Win32 Adan 094 nie daje spokoju

Avast wykrywa plik :http://85.255.117.124/users/rainy/web/images/two.jpg nie można go usunąć tylko przerwać połączenie, co pare minut zarzuca mnie okienkami z zagrozeniem jest to denerwujące i uciążliwe, Wydaje mi sie również, że na kompie sa inne robale ale nie wiem jakie :oops:

Za pomoc z góry dziękuje

Logfile of HijackThis v1.99.1

Scan saved at 18:46:24, on 2006-07-27

Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)


Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\LEXBCES.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\Programy\Avast4\aswUpdSv.exe

C:\Programy\Avast4\ashServ.exe

C:\WINDOWS\system32\LEXPPS.EXE

C:\Programy\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

C:\Programy\Avast4\ashMaiSv.exe

C:\Programy\Avast4\ashWebSv.exe

C:\WINDOWS\System32\alg.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\Explorer.EXE

C:\Programy\Avast4\ashDisp.exe

C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Windows Media Player\wmplayer.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Programy\Pomoc\HijackThis.exe


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.onet.pl/

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza

O1 - Hosts: localhost 127.0.0.1

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\ProgramyAcrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll

O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"

O4 - HKLM\..\Run: [avast!] C:\Programy\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [BearShare] "C:\Programy\BearShare\BearShare.exe" /pause

O4 - HKLM\..\Run: [mpxlu.exe] C:\WINDOWS\system32\mpxlu.exe

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O17 - HKLM\System\CCS\Services\Tcpip\..\{3401D607-ABB8-4BD5-9AA3-AE8A163CE1A4}: NameServer = 85.255.115.86,85.255.112.5

O17 - HKLM\System\CCS\Services\Tcpip\..\{D9653D66-0F26-480A-A696-AAD28C02DB7D}: NameServer = 85.255.115.86,85.255.112.5

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.86 85.255.112.5

O17 - HKLM\System\CS1\Services\Tcpip\..\{3401D607-ABB8-4BD5-9AA3-AE8A163CE1A4}: NameServer = 85.255.115.86,85.255.112.5

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.115.86 85.255.112.5

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Programy\Avast4\aswUpdSv.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

O23 - Service: avast! Antivirus - Unknown owner - C:\Programy\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programy\Avast4\ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:\Programy\Avast4\ashWebSv.exe" /service (file missing)

O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Programy\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

Mam nadzieje ze poprawnie napisalem posta :slight_smile:

1.Startujesz do trybu awaryjnego

2.Wyłanczasz przywracanie systemu (tylko Me/Xp)

3.Kasujesz wpisy w HijackThis

4.Kasujesz pogrubione pliki/foldery

5.Dajesz nowy log z hjt + log z Silent Runners

Puścić w ruch fixwareout i pokazać raport

No to chyba normalne, a jak ma ci on niby wywalić plik z czyjegoś serwera

Widzi coś w tym jpg i nie pozwala na połączenie

Latasz po jakiś może dziwnych stronach, stąd te komunikaty

Jak chcesz sie ich pozbyć to:

Odpal osłonę rezydenta => Osłona WWW=> Dostosuj i w zakładce Podstawowe odhacz Użyj inteligentnego skanowania strumieni

Zrobilem tak ja napisaliscie w postach narazie żadne komunikaty z avasta mi nie wyskakuja :slight_smile:

Co do tych wpisów które miałem usunac to dwóch nie bylo

O1 - Hosts: localhost 127.0.0.1

O4 - HKLM…\Run: [mpxlu.exe] C:\WINDOWS\system32\mpxlu.exe

Logfile of HijackThis v1.99.1

Scan saved at 12:58:50, on 2006-07-28

Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)


Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\LEXBCES.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\Programy\Avast4\aswUpdSv.exe

C:\Programy\Avast4\ashServ.exe

C:\WINDOWS\system32\LEXPPS.EXE

C:\Programy\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

C:\Programy\Avast4\ashMaiSv.exe

C:\Programy\Avast4\ashWebSv.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\Explorer.EXE

C:\Programy\Avast4\ashDisp.exe

C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Programy\Pomoc\HijackThis.exe


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.onet.pl/

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\ProgramyAcrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll

O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"

O4 - HKLM\..\Run: [avast!] C:\Programy\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [BearShare] "C:\Programy\BearShare\BearShare.exe" /pause

O4 - HKLM\..\Run: [rrlvz.exe] C:\WINDOWS\system32\rrlvz.exe

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Programy\Avast4\aswUpdSv.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

O23 - Service: avast! Antivirus - Unknown owner - C:\Programy\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programy\Avast4\ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:\Programy\Avast4\ashWebSv.exe" /service (file missing)

O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Programy\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

"Silent Runners.vbs", revision 46, http://www.silentrunners.org/

Operating System: Windows XP SP2

Output limited to non-default values, except where indicated by "{++}"



Startup items buried in registry:

---------------------------------


HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}

"NVMixerTray" = ""C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"" ["NVIDIA Corporation"]

"avast!" = "C:\Programy\Avast4\ashDisp.exe" [null data]

"RemoteControl" = ""C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"" ["Cyberlink Corp."]

"BearShare" = ""C:\Programy\BearShare\BearShare.exe" /pause" ["Free Peers, Inc."]

"rrlvz.exe" = "C:\WINDOWS\system32\rrlvz.exe" [file not found]


HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)

  -> {HKLM...CLSID} = "AcroIEHlprObj Class"

                   \InProcServer32\(Default) = "C:\ProgramyAcrobat 6.0\Reader\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]

{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided)

  -> {HKLM...CLSID} = "SSVHelper Class"

                   \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll" ["Sun Microsystems, Inc."]


HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\

"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania"

  -> {HKLM...CLSID} = "Rozszerzenie CPL kadrowania wyświetlania"

                   \InProcServer32\(Default) = "deskpan.dll" [file not found]

"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"

  -> {HKLM...CLSID} = "HyperTerminal Icon Ext"

                   \InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]

"{472083B0-C522-11CF-8763-00608CC02F24}" = "avast"

  -> {HKLM...CLSID} = "avast"

                   \InProcServer32\(Default) = "C:\Programy\Avast4\ashShell.dll" ["ALWIL Software"]

"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"

  -> {HKLM...CLSID} = "WinRAR"

                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

"{A5110426-177D-4e08-AB3F-785F10B4439C}" = "My Phones"

  -> {HKLM...CLSID} = "My Phones"

                   \InProcServer32\(Default) = "C:\Programy\Sony Ericsson\Mobile\File Manager\fmgrgui.dll" ["Sony Ericsson Mobile Communications AB"]

"{32020A01-506E-484D-A2A8-BE3CF17601C3}" = "AlcoholShellEx"

  -> {HKLM...CLSID} = "AlcoholShellEx"

                   \InProcServer32\(Default) = "C:\Programy\ALCOHO~1\ALCOHO~1\axshlex.dll" ["Alcohol Soft Development Team"]


HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\

"System" = (value not set)


HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\

INFECTION WARNING! AtiExtEvent\DLLName = "Ati2evxx.dll" ["ATI Technologies Inc."]


HKLM\Software\Classes\*\shellex\ContextMenuHandlers\

avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"

  -> {HKLM...CLSID} = "avast"

                   \InProcServer32\(Default) = "C:\Programy\Avast4\ashShell.dll" ["ALWIL Software"]

WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"

  -> {HKLM...CLSID} = "WinRAR"

                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\

WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"

  -> {HKLM...CLSID} = "WinRAR"

                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\

avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"

  -> {HKLM...CLSID} = "avast"

                   \InProcServer32\(Default) = "C:\Programy\Avast4\ashShell.dll" ["ALWIL Software"]

WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"

  -> {HKLM...CLSID} = "WinRAR"

                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]



Active Desktop and Wallpaper:

-----------------------------


Active Desktop is disabled at this entry:

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState


HKCU\Control Panel\Desktop\

"Wallpaper" = "C:\WINDOWS\web\wallpaper\Idylla.bmp"



Enabled Screen Saver:

---------------------


HKCU\Control Panel\Desktop\

"SCRNSAVE.EXE" = "C:\WINDOWS\System32\logon.scr" [MS]



Winsock2 Service Provider DLLs:

-------------------------------


Namespace Service Providers


HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}

000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]

000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]


Transport Service Providers


HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}

0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:

%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 14

%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05



Toolbars, Explorer Bars, Extensions:

------------------------------------


Extensions (Tools menu items, main toolbar menu buttons)


HKLM\Software\Microsoft\Internet Explorer\Extensions\

{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\

"MenuText" = "Sun Java Console"

"CLSIDExtension" = "{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBC}"

  -> {HKCU...CLSID} = "Java Plug-in"

                   \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll" ["Sun Microsystems, Inc."]

  -> {HKLM...CLSID} = "Java Plug-in 1.5.0_07"

                   \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_07\bin\npjpi150_07.dll" ["Sun Microsystems, Inc."]


{FB5F1910-F110-11D2-BB9E-00C04F795683}\

"ButtonText" = "Messenger"

"MenuText" = "Windows Messenger"

"Exec" = "C:\Program Files\Messenger\msmsgs.exe" [MS]



Running Services (Display Name, Service Name, Path {Service DLL}):

------------------------------------------------------------------


Ati HotKey Poller, Ati HotKey Poller, "C:\WINDOWS\system32\Ati2evxx.exe" ["ATI Technologies Inc."]

avast! Antivirus, avast! Antivirus, ""C:\Programy\Avast4\ashServ.exe"" [null data]

avast! iAVS4 Control Service, aswUpdSv, ""C:\Programy\Avast4\aswUpdSv.exe"" [null data]

avast! Mail Scanner, avast! Mail Scanner, ""C:\Programy\Avast4\ashMaiSv.exe" /service" ["ALWIL Software"]

avast! Web Scanner, avast! Web Scanner, ""C:\Programy\Avast4\ashWebSv.exe" /service" ["ALWIL Software"]

LexBce Server, LexBceS, "C:\WINDOWS\system32\LEXBCES.EXE" ["Lexmark International, Inc."]

StarWind iSCSI Service, StarWindService, "C:\Programy\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe" ["Rocket Division Software"]



Print Monitors:

---------------


HKLM\System\CurrentControlSet\Control\Print\Monitors\

Lexmark Network Port\Driver = "LEXLMPM.DLL" ["Lexmark International, Inc."]



----------

+ This report excludes default entries except where indicated.

+ To see *everywhere* the script checks and *everything* it finds,

  launch it from a command prompt or a shortcut with the -all parameter.

+ The search for DESKTOP.INI DLL launch points on all local fixed drives

  took 61 seconds.

+ The search for all Registry CLSIDs containing dormant Explorer Bars

  took 8 seconds.

