files\SC\cheat559.chtC:\Program Files\SC\cheat560.chtC:\Program Files\SC\cheat561.chtC:\Program Files\SC\cheat562.chtC:\Program Files\SC\cheat563.chtC:\Program Files\SC\cheat564.chtC:\Program Files\SC\cheat565.chtC:\Program Files\SC\cheat566.chtC:\Program Files\SC\cheat567.chtC:\Program Files\SC\cheat568.chtC:\Program Files\SC\cheat569.chtC:\Program Files\SC\cheat570.chtC:\Program Files\SC\cheat571.chtC:\Program Files\SC\cheat573.chtC:\Program Files\SC\cheat574.chtC:\Program Files\SC\cheat575.chtC:\Program Files\SC\cheat576.chtC:\Program Files\SC\cheat577.chtC:\Program Files\SC\cheat578.chtC:\Program Files\SC\cheat579.chtC:\Program Files\SC\cheat580.chtC:\Program Files\SC\cheat581.chtC:\Program Files\SC\cheat582.chtC:\Program Files\SC\cheat583.chtC:\Program Files\SC\cheat584.chtC:\Program Files\SC\cheat585.chtC:\Program Files\SC\cheat586.chtC:\Program Files\SC\cheat587.chtC:\Program Files\SC\cheat589.chtC:\Program Files\SC\cheat590.chtC:\Program Files\SC\cheat591.chtC:\Program Files\SC\cheat592.chtC:\Program Files\SC\cheat593.chtC:\Program Files\SC\cheat594.chtC:\Program Files\SC\cheat595.chtC:\Program Files\SC\cheat596.chtC:\Program Files\SC\cheat597.chtC:\Program Files\SC\cheat598.chtC:\Program Files\SC\cheat599.chtC:\Program Files\SC\cheat600.chtC:\Program Files\SC\cheat601.chtC:\Program Files\SC\cheat602.chtC:\Program Files\SC\cheat604.chtC:\Program Files\SC\cheat605.chtC:\Program Files\SC\cheat606.chtC:\Program Files\SC\cheat607.chtC:\Program Files\SC\cheat608.chtC:\Program Files\SC\cheat610.chtC:\Program Files\SC\cheat611.chtC:\Program Files\SC\cheat612.chtC:\Program Files\SC\cheat613.chtC:\Program Files\SC\cheat614.chtC:\Program Files\SC\cheat615.chtC:\Program Files\SC\cheat616.chtC:\Program Files\SC\cheat617.chtC:\Program Files\SC\cheat618.chtC:\Program Files\SC\cheat619.chtC:\Program Files\SC\cheat620.chtC:\Program Files\SC\cheat621.chtC:\Program Files\SC\cheat622.chtC:\Program Files\SC\cheat623.chtC:\Program Files\SC\cheat624.chtC:\Program Files\SC\cheat625.chtC:\Program Files\SC\cheat626.chtC:\Program Files\SC\cheat627.chtC:\Program Files\SC\cheat628.chtC:\Program Files\SC\cheat630.chtC:\Program Files\SC\cheat631.chtC:\Program Files\SC\cheat632.chtC:\Program Files\SC\cheat633.chtC:\Program Files\SC\cheat634.chtC:\Program Files\SC\cheat635.chtC:\Program Files\SC\cheat636.chtC:\Program Files\SC\cheat637.chtC:\Program Files\SC\cheat638.chtC:\Program Files\SC\cheat639.chtC:\Program Files\SC\cheat640.chtC:\Program Files\SC\cheat641.chtC:\Program Files\SC\cheat642.chtC:\Program Files\SC\cheat643.chtC:\Program Files\SC\cheat645.chtC:\Program Files\SC\cheat646.chtC:\Program Files\SC\cheat647.chtC:\Program Files\SC\cheat648.chtC:\Program Files\SC\cheat649.chtC:\Program Files\SC\cheat650.chtC:\Program Files\SC\cheat651.chtC:\Program Files\SC\cheat652.chtC:\Program Files\SC\cheat653.chtC:\Program Files\SC\cheat654.chtC:\Program Files\SC\cheat655.chtC:\Program Files\SC\cheat656.chtC:\Program Files\SC\cheat657.chtC:\Program Files\SC\cheat658.chtC:\Program Files\SC\cheat659.chtC:\Program Files\SC\cheat660.chtC:\Program Files\SC\cheat662.chtC:\Program Files\SC\cheat664.chtC:\Program Files\SC\cheat665.chtC:\Program Files\SC\cheat666.chtC:\Program Files\SC\cheat667.chtC:\Program Files\SC\cheat669.chtC:\Program Files\SC\cheat670.chtC:\Program Files\SC\cheat672.chtC:\Program Files\SC\cheat673.chtC:\Program Files\SC\cheat674.chtC:\Program Files\SC\cheat675.chtC:\Program Files\SC\cheat676.chtC:\Program Files\SC\cheat677.chtC:\Program Files\SC\cheat678.chtC:\Program Files\SC\cheat679.chtC:\Program Files\SC\cheat680.chtC:\Program Files\SC\cheat681.chtC:\Program Files\SC\cheat682.chtC:\Program Files\SC\cheat683.chtC:\Program Files\SC\cheat684.chtC:\Program Files\SC\cheat685.chtC:\Program Files\SC\cheat688.chtC:\Program Files\SC\cheat691.chtC:\Program Files\SC\cheat692.chtC:\Program Files\SC\cheat693.chtC:\Program Files\SC\cheat694.chtC:\Program Files\SC\cheat695.chtC:\Program Files\SC\cheat696.chtC:\Program Files\SC\cheat697.chtC:\Program Files\SC\cheat698.chtC:\Program Files\SC\cheat699.chtC:\Program Files\SC\cheat700.chtC:\Program Files\SC\cheat701.chtC:\Program Files\SC\cheat702.chtC:\Program Files\SC\cheat703.chtC:\Program Files\SC\cheat704.chtC:\Program Files\SC\cheat705.chtC:\Program Files\SC\cheat706.chtC:\Program Files\SC\cheat707.chtC:\Program Files\SC\cheat708.chtC:\Program Files\SC\cheat709.chtC:\Program Files\SC\cheat710.chtC:\Program Files\SC\cheat711.chtC:\Program Files\SC\cheat712.chtC:\Program Files\SC\cheat713.chtC:\Program Files\SC\cheat714.chtC:\Program Files\SC\cheat715.chtC:\Program Files\SC\cheat716.chtC:\Program Files\SC\cheat717.chtC:\Program Files\SC\cheat718.chtC:\Program Files\SC\cheat719.chtC:\Program Files\SC\cheat720.chtC:\Program Files\SC\cheat721.chtC:\Program Files\SC\cheat722.chtC:\Program Files\SC\cheat723.chtC:\Program Files\SC\cheat724.chtC:\Program Files\SC\cheat725.chtC:\Program Files\SC\cheat726.chtC:\Program Files\SC\cheat727.chtC:\Program Files\SC\cheat728.chtC:\Program Files\SC\cheat729.chtC:\Program Files\SC\cheat730.chtC:\Program Files\SC\cheat731.chtC:\Program Files\SC\cheat732.chtC:\Program Files\SC\cheat733.chtC:\Program Files\SC\cheat734.chtC:\Program Files\SC\cheat735.chtC:\Program Files\SC\cheat736.chtC:\Program Files\SC\cheat737.chtC:\Program Files\SC\cheat738.chtC:\Program Files\SC\cheat739.chtC:\Program Files\SC\cheat740.chtC:\Program Files\SC\cheat741.chtC:\Program Files\SC\cheat742.chtC:\Program Files\SC\cheat743.chtC:\Program Files\SC\cheat744.chtC:\Program Files\SC\cheat745.chtC:\Program Files\SC\cheat746.chtC:\Program Files\SC\cheat748.chtC:\Program Files\SC\cheat749.chtC:\Program Files\SC\cheat750.chtC:\Program Files\SC\cheat751.chtC:\Program Files\SC\cheat752.chtC:\Program Files\SC\cheat753.chtC:\Program Files\SC\cheat755.chtC:\Program Files\SC\cheat756.chtC:\Program Files\SC\cheat758.chtC:\Program Files\SC\cheat759.chtC:\Program Files\SC\cheat761.chtC:\Program Files\SC\cheat762.chtC:\Program Files\SC\cheat763.chtC:\Program Files\SC\cheat764.chtC:\Program Files\SC\cheat765.chtC:\Program Files\SC\cheat766.chtC:\Program Files\SC\cheat767.chtC:\Program Files\SC\cheat768.chtC:\Program Files\SC\cheat769.chtC:\Program Files\SC\cheat770.chtC:\Program Files\SC\cheat771.chtC:\Program Files\SC\cheat772.chtC:\Program Files\SC\cheat773.chtC:\Program Files\SC\cheat775.chtC:\Program Files\SC\cheat776.chtC:\Program Files\SC\cheat777.chtC:\Program Files\SC\cheat778.chtC:\Program Files\SC\cheat779.chtC:\Program Files\SC\cheat780.chtC:\Program Files\SC\cheat782.chtC:\Program Files\SC\cheat783.chtC:\Program Files\SC\cheat784.chtC:\Program Files\SC\cheat785.chtC:\Program Files\SC\cheat786.chtC:\Program Files\SC\cheat787.chtC:\Program Files\SC\cheat788.chtC:\Program Files\SC\cheat789.chtC:\Program Files\SC\cheat790.chtC:\Program Files\SC\cheat791.chtC:\Program Files\SC\cheat792.chtC:\Program Files\SC\cheat793.chtC:\Program Files\SC\cheat794.chtC:\Program Files\SC\cheat795.chtC:\Program Files\SC\cheat796.chtC:\Program Files\SC\cheat797.chtC:\Program Files\SC\cheat798.chtC:\Program Files\SC\cheat799.chtC:\Program Files\SC\cheat800.chtC:\Program Files\SC\cheat801.chtC:\Program Files\SC\cheat802.chtC:\Program Files\SC\cheat803.chtC:\Program Files\SC\cheat804.chtC:\Program Files\SC\cheat805.chtC:\Program Files\SC\cheat806.chtC:\Program Files\SC\cheat808.chtC:\Program Files\SC\cheat809.chtC:\Program Files\SC\cheat810.chtC:\Program Files\SC\cheat811.chtC:\Program Files\SC\cheat812.chtC:\Program Files\SC\cheat813.chtC:\Program Files\SC\cheat814.chtC:\Program Files\SC\cheat815.chtC:\Program Files\SC\cheat816.chtC:\Program Files\SC\cheat817.chtC:\Program Files\SC\cheat818.chtC:\Program Files\SC\cheat819.chtC:\Program Files\SC\cheat820.chtC:\Program Files\SC\cheat821.chtC:\Program Files\SC\cheat823.chtC:\Program Files\SC\cheat824.chtC:\Program Files\SC\cheat825.chtC:\Program Files\SC\cheat826.chtC:\Program Files\SC\cheat827.chtC:\Program Files\SC\cheat828.chtC:\Program Files\SC\cheat829.chtC:\Program Files\SC\cheat830.chtC:\Program Files\SC\cheat831.chtC:\Program Files\SC\cheat833.chtC:\Program Files\SC\cheat835.chtC:\Program Files\SC\cheat836.chtC:\Program Files\SC\cheat837.chtC:\Program Files\SC\cheat838.chtC:\Program Files\SC\cheat839.chtC:\Program Files\SC\cheat840.chtC:\Program Files\SC\cheat841.chtC:\Program Files\SC\cheat842.chtC:\Program Files\SC\cheat843.chtC:\Program Files\SC\cheat844.chtC:\Program Files\SC\cheat845.chtC:\Program Files\SC\cheat846.chtC:\Program Files\SC\cheat847.chtC:\Program Files\SC\cheat849.chtC:\Program Files\SC\cheat850.chtC:\Program Files\SC\cheat851.chtC:\Program Files\SC\cheat852.chtC:\Program Files\SC\cheat853.chtC:\Program Files\SC\cheat854.chtC:\Program Files\SC\cheat855.chtC:\Program Files\SC\cheat856.chtC:\Program Files\SC\cheat857.chtC:\Program Files\SC\cheat858.chtC:\Program Files\SC\cheat859.chtC:\Program Files\SC\cheat860.chtC:\Program Files\SC\cheat861.chtC:\Program Files\SC\cheat862.chtC:\Program Files\SC\cheat863.chtC:\Program Files\SC\cheat864.chtC:\Program Files\SC\cheat865.chtC:\Program Files\SC\cheat866.chtC:\Program Files\SC\cheat867.chtC:\Program Files\SC\cheat868.chtC:\Program Files\SC\cheat869.chtC:\Program Files\SC\cheat870.chtC:\Program Files\SC\cheat871.chtC:\Program Files\SC\cheat872.chtC:\Program Files\SC\cheat873.chtC:\Program Files\SC\cheat874.chtC:\Program Files\SC\cheat875.chtC:\Program Files\SC\cheat876.chtC:\Program Files\SC\cheat877.chtC:\Program Files\SC\cheat879.chtC:\Program Files\SC\cheat880.chtC:\Program Files\SC\cheat881.chtC:\Program Files\SC\cheat882.chtC:\Program Files\SC\cheat883.chtC:\Program Files\SC\cheat884.chtC:\Program Files\SC\cheat885.chtC:\Program Files\SC\cheat886.chtC:\Program Files\SC\cheat887.chtC:\Program Files\SC\cheat888.chtC:\Program Files\SC\cheat890.chtC:\Program Files\SC\cheat891.chtC:\Program Files\SC\cheat892.chtC:\Program Files\SC\cheat893.chtC:\Program Files\SC\cheat894.chtC:\Program Files\SC\cheat895.chtC:\Program Files\SC\cheat896.chtC:\Program Files\SC\cheat897.chtC:\Program Files\SC\cheat898.chtC:\Program Files\SC\cheat899.chtC:\Program Files\SC\cheat900.chtC:\Program Files\SC\cheat901.chtC:\Program Files\SC\cheat902.chtC:\Program Files\SC\cheat903.chtC:\Program Files\SC\cheat904.chtC:\Program Files\SC\cheat905.chtC:\Program Files\SC\cheat906.chtC:\Program Files\SC\cheat907.chtC:\Program Files\SC\cheat908.chtC:\Program Files\SC\cheat909.chtC:\Program Files\SC\cheat910.chtC:\Program Files\SC\cheat911.chtC:\Program Files\SC\cheat912.chtC:\Program Files\SC\cheat913.chtC:\Program Files\SC\cheat914.chtC:\Program Files\SC\cheat915.chtC:\Program Files\SC\cheat916.chtC:\Program Files\SC\cheat917.chtC:\Program Files\SC\cheat918.chtC:\Program Files\SC\cheat920.chtC:\Program Files\SC\cheat921.chtC:\Program Files\SC\cheat922.chtC:\Program Files\SC\cheat923.chtC:\Program Files\SC\cheat924.chtC:\Program Files\SC\cheat925.chtC:\Program Files\SC\cheat926.chtC:\Program Files\SC\cheat927.chtC:\Program Files\SC\cheat928.chtC:\Program Files\SC\cheat929.chtC:\Program Files\SC\cheat930.chtC:\Program Files\SC\cheat931.chtC:\Program Files\SC\cheat932.chtC:\Program Files\SC\cheat934.chtC:\Program Files\SC\cheat935.chtC:\Program Files\SC\cheat936.chtC:\Program Files\SC\cheat937.chtC:\Program Files\SC\cheat938.chtC:\Program Files\SC\cheat939.chtC:\Program Files\SC\cheat940.chtC:\Program Files\SC\cheat941.chtC:\Program Files\SC\cheat942.chtC:\Program Files\SC\cheat943.chtC:\Program Files\SC\cheat944.chtC:\Program Files\SC\cheat945.chtC:\Program Files\SC\cheat946.chtC:\Program Files\SC\cheat948.chtC:\Program Files\SC\cheat949.chtC:\Program Files\SC\cheat950.chtC:\Program Files\SC\cheat951.chtC:\Program Files\SC\cheat952.chtC:\Program Files\SC\cheat953.chtC:\Program Files\SC\cheat954.chtC:\Program Files\SC\cheat955.chtC:\Program Files\SC\cheat956.chtC:\Program Files\SC\cheat957.chtC:\Program Files\SC\cheat958.chtC:\Program Files\SC\cheat959.chtC:\Program Files\SC\cheat960.chtC:\Program Files\SC\cheat961.chtC:\Program Files\SC\cheat962.chtC:\Program Files\SC\cheat963.chtC:\Program Files\SC\cheat964.chtC:\Program Files\SC\cheat966.chtC:\Program Files\SC\cheat967.chtC:\Program Files\SC\cheat968.chtC:\Program Files\SC\cheat969.chtC:\Program Files\SC\cheat970.chtC:\Program Files\SC\cheat971.chtC:\Program Files\SC\cheat972.chtC:\Program Files\SC\cheat973.chtC:\Program Files\SC\cheat974.chtC:\Program Files\SC\cheat975.chtC:\Program Files\SC\cheat976.chtC:\Program Files\SC\cheat977.chtC:\Program Files\SC\cheat978.chtC:\Program Files\SC\cheat979.chtC:\Program Files\SC\cheat980.chtC:\Program Files\SC\cheat982.chtC:\Program Files\SC\cheat983.chtC:\Program Files\SC\cheat984.chtC:\Program Files\SC\cheat985.chtC:\Program Files\SC\cheat986.chtC:\Program Files\SC\cheat987.chtC:\Program Files\SC\cheat989.chtC:\Program Files\SC\cheat990.chtC:\Program Files\SC\cheat991.chtC:\Program Files\SC\cheat992.chtC:\Program Files\SC\cheat993.chtC:\Program Files\SC\cheat994.chtC:\Program Files\SC\cheat995.chtC:\Program Files\SC\cheat996.chtC:\Program Files\SC\cheat997.chtC:\Program Files\SC\cheat998.chtC:\Program Files\SC\cheat999.chtC:\Program Files\SC\cheat\1000.chtC:\Program Files\SC\cheat\1001.chtC:\Program Files\SC\cheat\1002.chtC:\Program Files\SC\cheat\1003.chtC:\Program Files\SC\cheat\1004.chtC:\Program Files\SC\cheat\1005.chtC:\Program Files\SC\cheat\1006.chtC:\Program Files\SC\cheat\1007.chtC:\Program Files\SC\cheat\1008.chtC:\Program Files\SC\cheat\1009.chtC:\Program Files\SC\cheat\1010.chtC:\Program Files\SC\cheat\1011.chtC:\Program Files\SC\cheat\1012.chtC:\Program Files\SC\cheat\1013.chtC:\Program Files\SC\cheat\1014.chtC:\Program Files\SC\cheat\1015.chtC:\Program Files\SC\cheat\1016.chtC:\Program Files\SC\cheat\1017.chtC:\Program Files\SC\cheat\1018.chtC:\Program Files\SC\cheat\1019.chtC:\Program Files\SC\cheat\1020.chtC:\Program Files\SC\cheat\1021.chtC:\Program Files\SC\cheat\1022.chtC:\Program Files\SC\cheat\1023.chtC:\Program Files\SC\cheat\1024.chtC:\Program Files\SC\cheat\1025.chtC:\Program Files\SC\cheat\1026.chtC:\Program Files\SC\cheat\1027.chtC:\Program Files\SC\cheat\1028.chtC:\Program Files\SC\cheat\1029.chtC:\Program Files\SC\cheat\1031.chtC:\Program Files\SC\cheat\1032.chtC:\Program Files\SC\cheat\1033.chtC:\Program Files\SC\cheat\1034.chtC:\Program Files\SC\cheat\1035.chtC:\Program Files\SC\cheat\1036.chtC:\Program Files\SC\cheat\1037.chtC:\Program Files\SC\cheat\1038.chtC:\Program Files\SC\cheat\1039.chtC:\Program Files\SC\cheat\1040.chtC:\Program Files\SC\cheat\1041.chtC:\Program Files\SC\cheat\1042.chtC:\Program Files\SC\cheat\1043.chtC:\Program Files\SC\cheat\1044.chtC:\Program Files\SC\cheat\1045.chtC:\Program Files\SC\cheat\1046.chtC:\Program Files\SC\cheat\1047.chtC:\Program Files\SC\cheat\1048.chtC:\Program Files\SC\cheat\1049.chtC:\Program Files\SC\cheat\1050.chtC:\Program Files\SC\cheat\1051.chtC:\Program Files\SC\cheat\1052.chtC:\Program Files\SC\cheat\1053.chtC:\Program Files\SC\cheat\1054.chtC:\Program Files\SC\cheat\1055.chtC:\Program Files\SC\cheat\1057.chtC:\Program Files\SC\cheat\1058.chtC:\Program Files\SC\cheat\1059.chtC:\Program Files\SC\cheat\1060.chtC:\Program Files\SC\cheat\1062.chtC:\Program Files\SC\cheat\1063.chtC:\Program Files\SC\cheat\1064.chtC:\Program Files\SC\cheat\1065.chtC:\Program Files\SC\cheat\1066.chtC:\Program Files\SC\cheat\1067.chtC:\Program Files\SC\cheat\1068.chtC:\Program Files\SC\cheat\1069.chtC:\Program Files\SC\cheat\1070.chtC:\Program Files\SC\cheat\1071.chtC:\Program Files\SC\cheat\1072.chtC:\Program Files\SC\cheat\1074.chtC:\Program Files\SC\cheat\1076.chtC:\Program Files\SC\cheat\1077.chtC:\Program Files\SC\cheat\1078.chtC:\Program Files\SC\cheat\1079.chtC:\Program Files\SC\cheat\1080.chtC:\Program Files\SC\cheat\1081.chtC:\Program Files\SC\cheat\1082.chtC:\Program Files\SC\cheat\1083.chtC:\Program Files\SC\cheat\1085.chtC:\Program Files\SC\cheat\1086.chtC:\Program Files\SC\cheat\1087.chtC:\Program Files\SC\cheat\1088.chtC:\Program Files\SC\cheat\1089.chtC:\Program Files\SC\cheat\1090.chtC:\Program Files\SC\cheat\1091.chtC:\Program Files\SC\cheat\1092.chtC:\Program Files\SC\cheat\1093.chtC:\Program Files\SC\cheat\1094.chtC:\Program Files\SC\cheat\1095.chtC:\Program Files\SC\cheat\1096.chtC:\Program Files\SC\cheat\1099.chtC:\Program Files\SC\cheat\1100.chtC:\Program Files\SC\cheat\1101.chtC:\Program Files\SC\cheat\1102.chtC:\Program Files\SC\cheat\1103.chtC:\Program Files\SC\cheat\1106.chtC:\Program Files\SC\cheat\1107.chtC:\Program Files\SC\cheat\1108.chtC:\Program Files\SC\cheat\1109.chtC:\Program Files\SC\cheat\1110.chtC:\Program Files\SC\cheat\1111.chtC:\Program Files\SC\cheat\1113.chtC:\Program Files\SC\cheat\1114.chtC:\Program Files\SC\cheat\1115.chtC:\Program Files\SC\cheat\1116.chtC:\Program Files\SC\cheat\1118.chtC:\Program Files\SC\cheat\1119.chtC:\Program Files\SC\cheat\1121.chtC:\Program Files\SC\cheat\1122.chtC:\Program Files\SC\cheat\1124.chtC:\Program Files\SC\cheat\1125.chtC:\Program Files\SC\cheat\1126.chtC:\Program Files\SC\cheat\1127.chtC:\Program Files\SC\cheat\1128.chtC:\Program Files\SC\cheat\1130.chtC:\Program Files\SC\cheat\1131.chtC:\Program Files\SC\cheat\1132.chtC:\Program Files\SC\cheat\1133.chtC:\Program Files\SC\cheat\1134.chtC:\Program Files\SC\cheat\1135.chtC:\Program Files\SC\cheat\1136.chtC:\Program Files\SC\cheat\1137.chtC:\Program Files\SC\cheat\1138.chtC:\Program