---------- (total run time: 88 seconds)

Fixwareout ver 1.003

Last edited 07/1/2006

Post this report in the forums please 


Reg Entries that were deleted 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}83EEE9A7DCC5-9DB8-27E4-0E7C-35E934E5{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0674DAA8094A-0539-2BA4-8446-50CE4595{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E4D0970416BD-B449-43E4-310D-C4C19C33{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}56945987744C-4D89-B1E4-4DE4-19987575{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1ACF6F82F94E-1598-06C4-F998-4780AFF8{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}02B1C853B324-BEA9-63B4-538D-DBD1C649{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1AB641A6E8FC-838A-D674-65EB-94AA9CA6{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E4946C6F6A61-138A-C914-AEC7-92E28FFD{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5A5451B40745-6A9A-DBC4-9C39-E5D8E7EE{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5236C20C1569-DF18-8F74-9649-EEE450B5{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CC3429602DC0-3C29-EB24-7337-BF296A67{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}87B7B4FF719B-6B2A-2EB4-EE23-49368331{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}50BCA9DF07CC-D61A-4C14-3347-23CFF9C0{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8B193B84FD69-5EBB-DD04-5665-6723F81A{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}380D07310055-47CA-2534-7832-1CB061DF{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}DE85B76FBBB0-FC5A-B754-FCFE-E12F98E3{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}DEF38C31A2AB-EF7A-6DC4-C68F-C962DA5F{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D4B32526480E-B5FB-D114-6515-4F9E79DE{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F6CDB38A0A76-B21A-AC24-9FA5-A0AE516E{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}BB87CAF243F2-ADE9-4354-B020-5938A1BA{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E58AEF783DBF-9119-84E4-0934-C8FB28A6{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C2DDC87EE83C-F88A-D534-CE27-4D727B0E{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}408125B6662F-EF0A-FF44-EF2A-560EB40F{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}240465847C4A-ACB8-2D64-CAFE-626E1274{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}EC6C213C2277-A68B-DB24-0857-4B0A8DC6{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E9AD1F75074E-97DA-BFC4-C7B3-18C05F2F{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3542FD263518-49E9-8B84-8700-5F3D6CB2{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F4B66AB52701-47DA-BA14-DB34-3D97B69E{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}78B5F1E2F137-253A-97C4-C1CF-13D1040D{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}DC364CF9180F-40EA-A4F4-24F3-A11D2EB7{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0E7BC0A777B4-4829-8494-F267-3B95AAEF{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AC7D73EEE138-C9BA-6954-E94A-12F1A731{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9D5EB8E6BB49-3709-6754-9E5E-96F3D880{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9DBED37D6880-173B-5A84-9CCA-6DE39AE9{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}43764D6E5448-96E8-8E44-1A42-E8379B91{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FD35CEA9F32B-029B-FC04-8590-9D489B5E{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D00FBD15D887-E1F9-3654-C90F-C283DB7A{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0F70AEDC08B6-58C9-A674-08CC-462AFF74{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8EF9309BA0B9-086A-3214-498E-777CC349{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F48C0E76FC90-7C2A-2C34-281D-6D2E7622{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6CC6CB4A09D5-3D9B-3B14-497C-525C2506{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4381FEF6858D-2F1B-7214-AB65-C514609D{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B2D6C19CF54E-DA48-2BF4-89CB-30260F68{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6EF455BB6C66-0508-15E4-EFB0-BEEE018A{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3F372245132A-FCCA-72C4-A741-B4672AE2{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3E1BF2288E53-525A-8CF4-23F3-A0289D3B{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}BA8763D7FE5D-C23B-5674-49D0-9BFC36EC{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}47FB73E96384-A37B-10F4-5663-29F5BCD4{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0B097A74E33B-C3CB-DF64-94F2-6348CB39{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}75D6E0283B63-8249-EE94-9215-0605375B{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FB022200E32D-65A9-F7A4-2D36-EE9FFCCC{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6954718F6D32-833B-71C4-7D3C-176D1DA8{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B826F2D4B995-E62B-8F74-52BB-219BEAB0{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CD1178F63D8B-EB78-EB34-FDE7-A5A8740E{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}DA2CEA88259C-5569-35C4-0A30-B97AAC45{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}EFB1D3C95597-8E88-0CC4-DCCC-D3DA5F2A{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}220005FA7D90-4278-B504-1617-DCCBCB77{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5D00CB6B4D5B-D018-C054-2150-9BADB1CA{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C0126F71040C-5929-D074-157A-BB3ACFD3{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3A5D4B61E53F-2598-9414-D6DD-9A975C19{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3A83322A5C54-12C9-3B44-9943-5AA4D1B6{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}70BF16037109-08E9-2CD4-B91F-C501335C{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A55019139CAB-C63B-3704-3CEA-59045049{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}26BFEE2D0D62-9A0B-3294-F654-76955255{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E999DDD56AF8-ECFA-AF84-90A5-F044D692{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F5089B96688A-421A-BA74-BFFA-A41D2F31{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}79DA7BFFD344-2C49-2804-51FF-84CA353D{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}BB79D0D95517-FF0B-63D4-370F-412CD307{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2BD41D29E3DF-8689-8774-020D-597BC5B6{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}889F5BBC6383-AB99-8544-EEFD-BD32D367{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3C183B1D5EEB-7A29-CD34-EB71-68A5A1D1{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4C4677C2D10F-5B29-0634-C74C-B910C9BC{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1FFDEF30F762-0DFA-CE64-AD44-B4BF948B{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}BC3343AC9D60-C9E9-B0D4-2DB8-205B3358{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0361A60F8482-3369-8354-DE95-E7A58988{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}241207D7E3BB-CDCA-FA44-3642-335DF808{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8E5FA485013F-B058-61A4-9150-CA06DD95{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7627B9DC79B2-B4EA-E714-55FB-249FAFD9{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9F1C192FAA05-DF1B-D744-5559-A9EEB927{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6290D5210BD4-718B-0E34-6B6B-5454C558{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3F5A93AA83D3-FFF8-0CB4-B874-A246E0CA{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}60D38C54EBC7-9488-EE84-A614-DEA922C1{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D418BD9C897D-65DA-E574-7D3D-DB2A2902{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5FF7EEC270A5-0BBA-D404-E6E4-F98CFD13{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F13E8022C859-6DC8-68E4-5B0D-8BEC17A9{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B1FB769C7764-4C09-9544-8019-6A80BEFD{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C61E2111073D-A6DA-AA54-AF02-16339564{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}05C23A3ED028-301B-7AF4-0DD2-75D2368E{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1BA47CD63287-8F89-1C14-8848-E1EC929D{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D5CF5AD1E652-A659-4BB4-2099-6837F7F7{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F42B7D45BF52-A848-A024-5407-5EDC44C1{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}49A7C5AAA6AE-8E79-8CA4-C705-EC1A190D{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}40B0F5F01874-4588-7D94-EDE7-52376F68{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}08FE3C0E7247-A468-1CA4-AC19-F9D788DB{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}92635E9FBAD5-54C9-E2B4-5EB6-E938EB74{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}85BBA4517507-962A-D964-47D9-F219E3BA{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F54AABEBFBDE-A6E9-3FA4-4D75-AC9F96D4{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}64865EB38558-7C69-09B4-A101-2E515222{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A4FC567B14A0-A579-7EE4-2A88-5A9554DC{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6A6FEF14D33E-09B8-9AF4-87F0-1257ACE0{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}EE51DDE3CA0D-F76B-F0F4-B766-F5CA3864{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C08B12267615-EF28-8904-82A7-EB01D2A0{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}BD4B2CDBA139-A33A-78F4-C03E-D10ED7AA{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}28129B529EB8-30C9-2334-9AB1-E85D6B65{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}EF9E0F1B899C-42E9-4544-9C61-47B2CA19{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2B525CD071BF-C32B-A534-3FC3-B2C57820{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F7B788D40627-291B-9724-CBF2-2721B7A5{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B02F984F73E9-B7FB-7D44-AFD6-FCF7BFB3{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6EC12FB9931A-1389-A244-E37E-583D89AE{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7A36120B871D-FDB8-7614-8B12-87C44465{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}654FF49CD13E-9899-3D54-CFA3-95A9AD30{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B81727E6F314-39CB-B484-FD15-B353EF24{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AD891110A565-2B0B-A6C4-6FDB-C1798446{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4DA8A210ECFB-04DA-C264-4CA7-F947C338{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B2C4F5E1ED1F-73BB-61A4-C739-A74DC4EF{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F0324421735C-DD0B-9244-1A24-018EF96B{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FDF21EFE4361-70E8-0954-3455-1D8428DD{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0B4FA89BFE08-AA6B-2CB4-6B46-CE1B7737{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1DAAF25B4EED-C12A-FF74-EA31-97BEB51B{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}81DC3E6BF355-FF2B-B1C4-9A6F-829844CD{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CC521CD46DAE-CACA-2594-4BD1-41606538{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D4600E058F6D-5F88-F894-D634-0EC107E7{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}081347910630-F108-CB74-B8AD-4F6B6E39{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3E1A66E2ED54-1C38-66E4-2626-5209D790{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}88CB6F4BD84D-DD88-5D04-3F70-A1E30A5D{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}948CB7078FEA-5209-8EC4-D4CA-21708243{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}EC85BF369871-EBBA-8CF4-F3C8-88A82043{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7142C934BE22-9648-ACF4-010A-8332DC63{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9C894FADF850-84EB-EA44-8162-7862A5E7{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}46EBC6347803-B2A8-7784-C0EE-C2ACAC9E{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}755CD65DA832-FB49-9C54-C418-B970FAFF{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}CC3F7DFCF9D7-CCD9-2C94-3CB3-63C008EB{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F58A10C766DF-6ADB-B2B4-C878-FDADF32E{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}50F0C21663FA-D87B-5734-8243-59F52E16{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}00E1B6837BCB-2979-93C4-5D92-7EE1094C{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}874C723C08B8-F10B-9D34-9D1F-55D158CF{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B18FD9600BB8-75F9-BB04-8153-74D10712{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B7E3A2932F71-7A48-44B4-9D2A-84A8FEF7{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}416239A6C0FE-7A6B-D984-15BD-4D31BF8C{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D3A178A1B401-453B-CDE4-2B41-0D874016{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C85EA5E46A77-7089-2DE4-511C-7E9EE57D{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}64C907B08F78-9619-EDB4-C533-EA4D9C84{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8D8C069B5D18-9159-6F14-C13C-06A282EE{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C151772EB387-04AB-E944-CA51-C9C39D4F{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}40B30D7D766D-D4C8-8E14-692A-256ABF44{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}35566B2269B6-DE6B-5DF4-10B5-A346E12A{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