Files\SC\cheat\1139.chtC:\Program Files\SC\cheat\1140.chtC:\Program Files\SC\cheat\1141.chtC:\Program Files\SC\cheat\1142.chtC:\Program Files\SC\cheat\1143.chtC:\Program Files\SC\cheat\1145.chtC:\Program Files\SC\cheat\1146.chtC:\Program Files\SC\cheat\1147.chtC:\Program Files\SC\cheat\1148.chtC:\Program Files\SC\cheat\1149.chtC:\Program Files\SC\cheat\1150.chtC:\Program Files\SC\cheat\1152.chtC:\Program Files\SC\cheat\1153.chtC:\Program Files\SC\cheat\1154.chtC:\Program Files\SC\cheat\1155.chtC:\Program Files\SC\cheat\1156.chtC:\Program Files\SC\cheat\1157.chtC:\Program Files\SC\cheat\1158.chtC:\Program Files\SC\cheat\1159.chtC:\Program Files\SC\cheat\1160.chtC:\Program Files\SC\cheat\1161.chtC:\Program Files\SC\cheat\1162.chtC:\Program Files\SC\cheat\1163.chtC:\Program Files\SC\cheat\1164.chtC:\Program Files\SC\cheat\1165.chtC:\Program Files\SC\cheat\1166.chtC:\Program Files\SC\cheat\1167.chtC:\Program Files\SC\cheat\1168.chtC:\Program Files\SC\cheat\1169.chtC:\Program Files\SC\cheat\1170.chtC:\Program Files\SC\cheat\1171.chtC:\Program Files\SC\cheat\1172.chtC:\Program Files\SC\cheat\1173.chtC:\Program Files\SC\cheat\1174.chtC:\Program Files\SC\cheat\1175.chtC:\Program Files\SC\cheat\1176.chtC:\Program Files\SC\cheat\1177.chtC:\Program Files\SC\cheat\1178.chtC:\Program Files\SC\cheat\1179.chtC:\Program Files\SC\cheat\1180.chtC:\Program Files\SC\cheat\1181.chtC:\Program Files\SC\cheat\1183.chtC:\Program Files\SC\cheat\1184.chtC:\Program Files\SC\cheat\1185.chtC:\Program Files\SC\cheat\1186.chtC:\Program Files\SC\cheat\1187.chtC:\Program Files\SC\cheat\1188.chtC:\Program Files\SC\cheat\1189.chtC:\Program Files\SC\cheat\1190.chtC:\Program Files\SC\cheat\1191.chtC:\Program Files\SC\cheat\1192.chtC:\Program Files\SC\cheat\1193.chtC:\Program Files\SC\cheat\1194.chtC:\Program Files\SC\cheat\1195.chtC:\Program Files\SC\cheat\1196.chtC:\Program Files\SC\cheat\1197.chtC:\Program Files\SC\cheat\1198.chtC:\Program Files\SC\cheat\1199.chtC:\Program Files\SC\cheat\1200.chtC:\Program Files\SC\cheat\1201.chtC:\Program Files\SC\cheat\1202.chtC:\Program Files\SC\cheat\1203.chtC:\Program Files\SC\cheat\1204.chtC:\Program Files\SC\cheat\1205.chtC:\Program Files\SC\cheat\1206.chtC:\Program Files\SC\cheat\1207.chtC:\Program Files\SC\cheat\1208.chtC:\Program Files\SC\cheat\1209.chtC:\Program Files\SC\cheat\1210.chtC:\Program Files\SC\cheat\1211.chtC:\Program Files\SC\cheat\1212.chtC:\Program Files\SC\cheat\1213.chtC:\Program Files\SC\cheat\1214.chtC:\Program Files\SC\cheat\1215.chtC:\Program Files\SC\cheat\1216.chtC:\Program Files\SC\cheat\1217.chtC:\Program Files\SC\cheat\1218.chtC:\Program Files\SC\cheat\1219.chtC:\Program Files\SC\cheat\1220.chtC:\Program Files\SC\cheat\1221.chtC:\Program Files\SC\cheat\1222.chtC:\Program Files\SC\cheat\1223.chtC:\Program Files\SC\cheat\1224.chtC:\Program Files\SC\cheat\1225.chtC:\Program Files\SC\cheat\1226.chtC:\Program Files\SC\cheat\1227.chtC:\Program Files\SC\cheat\1228.chtC:\Program Files\SC\cheat\1229.chtC:\Program Files\SC\cheat\1230.chtC:\Program Files\SC\cheat\1231.chtC:\Program Files\SC\cheat\1232.chtC:\Program Files\SC\cheat\1233.chtC:\Program Files\SC\cheat\1234.chtC:\Program Files\SC\cheat\1235.chtC:\Program Files\SC\cheat\1236.chtC:\Program Files\SC\cheat\1237.chtC:\Program Files\SC\cheat\1238.chtC:\Program Files\SC\cheat\1239.chtC:\Program Files\SC\cheat\1240.chtC:\Program Files\SC\cheat\1241.chtC:\Program Files\SC\cheat\1242.chtC:\Program Files\SC\cheat\1243.chtC:\Program Files\SC\cheat\1244.chtC:\Program Files\SC\cheat\1245.chtC:\Program Files\SC\cheat\1246.chtC:\Program Files\SC\cheat\1247.chtC:\Program Files\SC\cheat\1248.chtC:\Program Files\SC\cheat\1249.chtC:\Program Files\SC\cheat\1250.chtC:\Program Files\SC\cheat\1251.chtC:\Program Files\SC\cheat\1252.chtC:\Program Files\SC\cheat\1253.chtC:\Program Files\SC\cheat\1254.chtC:\Program Files\SC\cheat\1255.chtC:\Program Files\SC\cheat\1256.chtC:\Program Files\SC\cheat\1257.chtC:\Program Files\SC\cheat\1259.chtC:\Program Files\SC\cheat\1260.chtC:\Program Files\SC\cheat\1261.chtC:\Program Files\SC\cheat\1262.chtC:\Program Files\SC\cheat\1263.chtC:\Program Files\SC\cheat\1264.chtC:\Program Files\SC\cheat\1265.chtC:\Program Files\SC\cheat\1266.chtC:\Program Files\SC\cheat\1267.chtC:\Program Files\SC\cheat\1268.chtC:\Program Files\SC\cheat\1269.chtC:\Program Files\SC\cheat\1270.chtC:\Program Files\SC\cheat\1271.chtC:\Program Files\SC\cheat\1272.chtC:\Program Files\SC\cheat\1273.chtC:\Program Files\SC\cheat\1274.chtC:\Program Files\SC\cheat\1275.chtC:\Program Files\SC\cheat\1276.chtC:\Program Files\SC\cheat\1277.chtC:\Program Files\SC\cheat\1278.chtC:\Program Files\SC\cheat\1279.chtC:\Program Files\SC\cheat\1280.chtC:\Program Files\SC\cheat\1281.chtC:\Program Files\SC\cheat\1282.chtC:\Program Files\SC\cheat\1283.chtC:\Program Files\SC\cheat\1284.chtC:\Program Files\SC\cheat\1285.chtC:\Program Files\SC\cheat\1286.chtC:\Program Files\SC\cheat\1287.chtC:\Program Files\SC\cheat\1288.chtC:\Program Files\SC\cheat\1289.chtC:\Program Files\SC\cheat\1290.chtC:\Program Files\SC\cheat\1291.chtC:\Program Files\SC\cheat\1292.chtC:\Program Files\SC\cheat\1293.chtC:\Program Files\SC\cheat\1295.chtC:\Program Files\SC\cheat\1296.chtC:\Program Files\SC\cheat\1298.chtC:\Program Files\SC\cheat\1299.chtC:\Program Files\SC\cheat\1300.chtC:\Program Files\SC\cheat\1301.chtC:\Program Files\SC\cheat\1305.chtC:\Program Files\SC\cheat\1306.chtC:\Program Files\SC\cheat\1307.chtC:\Program Files\SC\cheat\1309.chtC:\Program Files\SC\cheat\1310.chtC:\Program Files\SC\cheat\1311.chtC:\Program Files\SC\cheat\1312.chtC:\Program Files\SC\cheat\1313.chtC:\Program Files\SC\cheat\1314.chtC:\Program Files\SC\cheat\1315.chtC:\Program Files\SC\cheat\1316.chtC:\Program Files\SC\cheat\1317.chtC:\Program Files\SC\cheat\1318.chtC:\Program Files\SC\cheat\1319.chtC:\Program Files\SC\cheat\1320.chtC:\Program Files\SC\cheat\1321.chtC:\Program Files\SC\cheat\1322.chtC:\Program Files\SC\cheat\1323.chtC:\Program Files\SC\cheat\1324.chtC:\Program Files\SC\cheat\1325.chtC:\Program Files\SC\cheat\1326.chtC:\Program Files\SC\cheat\1329.chtC:\Program Files\SC\cheat\1330.chtC:\Program Files\SC\cheat\1331.chtC:\Program Files\SC\cheat\1332.chtC:\Program Files\SC\cheat\1333.chtC:\Program Files\SC\cheat\1334.chtC:\Program Files\SC\cheat\1335.chtC:\Program Files\SC\cheat\1336.chtC:\Program Files\SC\cheat\1337.chtC:\Program Files\SC\cheat\1338.chtC:\Program Files\SC\cheat\1339.chtC:\Program Files\SC\cheat\1340.chtC:\Program Files\SC\cheat\1341.chtC:\Program Files\SC\cheat\1343.chtC:\Program Files\SC\cheat\1344.chtC:\Program Files\SC\cheat\1346.chtC:\Program Files\SC\cheat\1347.chtC:\Program Files\SC\cheat\1348.chtC:\Program Files\SC\cheat\1349.chtC:\Program Files\SC\cheat\1350.chtC:\Program Files\SC\cheat\1352.chtC:\Program Files\SC\cheat\1353.chtC:\Program Files\SC\cheat\1354.chtC:\Program Files\SC\cheat\1355.chtC:\Program Files\SC\cheat\1356.chtC:\Program Files\SC\cheat\1357.chtC:\Program Files\SC\cheat\1358.chtC:\Program Files\SC\cheat\1359.chtC:\Program Files\SC\cheat\1360.chtC:\Program Files\SC\cheat\1361.chtC:\Program Files\SC\cheat\1362.chtC:\Program Files\SC\cheat\1363.chtC:\Program Files\SC\cheat\1364.chtC:\Program Files\SC\cheat\1365.chtC:\Program Files\SC\cheat\1366.chtC:\Program Files\SC\cheat\1367.chtC:\Program Files\SC\cheat\1368.chtC:\Program Files\SC\cheat\1369.chtC:\Program Files\SC\cheat\1370.chtC:\Program Files\SC\cheat\1371.chtC:\Program Files\SC\cheat\1372.chtC:\Program Files\SC\cheat\1373.chtC:\Program Files\SC\cheat\1374.chtC:\Program Files\SC\cheat\1375.chtC:\Program Files\SC\cheat\1376.chtC:\Program Files\SC\cheat\1377.chtC:\Program Files\SC\cheat\1378.chtC:\Program Files\SC\cheat\1379.chtC:\Program Files\SC\cheat\1380.chtC:\Program Files\SC\cheat\1381.chtC:\Program Files\SC\cheat\1382.chtC:\Program Files\SC\cheat\1383.chtC:\Program Files\SC\cheat\1384.chtC:\Program Files\SC\cheat\1385.chtC:\Program Files\SC\cheat\1386.chtC:\Program Files\SC\cheat\1387.chtC:\Program Files\SC\cheat\1388.chtC:\Program Files\SC\cheat\1389.chtC:\Program Files\SC\cheat\1390.chtC:\Program Files\SC\cheat\1391.chtC:\Program Files\SC\cheat\1392.chtC:\Program Files\SC\cheat\1393.chtC:\Program Files\SC\cheat\1394.chtC:\Program Files\SC\cheat\1395.chtC:\Program Files\SC\cheat\1396.chtC:\Program Files\SC\cheat\1397.chtC:\Program Files\SC\cheat\1398.chtC:\Program Files\SC\cheat\1399.chtC:\Program Files\SC\cheat\1401.chtC:\Program Files\SC\cheat\1402.chtC:\Program Files\SC\cheat\1403.chtC:\Program Files\SC\cheat\1404.chtC:\Program Files\SC\cheat\1405.chtC:\Program Files\SC\cheat\1406.chtC:\Program Files\SC\cheat\1407.chtC:\Program Files\SC\cheat\1408.chtC:\Program Files\SC\cheat\1409.chtC:\Program Files\SC\cheat\1410.chtC:\Program Files\SC\cheat\1411.chtC:\Program Files\SC\cheat\1412.chtC:\Program Files\SC\cheat\1413.chtC:\Program Files\SC\cheat\1414.chtC:\Program Files\SC\cheat\1415.chtC:\Program Files\SC\cheat\1416.chtC:\Program Files\SC\cheat\1417.chtC:\Program Files\SC\cheat\1418.chtC:\Program Files\SC\cheat\1419.chtC:\Program Files\SC\cheat\1420.chtC:\Program Files\SC\cheat\1421.chtC:\Program Files\SC\cheat\1422.chtC:\Program Files\SC\cheat\1423.chtC:\Program Files\SC\cheat\1424.chtC:\Program Files\SC\cheat\1425.chtC:\Program Files\SC\cheat\1426.chtC:\Program Files\SC\cheat\1427.chtC:\Program Files\SC\cheat\1428.chtC:\Program Files\SC\cheat\1429.chtC:\Program Files\SC\cheat\1430.chtC:\Program Files\SC\cheat\1431.chtC:\Program Files\SC\cheat\1432.chtC:\Program Files\SC\cheat\1433.chtC:\Program Files\SC\cheat\1434.chtC:\Program Files\SC\cheat\1435.chtC:\Program Files\SC\cheat\1436.chtC:\Program Files\SC\cheat\1437.chtC:\Program Files\SC\cheat\1438.chtC:\Program Files\SC\cheat\1439 .chtC:\Program Files\SC\cheat\1439.chtC:\Program Files\SC\cheat\1440.chtC:\Program Files\SC\cheat\1441.chtC:\Program Files\SC\cheat\1442.chtC:\Program Files\SC\cheat\1443.chtC:\Program Files\SC\cheat\1444.chtC:\Program Files\SC\cheat\1445.chtC:\Program Files\SC\cheat\1446.chtC:\Program Files\SC\cheat\1447.chtC:\Program Files\SC\cheat\1448.chtC:\Program Files\SC\cheat\1449.chtC:\Program Files\SC\cheat\1450.chtC:\Program Files\SC\cheat\1451.chtC:\Program Files\SC\cheat\1453.chtC:\Program Files\SC\cheat\1454.chtC:\Program Files\SC\cheat\1455.chtC:\Program Files\SC\cheat\1456.chtC:\Program Files\SC\cheat\1458.chtC:\Program Files\SC\cheat\1459.chtC:\Program Files\SC\cheat\1460.chtC:\Program Files\SC\cheat\1461.chtC:\Program Files\SC\cheat\1462.chtC:\Program Files\SC\cheat\1465.chtC:\Program Files\SC\cheat\1466.chtC:\Program Files\SC\cheat\1467.chtC:\Program Files\SC\cheat\1468.chtC:\Program Files\SC\cheat\1470.chtC:\Program Files\SC\cheat\1471.chtC:\Program Files\SC\cheat\1472.chtC:\Program Files\SC\cheat\1473.chtC:\Program Files\SC\cheat\1474.chtC:\Program Files\SC\cheat\1475.chtC:\Program Files\SC\cheat\1476.chtC:\Program Files\SC\cheat\1477.chtC:\Program Files\SC\cheat\1478.chtC:\Program Files\SC\cheat\1479.chtC:\Program Files\SC\cheat\1480.chtC:\Program Files\SC\cheat\1481.chtC:\Program Files\SC\cheat\1482.chtC:\Program Files\SC\cheat\1483.chtC:\Program Files\SC\cheat\1484.chtC:\Program Files\SC\cheat\1485.chtC:\Program Files\SC\cheat\1486.chtC:\Program Files\SC\cheat\1487.chtC:\Program Files\SC\cheat\1488.chtC:\Program Files\SC\cheat\1489.chtC:\Program Files\SC\cheat\1490.chtC:\Program Files\SC\cheat\1491.chtC:\Program Files\SC\cheat\1492.chtC:\Program Files\SC\cheat\1493.chtC:\Program Files\SC\cheat\1494.chtC:\Program Files\SC\cheat\1495.chtC:\Program Files\SC\cheat\1496.chtC:\Program Files\SC\cheat\1497.chtC:\Program Files\SC\cheat\1498.chtC:\Program Files\SC\cheat\1499.chtC:\Program Files\SC\cheat\1500.chtC:\Program Files\SC\cheat\1501.chtC:\Program Files\SC\cheat\1502.chtC:\Program Files\SC\cheat\1503.chtC:\Program Files\SC\cheat\1504.chtC:\Program Files\SC\cheat\1506.chtC:\Program Files\SC\cheat\1508.chtC:\Program Files\SC\cheat\1510.chtC:\Program Files\SC\cheat\1511.chtC:\Program Files\SC\cheat\1512.chtC:\Program Files\SC\cheat\1513.chtC:\Program Files\SC\cheat\1514.chtC:\Program Files\SC\cheat\1516.chtC:\Program Files\SC\cheat\1517.chtC:\Program Files\SC\cheat\1518.chtC:\Program Files\SC\cheat\1519.chtC:\Program Files\SC\cheat\1520.chtC:\Program Files\SC\cheat\1521.chtC:\Program Files\SC\cheat\1523.chtC:\Program Files\SC\cheat\1526.chtC:\Program Files\SC\cheat\1527.chtC:\Program Files\SC\cheat\1528.chtC:\Program Files\SC\cheat\1529.chtC:\Program Files\SC\cheat\1530.chtC:\Program Files\SC\cheat\1531.chtC:\Program Files\SC\cheat\1532.chtC:\Program Files\SC\cheat\1533.chtC:\Program Files\SC\cheat\1534.chtC:\Program Files\SC\cheat\1535.chtC:\Program Files\SC\cheat\1536.chtC:\Program Files\SC\cheat\1537.chtC:\Program Files\SC\cheat\1538.chtC:\Program Files\SC\cheat\1539.chtC:\Program Files\SC\cheat\1540.chtC:\Program Files\SC\cheat\1541.chtC:\Program Files\SC\cheat\1542.chtC:\Program Files\SC\cheat\1544.chtC:\Program Files\SC\cheat\1547.chtC:\Program Files\SC\cheat\1548.chtC:\Program Files\SC\cheat\1551.chtC:\Program Files\SC\cheat\1552.chtC:\Program Files\SC\cheat\1553.chtC:\Program Files\SC\cheat\1554.chtC:\Program Files\SC\cheat\1555.chtC:\Program Files\SC\cheat\1556.chtC:\Program Files\SC\cheat\1559.chtC:\Program Files\SC\cheat\1560.chtC:\Program Files\SC\cheat\1562.chtC:\Program Files\SC\cheat\1563.chtC:\Program Files\SC\cheat\1565.chtC:\Program Files\SC\cheat\1566.chtC:\Program Files\SC\cheat\1567.chtC:\Program Files\SC\cheat\1568.chtC:\Program Files\SC\cheat\1569.chtC:\Program Files\SC\cheat\1570.chtC:\Program Files\SC\cheat\1571.chtC:\Program Files\SC\cheat\1572.chtC:\Program Files\SC\cheat\1573.chtC:\Program Files\SC\cheat\1576.chtC:\Program Files\SC\cheat\1577.chtC:\Program Files\SC\cheat\1579.chtC:\Program Files\SC\cheat\1581.chtC:\Program Files\SC\cheat\1584.chtC:\Program Files\SC\cheat\1586.chtC:\Program Files\SC\cheat\1588.chtC:\Program Files\SC\cheat\1589.chtC:\Program Files\SC\cheat\1590.chtC:\Program Files\SC\cheat\1592.chtC:\Program Files\SC\cheat\1593.chtC:\Program Files\SC\cheat\1594.chtC:\Program Files\SC\cheat\1595.chtC:\Program Files\SC\cheat\1596.chtC:\Program Files\SC\cheat\1598.chtC:\Program Files\SC\cheat\1599.chtC:\Program Files\SC\cheat\1602.chtC:\Program Files\SC\cheat\1603.chtC:\Program Files\SC\cheat\1604.chtC:\Program Files\SC\cheat\1605.chtC:\Program Files\SC\cheat\1606.chtC:\Program Files\SC\cheat\1607.chtC:\Program Files\SC\cheat\1608.chtC:\Program Files\SC\cheat\1609.chtC:\Program Files\SC\cheat\1610.chtC:\Program Files\SC\cheat\1611.chtC:\Program Files\SC\cheat\1612.chtC:\Program Files\SC\cheat\1613.chtC:\Program Files\SC\cheat\1614.chtC:\Program Files\SC\cheat\1615.chtC:\Program Files\SC\cheat\1623.chtC:\Program Files\SC\cheat\1625.chtC:\Program Files\SC\cheat\1626.chtC:\Program Files\SC\cheat\1627.chtC:\Program Files\SC\cheat\1628.chtC:\Program Files\SC\cheat\1629.chtC:\Program Files\SC\cheat\1630.chtC:\Program Files\SC\cheat\1631.chtC:\Program Files\SC\cheat\1632.chtC:\Program Files\SC\cheat\1633.chtC:\Program Files\SC\cheat\1634.chtC:\Program Files\SC\cheat\1635.chtC:\Program Files\SC\cheat\1636.chtC:\Program Files\SC\cheat\1637.chtC:\Program Files\SC\cheat\1638.chtC:\Program Files\SC\cheat\1639.chtC:\Program Files\SC\cheat\1640.chtC:\Program Files\SC\cheat\1641.chtC:\Program Files\SC\cheat\1642.chtC:\Program Files\SC\cheat\1643.chtC:\Program Files\SC\cheat\1645.chtC:\Program Files\SC\cheat\1647.chtC:\Program Files\SC\cheat\1648.chtC:\Program Files\SC\cheat\1649.chtC:\Program Files\SC\cheat\1652.chtC:\Program Files\SC\cheat\1653.chtC:\Program Files\SC\cheat\1654.chtC:\Program Files\SC\cheat\1655.chtC:\Program Files\SC\cheat\1656.chtC:\Program Files\SC\cheat\1657.chtC:\Program Files\SC\cheat\1658.chtC:\Program Files\SC\cheat\1659.chtC:\Program Files\SC\cheat\1660.chtC:\Program Files\SC\cheat\1661.chtC:\Program Files\SC\cheat\1662.chtC:\Program Files\SC\cheat\1663.chtC:\Program Files\SC\cheat\1664.chtC:\Program Files\SC\cheat\1665.chtC:\Program Files\SC\cheat\1666.chtC:\Program Files\SC\cheat\1667.chtC:\Program Files\SC\cheat\1668.chtC:\Program Files\SC\cheat\1670.chtC:\Program Files\SC\cheat\1671.chtC:\Program Files\SC\cheat\1672.chtC:\Program Files\SC\cheat\1673.chtC:\Program Files\SC\cheat\1674.chtC:\Program Files\SC\cheat\1675.chtC:\Program Files\SC\cheat\1676.chtC:\Program Files\SC\cheat\1677.chtC:\Program Files\SC\cheat\1678.chtC:\Program Files\SC\cheat\1679.chtC:\Program Files\SC\cheat\1680.chtC:\Program Files\SC\cheat\1681.chtC:\Program Files\SC\cheat\1682.chtC:\Program Files\SC\cheat\1685.chtC:\Program Files\SC\cheat\1686.chtC:\Program Files\SC\cheat\1690.chtC:\Program Files\SC\cheat\1691.chtC:\Program Files\SC\cheat\1692.chtC:\Program Files\SC\cheat\1693.chtC:\Program Files\SC\cheat\1694.chtC:\Program Files\SC\cheat\1695.chtC:\Program Files\SC\cheat\1696.chtC:\Program Files\SC\cheat\1697.chtC:\Program Files\SC\cheat\1698.chtC:\Program Files\SC\cheat\1700.chtC:\Program Files\SC\cheat\1701.chtC:\Program Files\SC\cheat\1702.chtC:\Program Files\SC\cheat\1703.chtC:\Program Files\SC\cheat\1704.chtC:\Program Files\SC\cheat\1705.chtC:\Program Files\SC\cheat\1706.chtC:\Program Files\SC\cheat\1707.chtC:\Program Files\SC\cheat\1708.chtC:\Program Files\SC\cheat\1709.chtC:\Program Files\SC\cheat\1710.chtC:\Program Files\SC\cheat\1713.chtC:\Program Files\SC\cheat\1714.chtC:\Program Files\SC\cheat\1715.chtC:\Program Files\SC\cheat\1716.chtC:\Program Files\SC\cheat\1717.chtC:\Program Files\SC\cheat\1718.chtC:\Program Files\SC\cheat\1719.chtC:\Program Files\SC\cheat\1720.chtC:\Program Files\SC\cheat\1721.chtC:\Program Files\SC\cheat\1722.chtC:\Program Files\SC\cheat\1723.chtC:\Program Files\SC\cheat\1724.chtC:\Program Files\SC\cheat\1725.chtC:\Program Files\SC\cheat\1726.chtC:\Program Files\SC\cheat\1727.chtC:\Program Files\SC\cheat\1728.chtC:\Program Files\SC\cheat\1729.chtC:\Program Files\SC\cheat\1730.chtC:\Program Files\SC\cheat\1731.chtC:\Program Files\SC\cheat\1732.chtC:\Program Files\SC\cheat\1733.chtC:\Program Files\SC\cheat\1734.chtC:\Program Files\SC\cheat\1735.chtC:\Program Files\SC\cheat\1736.chtC:\Program Files\SC\cheat\1737.chtC:\Program Files\SC\cheat\1738.chtC:\Program Files\SC\cheat\1739.chtC:\Program Files\SC\cheat\1740.chtC:\Program Files\SC\cheat\1741.chtC:\Program Files\SC\cheat\1742.chtC:\Program Files\SC\cheat\1743.chtC:\Program Files\SC\cheat\1744.chtC:\Program Files\SC\cheat\1749.chtC:\Program Files\SC\cheat\1750.chtC:\Program Files\SC\cheat\1751.chtC:\Program Files\SC\cheat\1752.chtC:\Program Files\SC\cheat\1753.chtC:\Program Files\SC\cheat\1754.chtC:\Program Files\SC\cheat\1755.chtC:\Program Files\SC\cheat\1756.chtC:\Program Files\SC\cheat\1757.chtC:\Program Files\SC\cheat\1758.chtC:\Program Files\SC\cheat\1759.chtC:\Program Files\SC\cheat\1760.chtC:\Program Files\SC\cheat\1761.chtC:\Program Files\SC\cheat\1762.chtC:\Program Files\SC\cheat\1763.chtC:\Program Files\SC\cheat\1764.chtC:\Program Files\SC\cheat\1765.chtC:\Program Files\SC\cheat\1766.chtC:\Program Files\SC\cheat\1767.chtC:\Program Files\SC\cheat\1768.chtC:\Program Files\SC\cheat\1769.chtC:\Program Files\SC\cheat\1770.chtC:\Program Files\SC\cheat\1771.chtC:\Program Files\SC\cheat\1772.chtC:\Program Files\SC\cheat\1773.chtC:\Program Files\SC\cheat\1774.chtC:\Program Files\SC\cheat\1775.chtC:\Program Files\SC\cheat\1776.chtC:\Program Files\SC\cheat\1777.chtC:\Program Files\SC\cheat\1778.chtC:\Program Files\SC\cheat\1779.chtC:\Program Files\SC\cheat\1780.chtC:\Program Files\SC\cheat\1781.chtC:\Program Files\SC\cheat\1782.chtC:\Program Files\SC\cheat\1783.chtC:\Program Files\SC\cheat\1784.chtC:\Program Files\SC\cheat\1785.chtC:\Program Files\SC\cheat\1786.chtC:\Program Files\SC\cheat\1787.chtC:\Program Files\SC\cheat\1788.chtC:\Program Files\SC\cheat\1789.chtC:\Program Files\SC\cheat\1790.chtC:\Program Files\SC\cheat\1791.chtC:\Program Files\SC\cheat\1792.chtC:\Program Files\SC\cheat\1793.chtC:\Program Files\SC\cheat\1794.chtC:\Program Files\SC\cheat\1795.chtC:\Program Files\SC\cheat\1796.chtC:\Program Files\SC\cheat\1797.chtC:\Program Files\SC\cheat\1798.chtC:\Program Files\SC\cheat\1799.chtC:\Program Files\SC\cheat\1800.chtC:\Program Files\SC\cheat\1801.chtC:\Program Files\SC\cheat\1802.chtC:\Program Files\SC\cheat\1803.chtC:\Program Files\SC\cheat\1804.chtC:\Program Files\SC\cheat\1805.chtC:\Program Files\SC\cheat\1806.chtC:\Program Files\SC\cheat\1807.chtC:\Program Files\SC\cheat\1808.chtC:\Program Files\SC\cheat\1809.chtC:\Program Files\SC\cheat\1810.chtC:\Program Files\SC\cheat\1811.chtC:\Program Files\SC\cheat\1812.chtC:\Program Files\SC\cheat\1813.chtC:\Program Files\SC\cheat\1814.chtC:\Program Files\SC\cheat\1815.chtC:\Program Files\SC\cheat\1816.chtC:\Program Files\SC\cheat\1817.chtC:\Program Files\SC\cheat\1819.chtC:\Program Files\SC\cheat\1820.chtC:\Program Files\SC\cheat\1821.chtC:\Program Files\SC\cheat\1822.chtC:\Program Files\SC\cheat\1823.chtC:\Program Files\SC\cheat\1824.chtC:\Program Files\SC\cheat\1825.chtC:\Program Files\SC\cheat\1826.chtC:\Program Files\SC\cheat\1827.chtC:\Program Files\SC\cheat\1828.chtC:\Program Files\SC\cheat\1829.chtC:\Program Files\SC\cheat\1830.chtC:\Program Files\SC\cheat\1831.chtC:\Program Files\SC\cheat\1832.chtC:\Program Files\SC\cheat\1833.chtC:\Program Files\SC\cheat\1834.chtC:\Program Files\SC\cheat\1835.chtC:\Program Files\SC\cheat\1836.chtC:\Program Files\SC\cheat\1837.chtC:\Program Files\SC\cheat\1838.chtC:\Program Files\SC\cheat\1839.chtC:\Program Files\SC\cheat\1840.chtC:\Program Files\SC\cheat\1841.chtC:\Program Files\SC\cheat\1842.chtC:\Program Files\SC\cheat\1843.chtC:\Program Files\SC\cheat\1845.chtC:\Program Files\SC\cheat\1846.chtC:\Program Files\SC\cheat\1847.chtC:\Program Files\SC\cheat\1848.chtC:\Program Files\SC\cheat\1849.chtC:\Program Files\SC\cheat\1850.chtC:\Program Files\SC\cheat\1851.chtC:\Program Files\SC\cheat\1852.chtC:\Program Files\SC\cheat\1853.chtC:\Program Files\SC\cheat\1854.chtC:\Program Files\SC\cheat\1855.chtC:\Program Files\SC\cheat\1856.chtC:\Program Files\SC\cheat\1858.chtC:\Program Files\SC\cheat\1859.chtC:\Program Files\SC\cheat\1860.chtC:\Program Files\SC\cheat\1861.chtC:\Program Files\SC\cheat\1862.chtC:\Program Files\SC\cheat\1863.chtC:\Program Files\SC\cheat\1864.chtC:\Program Files\SC\cheat\1865.chtC:\Program Files\SC\cheat\1866.chtC:\Program Files\SC\cheat\1867.chtC:\Program Files\SC\cheat\1868.chtC:\Program Files\SC\cheat\1869.chtC:\Program Files\SC\cheat\1870.chtC:\Program Files\SC\cheat\1871.chtC:\Program Files\SC\cheat\1872.chtC:\Program Files\SC\cheat\1873.chtC:\Program Files\SC\cheat\1874.chtC:\Program Files\SC\cheat\1875.chtC:\Program Files\SC\cheat\1876.chtC:\Program Files\SC\cheat\1877.chtC:\Program Files\SC\cheat\1878.chtC:\Program Files\SC\cheat\1879.chtC:\Program Files\SC\cheat\1880.chtC:\Program Files\SC\cheat\1881.chtC:\Program Files\SC\cheat\1882.chtC:\Program Files\SC\cheat\1883.chtC:\Program Files\SC\cheat\1885.chtC:\Program Files\SC\cheat\1886.chtC:\Program Files\SC\cheat\1887.chtC:\Program Files\SC\cheat\1888.chtC:\Program Files\SC\cheat\1890.chtC:\Program Files\SC\cheat\1896.chtC:\Program Files\SC\cheat\1899.chtC:\Program Files\SC\cheat\1900.chtC:\Program Files\SC\cheat\1901.chtC:\Program Files\SC\cheat\1902.chtC:\Program Files\SC\cheat\1903.chtC:\Program Files\SC\cheat\1905.chtC:\Program Files\SC\cheat\1906.chtC:\Program Files\SC\cheat\1908.chtC:\Program Files\SC\cheat\1909.chtC:\Program Files\SC\cheat\1910.chtC:\Program Files\SC\cheat\1911.chtC:\Program Files\SC\cheat\1912.chtC:\Program Files\SC\cheat\1914.chtC:\Program Files\SC\cheat\1915.chtC:\Program Files\SC\cheat\1916.chtC:\Program Files\SC\cheat\1917.chtC:\Program Files\SC\cheat\1918.chtC:\Program Files\SC\cheat\1919.chtC:\Program Files\SC\cheat\1920.chtC:\Program Files\SC\cheat\1921.chtC:\Program Files\SC\cheat\1922.chtC:\Program Files\SC\cheat\1923.chtC:\Program Files\SC\cheat\1924.chtC:\Program Files\SC\cheat\1925.chtC:\Program Files\SC\cheat\1926.chtC:\Program Files\SC\cheat\1929.chtC:\Program Files\SC\cheat\1931.chtC:\Program Files\SC\cheat\1934.chtC:\Program Files\SC\cheat\1936.chtC:\Program Files\SC\cheat\1937.chtC:\Program Files\SC\cheat\1939.chtC:\Program Files\SC\cheat\1940.chtC:\Program Files\SC\cheat\1941.chtC:\Program Files\SC\cheat\1944.chtC:\Program Files\SC\cheat\1945.chtC:\Program Files\SC\cheat\1946.chtC:\Program Files\SC\cheat\1947.chtC:\Program Files\SC\cheat\1948.chtC:\Program Files\SC\cheat\1949.chtC:\Program Files\SC\cheat\1950.chtC:\Program Files\SC\cheat\1951.chtC:\Program Files\SC\cheat\1952.chtC:\Program Files\SC\cheat\1953.chtC:\Program Files\SC\cheat\1954.chtC:\Program Files\SC\cheat\1955.chtC:\Program Files\SC\cheat\1956.chtC:\Program Files\SC\cheat\1957.chtC:\Program Files\SC\cheat\1958.chtC:\Program Files\SC\cheat\1960.chtC:\Program Files\SC\cheat\1961.chtC:\Program Files\SC\cheat\1962.chtC:\Program Files\SC\cheat\1963.chtC:\Program Files\SC\cheat\1967.chtC:\Program Files\SC\cheat\1969.chtC:\Program Files\SC\cheat\1970.chtC:\Program Files\SC\cheat\1971.chtC:\Program Files\SC\cheat\1972.chtC:\Program Files\SC\cheat\1973.chtC:\Program Files\SC\cheat\1974.chtC:\Program Files\SC\cheat\1975.chtC:\Program Files\SC\cheat\1976.chtC:\Program Files\SC\cheat\1977.chtC:\Program Files\SC\cheat\1978.chtC:\Program Files\SC\cheat\1979.chtC:\Program Files\SC\cheat\1980.chtC:\Program Files\SC\cheat\1981.chtC:\Program Files\SC\cheat\1982.chtC:\Program Files\SC\cheat\1983.chtC:\Program Files\SC\cheat\1984.chtC:\Program Files\SC\cheat\1985.chtC:\Program Files\SC\cheat\1986.chtC:\Program Files\SC\cheat\1987.chtC:\Program Files\SC\cheat\1989.chtC:\Program Files\SC\cheat\1990.chtC:\Program Files\SC\cheat\1991.chtC:\Program Files\SC\cheat\1993.chtC:\Program Files\SC\cheat\1994.chtC:\Program Files\SC\cheat\1996.chtC:\Program Files\SC\cheat\1997.chtC:\Program Files\SC\cheat\1998.chtC:\Program Files\SC\cheat\1999.chtC:\Program Files\SC\cheat\2000.chtC:\Program Files\SC\cheat\2001.chtC:\Program Files\SC\cheat\2002.chtC:\Program Files\SC\cheat\2003.chtC:\Program Files\SC\cheat\2004.chtC:\Program Files\SC\cheat\2005.chtC:\Program Files\SC\cheat\2006.chtC:\Program Files\SC\cheat\2007.chtC:\Program Files\SC\cheat\2008.chtC:\Program Files\SC\cheat\2009.chtC:\Program Files\SC\cheat\2010.chtC:\Program Files\SC\cheat\2011.chtC:\Program Files\SC\cheat\2012.chtC:\Program Files\SC\cheat\2013.chtC:\Program Files\SC\cheat\2014.chtC:\Program Files\SC\cheat\2015.chtC:\Program Files\SC\cheat\2016.chtC:\Program Files\SC\cheat\2017.chtC:\Program Files\SC\cheat\2018.chtC:\Program Files\SC\cheat\2019.chtC:\Program Files\SC\cheat\2020.chtC:\Program Files\SC\cheat\2021.chtC:\Program Files\SC\cheat\2022.chtC:\Program Files\SC\cheat\2023.chtC:\Program Files\SC\cheat\2024.chtC:\Program Files\SC\cheat\2025.chtC:\Program Files\SC\cheat\2026.chtC:\Program Files\SC\cheat\2028.chtC:\Program Files\SC\cheat\2029.chtC:\Program Files\SC\cheat\2030.chtC:\Program Files\SC\cheat\2031.chtC:\Program Files\SC\cheat\2032.chtC:\Program Files\SC\cheat\2033.chtC:\Program Files\SC\cheat\2034.chtC:\Program Files\SC\cheat\2035.chtC:\Program Files\SC\cheat\2036.chtC:\Program Files\SC\cheat\2037.chtC:\Program Files\SC\cheat\2038.chtC:\Program Files\SC\cheat\2039.chtC:\Program Files\SC\cheat\2040.chtC:\Program Files\SC\cheat\2041.chtC:\Program Files\SC\cheat\2042.chtC:\Program Files\SC\cheat\2043.chtC:\Program Files\SC\cheat\2044.chtC:\Program Files\SC\cheat\2045.chtC:\Program Files\SC\cheat\2046.chtC:\Program Files\SC\cheat\2047.chtC:\Program Files\SC\cheat\2050.chtC:\Program Files\SC\cheat\2051.chtC:\Program Files\SC\cheat\2052.chtC:\Program Files\SC\cheat\2053.chtC:\Program Files\SC\cheat\2054.chtC:\Program Files\SC\cheat\2055.chtC:\Program Files\SC\cheat\2056.chtC:\Program Files\SC\cheat\2057.chtC:\Program Files\SC\cheat\2058.chtC:\Program Files\SC\cheat\2059.chtC:\Program Files\SC\cheat\2060.chtC:\Program Files\SC\cheat\2061.chtC:\Program Files\SC\cheat\2062.chtC:\Program Files\SC\cheat\2063.chtC:\Program Files\SC\cheat\2064.chtC:\Program Files\SC\cheat\2065.chtC:\Program Files\SC\cheat\2066.chtC:\Program Files\SC\cheat\2067.chtC:\Program Files\SC\cheat\2068.chtC:\Program Files\SC\cheat\2069.chtC:\Program Files\SC\cheat\2070.chtC:\Program Files\SC\cheat\2071.chtC:\Program Files\SC\cheat\2072.chtC:\Program Files\SC\cheat\2073.chtC:\Program Files\SC\cheat\2074.chtC:\Program Files\SC\cheat\2075.chtC:\Program Files\SC\cheat\2076.chtC:\Program Files\SC\cheat\2077.chtC:\Program Files\SC\cheat\2078.chtC:\Program Files\SC\cheat\2079.chtC:\Program Files\SC\cheat\2080.chtC:\Program Files\SC\cheat\2081.chtC:\Program Files\SC\cheat\2082.chtC:\Program Files\SC\cheat\2083.chtC:\Program Files\SC\cheat\2084.chtC:\Program Files\SC\cheat\2085.chtC:\Program Files\SC\cheat\2086.chtC:\Program Files\SC\cheat\2087.chtC:\Program Files\SC\cheat\2088.chtC:\Program Files\SC\cheat\2089.chtC:\Program Files\SC\cheat\2090.chtC:\Program Files\SC\cheat\2091.chtC:\Program Files\SC\cheat\2092.chtC:\Program Files\SC\cheat\2093.chtC:\Program Files\SC\cheat\2094.chtC:\Program Files\SC\cheat\2095.chtC:\Program Files\SC\cheat\2099.chtC:\Program Files\SC\cheat\2100.chtC:\Program Files\SC\cheat\2101.chtC:\Program Files\SC\cheat\2102.chtC:\Program Files\SC\cheat\2103.chtC:\Program Files\SC\cheat\2104.chtC:\Program Files\SC\cheat\2105.chtC:\Program Files\SC\cheat\2106.chtC:\Program Files\SC\cheat\2107.chtC:\Program Files\SC\cheat\2108.chtC:\Program Files\SC\cheat\2109.chtC:\Program Files\SC\cheat\2110.chtC:\Program Files\SC\cheat\2111.chtC:\Program Files\SC\cheat\2112.chtC:\Program Files\SC\cheat\2113.chtC:\Program Files\SC\cheat\2114.chtC:\Program Files\SC\cheat\2115.chtC:\Program Files\SC\cheat\2116.chtC:\Program Files\SC\cheat\2117.chtC:\Program Files\SC\cheat\2118.chtC:\Program Files\SC\cheat\2119.chtC:\Program Files\SC\cheat\2120.chtC:\Program Files\SC\cheat\2121.chtC:\Program Files\SC\cheat\2122.chtC:\Program Files\SC\cheat\2123.chtC:\Program Files\SC\cheat\2124.chtC:\Program Files\SC\cheat\2125.chtC:\Program Files\SC\cheat\2126.chtC:\Program Files\SC\cheat\2127.chtC:\Program Files\SC\cheat\2128.chtC:\Program Files\SC\cheat\2129.chtC:\Program Files\SC\cheat\2130.chtC:\Program Files\SC\cheat\2131.chtC:\Program Files\SC\cheat\2132.chtC:\Program Files\SC\cheat\2133.chtC:\Program Files\SC\cheat\2134.chtC:\Program Files\SC\cheat\2135.chtC:\Program Files\SC\cheat\2136.chtC:\Program Files\SC\cheat\2137.chtC:\Program Files\SC\cheat\2138.chtC:\Program Files\SC\cheat\2139.chtC:\Program Files\SC\cheat\2140.chtC:\Program Files\SC\cheat\2141.chtC:\Program Files\SC\cheat\2142.chtC:\Program Files\SC\cheat\2143.chtC:\Program Files\SC\cheat\2144.chtC:\Program Files\SC\cheat\2145.chtC:\Program Files\SC\cheat\2146.chtC:\Program Files\SC\cheat\2147.chtC:\Program Files\SC\cheat\2148.chtC:\Program Files\SC\cheat\2149.chtC:\Program Files\SC\cheat\2150.chtC:\Program Files\SC\cheat\2151.chtC:\Program Files\SC\cheat\2152.chtC:\Program Files\SC\cheat\2153.chtC:\Program Files\SC\cheat\2154.chtC:\Program Files\SC\cheat\2155.chtC:\Program Files\SC\cheat\2156.chtC:\Program Files\SC\cheat\2157.chtC:\Program Files\SC\cheat\2158.chtC:\Program Files\SC\cheat\2159.chtC:\Program Files\SC\cheat\2160.chtC:\Program Files\SC\cheat\2161.chtC:\Program Files\SC\cheat\2162.chtC:\Program Files\SC\cheat\2163.chtC:\Program Files\SC\cheat\2164.chtC:\Program Files\SC\cheat\2166.chtC:\Program Files\SC\cheat\2167.chtC:\Program Files\SC\cheat\2168.chtC:\Program Files\SC\cheat\2169.chtC:\Program Files\SC\cheat\2170.chtC:\Program Files\SC\cheat\2171.chtC:\Program Files\SC\cheat\2172.chtC:\Program Files\SC\cheat\2173.chtC:\Program Files\SC\cheat\2174.chtC:\Program Files\SC\cheat\2175.chtC:\Program Files\SC\cheat\2176.chtC:\Program Files\SC\cheat\2177.chtC:\Program Files\SC\cheat\2178.chtC:\Program Files\SC\cheat\2179.chtC:\Program Files\SC\cheat\2180.chtC:\Program Files\SC\cheat\2181.chtC:\Program Files\SC\cheat\2184.chtC:\Program Files\SC\cheat\2185.chtC:\Program Files\SC\cheat\2187.chtC:\Program Files\SC\cheat\2188.chtC:\Program Files\SC\cheat\2189.chtC:\Program Files\SC\cheat\2190.chtC:\Program Files\SC\cheat\2191.chtC:\Program Files\SC\cheat\2193.chtC:\Program Files\SC\cheat\2194.chtC:\Program Files\SC\cheat\2199.chtC:\Program Files\SC\cheat\2200.chtC:\Program Files\SC\cheat\2203.chtC:\Program Files\SC\cheat\2206.chtC:\Program Files\SC\cheat\2208.chtC:\Program Files\SC\cheat\2211.chtC:\Program Files\SC\cheat\2212.chtC:\Program Files\SC\cheat\2214.chtC:\Program Files\SC\cheat\2218.chtC:\Program Files\SC\cheat\2219.chtC:\Program Files\SC\cheat\2221.chtC:\Program Files\SC\cheat\2223.chtC:\Program Files\SC\cheat\2224.chtC:\Program Files\SC\cheat\2229.chtC:\Program Files\SC\cheat\2231.chtC:\Program Files\SC\cheat\2233.chtC:\Program Files\SC\cheat\2234.chtC:\Program Files\SC\cheat\2239.chtC:\Program Files\SC\cheat\2241.chtC:\Program Files\SC\cheat\2242.chtC:\Program Files\SC\cheat\2243.chtC:\Program Files\SC\cheat\2245.chtC:\Program Files\SC\cheat\2249.chtC:\Program Files\SC\cheat\2250.chtC:\Program Files\SC\cheat\2253.chtC:\Program Files\SC\cheat\2254.chtC:\Program Files\SC\cheat\2255.chtC:\Program Files\SC\cheat\2256.chtC:\Program Files\SC\cheat\2257.chtC:\Program Files\SC\cheat\2258.chtC:\Program Files\SC\cheat\2259.chtC:\Program Files\SC\cheat\2262.chtC:\Program Files\SC\cheat\2264.chtC:\Program Files\SC\cheat\2267.chtC:\Program Files\SC\cheat\2268.chtC:\Program Files\SC\cheat\2269.chtC:\Program Files\SC\cheat\2270.chtC:\Program Files\SC\cheat\2271.chtC:\Program Files\SC\cheat\2272.chtC:\Program Files\SC\cheat\2273.chtC:\Program Files\SC\cheat\2274.chtC:\Program Files\SC\cheat\2276.chtC:\Program Files\SC\cheat\2277.chtC:\Program Files\SC\cheat\2278.chtC:\Program Files\SC\cheat\2279.chtC:\Program Files\SC\cheat\2280.chtC:\Program Files\SC\cheat\2281.chtC:\Program Files\SC\cheat\2282.chtC:\Program Files\SC\cheat\2283.chtC:\Program Files\SC\cheat\2284.chtC:\Program Files\SC\cheat\2285.chtC:\Program Files\SC\cheat\2286.chtC:\Program Files\SC\cheat\2287.chtC:\Program Files\SC\cheat\2288.chtC:\Program Files\SC\cheat\2289.chtC:\Program Files\SC\cheat\2290.chtC:\Program Files\SC\cheat\2291.chtC:\Program Files\SC\cheat\2292.chtC:\Program Files\SC\cheat\2293.chtC:\Program Files\SC\cheat\2294.chtC:\Program Files\SC\cheat\2295.chtC:\Program Files\SC\cheat\2296.chtC:\Program Files\SC\cheat\2297.chtC:\Program Files\SC\cheat\2299.chtC:\Program Files\SC\cheat\2300.chtC:\Program Files\SC\cheat\2301.chtC:\Program Files\SC\gep.exeC:\Program Files\SC\HZK16C:\Program Files\SC\isave.sciC:\Program Files\SC\LANGUAGE.INIC:\Program Files\SC\MFC70.DLLC:\Program Files\SC\MFC70U.DLLC:\Program Files\SC\MSVCP70.DLLC:\Program Files\SC\MSVCR70.DLLC:\Program Files\SC\ndscheat\chs\A2DE_00006199.sccC:\Program Files\SC\ndscheat\chs\A2DJ_0000607a.sccC:\Program