7C6A95DDBEB9-1A7B-AD94-38A9-6AB5BE7F{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}19D71BD156DC-8488-0E54-1DF3-1382C6CB{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C2D7650B6C74-E739-F264-5D90-2021AEAB{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B01956F1C5B5-2A8A-34E4-5537-E1CBDE2B{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}61A52D8C9B85-E0AA-1964-4734-53B7DFC2{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}57E2DABE33FD-C118-C0B4-5A81-C574FA1D{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}07E89111F758-5679-DDB4-041A-8E886A89{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}DF8F00492310-A67B-DFE4-7748-70859426{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}047DE97F5E0D-27C8-AD94-B526-81B23CE6{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7820FE2CC805-EC18-8EC4-6825-221405F9{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3F4317D6FC83-D989-6954-4119-260C4BD5{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A8ACE3D6AB78-9B2A-AD54-C1BA-5E466496{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}63833057708E-34E8-02F4-7EF4-908E4A72{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}57EA48FC189F-C338-E214-3897-181C0CE1{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FD29AEC9BBA1-0FF8-E844-705C-D04A3C53{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}861BD75BD32D-5B09-BBF4-582F-0451C9F4{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6C7140AEC62E-6498-8E04-21E2-0A9668A2{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3E89E36211E4-D30B-E724-165E-2C2583C9{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5A69A0630BFD-8C2B-3464-E0D1-40E97F44{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}423B3B63B2AA-9608-6414-DCDC-B811F39E{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B4D605A3FF9F-0698-DD94-13F3-5B93DFAB{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}560A7B1F2D31-7D4A-A6F4-8E59-0D43D473{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}32FF495AD617-BDEA-2C64-85FA-12F319E0{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}DA6601F9FF65-F82B-4ED4-379A-A0615275{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6EFF2D6F7B79-B129-03C4-DC69-104FF8C8{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}DC4929DAC2A4-76A8-A674-C839-BA2C1FC1{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}43E5E2555418-42BA-7044-B766-94AD4518{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}06B400C3711F-2108-5D74-B67D-5E1F1EC8{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E692BBDE6D08-DF0A-5834-6F96-2C231D4A{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}96D7A2157ADA-E2F8-8A94-E214-FC48F9DD{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D8925C2DEAE7-4498-ED44-ED7B-114D90BD{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}53583310A4C4-99D9-9954-F7E3-B73EC262{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9B465E1901E8-4768-0744-E605-02E089E8{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}83A5EC58355D-9DBA-F2A4-805D-62CC1123{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}425CD4E5C2D9-CC98-0CB4-F5EE-7E5CD18D{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4881C2640AB6-0639-DE34-FF6A-2EF7959B{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B57F18E63679-FCA8-3D64-5D04-DB61B776{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A6A2FB257BEC-AC6A-78E4-4584-C330D747{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FAA7E4D065F1-AA4A-DCB4-9F63-B1D70D3D{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}987FD3D2B14F-8058-9574-40B6-82EC1576{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B2267E6D76ED-416A-EB54-A23B-20207921{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2BF9BB62FE39-8E58-7D84-DC4A-1488D1C6{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3F4D85058B61-08A9-B9D4-C61F-F29350E3{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}604AB54508E8-CBEA-AC54-D4D4-4137FCFB{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D0BD0131A7C4-B4CB-01E4-8270-BBB58AA9{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}05679E885F92-97B8-BB14-14F9-2398E168{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E541198BCE8A-6408-54D4-4C56-D8CEE807{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1F6C8E6E311E-4FA9-78A4-EC2F-D63E72AF{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5FC433AE9DD5-9838-A834-CE7C-D8EC5577{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}32E3BF5E0FBA-DA59-5A14-8C0F-7B2E9886{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8611016014C9-87D8-3E04-4801-D6B2BF2A{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0AC423C435E0-EC4B-E744-FAF4-EB3C7FD5{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}DD91DD790A81-8728-1BD4-A779-C41CD954{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C1C5D43A12D8-C67A-5924-56D5-CA4DCEBD{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1A42088F7BED-7E48-A074-D8A7-913DEFFF{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}ACCC06686236-5B8A-0964-7309-C4E5A3BF{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7128A73DF7E5-D478-CC84-DE9B-03EEFFB4{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4A502E03BC02-CF58-BCF4-2943-01B9BAC8{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8703097A06BB-F699-B104-8491-E35BD101{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A16B3F3F26AC-4EEA-60A4-CA6F-FDAB240A{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FEB53F5B33F5-909A-0524-22C8-FDDE4F43{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D3E385A7E6D6-E639-EF64-0594-E45F78C8{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}87257A8B2624-770B-D3B4-7B16-915B5E2C{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D04AB1DE0F1F-F408-8BD4-01F9-F22B6552{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E9D1659D5959-BA69-4074-1A92-E76ECF80{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}2605872C6456-1779-91F4-D6AF-A5FD010A{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3E5D3ED8A244-1B8B-4374-5EE9-DB338A28{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C83B652366A5-90D9-88F4-0453-F2DBB4ED{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}ACA6DD0F42E6-31EB-7234-A8B3-2EA76A2A{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E877A9F3F3E8-E97A-5314-07FB-37AF3773{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FEA51060F5C5-27C8-FE54-6B27-6FBA685B{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}74846849C49F-81EB-5DA4-2956-C02D9D35{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8D4E2A405F4F-7D48-A3F4-D148-15EEF476{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D7A25F5751BB-5118-9BD4-7FD3-22436FC6{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\mpfmd