Files\SC\ndscheat\chs\A2FJ_000060b6.sccC:\Program Files\SC\ndscheat\chs\A2GE_00005d70.sccC:\Program Files\SC\ndscheat\chs\A2GJ_00005f66.sccC:\Program Files\SC\ndscheat\chs\A2GP_00005f25.sccC:\Program Files\SC\ndscheat\chs\A2ME_00005c98.sccC:\Program Files\SC\ndscheat\chs\A2SE_00005cc0.sccC:\Program Files\SC\ndscheat\chs\A2VE_00005dbf.sccC:\Program Files\SC\ndscheat\chs\A3DJ_00005ea5.sccC:\Program Files\SC\ndscheat\chs\A3GJ_00005e1a.sccC:\Program Files\SC\ndscheat\chs\A3MJ_00005f8c.sccC:\Program Files\SC\ndscheat\chs\A3OE_00005e60.sccC:\Program Files\SC\ndscheat\chs\A3VJ_000060a0.sccC:\Program Files\SC\ndscheat\chs\A3XE_0000603b.sccC:\Program Files\SC\ndscheat\chs\A4OE_000060c1.sccC:\Program Files\SC\ndscheat\chs\A4OJ_00005f99.sccC:\Program Files\SC\ndscheat\chs\A4OP_00005fde.sccC:\Program Files\SC\ndscheat\chs\A4PE_00005e4c.sccC:\Program Files\SC\ndscheat\chs\A5EJ_00005f47.sccC:\Program Files\SC\ndscheat\chs\A5FJ_00005f58.sccC:\Program Files\SC\ndscheat\chs\A5KJ_000060cf.sccC:\Program Files\SC\ndscheat\chs\A5QJ_00005d79.sccC:\Program Files\SC\ndscheat\chs\A5TE_00005f02.sccC:\Program Files\SC\ndscheat\chs\A5TJ_00005ea6.sccC:\Program Files\SC\ndscheat\chs\A5TP_00005de3.sccC:\Program Files\SC\ndscheat\chs\A6AJ_00006215.sccC:\Program Files\SC\ndscheat\chs\A6BJ_000062d8.sccC:\Program Files\SC\ndscheat\chs\A6CJ_0000635d.sccC:\Program Files\SC\ndscheat\chs\A6DJ_00005d7a.sccC:\Program Files\SC\ndscheat\chs\A6RJ_00006189.sccC:\Program Files\SC\ndscheat\chs\A6SP_00005f2a.sccC:\Program Files\SC\ndscheat\chs\A8GJ_00005e05.sccC:\Program Files\SC\ndscheat\chs\A8QE_00005fff.sccC:\Program Files\SC\ndscheat\chs\A8QJ_00005f50.sccC:\Program Files\SC\ndscheat\chs\A8QP_00006065.sccC:\Program Files\SC\ndscheat\chs\AB3E_00005f60.sccC:\Program Files\SC\ndscheat\chs\AB3J_00005c3d.sccC:\Program Files\SC\ndscheat\chs\AB3P_00005db4.sccC:\Program Files\SC\ndscheat\chs\AB5J_00005f90.sccC:\Program Files\SC\ndscheat\chs\AB6E_000060c2.sccC:\Program Files\SC\ndscheat\chs\AB6J_00005c94.sccC:\Program Files\SC\ndscheat\chs\AB6P_00005d81.sccC:\Program Files\SC\ndscheat\chs\AB8E_00005ca0.sccC:\Program Files\SC\ndscheat\chs\ABBJ_00005d37.sccC:\Program Files\SC\ndscheat\chs\ABCE_00005d02.sccC:\Program Files\SC\ndscheat\chs\ABCJ_00005dd2.sccC:\Program Files\SC\ndscheat\chs\ABCP_00005ed6.sccC:\Program Files\SC\ndscheat\chs\ABHE_00005f7b.sccC:\Program Files\SC\ndscheat\chs\ABHJ_00005ed1.sccC:\Program Files\SC\ndscheat\chs\ABHP_00005e3f.sccC:\Program Files\SC\ndscheat\chs\ABJJ_0000630f.sccC:\Program Files\SC\ndscheat\chs\ABME_00005e10.sccC:\Program Files\SC\ndscheat\chs\ABMJ_00005eec.sccC:\Program Files\SC\ndscheat\chs\ABMP_00005d96.sccC:\Program Files\SC\ndscheat\chs\ABNJ_00006280.sccC:\Program Files\SC\ndscheat\chs\ABOE_00005d13.sccC:\Program Files\SC\ndscheat\chs\ABOP_00005dde.sccC:\Program Files\SC\ndscheat\chs\ABRE_00005ec0.sccC:\Program Files\SC\ndscheat\chs\ABRP_0000626d.sccC:\Program Files\SC\ndscheat\chs\ABTE_00005bf8.sccC:\Program Files\SC\ndscheat\chs\ABTP_00005ceb.sccC:\Program Files\SC\ndscheat\chs\ABVJ_00005f90.sccC:\Program Files\SC\ndscheat\chs\ABXE_00006016.sccC:\Program Files\SC\ndscheat\chs\ABXJ_00006136.sccC:\Program Files\SC\ndscheat\chs\ABXP_000061e1.sccC:\Program Files\SC\ndscheat\chs\ABZJ_00006161.sccC:\Program Files\SC\ndscheat\chs\AC4E_00006232.sccC:\Program Files\SC\ndscheat\chs\AC4J_00006032.sccC:\Program Files\SC\ndscheat\chs\AC4P_00005fdf.sccC:\Program Files\SC\ndscheat\chs\AC6E_00005ecb.sccC:\Program Files\SC\ndscheat\chs\AC9D_00005cc0.sccC:\Program Files\SC\ndscheat\chs\AC9E_00005cb2.sccC:\Program Files\SC\ndscheat\chs\AC9F_00005c52.sccC:\Program Files\SC\ndscheat\chs\ACAP_0000601a.sccC:\Program Files\SC\ndscheat\chs\ACBE_00006213.sccC:\Program Files\SC\ndscheat\chs\ACBJ_00006531.sccC:\Program Files\SC\ndscheat\chs\ACBP_00006429.sccC:\Program Files\SC\ndscheat\chs\ACHJ_0000609b.sccC:\Program Files\SC\ndscheat\chs\ACJE_00005fbc.sccC:\Program Files\SC\ndscheat\chs\ACJP_00006052.sccC:\Program Files\SC\ndscheat\chs\ACLE_0000624c.sccC:\Program Files\SC\ndscheat\chs\ACLJ_00006158.sccC:\Program Files\SC\ndscheat\chs\ACOE_00005d27.sccC:\Program Files\SC\ndscheat\chs\ACOJ_00005ada.sccC:\Program Files\SC\ndscheat\chs\ACOP_00005d82.sccC:\Program Files\SC\ndscheat\chs\ACRE_00005aa6.sccC:\Program Files\SC\ndscheat\chs\ACRP_00005c58.sccC:\Program Files\SC\ndscheat\chs\ACUE_00005efc.sccC:\Program Files\SC\ndscheat\chs\ACUX_00005e3a.sccC:\Program Files\SC\ndscheat\chs\ACVE_00005f84.sccC:\Program Files\SC\ndscheat\chs\ACVJ_00005dc6.sccC:\Program Files\SC\ndscheat\chs\ACVP_000060b4.sccC:\Program Files\SC\ndscheat\chs\ACZP_00005e29.sccC:\Program Files\SC\ndscheat\chs\AD2E_00005e88.sccC:\Program Files\SC\ndscheat\chs\AD3E_00005f17.sccC:\Program Files\SC\ndscheat\chs\AD7E_00005fbd.sccC:\Program Files\SC\ndscheat\chs\ADAE_00005fc1.sccC:\Program Files\SC\ndscheat\chs\ADAJ_00005faa.sccC:\Program Files\SC\ndscheat\chs\ADBJ_00005fbd.sccC:\Program Files\SC\ndscheat\chs\ADBP_00005fc9.sccC:\Program Files\SC\ndscheat\chs\ADCE_00005de3.sccC:\Program Files\SC\ndscheat\chs\ADDE_000061c6.sccC:\Program Files\SC\ndscheat\chs\ADDP_00006068.sccC:\Program Files\SC\ndscheat\chs\ADFP_00005c0e.sccC:\Program Files\SC\ndscheat\chs\ADGE_00005e0d.sccC:\Program Files\SC\ndscheat\chs\ADLE_000060e8.sccC:\Program Files\SC\ndscheat\chs\ADME_00006289.sccC:\Program Files\SC\ndscheat\chs\ADMJ_0000615a.sccC:\Program Files\SC\ndscheat\chs\ADMP_0000611b.sccC:\Program Files\SC\ndscheat\chs\ADNE_000062d7.sccC:\Program Files\SC\ndscheat\chs\ADNJ_00006227.sccC:\Program Files\SC\ndscheat\chs\ADQE_00005dd9.sccC:\Program Files\SC\ndscheat\chs\ADQJ_00005b25.sccC:\Program Files\SC\ndscheat\chs\ADRE_00005e96.sccC:\Program Files\SC\ndscheat\chs\ADVJ_00005c7f.sccC:\Program Files\SC\ndscheat\chs\ADVP_00005e6c.sccC:\Program Files\SC\ndscheat\chs\AE4J_0000607d.sccC:\Program Files\SC\ndscheat\chs\AEGE_00005dbd.sccC:\Program Files\SC\ndscheat\chs\AEGP_00005dc7.sccC:\Program Files\SC\ndscheat\chs\AEKE_00005bfc.sccC:\Program Files\SC\ndscheat\chs\AEKP_00005a1a.sccC:\Program Files\SC\ndscheat\chs\AF7E_00005ead.sccC:\Program Files\SC\ndscheat\chs\AF7P_00005e28.sccC:\Program Files\SC\ndscheat\chs\AF9E_00005ec8.sccC:\Program Files\SC\ndscheat\chs\AFFE_00006031.sccC:\Program Files\SC\ndscheat\chs\AFFJ_00005e84.sccC:\Program Files\SC\ndscheat\chs\AFGE_00005dfd.sccC:\Program Files\SC\ndscheat\chs\AFIP_00005de9.sccC:\Program Files\SC\ndscheat\chs\AFND_000060ce.sccC:\Program Files\SC\ndscheat\chs\AFNE_00006243.sccC:\Program Files\SC\ndscheat\chs\AFNJ_000062da.sccC:\Program Files\SC\ndscheat\chs\AFNP_00006071.sccC:\Program Files\SC\ndscheat\chs\AFNY_00006297.sccC:\Program Files\SC\ndscheat\chs\AFOJ_000060d9.sccC:\Program Files\SC\ndscheat\chs\AFPJ_00005ea6.sccC:\Program Files\SC\ndscheat\chs\AFUJ_000060d4.sccC:\Program Files\SC\ndscheat\chs\AFWP_000060d4.sccC:\Program Files\SC\ndscheat\chs\AG7E_00005f3d.sccC:\Program Files\SC\ndscheat\chs\AG8E_00006110.sccC:\Program Files\SC\ndscheat\chs\AG9J_00005fd2.sccC:\Program Files\SC\ndscheat\chs\AGCJ_00005f39.sccC:\Program Files\SC\ndscheat\chs\AGFE_00005e69.sccC:\Program Files\SC\ndscheat\chs\AGFJ_00005c0c.sccC:\Program Files\SC\ndscheat\chs\AGGJ_00005bc0.sccC:\Program Files\SC\ndscheat\chs\AGLE_00005e4a.sccC:\Program Files\SC\ndscheat\chs\AGLP_00006076.sccC:\Program Files\SC\ndscheat\chs\AGRJ_00005d83.sccC:\Program Files\SC\ndscheat\chs\AGWE_00005ec1.sccC:\Program Files\SC\ndscheat\chs\AGWJ_00006040.sccC:\Program Files\SC\ndscheat\chs\AGYE_00005fd3.sccC:\Program Files\SC\ndscheat\chs\AGYJ_00005de8.sccC:\Program Files\SC\ndscheat\chs\AGYP_00005ea0.sccC:\Program Files\SC\ndscheat\chs\AGYX_00005fa4.sccC:\Program Files\SC\ndscheat\chs\AH6E_00005db3.sccC:\Program Files\SC\ndscheat\chs\AH6J_00005eef.sccC:\Program Files\SC\ndscheat\chs\AH8E_00005c48.sccC:\Program Files\SC\ndscheat\chs\AHBE_00005e7b.sccC:\Program Files\SC\ndscheat\chs\AHEJ_000061b6.sccC:\Program Files\SC\ndscheat\chs\AHFP_00005ecc.sccC:\Program Files\SC\ndscheat\chs\AHHE_00005f39.sccC:\Program Files\SC\ndscheat\chs\AHPE_000061ac.sccC:\Program Files\SC\ndscheat\chs\AHRE_00005db0.sccC:\Program Files\SC\ndscheat\chs\AHRJ_00005b84.sccC:\Program Files\SC\ndscheat\chs\AHSE_00005d53.sccC:\Program Files\SC\ndscheat\chs\AHSJ_00005cf3.sccC:\Program Files\SC\ndscheat\chs\AHVE_00005fee.sccC:\Program Files\SC\ndscheat\chs\AI3P_00005f6c.sccC:\Program Files\SC\ndscheat\chs\AIAP_00005f96.sccC:\Program Files\SC\ndscheat\chs\AICE_00006045.sccC:\Program Files\SC\ndscheat\chs\AIFJ_00005ce3.sccC:\Program Files\SC\ndscheat\chs\AIGJ_00006165.sccC:\Program Files\SC\ndscheat\chs\AIKJ_00005efc.sccC:\Program Files\SC\ndscheat\chs\AIRJ_00005cb0.sccC:\Program Files\SC\ndscheat\chs\AISE_00005aa7.sccC:\Program Files\SC\ndscheat\chs\AISP_00005bdc.sccC:\Program Files\SC\ndscheat\chs\AIYE_00006149.sccC:\Program Files\SC\ndscheat\chs\AJAJ_00005e8d.sccC:\Program Files\SC\ndscheat\chs\AJGJ_00005e73.sccC:\Program Files\SC\ndscheat\chs\AJMJ_00005f29.sccC:\Program Files\SC\ndscheat\chs\AJPP_00005d06.sccC:\Program Files\SC\ndscheat\chs\AJRJ_000060b3.sccC:\Program Files\SC\ndscheat\chs\AJSJ_00005bbc.sccC:\Program Files\SC\ndscheat\chs\AJUJ_00005de7.sccC:\Program Files\SC\ndscheat\chs\AJXJ_00005e68.sccC:\Program Files\SC\ndscheat\chs\AK2J_0000602c.sccC:\Program Files\SC\ndscheat\chs\AKAE_0000616d.sccC:\Program Files\SC\ndscheat\chs\AKDE_000060ea.sccC:\Program Files\SC\ndscheat\chs\AKDJ_00005fd7.sccC:\Program Files\SC\ndscheat\chs\AKEJ_00005d69.sccC:\Program Files\SC\ndscheat\chs\AKFJ_00005c9e.sccC:\Program Files\SC\ndscheat\chs\AKGE_00005d3c.sccC:\Program Files\SC\ndscheat\chs\AKMJ_0000608b.sccC:\Program Files\SC\ndscheat\chs\AKOJ_0000600a.sccC:\Program Files\SC\ndscheat\chs\AKPE_00005ccc.sccC:\Program Files\SC\ndscheat\chs\AKWE_000061b3.sccC:\Program Files\SC\ndscheat\chs\AKWJ_00005fc2.sccC:\Program Files\SC\ndscheat\chs\AKYJ_000061ba.sccC:\Program Files\SC\ndscheat\chs\AL2E_000060ff.sccC:\Program Files\SC\ndscheat\chs\AL2J_0000610b.sccC:\Program Files\SC\ndscheat\chs\AL8E_000060cc.sccC:\Program Files\SC\ndscheat\chs\AL8P_0000612c.sccC:\Program Files\SC\ndscheat\chs\ALEJ_00005e3c.sccC:\Program Files\SC\ndscheat\chs\ALHE_00005fdc.sccC:\Program Files\SC\ndscheat\chs\ALKE_000061bb.sccC:\Program Files\SC\ndscheat\chs\ALKJ_000060ea.sccC:\Program Files\SC\ndscheat\chs\ALKP_00006182.sccC:\Program Files\SC\ndscheat\chs\ALNE_00005d97.sccC:\Program Files\SC\ndscheat\chs\ALRJ_00006014.sccC:\Program Files\SC\ndscheat\chs\ALTE_00005f4d.sccC:\Program Files\SC\ndscheat\chs\ALUJ_00005e66.sccC:\Program Files\SC\ndscheat\chs\ALXE_000060e8.sccC:\Program Files\SC\ndscheat\chs\AM5J_00005f7d.sccC:\Program Files\SC\ndscheat\chs\AM6E_00005bf4.sccC:\Program Files\SC\ndscheat\chs\AM6P_00005c65.sccC:\Program Files\SC\ndscheat\chs\AM7J_00005e98.sccC:\Program Files\SC\ndscheat\chs\AM7K_00005d03.sccC:\Program Files\SC\ndscheat\chs\AM9J_00005fb8.sccC:\Program Files\SC\ndscheat\chs\AMCE_00005fd6.sccC:\Program Files\SC\ndscheat\chs\AMDE_00005f5c.sccC:\Program Files\SC\ndscheat\chs\AMGD_00005cf6.sccC:\Program Files\SC\ndscheat\chs\AMGE_00005c3d.sccC:\Program Files\SC\ndscheat\chs\AMGF_00005ce3.sccC:\Program Files\SC\ndscheat\chs\AMGI_00005d52.sccC:\Program Files\SC\ndscheat\chs\AMGJ_00005d8e.sccC:\Program Files\SC\ndscheat\chs\AMGP_00005c7f.sccC:\Program Files\SC\ndscheat\chs\AMGS_00005c36.sccC:\Program Files\SC\ndscheat\chs\AMHE_00005fe1.sccC:\Program Files\SC\ndscheat\chs\AMJJ_00005b01.sccC:\Program Files\SC\ndscheat\chs\AMOE_00005eb2.sccC:\Program Files\SC\ndscheat\chs\AMOP_00005f11.sccC:\Program Files\SC\ndscheat\chs\AMPE_00005fec.sccC:\Program Files\SC\ndscheat\chs\AMQE_000061a5.sccC:\Program Files\SC\ndscheat\chs\AMQJ_0000631b.sccC:\Program Files\SC\ndscheat\chs\AMQP_000061c7.sccC:\Program Files\SC\ndscheat\chs\AMSJ_00005ff3.sccC:\Program Files\SC\ndscheat\chs\AMTE_00005c95.sccC:\Program Files\SC\ndscheat\chs\AMTJ_00005d10.sccC:\Program Files\SC\ndscheat\chs\AMTP_00005b88.sccC:\Program Files\SC\ndscheat\chs\AMVE_00005e39.sccC:\Program Files\SC\ndscheat\chs\AMWP_00005b4f.sccC:\Program Files\SC\ndscheat\chs\AMXP_00005e7e.sccC:\Program Files\SC\ndscheat\chs\AMYJ_00006044.sccC:\Program Files\SC\ndscheat\chs\AN2J_000060fe.sccC:\Program Files\SC\ndscheat\chs\AN4J_00005d14.sccC:\Program Files\SC\ndscheat\chs\AN7E_00005ebf.sccC:\Program Files\SC\ndscheat\chs\AN7P_00005e2c.sccC:\Program Files\SC\ndscheat\chs\AN8E_00005bbc.sccC:\Program Files\SC\ndscheat\chs\AN8P_00005c6f.sccC:\Program Files\SC\ndscheat\chs\AN9E_0000607a.sccC:\Program Files\SC\ndscheat\chs\ANDE_00005cb8.sccC:\Program Files\SC\ndscheat\chs\ANEJ_00005db9.sccC:\Program Files\SC\ndscheat\chs\ANFE_00005ce8.sccC:\Program Files\SC\ndscheat\chs\ANJE_00005d0c.sccC:\Program Files\SC\ndscheat\chs\ANOP_00005f2f.sccC:\Program Files\SC\ndscheat\chs\ANPE_000062f7.sccC:\Program Files\SC\ndscheat\chs\ANPP_00006370.sccC:\Program Files\SC\ndscheat\chs\ANRJ_00005ea0.sccC:\Program Files\SC\ndscheat\chs\ANSJ_00005c4a.sccC:\Program Files\SC\ndscheat\chs\ANSP_00005cd5.sccC:\Program Files\SC\ndscheat\chs\ANTJ_00006076.sccC:\Program Files\SC\ndscheat\chs\ANWE_00005fd7.sccC:\Program Files\SC\ndscheat\chs\ANZP_00005ee2.sccC:\Program Files\SC\ndscheat\chs\AOSE_00005fa4.sccC:\Program Files\SC\ndscheat\chs\AOSJ_00005bc7.sccC:\Program Files\SC\ndscheat\chs\AOZE_00005e15.sccC:\Program Files\SC\ndscheat\chs\AP2E_00005d76.sccC:\Program Files\SC\ndscheat\chs\AP2J_00005c1b.sccC:\Program Files\SC\ndscheat\chs\AP8J_00005f98.sccC:\Program Files\SC\ndscheat\chs\APAE_00005f69.sccC:\Program Files\SC\ndscheat\chs\APAJ_0000607c.sccC:\Program Files\SC\ndscheat\chs\APBJ_00005ef2.sccC:\Program Files\SC\ndscheat\chs\APCE_00005d95.sccC:\Program Files\SC\ndscheat\chs\APCJ_00005b53.sccC:\Program Files\SC\ndscheat\chs\APCP_00005ab4.sccC:\Program Files\SC\ndscheat\chs\APDE_00005fb6.sccC:\Program Files\SC\ndscheat\chs\APDJ_00005e8c.sccC:\Program Files\SC\ndscheat\chs\APDP_00005e1b.sccC:\Program Files\SC\ndscheat\chs\APGE_00005d3c.sccC:\Program Files\SC\ndscheat\chs\APGJ_00005d75.sccC:\Program Files\SC\ndscheat\chs\APGP_00005d96.sccC:\Program Files\SC\ndscheat\chs\APHE_00006108.sccC:\Program Files\SC\ndscheat\chs\APHJ_00005c19.sccC:\Program Files\SC\ndscheat\chs\APHJ_00005d6b.sccC:\Program Files\SC\ndscheat\chs\APHP_00005f3c.sccC:\Program Files\SC\ndscheat\chs\APKJ_00005e3b.sccC:\Program Files\SC\ndscheat\chs\APLE_00005ce5.sccC:\Program Files\SC\ndscheat\chs\APLP_00005fba.sccC:\Program Files\SC\ndscheat\chs\APNE_00005f3b.sccC:\Program Files\SC\ndscheat\chs\APNJ_00005eb2.sccC:\Program Files\SC\ndscheat\chs\APNP_00005d91.sccC:\Program Files\SC\ndscheat\chs\APPD_00005ede.sccC:\Program Files\SC\ndscheat\chs\APPE_00005e38.sccC:\Program Files\SC\ndscheat\chs\APPF_00005f74.sccC:\Program Files\SC\ndscheat\chs\APPP_00006068.sccC:\Program Files\SC\ndscheat\chs\APRE_00006029.sccC:\Program Files\SC\ndscheat\chs\APRJ_00005eb2.sccC:\Program Files\SC\ndscheat\chs\APTE_00005cb8.sccC:\Program Files\SC\ndscheat\chs\APTJ_00005ca5.sccC:\Program Files\SC\ndscheat\chs\APTP_00006009.sccC:\Program Files\SC\ndscheat\chs\APWE_00005e63.sccC:\Program Files\SC\ndscheat\chs\APXJ_0000618d.sccC:\Program Files\SC\ndscheat\chs\APYE_00005fa7.sccC:\Program Files\SC\ndscheat\chs\APYJ_00005fd6.sccC:\Program Files\SC\ndscheat\chs\APYP_00005e16.sccC:\Program Files\SC\ndscheat\chs\APZJ_00005d20.sccC:\Program Files\SC\ndscheat\chs\AQ4E_00005e32.sccC:\Program Files\SC\ndscheat\chs\AQAE_00005eed.sccC:\Program Files\SC\ndscheat\chs\AQCJ_00005fee.sccC:\Program Files\SC\ndscheat\chs\AQRF_0000623e.sccC:\Program Files\SC\ndscheat\chs\AQRP_00005f5c.sccC:\Program Files\SC\ndscheat\chs\AQWE_00005e6e.sccC:\Program Files\SC\ndscheat\chs\AR3J_00005f3f.sccC:\Program Files\SC\ndscheat\chs\AR5E_00005d7c.sccC:\Program Files\SC\ndscheat\chs\AR5P_00005c8d.sccC:\Program Files\SC\ndscheat\chs\AR7J_00006024.sccC:\Program Files\SC\ndscheat\chs\AR9J_0000601b.sccC:\Program Files\SC\ndscheat\chs\ARBE_0000590b.sccC:\Program Files\SC\ndscheat\chs\AREJ_00005e7c.sccC:\Program Files\SC\ndscheat\chs\ARFJ_00005fd5.sccC:\Program Files\SC\ndscheat\chs\ARGE_00006051.sccC:\Program Files\SC\ndscheat\chs\ARGJ_0000611a.sccC:\Program Files\SC\ndscheat\chs\ARGP_00006116.sccC:\Program Files\SC\ndscheat\chs\ARIE_00006157.sccC:\Program Files\SC\ndscheat\chs\ARIJ_00005e62.sccC:\Program Files\SC\ndscheat\chs\ARIP_00005e3c.sccC:\Program Files\SC\ndscheat\chs\ARKJ_00006008.sccC:\Program Files\SC\ndscheat\chs\ARME_00005df0.sccC:\Program Files\SC\ndscheat\chs\ARMJ_00005fc2.sccC:\Program Files\SC\ndscheat\chs\ARMP_00005e80.sccC:\Program Files\SC\ndscheat\chs\ARNE_0000618c.sccC:\Program Files\SC\ndscheat\chs\AROJ_0000616e.sccC:\Program Files\SC\ndscheat\chs\ARPE_00005e3d.sccC:\Program Files\SC\ndscheat\chs\ARPP_00005e40.sccC:\Program Files\SC\ndscheat\chs\ARRE_00005c9f.sccC:\Program Files\SC\ndscheat\chs\ARXJ_00005e77.sccC:\Program Files\SC\ndscheat\chs\ARYE_00005ce9.sccC:\Program Files\SC\ndscheat\chs\ARYP_00005b15.sccC:\Program Files\SC\ndscheat\chs\ARZE_00006154.sccC:\Program Files\SC\ndscheat\chs\ARZJ_0000612b.sccC:\Program Files\SC\ndscheat\chs\AS2E_00005ed1.sccC:\Program Files\SC\ndscheat\chs\AS2J_00006039.sccC:\Program Files\SC\ndscheat\chs\AS2P_0000618c.sccC:\Program Files\SC\ndscheat\chs\AS2X_0000625d.sccC:\Program Files\SC\ndscheat\chs\AS4E_0000607e.sccC:\Program Files\SC\ndscheat\chs\AS6J_00005ff2.sccC:\Program Files\SC\ndscheat\chs\AS9E_000062d9.sccC:\Program Files\SC\ndscheat\chs\ASBE_00005e49.sccC:\Program Files\SC\ndscheat\chs\ASCE_0000607d.sccC:\Program Files\SC\ndscheat\chs\ASEE_00005ff2.sccC:\Program Files\SC\ndscheat\chs\ASEJ_00005ef4.sccC:\Program Files\SC\ndscheat\chs\ASEP_00005ea7.sccC:\Program Files\SC\ndscheat\chs\ASFE_00006392.sccC:\Program Files\SC\ndscheat\chs\ASFP_000060a4.sccC:\Program Files\SC\ndscheat\chs\ASHE_00005d4f.sccC:\Program Files\SC\ndscheat\chs\ASHJ_00005ca1.sccC:\Program Files\SC\ndscheat\chs\ASHP_00005bec.sccC:\Program Files\SC\ndscheat\chs\ASIE_00005e7f.sccC:\Program Files\SC\ndscheat\chs\ASIP_00005ebf.sccC:\Program Files\SC\ndscheat\chs\ASJE_00005cfb.sccC:\Program Files\SC\ndscheat\chs\ASJJ_00005c19.sccC:\Program Files\SC\ndscheat\chs\ASJP_00005e0e.sccC:\Program Files\SC\ndscheat\chs\ASKE_00005bf1.sccC:\Program Files\SC\ndscheat\chs\ASKJ_00005b14.sccC:\Program Files\SC\ndscheat\chs\ASKP_00005c3d.sccC:\Program Files\SC\ndscheat\chs\ASME_0000618d.sccC:\Program Files\SC\ndscheat\chs\ASME_000063a7.sccC:\Program Files\SC\ndscheat\chs\ASMP_0000615e.sccC:\Program Files\SC\ndscheat\chs\ASNE_00005d11.sccC:\Program Files\SC\ndscheat\chs\ASNJ_00005b9d.sccC:\Program Files\SC\ndscheat\chs\ASPE_00006171.sccC:\Program Files\SC\ndscheat\chs\ASPJ_00006159.sccC:\Program Files\SC\ndscheat\chs\ASSE_00005e2c.sccC:\Program Files\SC\ndscheat\chs\ASTE_000060bc.sccC:\Program Files\SC\ndscheat\chs\ASUE_00005d34.sccC:\Program Files\SC\ndscheat\chs\ASUP_00005fd2.sccC:\Program Files\SC\ndscheat\chs\ASVE_00005c34.sccC:\Program Files\SC\ndscheat\chs\ASZE_00005e8e.sccC:\Program Files\SC\ndscheat\chs\ATAE_00005f28.sccC:\Program Files\SC\ndscheat\chs\ATAJ_00005fe6.sccC:\Program Files\SC\ndscheat\chs\ATCE_00005d03.sccC:\Program Files\SC\ndscheat\chs\ATCP_00005cd2.sccC:\Program Files\SC\ndscheat\chs\ATDE_000061e6.sccC:\Program Files\SC\ndscheat\chs\ATKE_00005f42.sccC:\Program Files\SC\ndscheat\chs\ATKJ_00005d56.sccC:\Program Files\SC\ndscheat\chs\ATKP_00005f70.sccC:\Program Files\SC\ndscheat\chs\ATLE_00005ede.sccC:\Program Files\SC\ndscheat\chs\ATLP_00005dcc.sccC:\Program Files\SC\ndscheat\chs\ATMJ_00005fa5.sccC:\Program Files\SC\ndscheat\chs\ATWE_00005f6a.sccC:\Program Files\SC\ndscheat\chs\ATWE_0000603f.sccC:\Program Files\SC\ndscheat\chs\ATWJ_00005ea9.sccC:\Program Files\SC\ndscheat\chs\AU2J_00005f5e.sccC:\Program Files\SC\ndscheat\chs\AU5E_00005d30.sccC:\Program Files\SC\ndscheat\chs\AUGE_00005c9a.sccC:\Program Files\SC\ndscheat\chs\AUGP_00005c57.sccC:\Program Files\SC\ndscheat\chs\AUSD_00005e39.sccC:\Program Files\SC\ndscheat\chs\AUSE_00005dba.sccC:\Program Files\SC\ndscheat\chs\AUSF_00005cea.sccC:\Program Files\SC\ndscheat\chs\AUSI_00005ea8.sccC:\Program Files\SC\ndscheat\chs\AUSP_00005d68.sccC:\Program Files\SC\ndscheat\chs\AUSS_00005dab.sccC:\Program Files\SC\ndscheat\chs\AVAE_00006112.sccC:\Program Files\SC\ndscheat\chs\AVAP_00006089.sccC:\Program Files\SC\ndscheat\chs\AVCE_00005fa4.sccC:\Program Files\SC\ndscheat\chs\AVCP_000060fa.sccC:\Program Files\SC\ndscheat\chs\AVGJ_000060de.sccC:\Program Files\SC\ndscheat\chs\AVJE_00005d87.sccC:\Program Files\SC\ndscheat\chs\AVJP_00005cf9.sccC:\Program Files\SC\ndscheat\chs\AVKE_0000601d.sccC:\Program Files\SC\ndscheat\chs\AVPJ_00005d27.sccC:\Program Files\SC\ndscheat\chs\AVSJ_000060ed.sccC:\Program Files\SC\ndscheat\chs\AW7J_00005f63.sccC:\Program Files\SC\ndscheat\chs\AWAJ_00005cf5.sccC:\Program Files\SC\ndscheat\chs\AWDE_00005db8.sccC:\Program Files\SC\ndscheat\chs\AWDP_000060e0.sccC:\Program Files\SC\ndscheat\chs\AWGJ_00006104.sccC:\Program Files\SC\ndscheat\chs\AWHP_00005d98.sccC:\Program Files\SC\ndscheat\chs\AWKP_00005de7.sccC:\Program Files\SC\ndscheat\chs\AWME_00005c59.sccC:\Program Files\SC\ndscheat\chs\AWPE_00005d75.sccC:\Program Files\SC\ndscheat\chs\AWRE_00005fd0.sccC:\Program Files\SC\ndscheat\chs\AWSP_00005cb2.sccC:\Program Files\SC\ndscheat\chs\AWUE_000062b3.sccC:\Program Files\SC\ndscheat\chs\AWZJ_00005ffd.sccC:\Program Files\SC\ndscheat\chs\AX3J_00005eb5.sccC:\Program Files\SC\ndscheat\chs\AX4J_00005f80.sccC:\Program Files\SC\ndscheat\chs\AX7J_00005fb9.sccC:\Program Files\SC\ndscheat\chs\AX9J_00005ead.sccC:\Program Files\SC\ndscheat\chs\AXCJ_00005f52.sccC:\Program Files\SC\ndscheat\chs\AXFJ_00005fde.sccC:\Program Files\SC\ndscheat\chs\AXLE_00006037.sccC:\Program Files\SC\ndscheat\chs\AXXJ_00006154.sccC:\Program Files\SC\ndscheat\chs\AY7E_00005ef6.sccC:\Program Files\SC\ndscheat\chs\AY7J_00005eef.sccC:\Program Files\SC\ndscheat\chs\AYAP_00005f78.sccC:\Program Files\SC\ndscheat\chs\AYGE_00005e85.sccC:\Program Files\SC\ndscheat\chs\AYGJ_00006090.sccC:\Program Files\SC\ndscheat\chs\AYGP_0000623f.sccC:\Program Files\SC\ndscheat\chs\AYHJ_00005f41.sccC:\Program Files\SC\ndscheat\chs\AYSJ_00005e87.sccC:\Program Files\SC\ndscheat\chs\AYSP_00005f03.sccC:\Program Files\SC\ndscheat\chs\AYWE_0000608b.sccC:\Program Files\SC\ndscheat\chs\AYWJ_00006194.sccC:\Program Files\SC\ndscheat\chs\AYWP_000061fa.sccC:\Program Files\SC\ndscheat\chs\AYXE_000061e3.sccC:\Program Files\SC\ndscheat\chs\AYXJ_00006251.sccC:\Program Files\SC\ndscheat\chs\AYXP_00006127.sccC:\Program Files\SC\ndscheat\chs\AZHJ_00005aac.sccC:\Program Files\SC\ndscheat\chs\AZKJ_00005d74.sccC:\Program Files\SC\ndscheat\chs\AZQP_00005e77.sccC:\Program Files\SC\ndscheat\chs\AZRJ_00005d79.sccC:\Program Files\SC\ndscheat\chs\AZSJ_0000611a.sccC:\Program Files\SC\ndscheat\chs\AZVE_00005d84.sccC:\Program Files\SC\ndscheat\chs\AZVP_00005e87.sccC:\Program Files\SC\ndscheat\chs\AZWE_000062a4.sccC:\Program Files\SC\ndscheat\chs\YALJ_00005e56.sccC:\Program Files\SC\ndscheat\eng\A2DE_00006199.sccC:\Program Files\SC\ndscheat\eng\A2DJ_0000607a.sccC:\Program Files\SC\ndscheat\eng\A2GE_00005d70.sccC:\Program Files\SC\ndscheat\eng\A2ME_00005c98.sccC:\Program Files\SC\ndscheat\eng\A2SE_00005cc0.sccC:\Program Files\SC\ndscheat\eng\A3XE_0000603b.sccC:\Program Files\SC\ndscheat\eng\A4PE_00005e4c.sccC:\Program Files\SC\ndscheat\eng\A5TE_00005f02.sccC:\Program Files\SC\ndscheat\eng\A6SP_00005f2a.sccC:\Program Files\SC\ndscheat\eng\A8QE_00005fff.sccC:\Program Files\SC\ndscheat\eng\A8QP_00006065.sccC:\Program Files\SC\ndscheat\eng\AB3E_00005f60.sccC:\Program Files\SC\ndscheat\eng\AB6P_00005d81.sccC:\Program Files\SC\ndscheat\eng\AB8E_00005ca0.sccC:\Program Files\SC\ndscheat\eng\ABBJ_00005d37.sccC:\Program Files\SC\ndscheat\eng\ABCE_00005d02.sccC:\Program Files\SC\ndscheat\eng\ABCJ_00005dd2.sccC:\Program Files\SC\ndscheat\eng\ABCP_00005ed6.sccC:\Program Files\SC\ndscheat\eng\ABHE_00005f7b.sccC:\Program Files\SC\ndscheat\eng\ABHJ_00005ed1.sccC:\Program Files\SC\ndscheat\eng\ABME_00005e10.sccC:\Program Files\SC\ndscheat\eng\ABOE_00005d13.sccC:\Program Files\SC\ndscheat\eng\ABOP_00005dde.sccC:\Program Files\SC\ndscheat\eng\ABRE_00005ec0.sccC:\Program Files\SC\ndscheat\eng\ABRP_0000626d.sccC:\Program Files\SC\ndscheat\eng\ABXE_00006016.sccC:\Program Files\SC\ndscheat\eng\AC6E_00005ecb.sccC:\Program Files\SC\ndscheat\eng\AC9E_00005cb2.sccC:\Program Files\SC\ndscheat\eng\ACAP_0000601a.sccC:\Program Files\SC\ndscheat\eng\ACBE_00006213.sccC:\Program Files\SC\ndscheat\eng\ACBJ_00006531.sccC:\Program Files\SC\ndscheat\eng\ACBP_00006429.sccC:\Program Files\SC\ndscheat\eng\ACJE_00005fbc.sccC:\Program Files\SC\ndscheat\eng\ACJP_00006052.sccC:\Program Files\SC\ndscheat\eng\ACLE_0000624c.sccC:\Program Files\SC\ndscheat\eng\ACLJ_00006158.sccC:\Program Files\SC\ndscheat\eng\ACOE_00005d27.sccC:\Program Files\SC\ndscheat\eng\ACOJ_00005ada.sccC:\Program Files\SC\ndscheat\eng\ACRE_00005aa6.sccC:\Program Files\SC\ndscheat\eng\ACRP_00005c58.sccC:\Program Files\SC\ndscheat\eng\ACUE_00005efc.sccC:\Program Files\SC\ndscheat\eng\ACUX_00005e3a.sccC:\Program Files\SC\ndscheat\eng\ACVE_00005f84.sccC:\Program Files\SC\ndscheat\eng\ACVJ_00005dc6.sccC:\Program Files\SC\ndscheat\eng\ACVP_000060b4.sccC:\Program Files\SC\ndscheat\eng\ACZP_00005e29.sccC:\Program Files\SC\ndscheat\eng\AD2E_00005e88.sccC:\Program Files\SC\ndscheat\eng\AD3E_00005f17.sccC:\Program Files\SC\ndscheat\eng\AD7E_00005fbd.sccC:\Program Files\SC\ndscheat\eng\ADCE_00005de3.sccC:\Program Files\SC\ndscheat\eng\ADDE_000061c6.sccC:\Program Files\SC\ndscheat\eng\ADDP_00006068.sccC:\Program Files\SC\ndscheat\eng\ADFP_00005c0e.sccC:\Program Files\SC\ndscheat\eng\ADGE_00005e0d.sccC:\Program Files\SC\ndscheat\eng\ADLE_000060e8.sccC:\Program Files\SC\ndscheat\eng\ADME_00006289.sccC:\Program Files\SC\ndscheat\eng\ADMP_0000611b.sccC:\Program Files\SC\ndscheat\eng\ADNE_000062d7.sccC:\Program Files\SC\ndscheat\eng\ADQE_00005dd9.sccC:\Program Files\SC\ndscheat\eng\ADRE_00005e96.sccC:\Program Files\SC\ndscheat\eng\ADVP_00005e6c.sccC:\Program Files\SC\ndscheat\eng\AE4J_0000607d.sccC:\Program Files\SC\ndscheat\eng\AEKE_00005bfc.sccC:\Program Files\SC\ndscheat\eng\AEKP_00005a1a.sccC:\Program Files\SC\ndscheat\eng\AF7E_00005ead.sccC:\Program Files\SC\ndscheat\eng\AF7P_00005e28.sccC:\Program Files\SC\ndscheat\eng\AFFE_00006031.sccC:\Program Files\SC\ndscheat\eng\AFFJ_00005e84.sccC:\Program Files\SC\ndscheat\eng\AFGE_00005dfd.sccC:\Program Files\SC\ndscheat\eng\AFIP_00005de9.sccC:\Program Files\SC\ndscheat\eng\AFWP_000060d4.sccC:\Program Files\SC\ndscheat\eng\AG7E_00005f3d.sccC:\Program Files\SC\ndscheat\eng\AG8E_00006110.sccC:\Program Files\SC\ndscheat\eng\AGFE_00005e69.sccC:\Program Files\SC\ndscheat\eng\AGGJ_00005bc0.sccC:\Program Files\SC\ndscheat\eng\AGLE_00005e4a.sccC:\Program Files\SC\ndscheat\eng\AGLP_00006076.sccC:\Program Files\SC\ndscheat\eng\AGWE_00005ec1.sccC:\Program Files\SC\ndscheat\eng\AGWJ_00006040.sccC:\Program Files\SC\ndscheat\eng\AH8E_00005c48.sccC:\Program Files\SC\ndscheat\eng\AHBE_00005e7b.sccC:\Program Files\SC\ndscheat\eng\AHFP_00005ecc.sccC:\Program Files\SC\ndscheat\eng\AHHE_00005f39.sccC:\Program Files\SC\ndscheat\eng\AHPE_000061ac.sccC:\Program Files\SC\ndscheat\eng\AHRE_00005db0.sccC:\Program Files\SC\ndscheat\eng\AHSE_00005d53.sccC:\Program Files\SC\ndscheat\eng\AHSJ_00005cf3.sccC:\Program Files\SC\ndscheat\eng\AHVE_00005fee.sccC:\Program Files\SC\ndscheat\eng\AIAP_00005f96.sccC:\Program Files\SC\ndscheat\eng\AICE_00006045.sccC:\Program Files\SC\ndscheat\eng\AIGJ_00006165.sccC:\Program Files\SC\ndscheat\eng\AIYE_00006149.sccC:\Program Files\SC\ndscheat\eng\AJMJ_00005f29.sccC:\Program Files\SC\ndscheat\eng\AJPP_00005d06.sccC:\Program Files\SC\ndscheat\eng\AJRJ_000060b3.sccC:\Program Files\SC\ndscheat\eng\AJSJ_00005bbc.sccC:\Program Files\SC\ndscheat\eng\AJUJ_00005de7.sccC:\Program Files\SC\ndscheat\eng\AKAE_0000616d.sccC:\Program Files\SC\ndscheat\eng\AKDE_000060ea.sccC:\Program Files\SC\ndscheat\eng\AKDJ_00005fd7.sccC:\Program Files\SC\ndscheat\eng\AKFJ_00005c9e.sccC:\Program Files\SC\ndscheat\eng\AKGE_00005d3c.sccC:\Program Files\SC\ndscheat\eng\AKMJ_0000608b.sccC:\Program Files\SC\ndscheat\eng\AKOJ_0000600a.sccC:\Program Files\SC\ndscheat\eng\AKPE_00005ccc.sccC:\Program Files\SC\ndscheat\eng\AKWE_000061b3.sccC:\Program Files\SC\ndscheat\eng\AL8E_000060cc.sccC:\Program Files\SC\ndscheat\eng\AL8P_0000612c.sccC:\Program Files\SC\ndscheat\eng\ALHE_00005fdc.sccC:\Program Files\SC\ndscheat\eng\ALKE_000061bb.sccC:\Program Files\SC\ndscheat\eng\ALNE_00005d97.sccC:\Program Files\SC\ndscheat\eng\ALTE_00005f4d.sccC:\Program Files\SC\ndscheat\eng\ALXE_000060e8.sccC:\Program Files\SC\ndscheat\eng\AM9J_00005fb8.sccC:\Program Files\SC\ndscheat\eng\AMCE_00005fd6.sccC:\Program Files\SC\ndscheat\eng\AMHE_00005fe1.sccC:\Program Files\SC\ndscheat\eng\AMOE_00005eb2.sccC:\Program Files\SC\ndscheat\eng\AMOP_00005f11.sccC:\Program Files\SC\ndscheat\eng\AMPE_00005fec.sccC:\Program Files\SC\ndscheat\eng\AMQE_000061a5.sccC:\Program Files\SC\ndscheat\eng\AMQJ_0000631b.sccC:\Program Files\SC\ndscheat\eng\AMSJ_00005ff3.sccC:\Program Files\SC\ndscheat\eng\AMVE_00005e39.sccC:\Program Files\SC\ndscheat\eng\AMWP_00005b4f.sccC:\Program Files\SC\ndscheat\eng\AMXP_00005e7e.sccC:\Program Files\SC\ndscheat\eng\AN6E_0000623e.sccC:\Program Files\SC\ndscheat\eng\AN7E_00005ebf.sccC:\Program Files\SC\ndscheat\eng\AN7P_00005e2c.sccC:\Program Files\SC\ndscheat\eng\AN9E_0000607a.sccC:\Program Files\SC\ndscheat\eng\ANDE_00005cb8.sccC:\Program Files\SC\ndscheat\eng\ANJE_00005d0c.sccC:\Program Files\SC\ndscheat\eng\ANOP_00005f2f.sccC:\Program Files\SC\ndscheat\eng\ANPE_000062f7.sccC:\Program Files\SC\ndscheat\eng\ANRJ_00005ea0.sccC:\Program Files\SC\ndscheat\eng\ANSP_00005cd5.sccC:\Program Files\SC\ndscheat\eng\ANTJ_00006076.sccC:\Program Files\SC\ndscheat\eng\ANWE_00005fd7.sccC:\Program Files\SC\ndscheat\eng\ANZP_00005ee2.sccC:\Program Files\SC\ndscheat\eng\AOSE_00005fa4.sccC:\Program Files\SC\ndscheat\eng\AOSJ_00005bc7.sccC:\Program Files\SC\ndscheat\eng\AOZE_00005e15.sccC:\Program Files\SC\ndscheat\eng\AP2E_00005d76.sccC:\Program Files\SC\ndscheat\eng\AP2J_00005c1b.sccC:\Program Files\SC\ndscheat\eng\APDE_00005fb6.sccC:\Program Files\SC\ndscheat\eng\APGE_00005d3c.sccC:\Program Files\SC\ndscheat\eng\APHJ_00005c19.sccC:\Program Files\SC\ndscheat\eng\APKJ_00005e3b.sccC:\Program Files\SC\ndscheat\eng\APLE_00005ce5.sccC:\Program Files\SC\ndscheat\eng\APLP_00005fba.sccC:\Program Files\SC\ndscheat\eng\APNE_00005f3b.sccC:\Program Files\SC\ndscheat\eng\APRE_00006029.sccC:\Program Files\SC\ndscheat\eng\APRJ_00005eb2.sccC:\Program Files\SC\ndscheat\eng\APWE_00005e63.sccC:\Program Files\SC\ndscheat\eng\APYE_00005fa7.sccC:\Program Files\SC\ndscheat\eng\APYJ_00005fd6.sccC:\Program Files\SC\ndscheat\eng\AQ4E_00005e32.sccC:\Program Files\SC\ndscheat\eng\AQAE_00005eed.sccC:\Program Files\SC\ndscheat\eng\AR5P_00005c8d.sccC:\Program Files\SC\ndscheat\eng\AR7J_00006024.sccC:\Program Files\SC\ndscheat\eng\ARBE_0000590b.sccC:\Program Files\SC\ndscheat\eng\ARGE_00006051.sccC:\Program Files\SC\ndscheat\eng\ARKJ_00006008.sccC:\Program Files\SC\ndscheat\eng\ARME_00005df0.sccC:\Program Files\SC\ndscheat\eng\ARMJ_00005fc2.sccC:\Program Files\SC\ndscheat\eng\ARMP_00005e80.sccC:\Program Files\SC\ndscheat\eng\ARPE_00005e3d.sccC:\Program Files\SC\ndscheat\eng\ARPP_00005e40.sccC:\Program Files\SC\ndscheat\eng\ARRE_00005c9f.sccC:\Program Files\SC\ndscheat\eng\AS2E_00005ed1.sccC:\Program Files\SC\ndscheat\eng\AS9E_000062d9.sccC:\Program Files\SC\ndscheat\eng\ASBE_00005e49.sccC:\Program Files\SC\ndscheat\eng\ASCE_0000607d.sccC:\Program Files\SC\ndscheat\eng\ASEE_00005ff2.sccC:\Program Files\SC\ndscheat\eng\ASEJ_00005ef4.sccC:\Program Files\SC\ndscheat\eng\ASEP_00005ea7.sccC:\Program Files\SC\ndscheat\eng\ASFE_00006392.sccC:\Program Files\SC\ndscheat\eng\ASFP_000060a4.sccC:\Program Files\SC\ndscheat\eng\ASJE_00005cfb.sccC:\Program Files\SC\ndscheat\eng\ASKE_00005bf1.sccC:\Program Files\SC\ndscheat\eng\ASME_0000618d.sccC:\Program Files\SC\ndscheat\eng\ASME_000063a7.sccC:\Program Files\SC\ndscheat\eng\ASMP_0000615e.sccC:\Program Files\SC\ndscheat\eng\ASNE_00005d11.sccC:\Program Files\SC\ndscheat\eng\ASNJ_00005b9d.sccC:\Program Files\SC\ndscheat\eng\ASPE_00006171.sccC:\Program Files\SC\ndscheat\eng\ASSE_00005e2c.sccC:\Program Files\SC\ndscheat\eng\ASTE_000060bc.sccC:\Program Files\SC\ndscheat\eng\ASUE_00005d34.sccC:\Program Files\SC\ndscheat\eng\ASUP_00005fd2.sccC:\Program Files\SC\ndscheat\eng\ASVE_00005c34.sccC:\Program Files\SC\ndscheat\eng\ASZE_00005e8e.sccC:\Program Files\SC\ndscheat\eng\ATAE_00005f28.sccC:\Program Files\SC\ndscheat\eng\ATAJ_00005fe6.sccC:\Program Files\SC\ndscheat\eng\ATCE_00005d03.sccC:\Program Files\SC\ndscheat\eng\ATDE_000061e6.sccC:\Program Files\SC\ndscheat\eng\ATKE_00005f42.sccC:\Program Files\SC\ndscheat\eng\ATKJ_00005d56.sccC:\Program Files\SC\ndscheat\eng\ATWE_00005f6a.sccC:\Program Files\SC\ndscheat\eng\AUSE_00005dba.sccC:\Program Files\SC\ndscheat\eng\AVAE_00006112.sccC:\Program Files\SC\ndscheat\eng\AVAP_00006089.sccC:\Program Files\SC\ndscheat\eng\AVCE_00005fa4.sccC:\Program Files\SC\ndscheat\eng\AVCP_000060fa.sccC:\Program Files\SC\ndscheat\eng\AVJE_00005d87.sccC:\Program Files\SC\ndscheat\eng\AVJP_00005cf9.sccC:\Program Files\SC\ndscheat\eng\AVKE_0000601d.sccC:\Program Files\SC\ndscheat\eng\AWAJ_00005cf5.sccC:\Program Files\SC\ndscheat\eng\AWGJ_00006104.sccC:\Program Files\SC\ndscheat\eng\AWKP_00005de7.sccC:\Program Files\SC\ndscheat\eng\AWME_00005c59.sccC:\Program Files\SC\ndscheat\eng\AWRE_00005fd0.sccC:\Program Files\SC\ndscheat\eng\AWSP_00005cb2.sccC:\Program Files\SC\ndscheat\eng\AWUE_000062b3.sccC:\Program Files\SC\ndscheat\eng\AWZJ_00005ffd.sccC:\Program Files\SC\ndscheat\eng\AXLE_00006037.sccC:\Program Files\SC\ndscheat\eng\AY7E_00005ef6.sccC:\Program Files\SC\ndscheat\eng\AYAP_00005f78.sccC:\Program Files\SC\ndscheat\eng\AYGJ_00006090.sccC:\Program Files\SC\ndscheat\eng\AYSP_00005f03.sccC:\Program Files\SC\ndscheat\eng\AYWE_0000608b.sccC:\Program Files\SC\ndscheat\eng\AYWJ_00006194.sccC:\Program Files\SC\ndscheat\eng\AYXE_000061e3.sccC:\Program Files\SC\ndscheat\eng\AZHJ_00005aac.sccC:\Program Files\SC\ndscheat\eng\AZKJ_00005d74.sccC:\Program Files\SC\ndscheat\eng\AZSJ_0000611a.sccC:\Program Files\SC\ndscheat\eng\AZVE_00005d84.sccC:\Program Files\SC\ndscheat\eng\AZVP_00005e87.sccC:\Program Files\SC\ndscheat\eng\AZWE_000062a4.sccC:\Program Files\SC\ndsrominfo.datC:\Program Files\SC\NesFileName.savC:\Program Files\SC\out\T.TXTC:\Program Files\SC\rominfo.datC:\Program Files\SC\save.savC:\Program Files\SC\saver113.savC:\Program Files\SC\saver131.savC:\Program Files\SC\saver135.savC:\Program Files\SC\saver188.savC:\Program Files\SC\saver286.savC:\Program Files\SC\saver534.savC:\Program Files\SC\saver535.savC:\Program