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6BCF2D231FA1-618A-6B94-D752-6344ED24{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}48B686D53350-D08A-3264-CEA2-97EABCA9{

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\swen

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\ogol

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\eno

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\llun

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\ruof

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\evif

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\repiwoh

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\putesprpgd

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\onisacputes

...


Random Runs removed from HKLM 

"dmfpm.exe"=-

...


PLEASE NOTE, There WILL be LEGIT FILES LISTED. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.

Example ipsec6.exe is legitimate


»»»»» Search by size and names... 

* csr.exe C:\WINDOWS\System32\CSHGK.EXE


»»»»» Misc files 


»»»»» Checking for older varients covered by the Rem3 tool


»»»»» 

Search five digit cs, dm and jb files

This WILL/CAN also list Legit Files, Submit them at Virustotal

C:\WINDOWS\SYSTEM32\CSHGK.EXE 51 229 2006-07-26      

C:\WINDOWS\SYSTEM32\DMFPM.EXE 61 960 2004-08-04

 Other suspects

Directory of C:\WINDOWS\system32

{9ACBAE79-2AEC-4623-A80D-05335D686B84}.exe

{6CF63422-3DF7-4DB9-8115-BB1575F52A7D}.exe

{53D9D20C-6592-4AD5-BE18-F94C94864847}.exe

{B586ABF6-72B6-45EF-8C72-5C5F06015AEF}.exe

{3773FA73-BF70-4135-A79E-8E3F3F9A778E}.exe

{A2A67AE2-3B8A-4327-BE13-6E24F0DD6ACA}.exe

{DE4BBD2F-3540-4F88-9D09-5A663256B38C}.exe

{82A833BD-9EE5-4734-B8B1-442A8DE3D5E3}.exe

{A010DF5A-FA6D-4F19-9771-6546C2785062}.exe

{08FCE67E-29A1-4704-96AB-9595D9561D9E}.exe

{2556B22F-9F10-4DB8-804F-F1F0ED1BA40D}.exe

{C2E5B519-61B7-4B3D-B077-4262B8A75278}.exe

{8C87F54E-4950-46FE-936E-6D6E7A583E3D}.exe

{34F4EDDF-8C22-4250-A909-5F33B5F35BEF}.exe

{A042BADF-F6AC-4A06-AEE4-CA62F3F3B61A}.exe

{101DB53E-1948-401B-996F-BB60A7903078}.exe

{8CAB9B10-3492-4FCB-85FC-20CB30E205A4}.exe

{4BFFEE30-B9ED-48CC-874D-5E7FD37A8217}.exe

{FB3A5E4C-9037-4690-A8B5-63268660CCCA}.exe

{FFFED319-7A8D-470A-84E7-DEB7F88024A1}.exe

{DBECD4AC-5D65-4295-A76C-8D21A34D5C1C}.exe

{459DC14C-977A-4DB1-8278-18A097DD19DD}.exe

{5DF7C3BE-4FAF-447E-B4CE-0E534C324CA0}.exe

{A2FB2B6D-1084-40E3-8D78-9C4106101168}.exe

{6889E2B7-F0C8-41A5-95AD-ABF0E5FB3E23}.exe

{7755CE8D-C7EC-438A-8389-5DD9EA334CF5}.exe

{FA27E36D-F2CE-4A87-9AF4-E113E6E8C6F1}.exe

{708EEC8D-65C4-4D45-8046-A8ECB891145E}.exe

{861E8932-9F41-41BB-8B79-29F588E97650}.exe

{9AA85BBB-0728-4E10-BC4B-4C7A1310DB0D}.exe

{BFCF7314-4D4D-45CA-AEBC-8E80545BA406}.exe

{3E05392F-F16C-4D9B-9A80-16B85058D4F3}.exe

{6C1D8841-A4CD-48D7-85E8-93EF26BB9FB2}.exe

{12970202-B32A-45BE-A614-DE67D6E7622B}.exe

{6751CE28-6B04-4759-8508-F41B2D3DF789}.exe

{D3D07D1B-36F9-4BCD-A4AA-1F560D4E7AAF}.exe

{747D033C-4854-4E87-A6CA-CEB752BF2A6A}.exe

{677B16BD-40D5-46D3-8ACF-97636E81F75B}.exe

{B9597FE2-A6FF-43ED-9360-6BA0462C1884}.exe

{D81DC5E7-EE5F-4BC0-89CC-9D2C5E4DC524}.exe

{8E980E20-506E-4470-8674-8E1091E564B9}.exe

{262CE37B-3E7F-4599-9D99-4C4A01338535}.exe

{DB09D411-B7DE-44DE-8944-7EAED2C5298D}.exe

{DD9F84CF-412E-49A8-8F2E-ADA7512A7D69}.exe

{A4D132C2-69F6-4385-A0FD-80D6EDBB296E}.exe

{8CE1F1E5-D76B-47D5-8012-F1173C004B60}.exe

{8154DA49-667B-4407-AB24-8145552E5E34}.exe

{1CF1C2AB-938C-476A-8A67-4A2CAD9294CD}.exe

{8C8FF401-96CD-4C30-921B-97B7F6D2FFE6}.exe

{5725160A-A973-4DE4-B28F-56FF9F1066AD}.exe

{0E913F21-AF58-46C2-AEDB-716DA594FF23}.exe

{374D34D0-95E8-4F6A-A4D7-13D2F1B7A065}.exe

{BAFD39B5-3F31-49DD-8960-F9FF3A506D4B}.exe

{E93F118B-CDCD-4146-8069-AA2B36B3B324}.exe

{44F79E04-1D0E-4643-B2C8-DFB0360A96A5}.exe