Files\SC\saver576.savC:\Program Files\SC\saver577.savC:\Program Files\SC\srampatch.exeC:\Program Files\SC\SuperCardnew.exeC:\Program Files\SC\temp\18b030ca.tmpC:\Program Files\SC\temp\18c17e7a.tmpC:\Program Files\SC\temp\1947254a.tmpC:\Program Files\SC\temp\23e23bca.tmpC:\Program Files\SC\temp\242fe88a.tmpC:\Program Files\SC\temp\2449cd7a.tmpC:\Program Files\SC\temp\44454bd.tmpC:\Program Files\SC\temp\471b3fd.tmpC:\Program Files\SC\temp\4bc6a3cc.tmpC:\Program Files\SC\temp\4bc988fa.tmpC:\Program Files\SC\temp\4c1e0dba.tmpC:\Program Files\SC\temp\bdd6ad.tmpC:\Program Files\SC\temp\T.TXTC:\Program Files\SC\unins000.datC:\Program Files\SC\unins000.exeC:\Program Files\SC\UPGRADE.scuC:\Program Files\winantispyware 2007C:\Program Files\WinAntiSpyware 2007\RTMonitor(2).dat\795cb2cd67cf494bec2c6791(2)\103f41849a49468e80e6c994(2)27aff2e1df54524d72e76b4\#dataC:\Program Files\winantispyware 2007\RTMonitor(2).dat\795cb2cd67cf494bec2c6791(2)\103f41849a49468e80e6c994(2)27aff2e1df54524d72e76b4\#internalC:\Program Files\WinAntiSpyware 2007\RTMonitor(2).dat\795cb2cd67cf494bec2c6791(2)\103f41849a49468e80e6c994(2)27aff2e1df54524d72e76b4\#nameC:\Program Files\winantispyware 2007\RTMonitor(2).dat\795cb2cd67cf494bec2c6791(2)\103f41849a49468e80e6c994(2)\12bda09a296b4ce98aeb6082\#dataC:\Program Files\winantispyware 2007\RTMonitor(2).dat\795cb2cd67cf494bec2c6791(2)\103f41849a49468e80e6c994(2)\12bda09a296b4ce98aeb6082\#internalC:\Program Files\WinAntiSpyware 2007\RTMonitor(2).dat\795cb2cd67cf494bec2c6791(2)\103f41849a49468e80e6c994(2)\12bda09a296b4ce98aeb6082\#nameC:\Program Files\winantispyware 2007\RTMonitor(2).dat\795cb2cd67cf494bec2c6791(2)\103f41849a49468e80e6c994(2)\7d8197c125cb432cf95db2b9\#dataC:\Program Files\WinAntiSpyware 2007\RTMonitor(2).dat\795cb2cd67cf494bec2c6791(2)\103f41849a49468e80e6c994(2)\7d8197c125cb432cf95db2b9\#internalC:\Program Files\winantispyware 2007\RTMonitor(2).dat\795cb2cd67cf494bec2c6791(2)\103f41849a49468e80e6c994(2)\7d8197c125cb432cf95db2b9\#nameC:\Program Files\winantispyware 2007\RTMonitor(2).dat\795cb2cd67cf494bec2c6791(2)\103f41849a49468e80e6c994(2)\de3606fb213b4bff92ffca90\#dataC:\Program Files\WinAntiSpyware 2007\RTMonitor(2).dat\795cb2cd67cf494bec2c6791(2)\103f41849a49468e80e6c994(2)\de3606fb213b4bff92ffca90\#internalC:\Program Files\WinAntiSpyware 2007\RTMonitor(2).dat\795cb2cd67cf494bec2c6791(2)\103f41849a49468e80e6c994(2)\de3606fb213b4bff92ffca90\#nameC:\Program Files\WinAntiSpyware 2007\RTMonitor(2).dat\795cb2cd67cf494bec2c6791(2)\3bc7254f9c194fc9e8ac8ca4(2)\d06144aa7254431ef9dab297\#dataC:\Program Files\WinAntiSpyware 2007\RTMonitor(2).dat\795cb2cd67cf494bec2c6791(2)\3bc7254f9c194fc9e8ac8ca4(2)\d06144aa7254431ef9dab297\#internalC:\Program Files\winantispyware 2007\RTMonitor(2).dat\795cb2cd67cf494bec2c6791(2)\3bc7254f9c194fc9e8ac8ca4(2)\d06144aa7254431ef9dab297\#nameC:\Program Files\WinAntiSpyware 2007\RTMonitor(2).dat\795cb2cd67cf494bec2c6791(2)\3bc7254f9c194fc9e8ac8ca4(2)\d06144aa7254431ef9dab297\Pete'sC:\Program Files\WinAntiSpyware 2007\RTMonitor(2).dat\795cb2cd67cf494bec2c6791(2)\3bc7254f9c194fc9e8ac8ca4(2)\eb327e245f0a4d963b8c70b2\#dataC:\Program Files\WinAntiSpyware 2007\RTMonitor(2).dat\795cb2cd67cf494bec2c6791(2)\3bc7254f9c194fc9e8ac8ca4(2)\eb327e245f0a4d963b8c70b2\#internalC:\Program Files\WinAntiSpyware 2007\RTMonitor(2).dat\795cb2cd67cf494bec2c6791(2)\3bc7254f9c194fc9e8ac8ca4(2)\eb327e245f0a4d963b8c70b2\#nameC:\tempc2C:\tempc2\tmpFF.logC:\temp\brrC:\temp\brr\tmpZTF.logC:\WINDOWS\cookies.iniC:\WINDOWS\dat.txtC:\WINDOWS\rs.txtC:\WINDOWS\system32\aefwwuws.exeC:\WINDOWS\system32\ahviptds.exeC:\WINDOWS\system32\apmsycwe.exeC:\WINDOWS\system32\arvgymlv.exeC:\WINDOWS\system32\auojsluu.exeC:\WINDOWS\system32\b02FdUeC:\WINDOWS\system32\bknruawb.exeC:\WINDOWS\system32\bnrgfcyy.exeC:\WINDOWS\system32\boxavbkc.exeC:\WINDOWS\system32\bqlfceno.exeC:\WINDOWS\system32\brjchwdp.exeC:\WINDOWS\system32\bsluyvwr.exeC:\WINDOWS\system32\cctxiiuq.exeC:\WINDOWS\system32\clshtinn.exeC:\WINDOWS\system32\cytcdlhu.exeC:\WINDOWS\system32\dcmgpqws.exeC:\WINDOWS\system32\djnjbxwa.exeC:\WINDOWS\system32\dmeaxavy.exeC:\WINDOWS\system32\dtgufwfa.exeC:\WINDOWS\system32\dtieeaar.exeC:\WINDOWS\system32\dwdsrngt.exeC:\WINDOWS\system32\eerpwahc.exeC:\WINDOWS\system32\efijtflg.exeC:\WINDOWS\system32\elxnqvoj.exeC:\WINDOWS\system32\epxkwvnh.exeC:\WINDOWS\system32\eulumrfo.exeC:\WINDOWS\system32\evpifsox.exeC:\WINDOWS\system32\exjqctyt.exeC:\WINDOWS\system32\eymbrmsr.exeC:\WINDOWS\system32\eyqkyona.exeC:\WINDOWS\system32\ffabrlrf.exeC:\WINDOWS\system32\gctaebqn.exeC:\WINDOWS\system32\gcwsbvlu.exeC:\WINDOWS\system32\gftjimxs.exeC:\WINDOWS\system32\ggtlanbv.exeC:\WINDOWS\system32\ghomkhnq.exeC:\WINDOWS\system32\ghtycdpm.exeC:\WINDOWS\system32\gstjwlkt.exeC:\WINDOWS\system32\gwarlmjd.exeC:\WINDOWS\system32\hbdrbtnn.exeC:\WINDOWS\system32\hdktltgh.exeC:\WINDOWS\system32\hipqwplj.exeC:\WINDOWS\system32\hkasakfa.exeC:\WINDOWS\system32\hviiscyv.exeC:\WINDOWS\system32\iaumboxl.exeC:\WINDOWS\system32\ifilaykf.exeC:\WINDOWS\system32\ifjunyfo.exeC:\WINDOWS\system32\igorrulb.exeC:\WINDOWS\system32\iifcaay.dllC:\WINDOWS\system32\ijllm.bak1C:\WINDOWS\system32\ijllm.bak2C:\WINDOWS\system32\ilgorkbs.exeC:\WINDOWS\system32\inmkcpar.exeC:\WINDOWS\system32\irgjxtbq.exeC:\WINDOWS\system32\ivtbgpno.exeC:\WINDOWS\system32\jbbqigeg.exeC:\WINDOWS\system32\jcsnoxqh.exeC:\WINDOWS\system32\jdsrouhr.exeC:\WINDOWS\system32\jhbyyphq.exeC:\WINDOWS\system32\jhqryvml.exeC:\WINDOWS\system32\jhucgsqq.exeC:\WINDOWS\system32\jkkvduqk.exeC:\WINDOWS\system32\jkmvqdvq.exeC:\WINDOWS\system32\jlnoinpq.exeC:\WINDOWS\system32\jmeybmff.exeC:\WINDOWS\system32\jnknllyr.exeC:\WINDOWS\system32\jqgrwaju.exeC:\WINDOWS\system32\jqhfuoni.exeC:\WINDOWS\system32\jqrqjknw.exeC:\WINDOWS\system32\jrhyrarb.exeC:\WINDOWS\system32\jtmgxxft.exeC:\WINDOWS\system32\jwfiwyxh.exeC:\WINDOWS\system32\kagomquy.exeC:\WINDOWS\system32\keelhdht.exeC:\WINDOWS\system32\krovexcx.exeC:\WINDOWS\system32\ljqsrqve.exeC:\WINDOWS\system32\lrkyepii.exeC:\WINDOWS\system32\luhijkbe.exeC:\WINDOWS\system32\mftjvkml.exeC:\WINDOWS\system32\miwlgref.exeC:\WINDOWS\system32\mjnkdjaj.exeC:\WINDOWS\system32\mktmaqqr.exeC:\WINDOWS\system32\mllji.dllC:\WINDOWS\system32\mmaooktc.exeC:\WINDOWS\system32\mnvqvxqd.exeC:\WINDOWS\system32\morlxjsw.exeC:\WINDOWS\system32\msnav32.axC:\WINDOWS\system32\mvkfprvf.exeC:\WINDOWS\system32\mvwuhpyy.exeC:\WINDOWS\system32\myyuullp.exeC:\WINDOWS\system32\nbrjikvu.exeC:\WINDOWS\system32\nbvvkwmv.exeC:\WINDOWS\system32\ndekpepp.exeC:\WINDOWS\system32\nlgtiqni.exeC:\WINDOWS\system32\nlmsodpx.exeC:\WINDOWS\system32\nmxlnhnc.exeC:\WINDOWS\system32\ntggmhid.exeC:\WINDOWS\system32\nvhxjugb.exeC:\WINDOWS\system32\nwyujmlo.exeC:\WINDOWS\system32\nxswlcth.exeC:\WINDOWS\system32\nytijdmq.exeC:\WINDOWS\system32\nytqlkjb.exeC:\WINDOWS\system32\ocxyahga.exeC:\WINDOWS\system32\ocytqrfr.exeC:\WINDOWS\system32\ofgjvyml.exeC:\WINDOWS\system32\okkqwucj.exeC:\WINDOWS\system32\opwychlt.exeC:\WINDOWS\system32\orkjkxgb.exeC:\WINDOWS\system32\pholwlhi.exeC:\WINDOWS\system32\phuswosl.exeC:\WINDOWS\system32\piwknnky.exeC:\WINDOWS\system32\piwvirvs.exeC:\WINDOWS\system32\pjneskhn.exeC:\WINDOWS\system32\pkwfiwiu.exeC:\WINDOWS\system32\psaatulw.exeC:\WINDOWS\system32\qdjmedpk.exeC:\WINDOWS\system32\qdnqemek.exeC:\WINDOWS\system32\qgrwbayc.exeC:\WINDOWS\system32\qnrdligo.exeC:\WINDOWS\system32\qodplpty.exeC:\WINDOWS\system32\qyykmltg.exeC:\WINDOWS\system32\rdpdrmkd.exeC:\WINDOWS\system32\rhelayjj.exeC:\WINDOWS\system32\rhuywycq.exeC:\WINDOWS\system32\rplckioe.exeC:\WINDOWS\system32\slfugsrx.exeC:\WINDOWS\system32\smnovfjs.exeC:\WINDOWS\system32\svoxxjaj.exeC:\WINDOWS\system32\swbrwtwe.exeC:\WINDOWS\system32\tkdivwyj.exeC:\WINDOWS\system32\tmiocnua.exeC:\WINDOWS\system32\tmipuitg.exeC:\WINDOWS\system32\tsmqyvox.exeC:\WINDOWS\system32\tvalsolt.exeC:\WINDOWS\system32\uffskdaf.exeC:\WINDOWS\system32\ujweeaqf.exeC:\WINDOWS\system32\unxudbtl.exeC:\WINDOWS\system32\uyslucpl.exeC:\WINDOWS\system32\vbedxlfp.exeC:\WINDOWS\system32\vgxulvfy.exeC:\WINDOWS\system32\vkpgfubx.exeC:\WINDOWS\system32\vkvxdctr.exeC:\WINDOWS\system32\vmddfldq.exeC:\WINDOWS\system32\vrdxyxpw.exeC:\WINDOWS\system32\vvqsyiph.exeC:\WINDOWS\system32\vybuqhef.exeC:\WINDOWS\system32\waysmhch.exeC:\WINDOWS\system32\welcgytu.exeC:\WINDOWS\system32\whkdomlt.exeC:\WINDOWS\system32\winpfz32.sysC:\WINDOWS\system32\wiqxdsji.exeC:\WINDOWS\system32\wmtehaik.exeC:\WINDOWS\system32\wvexemju.exeC:\WINDOWS\system32\xbnkugnj.exeC:\WINDOWS\system32\xcradfwd.exeC:\WINDOWS\system32\xmpvefnn.exeC:\WINDOWS\system32\xxnlcsrd.exeC:\WINDOWS\system32\ybkgdrqq.exeC:\WINDOWS\system32\ybtnyfoq.exeC:\WINDOWS\system32\yccdhise.exeC:\WINDOWS\system32\ycqtcafr.exeC:\WINDOWS\system32\yfgmjans.exeC:\WINDOWS\system32\ygepxnrr.exeC:\WINDOWS\system32\yiiudiot.exeC:\WINDOWS\system32\zxdnt3d.cfgC:\WINDOWS\wr.txtD:\Autorun.inf.((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))-------\LEGACY_DOMAINSERVICE-------\DomainService((((((((((((((((((((((((( Files Created from 203.-01-28 to 203.0.2.97 ))))))))))))))))))))))))))))))).No new files created in this timespan.(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))).2007-02-18 12:36 26624 --a------ C:\Documents and Settings\Pete's\LLII.exe2007-02-18 11:24 26624 --a------ C:\Documents and Settings\Pete's\DNRL.exe2007-02-18 08:37 26624 --a------ C:\Documents and Settings\Pete's\KPGI.exe2007-02-18 08:32 26624 --a------ C:\Documents and Settings\Pete's\BQPA.exe2007-02-17 21:25 26624 --a------ C:\Documents and Settings\Pete's\ASOJ.exe2007-02-17 20:22 26624 --a------ C:\Documents and Settings\Pete's\DJIK.exe2007-02-17 19:33 26624 --a------ C:\Documents and Settings\Pete's\MNGA.exe2007-02-17 19:10 26624 --a------ C:\Documents and Settings\Pete's\AUBD.exe2007-02-17 17:19 26624 --a------ C:\Documents and Settings\Pete's\TBJM.exe2007-02-17 17:06 26624 --a------ C:\Documents and Settings\Pete's\GKSO.exe2007-02-17 16:38 26624 --a------ C:\Documents and Settings\Pete's\TESE.exe2007-02-17 16:33 26624 --a------ C:\Documents and Settings\Pete's\NKIC.exe2007-02-17 16:33 26624 --a------ C:\Documents and Settings\Pete's\LIBF.exe2007-02-17 15:36 26624 --a------ C:\Documents and Settings\Pete's\BUTA.exe2007-02-17 14:51 26624 --a------ C:\Documents and Settings\Pete's\TCMH.exe2007-02-17 14:49 26624 --a------ C:\Documents and Settings\Pete's\POOT.exe2007-02-17 14:43 26624 --a------ C:\Documents and Settings\Pete's\PREK.exe2007-02-17 12:23 26624 --a------ C:\Documents and Settings\Pete's\QPPP.exe2007-02-17 11:59 26624 --a------ C:\Documents and Settings\Pete's\NPPH.exe2007-02-17 11:59 26624 --a------ C:\Documents and Settings\Pete's\INTH.exe2007-02-17 11:59 26624 --a------ C:\Documents and Settings\Pete's\GRJB.exe2007-02-17 11:52 26624 --a------ C:\Documents and Settings\Pete's\JRSC.exe2007-02-17 11:49 26624 --a------ C:\Documents and Settings\Pete's\FPFU.exe2007-02-17 11:46 26624 --a------ C:\Documents and Settings\Pete's\SGLJ.exe2007-02-17 11:42 26624 --a------ C:\Documents and Settings\Pete's\FBBF.exe2007-02-17 11:39 26624 --a------ C:\Documents and Settings\Pete's\POSS.exe2007-02-17 10:41 26624 --a------ C:\Documents and Settings\Pete's\EBUT.exe2007-02-17 09:31 26624 --a------ C:\Documents and Settings\Pete's\KPUK.exe2007-02-17 09:19 26624 --a------ C:\Documents and Settings\Pete's\SGTK.exe2007-02-17 09:19 26624 --a------ C:\Documents and Settings\Pete's\CRIN.exe2007-02-17 09:18 26624 --a------ C:\Documents and Settings\Pete's\GETS.exe2007-02-16 23:04 26624 --a------ C:\Documents and Settings\Pete's\IBHA.exe2007-02-16 22:56 26624 --a------ C:\Documents and Settings\Pete's\HQAL.exe2007-02-16 21:59 26624 --a------ C:\Documents and Settings\Pete's\LOMS.exe2007-02-16 21:51 26624 --a------ C:\Documents and Settings\Pete's\PJNP.exe2007-02-16 21:14 26624 --a------ C:\Documents and Settings\Pete's\IHPN.exe2007-02-16 21:10 26624 --a------ C:\Documents and Settings\Pete's\MIRP.exe2007-02-16 21:08 26624 --a------ C:\Documents and Settings\Pete's\RPRD.exe2007-02-16 21:05 26624 --a------ C:\Documents and Settings\Pete's\IRTI.exe2007-02-16 20:14 26624 --a------ C:\Documents and Settings\Pete's\ELIM.exe2007-02-16 19:11 26624 --a------ C:\Documents and Settings\Pete's\OULD.exe2007-02-16 19:10 26624 --a------ C:\Documents and Settings\Pete's\ORUR.exe2007-02-16 18:58 26624 --a------ C:\Documents and Settings\Pete's\UJRH.exe2007-02-16 18:58 26624 --a------ C:\Documents and Settings\Pete's\NQQD.exe2007-02-16 18:58 26624 --a------ C:\Documents and Settings\Pete's\FSRM.exe2007-02-16 16:52 26624 --a------ C:\Documents and Settings\Pete's\ULBU.exe2007-02-16 16:51 26624 --a------ C:\Documents and Settings\Pete's\JKIA.exe2007-02-16 16:46 26624 --a------ C:\Documents and Settings\Pete's\QNBI.exe2007-02-16 16:45 26624 --a------ C:\Documents and Settings\Pete's\QHQU.exe2007-02-16 16:45 26624 --a------ C:\Documents and Settings\Pete's\BNHJ.exe2007-02-16 16:43 26624 --a------ C:\Documents and Settings\Pete's\MMGO.exe2007-02-16 16:39 26624 --a------ C:\Documents and Settings\Pete's\IKBH.exe2007-02-16 16:36 26624 --a------ C:\Documents and Settings\Pete's\NTJO.exe2007-02-16 16:31 26624 --a------ C:\Documents and Settings\Pete's\AAKQ.exe2007-02-16 16:27 26624 --a------ C:\Documents and Settings\Pete's\RLNH.exe2007-02-16 16:25 26624 --a------ C:\Documents and Settings\Pete's\ORHE.exe2007-02-16 16:23 26624 --a------ C:\Documents and Settings\Pete's\JREN.exe2007-02-16 16:18 26624 --a------ C:\Documents and Settings\Pete's\CDEG.exe2007-02-15 20:32 26624 --a------ C:\Documents and Settings\Pete's\LUPQ.exe2007-02-15 17:36 26624 --a------ C:\Documents and Settings\Pete's\KRUP.exe2007-02-15 17:30 26624 --a------ C:\Documents and Settings\Pete's\NOCN.exe2007-02-15 17:05 26624 --a------ C:\Documents and Settings\Pete's\MOFD.exe2007-02-15 17:02 26624 --a------ C:\Documents and Settings\Pete's\QFLJ.exe2007-02-15 17:02 26624 --a------ C:\Documents and Settings\Pete's\NSDG.exe2007-02-15 16:59 26624 --a------ C:\Documents and Settings\Pete's\KRPN.exe2007-02-15 16:58 26624 --a------ C:\Documents and Settings\Pete's\NNSQ.exe2007-02-15 16:58 26624 --a------ C:\Documents and Settings\Pete's\BPHG.exe2007-02-15 16:57 26624 --a------ C:\Documents and Settings\Pete's\TLLH.exe2007-02-15 16:55 26624 --a------ C:\Documents and Settings\Pete's\DCBL.exe2007-02-15 16:54 26624 --a------ C:\Documents and Settings\Pete's\FNLH.exe2007-02-15 16:49 26624 --a------ C:\Documents and Settings\Pete's\HHJD.exe2007-02-15 16:47 26624 --a------ C:\Documents and Settings\Pete's\BFUM.exe2007-02-15 16:43 26624 --a------ C:\Documents and Settings\Pete's\EGCT.exe2007-02-15 16:42 26624 --a------ C:\Documents and Settings\Pete's\HFOD.exe2007-02-15 16:40 26624 --a------ C:\Documents and Settings\Pete's\CSRD.exe2007-02-15 16:38 26624 --a------ C:\Documents and Settings\Pete's\LKSB.exe2007-02-15 16:35 26624 --a------ C:\Documents and Settings\Pete's\OSTQ.exe2007-02-15 16:33 26624 --a------ C:\Documents and Settings\Pete's\PAOM.exe2007-02-15 16:31 26624 --a------ C:\Documents and Settings\Pete's\JRKJ.exe2007-02-15 16:30 26624 --a------ C:\Documents and Settings\Pete's\CTHC.exe2007-02-15 16:27 26624 --a------ C:\Documents and Settings\Pete's\RHLR.exe2007-02-15 16:27 26624 --a------ C:\Documents and Settings\Pete's\IARP.exe2007-02-15 16:24 26624 --a------ C:\Documents and Settings\Pete's\JERR.exe2007-02-15 16:23 26624 --a------ C:\Documents and Settings\Pete's\RPNH.exe2007-02-14 22:23 26624 --a------ C:\Documents and Settings\Pete's\NUSU.exe2007-02-14 22:06 26624 --a------ C:\Documents and Settings\Pete's\OQRO.exe2007-02-14 22:05 26624 --a------ C:\Documents and Settings\Pete's\IKIO.exe2007-02-14 22:02 26624 --a------ C:\Documents and Settings\Pete's\TBDT.exe2007-02-14 22:02 26624 --a------ C:\Documents and Settings\Pete's\EAEI.exe2007-02-14 21:59 26624 --a------ C:\Documents and Settings\Pete's\MJMN.exe2007-02-14 21:58 26624 --a------ C:\Documents and Settings\Pete's\RGTB.exe2007-02-14 21:58 26624 --a------ C:\Documents and Settings\Pete's\GKUI.exe2007-02-14 21:51 26624 --a------ C:\Documents and Settings\Pete's\CJNB.exe2007-02-14 21:39 26624 --a------ C:\Documents and Settings\Pete's\QUOK.exe2007-02-14 21:09 26624 --a------ C:\Documents and Settings\Pete's\HHGL.exe2007-02-14 20:58 26624 --a------ C:\Documents and Settings\Pete's\QHDJ.exe2007-02-14 20:56 26624 --a------ C:\Documents and Settings\Pete's\IERE.exe2007-02-14 20:55 26624 --a------ C:\Documents and Settings\Pete's\CIMU.exe2007-02-14 20:54 26624 --a------ C:\Documents and Settings\Pete's\BGRU.exe2007-02-14 20:44 26624 --a------ C:\Documents and Settings\Pete's\UPJD.exe.((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))..*Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B62F5B2F-FB3C-45BC-97BF-9EBE1A61AED4}] C:\WINDOWS\system32\awvtr.dll[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 17:04]"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2005-01-12 14:54]"HPHUPD05"="c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [2003-08-21 04:23]"HPHmon05"="C:\WINDOWS\System32\hphmon05.exe" [2003-08-21 04:15]"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-14 13:43]"VTTimer"="VTTimer.exe" [2004-01-15 21:33 C:\WINDOWS\system32\VTTimer.exe]"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-03-09 11:47]"UpdateManager"="c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 02:01]"AGRSMMSG"="AGRSMMSG.exe" [2005-03-04 12:01 C:\WINDOWS\AGRSMMSG.exe]"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-11-30 22:10]"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2005-02-11 18:24]"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-16 23:11]"KBD"="C:\HP\KBD\KBD.EXE" [2005-02-02 16:44]"lxcrmon.exe"="C:\Program Files\Lexmark 2400 Series\lxcrmon.exe" [2006-03-06 13:48]"EzPrint"="C:\Program Files\Lexmark 2400 Series\ezprint.exe" [2006-02-07 01:10]"LXCRCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll" [2006-02-24 07:54]"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24]"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-07-31 18:44]"{08-8B-BF-FC-ZN}"="c:\windows\system32\dwdsrngt.exe" [2007-10-04 19:21]"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 02:25]"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-08-25 19:07]"SpyHunter"="C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exe" []"Ink Monitor"="C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe" [2001-10-16 11:10]"C2K"="C:\WINDOWS\Cyb2k.exe" [2004-08-03 10:47]"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11][HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 09:24]"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24]"BackupNotify"="c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe" [2004-01-09 02:34]"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-04 19:23]C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe [2005-01-02 16:50:01]EPSON Status Monitor 3 Environment Check 2.lnk - C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE [2004-08-22 12:45:32]HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 13:19:24]Run Nintendo Wi-Fi USB Connector Registration Tool.lnk - C:\Program Files\WiFiConnector\NintendoWFCReg.exe [2006-12-09 19:08:41]Updates from HP.lnk - C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe [2004-04-01 14:16:45]C:\Documents and Settings\Pete's\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe [2007-02-03 19:40:21] TA_Start.lnk - C:\WINDOWS\system32\dwdsrngt.exe [2007-10-04 19:21:34]C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe [2005-01-02 16:50:01]EPSON Status Monitor 3 Environment Check 2.lnk - C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE [2004-08-22 12:45:32]HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 13:19:24]Run Nintendo Wi-Fi USB Connector Registration Tool.lnk - C:\Program Files\WiFiConnector\NintendoWFCReg.exe [2006-12-09 19:08:41]Updates from HP.lnk - C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe [2004-04-01 14:16:45][HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]"DisableRegistryTools"=0 (0x0)R2 UnoInstallerService;Uno Installer;C:\Program Files\M-Audio Uno\UnoInst.exeR3 dsreader;MaxDrive Driver (dsreader.sys);C:\WINDOWS\system32\Drivers\dsreader.sysR3 Eplpdx02;Eplpdx02;\??\C:\WINDOWS\System32\Drivers\EPLPDX02.SYSS3 EVOLUSB;%EVOL_USB_SvcDesc%;C:\WINDOWS\system32\drivers\evolusb.sysS3 pnicml;pnicml;\??\C:\DOCUME~1\Owner\LOCALS~1\Temp\pnicml.sysS3 samhid;samhid;C:\WINDOWS\system32\drivers\samhid.sys[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]AutoRun\command- D:\Info.exe folder.htt 480 480[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4d11b6a8-9432-11db-acf2-000d0bf817b3}]AutoRun\command- L:\setupSNK.exe.Contents of the 'Scheduled Tasks' folder"2007-09-08 04:40:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"- C:\Program Files\Apple Software Update\SoftwareUpdate.exe"2007-09-29 03:00:00 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - Owner.job""2007-09-14 22:16:34 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - Pete's.job"- c:\PROGRA~1\NORTON~1\NAVW32.EXE.**************************************************************************catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2007-10-04 19:21:30Windows 5.1.2600 Service Pack 2 NTFSscanning hidden processes ... scanning hidden autostart entries ...scanning hidden files ... **************************************************************************.Completion time: 2007-10-04 19:26:47 - machine was rebooted C:\ComboFix-quarantined-files.txt ... 2007-10-04 19:26. --- E O F --- Link to post Share on other sites
Andro1d Posted October 5, 2007 Report Share Posted October 5, 2007 Hello again,Well your PC just keeps getting reinfected right after we clean it. First what is your current AV that you are using? From what I can see they like like old 2004 Norton products, is that correct? Also do you have a firewall installed besides the built in Windows one?Please go to Start > Control Panel > Add or Remove Programs and remove the following (if present):Javaâ„¢ 6 Update 2Please also post a new HJT log. Link to post Share on other sites
kohu Posted October 5, 2007 Author Report Share Posted October 5, 2007 (edited) Ooh...Thats not good at all.yep We have the 2004 norton stuff, I think it came with the computer and it hasn't been renewed in a few years. I'm not sure if the norton firewall is active or not, but if it isn't then no. No other firewalls. Norton antivirus is used also.Edit: oops, forgot the HJT log, here it isLogfile of HijackThis v1.99.1Scan saved at 8:09:44 PM, on 10/4/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16512)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exec:\Program Files\Common Files\Symantec Shared\ccSetMgr.exec:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exeC:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exec:\Program Files\Common Files\Symantec Shared\ccProxy.exeC:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exec:\Program Files\Norton AntiVirus\navapsvc.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\M-Audio Uno\UnoInst.exeC:\Program Files\Viewpoint\Common\ViewpointService.exeC:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\wscntfy.exeC:\WINDOWS\System32\svchost.exeC:\windows\system\hpsysdrv.exeC:\Program Files\HP\hpcoretech\hpcmpmgr.exeC:\WINDOWS\System32\hphmon05.exeC:\WINDOWS\system32\VTTimer.exeC:\Program Files\Common Files\Symantec Shared\ccApp.exeC:\WINDOWS\AGRSMMSG.exeC:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exeC:\Program Files\HP\HP Software Update\HPWuSchd2.exeC:\HP\KBD\KBD.EXEC:\Program Files\Lexmark 2400 Series\lxcrmon.exeC:\Program Files\Lexmark 2400 Series\ezprint.exeC:\Program Files\iTunes\iTunesHelper.exeC:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exec:\windows\system32\dwdsrngt.exeC:\WINDOWS\system32\lxcrcoms.exeC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\WINDOWS\Cyb2k.exeC:\Program Files\Messenger\msmsgs.exeC:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exeC:\Program Files\HP\Digital Imaging\bin\hpqtra08.exeC:\Program Files\WiFiConnector\NintendoWFCReg.exeC:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exeC:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXEC:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exeC:\Program Files\iPod\bin\iPodService.exeC:\WINDOWS\system32\msiexec.exeC:\Program Files\Java\jre1.6.0_03\bin\jusched.exeC:\Documents and Settings\Pete's\My Documents\highjackthis\energy.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktopR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhostO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocxO2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dllO2 - BHO: StumbleUpon Launcher - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dllO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dllO2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dllO2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - c:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dllO2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dllO2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dllO2 - BHO: (no name) - {B62F5B2F-FB3C-45BC-97BF-9EBE1A61AED4} - C:\WINDOWS\system32\awvtr.dll (file missing)O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dllO3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dllO3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dllO3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dllO3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dllO3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - c:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dllO4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exeO4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exeO4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exeO4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXEO4 - HKLM\..\Run: [VTTimer] VTTimer.exeO4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"O4 - HKLM\..\Run: [updateManager] "c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /rO4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exeO4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exeO4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exeO4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exeO4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXEO4 - HKLM\..\Run: [lxcrmon.exe] "C:\Program Files\Lexmark 2400 Series\lxcrmon.exe"O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2400 Series\ezprint.exe"O4 - HKLM\..\Run: [LXCRCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll,_RunDLLEntry@16O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"O4 - HKLM\..\Run: [{08-8B-BF-FC-ZN}] c:\windows\system32\dwdsrngt.exe CHD003O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimizedO4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osbootO4 - HKLM\..\Run: [spyHunter] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exeO4 - HKLM\..\Run: [ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exeO4 - HKLM\..\Run: [C2K] C:\WINDOWS\Cyb2k.exeO4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /backgroundO4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - HKCU\..\Run: [backupNotify] c:\Program Files\HP\Digital Imaging\bin\backupnotify.exeO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exeO4 - Startup: PowerReg Scheduler V3.exeO4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\dwdsrngt.exeO4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exeO4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXEO4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exeO4 - Global Startup: Run Nintendo Wi-Fi USB Connector Registration Tool.lnk = C:\Program Files\WiFiConnector\NintendoWFCReg.exeO4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exeO8 - Extra context menu item: Download all links using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htmO8 - Extra context menu item: Download all videos using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htmO8 - Extra context menu item: Download link using &BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htmO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000O8 - Extra context menu item: Open in New &Window (PopOops) - C:\WINDOWS\Web\PopOops.htmO8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimageO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dllO9 - Extra button: Panda ActiveScan - {653D93AF-C741-4e5e-8C1B-59BA43F93E16} - http://www.pandasoftware.com/activescan (file missing)O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLLO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO11 - Options group: [iNTERNATIONAL] International*O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dllO15 - Trusted Zone: *.stumbleupon.comO16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cabO16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cabO16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cabO16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cabO16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cabO16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1187204501375O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cabO16 - DPF: {A954AFC3-3A26-44C2-A126-2B61C09F8FC9} (SNRecovery Control) - http://www.cybersitter.com/recovery/ocx/SerialRecovery.ocxO16 - DPF: {C52439A0-2693-4E40-B141-9F9AD5257241} (Lexmark eDiagnostics Class) - https://ediagnostics.lexmark.com/serval.cabO16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cabO20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dllO20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dllO21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dllO23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeO23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exeO23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exeO23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exeO23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exeO23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeO23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exeO23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exeO23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeO23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exeO23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exeO23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exeO23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXEO23 - Service: lxcr_device - - C:\WINDOWS\system32\lxcrcoms.exeO23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exeO23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exeO23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exeO23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exeO23 - Service: Uno Installer (UnoInstallerService) - Unknown owner - C:\Program Files\M-Audio Uno\UnoInst.exeO23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exeO23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe Edited October 5, 2007 by Kohu Link to post Share on other sites
Andro1d Posted October 5, 2007 Report Share Posted October 5, 2007 Well we don't really recommend Norton in the malware removal community due to it being a very big resource hog, there I am going to recommend you uninstall it since its outdated as well.Step 1So, let’s set you up with a FREE and excellent anti-virus program called avast! 4 Home Edition.First go HERE and download avast! 4 Home Edition to your Desktop. Steps for installing avast! 4 Home Edition:Locate the file for installing avast! double-click on the file to launch the installation of avast! Click Next on the avast! Setup window and on the next window with the ReadMe File.Now you will see the Legal Agreement, just click I agree, and then click Next to continue.You will be prompted with Configuration window, make sure that you choose Typical configuration and then click Next. Click Next to the windows that will follow, when the installation will finish, you will be given an option to schedule a boot time scan, select No Now you have to restart your machine, select Restart and then click Finish.After you restart you will get a message about avast! it will give you the general "Hello and Thank you for choicing our Product." Also after you restart you will notice 2 new icons in the bottom right corner of the screen.VERY IMPORTANT - after restarting, you will see two new tray icons right click on the a icon in the taskbar and select Updating, then highlight and click Program. You will get popup after its done updating. If avast! had to download anything for your computer you may get a message asking you to restart. After you have updated avast! right click the small icon a in task bar and click Start Avast! AntiVirus Click Program Registration and you will be taken to their website. Fill out the form and then check you e-mail. Once you get an e-mail from them (usually about 1 minute after submitting the form) copy and paste the serial they provided into the highlighted box. Then click ok.After this, you will need to Schedule Boot-Time Scan with avast! Click on the little button placed up in the left corner, and select Schedule Boot-Time Scan. Next, choose Scan all local disks scan archive filesclick on ScheduleOn the next dialog Operating system restart needed select YesNow avast! will restart your computer and start to scan before Windows fully loads. If detects infections while boot time scaning, you will be given choices for actions, choose move to chest actions and don't delete anything.IMPORTANT NOTE since your system has infections on it, avast! will give you dialog box with recommended actions, and options, please make sure if this happens, to click the Move to Chest button, and not to delete any reported files.Finally when the scan will finish the computer will boot in Normal Mode, then using Windows Explorer navigate to C:\Program Files\Alwil Software\Avast4\DATA\report\aswBoot.txt double click on aswBoot.txt it will open Notepad with report of the scan, please copy and paste the report in this thread. Note:If you are not able to use Normal Mode, to download programs and to update avast! use Safe Mode with Networking. To run scans reboot to Safe Mode. Do NOT use "Safe Mode with Networking" for running scans!If you have installed avast! from Safe Mode, when the setup is done, you will not see the two icons in the tray, instead of that use the icon at the desktop for updating and scheduling boot time scan The icons in the tray are visible in Normal Mode!Please post back with avast! scan report and new HijackThis log. Let me know if you have any problems with above instructions, or you have any questionsNote: You must use only 1 (one) AV at a time because if you have 2 or more AVs running at the same time, they will conflict with each other and make your security less reliable.Step 2Please install one of the following free firewalls for your PCComodoZone AlarmOutpost.**Tutorial on Firewalls can be found HERE**Step 3Please download the Norton Removal Tool from HERE and Save it to your DesktopClose all programs and double click the Norton_Removal_Tool.exeFollow the on-screen instructionsRestart the computer if askedThen delete Norton_Removal_Tool.exe from your desktopNow open the Program Files folder on your local disk ( normally C: )Find and delete the following folders (if present)Norton AntiVirus Norton Internet Security Norton SystemWorks Norton Personal Firewall Link to post Share on other sites