{9C3852C2-E561-427E-B03D-4E11263E98E3}.exe

{2A8669A0-2E12-40E8-8946-E26CEA0417C6}.exe

{4F9C1540-F285-4FBB-90B5-D23DB57DB168}.exe

{35C3A40D-C507-448E-8FF0-1ABB9CEA92DF}.exe

{1EC0C181-7983-412E-833C-F981CF84AE75}.exe

{27A4E809-4FE7-4F20-8E43-E80775033836}.exe

{694664E5-AB1C-45DA-A2B9-87BA6D3ECA8A}.exe

{5DB4C062-9114-4596-989D-38CF6D7134F3}.exe

{9F504122-5286-4CE8-81CE-508CC2EF0287}.exe

{6EC32B18-625B-49DA-8C72-D0E5F79ED740}.exe

{62495807-8477-4EFD-B76A-01329400F8FD}.exe

{98A688E8-A140-4BDD-9765-857F11198E70}.exe

{D1AF475C-18A5-4B0C-811C-DF33EBAD2E75}.exe

{2CFD7B35-4374-4691-AA0E-58B9C8D25A16}.exe

{B2EDBC1E-7355-4E43-A8A2-5B5C1F65910B}.exe

{BAEA1202-09D5-462F-937E-47C6B0567D2C}.exe

{BC6C2831-3FD1-45E0-8848-CD651DB17D91}.exe

{F7EB5BA6-9A83-49DA-B7A1-9BEBDD59A6C7}.exe

{A21E643A-5B01-4FD5-B6ED-6B9622B66553}.exe

{44FBA652-A296-41E8-8C4D-D667D7D03B04}.exe

{F4D93C9C-15AC-449E-BA40-783BE277151C}.exe

{EE282A60-C31C-41F6-9519-81D5B960C8D8}.exe

{48C9D4AE-335C-4BDE-9169-87F80B709C46}.exe

{D75EE9E7-C115-4ED2-9807-77A64E5AE58C}.exe

{610478D0-14B2-4EDC-B354-104B1A871A3D}.exe

{C8FB13D4-DB51-489D-B6A7-EF0C6A932614}.exe

{7FEF8A48-A2D9-4B44-84A7-17F2392A3E7B}.exe

{21701D47-3518-40BB-9F57-8BB0069DF81B}.exe

{FC851D55-F1D9-43D9-B01F-8B80C327C478}.exe

{C4901EE7-29D5-4C39-9792-BCB7386B1E00}.exe

{61E25F95-3428-4375-B78D-AF36612C0F05}.exe

{E23FDADF-878C-4B2B-BDA6-FD667C01A85F}.exe

{BE800C36-3BC3-49C2-9DCC-7D9FCFD7F3CC}.exe

{FFAF079B-814C-45C9-94BF-238AD56DC557}.exe

{E9CACA2C-EE0C-4877-8A2B-3087436CBE64}.exe

{7E5A2687-2618-44AE-BE48-058FDAF498C9}.exe

{36CD2338-A010-4FCA-8469-22EB439C2417}.exe

{34028A88-8C3F-4FC8-ABBE-178963FB58CE}.exe

{34280712-AC4D-4CE8-9025-AEF8707BC849}.exe

{D5A03E1A-07F3-40D5-88DD-D48DB4F6BC88}.exe

{097D9025-6262-4E66-83C1-45DE2E66A1E3}.exe

{93E6B6F4-DA8B-47BC-801F-036019743180}.exe

{7E701CE0-436D-498F-88F5-D6F850E0064D}.exe

{83560614-1DB4-4952-ACAC-EAD64DC125CC}.exe

{DC448928-F6A9-4C1B-B2FF-553FB6E3CD18}.exe

{B15BEB79-13AE-47FF-A21C-DEE4B52FAAD1}.exe

{7377B1EC-64B6-4BC2-B6AA-80EFB98AF4B0}.exe

{DD8248D1-5543-4590-8E07-1634EFE12FDF}.exe

{B69FE810-42A1-4429-B0DD-C5371244230F}.exe

{FE4CD47A-937C-4A16-BB37-F1DE1E5F4C2B}.exe

{833C749F-7AC4-462C-AD40-BFCE012A8AD4}.exe

{6448971C-BDF6-4C6A-B0B2-565A011198DA}.exe

{42FE353B-51DF-484B-BC93-413F6E72718B}.exe

{03DA9A59-3AFC-45D3-9989-E31DC94FF456}.exe

{56444C78-21B8-4167-8BDF-D178B02163A7}.exe

{EA98D385-E73E-442A-9831-A1399BF21CE6}.exe

{3BFB7FCF-6DFA-44D7-BF7B-9E37F489F20B}.exe

{5A7B1272-2FBC-4279-B192-72604D887B7F}.exe

{02875C2B-3CF3-435A-B23C-FB170DC525B2}.exe

{91AC2B74-16C9-4454-9E24-C998B1F0E9FE}.exe

{56B6D58E-1BA9-4332-9C03-8BE925B92182}.exe

{AA7DE01D-E30C-4F87-A33A-931ABDC2B4DB}.exe

{9DF390F4-98B3-4207-8F55-4B6C7F777AF2}.exe

{05A7D14C-1580-4269-8543-D68447334767}.exe

{4AE38142-50CC-413A-91FC-124A399226CA}.exe

{0A2D10BE-7A28-4098-82FE-51676221B80C}.exe

{4683AC5F-667B-4F0F-B67F-D0AC3EDD15EE}.exe

{0ECA7521-0F78-4FA9-8B90-E33D41FEF6A6}.exe

{CD4559A5-88A2-4EE7-975A-0A41B765CF4A}.exe

{222515E2-101A-4B90-96C7-85583BE56846}.exe

{4D69F9CA-57D4-4AF3-9E6A-EDBFBEBAA45F}.exe

{AB3E912F-9D74-469D-A269-7057154ABB58}.exe

{47BE839E-6BE5-4B2E-9C45-5DABF9E53629}.exe

{BD887D9F-91CA-4AC1-864A-7427E0C3EF80}.exe

{86F67325-7EDE-49D7-8854-47810F5F0B04}.exe

{D091A1CE-507C-4AC8-97E8-EA6AAA5C7A94}.exe

{1C44CDE5-7045-420A-848A-25FB54D7B24F}.exe

{7F7F7386-9902-4BB4-956A-256E1DA5FC5D}.exe

{D929CE1E-8488-41C1-98F8-78236DC74AB1}.exe

{E8632D57-2DD0-4FA7-B103-820DE3A32C50}.exe

{46593361-20FA-45AA-AD6A-D3701112E16C}.exe

{DFEB08A6-9108-4459-90C4-4677C967BF1B}.exe

{9A71CEB8-D0B5-4E86-8CD6-958C2208E31F}.exe

{31DFC89F-4E6E-404D-ABB0-5A072CEE7FF5}.exe

{2092A2BD-D3D7-475E-AD56-D798C9DB814D}.exe