kohu Posted October 6, 2007 Author Report Share Posted October 6, 2007 Okay! Deleted Norton, installed Avast! and got Comodo running. I need to know if twinqmds.exe is safe or not because I can't find anything about it on google.Anyways, heres my HJT log. I'll post the Avast! log nextLogfile of HijackThis v1.99.1Scan saved at 7:20:01 PM, on 10/5/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16512)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Alwil Software\Avast4\aswUpdSv.exeC:\Program Files\Alwil Software\Avast4\ashServ.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\windows\system\hpsysdrv.exeC:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exeC:\Program Files\HP\hpcoretech\hpcmpmgr.exeC:\WINDOWS\System32\hphmon05.exeC:\WINDOWS\system32\VTTimer.exeC:\Program Files\Comodo\Firewall\cmdagent.exeC:\WINDOWS\AGRSMMSG.exeC:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exeC:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\HP\HP Software Update\HPWuSchd2.exeC:\HP\KBD\KBD.EXEC:\Program Files\M-Audio Uno\UnoInst.exeC:\Program Files\Viewpoint\Common\ViewpointService.exeC:\Program Files\Lexmark 2400 Series\lxcrmon.exeC:\Program Files\Lexmark 2400 Series\ezprint.exeC:\Program Files\iTunes\iTunesHelper.exeC:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exeC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\WINDOWS\Cyb2k.exeC:\Program Files\Java\jre1.6.0_03\bin\jusched.exeC:\WINDOWS\system32\twinqmds.exeC:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exeC:\Program Files\Comodo\Firewall\CPF.exeC:\Program Files\Messenger\msmsgs.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\Alwil Software\Avast4\ashMaiSv.exeC:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exeC:\Program Files\Alwil Software\Avast4\ashWebSv.exeC:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exeC:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exeC:\WINDOWS\system32\lxcrcoms.exeC:\Program Files\HP\Digital Imaging\bin\hpqtra08.exeC:\Program Files\WiFiConnector\NintendoWFCReg.exeC:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exeC:\Program Files\Internet Explorer\IEXPLORE.EXEC:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXEC:\WINDOWS\System32\svchost.exeC:\Program Files\internet explorer\iexplore.exeC:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exeC:\Program Files\iPod\bin\iPodService.exeC:\Documents and Settings\Pete's\My Documents\highjackthis\energy.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktopR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhostO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocxO2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dllO2 - BHO: StumbleUpon Launcher - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dllO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dllO2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dllO2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dllO2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dllO2 - BHO: (no name) - {B62F5B2F-FB3C-45BC-97BF-9EBE1A61AED4} - C:\WINDOWS\system32\awvtr.dll (file missing)O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dllO3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dllO3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dllO4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exeO4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exeO4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exeO4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXEO4 - HKLM\..\Run: [VTTimer] VTTimer.exeO4 - HKLM\..\Run: [updateManager] "c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /rO4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exeO4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exeO4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exeO4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXEO4 - HKLM\..\Run: [lxcrmon.exe] "C:\Program Files\Lexmark 2400 Series\lxcrmon.exe"O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2400 Series\ezprint.exe"O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimizedO4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osbootO4 - HKLM\..\Run: [spyHunter] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exeO4 - HKLM\..\Run: [ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exeO4 - HKLM\..\Run: [C2K] C:\WINDOWS\Cyb2k.exeO4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\twinqmds.exe CHD003O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exeO4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /backgroundO4 - HKLM\..\Run: [LXCRCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll,_RunDLLEntry@16O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /backgroundO4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - HKCU\..\Run: [backupNotify] c:\Program Files\HP\Digital Imaging\bin\backupnotify.exeO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exeO4 - Startup: PowerReg Scheduler V3.exeO4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\twinqmds.exeO4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exeO4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXEO4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exeO4 - Global Startup: Run Nintendo Wi-Fi USB Connector Registration Tool.lnk = C:\Program Files\WiFiConnector\NintendoWFCReg.exeO4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exeO8 - Extra context menu item: Download all links using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htmO8 - Extra context menu item: Download all videos using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htmO8 - Extra context menu item: Download link using &BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htmO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000O8 - Extra context menu item: Open in New &Window (PopOops) - C:\WINDOWS\Web\PopOops.htmO8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimageO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dllO9 - Extra button: Panda ActiveScan - {653D93AF-C741-4e5e-8C1B-59BA43F93E16} - http://www.pandasoftware.com/activescan (file missing)O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLLO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO11 - Options group: [iNTERNATIONAL] International*O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dllO15 - Trusted Zone: *.stumbleupon.comO16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cabO16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cabO16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cabO16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cabO16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cabO16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1187204501375O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cabO16 - DPF: {A954AFC3-3A26-44C2-A126-2B61C09F8FC9} (SNRecovery Control) - http://www.cybersitter.com/recovery/ocx/SerialRecovery.ocxO16 - DPF: {C52439A0-2693-4E40-B141-9F9AD5257241} (Lexmark eDiagnostics Class) - https://ediagnostics.lexmark.com/serval.cabO16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cabO20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dllO20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dllO21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dllO23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeO23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exeO23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exeO23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exeO23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exeO23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exeO23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exeO23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exeO23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exeO23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exeO23 - Service: lxcr_device - - C:\WINDOWS\system32\lxcrcoms.exeO23 - Service: Uno Installer (UnoInstallerService) - Unknown owner - C:\Program Files\M-Audio Uno\UnoInst.exeO23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exeO23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe Link to post Share on other sites
kohu Posted October 6, 2007 Author Report Share Posted October 6, 2007 Link to post Share on other sites
kohu Posted October 6, 2007 Author Report Share Posted October 6, 2007 (edited) Oh! And when I got home today there was a shortcut on my desktop for "15 free ringtones!" and "get yopur free iPhone here!" two more appeared just now. I think It might be because of thinkadz or something. Edited October 6, 2007 by Kohu Link to post Share on other sites
Andro1d Posted October 6, 2007 Report Share Posted October 6, 2007 (edited) Hi Kohu,Step 1Please re-open HijackThis and scan. Check the boxes next to all the entries listed below. O2 - BHO: (no name) - {B62F5B2F-FB3C-45BC-97BF-9EBE1A61AED4} - C:\WINDOWS\system32\awvtr.dll (file missing)O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\twinqmds.exe CHD003O4 - Startup: PowerReg Scheduler V3.exeO4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\twinqmds.exeO16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cabO16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cabNow close all windows other than Hijackthis, then click Fix Checked. Close HijackThis. Using Windows Explorer (to get there right-click your Start button and go to "Explore"), please delete these files (if present):C:\WINDOWS\system32\twinqmds.exeStep 2Download and unzip BFUzip from http://www.merijn.org/files/bfu.zipRun the program and click the Web button as shown here:Use this URL to copy into the address bar of the Download script window:http://metallica.geekstogo.com/MediaGateway.BFUMake sure all IE windows are closed.Execute the script by clicking the Execute button.If you have any questions about the use of BFU please read here:http://metallica.geekstogo.com/BFUinstructions.htmlStep 3Please run the F-Secure Online ScannerNote: This Scanner is for Internet Explorer Only!Follow the Instruction Here for installation.Accept the License Agreement.Once the ActiveX installs, Click Full System ScanOnce the download completes,the scan will begin automatically.The scan will take some time to finish, so please be patient.When the scan completes, click the Automatic cleaning (recommended) button.Click the Show Report button Please highlight everything inside the box, right-click, and choose copy.Please paste the information here for me. Edited October 6, 2007 by MoNsTeReNeRgY22 Link to post Share on other sites
kohu Posted October 6, 2007 Author Report Share Posted October 6, 2007 K, did the BFU thing and heres the log from F-SecureScanning ReportSaturday, October 06, 2007 11:02:54 - 13:30:52Computer name: SHADOW Scanning type: Scan system for viruses, rootkits, spyware Target: C:\ D:\ --------------------------------------------------------------------------------Result: 68 malware foundMalware.ADRA (virus) C:\HP\BIN\TRIALHTML\OFFICE 2003 EDITION 60 DAY TRIAL.EXE (Submitted) Tracking Cookie (spyware) System (Disinfected) System System System System System System System System System System System System System System System System System System System System System System System System System Vundo.dam (virus) C:\DECKARD\SYSTEM SCANNER\BACKUP\DOCUME~1\PETE'S\LOCALS~1\TEMP\QEYTGTMC.DLL (Submitted) C:\DECKARD\SYSTEM SCANNER\BACKUP\DOCUME~1\PETE'S\LOCALS~1\TEMP\TYKSNGLX.DLL (Submitted) C:\DECKARD\SYSTEM SCANNER\BACKUP\DOCUME~1\PETE'S\LOCALS~1\TEMP\VLAAGGVY.DLL (Submitted) C:\DECKARD\SYSTEM SCANNER\BACKUP\DOCUME~1\PETE'S\LOCALS~1\TEMP\VVEXJYSP.DLL (Submitted) Vundo.gen38 (virus) C:\WINDOWS\SYSTEM32\AOKLYWNB.INI (Submitted) C:\WINDOWS\SYSTEM32\DKTQLWMB.INI (Submitted) C:\WINDOWS\SYSTEM32\DVXBNWJX.INI (Submitted) C:\WINDOWS\SYSTEM32\DWVWGUKI.INI (Submitted) C:\WINDOWS\SYSTEM32\EUGOEIUB.INI (Submitted) C:\WINDOWS\SYSTEM32\EVNXUPBM.INI (Submitted) C:\WINDOWS\SYSTEM32\FGIRIWGE.INI (Submitted) C:\WINDOWS\SYSTEM32\JRKYSUUH.INI (Submitted) C:\WINDOWS\SYSTEM32\KNCAHCUV.INI (Submitted) C:\WINDOWS\SYSTEM32\ODEXOPRA.INI (Submitted) C:\WINDOWS\SYSTEM32\QBMYWCIV.INI (Submitted) C:\WINDOWS\SYSTEM32\RASIQALO.INI (Submitted) C:\WINDOWS\SYSTEM32\RYISDBET.INI (Submitted) C:\WINDOWS\SYSTEM32\SKMASOQM.INI (Submitted) C:\WINDOWS\SYSTEM32\SOEJVRLQ.INI (Submitted) C:\WINDOWS\SYSTEM32\THEQWNDY.INI (Submitted) C:\WINDOWS\SYSTEM32\TINAROEK.INI (Submitted) C:\WINDOWS\SYSTEM32\TLMGWICF.INI (Submitted) C:\WINDOWS\SYSTEM32\UBQWIPKS.INI (Submitted) C:\WINDOWS\SYSTEM32\VPWVONJJ.INI (Submitted) Vundo.gen39 (virus) C:\WINDOWS\SYSTEM32\AJHHKBJY.INI (Submitted) C:\WINDOWS\SYSTEM32\BHJPMRIE.INI (Submitted) C:\WINDOWS\SYSTEM32\EEEQIPDS.INI (Submitted) C:\WINDOWS\SYSTEM32\GHMXISUM.INI (Submitted) C:\WINDOWS\SYSTEM32\HNRWTSCL.INI (Submitted) C:\WINDOWS\SYSTEM32\ITOSLLCF.INI (Submitted) C:\WINDOWS\SYSTEM32\JPTPINSG.INI (Submitted) C:\WINDOWS\SYSTEM32\KAMOFHOA.INI (Submitted) C:\WINDOWS\SYSTEM32\LWOBJSST.INI (Submitted) C:\WINDOWS\SYSTEM32\MSDKIIUS.INI (Submitted) C:\WINDOWS\SYSTEM32\OKGJIBGB.INI (Submitted) C:\WINDOWS\SYSTEM32\PUCBSJTN.INI (Submitted) C:\WINDOWS\SYSTEM32\QIGRKETY.INI (Submitted) C:\WINDOWS\SYSTEM32\SOFLECPJ.INI (Submitted) C:\WINDOWS\SYSTEM32\SRTBVXEW.INI (Submitted) C:\WINDOWS\SYSTEM32\TUWRFDWI.INI (Submitted) C:\WINDOWS\SYSTEM32\TWUTSNIL.INI (Submitted) --------------------------------------------------------------------------------StatisticsScanned:Files: 74815 System: 6830 Not scanned: 13 Actions:Disinfected: 1 Renamed: 0 Deleted: 0 None: 67 Submitted: 42 Files not scanned:C:\HIBERFIL.SYS C:\PAGEFILE.SYS C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT C:\WINDOWS\PREFETCH\LAYOUT.INI C:\WINDOWS\$NTUNINSTALLQ828026$\MSDXM.OCX C:\WINDOWS\$NTUNINSTALLQ828026$\WMP.DLL C:\WINDOWS\$NTUNINSTALLKB839645$\FLDRCLNR.DLL C:\WINDOWS\$NTUNINSTALLKB837001$\DAO360.DLL C:\RECYCLER\S-1-5-21-321053874-2636943631-3830183119-1003\DC11.LNK C:\PROGRAM FILES\VIEWPOINT\VIEWPOINT MEDIA PLAYER\COMPONENTS\VETSDK.DLL C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE EDITION\XAUPDATE.EXE C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\PLUG_INS\MULTIMEDIA\MPP\ATMOSPHEREMPP.MPP C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\1DD491DC9AFBF2A7891310B584217359_A041A4AD-923E-4008-913D-823040B1FB43 --------------------------------------------------------------------------------OptionsScanning engines:F-Secure Libra: 2.4.2, 2007-10-05 F-Secure AVP: 7.0.171, 2007-10-06 F-Secure Orion: 1.2.37, 2007-10-06 F-Secure Blacklight: 1.0.64 F-Secure Draco: 1.0.35, 0598-150-72 F-Secure Pegasus: 1.19.0, 2007-09-02 Scanning options:Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB BAT LNK ANI AVB CEO CMD LSP MAP MHT MIF PDF PHP POT WMF NWS TAR TGZ WSF ZL? {* ZIP JAR ARJ LZH TAR TGZ GZ CAB RAR BZ2 HQX Use Advanced heuristics --------------------------------------------------------------------------------Copyright © 1998-2006 Product support |Send virus sample to F-SecureF-Secure assumes no responsibility for material created or published by third parties that F-Secure World Wide Web pages have a link to. Unless you have clearly stated otherwise, by submitting material to any of our servers, for example by E-mail or via our F-Secure's CGI E-mail, you agree that the material you make available may be published in the F-Secure World Wide Pages or hard-copy publications. You will reach F-Secure public web site by clicking on underlined links. While doing this, your access will be logged to our private access statistics with your domain name.This information will not be given to any third party. You agree not to take action against us in relation to material that you submit. Unless you have clearly stated otherwise, by submitting material you warrant that F-Secure may incorporate any concepts described in it in the F-Secure products/publications without liability. Link to post Share on other sites
Andro1d Posted October 7, 2007 Report Share Posted October 7, 2007 Hello again,Download ComboFix from Here or Here to your Desktop.Double click combofix.exe and follow the prompts.When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next replyNote: Do not mouseclick combofix's window while its running. That may cause it to stall Link to post Share on other sites
kohu Posted October 7, 2007 Author Report Share Posted October 7, 2007 Okay, I attached the Combofix log because It was too big to copy+paste.log.txt Link to post Share on other sites
Recommended Posts