{1C229AED-416A-48EE-8849-7CBE45C83D06}.exe

{AC0E642A-478B-4BC0-8FFF-3D38AA39A5F3}.exe

{855C4545-B6B6-43E0-B817-4DB0125D0926}.exe

{729BEE9A-9555-447D-B1FD-50AAF291C1F9}.exe

{9DFAF942-BF55-417E-AE4B-2B97CD9B7267}.exe

{59DD60AC-0519-4A16-850B-F310584AF5E8}.exe

{808FD533-2463-44AF-ACDC-BB3E7D702142}.exe

{88985A7E-59ED-4538-9633-2848F06A1630}.exe

{8533B502-8BD2-4D0B-9E9C-06D9CA3433CB}.exe

{B849FB4B-44DA-46EC-AFD0-267F03FEDFF1}.exe

{CB9C019B-C47C-4360-92B5-F01D2C7764C4}.exe

{1D1A5A86-17BE-43DC-92A7-BEE5D1B381C3}.exe

{763D23DB-DFEE-4458-99BA-3836CBB5F988}.exe

{6B5CB795-D020-4778-9868-FD3E92D14DB2}.exe

{703DC214-F073-4D36-B0FF-71559D0D97BB}.exe

{D353AC48-FF15-4082-94C2-443DFFB7AD97}.exe

{13F2D14A-AFFB-47AB-A124-A88669B9805F}.exe

{296D440F-5A09-48FA-AFCE-8FA65DDD999E}.exe

{55255967-456F-4923-B0A9-26D0D2EEFB62}.exe

{94054095-AEC3-4073-B36C-BAC93191055A}.exe

{C533105C-F19B-4DC2-9E80-90173061FB07}.exe

{6B1D4AA5-3499-44B3-9C21-45C5A22338A3}.exe

{91C579A9-DD6D-4149-8952-F35E16B4D5A3}.exe

{3DFCA3BB-A751-470D-9295-C04017F6210C}.exe

{AC1BDAB9-0512-450C-810D-B5D4B6BC00D5}.exe

{77BCBCCD-7161-405B-8724-09D7AF500022}.exe

{A2F5AD3D-CCCD-4CC0-88E8-79559C3D1BFE}.exe

{54CAA79B-03A0-4C53-9655-C95288AEC2AD}.exe

{E0478A5A-7EDF-43BE-87BE-B8D36F8711DC}.exe

{0BAEB912-BB25-47F8-B26E-599B4D2F628B}.exe

{8AD1D671-C3D7-4C17-B338-23D6F8174596}.exe

{CCCFF9EE-63D2-4A7F-9A56-D23E002220BF}.exe

{B5735060-5129-49EE-9428-36B3820E6D57}.exe

{93BC8436-2F49-46FD-BC3C-B33E47A790B0}.exe

{4DCB5F92-3665-4F01-B73A-48369E37BF74}.exe

{CE63CFB9-0D94-4765-B32C-D5EF7D3678AB}.exe

{B3D9820A-3F32-4FC8-A525-35E8822FB1E3}.exe

{2EA2764B-147A-4C27-ACCF-A231542273F3}.exe

{A810EEEB-0BFE-4E51-8050-66C6BB554FE6}.exe

{86F06203-BC98-4FB2-84AD-E45FC91C6D2B}.exe

{D906415C-56BA-4127-B1F2-D8586FEF1834}.exe

{6052C525-C794-41B3-B9D3-5D90A4BC6CC6}.exe

{2267E2D6-D182-43C2-A2C7-09CF67E0C84F}.exe

{943CC777-E894-4123-A680-9B0AB9039FE8}.exe

{47FFA264-CC80-476A-9C85-6B80CDEA07F0}.exe

{A7BD382C-F09C-4563-9F1E-788D51DBF00D}.exe

{E5B984D9-0958-40CF-B920-B23F9AEC53DF}.exe

{19B9738E-24A1-44E8-8E69-8445E6D46734}.exe

{9EA93ED6-ACC9-48A5-B371-0886D73DEBD9}.exe

{088D3F69-E5E9-4576-9073-94BB6E8BE5D9}.exe

{137A1F21-A49E-4596-AB9C-831EEE37D7CA}.exe

{FEAA59B3-762F-4948-9284-4B777A0CB7E0}.exe

{7BE2D11A-3F42-4F4A-AE04-F0819FC463CD}.exe

{D0401D31-FC1C-4C79-A352-731F2E1F5B87}.exe

{E96B79D3-43BD-41AB-AD74-10725BA66B4F}.exe

{2BC6D3F5-0078-48B8-9E94-815362DF2453}.exe

{F2F50C81-3B7C-4CFB-AD79-E47057F1DA9E}.exe

{6CD8A0B4-7580-42BD-B86A-7722C312C6CE}.exe

{4721E626-EFAC-46D2-8BCA-A4C748564042}.exe

{F04BE065-A2FE-44FF-A0FE-F2666B521804}.exe

{E0B727D4-72EC-435D-A88F-C38EE78CDD2C}.exe

{6A82BF8C-4390-4E48-9119-FBD387FEA85E}.exe

{AB1A8395-020B-4534-9EDA-2F342FAC78BB}.exe

{E615EA0A-5AF9-42CA-A12B-67A0A83BDC6F}.exe

{ED97E9F4-5156-411D-BF5B-E08462523B4D}.exe

{F5AD269C-F86C-4CD6-A7FE-BA2A13C83FED}.exe

{3E89F21E-EFCF-457B-A5CF-0BBBF67B58ED}.exe

{FD160BC1-2387-4352-AC74-55001370D083}.exe

{A18F3276-5665-40DD-BBE5-96DF48B391B8}.exe

{0C9FFC32-7433-41C4-A16D-CC70FD9ACB05}.exe

{13386394-32EE-4BE2-A2B6-B917FF4B7B78}.exe

{5B054EEE-9469-47F8-81FD-9651C02C6325}.exe

{EE7E8D5E-93C9-4CBD-A9A6-54704B1545A5}.exe

{DFF82E29-7CEA-419C-A831-16A6F6C6494E}.exe

{6AC9AA49-BE56-476D-A838-CF8E6A146BA1}.exe

{946C1DBD-D835-4B36-9AEB-423B358C1B20}.exe

{8FFA0874-899F-4C60-8951-E49F28F6FCA1}.exe

{57578991-4ED4-4E1B-98D4-C44778954965}.exe

{33C91C4C-D013-4E34-944B-DB6140790D4E}.exe

{5954EC05-6448-4AB2-9350-A4908AAD4760}.exe

Nie wiem czy poprawnie umiescilem ten ostatni raport wydaje mi sie troche przydługi

Skasuj hijackiem

Otwórz notatnik i wklej:

Plik>>>zapisz jako>>>zmień rozszerzenie z .txt na wszystki pliki>>>zapisz pod nazwą FIX.BAT i uruchom w trybie awaryjnym